wrap pretty much all freemarker variables (i.e the data) in encodeHTML(data..). this...
[mir.git] / templates-dist / admin / breaking.template
1 <html>
2 <head>
3 <title>
4 ${lang("breaking.htmltitle")}
5 </title>
6 <head>
7
8 <body bgcolor="#FFFFFF">
9 <include "admin/head.template">
10 <form action="${encodeHTML(config.actionRoot)}" method="post">
11         <input type="hidden" name="module" value="Breaking">
12         <input type="hidden" name="id" value="${encodeHTML(data.id)}">
13         <if data.new><input type="hidden" name="do" value="insert">
14         <else><input type="hidden" name="do" value="update"></if>
15 <table border="0">
16   <tr>
17     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
18         <B>${lang("breaking.date")}:</B></font></td>
19     <td>
20       ${encodeHTML(data.webdb_create_formatted)}
21     </td>
22   </tr>
23
24   <tr> 
25     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
26         <B>${lang("breaking.text")}:</B> ${lang("breaking.textinfo")}</font></td>
27     <td>
28          <textarea cols="50" rows="3" name="text" wrap=virtual>${encodeHTML(data.text)}</textarea>
29     </td>
30   </tr>
31
32   <tr>
33     <td colspan="2" align="right"> <font color="#ffffff"><if data.new>
34       <input type="submit" name="save" value="${lang("insert")}">
35     <else>
36     <input type="submit" name="save" value="${lang("save")}">
37     </if> </font></form></font>
38     </td>
39 </table>
40 <include "admin/foot.template">
41 </body>
42 </html>