MantisBT - Piwigo
View Issue Details
0002297Piwigodisplaypublic2011.05.04 23:412011.05.12 15:13
LucMorizur 
flop25 
normaltweakalways
closedfixed 
AnyAny
2.2.1 
2.2.22.2.2 
any
Apache 1.3.x
0002297: Stripslashes() missing sometimes to display username
When adding user « Test d'apostrophe », the information message says: « User "Test d\'apostrophe" added » (see attached picture).

The same issue occurs for the comment author name (at least, maybe is there some other occurrences of this issue), but there it is more complex and I don't know how to solve it.
Add a user with characters that should be escaped in the DB
From line 232 of admin/user_list.php:

    if (count($page['errors']) == 0)
    {
      array_push(
        $page['infos'],
        sprintf(
          l10n('user "%s" added'),
          stripslashes($_POST['login'])
          )
        );
    }

The stripslashes() must be added on line 238.
No tags attached.
png screen_copy.png (6,511) 2011.05.04 23:41
http://piwigo.org/bugs/file_download.php?file_id=135&type=bug
png
Issue History
2011.05.04 23:41LucMorizurNew Issue
2011.05.04 23:41LucMorizurFile Added: screen_copy.png
2011.05.04 23:41LucMorizurbrowser => any
2011.05.04 23:41LucMorizurWeb server => Apache 1.3.x
2011.05.12 15:08svnCheckin
2011.05.12 15:08svnNote Added: 0005094
2011.05.12 15:11svnCheckin
2011.05.12 15:11svnNote Added: 0005095
2011.05.12 15:13flop25Assigned To => flop25
2011.05.12 15:13flop25Statusnew => closed
2011.05.12 15:13flop25Resolutionopen => fixed
2011.05.12 15:13flop25Fixed in Version => 2.2.2
2011.05.12 15:13flop25Target Version => 2.2.2

Notes
(0005094)
svn   
2011.05.12 15:08   
[Subversion] r10856 by flop25 on trunk

-----[Subversion commit log]----------------------------------------------------
bug:2297
stripslashes added
(0005095)
svn   
2011.05.12 15:11   
[Subversion] r10857 by flop25 on branch 2.2

-----[Subversion commit log]----------------------------------------------------
merge r10856 from trunk to branch 2.2
bug:2297
stripslashes added