aboutsummaryrefslogtreecommitdiff
path: root/views/installation/input/form.php
diff options
context:
space:
mode:
authorcash <cash@36083f99-b078-4883-b0ff-0f9b5a30f544>2010-10-05 10:53:40 +0000
committercash <cash@36083f99-b078-4883-b0ff-0f9b5a30f544>2010-10-05 10:53:40 +0000
commit7f01270ba106937300cf491927839d3428360d0a (patch)
tree589b179f84b2fb8d8c229099d0b9f6d3ece682ea /views/installation/input/form.php
parentf1c75074c96f8c8f144bc132f75443dd8502c440 (diff)
downloadelgg-7f01270ba106937300cf491927839d3428360d0a.tar.gz
elgg-7f01270ba106937300cf491927839d3428360d0a.tar.bz2
moved installation to its own viewtype
git-svn-id: http://code.elgg.org/elgg/trunk@7010 36083f99-b078-4883-b0ff-0f9b5a30f544
Diffstat (limited to 'views/installation/input/form.php')
-rw-r--r--views/installation/input/form.php53
1 files changed, 53 insertions, 0 deletions
diff --git a/views/installation/input/form.php b/views/installation/input/form.php
new file mode 100644
index 000000000..35e718adb
--- /dev/null
+++ b/views/installation/input/form.php
@@ -0,0 +1,53 @@
+<?php
+/**
+ * Create a form for data submission.
+ * Use this view for forms rather than creating a form tag in the wild as it provides
+ * extra security which help prevent CSRF attacks.
+ *
+ * @package Elgg
+ * @subpackage Core
+ * @author Curverider Ltd
+ * @link http://elgg.org/
+ *
+ * @uses $vars['body'] The body of the form (made up of other input/xxx views and html
+ * @uses $vars['method'] Method (default POST)
+ * @uses $vars['enctype'] How the form is encoded, default blank
+ * @uses $vars['action'] URL of the action being called
+ *
+ */
+
+if (isset($vars['internalid'])) {
+ $id = $vars['internalid'];
+} else {
+ $id = '';
+}
+if (isset($vars['internalname'])) {
+ $name = $vars['internalname'];
+} else {
+ $name = '';
+}
+$body = $vars['body'];
+$action = $vars['action'];
+if (isset($vars['enctype'])) {
+ $enctype = $vars['enctype'];
+} else {
+ $enctype = '';
+}
+if (isset($vars['method'])) {
+ $method = $vars['method'];
+} else {
+ $method = 'POST';
+}
+
+$method = strtolower($method);
+
+// Generate a security header
+$security_header = "";
+if (!isset($vars['disable_security']) || $vars['disable_security'] != true) {
+ $security_header = elgg_view('input/securitytoken');
+}
+?>
+<form <?php if ($id) { ?>id="<?php echo $id; ?>" <?php } ?> <?php if ($name) { ?>name="<?php echo $name; ?>" <?php } ?> action="<?php echo $action; ?>" method="<?php echo $method; ?>" <?php if ($enctype!="") echo "enctype=\"$enctype\""; ?>>
+<?php echo $security_header; ?>
+<?php echo $body; ?>
+</form> \ No newline at end of file