Incremental fix for Bug 2847, Use HTML escape in templates where appropriate
authorOwen Leonard <oleonard@myacpl.org>
Fri, 11 Nov 2011 17:34:44 +0000 (12:34 -0500)
committerChris Nighswonger <chris.nighswonger@gmail.com>
Sat, 19 Nov 2011 22:02:59 +0000 (17:02 -0500)
commit7e92a497aa2d1c25ab0950855e1a57fc1dd897d1
treea7e7a4c8bc97193184d2e4c793620dcd04edbd75
parent4d09e483846fb6d8d1df2f44eae874ba074db3a7
Incremental fix for Bug 2847, Use HTML escape in templates where appropriate

Fixes for output in a couple of acquisitions templates where
user-generated data should be escaped. This instances were found
by creating a vendor name like "Baker & Taylor" and finding
that the ampersand was not escaped, causing validation errors.

This patch also consolidates multiple <script> blocks which
do not need to be separate and corrects a couple of unclosed
<input> tags.

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
Signed-off-by: Paul Poulain <paul.poulain@biblibre.com>
(cherry picked from commit bfe06ef399da831e5602784fbe54cea6dfc1ab65)

Signed-off-by: Chris Nighswonger <chris.nighswonger@gmail.com>
koha-tmpl/intranet-tmpl/prog/en/includes/acquisitions-search.inc
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/basket.tt