diff --git a/core/includes/theme.inc b/core/includes/theme.inc
index 5d645e2..340ac77 100644
--- a/core/includes/theme.inc
+++ b/core/includes/theme.inc
@@ -1372,7 +1372,7 @@ function template_preprocess_page(&$variables) {
$variables['language'] = $language_interface;
$variables['logo'] = theme_get_setting('logo.url');
$variables['site_name'] = (theme_get_setting('features.name') ? SafeMarkup::checkPlain($site_config->get('name')) : '');
- $variables['site_slogan'] = (theme_get_setting('features.slogan') ? Xss::filterAdmin($site_config->get('slogan')) : '');
+ $variables['site_slogan'] = (theme_get_setting('features.slogan') ? SafeMarkup::checkAdminXss($site_config->get('slogan')) : '');
// An exception might be thrown.
try {
diff --git a/core/lib/Drupal/Component/Utility/SafeMarkup.php b/core/lib/Drupal/Component/Utility/SafeMarkup.php
index 07bc320..9182716 100644
--- a/core/lib/Drupal/Component/Utility/SafeMarkup.php
+++ b/core/lib/Drupal/Component/Utility/SafeMarkup.php
@@ -157,15 +157,30 @@ public static function checkAdminXss($string) {
}
/**
+ * Filters HTML to prevent cross-site-scripting (XSS) vulnerabilities.
+ *
+ * This method is preferred to \Drupal\Component\Utility\Xss::filter() when
+ * the result is being used directly in the rendering system.
+ *
* @param $string
+ * The string with raw HTML in it. It will be stripped of everything that
+ * can cause an XSS attack.
* @param array $html_tags
+ * An array of HTML tags.
+ *
* @return string
+ * An XSS safe version of $string, or an empty string if $string is not
+ * valid UTF-8. The string has been marked safe. If the string has already
+ * been marked safe, it won't be escaped again.
*
* @see \Drupal\Component\Utility\Xss::filter()
*/
public static function filterXss($string, $html_tags = array('a', 'em', 'strong', 'cite', 'blockquote', 'code', 'ul', 'ol', 'li', 'dl', 'dt', 'dd')) {
- $string = Xss::filter($string, $html_tags);
- return static::set($string);
+ if (!static::isSafe($string)) {
+ $string = Xss::filter($string, $html_tags);
+ static::set($string);
+ }
+ return $string;
}
/**
diff --git a/core/modules/filter/filter.module b/core/modules/filter/filter.module
index 400d6cc..96d6aa3 100644
--- a/core/modules/filter/filter.module
+++ b/core/modules/filter/filter.module
@@ -430,7 +430,7 @@ function template_preprocess_filter_tips(&$variables) {
foreach ($variables['tips'] as $name => $tiplist) {
foreach ($tiplist as $tip_key => $tip) {
$tiplist[$tip_key]['attributes'] = new Attribute();
- $tiplist[$tip_key]['tip'] = Xss::filterAdmin($tiplist[$tip_key]['tip']);
+ $tiplist[$tip_key]['tip'] = SafeMarkup::checkAdminXss($tiplist[$tip_key]['tip']);
}
$variables['tips'][$name] = array(
diff --git a/core/modules/filter/src/Plugin/Filter/FilterCaption.php b/core/modules/filter/src/Plugin/Filter/FilterCaption.php
index 32977ec..acd4e09 100644
--- a/core/modules/filter/src/Plugin/Filter/FilterCaption.php
+++ b/core/modules/filter/src/Plugin/Filter/FilterCaption.php
@@ -45,7 +45,7 @@ public function process($text, $langcode) {
// Sanitize caption: decode HTML encoding, limit allowed HTML tags; only
// allow inline tags that are allowed by default, plus
.
$caption = Html::decodeEntities($caption);
- $caption = Xss::filter($caption, array('a', 'em', 'strong', 'cite', 'code', 'br'));
+ $caption = SafeMarkup::filterXss($caption, array('a', 'em', 'strong', 'cite', 'code', 'br'));
// The caption must be non-empty.
if (Unicode::strlen($caption) === 0) {
diff --git a/core/modules/search/search.module b/core/modules/search/search.module
index b4c4126..a888b1b 100644
--- a/core/modules/search/search.module
+++ b/core/modules/search/search.module
@@ -8,7 +8,6 @@
use Drupal\Component\Utility\SafeMarkup;
use Drupal\Component\Utility\Html;
use Drupal\Component\Utility\Unicode;
-use Drupal\Component\Utility\Xss;
use Drupal\Core\Cache\Cache;
use Drupal\Core\Form\FormStateInterface;
use Drupal\Core\Routing\RouteMatchInterface;
@@ -768,7 +767,7 @@ function search_excerpt($keys, $text, $langcode = NULL) {
// Highlight keywords. Must be done at once to prevent conflicts ('strong'
// and '').
$text = trim(preg_replace('/' . $boundary . '(?:' . implode('|', $keys) . ')' . $boundary . '/iu', '\0', ' ' . $text . ' '));
- return Xss::filter($text, ['strong']);
+ return SafeMarkup::filterXss($text, ['strong']);
}
/**
diff --git a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
index c5ebaa5..f619bd1 100644
--- a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
+++ b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
@@ -7,6 +7,7 @@
namespace Drupal\system\Plugin\Block;
+use Drupal\Component\Utility\SafeMarkup;
use Drupal\Core\Block\BlockBase;
use Drupal\Core\Cache\Cache;
use Drupal\Core\Config\ConfigFactoryInterface;
@@ -173,7 +174,7 @@ public function build() {
);
$build['site_slogan'] = array(
- '#markup' => Xss::filterAdmin($site_config->get('slogan')),
+ '#markup' => SafeMarkup::checkAdminXss($site_config->get('slogan')),
'#access' => $this->configuration['use_site_slogan'],
);