diff --git a/core/includes/theme.inc b/core/includes/theme.inc index 5d645e2..340ac77 100644 --- a/core/includes/theme.inc +++ b/core/includes/theme.inc @@ -1372,7 +1372,7 @@ function template_preprocess_page(&$variables) { $variables['language'] = $language_interface; $variables['logo'] = theme_get_setting('logo.url'); $variables['site_name'] = (theme_get_setting('features.name') ? SafeMarkup::checkPlain($site_config->get('name')) : ''); - $variables['site_slogan'] = (theme_get_setting('features.slogan') ? Xss::filterAdmin($site_config->get('slogan')) : ''); + $variables['site_slogan'] = (theme_get_setting('features.slogan') ? SafeMarkup::checkAdminXss($site_config->get('slogan')) : ''); // An exception might be thrown. try { diff --git a/core/lib/Drupal/Component/Utility/SafeMarkup.php b/core/lib/Drupal/Component/Utility/SafeMarkup.php index 07bc320..9182716 100644 --- a/core/lib/Drupal/Component/Utility/SafeMarkup.php +++ b/core/lib/Drupal/Component/Utility/SafeMarkup.php @@ -157,15 +157,30 @@ public static function checkAdminXss($string) { } /** + * Filters HTML to prevent cross-site-scripting (XSS) vulnerabilities. + * + * This method is preferred to \Drupal\Component\Utility\Xss::filter() when + * the result is being used directly in the rendering system. + * * @param $string + * The string with raw HTML in it. It will be stripped of everything that + * can cause an XSS attack. * @param array $html_tags + * An array of HTML tags. + * * @return string + * An XSS safe version of $string, or an empty string if $string is not + * valid UTF-8. The string has been marked safe. If the string has already + * been marked safe, it won't be escaped again. * * @see \Drupal\Component\Utility\Xss::filter() */ public static function filterXss($string, $html_tags = array('a', 'em', 'strong', 'cite', 'blockquote', 'code', 'ul', 'ol', 'li', 'dl', 'dt', 'dd')) { - $string = Xss::filter($string, $html_tags); - return static::set($string); + if (!static::isSafe($string)) { + $string = Xss::filter($string, $html_tags); + static::set($string); + } + return $string; } /** diff --git a/core/modules/filter/filter.module b/core/modules/filter/filter.module index 400d6cc..96d6aa3 100644 --- a/core/modules/filter/filter.module +++ b/core/modules/filter/filter.module @@ -430,7 +430,7 @@ function template_preprocess_filter_tips(&$variables) { foreach ($variables['tips'] as $name => $tiplist) { foreach ($tiplist as $tip_key => $tip) { $tiplist[$tip_key]['attributes'] = new Attribute(); - $tiplist[$tip_key]['tip'] = Xss::filterAdmin($tiplist[$tip_key]['tip']); + $tiplist[$tip_key]['tip'] = SafeMarkup::checkAdminXss($tiplist[$tip_key]['tip']); } $variables['tips'][$name] = array( diff --git a/core/modules/filter/src/Plugin/Filter/FilterCaption.php b/core/modules/filter/src/Plugin/Filter/FilterCaption.php index 32977ec..acd4e09 100644 --- a/core/modules/filter/src/Plugin/Filter/FilterCaption.php +++ b/core/modules/filter/src/Plugin/Filter/FilterCaption.php @@ -45,7 +45,7 @@ public function process($text, $langcode) { // Sanitize caption: decode HTML encoding, limit allowed HTML tags; only // allow inline tags that are allowed by default, plus
. $caption = Html::decodeEntities($caption); - $caption = Xss::filter($caption, array('a', 'em', 'strong', 'cite', 'code', 'br')); + $caption = SafeMarkup::filterXss($caption, array('a', 'em', 'strong', 'cite', 'code', 'br')); // The caption must be non-empty. if (Unicode::strlen($caption) === 0) { diff --git a/core/modules/search/search.module b/core/modules/search/search.module index b4c4126..a888b1b 100644 --- a/core/modules/search/search.module +++ b/core/modules/search/search.module @@ -8,7 +8,6 @@ use Drupal\Component\Utility\SafeMarkup; use Drupal\Component\Utility\Html; use Drupal\Component\Utility\Unicode; -use Drupal\Component\Utility\Xss; use Drupal\Core\Cache\Cache; use Drupal\Core\Form\FormStateInterface; use Drupal\Core\Routing\RouteMatchInterface; @@ -768,7 +767,7 @@ function search_excerpt($keys, $text, $langcode = NULL) { // Highlight keywords. Must be done at once to prevent conflicts ('strong' // and ''). $text = trim(preg_replace('/' . $boundary . '(?:' . implode('|', $keys) . ')' . $boundary . '/iu', '\0', ' ' . $text . ' ')); - return Xss::filter($text, ['strong']); + return SafeMarkup::filterXss($text, ['strong']); } /** diff --git a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php index c5ebaa5..f619bd1 100644 --- a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php +++ b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php @@ -7,6 +7,7 @@ namespace Drupal\system\Plugin\Block; +use Drupal\Component\Utility\SafeMarkup; use Drupal\Core\Block\BlockBase; use Drupal\Core\Cache\Cache; use Drupal\Core\Config\ConfigFactoryInterface; @@ -173,7 +174,7 @@ public function build() { ); $build['site_slogan'] = array( - '#markup' => Xss::filterAdmin($site_config->get('slogan')), + '#markup' => SafeMarkup::checkAdminXss($site_config->get('slogan')), '#access' => $this->configuration['use_site_slogan'], );