From b244522e22c3a9d5ec40bde0c320ad73b67db498 Mon Sep 17 00:00:00 2001 From: Dennis Eichhorn Date: Mon, 24 Jul 2017 20:48:22 +0200 Subject: [PATCH] Add html escaping --- Theme/Backend/dashboard-task.tpl.php | 16 ++++----- Theme/Backend/task-analysis.tpl.php | 30 ++++++++-------- Theme/Backend/task-create.tpl.php | 42 +++++++++++----------- Theme/Backend/task-dashboard.tpl.php | 52 ++++++++++++++-------------- Theme/Backend/task-single.tpl.php | 52 ++++++++++++++-------------- 5 files changed, 96 insertions(+), 96 deletions(-) diff --git a/Theme/Backend/dashboard-task.tpl.php b/Theme/Backend/dashboard-task.tpl.php index 70699a3..9d39779 100644 --- a/Theme/Backend/dashboard-task.tpl.php +++ b/Theme/Backend/dashboard-task.tpl.php @@ -21,11 +21,11 @@ $tasks = $this->getData('tasks');
- + - $task) : $c++; @@ -37,11 +37,11 @@ $tasks = $this->getData('tasks'); elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::CANCELED) { $color = 'red'; } elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::SUSPENDED) { $color = 'yellow'; } ;?> -
getText('Tasks'); ?>getHtml('Tasks') ?>
getText('Status'); ?> - getText('Due'); ?> - getText('Title'); ?> + getHtml('Status') ?> + getHtml('Due') ?> + getHtml('Title') ?>
getText('S' . $task->getStatus()); ?> - getDue()->format('Y-m-d H:i'); ?> - getTitle(); ?> + getHtml('S' . $task->getStatus()) ?> + getDue()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?> + getTitle(), ENT_COMPAT, 'utf-8'); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
diff --git a/Theme/Backend/task-analysis.tpl.php b/Theme/Backend/task-analysis.tpl.php index 58daeca..df0002a 100644 --- a/Theme/Backend/task-analysis.tpl.php +++ b/Theme/Backend/task-analysis.tpl.php @@ -20,17 +20,17 @@ echo $this->getData('nav')->render(); ?>
-

getText('Account'); ?>

+

getHtml('Account') ?>

-
+
-
-
-
-
-
+
+
+
+
+
@@ -39,15 +39,15 @@ echo $this->getData('nav')->render(); ?>
-

getText('Statistics'); ?>

+

getHtml('Statistics') ?>

-
getText('Received'); ?>0 -
getText('Created'); ?>0 -
getText('Forwarded'); ?>0 -
getText('AverageAmount'); ?>0 -
getText('AverageProcessTime'); ?>0 -
getText('InTime'); ?>0 +
getHtml('Received') ?>0 +
getHtml('Created') ?>0 +
getHtml('Forwarded') ?>0 +
getHtml('AverageAmount') ?>0 +
getHtml('AverageProcessTime') ?>0 +
getHtml('InTime') ?>0
@@ -57,7 +57,7 @@ echo $this->getData('nav')->render(); ?>
-

getText('History'); ?>

+

getHtml('History') ?>

diff --git a/Theme/Backend/task-create.tpl.php b/Theme/Backend/task-create.tpl.php index fc39f3c..c22b773 100644 --- a/Theme/Backend/task-create.tpl.php +++ b/Theme/Backend/task-create.tpl.php @@ -20,32 +20,32 @@ echo $this->getData('nav')->render(); ?>
-

getText('Task'); ?>

+

getHtml('Task') ?>

-
-
getData('accGrpSelector')->render('iReceiver'); ?> -
-
getData('accGrpSelector')->render('iCC'); ?> -
+
+
getData('accGrpSelector')->render('iReceiver'); ?> +
+
getData('accGrpSelector')->render('iCC'); ?> +
-
-
-
-
-
+
+
+
+
+
-
+
@@ -54,15 +54,15 @@ echo $this->getData('nav')->render(); ?>
-

getText('Media'); ?>

+

getHtml('Media') ?>

-
-
-
+
+
+
diff --git a/Theme/Backend/task-dashboard.tpl.php b/Theme/Backend/task-dashboard.tpl.php index 7ffb574..4f5de3a 100644 --- a/Theme/Backend/task-dashboard.tpl.php +++ b/Theme/Backend/task-dashboard.tpl.php @@ -23,13 +23,13 @@ echo $this->getData('nav')->render(); ?>
- + - $task) : $c++; @@ -41,13 +41,13 @@ echo $this->getData('nav')->render(); ?> elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::CANCELED) { $color = 'red'; } elseif($task->getStatus() === \Modules\Tasks\Models\TaskStatus::SUSPENDED) { $color = 'yellow'; } ;?> -
getText('Tasks'); ?>getHtml('Tasks') ?>
getText('Status'); ?> - getText('Due'); ?> - getText('Title'); ?> - getText('Creator'); ?> - getText('Created'); ?> + getHtml('Status') ?> + getHtml('Due') ?> + getHtml('Title') ?> + getHtml('Creator') ?> + getHtml('Created') ?>
getText('S' . $task->getStatus()); ?> - getDue()->format('Y-m-d H:i'); ?> - getTitle(); ?> - getCreatedBy()->getName1(); ?> - getCreatedAt()->format('Y-m-d H:i'); ?> + getHtml('S' . $task->getStatus()) ?> + getDue()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?> + getTitle(), ENT_COMPAT, 'utf-8'); ?> + getCreatedBy()->getName1(), ENT_COMPAT, 'utf-8'); ?> + getCreatedAt()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?> -
getText('Empty', 0, 0); ?> +
getHtml('Empty', 0, 0); ?>
@@ -55,17 +55,17 @@ echo $this->getData('nav')->render(); ?>
-

getText('Settings'); ?>

+

getHtml('Settings') ?>

-
+
@@ -73,15 +73,15 @@ echo $this->getData('nav')->render(); ?>
-

getText('Settings'); ?>

+

getHtml('Settings') ?>

-
getText('Received'); ?>0 -
getText('Created'); ?>0 -
getText('Forwarded'); ?>0 -
getText('AverageAmount'); ?>0 -
getText('AverageProcessTime'); ?>0 -
getText('InTime'); ?>0 +
getHtml('Received') ?>0 +
getHtml('Created') ?>0 +
getHtml('Forwarded') ?>0 +
getHtml('AverageAmount') ?>0 +
getHtml('AverageProcessTime') ?>0 +
getHtml('InTime') ?>0
diff --git a/Theme/Backend/task-single.tpl.php b/Theme/Backend/task-single.tpl.php index 735d634..9cbe343 100644 --- a/Theme/Backend/task-single.tpl.php +++ b/Theme/Backend/task-single.tpl.php @@ -30,20 +30,20 @@ echo $this->getData('nav')->render(); ?>
-

getTitle(); ?>

+

getTitle(), ENT_COMPAT, 'utf-8'); ?>

-
Due getDue()->format('Y-m-d H:i'); ?>
-
Created getCreatedAt()->format('Y-m-d H:i'); ?>
+
Due getDue()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?>
+
Created getCreatedAt()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?>
- getDescription(); ?> + getDescription(), ENT_COMPAT, 'utf-8'); ?>
-
Created getCreatedBy()->getName1(); ?>
- getText('S' . $task->getStatus()); ?> +
Created getCreatedBy()->getName1(), ENT_COMPAT, 'utf-8'); ?>
+ getHtml('S' . $task->getStatus()) ?>
@@ -57,27 +57,27 @@ echo $this->getData('nav')->render(); ?> elseif($element->getStatus() === \Modules\Tasks\Models\TaskStatus::SUSPENDED) { $color = 'yellow'; } ?>
-
getCreatedBy()->getName1(); ?> - getCreatedAt()->format('Y-m-d H:i'); ?>
- getText('S' . $element->getStatus()); ?> +
getCreatedBy()->getName1(), ENT_COMPAT, 'utf-8'); ?> - getCreatedAt()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?>
+ getHtml('S' . $element->getStatus()) ?>
getDescription() !== '') : ?>
- getDescription(); ?> + getDescription(), ENT_COMPAT, 'utf-8'); ?>
getForwarded() !== 0) : ?> -
Forwarded getForwarded()->getName1(); ?>
+
Forwarded getForwarded()->getName1(), ENT_COMPAT, 'utf-8'); ?>
getStatus() !== \Modules\Tasks\Models\TaskStatus::CANCELED || $element->getStatus() !== \Modules\Tasks\Models\TaskStatus::DONE || $element->getStatus() !== \Modules\Tasks\Models\TaskStatus::SUSPENDED || $c != $cElements ) : ?> -
Due getDue()->format('Y-m-d H:i'); ?>
+
Due getDue()->format('Y-m-d H:i'), ENT_COMPAT, 'utf-8'); ?>
@@ -86,25 +86,25 @@ echo $this->getData('nav')->render(); ?>
-
+
-
-
-
+
+
+
-
-
-
-
-
+
+
+
+
+
-
+