// Fix some XSS

This commit is contained in:
tDidierjean
2011-12-14 18:34:59 +00:00
parent 00736049d4
commit b8a3ea0404
2 changed files with 5 additions and 10 deletions
+3 -8
View File
@@ -180,8 +180,8 @@ class HelperListCore extends Helper
$tpl_enable = $this->createTemplate('list_action_enable.tpl'); $tpl_enable = $this->createTemplate('list_action_enable.tpl');
$tpl_enable->assign(array( $tpl_enable->assign(array(
'enabled' => (bool)$value, 'enabled' => (bool)$value,
'url_enable' => $this->currentIndex.'&'.$this->identifier.'='.$id.'&'.$active.$this->table. 'url_enable' => $this->currentIndex.'&'.$this->identifier.'='.(int)$id.'&'.$active.$this->table.
((int)$id_category && (int)$id_product ? '&id_category='.$id_category : '').'&token='.($token != null ? $token : $this->token) ((int)$id_category && (int)$id_product ? '&id_category='.(int)$id_category : '').'&token='.($token != null ? $token : $this->token)
)); ));
return $tpl_enable->fetch(); return $tpl_enable->fetch();
} }
@@ -491,7 +491,7 @@ class HelperListCore extends Helper
*/ */
public function displayListHeader($token = null) public function displayListHeader($token = null)
{ {
$id_cat = Tools::getValue('id_'.($this->is_cms ? 'cms_' : '').'category'); $id_cat = (int)Tools::getValue('id_'.($this->is_cms ? 'cms_' : '').'category');
if (!isset($token) || empty($token)) if (!isset($token) || empty($token))
$token = $this->token; $token = $this->token;
@@ -621,8 +621,6 @@ class HelperListCore extends Helper
'table_dnd' => isset($table_dnd) ? $table_dnd : null, 'table_dnd' => isset($table_dnd) ? $table_dnd : null,
'name' => isset($name) ? $name : null, 'name' => isset($name) ? $name : null,
'name_id' => isset($name_id) ? $name_id : null, 'name_id' => isset($name_id) ? $name_id : null,
/*'back' => Tools::getValue('back'),
'no_back' => $this->no_back,*/
))); )));
return $this->header_tpl->fetch(); return $this->header_tpl->fetch();
@@ -637,10 +635,7 @@ class HelperListCore extends Helper
'token' => $this->token, 'token' => $this->token,
'table' => $this->table, 'table' => $this->table,
'current' => $this->currentIndex, 'current' => $this->currentIndex,
'simple_header' => $this->simple_header,
'bulk_actions' => $this->bulk_actions, 'bulk_actions' => $this->bulk_actions,
'back' => Tools::getValue('back'),
'no_back' => $this->no_back,
))); )));
return $this->footer_tpl->fetch(); return $this->footer_tpl->fetch();
} }
@@ -147,7 +147,7 @@ class AdminCategoriesControllerCore extends AdminController
if (Tools::getValue('id_category') && !Tools::isSubmit('updatecategory')) if (Tools::getValue('id_category') && !Tools::isSubmit('updatecategory'))
{ {
$this->toolbar_btn['edit'] = array( $this->toolbar_btn['edit'] = array(
'href' => self::$currentIndex.'&update'.$this->table.'&id_category='.Tools::getValue('id_category').'&token='.$this->token, 'href' => self::$currentIndex.'&update'.$this->table.'&id_category='.(int)Tools::getValue('id_category').'&token='.$this->token,
'desc' => $this->l('Edit') 'desc' => $this->l('Edit')
); );
$back = Tools::safeOutput(Tools::getValue('back', '')); $back = Tools::safeOutput(Tools::getValue('back', ''));
@@ -160,7 +160,7 @@ class AdminCategoriesControllerCore extends AdminController
} }
if ($this->display == 'view') if ($this->display == 'view')
$this->toolbar_btn['new'] = array( $this->toolbar_btn['new'] = array(
'href' => self::$currentIndex.'&add'.$this->table.'&id_parent='.Tools::getValue('id_category').'&token='.$this->token, 'href' => self::$currentIndex.'&add'.$this->table.'&id_parent='.(int)Tools::getValue('id_category').'&token='.$this->token,
'desc' => $this->l('Add new') 'desc' => $this->l('Add new')
); );
parent::initToolbar(); parent::initToolbar();