From bb8ec7e386d16b4e5dca251d93ae471d8afaf747 Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/invoice-create.tpl.php | 152 ++++++++++---------- Theme/Backend/invoice-list.tpl.php | 22 +-- Theme/Backend/purchase-invoice-list.tpl.php | 22 +-- 3 files changed, 98 insertions(+), 98 deletions(-) diff --git a/Theme/Backend/invoice-create.tpl.php b/Theme/Backend/invoice-create.tpl.php index 1f60ed5..c2674bc 100644 --- a/Theme/Backend/invoice-create.tpl.php +++ b/Theme/Backend/invoice-create.tpl.php @@ -21,12 +21,12 @@ echo $this->getData('nav')->render(); ?>
@@ -35,37 +35,37 @@ echo $this->getData('nav')->render(); ?>
-

getText('Invoice') ?>

+

getHtml('Invoice'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -74,23 +74,23 @@ echo $this->getData('nav')->render(); ?>
-

getText('Invoice') ?>

+

getHtml('Invoice'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
@@ -100,23 +100,23 @@ echo $this->getData('nav')->render(); ?>
-

getText('Delivery') ?>

+

getHtml('Delivery'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
@@ -131,26 +131,26 @@ echo $this->getData('nav')->render(); ?>
- +
getText('Invoice') ?>getHtml('Invoice'); ?>
- getText('Item'); ?> - getText('Variation'); ?> - getText('Name'); ?> - getText('Quantity'); ?> - getText('Discount'); ?> - getText('DiscountP'); ?> - getText('Bonus'); ?> - getText('Tax'); ?> - getText('Net'); ?> + getHtml('Item') ?> + getHtml('Variation') ?> + getHtml('Name') ?> + getHtml('Quantity') ?> + getHtml('Discount') ?> + getHtml('DiscountP') ?> + getHtml('Bonus') ?> + getHtml('Tax') ?> + getHtml('Net') ?>
- getText('Freightage'); ?>: 0.00 - - getText('Net'); ?>: 0.00 - - getText('Tax'); ?>: 0.00 - - getText('Total'); ?>: 0.00 + getHtml('Freightage') ?>: 0.00 - + getHtml('Net') ?>: 0.00 - + getHtml('Tax') ?>: 0.00 - + getHtml('Total') ?>: 0.00
@@ -176,33 +176,33 @@ echo $this->getData('nav')->render(); ?>
-

getText('Payment') ?>

+

getHtml('Payment'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -215,15 +215,15 @@ echo $this->getData('nav')->render(); ?>
-

getText('Media'); ?>

+

getHtml('Media') ?>

-
-
-
+
+
+
@@ -244,24 +244,24 @@ echo $this->getData('nav')->render(); ?>
- + - -
getText('Logs') ?>getHtml('Logs'); ?>
IP - getText('ID', 0, 0); ?> - getText('Name'); ?> - getText('Log'); ?> - getText('Date'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Name') ?> + getHtml('Log') ?> + getHtml('Date') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
request->getOrigin(); ?> - request->getAccount(); ?> - request->getAccount(); ?> + request->getOrigin(), ENT_COMPAT, 'utf-8'); ?> + request->getAccount(), ENT_COMPAT, 'utf-8'); ?> + request->getAccount(), ENT_COMPAT, 'utf-8'); ?> Create Invoice - format('Y-m-d H:i:s') ?> + format('Y-m-d H:i:s') , ENT_COMPAT, 'utf-8'); ?>
diff --git a/Theme/Backend/invoice-list.tpl.php b/Theme/Backend/invoice-list.tpl.php index 0b40485..056e3b1 100644 --- a/Theme/Backend/invoice-list.tpl.php +++ b/Theme/Backend/invoice-list.tpl.php @@ -24,25 +24,25 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; ?> -
getText('Invoices') ?>getHtml('Invoices'); ?>
getText('ID', 0, 0); ?> - getText('Type'); ?> - getText('ClientID'); ?> - getText('Client'); ?> - getText('Net'); ?> - getText('Gross'); ?> - getText('Created'); ?> - getText('Due'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Type') ?> + getHtml('ClientID') ?> + getHtml('Client') ?> + getHtml('Net') ?> + getHtml('Gross') ?> + getHtml('Created') ?> + getHtml('Due') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/purchase-invoice-list.tpl.php b/Theme/Backend/purchase-invoice-list.tpl.php index 3b65458..9140b75 100644 --- a/Theme/Backend/purchase-invoice-list.tpl.php +++ b/Theme/Backend/purchase-invoice-list.tpl.php @@ -24,25 +24,25 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; ?> -
getText('Invoices') ?>getHtml('Invoices'); ?>
getText('ID', 0, 0); ?> - getText('Type'); ?> - getText('SupplierID'); ?> - getText('Supplier'); ?> - getText('Net'); ?> - getText('Gross'); ?> - getText('Created'); ?> - getText('Due'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Type') ?> + getHtml('SupplierID') ?> + getHtml('Supplier') ?> + getHtml('Net') ?> + getHtml('Gross') ?> + getHtml('Created') ?> + getHtml('Due') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>