-<% session[:token] = @user.tokens.create.token unless session[:token] %>
-
-<% if params['mlon'] and params['mlat'] %>
-<% lon = params['mlon'] %>
-<% lat = params['mlat'] %>
-<% zoom = params['zoom'] || '12' %>
-<% elsif @user and params['lon'].nil? and params['lat'].nil? %>
-<% lon = @user.home_lon %>
-<% lat = @user.home_lat %>
-<% zoom = '12' %>
-<%else%>
-<% lon = params['lon'] || '-0.1' %>
-<% lat = params['lat'] || '51.5' %>
-<% zoom = params['zoom'] || '12' %>
-<% end %>
-
-<div id="map">You need a Flash player to use Potlatch, the
+<%
+session[:token] = @user.tokens.create.token unless session[:token]
+
+if params['mlon'] and params['mlat']
+ lon = h(params['mlon'])
+ lat = h(params['mlat'])
+ zoom = h(params['zoom'] || '14')
+
+elsif @user and params['lon'].nil? and params['lat'].nil? and params['gpx'].nil?
+ lon = @user.home_lon
+ lat = @user.home_lat
+ zoom = '14'
+else
+ lon = h(params['lon'] || 'null')
+ lat = h(params['lat'] || 'null')
+ zoom = h(params['zoom'] || '14')
+end
+%>
+
+<div id="map">
+ You need a Flash player to use Potlatch, the