Change comment:
Imported from XAR
Summary
-
Page properties (3 modified, 0 added, 0 removed)
Details
- Page properties
-
- Author
-
... ... @@ -1,1 +1,1 @@ 1 -XWiki. ThomasMortagne1 +XWiki.VincentMassol - Hidden
-
... ... @@ -1,1 +1,1 @@ 1 - false1 +true - Content
-
... ... @@ -33,8 +33,8 @@ 33 33 #elseif (!$xwiki.getDocument($name).isNew()) 34 34 #blog__actionResponseError(409, 'xe.blog.manageCategories.create.error.alreadyExists', []) 35 35 #else 36 - #set($title = $ util.encodeURI($title))37 - #set($newCategoryParent = $ util.encodeURI($request.newCategoryParent))36 + #set($title = $escapetool.url($title)) 37 + #set($newCategoryParent = $escapetool.url($request.newCategoryParent)) 38 38 #if($request.ajax) 39 39 #if("$!{request.mode}" == 'select') 40 40 #set($xredirect = ${doc.getURL('view', "xpage=plain&display=list&listType=selectable&root=${newCategoryParent}")}) ... ... @@ -41,9 +41,9 @@ 41 41 #else 42 42 #set($xredirect = ${doc.getURL('view', "xpage=plain&display=list&root=${newCategoryParent}")}) 43 43 #end 44 - $response.sendRedirect($xwiki.getURL($name, 'save', "template=${blogCategoryTemplate}&parent=${newCategoryParent}&${blogCategoryClassname}_0_name=${title}&${blogCategoryClassname}_0_description=&xredirect=$ util.encodeURI($xredirect)&form_token=$!{services.csrf.getToken()}"))44 + $response.sendRedirect($xwiki.getURL($name, 'save', "template=${blogCategoryTemplate}&parent=${newCategoryParent}&${blogCategoryClassname}_0_name=${title}&${blogCategoryClassname}_0_description=&xredirect=${escapetool.url($xredirect)}&form_token=$!{services.csrf.getToken()}")) 45 45 #else ## request.ajax 46 - $response.sendRedirect($xwiki.getURL($name, 'save', "template=${blogCategoryTemplate}&parent=${newCategoryParent}&${blogCategoryClassname}_0_name=${title}&${blogCategoryClassname}_0_description=&xredirect=${ util.encodeURI(${doc.getURL()})}&form_token=$!{services.csrf.getToken()}"))46 + $response.sendRedirect($xwiki.getURL($name, 'save', "template=${blogCategoryTemplate}&parent=${newCategoryParent}&${blogCategoryClassname}_0_name=${title}&${blogCategoryClassname}_0_description=&xredirect=${escapetool.url(${doc.getURL()})}&form_token=$!{services.csrf.getToken()}")) 47 47 #end 48 48 #end ## empty title 49 49 #end