<?xml version="1.0" encoding="UTF-8"?>
<commit>
  <added type="array"/>
  <modified type="array">
    <modified>
      <diff>@@ -297,11 +297,16 @@ class BasketsController &lt; ApplicationController
   def update_appearance
     @basket = Basket.find(params[:id])
     do_not_sanitize = (params[:settings][:do_not_sanitize_footer_content] == 'true')
+    original_html = params[:settings][:additional_footer_content]
+    sanitized_html = original_html
     unless do_not_sanitize &amp;&amp; @site_admin
-      params[:settings][:additional_footer_content] = sanitize(params[:settings][:additional_footer_content])
+      sanitized_html = sanitize(original_html)
+      params[:settings][:additional_footer_content] = sanitized_html
     end
     set_settings
     flash[:notice] = 'Basket appearance was updated.'
+    logger.debug(&quot;sanitized yes&quot;) if original_html != sanitized_html
+    flash[:notice] += ' Your submitted footer content was changed for security reasons.' if original_html != sanitized_html
     redirect_to :action =&gt; :appearance
   end
 
@@ -378,7 +383,7 @@ class BasketsController &lt; ApplicationController
   end
 
   def current_basket_is_selected?
-    params[:id].blank? or @current_basket.id == params[:id]
+    params[:id].blank? || @current_basket.id == params[:id]
   end
 
   private</diff>
      <filename>app/controllers/baskets_controller.rb</filename>
    </modified>
  </modified>
  <removed type="array"/>
  <parents type="array">
    <parent>
      <id>74f5860aa9e549b9c585ef32bb5709538b1e6c75</id>
    </parent>
  </parents>
  <author>
    <name>Walter McGinnis</name>
    <email>walter@katipo.co.nz</email>
  </author>
  <url>http://github.com/kete/kete/commit/6eff4ae9f97657f174e1222f443079613a9e52bf</url>
  <id>6eff4ae9f97657f174e1222f443079613a9e52bf</id>
  <committed-date>2008-11-20T19:01:43-08:00</committed-date>
  <authored-date>2008-11-20T19:01:43-08:00</authored-date>
  <message>refinement: adding message if the submitted html is changed because it
is insecure, so user doesn't get unexpected results.</message>
  <tree>91829ee9e78c657e53e01f154d2d4d5177ad7bb8</tree>
  <committer>
    <name>Walter McGinnis</name>
    <email>walter@katipo.co.nz</email>
  </committer>
</commit>
