]> git.sesse.net Git - pr0n/blobdiff - perl/Sesse/pr0n/Index.pm
Fix a few XSS-ish issues.
[pr0n] / perl / Sesse / pr0n / Index.pm
index ee4c0f967a838c8ef2ea4ed9f84b9dfcaf45a09d..b8825bdb748fd0e6ddd01902737d52546d4e89a5 100644 (file)
@@ -251,17 +251,28 @@ sub handler {
                                for my $e (@equipment) {
                                        my $eqspec = $e->{'model'};
                                        $eqspec .= ', ' . $e->{'lens'} if (defined($e->{'lens'}));
+                                       $eqspec = HTML::Entities::encode_entities($eqspec);
 
                                        my %newsettings = %defsettings;
-                                       $newsettings{'model'} = $e->{'model'};
-                                       $newsettings{'lens'} = defined($e->{'lens'}) ? $e->{'lens'} : '';
+
+                                       my $action;
+                                       if (defined($model) && defined($lens)) {
+                                               chomp ($action = Sesse::pr0n::Templates::fetch_template($r, "unfilter"));
+                                               $newsettings{'model'} = undef;
+                                               $newsettings{'lens'} = undef;
+                                       } else {
+                                               chomp ($action = Sesse::pr0n::Templates::fetch_template($r, "filter"));
+                                               $newsettings{'model'} = $e->{'model'};
+                                               $newsettings{'lens'} = defined($e->{'lens'}) ? $e->{'lens'} : '';
+                                       }
+                                       
                                        my $url = "/$event/" . Sesse::pr0n::Common::get_query_string(\%newsettings, \%defsettings);
 
                                        # This isn't correct for all languages. Fix if we ever need to care. :-)
                                        if ($e->{'num'} == 1) {
-                                               Sesse::pr0n::Templates::print_template($r, "equipment-item-singular", { eqspec => $eqspec, filterurl => $url });
+                                               Sesse::pr0n::Templates::print_template($r, "equipment-item-singular", { eqspec => $eqspec, filterurl => $url, action => $action });
                                        } else {
-                                               Sesse::pr0n::Templates::print_template($r, "equipment-item", { eqspec => $eqspec, num => $e->{'num'}, filterurl => $url });
+                                               Sesse::pr0n::Templates::print_template($r, "equipment-item", { eqspec => $eqspec, num => $e->{'num'}, filterurl => $url, action => $action });
                                        }
                                }
                                Sesse::pr0n::Templates::print_template($r, "equipment-end");