Skip to content

Commit 3bc1d17

Browse files
committed
missed a spot
1 parent 3205170 commit 3bc1d17

File tree

1 file changed

+8
-7
lines changed

1 file changed

+8
-7
lines changed

webroot/panel/groups.php

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -98,19 +98,20 @@
9898
$WEBHOOK
9999
);
100100
$requested_owner = $requested_account->getOwner();
101-
$full_name = $requested_owner->getFirstname() . " " . $requested_owner->getLastname();
101+
$gecos = htmlspecialchars($requested_owner->getFullname());
102102
$mail_link = "mailto:" . urlencode($requested_owner->getMail());
103103
$mail_display = htmlspecialchars($requested_owner->getMail());
104+
$gid = htmlspecialchars($requested_account->gid);
104105
echo "<tr class='pending_request'>";
105-
echo "<td>$full_name</td>";
106+
echo "<td>$gecos</td>";
106107
echo "<td>" . $requested_account->gid . "</td>";
107108
echo "<td><a href='$mail_link'>$mail_display</a></td>";
108109
echo "<td>" . date("jS F, Y", strtotime($request['timestamp'])) . "</td>";
109110
echo "<td>";
110111
$CSRFTokenHiddenFormInput = UnityHTTPD::getCSRFTokenHiddenFormInput();
111112
echo "<form action='' method='POST' id='cancelPI'>
112113
$CSRFTokenHiddenFormInput
113-
<input type='hidden' name='pi' value='{$requested_account->gid}'>
114+
<input type='hidden' name='pi' value='{$gid}'>
114115
<input type='hidden' name='form_type' value='cancelPIForm'>
115116
<input name='cancel' style='margin-top: 10px;' type='submit' value='Cancel Request'/>
116117
</form>";
@@ -151,21 +152,21 @@
151152
continue;
152153
}
153154
$gecos = htmlspecialchars($owner->getFullname());
154-
$gid = htmlspecialchars($group->gid);
155+
$gid_escaped = htmlspecialchars($group->gid);
155156
$mail_link = "mailto:" . urlencode($owner->getMail());
156157
$mail_display = htmlspecialchars($owner->getMail());
157158
echo "<tr class='expandable'>";
158159
echo "<td><button class='btnExpand'>&#9654;</button>$gecos</td>";
159-
echo "<td>$gid</td>";
160+
echo "<td>$gid_escaped</td>";
160161
echo "<td><a href='$mail_link'>$mail_display</a></td>";
161162
$CSRFTokenHiddenFormInput = UnityHTTPD::getCSRFTokenHiddenFormInput();
162163
echo
163164
"<td>
164165
<form action='' method='POST'
165-
onsubmit='return confirm(\"Are you sure you want to leave the PI group " . $gid . "?\")'>
166+
onsubmit='return confirm(\"Are you sure you want to leave the PI group $gid_escaped?\")'>
166167
$CSRFTokenHiddenFormInput
167168
<input type='hidden' name='form_type' value='removePIForm'>
168-
<input type='hidden' name='pi' value='" . $gid . "'>
169+
<input type='hidden' name='pi' value='$gid_escaped'>
169170
<input type='submit' value='Leave Group'>
170171
</form>
171172
</td>";

0 commit comments

Comments
 (0)