add controller request secure param (#1060)
This commit is contained in:
parent
b2e43430b1
commit
c657d8291f
|
@ -46,7 +46,7 @@ class AddTopicController extends Controller {
|
|||
public function handler() {
|
||||
$topic = new Topic();
|
||||
$topic->setProperties([
|
||||
'name' => Controller::request('name'),
|
||||
'name' => Controller::request('name', true),
|
||||
'icon' => Controller::request('icon'),
|
||||
'iconColor' => Controller::request('iconColor'),
|
||||
'private' => Controller::request('private') ? 1 : 0
|
||||
|
|
|
@ -64,7 +64,7 @@ class AddArticleController extends Controller {
|
|||
|
||||
$article = new Article();
|
||||
$article->setProperties([
|
||||
'title' => Controller::request('title'),
|
||||
'title' => Controller::request('title', true),
|
||||
'content' => $this->replaceWithImagePaths($imagePaths, $content),
|
||||
'lastEdited' => Date::getCurrentDate(),
|
||||
'position' => Controller::request('position') || 1
|
||||
|
|
|
@ -52,7 +52,7 @@ class EditTopicController extends Controller {
|
|||
$topic = Topic::getDataStore(Controller::request('topicId'));
|
||||
|
||||
if(Controller::request('name')) {
|
||||
$topic->name = Controller::request('name');
|
||||
$topic->name = Controller::request('name', true);
|
||||
}
|
||||
|
||||
if(Controller::request('iconColor')) {
|
||||
|
|
|
@ -63,9 +63,9 @@ class AddCustomFieldController extends Controller {
|
|||
}
|
||||
|
||||
public function handler() {
|
||||
$name = Controller::request('name');
|
||||
$name = Controller::request('name', true);
|
||||
$type = Controller::request('type');
|
||||
$description = Controller::request('description');
|
||||
$description = Controller::request('description', true);
|
||||
$options = Controller::request('options');
|
||||
|
||||
if(!Customfield::getDataStore($name, 'name')->isNull())
|
||||
|
|
|
@ -39,7 +39,7 @@ class AddDepartmentController extends Controller {
|
|||
}
|
||||
|
||||
public function handler() {
|
||||
$name = Controller::request('name');
|
||||
$name = Controller::request('name', true);
|
||||
$private = Controller::request('private');
|
||||
|
||||
$departmentInstance = new Department();
|
||||
|
|
|
@ -54,7 +54,7 @@ class AddCustomResponseController extends Controller {
|
|||
public function handler() {
|
||||
$customResponse = new CustomResponse();
|
||||
$customResponse->setProperties([
|
||||
'name' => Controller::request('name'),
|
||||
'name' => Controller::request('name', true),
|
||||
'content' => Controller::request('content', true),
|
||||
'language' => Controller::request('language')
|
||||
]);
|
||||
|
|
|
@ -46,7 +46,7 @@ class CreateTagController extends Controller {
|
|||
}
|
||||
|
||||
public function handler() {
|
||||
$name = Controller::request('name');
|
||||
$name = Controller::request('name', true);
|
||||
$color = Controller::request('color');
|
||||
|
||||
if (!Tag::getDataStore($name, 'name')->isNull()) {
|
||||
|
|
|
@ -99,7 +99,7 @@ class CreateController extends Controller {
|
|||
$session->clearSessionData();
|
||||
}
|
||||
|
||||
$this->title = Controller::request('title');
|
||||
$this->title = Controller::request('title', true);
|
||||
$this->content = Controller::request('content', true);
|
||||
$this->departmentId = Controller::request('departmentId');
|
||||
$this->language = Controller::request('language');
|
||||
|
|
|
@ -102,8 +102,8 @@ class InviteUserController extends Controller {
|
|||
}
|
||||
|
||||
public function storeRequestData() {
|
||||
$this->userName = Controller::request('name');
|
||||
$this->userEmail = Controller::request('email');
|
||||
$this->userName = Controller::request('name', true);
|
||||
$this->userEmail = Controller::request('email', true);
|
||||
}
|
||||
|
||||
public function createNewUserAndRetrieveId() {
|
||||
|
|
|
@ -115,7 +115,7 @@ class SignUpController extends Controller {
|
|||
}
|
||||
|
||||
public function storeRequestData() {
|
||||
$this->userName = Controller::request('name');
|
||||
$this->userName = Controller::request('name', true);
|
||||
$this->userEmail = Controller::request('email');
|
||||
$this->userPassword = Controller::request('password');
|
||||
$this->verificationToken = Hashing::generateRandomToken();
|
||||
|
|
Loading…
Reference in New Issue