Commit c66afabbf17368402f12f2739541ff4e03c61b45

Authored by conradverm
1 parent db1c3aac

KTS-2178

"cross site scripting"
Updated.

Reviewed By: Kevin Fourie

git-svn-id: https://kt-dms.svn.sourceforge.net/svnroot/kt-dms/trunk@6929 c91229c3-7414-0410-bfa2-8a42b809f60b
templates/ktstandard/action/document_links.smarty
1   -<h2><img src="{if $config->get("ui/morphEnabled") == '1'}{$rootUrl}/skins/kts_{$config->get("ui/morphTo")}/title_bullet.png{else}{$rootUrl}/resources/graphics/title_bullet.png{/if}"/>{i18n}Document Links{/i18n}:<br />{$context->oDocument->getName()}</h2>
  1 +<h2><img src="{if $config->get("ui/morphEnabled") == '1'}{$rootUrl}/skins/kts_{$config->get("ui/morphTo")}/title_bullet.png{else}{$rootUrl}/resources/graphics/title_bullet.png{/if}"/>{i18n}Document Links{/i18n}:<br />{$context->oDocument->getName()|sanitize}</h2>
2 2  
3 3 <p class="descriptiveText">{i18n}The current links to and from this document are displayed below.{/i18n}</p>
4 4  
... ... @@ -12,15 +12,15 @@
12 12 <th>{i18n}Relationship{/i18n}</th>
13 13 </tr>
14 14 </thead>
15   -
  15 +
16 16 <tbody>
17 17  
18 18  
19 19  
20 20  
21 21  
22   -{if $links_from || $links_to}
23   -
  22 +{if $links_from || $links_to}
  23 +
24 24 {foreach from=$links_from item=link}
25 25  
26 26 {assign var="type" value=$link->getLinkType()}
... ... @@ -35,12 +35,12 @@
35 35 {/if}
36 36 </td>
37 37  
38   - <td><a href="{"viewDocument"|generateControllerUrl}&qs[fDocumentId]={$target->getId()}&qs[action]=main">{$target->getName()}</a></td>
  38 + <td><a href="{"viewDocument"|generateControllerUrl}&qs[fDocumentId]={$target->getId()}&qs[action]=main">{$target->getName()|sanitize}</a></td>
39 39 <td>{$type->getName()}</td>
40 40 <td>{i18n}Linked <b>from</b> this document{/i18n}</td>
41 41 </tr>
42   -
43   -{/foreach}
  42 +
  43 +{/foreach}
44 44  
45 45 {foreach from=$links_to item=link}
46 46  
... ... @@ -55,13 +55,13 @@
55 55 &nbsp;
56 56 {/if}
57 57 </td>
58   -
59   - <td><a href="{"viewDocument"|generateControllerUrl}&qs[fDocumentId]={$target->getId()}&qs[action]=main">{$target->getName()}</a></td>
  58 +
  59 + <td><a href="{"viewDocument"|generateControllerUrl}&qs[fDocumentId]={$target->getId()}&qs[action]=main">{$target->getName()|sanitize}</a></td>
60 60 <td>{$type->getName()}</td>
61 61 <td>{i18n}Links <b>to</b> this document{/i18n}</td>
62 62 </tr>
63   -
64   -{/foreach}
  63 +
  64 +{/foreach}
65 65  
66 66  
67 67 {else}
... ...