[TYPO3-core] Reminder - bug: 0000132: Incorrect handling of %-signin FORM.params

rupert germann rupi at gmx.li
Sat Apr 29 10:16:06 CEST 2006


On Friday 28 April 2006 20:44, Martin Kutschker wrote:
> +1 if you move the str_replace after the if-clause in the diff. Your patch
> only escapes FORM.params but not FORM.params.<type>.

you're absolutely right, thanks for the hint.

> I have attached a new version of it. A bit hard to read because I changed
> the formatting as well. Basically I have moved the str_replace so that it
> gets called only when $addParams is not empty.

works fine for me. I will add some {} around the 
$addParams=' '.str_replace('%','%%', $addParams); line when I commit it.

another +1?

greets
rupert
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.netfielders.de/pipermail/typo3-team-core/attachments/20060429/688daa90/attachment.pgp 


More information about the TYPO3-team-core mailing list