? .cvsignore
? SolrPhpClient
? Zend
? apachesolr_650534-12.patch
? entity-fixes-528086-11.patch
? entity-fixes-528086-9.patch
? notices-655006-6x-1x-6.patch
? notices-655006-6x-1x.patch
? text-analyzer.xml
Index: apachesolr.index.inc
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/apachesolr/apachesolr.index.inc,v
retrieving revision 1.1.2.14
diff -u -p -r1.1.2.14 apachesolr.index.inc
--- apachesolr.index.inc	15 Nov 2009 14:52:28 -0000	1.1.2.14
+++ apachesolr.index.inc	10 Dec 2009 18:14:09 -0000
@@ -16,13 +16,14 @@ function apachesolr_add_node_document(&$
 }
 
 /**
- * Strip html tags and also control characters that cause Jetty/Solr to fail.
+ * Strip html tags and decode entities. Becuase of decoding, we should not trust
+ * content returned from Solr - we need to apply check_plain().
  */
 function apachesolr_clean_text($text) {
   // Add spaces before stripping tags to avoid running words together.
   $text = filter_xss(str_replace(array('<', '>'), array(' <', '> '), $text), array());
-  // Decode entities and then make safe any < or > characters.
-  return htmlspecialchars(html_entity_decode($text, ENT_NOQUOTES, 'UTF-8'), ENT_NOQUOTES, 'UTF-8');
+  // Decode entities so we can search for them.
+  return html_entity_decode($text, ENT_NOQUOTES, 'UTF-8');
 }
 
 /**
Index: apachesolr_search.module
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/apachesolr/apachesolr_search.module,v
retrieving revision 1.1.2.6.2.120
diff -u -p -r1.1.2.6.2.120 apachesolr_search.module
--- apachesolr_search.module	10 Dec 2009 17:43:28 -0000	1.1.2.6.2.120
+++ apachesolr_search.module	10 Dec 2009 18:14:09 -0000
@@ -408,10 +408,15 @@ function apachesolr_process_response($re
       else {
         $snippet = '';
       }
-
+      // We decoded entities when we indexed, so we must make the text safe.
+      // Translate back STRONG tags used for highlighting matches.
+      $snippet = strtr(check_plain($snippet), array('&lt;strong&gt;' => '<strong>', '&lt;/strong&gt;' => '</strong>'));
       if (!isset($doc->body)) {
         $doc->body = $snippet;
       }
+      else {
+        $doc->body = check_plain($doc->body);
+      }
       $doc->created = strtotime($doc->created);
       $doc->changed = strtotime($doc->changed);
       // Allow modules to alter each document.
