Commit 238c6476f8113bff73e82cfd59530424539a5682

Authored by Conrad Vermeulen
1 parent 8aa4d7b5

KTS-2178

"cross site scripting"
Updated.

Reviewed By: Kevin Fourie

git-svn-id: https://kt-dms.svn.sourceforge.net/svnroot/kt-dms/trunk@6949 c91229c3-7414-0410-bfa2-8a42b809f60b
templates/ktcore/folder/bulkImport.smarty
@@ -12,9 +12,9 @@ @@ -12,9 +12,9 @@
12 {capture assign=sJavascript} 12 {capture assign=sJavascript}
13 {literal} 13 {literal}
14 function swapInItem(elementId, req) { 14 function swapInItem(elementId, req) {
15 - 15 +
16 var cp = getElement(elementId); 16 var cp = getElement(elementId);
17 - 17 +
18 cp.innerHTML = req.responseText; 18 cp.innerHTML = req.responseText;
19 initialiseConditionalFieldsets(); 19 initialiseConditionalFieldsets();
20 } 20 }
@@ -28,8 +28,8 @@ function swapElementFromRequest(elementId, url) { @@ -28,8 +28,8 @@ function swapElementFromRequest(elementId, url) {
28 var cp = getElement(elementId); 28 var cp = getElement(elementId);
29 cp.innerHTML=_("loading..."); 29 cp.innerHTML=_("loading...");
30 deff.addCallback(partial(swapInItem, elementId)); 30 deff.addCallback(partial(swapInItem, elementId));
31 -  
32 - 31 +
  32 +
33 } 33 }
34 34
35 function getMetadataForType(id) { 35 function getMetadataForType(id) {
@@ -54,7 +54,7 @@ addLoadEvent(startupMetadata); @@ -54,7 +54,7 @@ addLoadEvent(startupMetadata);
54 {/capture} 54 {/capture}
55 {$context->oPage->requireJSStandalone($sJavascript)} 55 {$context->oPage->requireJSStandalone($sJavascript)}
56 56
57 -<h2><img src="{if $config->get("ui/morphEnabled") == '1'}{$rootUrl}/skins/kts_{$config->get("ui/morphTo")}/title_bullet.png{else}{$rootUrl}/resources/graphics/title_bullet.png{/if}"/>{i18n}Import files into{/i18n}:<br />{$context->oFolder->getName()}</h2> 57 +<h2><img src="{if $config->get("ui/morphEnabled") == '1'}{$rootUrl}/skins/kts_{$config->get("ui/morphTo")}/title_bullet.png{else}{$rootUrl}/resources/graphics/title_bullet.png{/if}"/>{i18n}Import files into{/i18n}:<br />{$context->oFolder->getName()|sanitize}</h2>
58 58
59 <form method="POST" action="{$smarty.server.PHP_SELF}" enctype="multipart/form-data"> 59 <form method="POST" action="{$smarty.server.PHP_SELF}" enctype="multipart/form-data">
60 <fieldset><legend>{i18n}Import from Server Location{/i18n}</legend> 60 <fieldset><legend>{i18n}Import from Server Location{/i18n}</legend>