[-] FO: Fix #PSCFV-5061
git-svn-id: http://dev.prestashop.com/svn/v1/branches/1.5.x@17924 b9a71923-0436-4b27-9f14-aed3839534dd
This commit is contained in:
@@ -152,7 +152,7 @@
|
|||||||
</dl>
|
</dl>
|
||||||
<dl>
|
<dl>
|
||||||
<dt>{l s='Message:'}</dt>
|
<dt>{l s='Message:'}</dt>
|
||||||
<dd>{$message.message|nl2br}</dd>
|
<dd>{$message.message|escape:'htmlall':'UTF-8'|nl2br}</dd>
|
||||||
</dl>
|
</dl>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
|||||||
@@ -51,13 +51,13 @@ class OrderDetailControllerCore extends FrontController
|
|||||||
if (Tools::isSubmit('submitMessage'))
|
if (Tools::isSubmit('submitMessage'))
|
||||||
{
|
{
|
||||||
$idOrder = (int)(Tools::getValue('id_order'));
|
$idOrder = (int)(Tools::getValue('id_order'));
|
||||||
$msgText = htmlentities(Tools::getValue('msgText'), ENT_COMPAT, 'UTF-8');
|
$msgText = Tools::getValue('msgText');
|
||||||
|
|
||||||
if (!$idOrder || !Validate::isUnsignedId($idOrder))
|
if (!$idOrder || !Validate::isUnsignedId($idOrder))
|
||||||
$this->errors[] = Tools::displayError('Order is no longer valid');
|
$this->errors[] = Tools::displayError('Order is no longer valid');
|
||||||
else if (empty($msgText))
|
elseif (empty($msgText))
|
||||||
$this->errors[] = Tools::displayError('Message cannot be blank');
|
$this->errors[] = Tools::displayError('Message cannot be blank');
|
||||||
else if (!Validate::isMessage($msgText))
|
elseif (!Validate::isMessage($msgText))
|
||||||
$this->errors[] = Tools::displayError('Message is invalid (HTML is not allowed)');
|
$this->errors[] = Tools::displayError('Message is invalid (HTML is not allowed)');
|
||||||
if (!count($this->errors))
|
if (!count($this->errors))
|
||||||
{
|
{
|
||||||
@@ -86,7 +86,7 @@ class OrderDetailControllerCore extends FrontController
|
|||||||
else
|
else
|
||||||
$ct = new CustomerThread((int)$id_customer_thread);
|
$ct = new CustomerThread((int)$id_customer_thread);
|
||||||
$cm->id_customer_thread = $ct->id;
|
$cm->id_customer_thread = $ct->id;
|
||||||
$cm->message = Tools::htmlentitiesutf8($msgText);
|
$cm->message = $msgText;
|
||||||
$cm->ip_address = ip2long($_SERVER['REMOTE_ADDR']);
|
$cm->ip_address = ip2long($_SERVER['REMOTE_ADDR']);
|
||||||
$cm->add();
|
$cm->add();
|
||||||
|
|
||||||
@@ -196,6 +196,7 @@ class OrderDetailControllerCore extends FrontController
|
|||||||
'customizedDatas' => $customizedDatas
|
'customizedDatas' => $customizedDatas
|
||||||
/* DEPRECATED: customizedDatas @since 1.5 */
|
/* DEPRECATED: customizedDatas @since 1.5 */
|
||||||
));
|
));
|
||||||
|
|
||||||
if ($carrier->url && $order->shipping_number)
|
if ($carrier->url && $order->shipping_number)
|
||||||
$this->context->smarty->assign('followup', str_replace('@', $order->shipping_number, $carrier->url));
|
$this->context->smarty->assign('followup', str_replace('@', $order->shipping_number, $carrier->url));
|
||||||
$this->context->smarty->assign('HOOK_ORDERDETAILDISPLAYED', Hook::exec('displayOrderDetail', array('order' => $order)));
|
$this->context->smarty->assign('HOOK_ORDERDETAILDISPLAYED', Hook::exec('displayOrderDetail', array('order' => $order)));
|
||||||
|
|||||||
@@ -381,7 +381,7 @@
|
|||||||
<br />
|
<br />
|
||||||
{dateFormat date=$message.date_add full=1}
|
{dateFormat date=$message.date_add full=1}
|
||||||
</td>
|
</td>
|
||||||
<td>{$message.message|nl2br}</td>
|
<td>{$message.message|escape:'htmlall':'UTF-8'|nl2br}</td>
|
||||||
</tr>
|
</tr>
|
||||||
{/foreach}
|
{/foreach}
|
||||||
</tbody>
|
</tbody>
|
||||||
|
|||||||
Reference in New Issue
Block a user