# HG changeset patch # User Dan # Date 1235965940 18000 # Node ID b33241a7cc28f97514824096b5b7ea6dc34d25c2 # Parent 28d5049803f121df6391c064ce006c1c952c68b3 Template: addslashes() around wiki_edit_notice_text (whoops) diff -r 28d5049803f1 -r b33241a7cc28 includes/template.php --- a/includes/template.php Sat Feb 28 14:38:10 2009 -0500 +++ b/includes/template.php Sun Mar 01 22:52:20 2009 -0500 @@ -1151,7 +1151,7 @@ var disable_redirect = ' . ( isset($_GET['redirect']) && $_GET['redirect'] == 'no' ? 'true' : 'false' ) . '; var pref_disable_js_fx = ' . ( @$session->user_extra['disable_js_fx'] == 1 ? 'true' : 'false' ) . '; var csrf_token = "' . $session->csrf_token . '"; - var editNotice = \'' . ( (getConfig('wiki_edit_notice', '0')=='1') ? str_replace("\n", "\\\n", RenderMan::render(getConfig('wiki_edit_notice_text'))) : '' ) . '\'; + var editNotice = \'' . ( (getConfig('wiki_edit_notice', '0')=='1') ? str_replace("\n", "\\\n", addslashes(RenderMan::render(getConfig('wiki_edit_notice_text')))) : '' ) . '\'; var prot = ' . ( ($protected) ? 'true' : 'false' ) .'; // No, hacking this var won\'t work, it\'s re-checked on the server var ENANO_SPECIAL_CREATEPAGE = \''. makeUrl($paths->nslist['Special'].'CreatePage') .'\'; var ENANO_CREATEPAGE_PARAMS = \'_do=&pagename='. $urlname_clean .'&namespace=' . $local_namespace . '\';