Skip to content

Commit fd1d829

Browse files
simoncogginsdanpoltawski
authored andcommittedJan 7, 2013
MDL-35991 - use PARAM_LOCALURL for local urls
1 parent f7551c2 commit fd1d829

File tree

6 files changed

+7
-7
lines changed

6 files changed

+7
-7
lines changed
 

‎backup/backupfilesedit.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
// file parameters
3434
$component = optional_param('component', null, PARAM_COMPONENT);
3535
$filearea = optional_param('filearea', null, PARAM_AREA);
36-
$returnurl = optional_param('returnurl', null, PARAM_URL);
36+
$returnurl = optional_param('returnurl', null, PARAM_LOCALURL);
3737

3838
list($context, $course, $cm) = get_context_info_array($currentcontext);
3939
$filecontext = context::instance_by_id($contextid, IGNORE_MISSING);

‎comment/comment_post.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
$area = optional_param('area', '', PARAM_AREA);
3939
$content = optional_param('content', '', PARAM_RAW);
4040
$itemid = optional_param('itemid', '', PARAM_INT);
41-
$returnurl = optional_param('returnurl', '/', PARAM_URL);
41+
$returnurl = optional_param('returnurl', '/', PARAM_LOCALURL);
4242
$component = optional_param('component', '', PARAM_COMPONENT);
4343

4444
// Currently this script can only add comments

‎course/switchrole.php

+2-2
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535

3636
$id = required_param('id', PARAM_INT);
3737
$switchrole = optional_param('switchrole',-1, PARAM_INT);
38-
$returnurl = optional_param('returnurl', false, PARAM_URL);
38+
$returnurl = optional_param('returnurl', false, PARAM_LOCALURL);
3939

4040
$PAGE->set_url('/course/switchrole.php', array('id'=>$id));
4141

@@ -84,4 +84,4 @@
8484
$returnurl = new moodle_url('/course/view.php', array('id' => $course->id));
8585
}
8686

87-
redirect($returnurl);
87+
redirect($returnurl);

‎mod/wiki/filesedit.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@
3131
$subwikiid = required_param('subwiki', PARAM_INT);
3232
// not being used for file management, we use it to generate navbar link
3333
$pageid = optional_param('pageid', 0, PARAM_INT);
34-
$returnurl = optional_param('returnurl', '', PARAM_URL);
34+
$returnurl = optional_param('returnurl', '', PARAM_LOCALURL);
3535

3636
if (!$subwiki = wiki_get_subwiki($subwikiid)) {
3737
print_error('incorrectsubwikiid', 'wiki');

‎tag/coursetags_add.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
print_error('tagsaredisabled', 'tag');
3636
}
3737

38-
$returnurl = optional_param('returnurl', null, PARAM_TEXT);
38+
$returnurl = optional_param('returnurl', null, PARAM_LOCALURL);
3939
$keyword = optional_param('coursetag_new_tag', '', PARAM_TEXT);
4040
$courseid = optional_param('entryid', 0, PARAM_INT);
4141
$userid = optional_param('userid', 0, PARAM_INT);

‎user/files.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@
3232
die();
3333
}
3434

35-
$returnurl = optional_param('returnurl', '', PARAM_URL);
35+
$returnurl = optional_param('returnurl', '', PARAM_LOCALURL);
3636

3737
if (empty($returnurl)) {
3838
$returnurl = new moodle_url('/user/files.php');

0 commit comments

Comments
 (0)
Please sign in to comment.