]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - lib/noticeform.php
XSS vulnerability when remote-subscribing
[quix0rs-gnu-social.git] / lib / noticeform.php
index e241b5812c6af7b0ab73ea459b2d610921f0c655..f9b2309119485aa12c72ee0df0f0fa2f133c35ce 100644 (file)
@@ -99,14 +99,12 @@ class NoticeForm extends Form
      */
     function __construct($action, $options=null)
     {
-        // XXX: ??? Is this to keep notice forms distinct?
-        // Do we have to worry about sub-second race conditions?
-        // XXX: Needs to be above the parent::__construct() call...?
+        parent::__construct($action);
 
+        // When creating a notice form we don't want to collide with
+        // possibly existing HTML elements, as naming conventions are similar.
         $this->id_suffix = rand();
 
-        parent::__construct($action);
-
         if (is_null($options)) {
             $options = array();
         }
@@ -190,6 +188,15 @@ class NoticeForm extends Form
         $this->out->element('legend', null, _('Send a notice'));
     }
 
+    protected function placeholderText()
+    {
+        if ($this->inreplyto) {
+            return _('Write a reply...');
+        }
+
+        return _('Share your status...');
+    }
+
     /**
      * Data elements
      *
@@ -205,7 +212,7 @@ class NoticeForm extends Form
             // XXX: vary by defined max size
             $this->out->element('textarea', array('class' => 'notice_data-text',
                                                   'required' => 'required',
-                                                  'placeholder' => _('Share your status...'),
+                                                  'placeholder' => $this->placeholderText(),
                                                   'cols' => 35,
                                                   'rows' => 4,
                                                   'name' => 'status_textarea'),
@@ -221,15 +228,17 @@ class NoticeForm extends Form
 
             if (common_config('attachments', 'uploads')) {
                 $this->out->hidden('MAX_FILE_SIZE', common_config('attachments', 'file_quota'));
-                $this->out->elementStart('label', array('class' => 'notice_data-attach'));
-                // TRANS: Input label in notice form for adding an attachment.
-                $this->out->text(_('Attach'));
+                $this->out->element('label', array('class' => 'notice_data-attach',
+                                                   'for'   => $this->id().'-notice_data-attach'),
+                                    // TRANS: Input label in notice form for adding an attachment.
+                                    _('Attach'));
+                // The actual input element tends to be hidden with CSS.
                 $this->out->element('input', array('class' => 'notice_data-attach',
                                                    'type' => 'file',
                                                    'name' => 'attach',
+                                                   'id' => $this->id().'-notice_data-attach',
                                                    // TRANS: Title for input field to attach a file to a notice.
                                                    'title' => _('Attach a file.')));
-                $this->out->elementEnd('label');
             }
             if (!empty($this->actionName)) {
                 $this->out->hidden('notice_return-to', $this->actionName, 'returnto');
@@ -254,9 +263,7 @@ class NoticeForm extends Form
                                                       'data-api' => common_local_url('geocode')));
 
                 // @fixme checkbox method allows no way to change the id without changing the name
-                //// TRANS: Checkbox label to allow sharing geo location in notices.
                 //$this->out->checkbox('notice_data-geo', _('Share my location'), true);
-                $this->out->elementStart('label', 'notice_data-geo');
                 $this->out->element('input', array(
                     'name' => 'notice_data-geo',
                     'type' => 'checkbox',
@@ -264,10 +271,10 @@ class NoticeForm extends Form
                     'id' => $this->id() . '-notice_data-geo',
                     'checked' => true, // ?
                 ));
-                $this->out->text(' ');
-                // TRANS: Field label to add location to a notice.
-                $this->out->text(_('Share my location'));
-                $this->out->elementEnd('label');
+                $this->out->element('label', array('class' => 'notice_data-geo',
+                                                   'for'   => $this->id().'-notice_data-geo'),
+                                    // TRANS: Checkbox label to allow sharing geo location in notices.
+                                    _('Share my location'));
                                
                 $this->out->elementEnd('div');
                 // TRANS: Text to not share location for a notice in notice form.