Make WordPress Core


Ignore:
Timestamp:
05/04/2009 05:54:08 PM (17 years ago)
Author:
ryan
Message:

Attr escaping

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/includes/media.php

    r11152 r11173  
    752752    $out = array();
    753753    foreach ($alignments as $name => $label) {
    754 
     754        $name = attr($name);
    755755        $out[] = "<input type='radio' name='attachments[{$post->ID}][align]' id='image-align-{$name}-{$post->ID}' value='$name'".
    756756            ( $checked == $name ? " checked='checked'" : "" ) .
     
    11571157    $delete_href = wp_nonce_url("post.php?action=delete-post&amp;post=$attachment_id", 'delete-post_' . $attachment_id);
    11581158    if ( $send )
    1159         $send = "<input type='submit' class='button' name='send[$attachment_id]' value='" . attr( __( 'Insert into Post' ) ) . "' />";
     1159        $send = "<input type='submit' class='button' name='send[$attachment_id]' value='" . _a( 'Insert into Post' ) . "' />";
    11601160    if ( $delete )
    11611161        $delete = "<a href=\"#\" class=\"del-link\" onclick=\"document.getElementById('del_attachment_$attachment_id').style.display='block';return false;\">" . __('Delete') . "</a>";
     
    14141414?>
    14151415</div>
    1416 <input type="submit" class="button savebutton" name="save" value="<?php echo attr( __( 'Save all changes' ) ); ?>" />
     1416<input type="submit" class="button savebutton" name="save" value="<?php _ea( 'Save all changes' ); ?>" />
    14171417<?php
    14181418}
     
    15871587
    15881588<p class="ml-submit">
    1589 <input type="submit" class="button savebutton" style="display:none;" name="save" id="save-all" value="<?php echo attr( __( 'Save all changes' ) ); ?>" />
     1589<input type="submit" class="button savebutton" style="display:none;" name="save" id="save-all" value="<?php _ea( 'Save all changes' ); ?>" />
    15901590<input type="hidden" name="post_id" id="post_id" value="<?php echo (int) $post_id; ?>" />
    15911591<input type="hidden" name="type" value="<?php echo attr( $GLOBALS['type'] ); ?>" />
     
    16641664
    16651665<p class="ml-submit">
    1666 <input type="button" class="button" style="display:none;" onmousedown="wpgallery.update();" name="insert-gallery" id="insert-gallery" value="<?php echo attr( __( 'Insert gallery' ) ); ?>" />
    1667 <input type="button" class="button" style="display:none;" onmousedown="wpgallery.update();" name="update-gallery" id="update-gallery" value="<?php echo attr( __( 'Update gallery settings' ) ); ?>" />
     1666<input type="button" class="button" style="display:none;" onmousedown="wpgallery.update();" name="insert-gallery" id="insert-gallery" value="<?php _ea( 'Insert gallery' ); ?>" />
     1667<input type="button" class="button" style="display:none;" onmousedown="wpgallery.update();" name="update-gallery" id="update-gallery" value="<?php _ea( 'Update gallery settings' ); ?>" />
    16681668</p>
    16691669</div>
     
    17091709    <label class="hidden" for="media-search-input"><?php _e('Search Media');?>:</label>
    17101710    <input type="text" id="media-search-input" name="s" value="<?php the_search_query(); ?>" />
    1711     <input type="submit" value="<?php echo attr( __( 'Search Media' ) ); ?>" class="button" />
     1711    <input type="submit" value="<?php _ea( 'Search Media' ); ?>" class="button" />
    17121712</p>
    17131713
     
    18261826</div>
    18271827<p class="ml-submit">
    1828 <input type="submit" class="button savebutton" name="save" value="<?php echo attr( __( 'Save all changes' ) ); ?>" />
     1828<input type="submit" class="button savebutton" name="save" value="<?php _ea( 'Save all changes' ); ?>" />
    18291829<input type="hidden" name="post_id" id="post_id" value="<?php echo (int) $post_id; ?>" />
    18301830</p>
     
    19081908            <td></td>
    19091909            <td>
    1910                 <input type="button" class="button" id="go_button" style="color:#bbb;" onclick="addExtImage.insert()" value="' . attr(__('Insert into Post')) . '" />
     1910                <input type="button" class="button" id="go_button" style="color:#bbb;" onclick="addExtImage.insert()" value="' . _a('Insert into Post') . '" />
    19111911            </td>
    19121912        </tr>
     
    19441944            <td></td>
    19451945            <td>
    1946                 <input type="submit" class="button" name="insertonlybutton" value="' . attr(__('Insert into Post')) . '" />
     1946                <input type="submit" class="button" name="insertonlybutton" value="' . _a('Insert into Post') . '" />
    19471947            </td>
    19481948        </tr>
     
    19791979            <td></td>
    19801980            <td>
    1981                 <input type="submit" class="button" name="insertonlybutton" value="' . attr(__('Insert into Post')) . '" />
     1981                <input type="submit" class="button" name="insertonlybutton" value="' . _a('Insert into Post') . '" />
    19821982            </td>
    19831983        </tr>
     
    20142014            <td></td>
    20152015            <td>
    2016                 <input type="submit" class="button" name="insertonlybutton" value="' . attr(__('Insert into Post')) . '" />
     2016                <input type="submit" class="button" name="insertonlybutton" value="' . _a('Insert into Post') . '" />
    20172017            </td>
    20182018        </tr>
Note: See TracChangeset for help on using the changeset viewer.