summaryrefslogtreecommitdiff
path: root/themes
diff options
context:
space:
mode:
authorTim Almdal <tnalmdal@shaw.ca>2009-07-04 08:17:12 -0700
committerTim Almdal <tnalmdal@shaw.ca>2009-07-04 08:17:12 -0700
commitd6648c0affd122407b7567442aa924e9138104e7 (patch)
tree015f10205d96618edcf210ad93c672a74956d979 /themes
parent54ffea24196e8f5d88cf9d8607455f0f6aab305c (diff)
Fix for ticket #477. Use nl2br method when rendering comment::text and
item::description. In addition add p::clean or p::purify to places that xss cleaning had missed (i.e. rss feeds)
Diffstat (limited to 'themes')
-rw-r--r--themes/default/views/album.html.php2
-rw-r--r--themes/default/views/movie.html.php2
-rw-r--r--themes/default/views/photo.html.php2
3 files changed, 3 insertions, 3 deletions
diff --git a/themes/default/views/album.html.php b/themes/default/views/album.html.php
index 273b8a4e..65ea3381 100644
--- a/themes/default/views/album.html.php
+++ b/themes/default/views/album.html.php
@@ -3,7 +3,7 @@
<div id="gInfo">
<?= $theme->album_top() ?>
<h1><?= p::purify($item->title) ?></h1>
- <div class="gDescription"><?= p::purify($item->description) ?></div>
+ <div class="gDescription"><?= nl2br(p::purify($item->description)) ?></div>
</div>
<ul id="gAlbumGrid">
diff --git a/themes/default/views/movie.html.php b/themes/default/views/movie.html.php
index 2cd9806f..66c80ded 100644
--- a/themes/default/views/movie.html.php
+++ b/themes/default/views/movie.html.php
@@ -16,7 +16,7 @@
<div id="gInfo">
<h1><?= p::purify($item->title) ?></h1>
- <div><?= p::purify($item->description) ?></div>
+ <div><?= nl2br(p::purify($item->description)) ?></div>
</div>
<script type="text/javascript">
diff --git a/themes/default/views/photo.html.php b/themes/default/views/photo.html.php
index dc3a9dfd..bf4d9da3 100644
--- a/themes/default/views/photo.html.php
+++ b/themes/default/views/photo.html.php
@@ -51,7 +51,7 @@
<div id="gInfo">
<h1><?= p::purify($item->title) ?></h1>
- <div><?= p::purify($item->description) ?></div>
+ <div><?= nl2br(p::purify($item->description)) ?></div>
</div>
<script type="text/javascript">