Thanks MoT3rror,
but this is for the php file.
I need it for the javascript!
--------------- Added [DATE]1214975648[/DATE] at [TIME]1214975648[/TIME] ---------------
ok I know I should use escapeHTML()
but how to add that to this code?
Code:
<script type="text/javascript">
function init()
{
Event.observe("edit", "click", function(e){ edit_in_place() });
Event.observe("save", "click", function(e){ save() });
Event.observe("cancel", "click", function(e){ cancel() });
}
function edit_in_place()
{
$("save_settings").style.display = "inline";
$("edit_settings").style.display = "none";
var article_title = '<input type="text" name="article_title" id="article_title"';
article_title += 'size="30" value="'+$("title").innerHTML+'" >';
$("title").innerHTML = article_title;
}
function save()
{
new Ajax.Request("articles.php",
{
method: "post",
postBody: "title="+$F("article_title")+
"&uid=1"+"&save="+$F("save"),
onComplete: show
}
);
}
function show(res)
{
$("title").innerHTML = $("article_title").value;
$("save_settings").style.display = "none";
$("edit_settings").style.display = "inline";
}
function cancel()
{
$("title").innerHTML = "Edit the article title here...";
$("save_settings").style.display = "none";
$("edit_settings").style.display = "inline";
}
</script>