diff options
Diffstat (limited to 'mod/file')
| -rw-r--r-- | mod/file/pages/file/friends.php | 2 | ||||
| -rw-r--r-- | mod/file/pages/file/owner.php | 2 | ||||
| -rw-r--r-- | mod/file/pages/file/search.php | 18 | ||||
| -rw-r--r-- | mod/file/pages/file/world.php | 2 | 
4 files changed, 12 insertions, 12 deletions
| diff --git a/mod/file/pages/file/friends.php b/mod/file/pages/file/friends.php index 7bde42962..0b351efaf 100644 --- a/mod/file/pages/file/friends.php +++ b/mod/file/pages/file/friends.php @@ -11,7 +11,7 @@ elgg_push_breadcrumb(elgg_echo('file'), "file/all");  elgg_push_breadcrumb($owner->name, "file/owner/$owner->username");  elgg_push_breadcrumb(elgg_echo('friends')); -elgg_register_add_button(); +elgg_register_title_button();  $title = elgg_echo("file:friends"); diff --git a/mod/file/pages/file/owner.php b/mod/file/pages/file/owner.php index 2244de095..4e2ec89d4 100644 --- a/mod/file/pages/file/owner.php +++ b/mod/file/pages/file/owner.php @@ -13,7 +13,7 @@ $owner = elgg_get_page_owner_entity();  elgg_push_breadcrumb(elgg_echo('file'), "file/all");  elgg_push_breadcrumb($owner->name); -elgg_register_add_button(); +elgg_register_title_button();  $params = array(); diff --git a/mod/file/pages/file/search.php b/mod/file/pages/file/search.php index cffe67e0c..3e85d45db 100644 --- a/mod/file/pages/file/search.php +++ b/mod/file/pages/file/search.php @@ -15,10 +15,10 @@ group_gatekeeper();  // Get input  $md_type = 'simpletype'; -$tag = get_input('tag'); +// avoid reflected XSS attacks by only allowing alnum characters +$file_type = preg_replace('[\W]', '', get_input('tag'));  $listtype = get_input('listtype'); -$friends = get_input('friends', false); - +$friends = (bool)get_input('friends', false);  // breadcrumbs  elgg_push_breadcrumb(elgg_echo('file'), "file/all"); @@ -32,8 +32,8 @@ if ($owner) {  if ($friends && $owner) {  	elgg_push_breadcrumb(elgg_echo('friends'), "file/friends/$owner->username");  } -if ($tag) { -	elgg_push_breadcrumb(elgg_echo("file:type:$tag")); +if ($file_type) { +	elgg_push_breadcrumb(elgg_echo("file:type:$file_type"));  } else {  	elgg_push_breadcrumb(elgg_echo('all'));  } @@ -41,10 +41,10 @@ if ($tag) {  // title  if (!$owner) {  	// world files -	$title = elgg_echo('all') . ' ' . elgg_echo("file:type:$tag"); +	$title = elgg_echo('all') . ' ' . elgg_echo("file:type:$file_type");  } else {  	$friend_string = $friends ? elgg_echo('file:title:friends') : ''; -	$type_string = elgg_echo("file:type:$tag"); +	$type_string = elgg_echo("file:type:$file_type");  	$title = elgg_echo('file:list:title', array($owner->name, $friend_string, $type_string));  } @@ -76,9 +76,9 @@ $params = array(  	'full_view' => false,  ); -if ($tag) { +if ($file_type) {  	$params['metadata_name'] = $md_type; -	$params['metadata_value'] = $tag; +	$params['metadata_value'] = $file_type;  	$content = elgg_list_entities_from_metadata($params);  } else {  	$content = elgg_list_entities($params); diff --git a/mod/file/pages/file/world.php b/mod/file/pages/file/world.php index 560743bed..e438ca2f0 100644 --- a/mod/file/pages/file/world.php +++ b/mod/file/pages/file/world.php @@ -7,7 +7,7 @@  elgg_push_breadcrumb(elgg_echo('file')); -elgg_register_add_button(); +elgg_register_title_button();  $limit = get_input("limit", 10); | 
