Skip to:
Content

BuddyPress.org


Ignore:
Timestamp:
02/20/2019 03:06:18 PM (7 years ago)
Author:
boonebgorges
Message:

Improve character escaping in Messages AJAX.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/bp-core/bp-core-avatars.php

    r11858 r12338  
    836836    if ( bp_core_delete_existing_avatar( array( 'item_id' => $avatar_data['item_id'], 'object' => $avatar_data['object'] ) ) ) {
    837837        $return = array(
    838             'avatar' => html_entity_decode( bp_core_fetch_avatar( array(
     838            'avatar' => esc_url( bp_core_fetch_avatar( array(
    839839                'object'  => $avatar_data['object'],
    840840                'item_id' => $avatar_data['item_id'],
     
    12741274        } else {
    12751275            $return = array(
    1276                 'avatar' => html_entity_decode( bp_core_fetch_avatar( array(
     1276                'avatar' => esc_url( bp_core_fetch_avatar( array(
    12771277                    'object'  => $avatar_data['object'],
    12781278                    'item_id' => $avatar_data['item_id'],
     
    13311331    if ( bp_core_avatar_handle_crop( $r ) ) {
    13321332        $return = array(
    1333             'avatar' => html_entity_decode( bp_core_fetch_avatar( array(
     1333            'avatar' => esc_url( bp_core_fetch_avatar( array(
    13341334                'object'  => $avatar_data['object'],
    13351335                'item_id' => $avatar_data['item_id'],
Note: See TracChangeset for help on using the changeset viewer.