Re: cvs: pear /Structures_DataGrid/DataGrid/Renderer HTMLTable.php
| From: | Justin Patrin | Date: | Sat, 12 Mar 2005 03:41:24 +0000 |
| Subject: | Re: cvs: pear /Structures_DataGrid/DataGrid/Renderer HTMLTable.php | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-36660@lists.php.net to get a copy of this message | ||
On Fri, 11 Mar 2005 23:11:06 -0000, Andrew Nagy <asnagy@php.net> wrote:
> asnagy Fri Mar 11 18:11:06 2005 EDT
>
> Modified files:
> /pear/Structures_DataGrid/DataGrid/Renderer HTMLTable.php
> Log:
> Added htmlentities and stripslashes to content to ensure clean printing
>
>
> http://cvs.php.net/diff.php/pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php?r1=1.42&r2=1.43&ty=u
> Index: pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php
> diff -u pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.42
> pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.43
> --- pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.42 Fri Mar 11 18:08:00
> 2005
> +++ pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php Fri Mar 11 18:11:05 2005
> @@ -16,14 +16,14 @@
> // | Author: Andrew Nagy <asnagy@webitecture.org> |
> // +----------------------------------------------------------------------+
> //
> -// $Id: HTMLTable.php,v 1.42 2005/03/11 23:08:00 asnagy Exp $
> +// $Id: HTMLTable.php,v 1.43 2005/03/11 23:11:05 asnagy Exp $
>
> require_once 'HTML/Table.php';
>
> /**
> * Structures_DataGrid_Renderer_HTMLTable Class
> *
> - * @version $Revision: 1.42 $
> + * @version $Revision: 1.43 $
> * @author Andrew S. Nagy <asnagy@webitecture.org>
> * @access public
> * @package Structures_DataGrid
> @@ -435,7 +435,7 @@
> }
> } else {
> // Use Record Data
> - $content = $row[$column->fieldName];
> + $content =
> htmlentities(stripslashes($row[$column->fieldName]));
Htmlentities is ok, although it means you have to use a formatter to
put HTML in the content. Or will this affect renderers as well? If it
will, this should be removed.
And again, *please* remove the stripslashes. This is not appropriate.
If slashes need to be stripped, this is the responsibility of the
coder using DataGrid. If I put \" in a DB, I want it that way and I
want it to display that way. If there are extra slashes in your DB
data, you need to look at your entry code, not hack the output code.
I'm sure you've seen this before, but for the benefit of anyone else reading:
http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id178071
>
> if (($content == '') &&
> ($column->autoFillValue != '')) {
> @@ -527,4 +527,4 @@
>
> }
>
> -?>
> \ No newline at end of file
> +?>
>
--
Justin Patrin