diff --git a/src/dede/js/main.js b/src/dede/js/main.js index d85f885c..abccb8f0 100755 --- a/src/dede/js/main.js +++ b/src/dede/js/main.js @@ -354,7 +354,6 @@ function CkRemote() { //载入指定宽高的AJAX窗体 function LoadQuickDiv(e, surl, oname, w, h) { - console.log(e); if ($Nav() == 'IE') { if (window.event) { var posLeft = window.event.clientX - 20; diff --git a/src/plus/recommend.php b/src/plus/recommend.php index f0f93ef4..11fa6259 100755 --- a/src/plus/recommend.php +++ b/src/plus/recommend.php @@ -25,36 +25,26 @@ if (empty($aid)) { //读取文档信息 if ($action == '') { - if ($type == 'sys') { - //读取文档信息 - $arcRow = GetOneArchive($aid); - if ($arcRow['aid'] == '') { - ShowMsg("无法把未知文档推荐给好友!", "-1"); - exit(); - } - extract($arcRow, EXTR_OVERWRITE); - } else { - $arcRow = $dsql->GetOne("SELECT s.*,t.* FROM `#@__member_stow` AS s LEFT JOIN `#@__member_stowtype` AS t ON s.type=t.stowname WHERE s.aid='$aid' AND s.type='$type'"); - if (!is_array($arcRow)) { - ShowMsg("无法把未知文档推荐给好友!", "-1"); - exit(); - } - $arcRow['arcurl'] = $arcRow['indexurl'] . "=" . $arcRow['aid']; - extract($arcRow, EXTR_OVERWRITE); + //读取文档信息 + $arcRow = GetOneArchive($aid); + if ($arcRow['aid'] == '') { + ShowMsg("无法把未知文档推荐给好友!", "-1"); + exit(); } + extract($arcRow, EXTR_OVERWRITE); } //发送推荐信息 else if ($action == 'send') { if (!CheckEmail($email)) { - echo ""; + ShowMsg("Email格式不正确", -1); exit(); } $mailbody = ''; - $msg = dede_htmlspecialchars($msg); + $msg = RemoveXSS(dede_htmlspecialchars($msg)); $mailtitle = "你的好友给你推荐了一篇文章"; $mailbody .= "$msg \r\n\r\n"; - $mailbody .= "Power by https://www.dedebiz.com DedeCMSV6内容管理系统!"; + $mailbody .= "Powered by https://www.dedebiz.com DedeCMSV6内容管理系统!"; $headers = "From: " . $cfg_adminemail . "\r\nReply-To: " . $cfg_adminemail; diff --git a/src/templets/default/widget_article_feedback.htm b/src/templets/default/widget_article_feedback.htm index f70f8e9b..7ae7da05 100644 --- a/src/templets/default/widget_article_feedback.htm +++ b/src/templets/default/widget_article_feedback.htm @@ -233,7 +233,6 @@ $.post("{dede:field name='phpurl'/}/feedback.php", good, function (data) { let result = JSON.parse(data); $(`#feedbackGood${fid}`).html(result.data); - console.log(result); }) } \ No newline at end of file diff --git a/src/templets/plus/comments_frame.htm b/src/templets/plus/comments_frame.htm deleted file mode 100755 index d08d2a4f..00000000 --- a/src/templets/plus/comments_frame.htm +++ /dev/null @@ -1,171 +0,0 @@ - - -
- -你好友的Email: | -- |
你的留言: | -|
+ | + + | +