r96282 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r96281‎ | r96282 | r96283 >
Date:15:40, 5 September 2011
Author:platonides
Status:deferred
Tags:
Comment:
wfMsgHtml doesn't escape parameters
Follow-up to r96241
Modified paths:
  • /trunk/extensions/OpenID/OpenID.hooks.php (modified) (history)

Diff [purge]

Index: trunk/extensions/OpenID/OpenID.hooks.php
@@ -244,7 +244,7 @@
245245 $dbw = wfGetDB( DB_MASTER );
246246
247247 $dbw->delete( 'user_openid', array( 'uoi_user' => $userID ) );
248 - $wgOut->addHTML( "OpenID " . wfMsgHtml( 'usermerge-userdeleted', $username, $userID ) );
 248+ $wgOut->addHTML( "OpenID " . wfMsgExt( 'usermerge-userdeleted', array( 'escape' ), $username, $userID ) );
249249
250250 wfDebug( "OpenID: deleted OpenID user $username ($userID)\n" );
251251
@@ -269,7 +269,7 @@
270270 $dbw = wfGetDB( DB_MASTER );
271271
272272 $dbw->update( 'user_openid', array( 'uoi_user' => $toUserID ), array( 'uoi_user' => $fromUserID ) );
273 - $wgOut->addHTML( "OpenID " . wfMsgHtml( 'usermerge-updating', 'user_openid', $fromUsername, $toUsername ) . "<br />\n" );
 273+ $wgOut->addHTML( "OpenID " . wfMsgExt( 'usermerge-updating', array( 'escape' ), 'user_openid', $fromUsername, $toUsername ) . "<br />\n" );
274274
275275 wfDebug( "OpenID: transferred OpenID(s) of $fromUsername ($fromUserID) => $toUsername ($toUserID)\n" );
276276

Past revisions this follows-up on

RevisionCommit summaryAuthorDate
r96241Change some raw messages to escape htmlplatonides17:59, 4 September 2011

Status & tagging log