diff options
author | marcus <marcus@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2008-08-15 14:56:27 +0000 |
---|---|---|
committer | marcus <marcus@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2008-08-15 14:56:27 +0000 |
commit | 3c01acacc0e8a4794f2b925bda80632334fb3ab4 (patch) | |
tree | 59c0b5e1ddb0162f3b48abe71b15c39d0f0b3ca2 /views/failsafe/input/button.php | |
parent | 5c236cb446b8c3344ed668096f37a136ab02ae0d (diff) | |
download | elgg-3c01acacc0e8a4794f2b925bda80632334fb3ab4.tar.gz elgg-3c01acacc0e8a4794f2b925bda80632334fb3ab4.tar.bz2 |
Closes #224: Install now using failsafe views. Please test from scratch (including blanking setup) and make sure it works for you!
git-svn-id: https://code.elgg.org/elgg/trunk@1940 36083f99-b078-4883-b0ff-0f9b5a30f544
Diffstat (limited to 'views/failsafe/input/button.php')
-rw-r--r-- | views/failsafe/input/button.php | 41 |
1 files changed, 41 insertions, 0 deletions
diff --git a/views/failsafe/input/button.php b/views/failsafe/input/button.php new file mode 100644 index 000000000..9a72f38b0 --- /dev/null +++ b/views/failsafe/input/button.php @@ -0,0 +1,41 @@ +<?php + /** + * Create a input button + * Use this view for forms rather than creating a submit/reset button tag in the wild as it provides + * extra security which help prevent CSRF attacks. + * + * @package Elgg + * @subpackage Core + * @license http://www.gnu.org/licenses/old-licenses/gpl-2.0.html GNU Public License version 2 + * @author Curverider Ltd + * @copyright Curverider Ltd 2008 + * @link http://elgg.org/ + * + * @uses $vars['value'] The current value, if any + * @uses $vars['js'] Any Javascript to enter into the input tag + * @uses $vars['internalname'] The name of the input field + * @uses $vars['type'] Submit or reset, defaults to submit. + * @uses $vars['src'] Src of an image + * + */ + + global $CONFIG; + + $class = $vars['class']; + if (!$class) $class = "submit_button"; + + if (isset($vars['type'])) { $type = strtolower($vars['type']); } else { $type = 'submit'; } + switch ($type) + { + case 'button' : $type='button'; break; + case 'reset' : $type='reset'; break; + case 'submit': + default: $type = 'submit'; + } + + $value = htmlentities($vars['value'], null, 'UTF-8'); + $name = $vars['internalname']; + $src = $vars['src']; + if (strpos($src,$CONFIG->wwwroot)===false) $src = ""; // blank src if trying to access an offsite image. +?> +<input type="<?php echo $type; ?>" class="<?php echo $type; ?>_button" <?php echo $vars['js']; ?> value="<?php echo $value; ?>" src="<?php echo $src; ?>" class="<?php echo $class; ?>" />
\ No newline at end of file |