Skip to content

Commit

Permalink
And some more escaping fixed
Browse files Browse the repository at this point in the history
Signed-off-by: emanuele <emanuele45@gmail.com>
  • Loading branch information
emanuele45 committed Aug 13, 2014
1 parent b168a4a commit 19f4e83
Show file tree
Hide file tree
Showing 4 changed files with 16 additions and 16 deletions.
14 changes: 7 additions & 7 deletions sources/Load.php
Expand Up @@ -1630,15 +1630,15 @@ function loadTheme($id_theme = 0, $initialize = true)
);
// Default JS variables for use in every theme
addJavascriptVar(array(
'elk_theme_url' => '"' . $settings['theme_url'] . '"',
'elk_default_theme_url' => '"' . $settings['default_theme_url'] . '"',
'elk_images_url' => '"' . $settings['images_url'] . '"',
'elk_smiley_url' => '"' . $modSettings['smileys_url'] . '"',
'elk_scripturl' => '"' . $scripturl . '"',
'elk_theme_url' => JavaScriptEscape($settings['theme_url']),
'elk_default_theme_url' => JavaScriptEscape($settings['default_theme_url']),
'elk_images_url' => JavaScriptEscape($settings['images_url']),
'elk_smiley_url' => JavaScriptEscape($modSettings['smileys_url']),
'elk_scripturl' => JavaScriptEscape($scripturl),
'elk_iso_case_folding' => $context['server']['iso_case_folding'] ? 'true' : 'false',
'elk_charset' => '"UTF-8"',
'elk_session_id' => '"' . $context['session_id'] . '"',
'elk_session_var' => '"' . $context['session_var'] . '"',
'elk_session_id' => JavaScriptEscape($context['session_id']),
'elk_session_var' => JavaScriptEscape($context['session_var']),
'elk_member_id' => $context['user']['id'],
'ajax_notification_text' => JavaScriptEscape($txt['ajax_in_progress']),
'ajax_notification_cancel_text' => JavaScriptEscape($txt['modify_cancel']),
Expand Down
2 changes: 1 addition & 1 deletion sources/Subs.php
Expand Up @@ -2643,7 +2643,7 @@ function setupThemeContext($forceload = false)
$context['common_stats']['boardindex_total_posts'] = sprintf($txt['boardindex_total_posts'], $context['common_stats']['total_posts'], $context['common_stats']['total_topics'], $context['common_stats']['total_members']);

if (empty($settings['theme_version']))
addJavascriptVar(array('elk_scripturl' => $scripturl));
addJavascriptVar(array('elk_scripturl' => $scripturl), true);

if (!isset($context['page_title']))
$context['page_title'] = '';
Expand Down
6 changes: 3 additions & 3 deletions sources/admin/ManageThemes.controller.php
Expand Up @@ -1643,9 +1643,9 @@ private function _action_edit_submit()
elseif ($is_css)
{
addJavascriptVar(array(
'previewData' => '',
'previewTimeout' => '',
'refreshPreviewCache' => '',
'previewData' => '\'\'',
'previewTimeout' => '\'\'',
'refreshPreviewCache' => '\'\'',
'editFilename' => JavaScriptEscape($context['edit_filename']),
'theme_id' => $settings['theme_id'],
));
Expand Down
10 changes: 5 additions & 5 deletions sources/subs/Editor.subs.php
Expand Up @@ -154,11 +154,11 @@ function create_control_richedit($editorOptions)
// JS makes the editor go round
loadJavascriptFile(array('jquery.sceditor.min.js', 'jquery.sceditor.bbcode.min.js', 'jquery.sceditor.elkarte.js', 'post.js', 'splittag.plugin.js', 'dropAttachments.js'));
addJavascriptVar(array(
'post_box_name' => '"' . $editorOptions['id'] . '"',
'elk_smileys_url' => '"' . $settings['smileys_url'] . '"',
'bbc_quote_from' => '"' . addcslashes($txt['quote_from'], "'") . '"',
'bbc_quote' => '"' . addcslashes($txt['quote'], "'") . '"',
'bbc_search_on' => '"' . addcslashes($txt['search_on'], "'") . '"')
'post_box_name' => $editorOptions['id'],
'elk_smileys_url' => $settings['smileys_url'],
'bbc_quote_from' => $txt['quote_from'],
'bbc_quote' => $txt['quote'],
'bbc_search_on' => $txt['search_on']), true
);

// Editor language file
Expand Down

0 comments on commit 19f4e83

Please sign in to comment.