theme_modr8_note is encoding quotes and HTML special characters, which looks strange in plain text emails; for example, that's becomes that's. It's happening when theme_modr8_note uses @note to translate the text:

function theme_modr8_note($note){
  if ($note){
    $note = t("Note:
  @note", array('@note' => $note));
  }
  return $note;
}

I'd recommend that it use !note instead.. if the note needs to be escaped somewhere, it can be run through check_plain or re-translated with an @ there.

My workaround, in a theme's template.php:

function themename_modr8_note($note) {
  if ($note)
    $note = t("Note:\n  !note", array('!note' => $note));
  return $note;
}

Comments

pwolanin’s picture

hmm, I'll have to take a look - not even clear why t() is being used there,

pwolanin’s picture

I guess (?) that's safe for e-mail only. Can you roll a patch?

pwolanin’s picture

Status: Active » Needs review
StatusFileSize
new643 bytes

here's a patch - can you test it?

pwolanin’s picture

StatusFileSize
new1.25 KB

hmm - that's no good - provides a XSS hole since the message is displayed to moderators as e-mailed. Perhaps like this?

pwolanin’s picture

marked as duplicate: http://drupal.org/node/142488

pwolanin’s picture

please review

pwolanin’s picture

Status: Needs review » Fixed
StatusFileSize
new1.05 KB

hmmm, actually we don't need that last check_plain() since we have this already:
$message = filter_xss(nl2br($message), array('br', 'a')); // Return sanitized e-mail with HTML breaks added.

committed this patch to 5.x

pwolanin’s picture

Version: 5.x-2.3 » 6.x-1.x-dev
StatusFileSize
new909 bytes

and fixed for 6.x (HEAD) too.

Anonymous’s picture

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.