diff options
author | cash <cash@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2010-10-05 10:53:40 +0000 |
---|---|---|
committer | cash <cash@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2010-10-05 10:53:40 +0000 |
commit | 7f01270ba106937300cf491927839d3428360d0a (patch) | |
tree | 589b179f84b2fb8d8c229099d0b9f6d3ece682ea /views/installation/input/form.php | |
parent | f1c75074c96f8c8f144bc132f75443dd8502c440 (diff) | |
download | elgg-7f01270ba106937300cf491927839d3428360d0a.tar.gz elgg-7f01270ba106937300cf491927839d3428360d0a.tar.bz2 |
moved installation to its own viewtype
git-svn-id: http://code.elgg.org/elgg/trunk@7010 36083f99-b078-4883-b0ff-0f9b5a30f544
Diffstat (limited to 'views/installation/input/form.php')
-rw-r--r-- | views/installation/input/form.php | 53 |
1 files changed, 53 insertions, 0 deletions
diff --git a/views/installation/input/form.php b/views/installation/input/form.php new file mode 100644 index 000000000..35e718adb --- /dev/null +++ b/views/installation/input/form.php @@ -0,0 +1,53 @@ +<?php +/** + * Create a form for data submission. + * Use this view for forms rather than creating a form tag in the wild as it provides + * extra security which help prevent CSRF attacks. + * + * @package Elgg + * @subpackage Core + * @author Curverider Ltd + * @link http://elgg.org/ + * + * @uses $vars['body'] The body of the form (made up of other input/xxx views and html + * @uses $vars['method'] Method (default POST) + * @uses $vars['enctype'] How the form is encoded, default blank + * @uses $vars['action'] URL of the action being called + * + */ + +if (isset($vars['internalid'])) { + $id = $vars['internalid']; +} else { + $id = ''; +} +if (isset($vars['internalname'])) { + $name = $vars['internalname']; +} else { + $name = ''; +} +$body = $vars['body']; +$action = $vars['action']; +if (isset($vars['enctype'])) { + $enctype = $vars['enctype']; +} else { + $enctype = ''; +} +if (isset($vars['method'])) { + $method = $vars['method']; +} else { + $method = 'POST'; +} + +$method = strtolower($method); + +// Generate a security header +$security_header = ""; +if (!isset($vars['disable_security']) || $vars['disable_security'] != true) { + $security_header = elgg_view('input/securitytoken'); +} +?> +<form <?php if ($id) { ?>id="<?php echo $id; ?>" <?php } ?> <?php if ($name) { ?>name="<?php echo $name; ?>" <?php } ?> action="<?php echo $action; ?>" method="<?php echo $method; ?>" <?php if ($enctype!="") echo "enctype=\"$enctype\""; ?>> +<?php echo $security_header; ?> +<?php echo $body; ?> +</form>
\ No newline at end of file |