Merge pull request #10956 from annando/escapetags
Some removed escapeTags calls
This commit is contained in:
commit
edcfeaf66d
16 changed files with 39 additions and 50 deletions
|
|
@ -366,7 +366,7 @@ class Item
|
|||
public static function guid($item, $notify)
|
||||
{
|
||||
if (!empty($item['guid'])) {
|
||||
return Strings::escapeTags(trim($item['guid']));
|
||||
return trim($item['guid']);
|
||||
}
|
||||
|
||||
if ($notify) {
|
||||
|
|
|
|||
|
|
@ -911,18 +911,18 @@ class User
|
|||
|
||||
$using_invites = DI::config()->get('system', 'invitation_only');
|
||||
|
||||
$invite_id = !empty($data['invite_id']) ? Strings::escapeTags(trim($data['invite_id'])) : '';
|
||||
$username = !empty($data['username']) ? Strings::escapeTags(trim($data['username'])) : '';
|
||||
$nickname = !empty($data['nickname']) ? Strings::escapeTags(trim($data['nickname'])) : '';
|
||||
$email = !empty($data['email']) ? Strings::escapeTags(trim($data['email'])) : '';
|
||||
$openid_url = !empty($data['openid_url']) ? Strings::escapeTags(trim($data['openid_url'])) : '';
|
||||
$photo = !empty($data['photo']) ? Strings::escapeTags(trim($data['photo'])) : '';
|
||||
$password = !empty($data['password']) ? trim($data['password']) : '';
|
||||
$password1 = !empty($data['password1']) ? trim($data['password1']) : '';
|
||||
$confirm = !empty($data['confirm']) ? trim($data['confirm']) : '';
|
||||
$invite_id = !empty($data['invite_id']) ? trim($data['invite_id']) : '';
|
||||
$username = !empty($data['username']) ? trim($data['username']) : '';
|
||||
$nickname = !empty($data['nickname']) ? trim($data['nickname']) : '';
|
||||
$email = !empty($data['email']) ? trim($data['email']) : '';
|
||||
$openid_url = !empty($data['openid_url']) ? trim($data['openid_url']) : '';
|
||||
$photo = !empty($data['photo']) ? trim($data['photo']) : '';
|
||||
$password = !empty($data['password']) ? trim($data['password']) : '';
|
||||
$password1 = !empty($data['password1']) ? trim($data['password1']) : '';
|
||||
$confirm = !empty($data['confirm']) ? trim($data['confirm']) : '';
|
||||
$blocked = !empty($data['blocked']);
|
||||
$verified = !empty($data['verified']);
|
||||
$language = !empty($data['language']) ? Strings::escapeTags(trim($data['language'])) : 'en';
|
||||
$language = !empty($data['language']) ? trim($data['language']) : 'en';
|
||||
|
||||
$netpublish = $publish = !empty($data['profile_publish_reg']);
|
||||
|
||||
|
|
|
|||
|
|
@ -40,7 +40,7 @@ class Delete extends BaseAdmin
|
|||
self::checkFormSecurityTokenRedirectOnError('/admin/item/delete', 'admin_deleteitem');
|
||||
|
||||
if (!empty($_POST['page_deleteitem_submit'])) {
|
||||
$guid = trim(Strings::escapeTags($_POST['deleteitemguid']));
|
||||
$guid = trim($_POST['deleteitemguid']);
|
||||
// The GUID should not include a "/", so if there is one, we got an URL
|
||||
// and the last part of it is most likely the GUID.
|
||||
if (strpos($guid, '/')) {
|
||||
|
|
|
|||
|
|
@ -39,7 +39,7 @@ class Settings extends BaseAdmin
|
|||
|
||||
self::checkFormSecurityTokenRedirectOnError('/admin/logs', 'admin_logs');
|
||||
|
||||
$logfile = (!empty($_POST['logfile']) ? Strings::escapeTags(trim($_POST['logfile'])) : '');
|
||||
$logfile = (!empty($_POST['logfile']) ? trim($_POST['logfile']) : '');
|
||||
$debugging = !empty($_POST['debugging']);
|
||||
$loglevel = ($_POST['loglevel'] ?? '') ?: LogLevel::ERROR;
|
||||
|
||||
|
|
|
|||
|
|
@ -37,7 +37,7 @@ class Storage extends BaseAdmin
|
|||
|
||||
self::checkFormSecurityTokenRedirectOnError('/admin/storage', 'admin_storage');
|
||||
|
||||
$storagebackend = Strings::escapeTags(trim($parameters['name'] ?? ''));
|
||||
$storagebackend = trim($parameters['name'] ?? '');
|
||||
|
||||
try {
|
||||
/** @var ICanConfigureStorage|false $newStorageConfig */
|
||||
|
|
|
|||
|
|
@ -302,7 +302,7 @@ class Register extends BaseModule
|
|||
|
||||
$using_invites = DI::config()->get('system', 'invitation_only');
|
||||
$num_invites = DI::config()->get('system', 'number_invites');
|
||||
$invite_id = (!empty($_POST['invite_id']) ? Strings::escapeTags(trim($_POST['invite_id'])) : '');
|
||||
$invite_id = (!empty($_POST['invite_id']) ? trim($_POST['invite_id']) : '');
|
||||
|
||||
if (intval(DI::config()->get('config', 'register_policy')) === self::OPEN) {
|
||||
if ($using_invites && $invite_id) {
|
||||
|
|
|
|||
|
|
@ -30,7 +30,6 @@ use Friendica\Model\Photo;
|
|||
use Friendica\Model\User;
|
||||
use Friendica\Protocol\ActivityNamespace;
|
||||
use Friendica\Protocol\Salmon;
|
||||
use Friendica\Util\Strings;
|
||||
|
||||
/**
|
||||
* Prints responses to /.well-known/webfinger or /xrd requests
|
||||
|
|
@ -45,7 +44,7 @@ class Xrd extends BaseModule
|
|||
return;
|
||||
}
|
||||
|
||||
$uri = urldecode(Strings::escapeTags(trim($_GET['uri'])));
|
||||
$uri = urldecode(trim($_GET['uri']));
|
||||
if (strpos($_SERVER['HTTP_ACCEPT'] ?? '', 'application/jrd+json') !== false) {
|
||||
$mode = 'json';
|
||||
} else {
|
||||
|
|
@ -56,7 +55,7 @@ class Xrd extends BaseModule
|
|||
return;
|
||||
}
|
||||
|
||||
$uri = urldecode(Strings::escapeTags(trim($_GET['resource'])));
|
||||
$uri = urldecode(trim($_GET['resource']));
|
||||
if (strpos($_SERVER['HTTP_ACCEPT'] ?? '', 'application/xrd+xml') !== false) {
|
||||
$mode = 'xml';
|
||||
} else {
|
||||
|
|
|
|||
|
|
@ -1996,8 +1996,6 @@ class Probe
|
|||
$data["name"] .= $perspart->text;
|
||||
}
|
||||
}
|
||||
|
||||
$data["name"] = Strings::escapeTags($data["name"]);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -37,7 +37,6 @@ use Friendica\Network\HTTPException;
|
|||
use Friendica\Security\TwoFactor\Repository\TrustedBrowser;
|
||||
use Friendica\Util\DateTimeFormat;
|
||||
use Friendica\Util\Network;
|
||||
use Friendica\Util\Strings;
|
||||
use LightOpenID;
|
||||
use Friendica\Core\L10n;
|
||||
use Psr\Log\LoggerInterface;
|
||||
|
|
@ -247,7 +246,7 @@ class Authentication
|
|||
['uid' => User::getIdFromPasswordAuthentication($username, $password)]
|
||||
);
|
||||
} catch (Exception $e) {
|
||||
$this->logger->warning('authenticate: failed login attempt', ['action' => 'login', 'username' => Strings::escapeTags($username), 'ip' => $_SERVER['REMOTE_ADDR']]);
|
||||
$this->logger->warning('authenticate: failed login attempt', ['action' => 'login', 'username' => $username, 'ip' => $_SERVER['REMOTE_ADDR']]);
|
||||
notice($this->l10n->t('Login failed. Please check your credentials.'));
|
||||
$this->baseUrl->redirect();
|
||||
}
|
||||
|
|
|
|||
|
|
@ -102,7 +102,7 @@ class OnePoll
|
|||
|
||||
if ($success) {
|
||||
self::updateContact($contact, ['failed' => false, 'last-update' => $updated, 'success_update' => $updated]);
|
||||
Contact::unmarkForArchival($contact);
|
||||
Contact::unmarkForArchival($contact);
|
||||
} else {
|
||||
self::updateContact($contact, ['failed' => true, 'last-update' => $updated, 'failure_update' => $updated]);
|
||||
Contact::markForArchival($contact);
|
||||
|
|
@ -317,7 +317,7 @@ class OnePoll
|
|||
$datarray['title'] .= $subpart->text;
|
||||
}
|
||||
}
|
||||
$datarray['title'] = Strings::escapeTags(trim($datarray['title']));
|
||||
$datarray['title'] = trim($datarray['title']);
|
||||
|
||||
//$datarray['title'] = Strings::escapeTags(trim($meta->subject));
|
||||
$datarray['created'] = DateTimeFormat::utc($meta->date);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue