Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-22959

PARAM_TEXT should not accept span with style to change the CSS

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Libraries
    • Labels:
      None
    • Difficulty:
      Difficult
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE

      Description

      At this moment PARAM_TEXT will validate stuff like:
      <span style="font-weight: bold;">Vote for Pedro</span>

      I'm using PARAM_TEXT everywhere in the hub web services, I could use PARAM_NOTAGS but Martin said that it would be better to fix the PARAM_TEXT.

      Quote: "new syntax is already <span lang="XX" class="multilang">one lang</span><span lang="YY" class="multilang">another language</span>

      • so we probably could strip anything that wasn't those two - esp style="xxxxx""

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              skodak Petr Skoda
              Reporter:
              jerome Jérôme Mouneyrac
              Tester:
              Nobody
              Participants:
              Component watchers:
              Amaia Anabitarte, Carlos Escobedo, Ferran Recio, Sara Arjona (@sarjona), Víctor Déniz Falcón
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Fix Release Date:
                24/Nov/10