From 9ef2afc85b77b913a9cb99ded033dab40a112a9d Mon Sep 17 00:00:00 2001 From: ryan Date: Tue, 28 Apr 2009 06:37:51 +0000 Subject: [PATCH] attr escaping. see #9650 git-svn-id: http://svn.automattic.com/wordpress/trunk@11110 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/edit-page-form.php | 32 ++++++++++++++++---------------- wp-admin/edit-pages.php | 6 +++--- wp-admin/edit-tag-form.php | 4 ++-- wp-admin/edit-tags.php | 8 ++++---- wp-admin/edit.php | 12 ++++++------ wp-admin/export.php | 4 ++-- wp-admin/install.php | 6 +++--- wp-admin/link-manager.php | 12 ++++++------ wp-admin/media-upload.php | 2 +- wp-admin/media.php | 6 +++--- wp-admin/options-discussion.php | 12 ++++++------ wp-admin/options-general.php | 6 +++--- wp-admin/options-media.php | 2 +- wp-admin/options-misc.php | 2 +- wp-admin/options-permalink.php | 8 ++++---- wp-admin/options-privacy.php | 2 +- wp-admin/options-reading.php | 2 +- wp-admin/options-writing.php | 2 +- wp-admin/options.php | 2 +- wp-admin/plugin-editor.php | 12 ++++++------ wp-admin/plugins.php | 10 +++++----- wp-admin/press-this.php | 14 +++++++------- wp-admin/sidebar.php | 10 +++++----- wp-admin/theme-editor.php | 12 ++++++------ wp-admin/update-core.php | 12 ++++++------ wp-admin/upload.php | 14 +++++++------- wp-admin/user-edit.php | 26 +++++++++++++------------- wp-admin/user-new.php | 12 ++++++------ wp-admin/users.php | 14 +++++++------- wp-admin/widgets.php | 12 ++++++------ 30 files changed, 139 insertions(+), 139 deletions(-) diff --git a/wp-admin/edit-page-form.php b/wp-admin/edit-page-form.php index 1c1c0cbff..3eefdbd44 100644 --- a/wp-admin/edit-page-form.php +++ b/wp-admin/edit-page-form.php @@ -73,9 +73,9 @@ function page_submit_meta_box($post) {
post_status && 'future' != $post->post_status && 'pending' != $post->post_status ) { ?> -post_status ) { ?>style="display:none" type="submit" name="save" id="save-post" value="" tabindex="4" class="button button-highlighted" /> +post_status ) { ?>style="display:none" type="submit" name="save" id="save-post" value="" tabindex="4" class="button button-highlighted" /> post_status && $can_publish ) { ?> - +
@@ -124,7 +124,7 @@ switch ( $post->post_status ) { post_status ) { ?>style="display:none;" class="edit-post-status hide-if-no-js" tabindex='4'>
- + - + + - - + + - - + + - - + +
@@ -293,7 +293,7 @@ function page_attributes_meta_box($post){ } ?>
-

+

'; ?> - - + + - - + + post_status ) wp_original_referer_field(true, 'previous'); ?> diff --git a/wp-admin/edit-pages.php b/wp-admin/edit-pages.php index b8eb28b77..95e27c4bc 100644 --- a/wp-admin/edit-pages.php +++ b/wp-admin/edit-pages.php @@ -171,7 +171,7 @@ endif; @@ -215,7 +215,7 @@ if ( $page_links ) : ?> - +
@@ -254,7 +254,7 @@ if ( $page_links ) - +
diff --git a/wp-admin/edit-tag-form.php b/wp-admin/edit-tag-form.php index d715d06a6..5390e6e51 100644 --- a/wp-admin/edit-tag-form.php +++ b/wp-admin/edit-tag-form.php @@ -20,7 +20,7 @@ do_action('edit_tag_form_pre', $tag); ?>
- + @@ -40,7 +40,7 @@ do_action('edit_tag_form_pre', $tag); ?>
-

+

diff --git a/wp-admin/edit-tags.php b/wp-admin/edit-tags.php index 11ab38fd7..5d52de1f2 100644 --- a/wp-admin/edit-tags.php +++ b/wp-admin/edit-tags.php @@ -160,7 +160,7 @@ endif; ?>
@@ -201,7 +201,7 @@ if ( $page_links ) - + @@ -244,7 +244,7 @@ if ( $page_links ) - +
@@ -297,7 +297,7 @@ else

-

+

diff --git a/wp-admin/edit.php b/wp-admin/edit.php index 0075299ac..551cfb989 100644 --- a/wp-admin/edit.php +++ b/wp-admin/edit.php @@ -166,13 +166,13 @@ endif; - + @@ -195,7 +195,7 @@ $page_links = paginate_links( array( - + yyear$arc_row->mmonth'>"; + echo ""; echo $wp_locale->get_month($arc_row->mmonth) . " $arc_row->yyear"; echo "\n"; } @@ -236,7 +236,7 @@ $dropdown_options = array('show_option_all' => __('View all categories'), 'hide_ wp_dropdown_categories($dropdown_options); do_action('restrict_manage_posts'); ?> - + @@ -275,7 +275,7 @@ if ( $page_links ) - +

diff --git a/wp-admin/export.php b/wp-admin/export.php index dbe1b143c..3f39ff1fb 100644 --- a/wp-admin/export.php +++ b/wp-admin/export.php @@ -42,14 +42,14 @@ require_once ('admin-header.php'); $authors = $wpdb->get_col( "SELECT post_author FROM $wpdb->posts GROUP BY post_author" ); foreach ( $authors as $id ) { $o = get_userdata( $id ); - echo ""; + echo ""; } ?> -

+

diff --git a/wp-admin/install.php b/wp-admin/install.php index 59678f0a6..370c34b19 100644 --- a/wp-admin/install.php +++ b/wp-admin/install.php @@ -57,18 +57,18 @@ function display_setup_form( $error = null ) { - + -

+

-

+

- +


@@ -103,14 +103,14 @@ if ( isset($_GET['deleted']) ) { - + \n"; $select_cat .= '\n"; foreach ((array) $categories as $cat) - $select_cat .= '\n"; + $select_cat .= '\n"; $select_cat .= "\n"; $select_order = " + @@ -190,7 +190,7 @@ if ( $links ) { switch($column_name) { case 'cb': - echo ''; + echo ''; break; case 'name': @@ -258,7 +258,7 @@ if ( $links ) { - +
diff --git a/wp-admin/media-upload.php b/wp-admin/media-upload.php index 8241a1562..8c8869cd8 100644 --- a/wp-admin/media-upload.php +++ b/wp-admin/media-upload.php @@ -78,7 +78,7 @@ if ( isset($_GET['inline']) ) {

- +

diff --git a/wp-admin/media.php b/wp-admin/media.php index a22da8a4d..a3f676e3b 100644 --- a/wp-admin/media.php +++ b/wp-admin/media.php @@ -93,9 +93,9 @@ case 'edit' :

- - - + + + diff --git a/wp-admin/options-discussion.php b/wp-admin/options-discussion.php index 32ea8e2ee..383b0792d 100644 --- a/wp-admin/options-discussion.php +++ b/wp-admin/options-discussion.php @@ -64,7 +64,7 @@ $maxdeep = (int) apply_filters( 'thread_comments_depth_max', 10 ); $thread_comments_depth = ' $value
"; + echo "\n\t
"; } ?> @@ -172,7 +172,7 @@ printf( __('Comments should be displayed with the %s comments at the top of each $ratings = array( 'G' => __('G — Suitable for all audiences'), 'PG' => __('PG — Possibly offensive, usually for audiences 13 and above'), 'R' => __('R — Intended for adult audiences above 17'), 'X' => __('X — Even more mature than above')); foreach ($ratings as $key => $rating) : $selected = (get_option('avatar_rating') == $key) ? 'checked="checked"' : ''; - echo "\n\t
"; + echo "\n\t
"; endforeach; ?> @@ -201,7 +201,7 @@ $size = 32; $avatar_list = ''; foreach ( $avatar_defaults as $default_key => $default_name ) { $selected = ($default == $default_key) ? 'checked="checked" ' : ''; - $avatar_list .= "\n\t

- +

diff --git a/wp-admin/options-general.php b/wp-admin/options-general.php index 2f03acbb6..dc5cc5c75 100644 --- a/wp-admin/options-general.php +++ b/wp-admin/options-general.php @@ -120,7 +120,7 @@ foreach ( $offset_range as $offset ) { $selected = " selected='selected'"; $current_offset_name = $offset_name; } - echo "'; + echo "'; } ?> @@ -263,7 +263,7 @@ if (empty($tzstring)) { // set the Etc zone if no timezone string exists " . $wp_locale->get_weekday($day_index) . ''; + echo "\n\t'; endfor; ?> @@ -274,7 +274,7 @@ endfor;

- +

diff --git a/wp-admin/options-media.php b/wp-admin/options-media.php index 87a6d0cef..0d5f2e3ef 100644 --- a/wp-admin/options-media.php +++ b/wp-admin/options-media.php @@ -65,7 +65,7 @@ include('admin-header.php');

- +

diff --git a/wp-admin/options-misc.php b/wp-admin/options-misc.php index d3d7af0a2..061587bf8 100644 --- a/wp-admin/options-misc.php +++ b/wp-admin/options-misc.php @@ -67,7 +67,7 @@ include('admin-header.php');

- +

diff --git a/wp-admin/options-permalink.php b/wp-admin/options-permalink.php index 5720e92a3..8eeff74bb 100644 --- a/wp-admin/options-permalink.php +++ b/wp-admin/options-permalink.php @@ -151,15 +151,15 @@ $structures = array( /?p=123 - + - + - + /archives/123 @@ -200,7 +200,7 @@ $structures = array(

- +

diff --git a/wp-admin/options-privacy.php b/wp-admin/options-privacy.php index c46b72083..862681b47 100644 --- a/wp-admin/options-privacy.php +++ b/wp-admin/options-privacy.php @@ -39,7 +39,7 @@ include('./admin-header.php');

- +

diff --git a/wp-admin/options-reading.php b/wp-admin/options-reading.php index fbd3bca91..e66606038 100644 --- a/wp-admin/options-reading.php +++ b/wp-admin/options-reading.php @@ -80,7 +80,7 @@ include('admin-header.php');

- +

diff --git a/wp-admin/options-writing.php b/wp-admin/options-writing.php index 10b34ef0c..ab148ed22 100644 --- a/wp-admin/options-writing.php +++ b/wp-admin/options-writing.php @@ -127,7 +127,7 @@ wp_dropdown_categories(array('hide_empty' => 0, 'name' => 'default_email_categor

- +

diff --git a/wp-admin/options.php b/wp-admin/options.php index 4255047ac..c371fc61c 100644 --- a/wp-admin/options.php +++ b/wp-admin/options.php @@ -130,7 +130,7 @@ endforeach; ?> -

+

diff --git a/wp-admin/plugin-editor.php b/wp-admin/plugin-editor.php index 595edb66d..2b45c518b 100644 --- a/wp-admin/plugin-editor.php +++ b/wp-admin/plugin-editor.php @@ -156,7 +156,7 @@ default: } ?> - +
@@ -204,11 +204,11 @@ foreach ( $plugin_files as $plugin_file ) :
- - + +
-
+
@@ -217,9 +217,9 @@ foreach ( $plugin_files as $plugin_file ) :

"; + echo ""; else - echo ""; + echo ""; ?>

diff --git a/wp-admin/plugins.php b/wp-admin/plugins.php index bea219f80..f762a7279 100644 --- a/wp-admin/plugins.php +++ b/wp-admin/plugins.php @@ -142,10 +142,10 @@ if ( !empty($action) ) { echo ''; ?> - +
- +

@@ -413,9 +413,9 @@ function print_plugin_actions($context) { - + - +
- +

diff --git a/wp-admin/press-this.php b/wp-admin/press-this.php index 1517eaa10..24481cb53 100644 --- a/wp-admin/press-this.php +++ b/wp-admin/press-this.php @@ -455,11 +455,11 @@ var ajaxurl = '';

- + - + -

+

@@ -479,9 +479,9 @@ var ajaxurl = '';

- + 0, 'name' => 'newcat_parent', 'orderby' => 'name', 'hierarchical' => 1, 'show_option_none' => __('Parent category'), 'tab_index' => 3 ) ); ?> - +

@@ -497,8 +497,8 @@ var ajaxurl = '';

diff --git a/wp-admin/sidebar.php b/wp-admin/sidebar.php index 210c0b9bf..ea9c4ea0f 100644 --- a/wp-admin/sidebar.php +++ b/wp-admin/sidebar.php @@ -88,10 +88,10 @@ form {
- + - - + +

- + - +

diff --git a/wp-admin/theme-editor.php b/wp-admin/theme-editor.php index d900499ad..b3a860788 100644 --- a/wp-admin/theme-editor.php +++ b/wp-admin/theme-editor.php @@ -94,7 +94,7 @@ default: $functions = wp_doc_link_parse( $content ); $docs_select = ' - +
@@ -199,14 +199,14 @@ if ($allowed_files) :
- - + +
- +
@@ -214,7 +214,7 @@ if ($allowed_files) :

"; + echo ""; ?>

diff --git a/wp-admin/update-core.php b/wp-admin/update-core.php index 952dd04ed..09a85621a 100644 --- a/wp-admin/update-core.php +++ b/wp-admin/update-core.php @@ -40,15 +40,15 @@ function list_core_update( $update ) { echo '
'; wp_nonce_field('upgrade-core'); echo '

'; - echo ' '; - echo ''; - echo ''; - echo '' . $download . ' '; + echo ' '; + echo ''; + echo ''; + echo '' . $download . ' '; if ( 'en_US' != $update->locale ) if ( !isset( $update->dismissed ) || !$update->dismissed ) - echo ''; + echo ''; else - echo ''; + echo ''; echo '

'; echo '
'; diff --git a/wp-admin/upload.php b/wp-admin/upload.php index a5593d0c9..29c29ee07 100644 --- a/wp-admin/upload.php +++ b/wp-admin/upload.php @@ -211,7 +211,7 @@ unset($type_links); @@ -247,7 +247,7 @@ if ( $page_links ) : ?> - + yyear$arc_row->mmonth'>"; + echo ""; echo $wp_locale->get_month($arc_row->mmonth) . " $arc_row->yyear"; echo "\n"; } @@ -280,12 +280,12 @@ foreach ($arc_result as $arc_row) { - + - +
@@ -325,7 +325,7 @@ foreach ($arc_result as $arc_row) { $att_title = wp_specialchars( _draft_or_post_title($post->ID) ); ?> - + ID, array(80, 60), true ) ) { ?> @@ -403,7 +403,7 @@ if ( $page_links ) - +

diff --git a/wp-admin/user-edit.php b/wp-admin/user-edit.php index b9bad3335..524ba31e7 100644 --- a/wp-admin/user-edit.php +++ b/wp-admin/user-edit.php @@ -215,7 +215,7 @@ $current_color = get_user_option('admin_color', $user_id); if ( empty($current_color) ) $current_color = 'fresh'; foreach ( $_wp_admin_css_colors as $color => $color_info ): ?> -
/> +
/> colors as $html_color ): ?> @@ -248,7 +248,7 @@ do_action('personal_options', $profileuser);
- + @@ -274,17 +274,17 @@ else - + - + - + @@ -303,7 +303,7 @@ else $public_display = array_map( 'trim', $public_display ); foreach ( $public_display as $id => $item ) { ?> - + @@ -317,27 +317,27 @@ else
- + - + - + - + - +
@@ -395,8 +395,8 @@ if ( $show_password_fields ) :

- - + +

diff --git a/wp-admin/user-new.php b/wp-admin/user-new.php index fe563363a..c2b1e6317 100644 --- a/wp-admin/user-new.php +++ b/wp-admin/user-new.php @@ -91,23 +91,23 @@ foreach ( array('user_login' => 'login', 'first_name' => 'firstname', 'last_name - + - + - + - + - + @@ -132,7 +132,7 @@ foreach ( array('user_login' => 'login', 'first_name' => 'firstname', 'last_name

- +

diff --git a/wp-admin/users.php b/wp-admin/users.php index cf696645f..9cd069cf5 100644 --- a/wp-admin/users.php +++ b/wp-admin/users.php @@ -149,7 +149,7 @@ case 'delete': if ( $id == $current_user->ID ) { echo "
  • " . sprintf(__('ID #%1s: %2s The current user will not be deleted.'), $id, $user->user_login) . "
  • \n"; } else { - echo "
  • " . sprintf(__('ID #%1s: %2s'), $id, $user->user_login) . "
  • \n"; + echo "
  • " . sprintf(__('ID #%1s: %2s'), $id, $user->user_login) . "
  • \n"; $go_delete = true; } } @@ -157,7 +157,7 @@ case 'delete': $user_dropdown = ''; ?> @@ -170,7 +170,7 @@ case 'delete': '.__('Attribute all posts and links to:')." $user_dropdown"; ?> -

    +

    @@ -292,7 +292,7 @@ unset($role_links); @@ -308,9 +308,9 @@ unset($role_links); - + - +
    @@ -374,7 +374,7 @@ foreach ( $wp_user_search->get_results() as $userid ) { - +
    diff --git a/wp-admin/widgets.php b/wp-admin/widgets.php index 3d3501c2f..00ff9ada0 100644 --- a/wp-admin/widgets.php +++ b/wp-admin/widgets.php @@ -262,7 +262,7 @@ if ( isset($_GET['editwidget']) && $_GET['editwidget'] ) {
    $sbvalue ) { - echo "\t\t
    "; + echo "\t\t
    "; if ( 'wp_inactive_widgets' == $sbname ) { echo ' '; } else { @@ -292,12 +292,12 @@ if ( isset($_GET['editwidget']) && $_GET['editwidget'] ) { - + - - - - + + + +