From e80d7230fb65f693b2a6c43076a34d1a4a51cb8a Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- .../Backend/projectmanagement-create.tpl.php | 34 +++++++++--------- Theme/Backend/projectmanagement-list.tpl.php | 18 +++++----- .../Backend/projectmanagement-profile.tpl.php | 36 +++++++++---------- 3 files changed, 44 insertions(+), 44 deletions(-) diff --git a/Theme/Backend/projectmanagement-create.tpl.php b/Theme/Backend/projectmanagement-create.tpl.php index 4d08893..57b95cc 100644 --- a/Theme/Backend/projectmanagement-create.tpl.php +++ b/Theme/Backend/projectmanagement-create.tpl.php @@ -18,35 +18,35 @@ echo $this->getData('nav')->render(); ?>
-

getText('Project'); ?>

+

getHtml('Project') ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
- -
+ +
diff --git a/Theme/Backend/projectmanagement-list.tpl.php b/Theme/Backend/projectmanagement-list.tpl.php index 5e3052b..0d2571b 100644 --- a/Theme/Backend/projectmanagement-list.tpl.php +++ b/Theme/Backend/projectmanagement-list.tpl.php @@ -26,25 +26,25 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $count++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/projectmanagement/profile?{?}&id=' . $value->getId());?> -
getText('Projects') ?>getHtml('Projects'); ?>
getText('Title'); ?> - getText('Start'); ?> - getText('Due'); ?> + getHtml('Title') ?> + getHtml('Start') ?> + getHtml('Due') ?>
render(); ?> + render(), ENT_COMPAT, 'utf-8'); ?>
getName(); ?> - getStart()->format('Y-m-d'); ?> - getEnd()->format('Y-m-d'); ?> + getName(), ENT_COMPAT, 'utf-8'); ?> + getStart()->format('Y-m-d'), ENT_COMPAT, 'utf-8'); ?> + getEnd()->format('Y-m-d'), ENT_COMPAT, 'utf-8'); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/projectmanagement-profile.tpl.php b/Theme/Backend/projectmanagement-profile.tpl.php index e00f1bd..70f78ae 100644 --- a/Theme/Backend/projectmanagement-profile.tpl.php +++ b/Theme/Backend/projectmanagement-profile.tpl.php @@ -20,20 +20,20 @@ echo $this->getData('nav')->render(); ?>
-

getName(); ?>

+

getName(), ENT_COMPAT, 'utf-8'); ?>

-
-
-
- -
- -
-
-
+
+
+
+ +
+ +
+
+
@@ -43,11 +43,11 @@ echo $this->getData('nav')->render(); ?>
- + - $task) : $c++; @@ -59,11 +59,11 @@ echo $this->getData('nav')->render(); ?> elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::CANCELED) { $color = 'red'; } elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::SUSPENDED) { $color = 'yellow'; } ;?> -
getText('Tasks', 'Tasks'); ?>getHtml('Tasks', 'Tasks') ?>
getText('Status'); ?> - getText('Due', 'Tasks'); ?> - getText('Title'); ?> + getHtml('Status') ?> + getHtml('Due', 'Tasks') ?> + getHtml('Title') ?>
getText('S' . $task->getStatus(), 'Tasks'); ?> - getDue()->format('Y-m-d H:i'); ?> - getTitle(); ?> + getHtml('S' . $task->getStatus(), 'Tasks') ?> + getDue()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?> + getTitle(), ENT_COMPAT, 'utf-8'); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>