mirror of
https://github.com/e107inc/e107.git
synced 2025-08-01 20:30:39 +02:00
show_emessage("ALERT", …): JSON type enforcement for alert() usages
This commit is contained in:
@@ -1152,11 +1152,11 @@ $SYSTEM_DIRECTORY = "e107_system/";</pre>
|
||||
|
||||
case "ALERT":
|
||||
$message = isset($emessage[$message]) ? $emessage[$message] : $message;
|
||||
echo "<noscript>$message</noscript><script type='text/javascript'>alert(\"".$tp->toJS($message)."\"); window.history.go(-1); </script>\n"; exit;
|
||||
echo "<noscript>$message</noscript><script type='text/javascript'>alert(".json_encode($message)."); window.history.go(-1); </script>\n"; exit;
|
||||
break;
|
||||
|
||||
case "P_ALERT":
|
||||
echo "<script type='text/javascript'>alert(\"".$tp->toJS($message)."\"); </script>\n";
|
||||
echo "<script type='text/javascript'>alert(".json_encode($message)."); </script>\n";
|
||||
break;
|
||||
|
||||
case 'POPUP':
|
||||
|
Reference in New Issue
Block a user