Revision 667
Added by doc almost 17 years ago
save.php | ||
---|---|---|
138 | 138 |
$setting_name = $setting['name']; |
139 | 139 |
$value = $admin->get_post($setting_name); |
140 | 140 |
if ($setting_name!='wb_version') { |
141 |
$value = strip_tags($admin->add_slashes($value)); |
|
141 |
$allow_tags_in_fields = array('website_header', 'website_footer'); |
|
142 |
if(!in_array($setting_name, $allow_tags_in_fields)) { |
|
143 |
$value = strip_tags($value); |
|
144 |
} |
|
142 | 145 |
switch ($setting_name) { |
143 | 146 |
case 'default_timezone': |
144 | 147 |
$value=$value*60*60; |
... | ... | |
153 | 156 |
if(trim($value)=='/') $value=''; |
154 | 157 |
break; |
155 | 158 |
} |
159 |
$value = $admin->add_slashes($value); |
|
156 | 160 |
$database->query("UPDATE ".TABLE_PREFIX."settings SET value = '$value' WHERE name = '$setting_name'"); |
157 | 161 |
} |
158 | 162 |
} |
Also available in: Unified diff
allowed usage of tags in settings fields: website_header, website_footer