Incremental fix for Bug 2847, Use HTML escape in templates where appropriate
authorOwen Leonard <oleonard@myacpl.org>
Fri, 11 Nov 2011 17:34:44 +0000 (12:34 -0500)
committerPaul Poulain <paul.poulain@biblibre.com>
Fri, 18 Nov 2011 22:12:26 +0000 (23:12 +0100)
commitbfe06ef399da831e5602784fbe54cea6dfc1ab65
treee29b7fa5f64e07719e79ed18e101ba91facb67be
parent440c0f21ee59664bfbd2238c638f84a6af3d9d80
Incremental fix for Bug 2847, Use HTML escape in templates where appropriate

Fixes for output in a couple of acquisitions templates where
user-generated data should be escaped. This instances were found
by creating a vendor name like "Baker & Taylor" and finding
that the ampersand was not escaped, causing validation errors.

This patch also consolidates multiple <script> blocks which
do not need to be separate and corrects a couple of unclosed
<input> tags.

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
Signed-off-by: Paul Poulain <paul.poulain@biblibre.com>
koha-tmpl/intranet-tmpl/prog/en/includes/acquisitions-search.inc
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/basket.tt