The default form action (request_uri) didn't escape HTML entities (such as &)
parent
f1f458ddf0
commit
7cd6e0b17d
|
@ -567,7 +567,7 @@ function format_tag($link, $text) {
|
||||||
}
|
}
|
||||||
|
|
||||||
function form($form, $method = "post", $action = 0, $options = 0) {
|
function form($form, $method = "post", $action = 0, $options = 0) {
|
||||||
return "<form action=\"". ($action ? $action : request_uri()) ."\" method=\"$method\"". ($options ? " $options" : "") .">\n$form</form>\n";
|
return "<form action=\"". ($action ? $action : htmlentities(request_uri())) ."\" method=\"$method\"". ($options ? " $options" : "") .">\n$form</form>\n";
|
||||||
}
|
}
|
||||||
|
|
||||||
function form_item($title, $value, $description = 0) {
|
function form_item($title, $value, $description = 0) {
|
||||||
|
|
Loading…
Reference in New Issue