From aac678de48da6057ab9c93196755bacd49ef1a01 Mon Sep 17 00:00:00 2001 From: Kijin Sung Date: Wed, 10 Oct 2018 13:08:24 +0900 Subject: [PATCH] Explicitly declare noescape --- common/tpl/common_layout.html | 10 +++++----- common/tpl/default_layout.html | 2 +- common/tpl/popup_layout.html | 2 +- layouts/default/layout.html | 2 +- layouts/simple_world/layout.html | 6 +++--- layouts/user_layout/layout.html | 2 +- layouts/xedition/layout.html | 2 +- m.layouts/colorCode/layout.html | 2 +- m.layouts/default/layout.html | 2 +- m.layouts/simpleGray/layout.html | 2 +- modules/admin/tpl/layout.html | 2 +- modules/admin/tpl/popup_layout.html | 2 +- .../communication/m.skins/default/read_message.html | 2 +- .../communication/m.skins/default/send_message.html | 2 +- modules/communication/m.skins/rx_prn/new_message.html | 2 +- modules/communication/m.skins/rx_prn/send_message.html | 2 +- modules/communication/skins/default/messages.html | 2 +- modules/communication/skins/default/new_message.html | 2 +- modules/communication/skins/default/send_message.html | 2 +- .../communication/skins/simple_world/new_message.html | 2 +- .../communication/skins/simple_world/send_message.html | 2 +- modules/editor/tpl/config_preview.html | 2 +- modules/editor/tpl/editor_frame.html | 2 +- modules/editor/tpl/popup.html | 2 +- modules/editor/tpl/preview.html | 2 +- modules/layout/tpl/layout_modify.html | 2 +- modules/widget/tpl/add_content_widget.html | 2 +- 27 files changed, 33 insertions(+), 33 deletions(-) diff --git a/common/tpl/common_layout.html b/common/tpl/common_layout.html index d82cf2c11..43bd43d4d 100644 --- a/common/tpl/common_layout.html +++ b/common/tpl/common_layout.html @@ -44,7 +44,7 @@ -{Context::getHtmlHeader()} +{Context::getHtmlHeader()|noescape} diff --git a/modules/communication/m.skins/default/read_message.html b/modules/communication/m.skins/default/read_message.html index 9a7d68407..baa758265 100644 --- a/modules/communication/m.skins/default/read_message.html +++ b/modules/communication/m.skins/default/read_message.html @@ -4,7 +4,7 @@

{$message->title}

{$message->nick_name} | {zdate($message->regdate, "Y.m.d H:i")}
-
{$message->content}
+
{$message->content|noescape}
{$lang->cmd_list} diff --git a/modules/communication/m.skins/default/send_message.html b/modules/communication/m.skins/default/send_message.html index bf65f38ae..fadd0c342 100644 --- a/modules/communication/m.skins/default/send_message.html +++ b/modules/communication/m.skins/default/send_message.html @@ -35,7 +35,7 @@
  • - {$source_message->content} + {$source_message->content|noescape}
  • diff --git a/modules/communication/m.skins/rx_prn/new_message.html b/modules/communication/m.skins/rx_prn/new_message.html index 74cde0577..24ea7870e 100644 --- a/modules/communication/m.skins/rx_prn/new_message.html +++ b/modules/communication/m.skins/rx_prn/new_message.html @@ -7,7 +7,7 @@ {$message->nick_name} / {zdate($message->regdate, "Y-m-d H:i")}
  • - {$message->content} + {$message->content|noescape}
    {$lang->cmd_reply_message} diff --git a/modules/communication/m.skins/rx_prn/send_message.html b/modules/communication/m.skins/rx_prn/send_message.html index 378c35b22..0192b0ccc 100644 --- a/modules/communication/m.skins/rx_prn/send_message.html +++ b/modules/communication/m.skins/rx_prn/send_message.html @@ -30,7 +30,7 @@
    {$lang->msg_send_mail_privacy}
    - {$editor} + {$editor|noescape}
    diff --git a/modules/communication/skins/default/messages.html b/modules/communication/skins/default/messages.html index 0e6d94f6a..773248ca5 100644 --- a/modules/communication/skins/default/messages.html +++ b/modules/communication/skins/default/messages.html @@ -29,7 +29,7 @@ - {$message->content} + {$message->content|noescape} diff --git a/modules/communication/skins/default/new_message.html b/modules/communication/skins/default/new_message.html index 66b992d41..e5c75ac3a 100644 --- a/modules/communication/skins/default/new_message.html +++ b/modules/communication/skins/default/new_message.html @@ -14,7 +14,7 @@ {htmlspecialchars($message->title, ENT_COMPAT | ENT_HTML401, 'UTF-8', false)} - {$message->content} + {$message->content|noescape}
    diff --git a/modules/communication/skins/default/send_message.html b/modules/communication/skins/default/send_message.html index 2a9ffe14b..cb6e066dc 100644 --- a/modules/communication/skins/default/send_message.html +++ b/modules/communication/skins/default/send_message.html @@ -35,7 +35,7 @@ {$lang->cmd_send_mail} {$lang->msg_send_mail_privacy} - {$editor} + {$editor|noescape}
    diff --git a/modules/communication/skins/simple_world/new_message.html b/modules/communication/skins/simple_world/new_message.html index 43c29a070..d1a160fa0 100644 --- a/modules/communication/skins/simple_world/new_message.html +++ b/modules/communication/skins/simple_world/new_message.html @@ -6,7 +6,7 @@ {$message->nick_name} / {zdate($message->regdate, "Y-m-d H:i")}
    - {$message->content} + {$message->content|noescape}
    - {$editor} + {$editor|noescape}
    diff --git a/modules/editor/tpl/config_preview.html b/modules/editor/tpl/config_preview.html index 2fbcfd03c..b5588ae6a 100644 --- a/modules/editor/tpl/config_preview.html +++ b/modules/editor/tpl/config_preview.html @@ -1,5 +1,5 @@
    -

    {$editor}

    +

    {$editor|noescape}

    diff --git a/modules/editor/tpl/editor_frame.html b/modules/editor/tpl/editor_frame.html index 3c96e7ca2..4575263e5 100644 --- a/modules/editor/tpl/editor_frame.html +++ b/modules/editor/tpl/editor_frame.html @@ -14,5 +14,5 @@
    - {$editor} + {$editor|noescape}
    diff --git a/modules/editor/tpl/popup.html b/modules/editor/tpl/popup.html index e1e981475..aa8c8f175 100644 --- a/modules/editor/tpl/popup.html +++ b/modules/editor/tpl/popup.html @@ -1,3 +1,3 @@
    -{$popup_content} +{$popup_content|noescape}
    diff --git a/modules/editor/tpl/preview.html b/modules/editor/tpl/preview.html index 151b89f55..2d996e430 100644 --- a/modules/editor/tpl/preview.html +++ b/modules/editor/tpl/preview.html @@ -1,4 +1,4 @@ -{$content} +{$content|noescape} diff --git a/modules/layout/tpl/layout_modify.html b/modules/layout/tpl/layout_modify.html index 8fdcc28d2..dc1e22014 100644 --- a/modules/layout/tpl/layout_modify.html +++ b/modules/layout/tpl/layout_modify.html @@ -1,3 +1,3 @@ -{$content} +{$content|noescape} diff --git a/modules/widget/tpl/add_content_widget.html b/modules/widget/tpl/add_content_widget.html index 9d1a4dc3a..ac8093ecd 100644 --- a/modules/widget/tpl/add_content_widget.html +++ b/modules/widget/tpl/add_content_widget.html @@ -15,7 +15,7 @@
    -
    {$editor}
    +
    {$editor|noescape}