<a href="/cgi-bin/koha/catalogue/detail.pl?biblionumber=<!-- TMPL_VAR NAME="biblionumber" -->"><!-- TMPL_VAR NAME="bibliotitle" --></a>
</td>
<td>
- <!-- TMPL_VAR NAME="review" -->
+ <!-- TMPL_VAR NAME="review" ESCAPE="HTML" -->
</td>
<td>
<a href="/cgi-bin/koha/reviews/reviewswaiting.pl?op=approve&reviewid=<!-- TMPL_VAR NAME="reviewid" -->">Approve</a> |
<!--TMPL_VAR NAME="datereviewed"-->
</small>
<p>
- <!--TMPL_VAR NAME="review"-->
+ <!--TMPL_VAR NAME="review" ESCAPE="HTML"-->
</p>
<!--/TMPL_LOOP-->
<!-- TMPL_ELSE -->
</div>
<!-- TMPL_IF NAME="OpacNav" --><div class="yui-b"><!--TMPL_INCLUDE NAME="navigation.inc" --></div><!-- /TMPL_IF -->
</div>
-<!-- TMPL_INCLUDE NAME="opac-bottom.inc" -->
\ No newline at end of file
+<!-- TMPL_INCLUDE NAME="opac-bottom.inc" -->
</h5>
<small><!-- TMPL_VAR NAME="datereviewed" --></small>
<p>
- <!-- TMPL_VAR NAME="review" -->
+ <!-- TMPL_VAR NAME="review" ESCAPE="HTML" -->
<a href="#" onclick="Dopop('/cgi-bin/koha/opac-review.pl?biblionumber=<!-- TMPL_VAR NAME="biblionumber"-->&reviewid=<!-- TMPL_VAR NAME="reviewid" -->');">Edit</a>
</p></div>
<!-- TMPL_ELSE -->
</h5>
<small><!-- TMPL_VAR NAME="datereviewed" --></small>
<p>
- <!-- TMPL_VAR NAME="review" -->
+ <!-- TMPL_VAR NAME="review" ESCAPE="HTML" -->
</p></div>
<!-- /TMPL_IF -->
<!-- /TMPL_LOOP -->
$('#reviewf').submit( function() {
<!-- TMPL_IF NAME="reviewid" -->
parent.opener.$('#c<!-- TMPL_VAR NAME="reviewid" --> p').prev("small").prev("h5").html("Your Edited Comment (preview, pending approval)");
- parent.opener.$('#c<!-- TMPL_VAR NAME="reviewid" --> p').html($("#review").val());
+ parent.opener.$('#c<!-- TMPL_VAR NAME="reviewid" --> p').html($("#review").val().replace(/&/g,'&').replace(/</g,'<').replace(/>/g,'>'));
parent.opener.$('#c<!-- TMPL_VAR NAME="reviewid" --> p').append(" <a href=\"#comment\" onclick=\"Dopop(\'/cgi-bin/koha/opac-review.pl?biblionumber=<!-- TMPL_VAR NAME="biblionumber"-->&reviewid=<!-- TMPL_VAR NAME="reviewid" -->\');\">Edit</a>");
window.close();
<!-- TMPL_ELSE -->
parent.opener.$('#newcomment').attr("class","yours");
parent.opener.$('#newcomment').html("<h5>Your Comment (preview, pending approval)</h5>");
- parent.opener.$('#newcomment').append("<p>"+$("#review").val());
+ parent.opener.$('#newcomment').append("<p>"+$("#review").val().replace(/&/g,'&').replace(/</g,'<').replace(/>/g,'>'));
parent.opener.$('#newcomment p').append(" <a href=\"#comment\" onclick=\"Dopop(\'/cgi-bin/koha/opac-review.pl?biblionumber=<!-- TMPL_VAR NAME="biblionumber"-->&reviewid=<!-- TMPL_VAR NAME="reviewid" -->\');\">Edit</a></p>");
parent.opener.$("#addcomment").prev("p").remove();
parent.opener.$("#addcomment").remove();