Make WordPress Core


Ignore:
Timestamp:
03/01/2013 04:28:40 PM (12 years ago)
Author:
ryan
Message:

Revert 23416, 23419, 23445 except for wp_reset_vars() changes. We are going a different direction with the slashing cleanup, so resetting to a clean slate. see #21767

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/user-new.php

    r23416 r23554  
    113113    } else {
    114114        // Adding a new user to this blog
    115         $user_details = wpmu_validate_user_signup( wp_unslash( $_REQUEST[ 'user_login' ] ), wp_unslash( $_REQUEST[ 'email' ] ) );
     115        $user_details = wpmu_validate_user_signup( $_REQUEST[ 'user_login' ], $_REQUEST[ 'email' ] );
    116116        if ( is_wp_error( $user_details[ 'errors' ] ) && !empty( $user_details[ 'errors' ]->errors ) ) {
    117117            $add_user_errors = $user_details[ 'errors' ];
    118118        } else {
    119             $new_user_login = apply_filters('pre_user_login', sanitize_user( wp_unslash( $_REQUEST['user_login'] ), true ) );
     119            $new_user_login = apply_filters('pre_user_login', sanitize_user(stripslashes($_REQUEST['user_login']), true));
    120120            if ( isset( $_POST[ 'noconfirmation' ] ) && is_super_admin() ) {
    121121                add_filter( 'wpmu_signup_user_notification', '__return_false' ); // Disable confirmation email
    122122            }
    123             wpmu_signup_user( $new_user_login, wp_unslash( $_REQUEST[ 'email' ] ), array( 'add_to_blog' => $wpdb->blogid, 'new_role' => $_REQUEST[ 'role' ] ) );
     123            wpmu_signup_user( $new_user_login, $_REQUEST[ 'email' ], array( 'add_to_blog' => $wpdb->blogid, 'new_role' => $_REQUEST[ 'role' ] ) );
    124124            if ( isset( $_POST[ 'noconfirmation' ] ) && is_super_admin() ) {
    125125                $key = $wpdb->get_var( $wpdb->prepare( "SELECT activation_key FROM {$wpdb->signups} WHERE user_login = %s AND user_email = %s", $new_user_login, $_REQUEST[ 'email' ] ) );
     
    310310    if( isset( $_POST['createuser'] ) ) {
    311311        if ( ! isset($$var) )
    312             $$var = isset( $_POST[$post_field] ) ? wp_unslash( $_POST[$post_field] ) : '';
     312            $$var = isset( $_POST[$post_field] ) ? stripslashes( $_POST[$post_field] ) : '';
    313313    } else {
    314314        $$var = false;
Note: See TracChangeset for help on using the changeset viewer.