1 <% include('/elements/header.html', 'Preferences for '. getotaker ) %>
3 <FORM METHOD="POST" NAME="pref_form" ACTION="pref-process.html">
5 <% include('/elements/error.html') %>
8 Change password (leave blank for no change)
9 <% ntable("#cccccc",2) %>
12 <TD ALIGN="right">Current password: </TD>
13 <TD><INPUT TYPE="password" NAME="_password"></TD>
17 <TD ALIGN="right">New password: </TD>
18 <TD><INPUT TYPE="password" NAME="new_password"></TD>
22 <TD ALIGN="right">Re-enter new password: </TD>
23 <TD><INPUT TYPE="password" NAME="new_password2"></TD>
30 <% ntable("#cccccc",2) %>
33 <TD>Menu location: </TD>
35 <INPUT TYPE="radio" NAME="menu_position" VALUE="left" onClick="document.images['menu_example'].src='../images/menu-left-example.png';" <% $menu_position eq 'left' ? ' CHECKED' : ''%>> Left<BR>
36 <INPUT TYPE="radio" NAME="menu_position" VALUE="top"onClick="document.images['menu_example'].src='../images/menu-top-example.png';" <% $menu_position eq 'top' ? ' CHECKED' : ''%>> Top <BR>
38 <TD><IMG NAME="menu_example" SRC="../images/menu-<% $menu_position %>-example.png"></TD>
44 % foreach my $prop (qw( height width availHeight availWidth colorDepth )) {
45 <INPUT TYPE="hidden" NAME="<% $prop %>" VALUE="">
46 <SCRIPT TYPE="text/javascript">
47 document.pref_form.<% $prop %>.value = screen.<% $prop %>;
51 <INPUT TYPE="submit" VALUE="Update preferences">
53 <% include('/elements/footer.html') %>
56 # XSS via your own preferences? seems unlikely, but nice try anyway...
57 ( $FS::CurrentUser::CurrentUser->option('menu_position') || 'left' )
58 =~ /^(\w+)$/ or die "illegal menu_position";
59 my $menu_position = $1;