[FOLLOWUP][FEATURE] Avatar for backend users 11/41911/3
authorGeorg Ringer <georg.ringer@gmail.com>
Fri, 24 Jul 2015 04:13:38 +0000 (06:13 +0200)
committerMarkus Klein <markus.klein@typo3.org>
Thu, 30 Jul 2015 22:24:57 +0000 (00:24 +0200)
The avatar is now really shown in the element information popup.
An additional call to htmlspecialchars() is added as well.

Change-Id: I960dc7630abe864dfef01650bcaf36021161392f
Resolves: #48947
Resolves: #57515
Releases: master
Reviewed-on: http://review.typo3.org/41911
Reviewed-by: Josef Glatz <jousch@gmail.com>
Tested-by: Josef Glatz <jousch@gmail.com>
Reviewed-by: Markus Klein <markus.klein@typo3.org>
Tested-by: Markus Klein <markus.klein@typo3.org>
typo3/sysext/backend/Classes/Controller/ContentElement/ElementInformationController.php

index e8b8681..559686c 100644 (file)
@@ -367,7 +367,7 @@ class ElementInformationController {
 
                                        $rowValue = '<span class="pull-left">' . $icon . '</span>' .
                                        '<strong>' . htmlspecialchars($GLOBALS['BE_USER']->user['username']) . '</strong><br />'
-                                       . ($GLOBALS['BE_USER']->user['realName']) ? $GLOBALS['BE_USER']->user['realName'] : '';
+                                       . ($GLOBALS['BE_USER']->user['realName'] ? htmlspecialchars($GLOBALS['BE_USER']->user['realName']) : '');
                                }
                        }