$filtres[] = new commonFiltre(__('Administrateur'), 'admin_book', $settings['filtres']);\r
}\r
$res = commonPage::barre($filtres , 'filtreBooks', 'books', $shortcuts);\r
- $res .= commonPage::tMain(null, true);\r
+ $res .= commonPage::tMain(null,wsDroits::admin());\r
$res .= commonPage::bh();\r
$res .= '<div id="listeBooks">';\r
$res .= self::listeBooks();\r
$odd = cubeMath::isOdd($i)?' class="odd"':'';\r
$res .= '<tr' . $odd . '>';\r
$res .= '<td>' . $book->book_id . '</td>';\r
- $res .= '<td>' . $book->nom . '</td>';\r
+ $res .= '<td>' . html::escapeHTML($book->nom) . '</td>';\r
$res .= '<td>' . mb_strtoupper($book->lang) . '</td>';\r
$res .= '<td>' . $book->parametres->pages . '</td>';\r
\r
if ($droits->revendeur) {\r
- $p = str_replace(" (", '<br /><em>', $book->proprietaire);\r
+ $p = str_replace(" (", '<br /><em>', html::escapeHTML($book->proprietaire));\r
$p = str_replace(')', '</em>', $p);\r
$res .= '<td><a href="#" class="popup" rel="formChangeBookProprietaire/' . $book->book_id . '" title="' . __('Mofifier le proprietaire') . '">' . $p . '</a></td>';\r
} else {\r
- $res .= '<td>' . $book->proprietaire_utilisateur . '</td>';\r
+ $res .= '<td>' . html::escapeHTML($book->proprietaire_utilisateur) . '</td>';\r
}\r
if ($droits->admin) {\r
- $res .= '<td>' . $book->facturable . '</td>';\r
+ $res .= '<td>' . html::escapeHTML($book->facturable) . '</td>';\r
}\r
if ($droits->revendeur) {\r
if ($droits->admin || $book->status <= 1) {\r
$jsvar['IMG'] = IMG;\r
$jsvar['SITE_PATH'] = SITE_PATH;\r
$css[] = CSS_PATH . '/style.css';\r
-$standard = 'XHTML 1.0 Strict';\r
+$standard = 'XHTML 1.0 Transitional';\r
\r
echo $core->url->getDocument();\r
$buffer = ob_get_contents();\r