On Fri, 10 Jul 2015 at 16:24:05, Marcel Korpel wrote:
[...] - <?php if ($row['UserName'] && $SID): - $row['UserName'] = "<a href=\"" . get_user_uri($row['UserName']) . "\">{$row['UserName']}</a>"; - endif; ?> + <?php if ($row['UserName'] && $SID) { + $row['UserName'] = '<a href="' . get_user_uri($row['UserName']) . '">' . htmlspecialchars($row['UserName']) . '</a>'; + } else { + $row['UserName'] = htmlspecialchars($row['UserName']); + } + if ($row['DelUserName'] && $SID) { + $row['DelUserName'] = '<a href="' . get_user_uri($row['DelUserName']) . '">' . htmlspecialchars($row['DelUserName']) . '</a>'; + } else { + $row['DelUserName'] = htmlspecialchars($row['DelUserName']); + } + if ($row['EditUserName'] && $SID) { + $row['EditUserName'] = '<a href="' . get_user_uri($row['EditUserName']) . '">' . htmlspecialchars($row['EditUserName']) . '</a>'; + } else { + $row['EditUserName'] = htmlspecialchars($row['EditUserName']); + } ?> [...]
Can we use html_format_username() or a similar helper function here?