Apply autoescape to admin module templates

This commit is contained in:
Kijin Sung 2018-10-10 15:24:10 +09:00
parent 24df74d618
commit d9178e91d6
20 changed files with 52 additions and 3 deletions

View file

@ -1,4 +1,7 @@
<config autoescape="on" />
<include target="config_header.html" />
<div cond="$XE_VALIDATOR_MESSAGE && $XE_VALIDATOR_ID == 'modules/admin/tpl/config_domains/1'" class="message {$XE_VALIDATOR_MESSAGE_TYPE}">
<p>{$XE_VALIDATOR_MESSAGE}</p>
</div>
@ -24,7 +27,7 @@
<tbody>
<tr loop="$domain_list->data => $domain">
<td class="nowr">
{$domain->settings->title}
{$domain->settings->title|noescape}
<i cond="$domain->is_default_domain === 'Y'" class="x_icon-home" title="{$lang->cmd_is_default_domain}">{$lang->cmd_is_default_domain}</i>
</td>
<td class="nowr">{$domain->domain}</td>