Skip to content
Snippets Groups Projects
Commit 9a6a429f authored by Chris Hallberg's avatar Chris Hallberg
Browse files

More & href escapes.

parent 76aa4da7
Branches
Tags
No related merge requests found
......@@ -40,14 +40,14 @@
<div class="browse list-group col-sm-3<? if (!empty($this->resultList)): ?> hidden-xs<? endif ?>" id="list3">
<? foreach($this->secondaryList as $secondary): ?>
<? $url = $BROWSE_BASE . '?findby=' . urlencode($this->findby)
. '&category=' . urlencode($this->category)
. '&query=' . urlencode($secondary['value']);
. '&amp;category=' . urlencode($this->category)
. '&amp;query=' . urlencode($secondary['value']);
if ($this->facetPrefix) {
$url .= '&facet_prefix=' . urlencode($secondary['displayText']);
$url .= '&amp;facet_prefix=' . urlencode($secondary['displayText']);
}
if ($this->secondaryParams) {
foreach($this->secondaryParams as $var=>$val) {
$url .= '&' . $var .'=' . urlencode($val);
$url .= '&amp;' . $var .'=' . urlencode($val);
}
}
$viewRecord = !empty($this->categoryList) && $this->currentAction != 'Tag' && $this->findby != 'alphabetical';
......
......@@ -6,7 +6,7 @@
foreach (isset($filters['Other']) ? $filters['Other'] : array() as $filter) {
$filter['urlPart'] = $filter['field'] . ':' . $filter['value'];
$filterList[] = $filter;
$filterString .= '&' . urlencode('filter[]') . '=' . urlencode($filter['urlPart']);
$filterString .= '&amp;' . urlencode('filter[]') . '=' . urlencode($filter['urlPart']);
}
?>
......@@ -42,7 +42,7 @@
$removalUrl = $this->url('collections-home') . '?from=' . urlencode($from);
foreach ($filterList as $current) {
if ($current['urlPart'] != $filter['urlPart']) {
$removalUrl .= '&' . urlencode('filter[]') . '=' . urlencode($current['urlPart']);
$removalUrl .= '&amp;' . urlencode('filter[]') . '=' . urlencode($current['urlPart']);
}
}
?>
......
......@@ -53,8 +53,8 @@
<?
$url = $this->currentPath() . $this->escapeHtmlAttr(
'?inst=' . urlencode($record->getInstructorId())
. '&course=' . urlencode($record->getCourseId())
. '&dept=' . urlencode($record->getDepartmentId())
. '&amp;course=' . urlencode($record->getCourseId())
. '&amp;dept=' . urlencode($record->getDepartmentId())
);
?>
<tr>
......
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment