Skip to:
Content

bbPress.org

Changeset 4977


Ignore:
Timestamp:
05/30/2013 10:52:32 PM (13 years ago)
Author:
johnjamesjacoby
Message:

Remove esc_attr() from bbp_get_displayed_user_field(), and practice late escaping where appropriate instead. See #4959.

Location:
trunk
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/includes/users/template-tags.php

    r4958 r4977  
    135135        // Return field if exists
    136136        if ( isset( $bbp->displayed_user->$field ) )
    137             $value = esc_attr( sanitize_text_field( $bbp->displayed_user->$field ) );
     137            $value = sanitize_text_field( $bbp->displayed_user->$field );
    138138
    139139        // Return empty
  • trunk/templates/default/bbpress/user-details.php

    r4948 r4977  
    1616
    1717            <span class='vcard'>
    18                 <a class="url fn n" href="<?php bbp_user_profile_url(); ?>" title="<?php bbp_displayed_user_field( 'display_name' ); ?>" rel="me">
     18                <a class="url fn n" href="<?php bbp_user_profile_url(); ?>" title="<?php echo esc_attr( bbp_get_displayed_user_field( 'display_name' ) ); ?>" rel="me">
    1919                    <?php echo get_avatar( bbp_get_displayed_user_field( 'user_email' ), apply_filters( 'bbp_single_user_details_avatar_size', 150 ) ); ?>
    2020                </a>
     
    2727                <li class="<?php if ( bbp_is_single_user_profile() ) :?>current<?php endif; ?>">
    2828                    <span class="vcard bbp-user-profile-link">
    29                         <a class="url fn n" href="<?php bbp_user_profile_url(); ?>" title="<?php printf( esc_attr__( "%s's Profile", 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>" rel="me"><?php _e( 'Profile', 'bbpress' ); ?></a>
     29                        <a class="url fn n" href="<?php bbp_user_profile_url(); ?>" title="<?php printf( esc_attr__( "%s's Profile", 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>" rel="me"><?php _e( 'Profile', 'bbpress' ); ?></a>
    3030                    </span>
    3131                </li>
     
    3333                <li class="<?php if ( bbp_is_single_user_topics() ) :?>current<?php endif; ?>">
    3434                    <span class='bbp-user-topics-created-link'>
    35                         <a href="<?php bbp_user_topics_created_url(); ?>" title="<?php printf( esc_attr__( "%s's Topics Started", 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>"><?php _e( 'Topics Started', 'bbpress' ); ?></a>
     35                        <a href="<?php bbp_user_topics_created_url(); ?>" title="<?php printf( esc_attr__( "%s's Topics Started", 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>"><?php _e( 'Topics Started', 'bbpress' ); ?></a>
    3636                    </span>
    3737                </li>
     
    3939                <li class="<?php if ( bbp_is_single_user_replies() ) :?>current<?php endif; ?>">
    4040                    <span class='bbp-user-replies-created-link'>
    41                         <a href="<?php bbp_user_replies_created_url(); ?>" title="<?php printf( esc_attr__( "%s's Replies Created", 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>"><?php _e( 'Replies Created', 'bbpress' ); ?></a>
     41                        <a href="<?php bbp_user_replies_created_url(); ?>" title="<?php printf( esc_attr__( "%s's Replies Created", 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>"><?php _e( 'Replies Created', 'bbpress' ); ?></a>
    4242                    </span>
    4343                </li>
     
    4646                    <li class="<?php if ( bbp_is_favorites() ) :?>current<?php endif; ?>">
    4747                        <span class="bbp-user-favorites-link">
    48                             <a href="<?php bbp_favorites_permalink(); ?>" title="<?php printf( esc_attr__( "%s's Favorites", 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>"><?php _e( 'Favorites', 'bbpress' ); ?></a>
     48                            <a href="<?php bbp_favorites_permalink(); ?>" title="<?php printf( esc_attr__( "%s's Favorites", 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>"><?php _e( 'Favorites', 'bbpress' ); ?></a>
    4949                        </span>
    5050                    </li>
     
    5656                        <li class="<?php if ( bbp_is_subscriptions() ) :?>current<?php endif; ?>">
    5757                            <span class="bbp-user-subscriptions-link">
    58                                 <a href="<?php bbp_subscriptions_permalink(); ?>" title="<?php printf( esc_attr__( "%s's Subscriptions", 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>"><?php _e( 'Subscriptions', 'bbpress' ); ?></a>
     58                                <a href="<?php bbp_subscriptions_permalink(); ?>" title="<?php printf( esc_attr__( "%s's Subscriptions", 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>"><?php _e( 'Subscriptions', 'bbpress' ); ?></a>
    5959                            </span>
    6060                        </li>
     
    6363                    <li class="<?php if ( bbp_is_single_user_edit() ) :?>current<?php endif; ?>">
    6464                        <span class="bbp-user-edit-link">
    65                             <a href="<?php bbp_user_profile_edit_url(); ?>" title="<?php printf( esc_attr__( 'Edit Profile of User %s', 'bbpress' ), bbp_get_displayed_user_field( 'display_name' ) ); ?>"><?php _e( 'Edit', 'bbpress' ); ?></a>
     65                            <a href="<?php bbp_user_profile_edit_url(); ?>" title="<?php printf( esc_attr__( 'Edit Profile of User %s', 'bbpress' ), esc_attr( bbp_get_displayed_user_field( 'display_name' ) ) ); ?>"><?php _e( 'Edit', 'bbpress' ); ?></a>
    6666                        </span>
    6767                    </li>
Note: See TracChangeset for help on using the changeset viewer.