Changeset 12801
- Timestamp:
- 01/22/2010 10:27:26 PM (16 years ago)
- Location:
- trunk/wp-admin
- Files:
-
- 2 edited
-
ms-sites.php (modified) (1 diff)
-
ms-users.php (modified) (5 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/wp-admin/ms-sites.php
r12800 r12801 379 379 <form action="ms-sites.php" method="get" id="ms-search"> 380 380 <input type="hidden" name="action" value="blogs" /> 381 <input type="text" name="s" value="<?php if (isset($_GET['s'])) echo stripslashes( esc_attr( $s )); ?>" size="17" />381 <input type="text" name="s" value="<?php echo($s); ?>" size="17" /> 382 382 <input type="submit" class="button" name="blog_name" value="<?php esc_attr_e('Search blogs by name') ?>" /> 383 383 <input type="submit" class="button" name="blog_id" value="<?php esc_attr_e('by blog ID') ?>" /> -
trunk/wp-admin/ms-users.php
r12781 r12801 15 15 wp_die( __('You do not have permission to access this page.') ); 16 16 17 if ( $_GET['updated'] == 'true' ) {17 if ( isset($_GET['updated']) && $_GET['updated'] == 'true' ) { 18 18 ?> 19 19 <div id="message" class="updated fade"><p> … … 46 46 $apage = isset( $_GET['apage'] ) ? intval( $_GET['apage'] ) : 1; 47 47 $num = isset( $_GET['num'] ) ? intval( $_GET['num'] ) : 15; 48 $s = wp_specialchars( trim( $_GET[ 's' ] ) );48 $s = isset($_GET[ 's' ]) ? esc_attr( trim( $_GET[ 's' ] ) ) : ''; 49 49 50 50 $query = "SELECT * FROM {$wpdb->users}"; … … 55 55 } 56 56 57 if ( !isset($_GET['sortby']) ) 58 $_GET['sortby'] = 'id'; 59 60 if ( $_GET['sortby'] == 'email' ) 57 $order_by = isset( $_GET['sortby'] ) ? $_GET['sortby'] : 'id'; 58 59 if ( $order_by == 'email' ) { 61 60 $query .= ' ORDER BY user_email '; 62 elseif ( $_GET['sortby'] == 'id' ) 61 } elseif ( $order_by == 'login' ) { 62 $query .= ' ORDER BY user_login '; 63 } elseif ( $order_by == 'name' ) { 64 $query .= ' ORDER BY display_name '; 65 } elseif ( $order_by == 'registered' ) { 66 $query .= ' ORDER BY user_registered '; 67 } else { 68 $order_by = 'id'; 63 69 $query .= ' ORDER BY ID '; 64 elseif ( $_GET['sortby'] == 'login' ) 65 $query .= ' ORDER BY user_login '; 66 elseif ( $_GET['sortby'] == 'name' ) 67 $query .= ' ORDER BY display_name '; 68 elseif ( $_GET['sortby'] == 'registered' ) 69 $query .= ' ORDER BY user_registered '; 70 71 $query .= ( $_GET['order'] == 'DESC' ) ? 'DESC' : 'ASC'; 70 } 71 72 $order = isset($_GET['order']) ? $_GET['order'] : 'ASC'; 73 $order = ( 'DESC' == $order ) ? 'DESC' : 'ASC'; 74 $query .= $order; 72 75 73 76 if ( !empty( $s ) ) … … 147 150 echo '<th scope="col" class="check-column"><input type="checkbox" /></th>'; 148 151 } else { ?> 149 <th scope="col"><a href="ms-users.php?sortby=<?php echo $column_id ?>&<?php if ( $ _GET['sortby'] == $column_id ) { if ( $_GET['order']== 'DESC' ) { echo "order=ASC&" ; } else { echo "order=DESC&"; } } ?>apage=<?php echo $apage ?>"><?php echo $column_display_name; ?></a></th>152 <th scope="col"><a href="ms-users.php?sortby=<?php echo $column_id ?>&<?php if ( $order_by == $column_id ) { if ( $order == 'DESC' ) { echo "order=ASC&" ; } else { echo "order=DESC&"; } } ?>apage=<?php echo $apage ?>"><?php echo $column_display_name; ?></a></th> 150 153 <?php } ?> 151 154 <?php } ?> … … 155 158 <?php if ($user_list) { 156 159 $bgcolor = ''; 160 $class = ''; 157 161 foreach ( (array) $user_list as $user) { 158 162 $class = ('alternate' == $class) ? '' : 'alternate';
Note: See TracChangeset
for help on using the changeset viewer.