Bug 22781: Escape cardnumber, category's description, library's name and dateexpiry
[koha.git] / koha-tmpl / intranet-tmpl / prog / en / modules / members / tables / members_results.tt
index e7bb691..bb0e176 100644 (file)
                     "<input type='checkbox' class='selection' name='borrowernumber' value='[% data.borrowernumber %]' />",
                 [% END %]
                 "dt_cardnumber":
-                    "[% data.cardnumber | html %]",
+                    "[% data.cardnumber | html | $To %]",
                 "dt_name":
                     "<span style='white-space:nowrap'><a href='/cgi-bin/koha/members/moremember.pl?borrowernumber=[% data.borrowernumber %]'>[% INCLUDE 'patron-title.inc' borrowernumber = data.borrowernumber category_type = data.category_type firstname = To.json(data.firstname) surname = To.json(data.surname) othernames = To.json(data.othernames) invert_name = 1 %]</a><br />[% INCLUDE escape_address data = data %][% IF data.email %]<br/>Email: <a href='mailto:[% data.email | html %]'>[% data.email | html %]</a>[% END %]</span>",
     "dt_dateofbirth":
         "[% data.dateofbirth | $KohaDates %]",
                 "dt_category":
-                    "[% data.category_description |html %] ([% data.category_type |html %])",
+                    "[% data.category_description | html | $To %] ([% data.category_type | html | $To %])",
                 "dt_branch":
-                    "[% data.branchname |html %]",
+                    "[% data.branchname | html | $To %]",
                 "dt_dateexpiry":
-                    "[% data.dateexpiry %]",
+                    "[% data.dateexpiry | html | $To %]",
                 "dt_od_checkouts":
                     "[% IF data.overdues %]<span class='overdue'><strong>[% data.overdues %]</strong></span>[% ELSE %][% data.overdues %][% END %] / [% data.issues %]",
                 "dt_fines":