diff --git a/main/exercice/showinframes.php b/main/exercice/showinframes.php index 5ab7fea785..6fb34d11c9 100644 --- a/main/exercice/showinframes.php +++ b/main/exercice/showinframes.php @@ -1,28 +1,9 @@ - - "> + + <body> <p>This page uses frames, but your browser doesn't support them. @@ -130,7 +111,7 @@ if ($origin!='learnpath') { } else { ?> <script language='Javascript' type='text/javascript'> - s='<?php echo $documentWebPath.$doc_url.$_user['user_id']; ?>.t.html?time=<?php echo $time; ?>'; + s='<?php echo $documentWebPath.$doc_url.$_user['user_id']; ?>.t.html?time=<?php echo Security::remove_XSS($time); ?>'; //document.write(s); window.location=s; </script> diff --git a/main/exercice/testheaderpage.php b/main/exercice/testheaderpage.php index 1a6f9ab0cd..d6c0b617f0 100644 --- a/main/exercice/testheaderpage.php +++ b/main/exercice/testheaderpage.php @@ -1,55 +1,34 @@ -<?php -/* - DOKEOS - elearning and course management software - - For a full list of contributors, see documentation/credits.html - - This program is free software; you can redistribute it and/or - modify it under the terms of the GNU General Public License - as published by the Free Software Foundation; either version 2 - of the License, or (at your option) any later version. - See "documentation/licence.html" more details. - - Contact: - Dokeos - Rue des Palais 44 Paleizenstraat - B-1030 Brussels - Belgium - Tel. +32 (2) 211 34 56 -*/ - - +<?php //$id: $ +/* For licensing terms, see /dokeos_license.txt */ /** * Code library for HotPotatoes integration. * @package dokeos.exercise * @author Istvan Mandak -* @version $Id: testheaderpage.php 20451 2009-05-10 12:02:22Z ivantcholakov $ */ - // name of the language file that needs to be included $language_file='exercice'; -include('../inc/global.inc.php'); - - require_once(api_get_path(SYS_CODE_PATH).'exercice/hotpotatoes.lib.php'); - $documentPath= api_get_path(SYS_COURSE_PATH).$_course['path']."/document"; - $my_file = Security::remove_XSS($_GET['file']); - $title = GetQuizName($my_file,$documentPath); - if ($title =='') { - $title = GetFileName($my_file); - } - $nameTools = $title; - $noPHP_SELF=true; - if (isset($_SESSION['gradebook'])){ - $gradebook= $_SESSION['gradebook']; - } - - if (!empty($gradebook) && $gradebook=='view') { - $interbreadcrumb[]= array ( - 'url' => '../gradebook/'.$_SESSION['gradebook_dest'], - 'name' => get_lang('Gradebook') - ); - } - $interbreadcrumb[]= array ("url"=>"./exercice.php", "name"=> get_lang('Exercices')); - Display::display_header($nameTools,"Exercise"); - echo "<a name='TOP'></a>"; -?> +require '../inc/global.inc.php'; + +require_once(api_get_path(SYS_CODE_PATH).'exercice/hotpotatoes.lib.php'); +$documentPath= api_get_path(SYS_COURSE_PATH).$_course['path']."/document"; +$my_file = Security::remove_XSS($_GET['file']); +$title = GetQuizName($my_file,$documentPath); +if ($title =='') { + $title = GetFileName($my_file); +} +$nameTools = $title; +$noPHP_SELF=true; +if (isset($_SESSION['gradebook'])){ + $gradebook= $_SESSION['gradebook']; +} + +if (!empty($gradebook) && $gradebook=='view') { + $interbreadcrumb[]= array ( + 'url' => '../gradebook/'.$_SESSION['gradebook_dest'], + 'name' => get_lang('Gradebook') + ); +} +$interbreadcrumb[]= array ("url"=>"./exercice.php", "name"=> get_lang('Exercices')); +Display::display_header($nameTools,"Exercise"); +echo "<a name='TOP'></a>"; \ No newline at end of file