Explicitly declare noescape

This commit is contained in:
Kijin Sung 2018-10-10 13:12:32 +09:00
parent aac678de48
commit 254b83dfd7
12 changed files with 12 additions and 12 deletions

View file

@ -1,5 +1,5 @@
<load target="./js/document_admin.js" />
{$content}
{$content|noescape}
<div class="btnArea">
<button class="btn" type="button" onclick="window.close();return false;">{$lang->cmd_close}</button>
</div>

View file

@ -7,7 +7,7 @@
{$val->name}: {$val->getValueHtml()}
<!--@end-->
<!--@end-->
{$oDocument->getContent(false, false)}
{$oDocument->getContent(false, false)|noescape}
<script>
jQuery(window).load(function() { window.print(); } );
</script>

View file

@ -18,7 +18,7 @@
<div id="body">
<div id="content">
{$content}
{$content|noescape}
</div>
<hr />
<div class="extension e1">

View file

@ -1 +1 @@
{$content}
{$content|noescape}

View file

@ -35,7 +35,7 @@
<label for="{$formTag->name}">{$formTag->title}</label>
<div cond="$formTag->name != 'signature'">{$formTag->inputTag}</div>
<div cond="$formTag->name =='signature'">
{$editor}
{$editor|noescape}
</div>
</li>
<li><label for="mailing" class="db fb al">{$lang->allow_mailing}</label><input id="mailing" type="checkbox" name="allow_mailing" value="Y" class="checkbox" <!--@if($member_info->allow_mailing!='N')-->checked="checked"<!--@end--> /> <p style="color:#666">{$lang->about_allow_mailing}</p></li>

View file

@ -31,7 +31,7 @@
<block loop="$formTags=>$formTag" cond="$formTag->name !== 'profile_image'">
<label for="{$formTag->name}" class="control-label">{trim(str_replace('*','',strip_tags($formTag->title)))}<!--@if(strpos($formTag->title,'<em style="color:red">*</em>') !== false)--><sup style="color:red">*</sup><!--@endif--></label>
<block cond="$formTag->name != 'signature'">{$formTag->inputTag}</block>
<block cond="$formTag->name =='signature'">{$editor}</block>
<block cond="$formTag->name =='signature'">{$editor|noescape}</block>
</block>
<label class="control-label">{$lang->allow_mailing}</label>
<div class="controls">

View file

@ -59,7 +59,7 @@
</block>
<block cond="$formTag->name == 'signature'">
<input type="hidden" name="signature" value="" />
{$editor}
{$editor|noescape}
</block>
</block>
<div class="control-label">{$lang->allow_mailing}</div>

View file

@ -30,7 +30,7 @@
<label for="{$formTag->name}" class="control-label">{$formTag->title}</label>
<div class="controls" cond="$formTag->name != 'signature'">{$formTag->inputTag}</div>
<div class="controls" cond="$formTag->name =='signature'">
{$editor}
{$editor|noescape}
<style scoped>
.xpress-editor>#smart_content,
.xpress-editor>#smart_content>.tool{clear:none}

View file

@ -59,7 +59,7 @@
</div>
<div class="controls" cond="$formTag->name == 'signature'">
<input type="hidden" name="signature" value="" />
{$editor}
{$editor|noescape}
<style scoped>
.xpress-editor>#smart_content,
.xpress-editor>#smart_content>.tool{clear:none}

View file

@ -25,7 +25,7 @@
<block loop="$formTags=>$formTag">
<label for="{$formTag->name}" class="control-label">{trim(str_replace('*','',strip_tags($formTag->title)))}<!--@if(strpos($formTag->title,'<em style="color:red">*</em>') !== false)--><sup style="color:red">*</sup><!--@endif--></label>
<block cond="$formTag->name != 'signature'">{$formTag->inputTag}</block>
<block cond="$formTag->name =='signature'">{$editor}</block>
<block cond="$formTag->name =='signature'">{$editor|noescape}</block>
</block>
<label class="control-label">{$lang->allow_mailing}</label>
<div class="controls">

View file

@ -53,7 +53,7 @@
</block>
<block cond="$formTag->name == 'signature'">
<input type="hidden" name="signature" value="" />
{$editor}
{$editor|noescape}
</block>
</block>
<div class="control-label">{$lang->allow_mailing}</div>

View file

@ -48,7 +48,7 @@
<div loop="$formTags=>$formTag" class="x_control-group">
<label class="x_control-label" for="{$formTag->name}">{$formTag->title}</label>
<div class="x_controls" cond="$formTag->name != 'signature'">{$formTag->inputTag}</div>
<div class="x_controls" cond="$formTag->name =='signature'">{$editor}</div>
<div class="x_controls" cond="$formTag->name =='signature'">{$editor|noescape}</div>
</div>
<style scoped>
.xpress-editor>#smart_content,