Bug 21526: uri escape TT variables when used in 'a href'
[koha_ffzg] / koha-tmpl / intranet-tmpl / prog / en / modules / serials / serials-collection.tt
index 1af50fe..2244f70 100644 (file)
@@ -49,7 +49,7 @@
 </tr>
 [% FOREACH subscription IN subscriptions %]
     <tr>
-        <td><a href="subscription-detail.pl?subscriptionid=[% subscription.subscriptionid | html %]"># [% subscription.subscriptionid | html %]</a> </td>
+        <td><a href="subscription-detail.pl?subscriptionid=[% subscription.subscriptionid | uri %]"># [% subscription.subscriptionid | html %]</a> </td>
         <td>[% subscription.frequency.description | html %]</td>
         <td>[% subscription.numberpattern.label | html %]</td>
         <td>[% IF subscription.branchcode %][% Branches.GetName( subscription.branchcode ) | html %][% END %]</td>
@@ -87,7 +87,7 @@
 [% END %]
 [% IF ( subscr ) %]
 [% IF ( subscriptioncount > 1 ) %]
-<tr ><td colspan="8">  <a href="serials-collection.pl?biblionumber=[% biblionumber | html %]">See any subscription attached to this biblio</a></td>
+<tr ><td colspan="8">  <a href="serials-collection.pl?biblionumber=[% biblionumber | uri %]">See any subscription attached to this biblio</a></td>
 </tr>
 [% END %]
 [% END %]
             [% IF year.year == 'manage' %]
                 <li><a href="#subscription-year-manage">Manage</a></li>
             [% ELSE %]
-                <li><a href="#subscription-year-[% year.year | html %]">[% year.year | html %]</a></li>
+                <li><a href="#subscription-year-[% year.year | uri %]">[% year.year | html %]</a></li>
             [% END %]
         [% END %]
     [% END %]
                 </td>
             [% END %]
 [% IF ( subscriptions.size > 1 ) %]
-                 <td><a href="serials-collection.pl?subscriptionid=[% serial.subscriptionid | html %]">[% serial.subscriptionid | html %]</a></td>
+                 <td><a href="serials-collection.pl?subscriptionid=[% serial.subscriptionid | uri %]">[% serial.subscriptionid | html %]</a></td>
 [% END %]
                 <td>
                     <span title="[% serial.publisheddate | html %]">