WordPress.org

Make WordPress Core


Ignore:
File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/2.6/wp-admin/includes/media.php

    r8607 r9077  
    619619            'html'       => "
    620620                <input type='text' name='attachments[$post->ID][url]' value='" . attribute_escape($file) . "' /><br />
    621                 <button type='button' class='button url-$post->ID' value=''>" . __('None') . "</button>
    622                 <button type='button' class='button url-$post->ID' value='" . attribute_escape($file) . "'>" . __('File URL') . "</button>
    623                 <button type='button' class='button url-$post->ID' value='" . attribute_escape($link) . "'>" . __('Post URL') . "</button>
     621                <button type='button' class='button url-$post->ID' title=''>" . __('None') . "</button>
     622                <button type='button' class='button url-$post->ID' title='" . attribute_escape($file) . "'>" . __('File URL') . "</button>
     623                <button type='button' class='button url-$post->ID' title='" . attribute_escape($link) . "'>" . __('Post URL') . "</button>
    624624                <script type='text/javascript'>
    625                 jQuery('button.url-$post->ID').bind('click', function(){jQuery(this).siblings('input').val(this.value);});
     625                jQuery('button.url-$post->ID').bind('click', function(){jQuery(this).siblings('input').val(jQuery(this).attr('title'));});
    626626                </script>\n",
    627627            'helps'      => __('Enter a link URL or click above for presets.'),
     
    814814            $item .= $field[$field['input']];
    815815        elseif ( $field['input'] == 'textarea' ) {
    816             $item .= "<textarea type='text' id='$name' name='$name'>" . attribute_escape( $field['value'] ) . $aria_required . "</textarea>";
     816            $item .= "<textarea type='text' id='$name' name='$name'" . $aria_required . ">" . htmlspecialchars( $field['value'] ) . "</textarea>";
    817817        } else {
    818818            $item .= "<input type='text' id='$name' name='$name' value='" . attribute_escape( $field['value'] ) . "'" . $aria_required . "/>";
Note: See TracChangeset for help on using the changeset viewer.