Explicitly declare noescape

This commit is contained in:
Kijin Sung 2018-10-10 13:08:24 +09:00
parent 56f20e84c0
commit aac678de48
27 changed files with 33 additions and 33 deletions

View file

@ -4,7 +4,7 @@
<h2>{$message->title}</h2><span class="ex">{$message->nick_name} | {zdate($message->regdate, "Y.m.d H:i")}</span>
</div>
<div class="co">
<div class="xe_content">{$message->content}</div>
<div class="xe_content">{$message->content|noescape}</div>
</div>
<div class="bna">
<span class="fl"><a href="{getUrl('message_srl', '')}" class="bn white">{$lang->cmd_list}</a></span>

View file

@ -35,7 +35,7 @@
<input type="text" name="title" id="message_title" value="{$source_message->title}"/>
</li>
<li class="xe_content">
{$source_message->content}
{$source_message->content|noescape}
</li>
<li>
<label for="message_content">{$lang->content}</label>

View file

@ -7,7 +7,7 @@
<a href="popup_menu_area" class="member_{$message->member_srl}">{$message->nick_name}</a> / {zdate($message->regdate, "Y-m-d H:i")}
</div>
<div class="xe_content">
{$message->content}
{$message->content|noescape}
</div>
<div class="prn-anchor-buttons">
<a cond="$message->message_type != 'S' && $message->member_srl != $logged_info->member_srl" href="#" onclick="doSendMessage('{$message->sender_srl}','{$message->message_srl}');">{$lang->cmd_reply_message}</a>

View file

@ -30,7 +30,7 @@
<label for="message_send_mail"><input type="checkbox" value="Y" name="send_mail" id="message_send_mail" /> {$lang->cmd_send_mail}</label>
<div class="rx_prn-notice info">{$lang->msg_send_mail_privacy}</div>
</div>
{$editor}
{$editor|noescape}
<div class="control-group">
<input type="submit" value="{$lang->cmd_send_message}" />
</div>

View file

@ -29,7 +29,7 @@
</tr>
<tr>
<td class="xe_content">
{$message->content}
{$message->content|noescape}
</td>
</tr>
</table>

View file

@ -14,7 +14,7 @@
<td>{htmlspecialchars($message->title, ENT_COMPAT | ENT_HTML401, 'UTF-8', false)}</td>
</tr>
<tr>
<td colspan="2" class="xe_content">{$message->content}</td>
<td colspan="2" class="xe_content">{$message->content|noescape}</td>
</tr>
</table>
<div class="btnArea">

View file

@ -35,7 +35,7 @@
<td><input type="checkbox" value="Y" name="send_mail" /> {$lang->cmd_send_mail} <span class="explanation">{$lang->msg_send_mail_privacy}</span></td>
</tr>
</table>
{$editor}
{$editor|noescape}
<div class="btnArea">
<input type="submit" value="{$lang->cmd_send_message}" class="btn btn-inverse" />
</div>

View file

@ -6,7 +6,7 @@
<a href="popup_menu_area" class="member_{$message->member_srl}">{$message->nick_name}</a> / {zdate($message->regdate, "Y-m-d H:i")}
</div>
<div class="xe_content">
{$message->content}
{$message->content|noescape}
</div>
<div class="sw-footer sw-anchor-buttons">
<a cond="$message->message_type != 'S' && $message->member_srl != $logged_info->member_srl" href="#" onclick="doSendMessage('{$message->sender_srl}','{$message->message_srl}');">{$lang->cmd_reply_message}</a>

View file

@ -29,7 +29,7 @@
<br>{$lang->msg_allow_message_please}
</div>
</div>
{$editor}
{$editor|noescape}
<div class="control-group">
<input type="submit" value="{$lang->cmd_send_message}" />
</div>