From 6da40780e66b7f5be3e560064ee6e2cc2b002460 Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/rnd-create.tpl.php | 34 ++++++++++++++++---------------- Theme/Backend/rnd-list.tpl.php | 24 +++++++++++----------- 2 files changed, 29 insertions(+), 29 deletions(-) diff --git a/Theme/Backend/rnd-create.tpl.php b/Theme/Backend/rnd-create.tpl.php index de401e1..d17cc00 100644 --- a/Theme/Backend/rnd-create.tpl.php +++ b/Theme/Backend/rnd-create.tpl.php @@ -15,35 +15,35 @@ echo $this->getData('nav')->render(); ?>
-

getText('Project'); ?>

+

getHtml('Project') ?>

-
+
-
+
-
+
-
+
-
+
-
+
-
+
- -
+ +
diff --git a/Theme/Backend/rnd-list.tpl.php b/Theme/Backend/rnd-list.tpl.php index 8a52fbf..116f5b5 100644 --- a/Theme/Backend/rnd-list.tpl.php +++ b/Theme/Backend/rnd-list.tpl.php @@ -29,28 +29,28 @@ echo $this->getData('nav')->render(); ?>
- + - - $value) : $c++; $url = \phpOMS\Uri\UriFactory::build('{/base}/{/lang}/backend/checklist/single?{?}&id=' . $value->getId()); ?> - -
getText('Projects'); ?>getHtml('Projects') ?>
getText('ID', 0, 0); ?> - getText('Status'); ?> - getText('Name'); ?> - getText('Creator'); ?> - getText('Created'); ?> + getHtml('ID', 0, 0); ?> + getHtml('Status') ?> + getHtml('Name') ?> + getHtml('Creator') ?> + getHtml('Created') ?>
render(); ?> +
render(), ENT_COMPAT, 'utf-8'); ?>
getId(); ?> - getName(); ?> - getParent(); ?> - getUnit(); ?> + getId(), ENT_COMPAT, 'utf-8'); ?> + getName(), ENT_COMPAT, 'utf-8'); ?> + getParent(), ENT_COMPAT, 'utf-8'); ?> + getUnit(), ENT_COMPAT, 'utf-8'); ?>
getText('Empty', 0, 0); ?> + getHtml('Empty', 0, 0); ?>