More EL code, security for $_POST elements rewritten (simplified):
[mailer.git] / inc / stylesheet.php
index 7cd2a38cf4d105ed69964e001fe0781b1813b130..81ee2dca3e8e9eff0c552a2f86a390a2de2663b9 100644 (file)
@@ -109,8 +109,11 @@ if ((isCssOutputMode()) || (getConfig('css_php') == 'DIRECT')) {
        if ((isInstallationPhase())) {
                // Default theme first
                $newTheme = 'default';
-               if (isGetRequestParameterSet('theme'))  $newTheme = getRequestParameter('theme');
-               if (isPostRequestParameterSet('theme')) $newTheme = secureString(postRequestParameter('theme'));
+               if (isPostRequestParameterSet('theme')) {
+                       $newTheme = postRequestParameter('theme');
+               } elseif (isGetRequestParameterSet('theme')) {
+                       $newTheme = getRequestParameter('theme');
+               }
                $OUT .= '?theme=' . $newTheme . '&installing=1';
        } else {
                // Add SVN revision to bypass caching problems