return $data;
}
+function html_cleanup(&$parms)
+{
+ foreach($parms as $name => $value) {
+// $value = @html_entity_decode($value, ENT_QUOTES, $_SESSION['language']->encoding);
+ if (is_array($value))
+ html_cleanup($parms[$name]);
+ else
+ $parms[$name] = @htmlspecialchars($value, ENT_QUOTES, $_SESSION['language']->encoding);
+ }
+ reset($parms); // needed for direct key() usage later throughout the sources
+}
+
//============================================================================
//
//
if (isset($_GET['path_to_root']) || isset($_POST['path_to_root']))
die("Restricted access");
+include_once($path_to_root . "/includes/errors.inc");
+// colect all error msgs
+set_error_handler('error_handler' /*, errtypes */);
+
include_once($path_to_root . "/includes/current_user.inc");
include_once($path_to_root . "/frontaccounting.php");
include_once($path_to_root . "/admin/db/security_db.inc");
include_once($path_to_root . "/includes/ui/ui_msgs.inc");
include_once($path_to_root . "/includes/prefs/sysprefs.inc");
+include_once($path_to_root . "/includes/hooks.inc");
+
/*
Uncomment the setting below when using FA on shared hosting
to avoid unexpeced session timeouts.
ini_set('session.gc_maxlifetime', 36000); // 10hrs
session_name('FA'.md5(dirname(__FILE__)));
+//include_once($path_to_root.'/modules/www_statistics/includes/db_sessions.inc');
session_start();
// this is to fix the "back-do-you-want-to-refresh" issue - thanx PHPFreaks
$_SESSION['language']->set_language($_SESSION['language']->code);
-// include $Hooks object if locale file exists
-if (file_exists($path_to_root . "/lang/".$_SESSION['language']->code."/locale.inc"))
-{
- include_once($path_to_root . "/lang/".$_SESSION['language']->code."/locale.inc");
- $Hooks = new Hooks();
-}
include_once($path_to_root . "/includes/access_levels.inc");
include_once($path_to_root . "/version.php");
register_shutdown_function('end_flush');
ob_start('output_html',0);
-// colect all error msgs
-set_error_handler('error_handler' /*, errtypes */);
-
if (!isset($_SESSION["wa_current_user"]))
$_SESSION["wa_current_user"] = new current_user();
+html_cleanup($_GET);
+html_cleanup($_POST);
+html_cleanup($_REQUEST);
+html_cleanup($_SERVER);
+
// logout.php is the only page we should have always
// accessable regardless of access level and current login status.
if (strstr($_SERVER['PHP_SELF'], 'logout.php') == false){
{
// strip ajax marker from uri, to force synchronous page reload
$_SESSION['timeout'] = array( 'uri'=>preg_replace('/JsHttpRequest=(?:(\d+)-)?([^&]+)/s',
- '', @$_SERVER['REQUEST_URI']),
+ '', @htmlspecialchars($_SERVER['REQUEST_URI'], ENT_QUOTES, $_SESSION['language']->encoding)),
'post' => $_POST);
include($path_to_root . "/access/login.php");
if (!$_SESSION["wa_current_user"]->old_db)
include_once($path_to_root . '/company/'.user_company().'/installed_extensions.php');
+ install_hooks();
+
if (!isset($_SESSION["App"])) {
$_SESSION["App"] = new front_accounting();
$_SESSION["App"]->init();
// POST vars cleanup needed for direct reuse.
// We quote all values later with db_escape() before db update.
- $_POST = strip_quotes($_POST);
+$_POST = strip_quotes($_POST);
?>
\ No newline at end of file