Commit Graph

3199 Commits

Author SHA1 Message Date
Brian Miyaji
52a074b586 Tag version 2.7.9 2021-11-06 20:37:55 +09:00
Brian Miyaji
0836c2465b Add missing escapes 2021-11-06 20:25:32 +09:00
Brian Miyaji
f2ded7b97a Escape outputs in core functions 2021-11-06 20:16:48 +09:00
Brian Miyaji
bb597b2658 Replace settings outputs with suitable escape functions 2021-11-06 20:04:07 +09:00
Brian Miyaji
fa8e3fdd73 Replace meta box outputs with suitable escape functions 2021-11-06 19:57:44 +09:00
Brian Miyaji
e2ab124b9d Merge branch 'master' of github.com:ThemeBoy/SportsPress 2021-11-06 19:44:15 +09:00
Brian Miyaji
ac70c3813f Replace with most suitable escape functions 2021-11-06 19:43:54 +09:00
savvasha
93cd99d5d7 Escape Include files vars (#1) 2021-11-06 12:38:37 +02:00
savvasha
e24a9fa4eb Escape output vars of includes files (#1) 2021-11-06 12:34:49 +02:00
Brian Miyaji
c87764cc02 Escape outputs on modules admin page 2021-11-06 19:14:57 +09:00
Brian Miyaji
b8d79e040d Escape output in admin ajax 2021-11-06 19:08:36 +09:00
Brian Miyaji
8be366b70d Escape output in template functions 2021-11-06 19:08:25 +09:00
Brian Miyaji
f07f42b5c9 Sanitize instead of escape inputs 2021-11-06 19:03:26 +09:00
savvasha
0c9a9dc104 Escape output vars of Admin Settings pages 2021-11-06 09:19:11 +02:00
savvasha
54eeca28e8 Escape output vars from admin meta-boxes (#3) 2021-11-06 08:59:30 +02:00
savvasha
6a29c3b1ee Escape output vars from admin meta-boxes (#2) 2021-11-06 08:48:09 +02:00
Brian Miyaji
b5427bd302 Add sanitization to config variable meta boxes 2021-11-06 11:34:57 +09:00
Brian Miyaji
a004ff7ebf Escape config links in admin 2021-11-06 11:30:53 +09:00
Brian Miyaji
bb6c518eda Sanitize staff meta boxes 2021-11-06 11:20:46 +09:00
Brian Miyaji
1d77800c18 Add sanitization to player list meta boxes 2021-11-06 11:18:31 +09:00
Brian Miyaji
11d03aa136 Add sanitization to taxonomies 2021-11-06 11:11:29 +09:00
Brian Miyaji
ff47d1976b Add sanitization to player meta boxes 2021-11-06 11:07:36 +09:00
Brian Miyaji
fe849389d3 Add sanitization to league table meta boxes 2021-11-06 10:53:08 +09:00
savvasha
02b2dd8f93 Merge branch 'master' of github.com:ThemeBoy/SportsPress 2021-11-05 17:57:21 +02:00
savvasha
696670e5d5 Escape output vars from admin meta-boxes (#1) 2021-11-05 17:56:58 +02:00
Brian Miyaji
e09a73a8b8 Merge branch 'master' of github.com:ThemeBoy/SportsPress 2021-11-06 00:52:30 +09:00
Brian Miyaji
8f075ccf98 Add sanitization to team meta boxes 2021-11-06 00:52:16 +09:00
Brian Miyaji
f84beeb71a Fix warning when viewing template order for the first time 2021-11-06 00:51:55 +09:00
Brian Miyaji
8f1becc68f Sanitization should be key 2021-11-06 00:51:32 +09:00
savvasha
04736f1765 Escape output of vars in SPEC, STAFF and STATISTIC Admin Classes 2021-11-05 17:38:40 +02:00
Brian Miyaji
39cf8f9662 Add sanitization to event meta boxes 2021-11-06 00:27:35 +09:00
Brian Miyaji
1baf375882 Fix sanitize title filter 2021-11-06 00:27:00 +09:00
Brian Miyaji
bf0e91919a Make sp_array_value map recursively for multidimensional arrays 2021-11-05 23:56:41 +09:00
Brian Miyaji
f7ed06dddc Sanitize calendar inputs using sp_array_value sanitization 2021-11-05 23:49:09 +09:00
Brian Miyaji
1554ac0d0e Sanitize calendar inputs 2021-11-05 23:44:00 +09:00
Brian Miyaji
f55c0cbd7c Sanitize input fields in setup wizard 2021-11-05 23:33:24 +09:00
Brian Miyaji
f3ee15c627 Sanitize importer delimiter 2021-11-05 22:24:22 +09:00
Brian Miyaji
9ca0c195c4 Sanitize user registration fields 2021-11-05 22:24:14 +09:00
Brian Miyaji
0a4b6726df Sanitize license key inputs 2021-11-05 22:24:05 +09:00
Brian Miyaji
9a35699d78 Sanitize tab key in tutorials 2021-11-05 22:23:56 +09:00
Brian Miyaji
47d62a9a81 Sanitize sport and timezone in general settings 2021-11-05 22:15:32 +09:00
Savvas Hadjigeorgiou
0739ef53dc Escape several vars on Admin Classes 2021-11-05 14:05:55 +02:00
Savvas Hadjigeorgiou
8c5f7f4dd8 Escape vars on SP_Admin_CPT_Calendar Class 2021-11-05 13:58:59 +02:00
Savvas Hadjigeorgiou
80795b5731 Escape vars on Importer Main Class 2021-11-05 13:51:34 +02:00
Savvas Hadjigeorgiou
630e913fa7 Escape vars on Event Performance Importer 2021-11-05 13:50:50 +02:00
Savvas Hadjigeorgiou
9f56144f50 Escape vars on Event Importer 2021-11-05 13:49:35 +02:00
Savvas Hadjigeorgiou
bdec9848d5 Escape Credits screen 2021-11-05 13:48:27 +02:00
Savvas Hadjigeorgiou
82dc48317c We should not be escaping when we build a variable, but when we output it at the end. We call this 'escaping late.' 2021-11-05 13:42:23 +02:00
Savvas Hadjigeorgiou
8074b59639 Escape outputp vars on Setup Wizard page 2021-11-05 13:38:15 +02:00
Savvas Hadjigeorgiou
4841d5948b Escape several output vars at Admin Settings page 2021-11-05 13:21:58 +02:00