mirror of
https://github.com/alchemy-fr/Phraseanet.git
synced 2025-10-23 09:53:15 +00:00
fix prod escaping
This commit is contained in:
@@ -597,7 +597,7 @@ class PushController extends Controller
|
||||
|
||||
private function formatUser(User $user)
|
||||
{
|
||||
$subtitle = array_filter([$user->getJob(), $user->getCompany()]);
|
||||
$subtitle = array_filter([htmlspecialchars($user->getJob()), htmlspecialchars($user->getCompany())]);
|
||||
|
||||
return [
|
||||
'type' => 'USER',
|
||||
|
@@ -939,7 +939,7 @@ class record_adapter implements RecordInterface, cache_cacheableInterface
|
||||
$this->set_data_to_cache(self::CACHE_TITLE, $title);
|
||||
}
|
||||
|
||||
return $title;
|
||||
return htmlspecialchars($title);
|
||||
}
|
||||
|
||||
/**
|
||||
|
@@ -149,7 +149,7 @@ class record_preview extends record_adapter
|
||||
$this->original_item = $element;
|
||||
$sbas_id = $element->getSbasId();
|
||||
$record_id = $element->getRecordId();
|
||||
$this->name = $Basket->getName();
|
||||
$this->name = htmlspecialchars($Basket->getName());
|
||||
$number = $element->getOrd();
|
||||
$first = false;
|
||||
}
|
||||
@@ -169,7 +169,7 @@ class record_preview extends record_adapter
|
||||
if ($element->getOrd() == $pos || $first) {
|
||||
$sbas_id = $element->getSbasId();
|
||||
$record_id = $element->getRecordId();
|
||||
$this->name = $entry->getTitle();
|
||||
$this->name = htmlspecialchars($entry->getTitle());
|
||||
$this->original_item = $element;
|
||||
$number = $element->getOrd();
|
||||
$first = false;
|
||||
|
Reference in New Issue
Block a user