Ignore:
Timestamp:
2011/03/20 14:45:13 (13 years ago)
Author:
kotani
Message:

#862 (テンプレート上のエスケープを簡単に)実装漏れ箇所

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/version-2_5-dev/data/Smarty/templates/admin/design/css.tpl

    r20645 r20741  
    2525<input type="hidden" name="<!--{$smarty.const.TRANSACTION_ID_NAME}-->" value="<!--{$transactionid}-->" /> 
    2626<input type="hidden" name="mode" value="" /> 
    27 <input type="hidden" name="area_row" value="<!--{$area_row}-->" /> 
    28 <input type="hidden" name="old_css_name" value="<!--{$old_css_name}-->" /> 
     27<input type="hidden" name="area_row" value="<!--{$area_row|h}-->" /> 
     28<input type="hidden" name="old_css_name" value="<!--{$old_css_name|h}-->" /> 
    2929<input type="hidden" name="device_type_id" value="<!--{$device_type_id|h}-->" /> 
    3030<div id="design" class="contents-main"> 
     
    3636            <td> 
    3737                <!--{if $arrErr.css_name != ""}--><span class="attention"><!--{$arrErr.css_name}--></span><br /><!--{/if}--> 
    38                 <input type="text" name="css_name" value="<!--{$css_name}-->" maxlength="<!--{$smarty.const.STEXT_LEN}-->" style="<!--{if $arrErr.css_name != ""}-->background-color: <!--{$smarty.const.ERR_COLOR}-->;<!--{/if}-->" size="60" class="box60" />.css<span class="attention"> (上限<!--{$smarty.const.STEXT_LEN}-->文字)</span> 
     38                <input type="text" name="css_name" value="<!--{$css_name|h}-->" maxlength="<!--{$smarty.const.STEXT_LEN}-->" style="<!--{if $arrErr.css_name != ""}-->background-color: <!--{$smarty.const.ERR_COLOR}-->;<!--{/if}-->" size="60" class="box60" />.css<span class="attention"> (上限<!--{$smarty.const.STEXT_LEN}-->文字)</span> 
    3939            </td> 
    4040        </tr> 
     
    6060    <h2>編集可能CSSファイル</h2> 
    6161    <div class="btn addnew"> 
    62         <a class="btn-normal" href="?" onclick="fnFormModeSubmit('form_css','','',''); return false;"><span>CSSを新規入力</span></a> 
     62        <a class="btn-normal" href="?device_type_id=<!--{$device_type_id|h}-->"><span>CSSを新規入力</span></a> 
    6363    </div> 
    6464    <table class="list" id="design-css-list"> 
     
    7171        <!--{foreach key=key item=item from=$arrCSSList}--> 
    7272        <tr> 
    73             <td style="background:<!--{if $item.css_name == $css_name}--><!--{$smarty.const.SELECT_RGB}--><!--{else}-->#ffffff<!--{/if}-->;"><!--{$item.file_name}--></td> 
     73            <td style="background:<!--{if $item.css_name == $css_name}--><!--{$smarty.const.SELECT_RGB}--><!--{else}-->#ffffff<!--{/if}-->;"><!--{$item.file_name|h}--></td> 
    7474            <td class="center" style="background:<!--{if $item.css_name == $css_name}--><!--{$smarty.const.SELECT_RGB}--><!--{else}-->#ffffff<!--{/if}-->;"> 
    75                 <a href="?css_name=<!--{$item.css_name}-->&amp;device_type_id=<!--{$device_type_id}-->">編集</a> 
     75                <a href="?css_name=<!--{$item.css_name|h}-->&amp;device_type_id=<!--{$device_type_id|h}-->">編集</a> 
    7676            </td> 
    7777            <td class="center" style="background:<!--{if $item.css_name == $css_name}--><!--{$smarty.const.SELECT_RGB}--><!--{else}-->#ffffff<!--{/if}-->;"> 
    78                 <a href="javascript:;" onclick="fnFormModeSubmit('form_css','delete','css_name','<!--{$item.css_name}-->'); return false;">削除</a> 
     78                <a href="javascript:;" onclick="fnFormModeSubmit('form_css','delete','css_name','<!--{$item.css_name|h}-->'); return false;">削除</a> 
    7979            </td> 
    8080        </tr> 
Note: See TracChangeset for help on using the changeset viewer.