X-Git-Url: http://git.shiar.net/minimedit.git/blobdiff_plain/159ee0f3d812c9681a00c37f6a2bcaf8a1de83bc..a7131e1013d54f0a6f0e80d05d04ff724d68466e:/upload.inc.php
diff --git a/upload.inc.php b/upload.inc.php
index ed9ee77..6175fe2 100644
--- a/upload.inc.php
+++ b/upload.inc.php
@@ -41,10 +41,17 @@ function userupload($input, $target = NULL, $filename = NULL)
function messagehtml($input)
{
# convert user textarea post to formatted html
+ global $User;
if (empty($input)) {
return;
}
- $html = htmlspecialchars($input);
- $html = nl2br($html);
+ if ($User->admin and preg_match('/\A<[a-z][^>]*>/', $input)) {
+ return $input; # allow html input as is if privileged
+ }
+ $html = preg_replace(
+ ["/\r?\n/", "'(?:
\n?){2}'"],
+ ["
\n", "
"], + htmlspecialchars($input) + ); return "
$html
"; }