- if (isset($_GET['post'])) { header('Location: ?post='.urlencode($_GET['post']).(!empty($_GET['title'])?'&title='.urlencode($_GET['title']):'').(!empty($_GET['description'])?'&description='.urlencode($_GET['description']):'').(!empty($_GET['source'])?'&source='.urlencode($_GET['source']):'')); exit; }
- if (isset($_POST['returnurl']))
- {
- if (endsWith($_POST['returnurl'],'?do=login')) { header('Location: ?'); exit; } // Prevent loops over login screen.
- header('Location: '.$_POST['returnurl']); exit;
+ if (isset($_GET['post'])) {
+ $uri = '?post='. urlencode($_GET['post']);
+ foreach (array('description', 'source', 'title') as $param) {
+ if (!empty($_GET[$param])) {
+ $uri .= '&'.$param.'='.urlencode($_GET[$param]);
+ }
+ }
+ header('Location: '. $uri);
+ exit;
+ }
+
+ if (isset($_GET['edit_link'])) {
+ header('Location: ?edit_link='. escape($_GET['edit_link']));
+ exit;
+ }
+
+ if (isset($_POST['returnurl'])) {
+ // Prevent loops over login screen.
+ if (strpos($_POST['returnurl'], 'do=login') === false) {
+ header('Location: '. escape($_POST['returnurl']));
+ exit;
+ }