Bug 13425 - XSS in opac facets - Patch for master and 3.18
[koha-equinox.git] / koha-tmpl / opac-tmpl / bootstrap / en / includes / opac-facets.inc
index 7044bfd..e1b69a5 100644 (file)
                                   [% IF facet.active %]
                                     [% SET url = url _ "&nolimit=" _ facet.type_link_value _ ":" _ facet.facet_link_value %]
                                     <span class="facet-label">[% facet.facet_label_value %]</span>
-                                    [<a href="[% url %]" title="Remove facet [% facet.facet_link_value | html %]">x</a>]
+                                    [<a href="[% url |url%]" title="Remove facet [% facet.facet_link_value | html %]">x</a>]
                                   [% ELSE %]
                                     [% SET url = url _ "&amp;limit=" _ facet.type_link_value _ ":" _ facet.facet_link_value %]
-                                    <span class="facet-label"><a href="[% url %]" title="[% facet.facet_title_value |html %]">[% facet.facet_label_value %]</a></span>
+                                    <span class="facet-label"><a href="[% url |url%]" title="[% facet.facet_title_value |html %]">[% facet.facet_label_value %]</a></span>
                                     [% IF ( displayFacetCount ) %]
                                       <span class="facet-count"> ([% facet.facet_count %])</span>
                                     [% END %]