mirror of
https://github.com/alchemy-fr/Phraseanet.git
synced 2025-10-13 21:13:26 +00:00
fix prod escaping
This commit is contained in:
@@ -597,7 +597,7 @@ class PushController extends Controller
|
||||
|
||||
private function formatUser(User $user)
|
||||
{
|
||||
$subtitle = array_filter([$user->getJob(), $user->getCompany()]);
|
||||
$subtitle = array_filter([htmlspecialchars($user->getJob()), htmlspecialchars($user->getCompany())]);
|
||||
|
||||
return [
|
||||
'type' => 'USER',
|
||||
|
@@ -939,7 +939,7 @@ class record_adapter implements RecordInterface, cache_cacheableInterface
|
||||
$this->set_data_to_cache(self::CACHE_TITLE, $title);
|
||||
}
|
||||
|
||||
return $title;
|
||||
return htmlspecialchars($title);
|
||||
}
|
||||
|
||||
/**
|
||||
|
@@ -149,7 +149,7 @@ class record_preview extends record_adapter
|
||||
$this->original_item = $element;
|
||||
$sbas_id = $element->getSbasId();
|
||||
$record_id = $element->getRecordId();
|
||||
$this->name = $Basket->getName();
|
||||
$this->name = htmlspecialchars($Basket->getName());
|
||||
$number = $element->getOrd();
|
||||
$first = false;
|
||||
}
|
||||
@@ -169,7 +169,7 @@ class record_preview extends record_adapter
|
||||
if ($element->getOrd() == $pos || $first) {
|
||||
$sbas_id = $element->getSbasId();
|
||||
$record_id = $element->getRecordId();
|
||||
$this->name = $entry->getTitle();
|
||||
$this->name = htmlspecialchars($entry->getTitle());
|
||||
$this->original_item = $element;
|
||||
$number = $element->getOrd();
|
||||
$first = false;
|
||||
|
@@ -19,7 +19,7 @@
|
||||
<img src='/assets/common/images/icons/basket_push_unread.png' title=''/>
|
||||
{% endif %}
|
||||
<img src='/assets/common/images/icons/basket.png' title=''/>
|
||||
{{basket.getName()}}
|
||||
{{basket.getName()|e}}
|
||||
</span>
|
||||
</a>
|
||||
<div class="menu">
|
||||
@@ -99,7 +99,7 @@
|
||||
{% else %}
|
||||
<img src='/assets/common/images/icons/basket.png' title=''/>
|
||||
{% endif %}
|
||||
{{basket.getName()}}
|
||||
{{basket.getName()|e}}
|
||||
</span>
|
||||
</a>
|
||||
<div class="menu">
|
||||
|
Reference in New Issue
Block a user