diff options
author | Karl 'vollmerk' Vollmer <vollmer@ampache.org> | 2007-12-23 22:36:23 +0000 |
---|---|---|
committer | Karl 'vollmerk' Vollmer <vollmer@ampache.org> | 2007-12-23 22:36:23 +0000 |
commit | d3423e0e37a6608edb82a7f6b6aa69d55aafec7d (patch) | |
tree | 0821f326d8cccdca64d4e24ce1f7640eee91db5c /templates/show_get_albumart.inc.php | |
parent | cbdb592407c339d8158fb96e0253c1b34e011dc5 (diff) | |
download | ampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.tar.gz ampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.tar.bz2 ampache-d3423e0e37a6608edb82a7f6b6aa69d55aafec7d.zip |
fixed an album art issue created with the new auth code
Diffstat (limited to 'templates/show_get_albumart.inc.php')
-rw-r--r-- | templates/show_get_albumart.inc.php | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/templates/show_get_albumart.inc.php b/templates/show_get_albumart.inc.php index df863e50..bf831436 100644 --- a/templates/show_get_albumart.inc.php +++ b/templates/show_get_albumart.inc.php @@ -21,14 +21,15 @@ */ ?> <?php show_box_top(_('Customize Search')); ?> -<form enctype="multipart/form-data" name="coverart" method="post" action="<?php echo Config::get('web_path'); ?>/albums.php?action=find_art&album_id=<?php echo $album->id; ?>&artist_name=<?php echo $_REQUEST['artist_name'];?>&album_name=<?php echo $_REQUEST['album_name']; ?>&cover=<?php echo scrub_out($_REQUEST['cover']); ?>" style="Display:inline;"> +<?php print_r($_GET); ?> +<form enctype="multipart/form-data" name="coverart" method="post" action="<?php echo Config::get('web_path'); ?>/albums.php?action=find_art&album_id=<?php echo $album->id; ?>&artist_name=<?php echo urlencode($_REQUEST['artist_name']);?>&album_name=<?php echo urlencode($_REQUEST['album_name']); ?>&cover=<?php echo urlencode($_REQUEST['cover']); ?>" style="Display:inline;"> <table> <tr> <td> <?php echo _('Artist'); ?> </td> <td> - <input type="text" size="20" id="artist_name" name="artist_name" value="<?php echo scrub_out($artistname); ?>" /> + <input type="text" size="20" id="artist_name" name="artist_name" value="<?php echo scrub_out(unhtmlentities($artistname)); ?>" /> </td> </tr> <tr> @@ -36,7 +37,7 @@ <?php echo _('Album'); ?> </td> <td> - <input type="text" size="20" id="album_name" name="album_name" value="<?php echo scrub_out($albumname); ?>" /> + <input type="text" size="20" id="album_name" name="album_name" value="<?php echo scrub_out(unhtmlentities($albumname)); ?>" /> </td> </tr> <tr> |