Filter fields through kses upon display. Introduce sanitize_user_object() and sanitize_user_field(). see #10751

git-svn-id: https://develop.svn.wordpress.org/trunk@11929 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Ryan Boren
2009-09-14 13:57:48 +00:00
parent e4045df0ab
commit b7f82a38b5
9 changed files with 260 additions and 86 deletions
+7 -6
View File
@@ -284,7 +284,7 @@ else
<table class="form-table">
<tr>
<th><label for="description"><?php _e('Biographical Info'); ?></label></th>
<td><textarea name="description" id="description" rows="5" cols="30"><?php echo $profileuser->description ?></textarea><br />
<td><textarea name="description" id="description" rows="5" cols="30"><?php echo esc_html($profileuser->description); ?></textarea><br />
<span class="description"><?php _e('Share a little biographical information to fill out your profile. This may be shown publicly.'); ?></span></td>
</tr>
@@ -311,16 +311,17 @@ if ( $show_password_fields ) :
}
?>
<?php if (count($profileuser->caps) > count($profileuser->roles) && apply_filters('additional_capabilities_display', true, $profileuser)): ?>
<?php if ( count($profileuser->caps) > count($profileuser->roles) && apply_filters('additional_capabilities_display', true, $profileuser) ) { ?>
<br class="clear" />
<table width="99%" style="border: none;" cellspacing="2" cellpadding="3" class="editform">
<tr>
<th scope="row"><?php _e('Additional Capabilities') ?></th>
<td><?php
$output = '';
foreach($profileuser->caps as $cap => $value) {
if(!$wp_roles->is_role($cap)) {
if($output != '') $output .= ', ';
foreach ( $profileuser->caps as $cap => $value ) {
if ( !$wp_roles->is_role($cap) ) {
if ( $output != '' )
$output .= ', ';
$output .= $value ? $cap : "Denied: {$cap}";
}
}
@@ -328,7 +329,7 @@ if ( $show_password_fields ) :
?></td>
</tr>
</table>
<?php endif; ?>
<?php } ?>
<p class="submit">
<input type="hidden" name="action" value="update" />