wrap pretty much all freemarker variables (i.e the data) in encodeHTML(data..). this...
[mir.git] / templates-dist / admin / comment.template
1 <html>
2 <head>
3 <title>
4 ${lang("comment.htmltitle")}
5 </title>
6 <head>
7
8 <body bgcolor="#FFFFFF">
9 <include "admin/head.template">
10
11 <form method="post" action="${encodeHTML(config.actionRoot)}">
12         <input type="hidden" name="module" value="Comment">
13         <input type="hidden" name="where" value="${encodeHTML(data.where)}">
14         <input type="hidden" name="offset" value="${encodeHTML(data.offset)}">
15         <input type="hidden" name="order" value="${encodeHTML(data.order)}">
16         <input type="hidden" name="id" value="${encodeHTML(data.id)}">
17         <input type="hidden" name="date" value="${encodeHTML(data.date)}">
18         <input type="hidden" name="to_media" value="${encodeHTML(data.to_media)}">
19         <if new> <input type="hidden" name="do" value="insert">
20         <else>   <input type="hidden" name="do" value="update">
21         </if>
22
23         <table border="0">      
24
25         <tr> 
26     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
27          <B>${lang("comment.date")}:</B></font></td>
28     <td>${encodeHTML(data.date)}</td>
29         </tr>
30         
31         <tr> 
32     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
33          <B>${lang("comment.title")}:</B></font></td>
34     <td><input type="text" size="40" maxlength="255" name="title" value="${encodeHTML(data.title)}"></td>
35         </tr>
36
37         <tr> 
38     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
39          <B>${lang("comment.creator")}:</B></font></td>
40     <td><input type="text" size="40" maxlength="80" name="creator" value="${encodeHTML(data.creator)}"></td>
41         </tr>
42
43         <tr> 
44     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
45          <B>${lang("comment.url")}:</B></font></td>
46     <td><input type="text" size="40" maxlength="255" name="main_url" value="${encodeHTML(data.main_url)}"></td>
47         </tr>
48   
49         <tr> 
50     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
51          <B>${lang("comment.email")}:</B></font></td>
52     <td><input type="text" size="40" maxlength="80" name="email" value="${encodeHTML(data.email)}"></td>
53         </tr>
54   
55         <tr> 
56     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
57          <B>${lang("comment.phone")}:</B></font></td>
58     <td><input type="text" size="40" maxlength="80" name="phone" value="${encodeHTML(data.phone)}"></td>
59         </tr>
60   
61         <tr> 
62     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
63          <B>${lang("comment.address")}:</B></font></td>
64     <td><input type="text" size="40" maxlength="80" name="address" value="${encodeHTML(data.address)}"></td>
65         </tr>
66   
67         <tr> 
68     <td align="right" bgcolor="#006600"><font color="#ffffff" face="Verdana, Arial, Helvetica, sans-serif" size="-1">
69          <B>${lang("comment.text")}:</B></font></td>
70     <td><textarea cols="40" rows="10" name="description" wrap="virtual">${encodeHTML(data.description)}</textarea></td>
71         </tr>
72
73     <td colspan="2" align="right"> <font color="black">
74         ${lang("comment.published")} <input type="checkbox" name="is_published" value="1" <if data.is_published=="1"> checked</if>>
75         <if new> 
76       <input type="submit" name="save" value="${lang("insert")}">
77     <else> 
78     <input type="submit" name="save" value="${lang("save")}">
79     </if> </font></form></font>
80     </td>
81 </table>
82
83 <include "admin/foot.template">
84 </body>
85 </html>