Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-29370

Cannot create a forum post with subject "x <> X"

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 2.1.1
    • Fix Version/s: None
    • Component/s: Forum, Libraries
    • Labels:
    • Testing Instructions:
      Hide

      1. Try to make a forum post with subject "x <> X"
      2. Make sure that subject is displayed correctly.

      Show
      1. Try to make a forum post with subject "x <> X" 2. Make sure that subject is displayed correctly.
    • Workaround:
      Hide

      Manually escape the < as <

      Show
      Manually escape the < as <
    • Difficulty:
      Difficult
    • Affected Branches:
      MOODLE_21_STABLE

      Description

      We seem to be doing the wrong sort of cleaning on post titles.

      Or, are we treating the input as HTML for the benefit of multilang? Even so, surely we can make PARAM_TEXT more intelligent so that it copes with this.

      I guess the final strip_tags in
      case PARAM_TEXT: // leave only tags needed for multilang
      is the problem.

      Changing it to judicious use of htmlspecialchars would be better.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                timhunt Tim Hunt
                Participants:
                Component watchers:
                Andrew Nicols, Jun Pataleta, Michael Hawkins, Shamim Rezaie, Simey Lameze, Amaia Anabitarte, Carlos Escobedo, Ferran Recio, Sara Arjona (@sarjona), Víctor Déniz Falcón
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated: