rhymix/modules/module/tpl/module_selector.html
conory fa5c7afce2 모듈 선택기 보안 문제 수정
매니저 권한을 가지고 있는 모듈만 출력하도록 조정
'site_keyword' xss
회원 모듈 스킨 '작성 글 보기', '작성 글 보기' 페이지에서 [모듈 찾기] 버튼 제거
기타 소스 코드 정리
2017-04-22 15:35:32 +09:00

52 lines
2.2 KiB
HTML

<load target="./js/module_admin.js" />
<div class="x_modal-header">
<h1>{$lang->module_selector}</h1>
</div>
<form action="./" method="post" class="x_modal-body x_form-horizontal" style="max-height:none">
<input type="hidden" name="module" value="module" />
<input type="hidden" name="act" value="dispModuleSelectList" />
<input type="hidden" name="id" value="{$id}" />
<input type="hidden" name="type" value="{$type}" />
<input type="hidden" name="vid" value="{$vid}" />
<div class="x_control-group" cond="$logged_info->is_admin === 'Y' && $site_count">
<label class="x_control-label" for="site_keyword">{$lang->virtual_site}</label>
<div class="x_controls">
<span class="x_input-append">
<input type="text" name="site_keyword" id="site_keyword" value="{$site_keyword}" />
<input type="submit" value="{$lang->cmd_search}" class="x_btn" />
</span>
<p class="x_help-block">{$lang->about_search_virtual_site}</p>
</div>
</div>
<div class="x_control-group">
<label class="x_control-label" for="selected_module">{$lang->module}</label>
<div class="x_controls">
<select name="selected_module" id="selected_module">
<option loop="$mid_list => $key,$val" value="{$key}" selected="selected"|cond="$key == $selected_module">{$val->title}</option>
</select>
<input type="submit" value="{$lang->cmd_search}" class="x_btn" />
</div>
</div>
<!--@foreach($selected_mids as $category_name => $list)-->
<h2 cond="$category_name" style="margin-top:40px;">{$category_name}</h2>
<table class="x_table x_table-striped x_table-hover" style="border-top:1px dotted #ddd">
<thead>
<tr>
<th>{$lang->mid}</th>
<th>{$lang->browser_title}</th>
<th>{$type=='single'?$lang->cmd_select:$lang->cmd_insert}</th>
<tr>
</thead>
<tbody>
<tr loop="$list => $mid_name,$module_info">
<td>{$mid_name}</td>
<td>{$module_info->browser_title}</td>
<td><a href="#" onclick="insertModule('{$id}', {$module_info->module_srl}, '{$mid_name}', '{escape($module_info->browser_title, false)}', {$type=='single'?'false':'true'}); return false;" class="button green"><span>{$type=='single'?$lang->cmd_select:$lang->cmd_insert}</span></a></td>
</tr>
</tbody>
</table>
<!--@end-->
</form>