According to people on #drupal, one is allowed to put both HTML and any valid UTF-8 string into an element's '#title' key. As exemplified by the og module, ( http://git.drupalcode.org/project/og.git?a=blob;f=includes/og.admin.inc;... ), this requires that ampersands not be escaped for this to function properly.
However, this also requires that every use of $element['#title'] be wrapped in a filter_xss_admin() call for valid HTML (or XHTML) to be produced. Such a call is missing in form.inc's theme_fieldset() function while it is present in most other renderings of $element['#title']. With the current code, invalid HTML is produced for a fieldset which has a '#title' with, for example, an ampersand in it.
For example, I have the following fieldset in a sample module:
$form['myfs'] = array(
'#type' => 'fieldset',
'#title' => t('1 & 2 & 3'),
'#collapsible' => TRUE,
);
Without my patch, I get:
<legend><span class="fieldset-legend">1 & 2 & 3</span></legend>
which is obviously invalid HTML.
The attached patch should fix this as well as fixing a few other places where I am convinced that filter_xss_admin() (or perhaps check_plain()?) should be called.
With my patch, I get:
<legend><span class="fieldset-legend">1 & 2 & 3</span></legend>
This same bug also exists in D6.
| Comment | File | Size | Author |
|---|---|---|---|
| drupal-HEAD-form-title-filter_xss_admin.patch | 2.63 KB | ohnobinki |
Comments
Comment #1
ohnobinki commentedtag:+xhtml compliance
Comment #2
fietserwinPart of #331879: Harden FAPI against $form array keys containing XSS. can you please review that one and RTBC if you think it's ok.