Closed (fixed)
Project:
modr8
Version:
6.x-1.x-dev
Component:
Code
Priority:
Minor
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
16 Sep 2007 at 14:28 UTC
Updated:
29 Apr 2008 at 00:07 UTC
Jump to comment: Most recent file
theme_modr8_note is encoding quotes and HTML special characters, which looks strange in plain text emails; for example, that's becomes that's. It's happening when theme_modr8_note uses @note to translate the text:
function theme_modr8_note($note){
if ($note){
$note = t("Note:
@note", array('@note' => $note));
}
return $note;
}
I'd recommend that it use !note instead.. if the note needs to be escaped somewhere, it can be run through check_plain or re-translated with an @ there.
My workaround, in a theme's template.php:
function themename_modr8_note($note) {
if ($note)
$note = t("Note:\n !note", array('!note' => $note));
return $note;
}
| Comment | File | Size | Author |
|---|---|---|---|
| #8 | notes-176088-8-6x.patch | 909 bytes | pwolanin |
| #7 | notes-176088-7.patch | 1.05 KB | pwolanin |
| #4 | notes-176088-4.patch | 1.25 KB | pwolanin |
| #3 | notes-176088-3.patch | 643 bytes | pwolanin |
Comments
Comment #1
pwolanin commentedhmm, I'll have to take a look - not even clear why t() is being used there,
Comment #2
pwolanin commentedI guess (?) that's safe for e-mail only. Can you roll a patch?
Comment #3
pwolanin commentedhere's a patch - can you test it?
Comment #4
pwolanin commentedhmm - that's no good - provides a XSS hole since the message is displayed to moderators as e-mailed. Perhaps like this?
Comment #5
pwolanin commentedmarked as duplicate: http://drupal.org/node/142488
Comment #6
pwolanin commentedplease review
Comment #7
pwolanin commentedhmmm, actually we don't need that last check_plain() since we have this already:
$message = filter_xss(nl2br($message), array('br', 'a')); // Return sanitized e-mail with HTML breaks added.committed this patch to 5.x
Comment #8
pwolanin commentedand fixed for 6.x (HEAD) too.
Comment #9
Anonymous (not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.