Kill a <font> tag, add html paranoia
authorBrion Vibber <brion@users.mediawiki.org>
Fri, 11 Feb 2005 07:16:36 +0000 (07:16 +0000)
committerBrion Vibber <brion@users.mediawiki.org>
Fri, 11 Feb 2005 07:16:36 +0000 (07:16 +0000)
includes/SpecialLockdb.php

index 1635aa4..db07f45 100644 (file)
@@ -46,11 +46,11 @@ class DBLockForm {
 
                if ( "" != $err ) {
                        $wgOut->setSubtitle( wfMsg( "formerror" ) );
-                       $wgOut->addHTML( "<p><font color='red' size='+1'>{$err}</font>\n" );
+                       $wgOut->addHTML( '<p class="error">' . htmlspecialchars( $err ) . "</p>\n" );
                }
-               $lc = wfMsg( "lockconfirm" );
-               $lb = wfMsg( "lockbtn" );
-               $elr = wfMsg( "enterlockreason" );
+               $lc = htmlspecialchars( wfMsg( "lockconfirm" ) );
+               $lb = htmlspecialchars( wfMsg( "lockbtn" ) );
+               $elr = htmlspecialchars( wfMsg( "enterlockreason" ) );
                $titleObj = Title::makeTitle( NS_SPECIAL, "Lockdb" );
                $action = $titleObj->escapeLocalURL( "action=submit" );