-<h1><%= t('user_block.revoke.heading',
- :block_on => @user_block.user.display_name,
- :block_by => @user_block.creator.display_name) %></h1>
+<% @title = t('user_block.revoke.title',
+ :block_on => h(@user_block.user.display_name),
+ :block_by => h(@user_block.creator.display_name)) %>
+<h1><%= t('user_block.revoke.heading',
+ :block_on => link_to(
+ h(@user_block.user.display_name),
+ {:controller => 'user', :action => 'view', :display_name => @user_block.user.display_name}),
+ :block_by => link_to(
+ h(@user_block.creator.display_name),
+ {:controller => 'user', :action => 'view', :display_name => @user_block.creator.display_name})) %></h1>
<% if @user_block.ends_at > Time.now %>
<p><b>
<%= t('user_block.revoke.time_future', :time => distance_of_time_in_words_to_now(@user_block.ends_at)) %>
</b></p>
-<% form_for :revoke, :url => { :action => "revoke" } do |f| %>
+<%= form_for :revoke, :url => { :action => "revoke" } do |f| %>
<%= f.error_messages %>
<p>
<%= check_box_tag 'confirm', 'yes' %>