X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/6c8f14c09105d0afa4c1574215c59b5021040e76..85ad385665744d9cc3bcd939906309be7268edb3:/wp-admin/users.php diff --git a/wp-admin/users.php b/wp-admin/users.php index 6ea17657..2a28f74b 100644 --- a/wp-admin/users.php +++ b/wp-admin/users.php @@ -7,7 +7,7 @@ */ /** WordPress Administration Bootstrap */ -require_once( './admin.php' ); +require_once( dirname( __FILE__ ) . '/admin.php' ); if ( ! current_user_can( 'list_users' ) ) wp_die( __( 'Cheatin’ uh?' ) ); @@ -64,9 +64,9 @@ get_current_screen()->set_help_sidebar( ); if ( empty($_REQUEST) ) { - $referer = ''; + $referer = ''; } elseif ( isset($_REQUEST['wp_http_referer']) ) { - $redirect = remove_query_arg(array('wp_http_referer', 'updated', 'delete_count'), stripslashes($_REQUEST['wp_http_referer'])); + $redirect = remove_query_arg(array('wp_http_referer', 'updated', 'delete_count'), wp_unslash( $_REQUEST['wp_http_referer'] ) ); $referer = ''; } else { $redirect = 'users.php'; @@ -86,6 +86,9 @@ jQuery(document).ready( function($) { $('input[name=delete_option]').one('change', function() { submit.prop('disabled', false); }); + $('#reassign_user').focus( function() { + $('#delete_option1').prop('checked', true).trigger('change'); + }); });
-

@@ -313,14 +315,13 @@ case 'remove': else $userids = $_REQUEST['users']; - include ('admin-header.php'); + include( ABSPATH . 'wp-admin/admin-header.php' ); ?>
-

    @@ -354,7 +355,7 @@ break; default: if ( !empty($_GET['_wp_http_referer']) ) { - wp_redirect(remove_query_arg(array('_wp_http_referer', '_wpnonce'), stripslashes($_SERVER['REQUEST_URI']))); + wp_redirect( remove_query_arg( array( '_wp_http_referer', '_wpnonce'), wp_unslash( $_SERVER['REQUEST_URI'] ) ) ); exit; } @@ -365,7 +366,7 @@ default: exit; } - include('./admin-header.php'); + include( ABSPATH . 'wp-admin/admin-header.php' ); $messages = array(); if ( isset($_GET['update']) ) : @@ -378,7 +379,7 @@ default: case 'add': if ( isset( $_GET['id'] ) && ( $user_id = $_GET['id'] ) && current_user_can( 'edit_user', $user_id ) ) { $messages[] = '

    ' . sprintf( __( 'New user created. Edit user' ), - esc_url( add_query_arg( 'wp_http_referer', urlencode( stripslashes( $_SERVER['REQUEST_URI'] ) ), + esc_url( add_query_arg( 'wp_http_referer', urlencode( wp_unslash( $_SERVER['REQUEST_URI'] ) ), self_admin_url( 'user-edit.php?user_id=' . $user_id ) ) ) ) . '

    '; } else { $messages[] = '

    ' . __( 'New user created.' ) . '

    '; @@ -422,7 +423,6 @@ if ( ! empty($messages) ) { } ?>
    -