WordPress/wp-admin/includes
Ryan Boren 469d1a3099 Escape form action urls with esc_url() rather than esc_attr().
Props SergeyBiryukov
fixes #23266


git-svn-id: http://core.svn.wordpress.org/trunk@23739 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2013-03-18 14:01:25 +00:00
..
admin.php
ajax-actions.php Create one autosave per user rather than a single autosave for all users. Remove unused code from autosave.js and wp_ajax_autosave(). See #23665. 2013-03-16 21:15:43 +00:00
bookmark.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-ftp-pure.php "LGPL License" is redundant. 2013-02-15 16:26:46 +00:00
class-ftp-sockets.php "LGPL License" is redundant. 2013-02-15 16:26:46 +00:00
class-ftp.php "LGPL License" is redundant. 2013-02-15 16:26:46 +00:00
class-pclzip.php
class-wp-comments-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-filesystem-base.php Correct return value for WP_Filesystem_Base::gethchmod(). props bananastalktome. fixes #23121. 2013-01-28 01:55:39 +00:00
class-wp-filesystem-direct.php its <=> it's in documentation, along with a rogue the, The, and looses. props trepmal. fixes #22665. 2012-12-20 15:55:32 +00:00
class-wp-filesystem-ftpext.php
class-wp-filesystem-ftpsockets.php its <=> it's in documentation, along with a rogue the, The, and looses. props trepmal. fixes #22665. 2012-12-20 15:55:32 +00:00
class-wp-filesystem-ssh2.php
class-wp-importer.php
class-wp-links-list-table.php Remove unused variables reset by wp_reset_vars(). Many of these haven't been used since b2. see #21767. 2013-02-16 18:28:41 +00:00
class-wp-list-table.php its <=> it's in documentation, along with a rogue the, The, and looses. props trepmal. fixes #22665. 2012-12-20 15:55:32 +00:00
class-wp-media-list-table.php Allow filtering attachments by Author name in Media Library. props greuben. fixes #16044. 2013-02-15 17:33:28 +00:00
class-wp-ms-sites-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-ms-themes-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-ms-users-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-plugin-install-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-plugins-list-table.php Replace deprecated WP_Screen::is_network property with WP_Screen::in_admin( 'network' ). props bpetty. fixes #23215. 2013-03-09 03:52:27 +00:00
class-wp-posts-list-table.php Post locks on the posts list screen: new icons for the lock, props empireoflight, show avatar for the user currently editing, props dh-shredder, see #23312 2013-03-13 00:28:07 +00:00
class-wp-terms-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-theme-install-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-themes-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-upgrader.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
class-wp-users-list-table.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
comment.php Revert 23416, 23419, 23445 except for wp_reset_vars() changes. We are going a different direction with the slashing cleanup, so resetting to a clean slate. see #21767 2013-03-01 16:28:40 +00:00
continents-cities.php
dashboard.php Add description for wp_dashboard_rss_output(). props aaronholbrook for initial patch. fixes #23301. 2013-03-04 04:34:39 +00:00
deprecated.php Remove an unslash in the deprecated WP_User_Search, as search_term is already unslashed in the constructor. see #21767. 2013-03-01 17:57:49 +00:00
export.php Remove redundant esc_url() call. props pauldewouters. fixes #23643. 2013-03-01 16:27:03 +00:00
file.php Escape form action urls with esc_url() rather than esc_attr(). 2013-03-18 14:01:25 +00:00
image-edit.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
image.php Declare the variable before using it. props danielbachhuber. fixes #23710. 2013-03-07 04:46:19 +00:00
import.php
list-table.php
media.php Escape form action urls with esc_url() rather than esc_attr(). 2013-03-18 14:01:25 +00:00
menu.php
meta-boxes.php Consistently use a helper function instead of directly printing the disabled attribute. 2013-01-28 03:23:01 +00:00
misc.php Autosave to the browser's sessionStorage, compare this autosave to the post content on page load and let the user restore it when the data is not the same. First run, see #23220 2013-03-13 10:08:16 +00:00
ms-deprecated.php
ms.php Fix fatal error in WP_User_Query when searching users by URL. Move wp_is_large_network() to wp-includes. fixes #23683 for trunk. 2013-03-12 09:19:55 +00:00
nav-menu.php Accessibility revamp for nav menus. 2013-03-16 04:47:19 +00:00
plugin-install.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
plugin.php Open external links to plugin homepages, plugin author homepages, and theme author homepages in a new window/tab. props SergeyBiryukov. fixes #20839. 2013-02-08 16:20:01 +00:00
post.php Create one autosave per user rather than a single autosave for all users. Remove unused code from autosave.js and wp_ajax_autosave(). See #23665. 2013-03-16 21:15:43 +00:00
schema.php Use prepare instead of escape. 2013-03-01 17:01:01 +00:00
screen.php Replace deprecated WP_Screen::is_network property with WP_Screen::in_admin( 'network' ). props bpetty. fixes #23215. 2013-03-09 03:52:27 +00:00
taxonomy.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:00:25 +00:00
template.php Escape form action urls with esc_url() rather than esc_attr(). 2013-03-18 14:01:25 +00:00
theme-install.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
theme.php Tighten our braces. Fixes #23118 props evansolomon. 2013-01-04 10:13:51 +00:00
update-core.php Make Twenty Thirteen the default theme. 2013-02-28 19:01:07 +00:00
update.php
upgrade.php Use wp_unslash() instead of stripslashes() and stripslashes_deep(). Use wp_slash() instead of add_magic_quotes(). 2013-03-01 17:14:09 +00:00
user.php When adding a new user in the admin, strip slashes from the password sent to the user by email. props hakre for initial patch. fixes #17018. 2013-03-07 06:00:16 +00:00
widgets.php