when showing user comments xss attack is prevented

Closes #260

Merge request reports

Loading