$res .= $banana->action_showArticle($group, $artid, $partid);
if ($banana->post->checkcancel()) {
$form = '<p class="error">'._b_('Voulez-vous vraiment annuler ce message ?').'</p>'
- . "<form action=\"?group=$group&artid=$artid\" method='post'><p>"
+ . '<form action="'
+ . htmlentities(makeLink(Array('group' => $group,
+ 'artid' => $artid)))
+ . '" method="post"><p>'
. '<input type="hidden" name="action" value="cancel" />'
. '<input type="submit" value="Annuler !" />'
. '</p></form>';
$cuts = displayshortcuts();
$html = '<h1>'._b_('Nouveau message').'</h1>'.$cuts;
- $html .= '<form enctype="multipart/form-data" action="?group='.$group.'" method="post" accept-charset="utf-8">';
+ $html .= '<form enctype="multipart/form-data" action="'
+ . htmlentities(makeLink(Array('group' => $group)))
+ .'" method="post" accept-charset="utf-8">';
$html .= '<table class="bicol" cellpadding="0" cellspacing="0">';
$html .= '<tr><th colspan="2">'._b_('En-tĂȘtes').'</th></tr>';
$html .= '<tr><td>'._b_('Nom').'</td><td>'.htmlentities($this->profile['name']).'</td></tr>';
$html .= '</table>';
if ($show_form) {
- return '<form method="post" action="?"><div class="center"><input type="submit" value="Valider" /></div>'
- .$html.'<div class="center"><input type="submit" value="Valider" /></div></form>';
+ return '<form method="post" action="' . htmlentities(makeLink(Array())) . '">'
+ . '<div class="center"><input type="submit" value="Valider" /></div>'
+ . $html . '<div class="center"><input type="submit" value="Valider" /></div></form>';
}
return $html;