mirror of
https://github.com/WordPress/WordPress.git
synced 2025-01-03 15:08:10 +01:00
Escape , , and for use in attributes by default since so many themes don't escape them. Use wp_get_current_commenter() to get the raw values.
git-svn-id: http://svn.automattic.com/wordpress/trunk@11722 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
parent
8dff8f9f73
commit
1466e9954b
@ -818,8 +818,31 @@ function comments_template( $file = '/comments.php', $separate_comments = false
|
|||||||
$file = '/comments.php';
|
$file = '/comments.php';
|
||||||
|
|
||||||
$req = get_option('require_name_email');
|
$req = get_option('require_name_email');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Raw comment author information fetched from the comment cookies.
|
||||||
|
*
|
||||||
|
* @uses wp_get_current_commenter()
|
||||||
|
*/
|
||||||
$commenter = wp_get_current_commenter();
|
$commenter = wp_get_current_commenter();
|
||||||
extract($commenter, EXTR_SKIP);
|
|
||||||
|
/**
|
||||||
|
* The name of the current comment author escaped for use in attributes. Use
|
||||||
|
* wp_get_current_commenter() to get the raw value.
|
||||||
|
*/
|
||||||
|
$comment_author = esc_attr($commenter['comment_author']);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The email address of the current comment author escaped for use in attributes. Use
|
||||||
|
* wp_get_current_commenter() to get the raw value.
|
||||||
|
*/
|
||||||
|
$comment_author_email = esc_attr($commenter['comment_author_email']);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The url of the current comment author escaped for use in attributes. Use
|
||||||
|
* wp_get_current_commenter() to get the raw value.
|
||||||
|
*/
|
||||||
|
$comment_author_url = esc_url($commenter['comment_author_url']);
|
||||||
|
|
||||||
/** @todo Use API instead of SELECTs. */
|
/** @todo Use API instead of SELECTs. */
|
||||||
if ( $user_ID) {
|
if ( $user_ID) {
|
||||||
|
Loading…
Reference in New Issue
Block a user