From 39a0f9464d3c4e9a107fd3db49e5ec40d0f3201d Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/editor-create.tpl.php | 18 +++++++++--------- Theme/Backend/editor-list.tpl.php | 18 +++++++++--------- Theme/Backend/editor-single.tpl.php | 2 +- Theme/Backend/editor.tpl.php | 8 ++++---- 4 files changed, 23 insertions(+), 23 deletions(-) diff --git a/Theme/Backend/editor-create.tpl.php b/Theme/Backend/editor-create.tpl.php index bf3dc27..a13e277 100644 --- a/Theme/Backend/editor-create.tpl.php +++ b/Theme/Backend/editor-create.tpl.php @@ -24,7 +24,7 @@ echo $this->getData('nav')->render(); ?>
- +
@@ -36,9 +36,9 @@ echo $this->getData('nav')->render(); ?>
@@ -99,8 +99,8 @@ echo $this->getData('nav')->render(); ?>
@@ -122,12 +122,12 @@ echo $this->getData('nav')->render(); ?>
-
+
-
-
+
+
diff --git a/Theme/Backend/editor-list.tpl.php b/Theme/Backend/editor-list.tpl.php index d993e6e..a11ce70 100644 --- a/Theme/Backend/editor-list.tpl.php +++ b/Theme/Backend/editor-list.tpl.php @@ -28,25 +28,25 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/editor/single?{?}&id=' . $value->getId()); ?> -
getText('Documents'); ?>getHtml('Documents') ?>
getText('Title'); ?> - getText('Creator'); ?> - getText('Created'); ?> + getHtml('Title') ?> + getHtml('Creator') ?> + getHtml('Created') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getTitle(); ?> - getCreatedBy()->getName1(); ?> - getCreatedAt()->format('Y-m-d H:i:s'); ?> + getTitle(), ENT_COMPAT, 'utf-8'); ?> + getCreatedBy()->getName1(), ENT_COMPAT, 'utf-8'); ?> + getCreatedAt()->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/editor-single.tpl.php b/Theme/Backend/editor-single.tpl.php index 7737b33..cec0e46 100644 --- a/Theme/Backend/editor-single.tpl.php +++ b/Theme/Backend/editor-single.tpl.php @@ -1,4 +1,4 @@ -getData('nav')->render(); ?> +getData('nav')->render(), ENT_COMPAT, 'utf-8'); ?>
diff --git a/Theme/Backend/editor.tpl.php b/Theme/Backend/editor.tpl.php index 3afe7c1..24ddf0a 100644 --- a/Theme/Backend/editor.tpl.php +++ b/Theme/Backend/editor.tpl.php @@ -45,19 +45,19 @@ $doc = $this->getData('doc') ?? null;
- +
- getContent() : ''; ?> + getContent() : '', ENT_COMPAT, 'utf-8'); ?>