]> scripts.mit.edu Git - autoinstalls/wordpress.git/blobdiff - wp-admin/press-this.php
Wordpress 2.9.2-scripts
[autoinstalls/wordpress.git] / wp-admin / press-this.php
index c6632b51952c56529521c22099020612847d4fbf..4eda788c5c710571b68735f0d4fd979688171e01 100644 (file)
@@ -42,38 +42,39 @@ function aposfix($text) {
 function press_it() {
        // define some basic variables
        $quick['post_status'] = 'draft'; // set as draft first
 function press_it() {
        // define some basic variables
        $quick['post_status'] = 'draft'; // set as draft first
-       $quick['post_category'] = isset($_REQUEST['post_category']) ? $_REQUEST['post_category'] : null;
-       $quick['tax_input'] = isset($_REQUEST['tax_input']) ? $_REQUEST['tax_input'] : '';
-       $quick['post_title'] = isset($_REQUEST['title']) ? $_REQUEST['title'] : '';
-       $quick['post_content'] = '';
+       $quick['post_category'] = isset($_POST['post_category']) ? $_POST['post_category'] : null;
+       $quick['tax_input'] = isset($_POST['tax_input']) ? $_POST['tax_input'] : null;
+       $quick['post_title'] = ( trim($_POST['title']) != '' ) ? $_POST['title'] : '  ';
+       $quick['post_content'] = isset($_POST['post_content']) ? $_POST['post_content'] : ''; 
 
        // insert the post with nothing in it, to get an ID
        $post_ID = wp_insert_post($quick, true);
 
        // insert the post with nothing in it, to get an ID
        $post_ID = wp_insert_post($quick, true);
-       $content = isset($_REQUEST['content']) ? $_REQUEST['content'] : '';
+       if ( is_wp_error($post_ID) )
+               wp_die($post_ID);
+
+       $content = isset($_POST['content']) ? $_POST['content'] : '';
 
        $upload = false;
 
        $upload = false;
-       if( !empty($_REQUEST['photo_src']) && current_user_can('upload_files') )
-               foreach( (array) $_REQUEST['photo_src'] as $key => $image)
+       if( !empty($_POST['photo_src']) && current_user_can('upload_files') ) {
+               foreach( (array) $_POST['photo_src'] as $key => $image) {
                        // see if files exist in content - we don't want to upload non-used selected files.
                        // see if files exist in content - we don't want to upload non-used selected files.
-                       if( strpos($_REQUEST['content'], $image) !== false ) {
-                               $desc = isset($_REQUEST['photo_description'][$key]) ? $_REQUEST['photo_description'][$key] : '';
+                       if ( strpos($_POST['content'], htmlspecialchars($image)) !== false ) {
+                               $desc = isset($_POST['photo_description'][$key]) ? $_POST['photo_description'][$key] : '';
                                $upload = media_sideload_image($image, $post_ID, $desc);
 
                                // Replace the POSTED content <img> with correct uploaded ones. Regex contains fix for Magic Quotes
                                $upload = media_sideload_image($image, $post_ID, $desc);
 
                                // Replace the POSTED content <img> with correct uploaded ones. Regex contains fix for Magic Quotes
-                               if( !is_wp_error($upload) ) $content = preg_replace('/<img ([^>]*)src=\\\?(\"|\')'.preg_quote($image, '/').'\\\?(\2)([^>\/]*)\/*>/is', $upload, $content);
+                               if( !is_wp_error($upload) )
+                                       $content = preg_replace('/<img ([^>]*)src=\\\?(\"|\')'.preg_quote(htmlspecialchars($image), '/').'\\\?(\2)([^>\/]*)\/*>/is', $upload, $content);
                        }
                        }
-
+               }
+       }
        // set the post_content and status
        // set the post_content and status
-       $quick['post_status'] = isset($_REQUEST['publish']) ? 'publish' : 'draft';
+       $quick['post_status'] = isset($_POST['publish']) ? 'publish' : 'draft';
        $quick['post_content'] = $content;
        $quick['post_content'] = $content;
-       // error handling for $post
-       if ( is_wp_error($post_ID)) {
-               wp_die($id);
-               wp_delete_post($post_ID);
        // error handling for media_sideload
        // error handling for media_sideload
-       } elseif ( is_wp_error($upload)) {
-               wp_die($upload);
+       if ( is_wp_error($upload) ) {
                wp_delete_post($post_ID);
                wp_delete_post($post_ID);
+               wp_die($upload);
        } else {
                $quick['ID'] = $post_ID;
                wp_update_post($quick);
        } else {
                $quick['ID'] = $post_ID;
                wp_update_post($quick);
@@ -91,89 +92,96 @@ if ( isset($_REQUEST['action']) && 'post' == $_REQUEST['action'] ) {
 }
 
 // Set Variables
 }
 
 // Set Variables
-$title = isset($_GET['t']) ? esc_html(aposfix(stripslashes($_GET['t']))) : '';
-$selection = isset($_GET['s']) ? trim( aposfix( stripslashes($_GET['s']) ) ) : '';
+$title = isset( $_GET['t'] ) ? trim( strip_tags( aposfix( stripslashes( $_GET['t'] ) ) ) ) : '';
+$selection = isset( $_GET['s'] ) ? trim( htmlspecialchars( html_entity_decode( aposfix( stripslashes( $_GET['s'] ) ) ) ) ) : '';
 if ( ! empty($selection) ) {
        $selection = preg_replace('/(\r?\n|\r)/', '</p><p>', $selection);
        $selection = '<p>'.str_replace('<p></p>', '', $selection).'</p>';
 }
 if ( ! empty($selection) ) {
        $selection = preg_replace('/(\r?\n|\r)/', '</p><p>', $selection);
        $selection = '<p>'.str_replace('<p></p>', '', $selection).'</p>';
 }
+
 $url = isset($_GET['u']) ? esc_url($_GET['u']) : '';
 $image = isset($_GET['i']) ? $_GET['i'] : '';
 
 if ( !empty($_REQUEST['ajax']) ) {
 $url = isset($_GET['u']) ? esc_url($_GET['u']) : '';
 $image = isset($_GET['i']) ? $_GET['i'] : '';
 
 if ( !empty($_REQUEST['ajax']) ) {
-switch ($_REQUEST['ajax']) {
-       case 'video': ?>
-               <script type="text/javascript" charset="utf-8">
-                       jQuery('.select').click(function() {
-                               append_editor(jQuery('#embed-code').val());
-                               jQuery('#extra_fields').hide();
-                               jQuery('#extra_fields').html('');
-                       });
-                       jQuery('.close').click(function() {
-                               jQuery('#extra_fields').hide();
-                               jQuery('#extra_fields').html('');
-                       });
-               </script>
-               <div class="postbox">
-               <h2><label for="embed-code"><?php _e('Embed Code') ?></label></h2>
-               <div class="inside">
-                       <textarea name="embed-code" id="embed-code" rows="8" cols="40"><?php echo format_to_edit($selection, true); ?></textarea>
-                       <p id="options"><a href="#" class="select button"><?php _e('Insert Video'); ?></a> <a href="#" class="close button"><?php _e('Cancel'); ?></a></p>
-               </div>
-               </div>
-               <?php break;
-
-       case 'photo_thickbox': ?>
-               <script type="text/javascript" charset="utf-8">
-                       jQuery('.cancel').click(function() {
-                               tb_remove();
-                       });
-                       jQuery('.select').click(function() {
-                               image_selector();
-                       });
-               </script>
-               <h3 class="tb"><label for="this_photo_description"><?php _e('Description') ?></label></h3>
-               <div class="titlediv">
-               <div class="titlewrap">
-                       <input id="this_photo_description" name="photo_description" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" value="<?php echo esc_attr($title);?>"/>
-               </div>
-               </div>
-
-               <p class="centered"><input type="hidden" name="this_photo" value="<?php echo esc_attr($image); ?>" id="this_photo" />
-                       <a href="#" class="select"><img src="<?php echo esc_url($image); ?>" alt="<?php echo esc_attr(__('Click to insert.')); ?>" title="<?php echo esc_attr(__('Click to insert.')); ?>" /></a></p>
-
-               <p id="options"><a href="#" class="select button"><?php _e('Insert Image'); ?></a> <a href="#" class="cancel button"><?php _e('Cancel'); ?></a></p>
-
-
-               <?php break;
+       switch ($_REQUEST['ajax']) {
+               case 'video': ?>
+                       <script type="text/javascript" charset="utf-8">
+                       /* <![CDATA[ */
+                               jQuery('.select').click(function() {
+                                       append_editor(jQuery('#embed-code').val());
+                                       jQuery('#extra-fields').hide();
+                                       jQuery('#extra-fields').html('');
+                               });
+                               jQuery('.close').click(function() {
+                                       jQuery('#extra-fields').hide();
+                                       jQuery('#extra-fields').html('');
+                               });
+                       /* ]]> */
+                       </script>
+                       <div class="postbox">
+                               <h2><label for="embed-code"><?php _e('Embed Code') ?></label></h2>
+                               <div class="inside">
+                                       <textarea name="embed-code" id="embed-code" rows="8" cols="40"><?php echo wp_htmledit_pre( $selection ); ?></textarea>
+                                       <p id="options"><a href="#" class="select button"><?php _e('Insert Video'); ?></a> <a href="#" class="close button"><?php _e('Cancel'); ?></a></p>
+                               </div>
+                       </div>
+                       <?php break;
 
 
-       case 'photo_thickbox_url': ?>
-               <script type="text/javascript" charset="utf-8">
-                       jQuery('.cancel').click(function() {
-                               tb_remove();
-                       });
-
-                       jQuery('.select').click(function() {
-                               image_selector();
-                       });
-               </script>
-               <h3 class="tb"><label for="this_photo"><?php _e('URL') ?></label></h3>
-               <div class="titlediv">
-                       <div class="titlewrap">
-                       <input id="this_photo" name="this_photo" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" />
+               case 'photo_thickbox': ?>
+                       <script type="text/javascript" charset="utf-8">
+                               /* <![CDATA[ */
+                               jQuery('.cancel').click(function() {
+                                       tb_remove();
+                               });
+                               jQuery('.select').click(function() {
+                                       image_selector();
+                               });
+                               /* ]]> */
+                       </script>
+                       <h3 class="tb"><label for="this_photo_description"><?php _e('Description') ?></label></h3>
+                       <div class="titlediv">
+                               <div class="titlewrap">
+                                       <input id="this_photo_description" name="photo_description" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" value="<?php echo esc_attr($title);?>"/>
+                               </div>
                        </div>
                        </div>
-               </div>
 
 
+                       <p class="centered">
+                               <input type="hidden" name="this_photo" value="<?php echo esc_attr($image); ?>" id="this_photo" />
+                               <a href="#" class="select">
+                                       <img src="<?php echo esc_url($image); ?>" alt="<?php echo esc_attr(__('Click to insert.')); ?>" title="<?php echo esc_attr(__('Click to insert.')); ?>" />
+                               </a>
+                       </p>
+
+                       <p id="options"><a href="#" class="select button"><?php _e('Insert Image'); ?></a> <a href="#" class="cancel button"><?php _e('Cancel'); ?></a></p>
+                       <?php break;
+
+               case 'photo_thickbox_url': ?>
+                       <script type="text/javascript" charset="utf-8">
+                               /* <![CDATA[ */
+                               jQuery('.cancel').click(function() {
+                                       tb_remove();
+                               });
 
 
-               <h3 class="tb"><label for="photo_description"><?php _e('Description') ?></label></h3>
-               <div id="titlediv">
-                       <div class="titlewrap">
-                       <input id="this_photo_description" name="photo_description" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" value="<?php echo esc_attr($title);?>"/>
+                               jQuery('.select').click(function() {
+                                       image_selector();
+                               });
+                               /* ]]> */
+                       </script>
+                       <h3 class="tb"><label for="this_photo"><?php _e('URL') ?></label></h3>
+                       <div class="titlediv">
+                               <div class="titlewrap">
+                                       <input id="this_photo" name="this_photo" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" />
+                               </div>
+                       </div>
+                       <h3 class="tb"><label for="photo_description"><?php _e('Description') ?></label></h3>
+                       <div id="titlediv">
+                               <div class="titlewrap">
+                                       <input id="this_photo_description" name="photo_description" class="tbtitle text" onkeypress="if(event.keyCode==13) image_selector();" value="<?php echo esc_attr($title);?>"/>
+                               </div>
                        </div>
                        </div>
-               </div>
 
 
-               <p id="options"><a href="#" class="select"><?php _e('Insert Image'); ?></a> | <a href="#" class="cancel"><?php _e('Cancel'); ?></a></p>
-               <?php break;
+                       <p id="options"><a href="#" class="select"><?php _e('Insert Image'); ?></a> | <a href="#" class="cancel"><?php _e('Cancel'); ?></a></p>
+                       <?php break;
        case 'photo_images':
                /**
                 * Retrieve all image URLs from given URI.
        case 'photo_images':
                /**
                 * Retrieve all image URLs from given URI.
@@ -186,13 +194,15 @@ switch ($_REQUEST['ajax']) {
                 * @return string
                 */
                function get_images_from_uri($uri) {
                 * @return string
                 */
                function get_images_from_uri($uri) {
+                       $uri = preg_replace('/\/#.+?$/','', $uri);
                        if( preg_match('/\.(jpg|jpe|jpeg|png|gif)$/', $uri) && !strpos($uri,'blogger.com') )
                        if( preg_match('/\.(jpg|jpe|jpeg|png|gif)$/', $uri) && !strpos($uri,'blogger.com') )
-                               return "'".$uri."'";
+                               return "'" . esc_attr( html_entity_decode($uri) ) . "'";
                        $content = wp_remote_fopen($uri);
                        if ( false === $content )
                                return '';
                        $host = parse_url($uri);
                        $content = wp_remote_fopen($uri);
                        if ( false === $content )
                                return '';
                        $host = parse_url($uri);
-                       $pattern = '/<img ([^>]*)src=(\"|\')([^<>]+?\.(png|jpeg|jpg|jpe|gif))[^<>\'\"]*(\2)([^>\/]*)\/*>/is';
+                       $pattern = '/<img ([^>]*)src=(\"|\')([^<>\'\"]+)(\2)([^>]*)\/*>/i';
+                       $content = str_replace(array("\n","\t","\r"), '', $content);
                        preg_match_all($pattern, $content, $matches);
                        if ( empty($matches[0]) )
                                return '';
                        preg_match_all($pattern, $content, $matches);
                        if ( empty($matches[0]) )
                                return '';
@@ -205,46 +215,45 @@ switch ($_REQUEST['ajax']) {
                                                $src = 'http://'.str_replace('//','/', $host['host'].'/'.$src);
                                        else
                                                $src = 'http://'.str_replace('//','/', $host['host'].'/'.dirname($host['path']).'/'.$src);
                                                $src = 'http://'.str_replace('//','/', $host['host'].'/'.$src);
                                        else
                                                $src = 'http://'.str_replace('//','/', $host['host'].'/'.dirname($host['path']).'/'.$src);
-                               $sources[] = esc_url($src);
+                               $sources[] = esc_attr($src);
                        }
                        return "'" . implode("','", $sources) . "'";
                }
                        }
                        return "'" . implode("','", $sources) . "'";
                }
-               $url = urldecode($url);
-               $url = str_replace(' ', '%20', $url);
+               $url = wp_kses(urldecode($url), null);
                echo 'new Array('.get_images_from_uri($url).')';
                echo 'new Array('.get_images_from_uri($url).')';
-
                break;
 
        case 'photo_js': ?>
                // gather images and load some default JS
                var last = null
                var img, img_tag, aspect, w, h, skip, i, strtoappend = "";
                break;
 
        case 'photo_js': ?>
                // gather images and load some default JS
                var last = null
                var img, img_tag, aspect, w, h, skip, i, strtoappend = "";
+               if(photostorage == false) {
+               var my_src = eval(
+                       jQuery.ajax({
+                               type: "GET",
+                               url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
+                               cache : false,
+                               async : false,
+                               data: "ajax=photo_images&u=<?php echo urlencode($url); ?>",
+                               dataType : "script"
+                       }).responseText
+               );
+               if(my_src.length == 0) {
                        var my_src = eval(
                                jQuery.ajax({
                        var my_src = eval(
                                jQuery.ajax({
-                                       type: "GET",
-                                       url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
+                                       type: "GET",
+                                       url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
                                        cache : false,
                                        async : false,
                                        cache : false,
                                        async : false,
-                                       data: "ajax=photo_images&u=<?php echo urlencode($url); ?>",
+                                       data: "ajax=photo_images&u=<?php echo urlencode($url); ?>",
                                        dataType : "script"
                                }).responseText
                        );
                        if(my_src.length == 0) {
                                        dataType : "script"
                                }).responseText
                        );
                        if(my_src.length == 0) {
-                               var my_src = eval(
-                               jQuery.ajax({
-                                       type: "GET",
-                                       url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
-                                       cache : false,
-                                       async : false,
-                                       data: "ajax=photo_images&u=<?php echo urlencode($url); ?>",
-                                       dataType : "script"
-                               }).responseText
-                               );
-                               if(my_src.length == 0) {
-                                       strtoappend = '<?php _e('Unable to retrieve images or no images on page.'); ?>';
-                               }
+                               strtoappend = '<?php _e('Unable to retrieve images or no images on page.'); ?>';
                        }
                        }
-
+               }
+               }
                for (i = 0; i < my_src.length; i++) {
                        img = new Image();
                        img.src = my_src[i];
                for (i = 0; i < my_src.length; i++) {
                        img = new Image();
                        img.src = my_src[i];
@@ -289,26 +298,12 @@ switch ($_REQUEST['ajax']) {
                        desc = jQuery('#this_photo_description').val();
                        src = jQuery('#this_photo').val();
                        pick(src, desc);
                        desc = jQuery('#this_photo_description').val();
                        src = jQuery('#this_photo').val();
                        pick(src, desc);
-                       jQuery('#extra_fields').hide();
-                       jQuery('#extra_fields').html('');
+                       jQuery('#extra-fields').hide();
+                       jQuery('#extra-fields').html('');
                        return false;
                }
                        return false;
                }
-
-               jQuery(document).ready(function() {
-                       jQuery('#extra_fields').html('<div class="postbox"><h2>Photo <small id="photo_directions">(<?php _e("click images to select") ?>)</small></h2><ul id="actions"><li><a href="#" id="photo_add_url" class="thickbox button"><?php _e("Add from URL") ?> +</a></li></ul><div class="inside"><div class="titlewrap"><div id="img_container"></div></div><p id="options"><a href="#" class="close button"><?php _e('Cancel'); ?></a><a href="#" class="refresh button"><?php _e('Refresh'); ?></a></p></div>');
-                       jQuery('.close').click(function() {
-                               jQuery('#extra_fields').hide();
-                               jQuery('#extra_fields').html('');
-                       });
-                       jQuery('.refresh').click(function() {
-                                               show('photo');
-                                       });
+                       jQuery('#extra-fields').html('<div class="postbox"><h2>Add Photos <small id="photo_directions">(<?php _e("click images to select") ?>)</small></h2><ul class="actions"><li><a href="#" id="photo-add-url" class="thickbox button"><?php _e("Add from URL") ?> +</a></li></ul><div class="inside"><div class="titlewrap"><div id="img_container"></div></div><p id="options"><a href="#" class="close button"><?php _e('Cancel'); ?></a><a href="#" class="refresh button"><?php _e('Refresh'); ?></a></p></div>');
                        jQuery('#img_container').html(strtoappend);
                        jQuery('#img_container').html(strtoappend);
-                       jQuery('#photo_add_url').attr('href', '?ajax=photo_thickbox_url&height=200&width=500');
-                       tb_init('#extra_fields .thickbox');
-
-
-               });
                <?php break;
 }
 die;
                <?php break;
 }
 die;
@@ -323,17 +318,18 @@ die;
 
 <?php
        add_thickbox();
 
 <?php
        add_thickbox();
-       wp_enqueue_style('press-this');
-       wp_enqueue_style('press-this-ie');
+       wp_enqueue_style( 'press-this' );
+       wp_enqueue_style( 'press-this-ie');
        wp_enqueue_style( 'colors' );
        wp_enqueue_script( 'post' );
        wp_enqueue_style( 'colors' );
        wp_enqueue_script( 'post' );
-       wp_enqueue_script('editor');
+       wp_enqueue_script( 'editor' );
 ?>
 <script type="text/javascript">
 //<![CDATA[
 addLoadEvent = function(func){if(typeof jQuery!="undefined")jQuery(document).ready(func);else if(typeof wpOnload!='function'){wpOnload=func;}else{var oldonload=wpOnload;wpOnload=function(){oldonload();func();}}};
 var userSettings = {'url':'<?php echo SITECOOKIEPATH; ?>','uid':'<?php if ( ! isset($current_user) ) $current_user = wp_get_current_user(); echo $current_user->ID; ?>','time':'<?php echo time() ?>'};
 ?>
 <script type="text/javascript">
 //<![CDATA[
 addLoadEvent = function(func){if(typeof jQuery!="undefined")jQuery(document).ready(func);else if(typeof wpOnload!='function'){wpOnload=func;}else{var oldonload=wpOnload;wpOnload=function(){oldonload();func();}}};
 var userSettings = {'url':'<?php echo SITECOOKIEPATH; ?>','uid':'<?php if ( ! isset($current_user) ) $current_user = wp_get_current_user(); echo $current_user->ID; ?>','time':'<?php echo time() ?>'};
-var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
+var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>', pagenow = 'press-this';
+var photostorage = false;
 //]]>
 </script>
 
 //]]>
 </script>
 
@@ -342,10 +338,8 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
        do_action('admin_print_scripts');
        do_action('admin_head');
 
        do_action('admin_print_scripts');
        do_action('admin_head');
 
-       if ( user_can_richedit() ) {
-               add_filter( 'teeny_mce_before_init', create_function( '$a', '$a["height"] = "400"; $a["onpageload"] = ""; $a["mode"] = "textareas"; $a["editor_selector"] = "mceEditor"; return $a;' ) );
-               wp_tiny_mce( true );
-       }
+       if ( user_can_richedit() )
+               wp_tiny_mce( true, array( 'height' => '370' ) );
 ?>
        <script type="text/javascript">
        function insert_plain_editor(text) {
 ?>
        <script type="text/javascript">
        function insert_plain_editor(text) {
@@ -373,11 +367,10 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
        }
 
        function show(tab_name) {
        }
 
        function show(tab_name) {
-               jQuery('#extra_fields').html('');
-               jQuery('#extra_fields').show();
+               jQuery('#extra-fields').html('');
                switch(tab_name) {
                        case 'video' :
                switch(tab_name) {
                        case 'video' :
-                               jQuery('#extra_fields').load('<?php echo esc_url($_SERVER['PHP_SELF']); ?>', { ajax: 'video', s: '<?php echo esc_attr($selection); ?>'}, function() {
+                               jQuery('#extra-fields').load('<?php echo esc_url($_SERVER['PHP_SELF']); ?>', { ajax: 'video', s: '<?php echo esc_attr($selection); ?>'}, function() {
                                        <?php
                                        $content = '';
                                        if ( preg_match("/youtube\.com\/watch/i", $url) ) {
                                        <?php
                                        $content = '';
                                        if ( preg_match("/youtube\.com\/watch/i", $url) ) {
@@ -399,27 +392,50 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                                        ?>
                                        jQuery('#embed-code').prepend('<?php echo htmlentities($content); ?>');
                                });
                                        ?>
                                        jQuery('#embed-code').prepend('<?php echo htmlentities($content); ?>');
                                });
+                               jQuery('#extra-fields').show();
                                return false;
                                break;
                        case 'photo' :
                                return false;
                                break;
                        case 'photo' :
-                               jQuery('#extra_fields').before('<p id="waiting"><img src="images/wpspin_light.gif" alt="" /> <?php echo esc_js( __( 'Loading...' ) ); ?></p>');
-                               jQuery.ajax({
-                                       type: "GET",
-                                       cache : false,
-                                       url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
-                                       data: "ajax=photo_js&u=<?php echo urlencode($url)?>",
-                                       dataType : "script",
-                                       success : function() {
-                                               jQuery('#waiting').remove();
-                                       }
-                               });
+                               function setup_photo_actions() {
+                                       jQuery('.close').click(function() {
+                                               jQuery('#extra-fields').hide();
+                                               jQuery('#extra-fields').html('');
+                                       });
+                                       jQuery('.refresh').click(function() {
+                                               photostorage = false;
+                                               show('photo');
+                                       });
+                                       jQuery('#photo-add-url').attr('href', '?ajax=photo_thickbox_url&height=200&width=500');
+                                       tb_init('#extra-fields .thickbox');
+                                       jQuery('#waiting').hide();
+                                       jQuery('#extra-fields').show();
+                               }
+                               jQuery('#extra-fields').before('<div id="waiting"><img src="images/wpspin_light.gif" alt="" /> <?php echo esc_js( __( 'Loading...' ) ); ?></div>');
+                               
+                               if(photostorage == false) {
+                                       jQuery.ajax({
+                                               type: "GET",
+                                               cache : false,
+                                               url: "<?php echo esc_url($_SERVER['PHP_SELF']); ?>",
+                                               data: "ajax=photo_js&u=<?php echo urlencode($url)?>",
+                                               dataType : "script",
+                                               success : function(data) {
+                                                       eval(data);
+                                                       photostorage = jQuery('#extra-fields').html();
+                                                       setup_photo_actions();
+                                               }
+                                       });
+                               } else {
+                                       jQuery('#extra-fields').html(photostorage);
+                                       setup_photo_actions();
+                               }
                                return false;
                                break;
                }
        }
                                return false;
                                break;
                }
        }
-       jQuery(document).ready(function() {
+       jQuery(document).ready(function($) {
                //resize screen
                //resize screen
-               window.resizeTo(720,570);
+               window.resizeTo(720,540);
                // set button actions
        jQuery('#photo_button').click(function() { show('photo'); return false; });
                jQuery('#video_button').click(function() { show('video'); return false; });
                // set button actions
        jQuery('#photo_button').click(function() { show('photo'); return false; });
                jQuery('#video_button').click(function() { show('video'); return false; });
@@ -433,16 +449,20 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                <?php } ?>
                jQuery('#title').unbind();
                jQuery('#publish, #save').click(function() { jQuery('#saving').css('display', 'inline'); });
                <?php } ?>
                jQuery('#title').unbind();
                jQuery('#publish, #save').click(function() { jQuery('#saving').css('display', 'inline'); });
+
+               $('#tagsdiv-post_tag, #categorydiv').children('h3, .handlediv').click(function(){
+                       $(this).siblings('.inside').toggle();
+               });
        });
 </script>
 </head>
        });
 </script>
 </head>
-<body class="press-this">
+<body class="press-this wp-admin">
 <div id="wphead"></div>
 <form action="press-this.php?action=post" method="post">
 <div id="poststuff" class="metabox-holder">
        <div id="side-info-column">
                <div class="sleeve">
 <div id="wphead"></div>
 <form action="press-this.php?action=post" method="post">
 <div id="poststuff" class="metabox-holder">
        <div id="side-info-column">
                <div class="sleeve">
-                       <h1 id="viewsite"><a class="button" href="<?php echo get_option('home'); ?>/" target="_blank"><?php bloginfo('name'); ?> &rsaquo; <?php _e('Press This') ?></a></span></h1>
+                       <h1 id="viewsite"><a href="<?php echo get_option('home'); ?>/" target="_blank"><?php bloginfo('name'); ?> &rsaquo; <?php _e('Press This') ?></a></span></h1>
 
                        <?php wp_nonce_field('press-this') ?>
                        <input type="hidden" name="post_type" id="post_type" value="text"/>
 
                        <?php wp_nonce_field('press-this') ?>
                        <input type="hidden" name="post_type" id="post_type" value="text"/>
@@ -454,6 +474,9 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        <div class="photolist"></div>
 
                        <div id="submitdiv" class="stuffbox">
                        <div class="photolist"></div>
 
                        <div id="submitdiv" class="stuffbox">
+                               <div class="handlediv" title="<?php _e( 'Click to toggle' ); ?>">
+                                       <br/>
+                               </div>
                                <h3><?php _e('Publish') ?></h3>
                                <div class="inside">
                                        <p>
                                <h3><?php _e('Publish') ?></h3>
                                <div class="inside">
                                        <p>
@@ -469,10 +492,14 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        </div>
 
                        <div id="categorydiv" class="stuffbox">
                        </div>
 
                        <div id="categorydiv" class="stuffbox">
+                               <div class="handlediv" title="<?php _e( 'Click to toggle' ); ?>">
+                                       <br/>
+                               </div>
                                <h3><?php _e('Categories') ?></h3>
                                <div class="inside">
 
                                        <div id="categories-all" class="tabs-panel">
                                <h3><?php _e('Categories') ?></h3>
                                <div class="inside">
 
                                        <div id="categories-all" class="tabs-panel">
+
                                                <ul id="categorychecklist" class="list:category categorychecklist form-no-clear">
                                                        <?php wp_category_checklist($post_ID, false) ?>
                                                </ul>
                                                <ul id="categorychecklist" class="list:category categorychecklist form-no-clear">
                                                        <?php wp_category_checklist($post_ID, false) ?>
                                                </ul>
@@ -492,16 +519,19 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        </div>
 
                        <div id="tagsdiv-post_tag" class="stuffbox" >
                        </div>
 
                        <div id="tagsdiv-post_tag" class="stuffbox" >
+                               <div class="handlediv" title="<?php _e( 'Click to toggle' ); ?>">
+                                       <br/>
+                               </div>
                                <h3><span><?php _e('Post Tags'); ?></span></h3>
                                <div class="inside">
                                        <div class="tagsdiv" id="post_tag">
                                                <p class="jaxtag">
                                                        <label class="screen-reader-text" for="newtag"><?php _e('Post Tags'); ?></label>
                                                        <input type="hidden" name="tax_input[post_tag]" class="the-tags" id="tax-input[post_tag]" value="" />
                                <h3><span><?php _e('Post Tags'); ?></span></h3>
                                <div class="inside">
                                        <div class="tagsdiv" id="post_tag">
                                                <p class="jaxtag">
                                                        <label class="screen-reader-text" for="newtag"><?php _e('Post Tags'); ?></label>
                                                        <input type="hidden" name="tax_input[post_tag]" class="the-tags" id="tax-input[post_tag]" value="" />
-                                                       <span class="ajaxtag" style="display:none;">
-                                                               <input type="text" name="newtag[post_tag]" class="newtag form-input-tip" size="16" autocomplete="off" value="<?php esc_attr_e('Add new tag'); ?>" />
+                                                       <div class="ajaxtag">
+                                                               <input type="text" name="newtag[post_tag]" class="newtag form-input-tip" size="16" autocomplete="off" value="" />
                                                                <input type="button" class="button tagadd" value="<?php esc_attr_e('Add'); ?>" tabindex="3" />
                                                                <input type="button" class="button tagadd" value="<?php esc_attr_e('Add'); ?>" tabindex="3" />
-                                                       </span>
+                                                       </div>
                                                </p>
                                                <div class="tagchecklist"></div>
                                        </div>
                                                </p>
                                                <div class="tagchecklist"></div>
                                        </div>
@@ -510,7 +540,6 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        </div>
                </div>
        </div>
                        </div>
                </div>
        </div>
-
        <div class="posting">
                <?php if ( isset($posted) && intval($posted) ) { $post_ID = intval($posted); ?>
                <div id="message" class="updated fade"><p><strong><?php _e('Your post has been saved.'); ?></strong> <a onclick="window.opener.location.replace(this.href); window.close();" href="<?php echo get_permalink( $post_ID); ?>"><?php _e('View post'); ?></a> | <a href="<?php echo get_edit_post_link( $post_ID ); ?>" onclick="window.opener.location.replace(this.href); window.close();"><?php _e('Edit post'); ?></a> | <a href="#" onclick="window.close();"><?php _e('Close Window'); ?></a></p></div>
        <div class="posting">
                <?php if ( isset($posted) && intval($posted) ) { $post_ID = intval($posted); ?>
                <div id="message" class="updated fade"><p><strong><?php _e('Your post has been saved.'); ?></strong> <a onclick="window.opener.location.replace(this.href); window.close();" href="<?php echo get_permalink( $post_ID); ?>"><?php _e('View post'); ?></a> | <a href="<?php echo get_edit_post_link( $post_ID ); ?>" onclick="window.opener.location.replace(this.href); window.close();"><?php _e('Edit post'); ?></a> | <a href="#" onclick="window.close();"><?php _e('Close Window'); ?></a></p></div>
@@ -522,10 +551,10 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        </div>
                </div>
 
                        </div>
                </div>
 
-               <div id="extra_fields" style="display: none"></div>
+               <div id="extra-fields" style="display: none"></div>
 
                <div class="postdivrich">
 
                <div class="postdivrich">
-                       <ul id="actions">
+                       <ul id="actions" class="actions">
 
                                <li id="photo_button">
                                        Add: <?php if ( current_user_can('upload_files') ) { ?><a title="<?php _e('Insert an Image'); ?>" href="#">
 
                                <li id="photo_button">
                                        Add: <?php if ( current_user_can('upload_files') ) { ?><a title="<?php _e('Insert an Image'); ?>" href="#">
@@ -547,10 +576,16 @@ var ajaxurl = '<?php echo admin_url('admin-ajax.php'); ?>';
                        </ul>
                        <div id="quicktags"></div>
                        <div class="editor-container">
                        </ul>
                        <div id="quicktags"></div>
                        <div class="editor-container">
-                               <textarea name="content" id="content" style="width:100%;" class="mceEditor" rows="15">
-                                       <?php if ($selection) echo wp_richedit_pre(htmlspecialchars_decode($selection)); ?>
-                                       <?php if ($url) { echo '<p>'; if($selection) _e('via '); echo "<a href='$url'>$title</a>."; echo '</p>'; } ?>
-                               </textarea>
+                               <textarea name="content" id="content" style="width:100%;" class="theEditor" rows="15"><?php
+                                       if ( $selection )
+                                               echo wp_richedit_pre($selection);
+                                       if ( $url ) {
+                                               echo '<p>';
+                                               if ( $selection )
+                                                       _e('via ');
+                                               printf( "<a href='%s'>%s</a>.</p>", esc_url( $url ), esc_html( $title ) );
+                                       }
+                               ?></textarea>
                        </div>
                </div>
        </div>
                        </div>
                </div>
        </div>