Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+4 -4
View File
@@ -184,7 +184,7 @@ echo '<tr><th>', _('Weight'), '</th><td>', format_float($box->weight, 2, 'kg'),
echo '<tr><th>', _('Storage'),"</th><td>", $box->sname, '&nbsp;';
echo '<a title="', _('View'), '" href="storage.php?f=view&id=', $box->sid, '"><i class="bi-eye"></i></a>';
echo "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", $box->remarks, "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", h($box->remarks, br:true), "</td></tr>\n";
echo "</table>\n";
form_view_buttons($g_scriptname, $id);
@@ -293,12 +293,12 @@ echo '<h2>', _('Edit Box'), "</h2>\n";
<input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3">
<label for="label" class="form-label"><?=_('Label')?></label>
<input type="text" class="form-control" id="label" name="label" value="<?=$box->label ?>">
<input type="text" class="form-control" id="label" name="label" value="<?=h($box->label)?>">
</div>
<?php form_create_select('boxtype', _('Box type'), $opt_none + $opt_boxtype, $box->boxtype); ?>
<div class="mb-3">
<label for="content" class="form-label"><?=_('Content')?></label>
<input type="text" class="form-control" id="content" name="content" value="<?=$box->content ?>">
<input type="text" class="form-control" id="content" name="content" value="<?=h($box->content)?>">
</div>
<div class="mb-3">
<label for="color"><?=_('Color')?></label>
@@ -311,7 +311,7 @@ echo '<h2>', _('Edit Box'), "</h2>\n";
<?php form_create_select('sid', _('Storage'), $opt_storage, $box->sid); ?>
<div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$box->remarks ?></textarea>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($box->remarks, br:true)?></textarea>
</div>
<?php