According to people on #drupal, one is allowed to put both HTML and any valid UTF-8 string into an element's '#title' key. As exemplified by the og module, ( http://git.drupalcode.org/project/og.git?a=blob;f=includes/og.admin.inc;... ), this requires that ampersands not be escaped for this to function properly.

However, this also requires that every use of $element['#title'] be wrapped in a filter_xss_admin() call for valid HTML (or XHTML) to be produced. Such a call is missing in form.inc's theme_fieldset() function while it is present in most other renderings of $element['#title']. With the current code, invalid HTML is produced for a fieldset which has a '#title' with, for example, an ampersand in it.

For example, I have the following fieldset in a sample module:

  $form['myfs'] = array(
    '#type' => 'fieldset',
    '#title' => t('1 & 2 & 3'),
    '#collapsible' => TRUE,
  );

Without my patch, I get:

<legend><span class="fieldset-legend">1 &amp; 2 & 3</span></legend>

which is obviously invalid HTML.

The attached patch should fix this as well as fixing a few other places where I am convinced that filter_xss_admin() (or perhaps check_plain()?) should be called.
With my patch, I get:

<legend><span class="fieldset-legend">1 &amp; 2 &amp; 3</span></legend>

This same bug also exists in D6.

Comments

ohnobinki’s picture

Issue tags: +xhtml compliance

tag:+xhtml compliance

fietserwin’s picture

Status: Needs review » Closed (duplicate)

Part of #331879: Harden FAPI against $form array keys containing XSS. can you please review that one and RTBC if you think it's ok.