From 5fbf516dc2cb8bdb982f9725c49db391c098572c Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Fri, 8 Jun 2018 00:29:09 -0600 Subject: [PATCH] Update contact_urls.php --- app/contacts/contact_urls.php | 42 +++++++++++++++++++---------------- 1 file changed, 23 insertions(+), 19 deletions(-) diff --git a/app/contacts/contact_urls.php b/app/contacts/contact_urls.php index 0841579d40..01ead503d1 100644 --- a/app/contacts/contact_urls.php +++ b/app/contacts/contact_urls.php @@ -17,22 +17,26 @@ The Initial Developer of the Original Code is Mark J Crane - Portions created by the Initial Developer are Copyright (C) 2008-2012 + Portions created by the Initial Developer are Copyright (C) 2008-2018 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ -require_once "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (permission_exists('contact_url_view')) { - //access granted -} -else { - echo "access denied"; - exit; -} + +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('contact_url_view')) { + //access granted + } + else { + echo "access denied"; + exit; + } //show the content echo "\n"; @@ -73,18 +77,18 @@ else { if ($result_count > 0) { foreach($result as $row) { if (permission_exists('contact_url_edit')) { - $tr_link = "href='contact_url_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_url_uuid']."'"; + $tr_link = "href='contact_url_edit.php?contact_uuid=".escape($row['contact_uuid'])."&id=".escape($row['contact_url_uuid'])."'"; } - echo "\n"; - echo " \n"; - echo " \n"; - echo " \n"; + echo "\n"; + echo " \n"; + echo " \n"; + echo " \n"; echo " \n"; echo "\n"; @@ -95,4 +99,4 @@ else { echo "
".$row['url_label']." ".$row['url_description']." 
".escape($row['url_label'])." ".escape($row['url_description'])." "; if (permission_exists('contact_url_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('contact_url_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo "
\n"; -?> \ No newline at end of file +?>