X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/ff81ee6e8304a1982a3ec4f5b134764a29d502cf..0f29eadd474473203a1182f52af1aa82721cecbd:/wp-admin/edit-page-form.php diff --git a/wp-admin/edit-page-form.php b/wp-admin/edit-page-form.php index ae594897..b0e603e0 100644 --- a/wp-admin/edit-page-form.php +++ b/wp-admin/edit-page-form.php @@ -5,40 +5,47 @@ "; } else { + $post_ID = (int) $post_ID; $form_action = 'editpost'; - $form_extra = ""; + $nonce_action = 'update-post_' . $post_ID; + $form_extra = ""; } -$sendto = $_SERVER['HTTP_REFERER']; +$temp_ID = (int) $temp_ID; +$user_ID = (int) $user_ID; + +$sendto = attribute_escape(wp_get_referer()); if ( 0 != $post_ID && $sendto == get_permalink($post_ID) ) $sendto = 'redo'; -$sendto = wp_specialchars( $sendto ); ?>
'; } ?> - +
@@ -57,7 +64,7 @@ addLoadEvent(focusit);

-
+
@@ -70,7 +77,7 @@ addLoadEvent(focusit);
-
+

+
id ) ) : // TODO: ROLE SYSTEM ?> @@ -95,6 +102,8 @@ foreach ($authors as $o) : $o = get_userdata( $o->ID ); if ( $post->post_author == $o->ID || ( empty($post_ID) && $user_ID == $o->ID ) ) $selected = 'selected="selected"'; else $selected = ''; +$o->ID = (int) $o->ID; +$o->display_name = wp_specialchars( $o->display_name ); echo ""; endforeach; ?> @@ -115,7 +124,7 @@ endforeach;
-
+
@@ -186,10 +195,10 @@ else ' . __('This feature requires iframe support.') . ''; + echo ''; } ?> @@ -209,17 +218,19 @@ if($metadata = has_meta($post_ID)) { meta_form(); ?>
+
- - escape($post->post_title) ) . "')\""; ?> /> + + post_title) ) . "') ) { document.forms.post._wpnonce.value = '$delete_nonce'; return true;}return false;\""; ?> /> -
- + +