summaryrefslogtreecommitdiff
path: root/modules/gallery/controllers/admin_theme_options.php
diff options
context:
space:
mode:
authorShad Laws <shad@shadlaws.com>2013-09-06 00:12:43 -0700
committerShad Laws <shad@shadlaws.com>2013-09-06 00:12:43 -0700
commit277cd9a98bfc47a95d221eecc6325c8ba7ab24b9 (patch)
tree95f925b01d7038736146b2212a13cebc654ec579 /modules/gallery/controllers/admin_theme_options.php
parent04953a4f5e863d15967414faf2caec7a8003ee86 (diff)
parent57d12c69a87bbc2057f5f513f425e8b0d6588b87 (diff)
Merge pull request #463 from shadlaws/fix_20130906_master
Fix 20130906 master
Diffstat (limited to 'modules/gallery/controllers/admin_theme_options.php')
-rw-r--r--modules/gallery/controllers/admin_theme_options.php14
1 files changed, 10 insertions, 4 deletions
diff --git a/modules/gallery/controllers/admin_theme_options.php b/modules/gallery/controllers/admin_theme_options.php
index 38d2b0a8..3258040c 100644
--- a/modules/gallery/controllers/admin_theme_options.php
+++ b/modules/gallery/controllers/admin_theme_options.php
@@ -53,11 +53,17 @@ class Admin_Theme_Options_Controller extends Admin_Controller {
module::set_var("gallery", "resize_size", $resize_size);
}
- module::set_var("gallery", "header_text", $form->edit_theme->header_text->value);
- module::set_var("gallery", "footer_text", $form->edit_theme->footer_text->value);
module::set_var("gallery", "show_credits", $form->edit_theme->show_credits->value);
- module::set_var("gallery", "favicon_url", $form->edit_theme->favicon_url->value);
- module::set_var("gallery", "apple_touch_icon_url", $form->edit_theme->apple_touch_icon_url->value);
+
+ // Sanitize values that get placed directly in HTML output by theme.
+ module::set_var("gallery", "header_text",
+ html::purify($form->edit_theme->header_text->value));
+ module::set_var("gallery", "footer_text",
+ html::purify($form->edit_theme->footer_text->value));
+ module::set_var("gallery", "favicon_url",
+ html::purify($form->edit_theme->favicon_url->value));
+ module::set_var("gallery", "apple_touch_icon_url",
+ html::purify($form->edit_theme->apple_touch_icon_url->value));
module::event("theme_edit_form_completed", $form);