Skip to content

Commit 61ae846

Browse files
committed
Add missing escaping
1 parent 2f2949e commit 61ae846

2 files changed

Lines changed: 4 additions & 2 deletions

File tree

themes/bootstrap5/templates/record/get-this/biblio-info.phtml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
<!-- Get-this: biblio-info -->
22
<?php
3-
$callNum = $this->getThis->getCallNumber() ?? $this->transEsc('data_unavailable');
3+
$callNum = $this->getThis->getCallNumber() ?? $this->translate('data_unavailable');
4+
$callNum = $this->escapeHtml($callNum);
45
?>
56
<div>
67
<p>

themes/bootstrap5/templates/record/get-this/holdings.phtml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,8 @@ function getDisplay($view, $item)
77
{
88
$item['item_id'] ??= null;
99
$location = $view->getThis->getLocation($item['item_id']);
10-
$callNumber = $view->getThis->getCallNumber($item['item_id']) ?? $view->transEsc('Alternative');
10+
$callNumber = $view->getThis->getCallNumber($item['item_id']) ?? $view->translate('Alternative');
11+
$callNumber = $view->escapeHtml($callNumber);
1112
if ($view->getThis->showCopyNumber() && $copyNumber = $view->getThis->getCopyNumber($item['item_id'])) {
1213
$copyNumber = ' (' . $view->transEscAttr('copy_number', ['%%number%%' => $copyNumber]) . ')';
1314
} else {

0 commit comments

Comments
 (0)