Add option to escape PMA_sanitize output.
This is required when it is used in form values.
This commit is contained in:
@@ -17,7 +17,7 @@
|
||||
*
|
||||
* @access public
|
||||
*/
|
||||
function PMA_sanitize($message)
|
||||
function PMA_sanitize($message, $escape = false)
|
||||
{
|
||||
$replace_pairs = array(
|
||||
'<' => '<',
|
||||
@@ -65,6 +65,10 @@ function PMA_sanitize($message)
|
||||
$message = preg_replace($pattern, '<a href="\1" target="\2">', $message);
|
||||
}
|
||||
|
||||
if ($escape) {
|
||||
$message = htmlspecialchars($message);
|
||||
}
|
||||
|
||||
return $message;
|
||||
}
|
||||
?>
|
||||
|
Reference in New Issue
Block a user