use escape
authorAlan <alan@roojs.com>
Wed, 28 Jun 2023 09:06:49 +0000 (17:06 +0800)
committerAlan <alan@roojs.com>
Wed, 28 Jun 2023 09:06:49 +0000 (17:06 +0800)
DataObjects/Mtrack_change.php

index 3d9dbb4..3e63d62 100644 (file)
@@ -766,13 +766,13 @@ class Pman_MTrack_DataObjects_Mtrack_change extends DB_DataObject
         $res = $tg->factory('SendMessage',array(
             'chat_id' => 35721679,
             'parse_mode' => 'MarkdownV2',
-            'text' => "/ticket@{$this->onid}  *". htmlspecialchars($t->summary) . "*\n\n".
-                    "{$this->cgtype} by {$this->person()->name} \n\n" . htmlspecialchars(implode("\n", $str))
+            'text' => "/ticket@{$this->onid}  *". $tg->escape($t->summary) . "*\n\n".
+                    "{$this->cgtype} by ". $tg->escape($this->person()->name) . "\n\n" . $tg->escape(implode("\n", $str))
                 
           
         ))->send();
          
-         print_R($res);exit;
+         
     }