diff options
author | Carles Bellver <carles.bellver@gmail.com> | 2005-08-27 13:35:36 +0200 |
---|---|---|
committer | Carles Bellver <carles.bellver@gmail.com> | 2005-08-27 13:35:36 +0200 |
commit | 1917aabc92099ce07db1c89ec4c63c31e07df7c6 (patch) | |
tree | b430762dc01460c55c2adf5f2a67f3116281d599 | |
parent | 5011da9d506a2907a8681b32b8649e6a20cfacdb (diff) | |
download | rpg-1917aabc92099ce07db1c89ec4c63c31e07df7c6.tar.gz rpg-1917aabc92099ce07db1c89ec4c63c31e07df7c6.tar.bz2 |
addslashes for JavScript language strings
If you use a single quote (escaped with a slash, of
course) in strings 'notsavedyet' or 'qb_alert', then
the edit toolbar doesn't show in your edit pages.
This is caused by the way these strings are inserted
in javascript code in inc/template.php. This patch
fixes it.
darcs-hash:20050827113536-cc4ee-02805ca80c3cc3fedac65e908dae71af92f412f7.gz
-rw-r--r-- | inc/template.php | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/inc/template.php b/inc/template.php index b033a82e0..4ce5041e9 100644 --- a/inc/template.php +++ b/inc/template.php @@ -204,8 +204,8 @@ function tpl_metaheaders(){ // include some JavaScript language strings ptln('<script language="javascript" type="text/javascript" charset="utf-8">',$it); - ptln(" var alertText = '".$lang['qb_alert']."'",$it); - ptln(" var notSavedYet = '".$lang['notsavedyet']."'",$it); + ptln(" var alertText = '".addslashes($lang['qb_alert'])."'",$it); + ptln(" var notSavedYet = '".addslashes($lang['notsavedyet'])."'",$it); ptln(" var DOKU_BASE = '".DOKU_BASE."'",$it); ptln('</script>',$it); |