r60084 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r60083‎ | r60084 | r60085 >
Date:18:48, 15 December 2009
Author:yaron
Status:deferred
Tags:
Comment:
Added HTML-escaping of values
Modified paths:
  • /trunk/extensions/SemanticDrilldown/includes/SD_AppliedFilter.php (modified) (history)
  • /trunk/extensions/SemanticDrilldown/includes/SD_FilterValue.php (modified) (history)

Diff [purge]

Index: trunk/extensions/SemanticDrilldown/includes/SD_AppliedFilter.php
@@ -18,7 +18,7 @@
1919 function create($filter, $values, $search_term = null, $lower_date = null, $upper_date = null) {
2020 $af = new SDAppliedFilter();
2121 $af->filter = $filter;
22 - $af->search_term = str_replace('_', ' ', $search_term);
 22+ $af->search_term = htmlspecialchars(str_replace('_', ' ', $search_term));
2323 if ($lower_date != null) {
2424 $af->lower_date = $lower_date;
2525 $af->lower_date_string = SDUtils::monthToString($lower_date['month']) . " " . $lower_date['day'] . ", " . $lower_date['year'];
Index: trunk/extensions/SemanticDrilldown/includes/SD_FilterValue.php
@@ -18,7 +18,7 @@
1919
2020 function create($actual_val, $filter_time_period = null) {
2121 $fv = new SDFilterValue();
22 - $fv->text = $actual_val;
 22+ $fv->text = htmlspecialchars($actual_val);
2323
2424 if ($fv->text == ' none')
2525 $fv->is_none = true;

Status & tagging log