From fbf05a159bc1a688940c16dc304eaaf140188b01 Mon Sep 17 00:00:00 2001 From: wei <> Date: Fri, 28 Jul 2006 07:56:03 +0000 Subject: Time-Tracker Demo: Escape html entities in output. --- .../protected/pages/TimeTracker/ReportResource.page | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) (limited to 'demos/time-tracker/protected/pages/TimeTracker/ReportResource.page') diff --git a/demos/time-tracker/protected/pages/TimeTracker/ReportResource.page b/demos/time-tracker/protected/pages/TimeTracker/ReportResource.page index 5e112505..e72fd0f2 100644 --- a/demos/time-tracker/protected/pages/TimeTracker/ReportResource.page +++ b/demos/time-tracker/protected/pages/TimeTracker/ReportResource.page @@ -31,9 +31,9 @@

Beginning Date

-

<%= $this->dateFrom->Date %>

+

<%= h($this->dateFrom->Date) %>

Ending Date

-

<%= $this->dateTo->Date %>

+

<%= h($this->dateTo->Date) %>

@@ -43,8 +43,8 @@ Total Hours - <%# $this->DataItem->Username %> - <%# $this->DataItem->TotalHours %> + <%# h($this->DataItem->Username) %> + <%# h($this->DataItem->TotalHours) %> @@ -68,10 +68,10 @@ Pattern="dd/MM/yyyy" Value=<%# $this->DataItem->ReportDate %> /> - <%# $this->DataItem->ProjectName %> - <%# $this->DataItem->CategoryName %> - <%# $this->DataItem->Duration %> - <%# $this->DataItem->Description %> + <%# h($this->DataItem->ProjectName) %> + <%# h($this->DataItem->CategoryName) %> + <%# h($this->DataItem->Duration) %> + <%# h($this->DataItem->Description) %> -- cgit v1.2.3