(bug 26603) returnto parameter in login link not escaped when viewed on Special:Userl...
authorRoan Kattouw <catrope@users.mediawiki.org>
Wed, 16 Feb 2011 11:28:58 +0000 (11:28 +0000)
committerRoan Kattouw <catrope@users.mediawiki.org>
Wed, 16 Feb 2011 11:28:58 +0000 (11:28 +0000)
includes/SkinTemplate.php

index d04a84c..2c5edf9 100644 (file)
@@ -570,7 +570,7 @@ class SkinTemplate extends Skin {
                $personal_urls = array();
                $page = $wgRequest->getVal( 'returnto', $this->thisurl );
                $query = $wgRequest->getVal( 'returntoquery', $this->thisquery );
-               $returnto = "returnto=$page";
+               $returnto = wfArrayToCGI( array( 'returnto' => $page ) );
                if( $this->thisquery != '' ) {
                        $returnto .= "&returntoquery=$query";
                }