From e6dedfbf9445eb1009fd246b26d870308b5877aa Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/item-create.tpl.php | 328 +++++++++++------------ Theme/Backend/purchase-item-list.tpl.php | 18 +- Theme/Backend/sales-item-list.tpl.php | 20 +- Theme/Backend/stock-list.tpl.php | 20 +- 4 files changed, 193 insertions(+), 193 deletions(-) diff --git a/Theme/Backend/item-create.tpl.php b/Theme/Backend/item-create.tpl.php index a4e16fe..ac29716 100644 --- a/Theme/Backend/item-create.tpl.php +++ b/Theme/Backend/item-create.tpl.php @@ -20,20 +20,20 @@ echo $this->getData('nav')->render(); ?>
@@ -42,24 +42,24 @@ echo $this->getData('nav')->render(); ?>
-

getText('Item') ?>

+

getHtml('Item'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -68,24 +68,24 @@ echo $this->getData('nav')->render(); ?>
-

getText('Language') ?>

+

getHtml('Language'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
@@ -96,116 +96,116 @@ echo $this->getData('nav')->render(); ?>
-

getText('Property') ?>

+

getHtml('Property'); ?>

-
+
-
+
-
+
-
+
-

getText('Language') ?>

+

getHtml('Language'); ?>

-
+
-
+
-
+
-
+
-

getText('Language') ?>

+

getHtml('Language'); ?>

-
+
-
+
-
+
-
+
-

getText('Attribute') ?>

+

getHtml('Attribute'); ?>

-
+
-
+
-
+
-
+
-

getText('Language') ?>

+

getHtml('Language'); ?>

-
+
-
+
-
+
-
+
-

getText('Language') ?>

+

getHtml('Language'); ?>

-
+
-
+
-
+
-
+
@@ -214,41 +214,41 @@ echo $this->getData('nav')->render(); ?>
-

getText('Sales') ?>

+

getHtml('Sales'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -256,34 +256,34 @@ echo $this->getData('nav')->render(); ?>
-

getText('Price') ?>

+

getHtml('Price'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
@@ -292,32 +292,32 @@ echo $this->getData('nav')->render(); ?>
-

getText('Purchase') ?>

+

getHtml('Purchase'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
@@ -325,64 +325,64 @@ echo $this->getData('nav')->render(); ?>
-

getText('Price') ?>

+

getHtml('Price'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-

getText('Stock') ?>

+

getHtml('Stock'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-

getText('Supplier') ?>

+

getHtml('Supplier'); ?>

-
+
-
+
-
+
@@ -391,18 +391,18 @@ echo $this->getData('nav')->render(); ?>
-

getText('Accounting') ?>

+

getHtml('Accounting'); ?>

-
+
-
+
-
+
-
+
@@ -412,18 +412,18 @@ echo $this->getData('nav')->render(); ?>
-

getText('Production') ?>

+

getHtml('Production'); ?>

-
+
-
+
-
+
-
+
-
+
@@ -442,16 +442,16 @@ echo $this->getData('nav')->render(); ?>
-

getText('StockList') ?>

+

getHtml('StockList'); ?>

-
+
-
+
-
+
@@ -460,7 +460,7 @@ echo $this->getData('nav')->render(); ?>
-

getText('QM') ?>

+

getHtml('QM'); ?>

@@ -473,30 +473,30 @@ echo $this->getData('nav')->render(); ?>
-

getText('Packaging') ?>

+

getHtml('Packaging'); ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -505,14 +505,14 @@ echo $this->getData('nav')->render(); ?>
-

getText('Media') ?>

+

getHtml('Media'); ?>

-
+
-
+
@@ -521,12 +521,12 @@ echo $this->getData('nav')->render(); ?>
-

getText('Stock') ?>

+

getHtml('Stock'); ?>

-
+
@@ -534,22 +534,22 @@ echo $this->getData('nav')->render(); ?>
-

getText('Stock') ?>

+

getHtml('Stock'); ?>

-
+
-
+
-
+
-
+
@@ -558,7 +558,7 @@ echo $this->getData('nav')->render(); ?>
-

getText('Disposal') ?>

+

getHtml('Disposal'); ?>

@@ -571,14 +571,14 @@ echo $this->getData('nav')->render(); ?>
-

getText('Files') ?>

+

getHtml('Files'); ?>

-
+
-
+
@@ -594,24 +594,24 @@ echo $this->getData('nav')->render(); ?> ?>
- + - -
getText('Logs') ?>getHtml('Logs'); ?>
IP - getText('ID', 0, 0); ?> - getText('Name'); ?> - getText('Log'); ?> - getText('Date'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Name') ?> + getHtml('Log') ?> + getHtml('Date') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
request->getOrigin(); ?> - request->getAccount(); ?> - request->getAccount(); ?> + request->getOrigin(), ENT_COMPAT, 'utf-8'); ?> + request->getAccount(), ENT_COMPAT, 'utf-8'); ?> + request->getAccount(), ENT_COMPAT, 'utf-8'); ?> Creating item - format('Y-m-d H:i:s') ?> + format('Y-m-d H:i:s') , ENT_COMPAT, 'utf-8'); ?>
diff --git a/Theme/Backend/purchase-item-list.tpl.php b/Theme/Backend/purchase-item-list.tpl.php index 46b99aa..188290a 100644 --- a/Theme/Backend/purchase-item-list.tpl.php +++ b/Theme/Backend/purchase-item-list.tpl.php @@ -24,23 +24,23 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; ?> -
getText('Items') ?>getHtml('Items'); ?>
getText('ID', 0, 0); ?> - getText('Name'); ?> - getText('Price'); ?> - getText('Available'); ?> - getText('Reserved'); ?> - getText('Ordered'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Name') ?> + getHtml('Price') ?> + getHtml('Available') ?> + getHtml('Reserved') ?> + getHtml('Ordered') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/sales-item-list.tpl.php b/Theme/Backend/sales-item-list.tpl.php index 5a56a5b..8ab8acd 100644 --- a/Theme/Backend/sales-item-list.tpl.php +++ b/Theme/Backend/sales-item-list.tpl.php @@ -26,23 +26,23 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/sales/item/single?{?}&id=' . $value->getId()); ?> -
getText('Items') ?>getHtml('Items'); ?>
getText('ID', 0, 0); ?> - getText('Name'); ?> - getText('Price'); ?> - getText('Available'); ?> - getText('Reserved'); ?> - getText('Ordered'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Name') ?> + getHtml('Price') ?> + getHtml('Available') ?> + getHtml('Reserved') ?> + getHtml('Ordered') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getNumber(); ?> + getNumber(), ENT_COMPAT, 'utf-8'); ?> @@ -50,7 +50,7 @@ echo $this->getData('nav')->render(); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/stock-list.tpl.php b/Theme/Backend/stock-list.tpl.php index af5f950..87e573f 100644 --- a/Theme/Backend/stock-list.tpl.php +++ b/Theme/Backend/stock-list.tpl.php @@ -29,26 +29,26 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $c++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/business/department/profile?{?}&id=' . $value->getId()); ?> - -
getText('Stock'); ?>getHtml('Stock') ?>
getText('ID', 0, 0); ?> - getText('Article'); ?> - getText('Quantity'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Article') ?> + getHtml('Quantity') ?>
render(); ?> +
render(), ENT_COMPAT, 'utf-8'); ?>
getId(); ?> - getName(); ?> - getParent(); ?> - getUnit(); ?> + getId(), ENT_COMPAT, 'utf-8'); ?> + getName(), ENT_COMPAT, 'utf-8'); ?> + getParent(), ENT_COMPAT, 'utf-8'); ?> + getUnit(), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>