cvs: pear /Pager Common.php package.xml

From: Date: Tue, 17 Aug 2004 14:45:57 +0000
Subject: cvs: pear /Pager Common.php package.xml
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-23009@lists.php.net to get a copy of this message
quipo Tue Aug 17 10:45:57 2004 EDT Modified files: /pear/Pager Common.php package.xml Log: prevent XSS attaks http://cvs.php.net/diff.php/pear/Pager/Common.php?r1=1.17&r2=1.18&ty=u Index: pear/Pager/Common.php diff -u pear/Pager/Common.php:1.17 pear/Pager/Common.php:1.18 --- pear/Pager/Common.php:1.17 Tue Aug 17 09:09:57 2004 +++ pear/Pager/Common.php Tue Aug 17 10:45:57 2004 @@ -33,7 +33,7 @@ // | Lorenzo Alberton <l.alberton at quipo.it> | // +-----------------------------------------------------------------------+ // -// $Id: Common.php,v 1.17 2004/08/17 13:09:57 quipo Exp $ +// $Id: Common.php,v 1.18 2004/08/17 14:45:57 quipo Exp $ /** * File Common.php @@ -60,7 +60,7 @@ * * @author Richard Heyes <richard@phpguru.org>, * @author Lorenzo Alberton <l.alberton at quipo.it> - * @version $Id: Common.php,v 1.17 2004/08/17 13:09:57 quipo Exp $ + * @version $Id: Common.php,v 1.18 2004/08/17 14:45:57 quipo Exp $ * @package Pager */ class Pager_Common @@ -485,19 +485,19 @@ * * @return mixed Next page ID */ - function getNextPageID() - { - return ($this->getCurrentPageID() == $this->numPages() ? false : $this->getCurrentPageID() + 1); - } + function getNextPageID() + { + return ($this->getCurrentPageID() == $this->numPages() ? false : $this->getCurrentPageID() + 1); + } - // }}} + // }}} // {{{ getPreviousPageID() /** * Returns previous page ID. If current page is first page - * this function returns FALSE - * - * @return mixed Previous pages' ID + * this function returns FALSE + * + * @return mixed Previous pages' ID */ function getPreviousPageID() { @@ -645,6 +645,7 @@ $querystring[] = $name . '=' . $value; } $querystring = array_merge($querystring, array_unique($arrays)); + $querystring = array_map('htmlspecialchars', $querystring); return '?' . implode('&amp;', $querystring) . (!empty($querystring) ? '&amp;' : '') . $this->_urlVar .'='; } http://cvs.php.net/diff.php/pear/Pager/package.xml?r1=1.27&r2=1.28&ty=u Index: pear/Pager/package.xml diff -u pear/Pager/package.xml:1.27 pear/Pager/package.xml:1.28 --- pear/Pager/package.xml:1.27 Sun Jul 18 03:39:19 2004 +++ pear/Pager/package.xml Tue Aug 17 10:45:57 2004 @@ -25,7 +25,7 @@ <release> <version>2.2.3</version> - <date>2004-07-18</date> + <date>2004-08-17</date> <state>stable</state> <notes> <![CDATA[ @@ -35,6 +35,7 @@ "attribute" parameter to allow extra attributes for the select tag. - added an example to show how this class can be used with big database resultsets efficiently. +- prevent XSS attacks (bug #2131), thanks to sou_sk at nifty dot com ]]> </notes> @@ -77,13 +78,17 @@ <changelog> <release> <version>2.2.3</version> - <date>2004-07-18</date> + <date>2004-08-17</date> <state>stable</state> <notes> <![CDATA[ -- array values given as GET parameters were not carried on (bug #1904) +- just the last one of a set of array values given as GET parameters + (i.e. site.php?foo[]=1&foo[]=2&foo[]=3) was carried on (bug #1904). - make 4th parameter of getPerPageSelectBox() an array, and add an - "attribute" parameter to allow extra attributes for the select tag + "attribute" parameter to allow extra attributes for the select tag. +- added an example to show how this class can be used with big database + resultsets efficiently. +- prevent XSS attacks (bug #2131), thanks to sou_sk at nifty dot com ]]> </notes> </release> @@ -99,7 +104,7 @@ * $showAllData (if true, an <option> to show all the data is displayed in the generated <select>); * $optionText (text to show in each <option>; use '%d' where you want to see - the number of pages selected) + the number of pages selected) - added showAllText option for alternate text in the $showAllData <option> (the default is the number of total items). - fixed getPageData() when $pageID is specified (bug #1377) (thanks to Ian Eure)

« previous php.pear.cvs (#23009) next »