Make WordPress Core


Ignore:
Timestamp:
02/22/2010 06:15:10 PM (15 years ago)
Author:
nacin
Message:

Use esc_url() instead of clean_url(). See #12309

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/ms-users.php

    r12949 r13297  
    181181                            case 'login':
    182182                                $avatar = get_avatar( $user['user_email'], 32 );
    183                                 $edit   = clean_url( add_query_arg( 'wp_http_referer', urlencode( clean_url( stripslashes( $_SERVER['REQUEST_URI'] ) ) ), "user-edit.php?user_id=".$user['ID'] ) );
     183                                $edit   = esc_url( add_query_arg( 'wp_http_referer', urlencode( esc_url( stripslashes( $_SERVER['REQUEST_URI'] ) ) ), "user-edit.php?user_id=".$user['ID'] ) );
    184184                                // @todo Make delete link work like delete button with transfering users (in ms-edit.php)
    185                                 //$delete   = clean_url( add_query_arg( 'wp_http_referer', urlencode( clean_url( stripslashes( $_SERVER['REQUEST_URI'] ) ) ), wp_nonce_url( 'ms-edit.php', 'deleteuser' ) . '&action=deleteuser&id=' . $user['ID'] ) );
     185                                //$delete   = esc_url( add_query_arg( 'wp_http_referer', urlencode( esc_url( stripslashes( $_SERVER['REQUEST_URI'] ) ) ), wp_nonce_url( 'ms-edit.php', 'deleteuser' ) . '&action=deleteuser&id=' . $user['ID'] ) );
    186186                                ?>
    187187                                <td class="username column-username">
Note: See TracChangeset for help on using the changeset viewer.