// Protected smarty variable in JS

This commit is contained in:
Damien Metzger
2013-06-27 16:41:38 +02:00
parent 374de1b6c8
commit 75cddbae99
5 changed files with 9 additions and 10 deletions
+1 -1
View File
@@ -29,7 +29,7 @@
{if $ajax_allowed}
<script type="text/javascript">
var CUSTOMIZE_TEXTFIELD = {$CUSTOMIZE_TEXTFIELD};
var img_dir = '{$img_dir}';
var img_dir = '{$img_dir|addslashes}';
</script>
{/if}
<script type="text/javascript">
@@ -23,7 +23,7 @@
if($(this).val().length > 0){
stopInstantSearchQueries();
instantSearchQuery = $.ajax({
url: '{if $search_ssl == 1}{$link->getPageLink('search', true)}{else}{$link->getPageLink('search')}{/if}',
url: '{if $search_ssl == 1}{$link->getPageLink('search', true)|addslashes}{else}{$link->getPageLink('search')|addslashes}{/if}',
data: {
instantSearch: 1,
id_lang: {$cookie->id_lang},
@@ -64,7 +64,7 @@
$('document').ready( function() {
$("#search_query_{$blocksearch_type}")
.autocomplete(
'{if $search_ssl == 1}{$link->getPageLink('search', true)}{else}{$link->getPageLink('search')}{/if}', {
'{if $search_ssl == 1}{$link->getPageLink('search', true)|addslashes}{else}{$link->getPageLink('search')|addslashes}{/if}', {
minChars: 3,
max: 10,
width: 500,
+1 -2
View File
@@ -35,7 +35,6 @@
{else}
<!-- Block search module TOP -->
<div id="search_block_top">
<form method="get" action="{$link->getPageLink('search')|escape:'html'}" id="searchbox">
<p>
<label for="search_query_top"><!-- image on background --></label>
@@ -44,7 +43,7 @@
<input type="hidden" name="orderway" value="desc" />
<input class="search_query" type="text" id="search_query_top" name="search_query" value="{if isset($smarty.get.search_query)}{$smarty.get.search_query|htmlentities:$ENT_QUOTES:'utf-8'|stripslashes}{/if}" />
<input type="submit" name="submit_search" value="{l s='Search' mod='blocksearch'}" class="button" />
</p>
</p>
</form>
</div>
{include file="$self/blocksearch-instantsearch.tpl"}
+4 -4
View File
@@ -43,10 +43,10 @@
<link rel="icon" type="image/vnd.microsoft.icon" href="{$favicon_url}?{$img_update_time}" />
<link rel="shortcut icon" type="image/x-icon" href="{$favicon_url}?{$img_update_time}" />
<script type="text/javascript">
var baseDir = '{$content_dir}';
var baseUri = '{$base_uri}';
var static_token = '{$static_token}';
var token = '{$token}';
var baseDir = '{$content_dir|addslashes}';
var baseUri = '{$base_uri|addslashes}';
var static_token = '{$static_token|addslashes}';
var token = '{$token|addslashes}';
var priceDisplayPrecision = {$priceDisplayPrecision*$currency->decimals};
var priceDisplayMethod = {$priceDisplay};
var roundMode = {$roundMode};
@@ -29,7 +29,7 @@
{if $ajax_allowed}
<script type="text/javascript">
var CUSTOMIZE_TEXTFIELD = {$CUSTOMIZE_TEXTFIELD};
var img_dir = '{$img_dir}';
var img_dir = '{$img_dir|addslashes}';
</script>
{/if}
<script type="text/javascript">