fix XSS
[freeside.git] / httemplate / edit / cust_main / top_misc.html
index 7ba167b..cfed8e4 100644 (file)
        <% $cust_main->residential_commercial eq 'Commercial' ? 'CHECKED' : '' %>
   ></TD>
 </TR>
-
 <SCRIPT TYPE="text/javascript">
-  function rescom_changed() {
-    var f = document.CustomerForm;
-
-    if        ( f.residential_commercial_Residential.checked ) {
-      document.getElementById('contacts_div').style.display = 'none';
-    } else { // if ( f.residential_commercial_Commercial.checked ) {
-      document.getElementById('contacts_div').style.display = '';
-    }
-
-    if        ( f.residential_commercial_Residential.checked && ! f.company.value.length ) {
-      document.getElementById('company_row').style.display = 'none'
-    } else { // if ( f.residential_commercial_Commercial.checked ) {
+  function rescom_changed(what) {
+    if ( what.checked == (what.value == 'Commercial' ) ) {
       document.getElementById('company_row').style.display = '';
-    }
-
-    if        ( f.residential_commercial_Residential.checked && ! f.ship_company.value.length ) {
-      document.getElementById('ship_company_row').style.display = 'none'
-    } else { // if ( f.residential_commercial_Commercial.checked ) {
-      document.getElementById('ship_company_row').style.display = '';
+      document.getElementById('contacts_div').style.display = '';
+    } else {
+      if ( document.getElementById('company').value.length == 0 ) {
+        document.getElementById('company_row').style.display = 'none';
+      }
+      document.getElementById('contacts_div').style.display = 'none';
     }
   }
 </SCRIPT>
   <TR>
     <TD ALIGN="right"><% mt('Referring customer') |h %></TD>
     <TD>
-      <A HREF="<% popurl(1) %>/cust_main.cgi?<% $cust_main->referral_custnum %>"><% $cust_main->referral_custnum %>: <% $referring_cust_main->name %></A>
+      <A HREF="<% popurl(1) %>/cust_main.cgi?<% $cust_main->referral_custnum %>"><% $cust_main->referral_custnum %>: <% $referring_cust_main->name |h %></A>
     </TD>
   </TR>
   <INPUT TYPE="hidden" NAME="referral_custnum" VALUE="<% $cust_main->referral_custnum %>">