From 9e1194082d6461bda0003fafba2abd90fd4d07af Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/dashboard.tpl.php | 34 +++++++++++++------------- Theme/Backend/mail-create.tpl.php | 10 ++++---- Theme/Backend/mail-out-view.tpl.php | 26 ++++++++++---------- Theme/Backend/mail-spam-view.tpl.php | 26 ++++++++++---------- Theme/Backend/mail-trash-view.tpl.php | 26 ++++++++++---------- Theme/Backend/mail-view.tpl.php | 4 +-- Theme/Backend/message-settings.tpl.php | 34 +++++++++++++------------- 7 files changed, 80 insertions(+), 80 deletions(-) diff --git a/Theme/Backend/dashboard.tpl.php b/Theme/Backend/dashboard.tpl.php index b11c2aa..3f27e38 100644 --- a/Theme/Backend/dashboard.tpl.php +++ b/Theme/Backend/dashboard.tpl.php @@ -22,46 +22,46 @@ echo $this->getData('nav')->render(); ?>
- + - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/messages/mail/single?{?}&id=' . $value->uid); ?> -
getText('Messages'); ?>getHtml('Messages') ?>
- getText('Tag'); ?> - getText('Subject'); ?> - getText('From'); ?> - getText('Date'); ?> + getHtml('Tag') ?> + getHtml('Subject') ?> + getHtml('From') ?> + getHtml('Date') ?>
/ +
/
- seen == 0 ? ' class="unseen"' : ''; ?>> - seen == 0 ? ' class="unseen"' : ''; ?>>subject)); ?> - seen == 0 ? ' class="unseen"' : ''; ?>>from; ?> - seen == 0 ? ' class="unseen"' : ''; ?>>date))->format('Y-m-d H:i:s'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>subject)), ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>from, ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>date))->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?> $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/messages/mail/single?{?}&id=' . $value->uid); ?>
- seen == 0 ? ' class="unseen"' : ''; ?>> - seen == 0 ? ' class="unseen"' : ''; ?>>subject)); ?> - seen == 0 ? ' class="unseen"' : ''; ?>>from; ?> - seen == 0 ? ' class="unseen"' : ''; ?>>date))->format('Y-m-d H:i:s'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>subject)), ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>from, ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>date))->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/mail-create.tpl.php b/Theme/Backend/mail-create.tpl.php index e9d417c..629d2da 100644 --- a/Theme/Backend/mail-create.tpl.php +++ b/Theme/Backend/mail-create.tpl.php @@ -18,13 +18,13 @@ echo $this->getData('nav')->render(); ?>
-
-
-
-
+
+
+
+
-
+
diff --git a/Theme/Backend/mail-out-view.tpl.php b/Theme/Backend/mail-out-view.tpl.php index 4e5664a..c6f8b3d 100644 --- a/Theme/Backend/mail-out-view.tpl.php +++ b/Theme/Backend/mail-out-view.tpl.php @@ -21,36 +21,36 @@ echo $this->getData('nav')->render(); ?>
- + - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/messages/mail/single?{?}&id=' . $value->uid); ?> -
getText('Messages'); ?>getHtml('Messages') ?>
- getText('Tag'); ?> - getText('Subject'); ?> - getText('From'); ?> - getText('Date'); ?> + getHtml('Tag') ?> + getHtml('Subject') ?> + getHtml('From') ?> + getHtml('Date') ?>
/ +
/
- seen == 0 ? ' class="unseen"' : ''; ?>> - seen == 0 ? ' class="unseen"' : ''; ?>>subject)); ?> - seen == 0 ? ' class="unseen"' : ''; ?>>from; ?> - seen == 0 ? ' class="unseen"' : ''; ?>>date))->format('Y-m-d H:i:s'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>subject)), ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>from, ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>date))->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/mail-spam-view.tpl.php b/Theme/Backend/mail-spam-view.tpl.php index 4e5664a..c6f8b3d 100644 --- a/Theme/Backend/mail-spam-view.tpl.php +++ b/Theme/Backend/mail-spam-view.tpl.php @@ -21,36 +21,36 @@ echo $this->getData('nav')->render(); ?>
- + - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/messages/mail/single?{?}&id=' . $value->uid); ?> -
getText('Messages'); ?>getHtml('Messages') ?>
- getText('Tag'); ?> - getText('Subject'); ?> - getText('From'); ?> - getText('Date'); ?> + getHtml('Tag') ?> + getHtml('Subject') ?> + getHtml('From') ?> + getHtml('Date') ?>
/ +
/
- seen == 0 ? ' class="unseen"' : ''; ?>> - seen == 0 ? ' class="unseen"' : ''; ?>>subject)); ?> - seen == 0 ? ' class="unseen"' : ''; ?>>from; ?> - seen == 0 ? ' class="unseen"' : ''; ?>>date))->format('Y-m-d H:i:s'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>subject)), ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>from, ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>date))->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/mail-trash-view.tpl.php b/Theme/Backend/mail-trash-view.tpl.php index 4e5664a..c6f8b3d 100644 --- a/Theme/Backend/mail-trash-view.tpl.php +++ b/Theme/Backend/mail-trash-view.tpl.php @@ -21,36 +21,36 @@ echo $this->getData('nav')->render(); ?>
- + - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/messages/mail/single?{?}&id=' . $value->uid); ?> -
getText('Messages'); ?>getHtml('Messages') ?>
- getText('Tag'); ?> - getText('Subject'); ?> - getText('From'); ?> - getText('Date'); ?> + getHtml('Tag') ?> + getHtml('Subject') ?> + getHtml('From') ?> + getHtml('Date') ?>
/ +
/
- seen == 0 ? ' class="unseen"' : ''; ?>> - seen == 0 ? ' class="unseen"' : ''; ?>>subject)); ?> - seen == 0 ? ' class="unseen"' : ''; ?>>from; ?> - seen == 0 ? ' class="unseen"' : ''; ?>>date))->format('Y-m-d H:i:s'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>subject)), ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>from, ENT_COMPAT, 'utf-8'); ?> + seen == 0 ? ' class="unseen"' : '', ENT_COMPAT, 'utf-8'); ?>>date))->format('Y-m-d H:i:s'), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/mail-view.tpl.php b/Theme/Backend/mail-view.tpl.php index 0626908..c1c5334 100644 --- a/Theme/Backend/mail-view.tpl.php +++ b/Theme/Backend/mail-view.tpl.php @@ -19,8 +19,8 @@ $mails = $mail->getEmail($this->getData('id')); echo $this->getData('nav')->render(); ?>
-

subject)); ?>

+

subject)), ENT_COMPAT, 'utf-8'); ?>

- encoding); ?> + encoding), ENT_COMPAT, 'utf-8'); ?>
diff --git a/Theme/Backend/message-settings.tpl.php b/Theme/Backend/message-settings.tpl.php index e011147..aa5b69e 100644 --- a/Theme/Backend/message-settings.tpl.php +++ b/Theme/Backend/message-settings.tpl.php @@ -19,46 +19,46 @@ $boxes = $mail->getBoxes(); echo $this->getData('nav')->render(); ?>
-

getText('Mailboxes'); ?>

+

getHtml('Mailboxes') ?>

-
+
-
+
-
+
-
+
-
+
-
+