Hi/Ahoj :-)
User submitted strings (which role name definitely is) should never be passed to t(). I also added check_plain() to it. It's not a security threat/bug, because roles are always created by administrator, but let's do this the right way and be sure.
Attaching a patch. I also fixed one english typo and removed $role_varname, as you never used it.
--
Jakub Suchy
| Comment | File | Size | Author |
|---|---|---|---|
| czech_audit_role.patch | 1.39 KB | meba |
Comments
Comment #1
michal.cihar commentedComment #2
Anonymous (not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.