--- loncom/publisher/lonpubdir.pm	2005/05/29 01:46:16	1.83
+++ loncom/publisher/lonpubdir.pm	2008/01/16 12:08:04	1.106
@@ -1,7 +1,7 @@
 # The LearningOnline Network with CAPA
 # Construction Space Directory Lister
 #
-# $Id: lonpubdir.pm,v 1.83 2005/05/29 01:46:16 www Exp $
+# $Id: lonpubdir.pm,v 1.106 2008/01/16 12:08:04 bisitz Exp $
 #
 # Copyright Michigan State University Board of Trustees
 #
@@ -36,10 +36,12 @@ use Apache::Constants qw(:common :http :
 use Apache::loncacc;
 use Apache::loncommon();
 use Apache::lonhtmlcommon();
+use Apache::londiff();
 use Apache::lonlocal;
 use Apache::lonmsg;
 use Apache::lonmenu;
 use Apache::lonnet;
+use LONCAPA;
 
 sub handler {
 
@@ -103,15 +105,15 @@ sub handler {
   my $numres = 0;
   
   # Start off the directory table.
-  $r->print('<h3>Directory Contents:</h3>');
-  $r->print('<table border="0" cellspacing="2" cellpadding="2"><tr>'.
-            '<th bgcolor="#DDDDDD">'.&mt('Type').'</th>'.
-            '<th bgcolor="#DDDDDD">'.&mt('Actions').'</th>'.
-            '<th bgcolor="#DDDDDD">'.&mt('Name').'</th>'.
-            '<th bgcolor="#DDDDDD">'.&mt('Title').'</th>'.
-	    '<th bgcolor="#DDDDDD">'.&mt('Status').'</th>'.
-            '<th bgcolor="#DDDDDD">'.&mt('Last Modified').
-	    '</th></tr>');
+  $r->print('<h3>'.&mt('Directory Contents:').'</h3>');
+  $r->print('<table id="LC_browser"><tr>'.
+            '<th>'.&mt('Type').'</th>'.
+            '<th>'.&mt('Actions').'</th>'.
+            '<th>'.&mt('Name').'</th>'.
+            '<th>'.&mt('Title').'</th>'.
+	    '<th>'.&mt('Status').'</th>'.
+            '<th>'.&mt('Last Modified').
+	    '</th></tr>'."\n");
 
   my $filename;
   my $dirptr=16384;		# Mask indicating a directory in stat.cmode.
@@ -137,7 +139,7 @@ sub handler {
   }
   closedir(DIR);
 
-  $r->print('</table></body></html>');
+  $r->print('</table>'.&Apache::loncommon::end_page());
   return OK;  
 }
 #
@@ -156,7 +158,7 @@ sub getEffectiveUrl {
 	#
 	$fn=~s/^http\:\/\/[^\/]+\///;
         $fn=~s/^\///;
-        $fn=~s/\~(\w+)/\/home\/$1\/public_html/;
+        $fn=~s{~($LONCAPA::username_re)}{/home/$1/public_html};
 	
 	#  Remove trailing / strings (?) 
 	
@@ -169,7 +171,7 @@ sub getEffectiveUrl {
 	    #internal authentication, needs fixup.
 	    $fn = $r->uri(); # non users do not get the full path request
                              # through SCRIPT_FILENAME
-	    $fn=~s|^/~(\w+)|/home/$1/public_html|;
+	    $fn=~s{^/~($LONCAPA::username_re)}{/home/$1/public_html};
 	}
     }
     $fn=~s/\/+/\//g;
@@ -191,14 +193,11 @@ sub startpage {
     my $currdir = '/priv/'.$uname.$thisdisfn;
     &Apache::loncommon::content_type($r,'text/html');
     $r->send_http_header;
-    my $html=&Apache::lonxml::xmlbegin();
-    $r->print($html.'<head><title>LON-CAPA Construction Space</title></head>');
 
-    my $pagetitle;
     my $formaction='/priv/'.$uname.$thisdisfn.'/';
-    $formaction=~s/\/+/\//g;
-    $pagetitle .= &Apache::loncommon::help_open_menu('','','','',3,'Authoring').
-        '<font face="Arial, Helvetica, sans-serif" size="+1"><b>Construction Space</b>:</font>&nbsp;'.
+    $formaction=~s|/+|/|g;
+    my $pagetitle .= &Apache::loncommon::help_open_menu('','',3,'Authoring').
+        '<font face="Arial, Helvetica, sans-serif" size="+1"><b>'.&mt('Construction Space').'</b>:</font>&nbsp;'.
         '<form name="dirs" method="post" action="'.$formaction.
         '" target="_parent"><tt><b>'.
         &Apache::lonhtmlcommon::crumbs($uname.$thisdisfn.'/','_top','/priv','','+1',1)."</b></tt><br />".
@@ -208,16 +207,22 @@ sub startpage {
     &Apache::lonhtmlcommon::store_recent('construct',$formaction,$formaction);
     if ($env{'environment.remote'} eq 'off') {
 	$env{'request.noversionuri'}=$currdir.'/';
-	$r->print(&Apache::loncommon::bodytag('Construction Space',undef,undef,undef,undef,undef,$pagetitle));
+	$r->print(&Apache::loncommon::start_page(&mt('Construction Space'),undef,
+						 {'body_title' =>
+						      $pagetitle,}));
     } else {
+	$r->print(&Apache::loncommon::start_page(&mt('Construction Space'),undef,
+						 { 'only_body' => 1,}));
 	$r->print($pagetitle);
     }
+
+    my $esc_thisdisfn = &Apache::loncommon::escape_single($thisdisfn);
     my $pubdirscript=(<<ENDPUBDIRSCRIPT);
 <script type="text/javascript">
-top.document.title = '$thisdisfn/ - LON-CAPA Construction Space';
+top.document.title = '$esc_thisdisfn/ - '.&mt('LON-CAPA Construction Space');
 // Store directory location for menu bar to find
 
-parent.lastknownpriv='/~$uname$thisdisfn/';
+parent.lastknownpriv='/~$uname$esc_thisdisfn/';
 
 // Confirmation dialogues
 
@@ -233,6 +238,11 @@ parent.lastknownpriv='/~$uname$thisdisfn
             document.printdir.postdata.value=theform.filename.value
             document.printdir.submit();
         }
+        if (theform.dirtask.options[theform.dirtask.selectedIndex].value == "delete") {
+              var delform = document.delresource
+              delform.filename.value = theform.filename.value
+              delform.submit()
+        }
     }
   
     function checkUpload(theform) {
@@ -259,6 +269,11 @@ parent.lastknownpriv='/~$uname$thisdisfn
             theform.postdata.value = theform.filename.value
             theform.submit()
         }
+        if (theform.diraction.options[theform.diraction.selectedIndex].value == "delete") {
+              var delform = document.delresource
+              delform.filename.value = theform.filename.value
+              delform.submit()
+        }
         return
     }
     function SetResChoice(theform) {
@@ -297,8 +312,9 @@ parent.lastknownpriv='/~$uname$thisdisfn
       return
     }
     function changename(theform,activity) {
-        var newname=prompt('New Name');
-        if (newname == "" || !newname)  {
+        var oldname=theform.dispfilename.value;
+        var newname=prompt('New Name',oldname);
+        if (newname == "" || !newname || newname == oldname)  {
             return
         }
         document.moveresource.newfilename.value = newname
@@ -319,21 +335,57 @@ ENDPUBDIRSCRIPT
 
 sub dircontrols {
     my ($r,$uname,$udom,$thisdisfn) = @_;
+    my %lt=&Apache::lonlocal::texthash(
+                                       cnpd => 'Cannot publish directory',
+                                       cnrd => 'Cannot retrieve directory',
+                                       mcdi => 'Must create new subdirectory inside a directory',
+                                       pubr => 'Publish this Resource',
+                                       pubd => 'Publish this Directory',
+                                       dedr => 'Delete Directory',
+                                       rtrv => 'Retrieve Old Version',
+                                       list => 'List Directory',
+                                       uplo => 'Upload file',  
+                                       dele => 'Delete',
+                                       edit => 'Edit Catalog Information', 
+                                       sela => 'Select Action',
+                                       nfil => 'New file',
+                                       nhtm => 'New HTML file',
+                                       nprb => 'New problem',
+                                       npag => 'New assembled page',
+                                       nseq => 'New assembled sequence',
+                                       ncrf => 'New custom rights file',
+                                       nsty => 'New style file',
+                                       nlib => 'New library file',
+                                       nbt  => 'New bridgetask file',
+                                       nsub => 'New subdirectory',
+                                       renm => 'Rename current file to',
+                                       move => 'Move current file to',
+                                       copy => 'Copy current file to',
+                                       type => 'Type Name Here',
+                                       go   => 'Go',
+                                       prnt => 'Print contents of directory',
+                                       crea => 'Create a new directory or LON-CAPA document',
+				       acti => 'Actions for current directory',
+				       updc => 'Upload a new document',
+				       pick => 'Please select an action to perform using the new filename',
+                                      );
+    my $mytype = $lt{'type'}; # avoid conflict with " and ' in javascript
     $r->print(<<END);
-        <table cellspacing="4" cellpadding="4" width="100%">
+        <table id="LC_cstr_controls">
          <tr>
-          <td bgcolor="#DDDDDD" align="middle"><font face="Arial, Helvetica, sans-serif" size="-1"><b>Actions for current directory</b></font></td>
-          <td bgcolor="#DDDDDD" align="middle"><font face="Arial, Helvetica, sans-serif" size="-1"><b>Upload a new document</b></font></td>
-          <td bgcolor="#DDDDDD" align="middle"><font face="Arial, Helvetica, sans-serif" size="-1"><b>Create a new directory or LON-CAPA document</b></font></td>
+          <th>$lt{'acti'}</th>
+          <th>$lt{'updc'}</th>
+          <th>$lt{'crea'}</th>
         </tr>
         <tr>
-         <td bgcolor="#ccddaa" valign="top" align="center">
+         <td>
           <form name="curractions" method="post" action="">
-           <select name="dirtask" onChange="currdiract(this.form)">
-            <option>Select action</option>
-            <option value="publish">Publish directory</option>
-            <option value="editcat">Edit catalog information</option>
-            <option value="printdir">Print contents of directory</option>
+           <select name="dirtask" onchange="currdiract(this.form)">
+            <option>$lt{'sela'}</option>
+            <option value="publish">$lt{'pubd'}</option>
+            <option value="editcat">$lt{'edit'}</option>
+            <option value="printdir">$lt{'prnt'}</option>
+            <option value="delete">$lt{'dedr'}</option>
            </select>
            <input type="hidden" name="filename" value="/~$uname$thisdisfn/" />
           </form>
@@ -345,29 +397,41 @@ sub dircontrols {
            <input type="hidden" name="postdata" value="" />
           </form>
          </td>
-         <td bgcolor="#ccddaa" valign="top" align="center">
+         <td>
 	    <form name="upublisher" enctype="multipart/form-data" method="post" action="/adm/upload" target="_parent">
 	      <input type="hidden" name="filename" value="/~$uname$thisdisfn/" />
 	      <input type="file" name="upfile" size="20" />
-	      <input type="button" value="Upload file"  onclick="checkUpload(this.form)" />
+	      <input type="button" value="$lt{'uplo'}"  onclick="checkUpload(this.form)" />
 	    </form>
 	 </td>
-	 <td bgcolor="#ccddaa" align="center">
+	 <td>
 	    <form name="fileaction" method="post" action="/adm/cfile" target="_parent">
-	      <nobr>
+	      <span style="white-space: nowrap">
 		<input type="hidden" name="filename" value="/~$uname$thisdisfn/" />
+                  <script type="text/javascript">
+                    function validate_go() {
+                        var selected = document.fileaction.action.selectedIndex;
+                        if (selected == 0) {
+                            alert('$lt{'pick'}');
+                        } else {
+                            document.fileaction.submit();
+                        }
+                    }
+                  </script>
 		  <select name="action">
-		    <option>Select Action</option>
-		    <option value="newfile">New file:</option>
-		    <option value="newhtmlfile">New HTML file:</option>
-		    <option value="newproblemfile">New problem:</option>
-                    <option value="newpagefile">New assembled page:</option>
-                    <option value="newsequencefile">New assembled sequence:</option>
-                    <option value="newrightsfile">New custom rights file:</option>
-                    <option value="newstyfile">New style file:</option>
-		    <option value="newdir">New subdirectory:</option>
-		  </select>&nbsp;<input type="text" name="newfilename" value="Type Name Here" onfocus="if (this.value == 'Type Name Here') this.value=''" />&nbsp;<input type="button" value="Go" onclick="document.fileaction.submit()" />
-		 </nobr>
+		    <option value="none">$lt{'sela'}</option>
+		    <option value="newfile">$lt{'nfil'}:</option>
+		    <option value="newhtmlfile">$lt{'nhtm'}:</option>
+		    <option value="newproblemfile">$lt{'nprb'}:</option>
+                    <option value="newpagefile">$lt{'npag'}:</option>
+                    <option value="newsequencefile">$lt{'nseq'}:</option>
+                    <option value="newrightsfile">$lt{'ncrf'}:</option>
+                    <option value="newstyfile">$lt{'nsty'}:</option>
+                    <option value="newtaskfile">$lt{'nbt'}:</option>
+                    <option value="newlibraryfile">$lt{'nlib'}:</option>
+	            <option value="newdir">$lt{'nsub'}:</option>
+		  </select>&nbsp;<input type="text" name="newfilename" value="$lt{'type'}" onfocus="if (this.value == '$mytype') this.value=''" />&nbsp;<input type="button" value="Go" onclick="validate_go();" />
+		 </span>
 		</form>
 	  </td>
          </tr>
@@ -381,7 +445,7 @@ sub pubbuttons {
               '<table><tr><td><input type="hidden" name="filename" value="/~'.
                $uname.$thisdisfn.'/" />'.
               '<input type="submit" value="'.&mt('Publish Directory').'" /></td><td>'.
-'<input type="button" onClick="window.location='."'/~".
+'<input type="button" onclick="window.location='."'/~".
                $uname.$thisdisfn."/default.meta'".'" value="'.
 &mt('Edit Directory Catalog Information').'" /></td></tr></table></form>');
 }
@@ -467,9 +531,9 @@ sub putdirectory {
 	%Apache::lonpublisher::metadatafields=();
 	%Apache::lonpublisher::metadatakeys=();
 	my $construct=$here;
-	$construct=~s:^/priv/(\w+)$:/home/$1/public_html:;
+	$construct=~s{^/priv/($LONCAPA::username_re)$}{/home/$1/public_html};
         my $dirpath = $here;
-        $dirpath=~s:^/priv/:/~:;
+        $dirpath=~s{^/priv/}{/~};
 	&Apache::lonpublisher::metaeval(&Apache::lonnet::getfile(
        				 $construct.'/'.$dirname.'/default.meta'
 								 ));
@@ -480,29 +544,33 @@ sub putdirectory {
             $actionitem = 
                     '<form name="dirselect_'.$$numdir.
                     '" action="/adm/publish" target="_parent">'.
-                    '<select name="diraction" onChange="SetPubDir(this.form,document)">'.
+                    '<select name="diraction" onchange="SetPubDir(this.form,document)">'.
                       '<option selected="selected">'.&mt('Select action').'</option>'.
                       '<option value="open">'.&mt('Open').'</option>'.
                       '<option value="publish">'.&mt('Publish').'</option>'.
-                      '<option value="publishsub">'.&mt('Publish with subdirectories').'</option>'.
                       '<option value="editcat">'.&mt('Edit catalog information').'</option>'.
                       '<option value="printdir">'.&mt('Print directory').'</option>'.
+                      '<option value="delete">'.&mt('Delete directory').'</option>'.
                     '</select>'.
-                     '<input type="hidden" name="filename" value="'.$dirpath.'/'.$dirname.'/" />'.
+                     '<input type="hidden" name="filename" value="'.&HTML::Entities::encode($dirpath.'/'.$dirname,'<>&"').'/" />'.
                      '<input type="hidden" name="openname" value="'.$here.'/'.$dirname.'/" />'.
                      '<input type="hidden" name="postdata" value="" />'.
                    '</form>';
             $$numdir ++;
         }
-	$r->print('<tr bgcolor="#CCCCFF">'.
+	$r->print('<tr class="LC_browser_folder">'.
 		  '<td><img src="'.
-		  $Apache::lonnet::perlvar{'lonIconsURL'}.'/folder_closed.gif" /></td>'.
+		  $Apache::lonnet::perlvar{'lonIconsURL'}.'/folder_closed.gif" alt="folder" /></td>'.
 		  '<td>'.$actionitem.'</td>'.
-		  '<td><font face="arial"><a href="'.$here.'/'.$dirname.'/" target="_parent">'.
-		  $disfilename.'</a></font></td>'.
-		        '<td colspan="2">'.($kaputt?&Apache::lonhtmlcommon::authorbombs($resdir.'/'.$disfilename.'/'):'').$Apache::lonpublisher::metadatafields{'title'}.' <i>'.
-		  $Apache::lonpublisher::metadatafields{'subject'}.'</i> '.
-		  $Apache::lonpublisher::metadatafields{'keywords'}.'</td>'.
+		  '<td><span class="LC_filename"><a href="'.&HTML::Entities::encode($here.'/'.$dirname,'<>&"').'/" target="_parent">'.
+		  $disfilename.'</a></span></td>'.
+		        '<td colspan="2">'.($kaputt?&Apache::lonhtmlcommon::authorbombs($resdir.'/'.$disfilename.'/'):'').$Apache::lonpublisher::metadatafields{'title'});
+	if ($Apache::lonpublisher::metadatafields{'subject'} ne '') {
+	    $r->print(' <i>'.
+		      $Apache::lonpublisher::metadatafields{'subject'}.
+		      '</i> ');
+	}
+	$r->print($Apache::lonpublisher::metadatafields{'keywords'}.'</td>'.
 		  '<td>'.&Apache::lonlocal::locallocaltime($modtime).'</td>'.
 		  "</tr>\n");
     }
@@ -518,53 +586,84 @@ sub putresource {
     &Apache::lonnet::devalidate_cache_new('meta',$targetdir.'/'.$filename);
     my $pubstatus = 'unpublished';
     my $status=&mt('Unpublished');
-    my $bgcolor='#FFAA99';
+    my $css_class='LC_browser_file';
     my $title='&nbsp;';
     my $publish_button=&mt('Publish');
+    my $cstr_dir = '/home/'.$uname.'/public_html/'.$thisdisfn.'/';
 #    my $action_buttons=
 #        '<br /><a target="_parent" href="/adm/cfile?action=delete&filename=/~'.
 #	$uname.'/'.$thisdisfn.'/'.$filename.'">'.
 #	&mt('Delete').'</a>';
     if (-e $resdir.'/'.$filename) {
+        my $same=0;
 	my ($rdev,$rino,$rmode,$rnlink,
 	    $ruid,$rgid,$rrdev,$rsize,
 	    $ratime,$rmtime,$rctime,
 	    $rblksize,$rblocks)=stat($resdir.'/'.$filename);
+        if ($rmtime>=$cmtime) {
+           $same=1;
+        } else {
+           if (&Apache::londiff::are_different_files($resdir.'/'.$filename,
+						     $cstr_dir.'/'.$filename)) {
+              $same=0;
+           } else {
+              $same=1;
+           }
+        }
+	my $meta_cmtime = (stat($cstr_dir.'/'.$filename.'.meta'))[9];
+	my $meta_rmtime = (stat($resdir.'/'.$filename.'.meta'))[9];
+	my $meta_same = 1;
+	if ($meta_rmtime < $meta_cmtime
+	    && &Apache::londiff::are_different_files($resdir.'/'.$filename.'.meta',
+						     $cstr_dir.'/'.$filename.'.meta')) {
+	    $meta_same = 0;
+	}
 	$publish_button=&mt('Re-publish');
-	if ($rmtime>=$cmtime) {
-            $pubstatus = 'published';
-	    $status=&mt('Published').'<br />'.
-		&mt(&getCopyRightString($targetdir.'/'.$filename)).' '.
-		&mt(&getSourceRightString($targetdir.'/'.$filename));
-	    $bgcolor='#CCFF88';
+	my $rights_status =
+	    &mt(&getCopyRightString($targetdir.'/'.$filename)).' '.
+	    &mt(&getSourceRightString($targetdir.'/'.$filename));
+	$title = '<a href="/res/'.$targetdir.'/'.$filename.
+	    '.meta" target="cat">'.
+	    &getTitleString($targetdir.'/'.$filename).'</a>';
+	if ($same) {
 	    if (&Apache::lonnet::metadata($targetdir.'/'.$filename,'obsolete')) {
                 $pubstatus = 'obsolete';
 		$status=&mt('Obsolete');
-                $bgcolor='#AAAAAA';
-            }
+            } else {
+		if (!$meta_same) {
+		    $pubstatus = 'metamodified';
+		} else {
+		    $pubstatus = 'published';
+		}
+		$status=&mt('Published').
+		    '<br />'. $rights_status;
+	    }
 #	    } else {
 #		$action_buttons='';
 #	    }
-	    $title='<a href="/res/'.$targetdir.'/'.$filename.
-		'.meta" target="cat">'.
-		&getTitleString($targetdir.'/'.$filename).'</a>';
 	} else {
             $pubstatus = 'modified';
-	    $status=&mt('Modified').'<br />'.
-		&mt(&getCopyRightString($targetdir.'/'.$filename)).' '.
-		&mt(&getSourceRightString($targetdir.'/'.$filename));
-            $bgcolor='#FFFF77';
+	    $status=&mt('Modified').
+		'<br />'. $rights_status;
 #	    $action_buttons='';
-	    $title='<a href="/res/'.$targetdir.'/'.$filename.'.meta" target="cat">'.
-		&getTitleString($targetdir.'/'.$filename).'</a>';
 	    if (&Apache::loncommon::fileembstyle(($filename=~/\.(\w+)$/)) eq 'ssi') {
 		$status.='<br /><a href="/adm/diff?filename=/~'.$uname.
 		    $thisdisfn.'/'.$filename.
 		    '&amp;versiontwo=priv" target="cat">'.&mt('Diffs').'</a>';
 	    }
-	}
+	} 
+
 	$title.="\n".'<br /><a href="/~'.$uname.$thisdisfn.'/'.$filename.'.meta">'. 
-	    ($$bombs{$targetdir.'/'.$filename}?'<img src="/adm/lonMisc/bomb.gif" border="0" />':'Edit Metadata').'</a>';
+	    ($$bombs{$targetdir.'/'.$filename}?'<img src="/adm/lonMisc/bomb.gif" border="0" alt="bomb" />':'Edit Metadata').'</a>';
+
+	if (!$meta_same) {
+	    $title = &mt('Metadata Modified').'<br />'.$title.
+		'<br /><a href="/adm/diff?filename=/~'.$uname.
+		$thisdisfn.'/'.$filename.'.meta'.
+		'&amp;versiontwo=priv" target="cat">'.&mt('Metadata Diffs').'</a>';
+	    $title.="\n".'<br /><a href="/adm/retrieve?filename=/~'.$uname.
+		$thisdisfn.'/'.$filename.'.meta" target="_parent">'.&mt('Retrieve Metadata').'</a>';
+	}
 	$status.="\n".'<br /><a href="/adm/retrieve?filename=/~'.$uname.
 	    $thisdisfn.'/'.$filename.'" target="_parent">'.&mt('Retrieve').'</a>';
     }
@@ -587,13 +686,13 @@ sub putresource {
     }
     my $pub_select = '';
     &create_pubselect($r,\$pub_select,$udom,$uname,$thisdisfn,$filename,$resdir,$pubstatus,$publish_button,$numres);
-    $r->print('<tr bgcolor="'.$bgcolor.'">'.
+    $r->print('<tr class="LC_browser_file_'.$pubstatus.'">'.
 	      '<td>'.($filename=~/[\#\~]$/?'&nbsp;':
-		      '<img src="'.&Apache::loncommon::icon($filename).'" /></td>').
+		      '<img src="'.&Apache::loncommon::icon($filename).'" alt="" />').'</td>'.
               '<td>'.$pub_select.'</td>'.
-	      '<td><font face="arial">'.
+	      '<td><span class="LC_filename">'.
 	      '<a href="'.$linkdir.'/'.$filename.'" target="_parent">'.
-               $filename.'</a></font>'.$editlink2.$editlink.
+               $filename.'</a></span>'.$editlink2.$editlink.
 	      '</td>'.
 	      '<td>'.$title.'</td>'.
 	      '<td>'.$status.'</td>'.
@@ -606,7 +705,7 @@ sub create_pubselect {
     my ($r,$pub_select,$udom,$uname,$thisdisfn,$filename,$resdir,$pubstatus,$publish_button,$numres) = @_;
     $$pub_select = '
 <form name="resselect_'.$$numres.'" action="">
-<select name="reschoice"  onChange="SetResChoice(this.form)">
+<select name="reschoice"  onchange="SetResChoice(this.form)">
 <option>'.&mt('Select action').'</option>'.
 '<option value="copy">'.&mt('Copy').'</option>';
     if ($pubstatus eq 'obsolete' || $pubstatus eq 'unpublished') {
@@ -630,7 +729,9 @@ sub create_pubselect {
 '<option value="print">'.&mt('Print').'</option>'.
 '</select>
 <input type="hidden" name="filename" value="/~'.
- $uname.$thisdisfn.'/'.$filename.'" /></form>';
+ &HTML::Entities::encode($uname.$thisdisfn.'/'.$filename,'<>&"').'" />
+ <input type="hidden" name="dispfilename" value="'.
+ &HTML::Entities::encode($filename).'" /></form>';
     $$numres ++;
 }