[Fusionforge-commits] r7786 - branches/Branch_4_7/gforge/www/docman

Roland Mas lolando at libremir.placard.fr.eu.org
Wed Jun 10 10:36:25 CEST 2009


Author: lolando
Date: 2009-06-10 10:36:25 +0200 (Wed, 10 Jun 2009)
New Revision: 7786

Modified:
   branches/Branch_4_7/gforge/www/docman/index.php
Log:
Backported from 4.8: fixed filename escaping for docman

Modified: branches/Branch_4_7/gforge/www/docman/index.php
===================================================================
--- branches/Branch_4_7/gforge/www/docman/index.php	2009-06-10 08:33:47 UTC (rev 7785)
+++ branches/Branch_4_7/gforge/www/docman/index.php	2009-06-10 08:36:25 UTC (rev 7786)
@@ -36,8 +36,8 @@
 			if (isset($nested_docs[$dg->getID()]) && is_array($nested_docs[$dg->getID()])) {
 				foreach ($nested_docs[$dg->getID()] as $d) {
 					$docurl=util_make_url ('/docman/view.php/'.$group_id.'/'.$d->getID().'/'.urlencode($d->getFileName()));
-					$docname=htmlspecialchars($d->getName(), ENT_QUOTES)." (".htmlspecialchars($d->getFileName(), ENT_QUOTES).")";
-					$docdesc=htmlspecialchars($d->getDescription(), ENT_QUOTES);
+					$docname=addslashes($d->getName(), ENT_QUOTES)." (".htmlspecialchars($d->getFileName(), ENT_QUOTES).")";
+					$docdesc=addslashes($d->getDescription());
 					echo ",['','".$docname."','".$docurl."','','".$docdesc."' ]";
 				}
 			}




More information about the Fusionforge-commits mailing list