From 0934fa9a63bc76b07a75c330a964866e1bd1ee08 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Wed, 6 Jun 2018 10:33:52 -0600 Subject: [PATCH] Update conference_rooms.php --- app/conference_centers/conference_rooms.php | 73 +++++++++++---------- 1 file changed, 39 insertions(+), 34 deletions(-) diff --git a/app/conference_centers/conference_rooms.php b/app/conference_centers/conference_rooms.php index 289a3884a9..dc2bf86a72 100644 --- a/app/conference_centers/conference_rooms.php +++ b/app/conference_centers/conference_rooms.php @@ -17,22 +17,26 @@ The Initial Developer of the Original Code is Mark J Crane - Portions created by the Initial Developer are Copyright (C) 2008-2014 + Portions created by the Initial Developer are Copyright (C) 2008-2018 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ -require_once "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (permission_exists('conference_room_view')) { - //access granted -} -else { - echo "access denied"; - exit; -} + +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('conference_room_view')) { + //access granted + } + else { + echo "access denied"; + exit; + } //add multi-lingual support $language = new text; @@ -153,7 +157,7 @@ else { echo "
\n"; echo " ".$text['title-conference_rooms']."\n"; echo " \n"; - echo " "; + echo " "; echo " "; echo " \n"; echo "
\n"; @@ -247,58 +251,58 @@ else { $participant_pin = substr($participant_pin, 0, 3) ."-". substr($participant_pin, 3, 3) ."-". substr($participant_pin, -3)."\n"; } - $tr_link = (permission_exists('conference_room_edit')) ? "href='conference_room_edit.php?id=".$row['conference_room_uuid']."'" : null; + $tr_link = (permission_exists('conference_room_edit')) ? "href='conference_room_edit.php?id=".escape($row['conference_room_uuid'])."'" : null; echo "\n"; echo " ".(($conference_room_name != '') ? "".$conference_room_name."" : " ")."\n"; echo " ".$moderator_pin."\n"; echo " ".$participant_pin."\n"; - //echo " ".$row['conference_center_uuid']." \n"; - //echo " ".$row['meeting_uuid']." \n"; - //echo " ".$row['profile']." \n"; + //echo " ".escape($row['conference_center_uuid'])." \n"; + //echo " ".escape($row['meeting_uuid'])." \n"; + //echo " ".escape($row['profile'])." \n"; echo " "; if ($row['record'] == "true") { - echo " ".$text['label-true'].""; + echo " ".$text['label-true'].""; } else { - echo " ".$text['label-false'].""; + echo " ".$text['label-false'].""; } echo "  \n"; echo " \n"; //echo " ".$row['max_members']." \n"; echo " "; if ($row['wait_mod'] == "true") { - echo " ".$text['label-true'].""; + echo " ".$text['label-true'].""; } else { - echo " ".$text['label-false'].""; + echo " ".$text['label-false'].""; } echo "  \n"; echo " \n"; echo " "; if ($row['announce'] == "true") { - echo " ".$text['label-true'].""; + echo " ".$text['label-true'].""; } else { - echo " ".$text['label-false'].""; + echo " ".$text['label-false'].""; } echo "  \n"; echo " \n"; echo " "; if ($row['mute'] == "true") { - echo " ".$text['label-true']." "; + echo " ".$text['label-true']." "; } else { - echo " ".$text['label-false']." "; + echo " ".$text['label-false']." "; } echo " \n"; echo " "; if ($row['sounds'] == "true") { - echo " ".$text['label-true'].""; + echo " ".$text['label-true'].""; } else { - echo " ".$text['label-false'].""; + echo " ".$text['label-false'].""; } echo "  \n"; echo " \n"; @@ -310,33 +314,33 @@ else { echo " 0\n"; } echo " \n"; - echo " ".$text['label-view']." \n"; - echo " ".$text['label-sessions']."\n"; + echo " ".$text['label-view']." \n"; + echo " ".$text['label-sessions']."\n"; echo " \n"; if (permission_exists('conference_room_enabled')) { echo " "; if ($row['enabled'] == "true") { - echo " ".$text['label-true'].""; + echo " ".$text['label-true'].""; } else { - echo " ".$text['label-false'].""; + echo " ".$text['label-false'].""; } echo "  \n"; echo " \n"; } echo " "; - echo " ".$row['description']."\n"; + echo " ".escape($row['description'])."\n"; echo "  \n"; echo " \n"; echo " "; if (permission_exists('conference_room_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('conference_room_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; @@ -369,4 +373,5 @@ else { //include the footer require_once "resources/footer.php"; -?> \ No newline at end of file + +?>