Changeset 23416 for trunk/wp-login.php
- Timestamp:
- 02/14/2013 10:51:06 PM (12 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/wp-login.php
r23336 r23416 397 397 398 398 // 10 days 399 setcookie( 'wp-postpass_' . COOKIEHASH, $wp_hasher->HashPassword( stripslashes( $_POST['post_password'] ) ), time() + 10 * DAY_IN_SECONDS, COOKIEPATH );399 setcookie( 'wp-postpass_' . COOKIEHASH, $wp_hasher->HashPassword( wp_unslash( $_POST['post_password'] ) ), time() + 10 * DAY_IN_SECONDS, COOKIEPATH ); 400 400 401 401 wp_safe_redirect( wp_get_referer() ); … … 432 432 login_header(__('Lost Password'), '<p class="message">' . __('Please enter your username or email address. You will receive a link to create a new password via email.') . '</p>', $errors); 433 433 434 $user_login = isset($_POST['user_login']) ? stripslashes($_POST['user_login']) : '';434 $user_login = isset($_POST['user_login']) ? wp_unslash($_POST['user_login']) : ''; 435 435 436 436 ?> … … 531 531 $user_email = ''; 532 532 if ( $http_post ) { 533 $user_login = $_POST['user_login'];534 $user_email = $_POST['user_email'];533 $user_login = wp_unslash( $_POST['user_login'] ); 534 $user_email = wp_unslash( $_POST['user_email'] ); 535 535 $errors = register_new_user($user_login, $user_email); 536 536 if ( !is_wp_error($errors) ) { … … 548 548 <p> 549 549 <label for="user_login"><?php _e('Username') ?><br /> 550 <input type="text" name="user_login" id="user_login" class="input" value="<?php echo esc_attr( stripslashes($user_login)); ?>" size="20" /></label>550 <input type="text" name="user_login" id="user_login" class="input" value="<?php echo esc_attr( $user_login ); ?>" size="20" /></label> 551 551 </p> 552 552 <p> 553 553 <label for="user_email"><?php _e('E-mail') ?><br /> 554 <input type="text" name="user_email" id="user_email" class="input" value="<?php echo esc_attr( stripslashes($user_email)); ?>" size="25" /></label>554 <input type="text" name="user_email" id="user_email" class="input" value="<?php echo esc_attr( $user_email ); ?>" size="25" /></label> 555 555 </p> 556 556 <?php do_action('register_form'); ?> … … 674 674 675 675 if ( isset($_POST['log']) ) 676 $user_login = ( 'incorrect_password' == $errors->get_error_code() || 'empty_password' == $errors->get_error_code() ) ? esc_attr( stripslashes($_POST['log'])) : '';676 $user_login = ( 'incorrect_password' == $errors->get_error_code() || 'empty_password' == $errors->get_error_code() ) ? esc_attr( wp_unslash( $_POST['log'] ) ) : ''; 677 677 $rememberme = ! empty( $_POST['rememberme'] ); 678 678 ?>
Note: See TracChangeset
for help on using the changeset viewer.