Permalink
Browse files

MDL-41623 rss: clean output rss content

  • Loading branch information...
1 parent 090a5f6 commit 3a986edd89ce5c365d97f053113aad9765d87fc3 @danpoltawski danpoltawski committed Sep 7, 2013
Showing with 11 additions and 7 deletions.
  1. +4 −3 blocks/rss_client/viewfeed.php
  2. +7 −4 blog/locallib.php
@@ -84,15 +84,16 @@
$feedtitle = $rss->get_title();
}
echo '<table align="center" width="50%" cellspacing="1">'."\n";
-echo '<tr><td colspan="2"><strong>'. $feedtitle .'</strong></td></tr>'."\n";
+echo '<tr><td colspan="2"><strong>'. s($feedtitle) .'</strong></td></tr>'."\n";
foreach ($rss->get_items() as $item) {
echo '<tr><td valign="middle">'."\n";
- echo '<a href="'. $item->get_link() .'" target="_blank"><strong>'. $item->get_title();
+ echo '<a href="'.$item->get_link().'" target="_blank"><strong>';
+ echo s($item->get_title());
echo '</strong></a>'."\n";
echo '</td>'."\n";
echo '</tr>'."\n";
echo '<tr><td colspan="2"><small>';
- echo $item->get_description() .'</small></td></tr>'."\n";
+ echo format_text($item->get_description(), FORMAT_HTML) .'</small></td></tr>'."\n";
}
echo '</table>'."\n";
View
@@ -214,11 +214,14 @@ public function print_html($return=false) {
$contentcell->text .= $template['body'];
$contentcell->text .= $attachedimages;
- // Uniquehash is used as a link to an external blog
if (!empty($this->uniquehash)) {
- $contentcell->text .= $OUTPUT->container_start('externalblog');
- $contentcell->text .= html_writer::link($this->uniquehash, get_string('linktooriginalentry', 'blog'));
- $contentcell->text .= $OUTPUT->container_end();
+ // Uniquehash is used as a link to an external blog
+ $url = clean_param($this->uniquehash, PARAM_URL);
+ if (!empty($url)) {
+ $contentcell->text .= $OUTPUT->container_start('externalblog');
+ $contentcell->text .= html_writer::link($url, get_string('linktooriginalentry', 'blog'));
+ $contentcell->text .= $OUTPUT->container_end();
+ }
}
// Links to tags

0 comments on commit 3a986ed

Please sign in to comment.