summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorScott McLewin2012-03-08 05:47:37 (GMT)
committer Scott McLewin2012-03-08 05:47:37 (GMT)
commit6660c335299ad294d0559601b30625a887ad8895 (patch)
treef62afb419c6a5b3dabaa288492bbd590c0905dd6
parent1f53034c8f495d09888263fcd459f816a7f9172d (diff)
Formatting and cleanup.6.x-2.66.x-2.x
-rw-r--r--wishlist.module4
1 files changed, 2 insertions, 2 deletions
diff --git a/wishlist.module b/wishlist.module
index 77bbea0..7a7eb70 100644
--- a/wishlist.module
+++ b/wishlist.module
@@ -1065,12 +1065,12 @@ function wishlist_reveal_form() {
'#type' => 'select',
'#name' => 'wishlist_reveal',
'#title' => '',
- '#default_value' => (isset($_GET['wl_reveal']) ? $_GET['wl_reveal'] : 0),
+ '#default_value' => (isset($_GET['wl_reveal']) ? check_plain($_GET['wl_reveal']) : 0),
'#options' => array(0 => t('Hide purchase details'), 1 => t('Show purchase details')),
'#description' => '',
'#multiple' => $multiple = FALSE,
'#required' => $required = FALSE,
- '#attributes' => array('onChange' => "top.location.href='/".$_GET['q']."?wl_reveal='+this.value"),
+ '#attributes' => array('onChange' => "top.location.href='/".check_plain($_GET['q'])."?wl_reveal='+this.value"),
);
return $form;