$include_attachments = (bool)db_escape_string($_REQUEST["include_attachments"]);
$since_id = (int)db_escape_string($_REQUEST["since_id"]);
$include_nested = (bool)db_escape_string($_REQUEST["include_nested"]);
+ $sanitize_content = true;
/* do not rely on params below */
$headlines = api_get_headlines($this->link, $feed_id, $limit, $offset,
$filter, $is_cat, $show_excerpt, $show_content, $view_mode, false,
$include_attachments, $since_id, $search, $search_mode, $match_on,
- $include_nested);
+ $include_nested, $sanitize_content);
print $this->wrap(self::STATUS_OK, $headlines);
} else {
function api_get_headlines($link, $feed_id, $limit, $offset,
$filter, $is_cat, $show_excerpt, $show_content, $view_mode, $order,
$include_attachments, $since_id,
- $search = "", $search_mode = "", $match_on = "", $include_nested = false) {
+ $search = "", $search_mode = "", $match_on = "",
+ $include_nested = false, $sanitize_content = true) {
$qfh_ret = queryFeedHeadlines($link, $feed_id, $limit,
$view_mode, $is_cat, $search, $search_mode, $match_on,
}
if ($show_content) {
- $headline_row["content"] = $line["content_preview"];
+ if ($sanitize_content) {
+ $headline_row["content"] = sanitize($link,
+ $line["content_preview"], false, false, $line["site_url"]);
+ } else {
+ $headline_row["content"] = $line["content_preview"];
+ }
}
// unify label output to ease parsing