Posts by minti

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

+1

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

So the fix for the XSS vulnerability is this line only, am I right?

if(hashtag){  hashtag = hashtag.replace(/<|>/g,''); }

Also, what is the timeframe to have this fixed? I know ASAP, just wanted to know if there is a deadline?

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

Great News!

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says


Hey guys,

Just wanted to be a little bit helpful. In my case, it worked just fine with the version from the Dev branch. That is: https://raw.githubusercontent.com/thomasgriffin/TGM-Plugin-Activation/develop/class-tgm-plugin-activation.php

Have a great day! Paul
+1 this works for me too, both local host and server

+1 whatever version this is, it works for me. The version suggested by StephenCronin doesn’t.

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says
$br = '<br />';
echo esc_html($br)

This does not make any sense at all. It would be nice to get a clear guideline on what to escape and what not.

Also, what is the correct way to deal with fields that allow HTML, such as a “Copyright Textarea” and Custom CSS (with > signs), Google Analytics Code, ..

- esc_html() followed by htmlspecialchars_decode() wouldn’t also make any sense as malicious code would be rendered again.

- wp_kses has a performance impact.

Has anyone a good solution and could we please get a clarification on this @envato?

Thanks!

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

I never had a job :|

+1

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says


Wow, yeah why is this unstickied when we haven’t even heard back from Collis yet?
+1 this should be stickied, it’s very important

+1 Bump. Seriously Envato? Are you trying to sweep things under the mat by adding new features and contests? This needs to be stickied!

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

Just brilliant.

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says


I’m also using the “Envato_marketplaces.php” – https://github.com/Japh/Envato-Marketplace-API-Wrapper-in-PHP/blob/master/Envato_marketplaces.php Any quick solution for this? I’m on vacation right now and don’t want to fiddle around with code too much here ;)
Hey there, here you can find the curl function from the Envato_marketplace.php file modified! ;)

You’re a lifesaver! Thanks a lot – works like a breeze :inlove:

62 posts
  • Became a Top 20 Author of the Month
  • Has referred 200+ members
  • Has sold $750,000+ on Envato Market
  • Has collected 100+ items on Envato Market
+7 more
minti
says

I’m also using the “Envato_marketplaces.php” – https://github.com/Japh/Envato-Marketplace-API-Wrapper-in-PHP/blob/master/Envato_marketplaces.php

Any quick solution for this? I’m on vacation right now and don’t want to fiddle around with code too much here ;)

by
by
by
by
by
by