diff --git a/CHANGELOG b/CHANGELOG index 281f254..5fa4146 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -1,6 +1,8 @@ +Version 1.16.4 - Apr. 15, 2016 Properly escape some parameters Add caching hack for aggressively caching browsers (e.g. links) Improve invalid filter handling + allow new line match with \n +Fix a few forms to be used cookie-less Version 1.16.3 - Apr. 14, 2016 Fix warning on redirection of links without a scheme diff --git a/chat.php b/chat.php index 87b56d8..720742e 100644 --- a/chat.php +++ b/chat.php @@ -366,7 +366,7 @@ function send_access_denied(){ echo "
<$H[form]>$H[commonform]".hidden('action', 'setup').hidden('do', 'backup'); if(!isSet($_REQUEST['session'])){ - hidden('session', $U['session']); + echo hidden('session', $U['session']); } echo submit($I['backuprestore']).' | '; echo "<$H[form]>$H[commonform]".hidden('action', 'setup').hidden('do', 'destroy'); if(!isSet($_REQUEST['session'])){ - hidden('session', $U['session']); + echo hidden('session', $U['session']); } echo submit($I['destroy'], 'class="delbutton"').' |