Skip to:
Content

bbPress.org

Changeset 6819


Ignore:
Timestamp:
05/14/2018 08:42:23 PM (8 years ago)
Author:
johnjamesjacoby
Message:

Prefer sanitize_html_class() over esc_attr().

This change uses the correct formatting function in places where potentially untrusted class strings are ran through array_map().

Location:
trunk/src/includes
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/includes/admin/classes/class-bbp-admin.php

    r6780 r6819  
    341341
    342342        // Assemble the message
    343         $message = '<div id="message" class="notice ' . implode( ' ', array_map( 'esc_attr', $classes ) ) . '">' . $message . '</div>';
     343        $message = '<div id="message" class="notice ' . implode( ' ', array_map( 'sanitize_html_class', $classes ) ) . '">' . $message . '</div>';
    344344        $message = str_replace( "'", "\'", $message );
    345345
  • trunk/src/includes/forums/template.php

    r6774 r6819  
    754754
    755755        // This could use bbp_get_forum_class() eventually...
    756         $subforum_classes_attr = 'class="' . implode( ' ', array_map( 'esc_attr', $subforum_classes ) ) . '"';
     756        $subforum_classes_attr = 'class="' . implode( ' ', array_map( 'sanitize_html_class', $subforum_classes ) ) . '"';
    757757
    758758        // Build this sub forums link
Note: See TracChangeset for help on using the changeset viewer.