Page 1 of 1

Skins submission/display issue

PostPosted: July 18th, 2008, 2:04 am
by SLoB
Cliff
you need to add in htmlspecialchars for skin/pic names to prevent people abusing/misusing/accidentally boshing ampersands in their skins titles/pictures etc..

for example new skin just added
http://xion.r2.com.au/skins/paqra/roll_&_rock_full.jpg

should be

http://xion.r2.com.au/skins/paqra/roll_ ... k_full.jpg

PostPosted: July 18th, 2008, 8:10 am
by Cliff Cawley
You only need to do that when storing in a database. Storing on a filesystem using the characters is fine. In the database that skin is currently stored as roll_&_rock :)

Cliff :)

PostPosted: July 18th, 2008, 8:16 am
by SLoB
its broken on the site, check it out on the skins page, the recent update also barfs, the skin preview barfs and the main skin pic barfs

The requested URL /skins/paqra/roll_&_rock_full.jpg was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.