From 79f869723b14def7f57db9fc3b6144564fb3082f Mon Sep 17 00:00:00 2001 From: Seamus Lee Date: Tue, 19 Sep 2017 13:23:29 +1000 Subject: [PATCH] CRM-21123 Ensure that the selectedChild on message templates is one of allowed types CRM-21123 Put the array into the if statement --- CRM/Admin/Page/MessageTemplates.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CRM/Admin/Page/MessageTemplates.php b/CRM/Admin/Page/MessageTemplates.php index d94ffc020e..b9b99b4235 100644 --- a/CRM/Admin/Page/MessageTemplates.php +++ b/CRM/Admin/Page/MessageTemplates.php @@ -199,9 +199,10 @@ class CRM_Admin_Page_MessageTemplates extends CRM_Core_Page_Basic { CRM_Core_BAO_MessageTemplate::revert($id); } - - $this->assign('selectedChild', CRM_Utils_Request::retrieve('selectedChild', 'String', $this)); - + $selectedChild = CRM_Utils_Request::retrieve('selectedChild', 'String', $this); + if (in_array($selectedChild, array('user', 'workflow'))) { + $this->assign('selectedChild', $selectedChild); + } return parent::run($args, $pageArgs, $sort); } -- 2.25.1