Make WordPress Core


Ignore:
Timestamp:
03/03/2013 04:30:38 PM (12 years ago)
Author:
ryan
Message:

Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes().

see #WP21767

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/user-new.php

    r23554 r23591  
    117117            $add_user_errors = $user_details[ 'errors' ];
    118118        } else {
    119             $new_user_login = apply_filters('pre_user_login', sanitize_user(stripslashes($_REQUEST['user_login']), true));
     119            $new_user_login = apply_filters('pre_user_login', sanitize_user(wp_unslash($_REQUEST['user_login']), true));
    120120            if ( isset( $_POST[ 'noconfirmation' ] ) && is_super_admin() ) {
    121121                add_filter( 'wpmu_signup_user_notification', '__return_false' ); // Disable confirmation email
     
    310310    if( isset( $_POST['createuser'] ) ) {
    311311        if ( ! isset($$var) )
    312             $$var = isset( $_POST[$post_field] ) ? stripslashes( $_POST[$post_field] ) : '';
     312            $$var = isset( $_POST[$post_field] ) ? wp_unslash( $_POST[$post_field] ) : '';
    313313    } else {
    314314        $$var = false;
Note: See TracChangeset for help on using the changeset viewer.