a86de321f6
Viewing a staged MARC record batch loads a DataTable from /tools/batch_records_ajax.pl, and both batch_records_ajax.pl and the DataTable just trust the author/title/isbn/issn to be free of HTML. They shouldn't. Test plan: 1. Without this patch applied, download attachment 170418, then Cataloging - Stage records for import - Select the downloaded file - Upload file - Stage for import 2. When the background job completes, View batch - you'll get three alert()s from the title, author, and ISSN, and the author and ISSN displayed huge 3. Apply patch, restart_all 4. Manage staged records - click HTMLescapingimporttestrecord.mrc - get zero alerts and no <h2> display Sponsored-by: Chetco Community Public Library Signed-off-by: David Cook <dcook@prosentient.com.au> Signed-off-by: Martin Renvoize <martin.renvoize@ptfs-europe.com> Signed-off-by: wainuiwitikapark <wainuiwitikapark@catalyst.net.nz> |
||
---|---|---|
.. | ||
intranet-tmpl | ||
opac-tmpl |