@@ -43,11 +43,11 @@ function onShow() {
4343
4444 $ pluginTpl = new tpl ;
4545 $ pluginTpl ->newTemplate ('templates/system_config_dns_ca_edit.htm ' );
46- include 'lib/lang/ ' .$ _SESSION ['s ' ]['language ' ].'_system_config.lng ' ;
46+ include 'lib/lang/ ' .$ app -> functions -> check_language ( $ _SESSION ['s ' ]['language ' ]) .'_system_config.lng ' ;
4747 $ pluginTpl ->setVar ($ wb );
48- if (isset ($ _GET ['action ' ]) && ($ _GET ['action ' ] == 'edit ' ) && $ _GET ['id ' ] > 0 ) {
48+ $ ca_id = $ app ->functions ->intval ($ _GET ['id ' ]);
49+ if (isset ($ _GET ['action ' ]) && ($ _GET ['action ' ] == 'edit ' ) && $ ca_id > 0 ) {
4950 $ pluginTpl ->setVar ('edit_record ' , 1 );
50- $ ca_id = intval ($ _GET ['id ' ]);
5151 $ rec = $ app ->db ->queryOneRecord ("SELECT * FROM dns_ssl_ca WHERE id = ? " , $ ca_id );
5252 $ pluginTpl ->setVar ('id ' , $ rec ['id ' ]);
5353 $ pluginTpl ->setVar ('ca_name ' , $ rec ['ca_name ' ]);
@@ -56,16 +56,15 @@ function onShow() {
5656 $ pluginTpl ->setVar ('ca_critical ' , $ rec ['ca_critical ' ]);
5757 $ pluginTpl ->setVar ('ca_iodef ' , $ rec ['ca_iodef ' ]);
5858 $ pluginTpl ->setVar ('active ' , $ rec ['active ' ]);
59- } elseif (isset ($ _GET ['action ' ]) && ($ _GET ['action ' ] == 'save ' ) && $ _GET [ ' id ' ] > 0 ) {
59+ } elseif (isset ($ _GET ['action ' ]) && ($ _GET ['action ' ] == 'save ' ) && $ ca_id > 0 ) {
6060 $ pluginTpl ->setVar ('edit_record ' , 0 );
61- $ ca_id = intval ($ _GET ['id ' ]);
6261 $ pluginTpl ->setVar ('id ' , $ ca_id );
63- $ pluginTpl ->setVar ('ca_name ' , $ _POST ['ca_name ' ]);
64- $ pluginTpl ->setVar ('ca_issue ' , $ _POST ['ca_issue ' ]);
65- $ pluginTpl ->setVar ('ca_wildcard ' , $ _POST ['ca_wildcard ' ]);
66- $ pluginTpl ->setVar ('ca_critical ' , $ _POST ['ca_critical ' ]);
67- $ pluginTpl ->setVar ('ca_iodef ' , $ _POST ['ca_iodef ' ]);
68- $ pluginTpl ->setVar ('active ' , $ _POST ['active ' ]);
62+ $ pluginTpl ->setVar ('ca_name ' , $ app -> functions -> htmlentities ( $ _POST ['ca_name ' ]) );
63+ $ pluginTpl ->setVar ('ca_issue ' , $ app -> functions -> htmlentities ( $ _POST ['ca_issue ' ]) );
64+ $ pluginTpl ->setVar ('ca_wildcard ' , $ app -> functions -> htmlentities ( $ _POST ['ca_wildcard ' ]) );
65+ $ pluginTpl ->setVar ('ca_critical ' , $ app -> functions -> htmlentities ( $ _POST ['ca_critical ' ]) );
66+ $ pluginTpl ->setVar ('ca_iodef ' , $ app -> functions -> htmlentities ( $ _POST ['ca_iodef ' ]) );
67+ $ pluginTpl ->setVar ('active ' , $ app -> functions -> htmlentities ( $ _POST ['active ' ]) );
6968 } else {
7069 $ pluginTpl ->setVar ('edit_record ' , 0 );
7170 }
@@ -77,10 +76,10 @@ function onShow() {
7776 function onUpdate () {
7877 global $ app ;
7978
80- $ id = intval ($ _GET ['id ' ]);
79+ $ ca_id = $ app -> functions -> intval ($ _GET ['id ' ]);
8180 if (isset ($ _GET ['action ' ]) && $ _GET ['action ' ] == 'save ' ) {
82- if ($ id > 0 ) {
83- $ app ->db ->query ("UPDATE dns_ssl_ca SET ca_name = ?, ca_issue = ?, ca_wildcard = ?, ca_iodef = ?, active = ? WHERE id = ? " , $ _POST ['ca_name ' ], $ _POST ['ca_issue ' ], $ _POST ['ca_wildcard ' ], $ _POST ['ca_iodef ' ], $ _POST ['active ' ], $ _GET [ ' id ' ] );
81+ if ($ ca_id > 0 ) {
82+ $ app ->db ->query ("UPDATE dns_ssl_ca SET ca_name = ?, ca_issue = ?, ca_wildcard = ?, ca_iodef = ?, active = ? WHERE id = ? " , $ _POST ['ca_name ' ], $ _POST ['ca_issue ' ], $ _POST ['ca_wildcard ' ], $ _POST ['ca_iodef ' ], $ _POST ['active ' ], $ ca_id );
8483 } else {
8584 $ app ->db ->query ("INSERT INTO (sys_userid, sys_groupid, sys_perm_user, sys_perm_group, sys_perm_other, ca_name, ca_issue, ca_wildcard, ca_iodef, active) VALUES(1, 1, 'riud', 'riud', '', ?, ?, ?, ?, ? " , $ _POST ['ca_name ' ], $ _POST ['ca_issue ' ], $ _POST ['ca_wildcard ' ], $ _POST ['ca_iodef ' ], $ _POST ['active ' ]);
8685 }
0 commit comments