Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
escape Message translate params value to prevent XSS attack (#554)
* runs params value through htmlspecialchars() to escape html content * add note about escaped content in translated messages * use Html::clean() instead of e() * Revert "add note about escaped content in translated messages" * escape params when translating messages; introduce transRaw method for legacy usage * Fix for #376 (#559) Fix for #376 * Add support for transOrderBy (#516) Add support for transOrderBy * update version file for 1.6.8 release * Disable safe mode checks for ML Static Pages. Fixes rainlab/pages-plugin#434. Refs: rainlab/pages-plugin#174, rainlab/pages-plugin@6b6b061 * Clear RainLab.Pages caches when saving a static page Fixes rainlab/pages-plugin#404 * Register asset bundle (#560) * make sure multi-lingual input form controls have padding-right of 44px * register asset bundle to process less files into css files * reposition language selector above textarea box * fix language selector position when commentAbove is defined * Update version file for 1.6.9 release * Fix error with casts fields default locale value (#556) * only call setLocale() if locale has changed (#561) * remove unused module Co-authored-by: Siarhei Karavai <[email protected]> Co-authored-by: Aurélien Roy <[email protected]> Co-authored-by: Ben Thomson <[email protected]> Co-authored-by: Luke Towers <[email protected]> Co-authored-by: Trysystems <[email protected]>
- Loading branch information