summaryrefslogtreecommitdiffstats
path: root/templates/show_get_albumart.inc.php
diff options
context:
space:
mode:
authorKarl 'vollmerk' Vollmer <vollmer@ampache.org>2007-12-23 22:36:23 +0000
committerKarl 'vollmerk' Vollmer <vollmer@ampache.org>2007-12-23 22:36:23 +0000
commitd3423e0e37a6608edb82a7f6b6aa69d55aafec7d (patch)
tree0821f326d8cccdca64d4e24ce1f7640eee91db5c /templates/show_get_albumart.inc.php
parentcbdb592407c339d8158fb96e0253c1b34e011dc5 (diff)
downloadampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.tar.gz
ampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.tar.bz2
ampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.zip
fixed an album art issue created with the new auth code
Diffstat (limited to 'templates/show_get_albumart.inc.php')
-rw-r--r--templates/show_get_albumart.inc.php7
1 files changed, 4 insertions, 3 deletions
diff --git a/templates/show_get_albumart.inc.php b/templates/show_get_albumart.inc.php
index df863e50..bf831436 100644
--- a/templates/show_get_albumart.inc.php
+++ b/templates/show_get_albumart.inc.php
@@ -21,14 +21,15 @@
*/
?>
<?php show_box_top(_('Customize Search')); ?>
-<form enctype="multipart/form-data" name="coverart" method="post" action="<?php echo Config::get('web_path'); ?>/albums.php?action=find_art&amp;album_id=<?php echo $album->id; ?>&amp;artist_name=<?php echo $_REQUEST['artist_name'];?>&amp;album_name=<?php echo $_REQUEST['album_name']; ?>&amp;cover=<?php echo scrub_out($_REQUEST['cover']); ?>" style="Display:inline;">
+<?php print_r($_GET); ?>
+<form enctype="multipart/form-data" name="coverart" method="post" action="<?php echo Config::get('web_path'); ?>/albums.php?action=find_art&amp;album_id=<?php echo $album->id; ?>&amp;artist_name=<?php echo urlencode($_REQUEST['artist_name']);?>&amp;album_name=<?php echo urlencode($_REQUEST['album_name']); ?>&amp;cover=<?php echo urlencode($_REQUEST['cover']); ?>" style="Display:inline;">
<table>
<tr>
<td>
<?php echo _('Artist'); ?>&nbsp;
</td>
<td>
- <input type="text" size="20" id="artist_name" name="artist_name" value="<?php echo scrub_out($artistname); ?>" />
+ <input type="text" size="20" id="artist_name" name="artist_name" value="<?php echo scrub_out(unhtmlentities($artistname)); ?>" />
</td>
</tr>
<tr>
@@ -36,7 +37,7 @@
<?php echo _('Album'); ?>&nbsp;
</td>
<td>
- <input type="text" size="20" id="album_name" name="album_name" value="<?php echo scrub_out($albumname); ?>" />
+ <input type="text" size="20" id="album_name" name="album_name" value="<?php echo scrub_out(unhtmlentities($albumname)); ?>" />
</td>
</tr>
<tr>