noalyss-commit
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Noalyss-commit] [noalyss] 186/219: Protect queryString with encodeURI


From: Dany De Bontridder
Subject: [Noalyss-commit] [noalyss] 186/219: Protect queryString with encodeURI
Date: Mon, 18 Dec 2017 13:23:00 -0500 (EST)

sparkyx pushed a commit to branch master
in repository noalyss.

commit 2e844abc39434a2f0682af2dc6aa1d9e78a2ffaa
Author: Dany De Bontridder <address@hidden>
Date:   Fri Dec 8 20:11:22 2017 +0100

    Protect queryString with encodeURI
---
 html/js/acc_ledger.js | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/html/js/acc_ledger.js b/html/js/acc_ledger.js
index 2238219..73d1dcc 100644
--- a/html/js/acc_ledger.js
+++ b/html/js/acc_ledger.js
@@ -162,7 +162,7 @@ function update_row(ctl)
     {
         var jrn = g('p_jrn').value;
         var dossier = g('gDossier').value;
-        var qs = 'gDossier=' + dossier + '&op=minrow&j=' + jrn + '&ctl=' + ctl;
+        var qs = encodeURI('gDossier=' + dossier + '&op=minrow&j=' + jrn + 
'&ctl=' + ctl);
         var action = new Ajax.Request(
                 "ajax_misc.php",
                 {
@@ -917,7 +917,7 @@ function filter_card(obj, queryString)
     {
         queryString = queryString + '&j=' + jrn;
     }
-    return queryString;
+    return encodeURI(queryString);
 }
 /**
  address@hidden to display the lettering for the operation, call
@@ -1058,7 +1058,7 @@ function op_save(obj)
             var action = new Ajax.Request('ajax_misc.php',
                     {
                         method: 'post',
-                        parameters: queryString,
+                        parameters: encodeURI(queryString),
                         onFailure: null,
                         onSuccess: infodiv
                     }



reply via email to

[Prev in Thread] Current Thread [Next in Thread]