diff --git a/core/lib/Drupal/Component/Utility/SafeMarkup.php b/core/lib/Drupal/Component/Utility/SafeMarkup.php index 9925ae1..0023c0c 100644 --- a/core/lib/Drupal/Component/Utility/SafeMarkup.php +++ b/core/lib/Drupal/Component/Utility/SafeMarkup.php @@ -15,8 +15,8 @@ * provides a store for known safe strings and methods to manage them * throughout the page request. * - * Strings sanitized by self::checkPlain(), self::xssFilter() or - * self::xssFilterAdmin() are automatically marked safe, as are markup strings + * Strings sanitized by self::checkPlain() and self::escape() or + * self::xssFilter() are automatically marked safe, as are markup strings * created from @link theme_render render arrays @endlink via drupal_render(). * * This class should be limited to internal use only. Module developers should @@ -143,16 +143,14 @@ public static function escape($string) { * * Note: This method only filters if $string is not marked safe already. * - * @deprecated as of Drupal 8.0.x, will be removed before Drupal 8.0.0. If the - * string used as part of a @link theme_render render array @endlink use - * #markup to allow the render system to filter automatically or just allow - * the Twig to autoescape the value. If the result is not being used - * directly in the rendering system (for example, when its result is being - * combined with other strings before rendering), use Xss::filterAdmin(). - * Otherwise, use SafeMarkup::xssFilter() and the tag list provided by - * Xss::getAdminTagList() instead. In the rare instance that the caller does - * not want to filter strings that are marked safe already, it needs to - * check SafeMarkup::isSafe() itself. + * @deprecated as of Drupal 8.0.x, will be removed before Drupal 8.0.0. If + * the string is used as part of a @link theme_render render array @endlink + * use #markup to allow the render system to filter automatically. If the + * result is not being used directly in the rendering system (for example, + * when its result is being combined with other strings before rendering), + * use Xss::filterAdmin(). Otherwise, use SafeMarkup::xssFilterAdmin(). In + * the rare instance that the caller does not want to filter strings that + * are marked safe already, it needs to check SafeMarkup::isSafe() itself. * * @see \Drupal\Component\Utility\SafeMarkup::xssFilter() * @see \Drupal\Component\Utility\SafeMarkup::isSafe() diff --git a/core/modules/block_content/block_content.pages.inc b/core/modules/block_content/block_content.pages.inc index dbb614a..9e019cd 100644 --- a/core/modules/block_content/block_content.pages.inc +++ b/core/modules/block_content/block_content.pages.inc @@ -28,7 +28,6 @@ function template_preprocess_block_content_add_list(&$variables) { $variables['types'][$type->id()] = array( 'link' => \Drupal::l($type->label(), new Url('block_content.add_form', array('block_content_type' => $type->id()), array('query' => $query))), 'description' => array( - // #markup is filtered for admin XSS automatically. '#markup' => $type->getDescription(), ), 'title' => $type->label(), diff --git a/core/modules/comment/src/CommentTypeListBuilder.php b/core/modules/comment/src/CommentTypeListBuilder.php index f813665..4f99871 100644 --- a/core/modules/comment/src/CommentTypeListBuilder.php +++ b/core/modules/comment/src/CommentTypeListBuilder.php @@ -46,7 +46,6 @@ public function buildHeader() { */ public function buildRow(EntityInterface $entity) { $row['type'] = SafeMarkup::checkPlain($entity->label()); - // #markup is filtered for admin XSS automatically. $row['description']['data'] = ['#markup' => $entity->getDescription()]; return $row + parent::buildRow($entity); } diff --git a/core/modules/dblog/src/Controller/DbLogController.php b/core/modules/dblog/src/Controller/DbLogController.php index 2d904b6..3982da6 100644 --- a/core/modules/dblog/src/Controller/DbLogController.php +++ b/core/modules/dblog/src/Controller/DbLogController.php @@ -285,7 +285,6 @@ public function eventDetails($event_id) { ), array( array('data' => $this->t('Operations'), 'header' => TRUE), - // #markup is filtered for admin XSS automatically. array('data' => array('#markup' => $dblog->link)), ), ); diff --git a/core/modules/filter/filter.module b/core/modules/filter/filter.module index 25acc43..77b2794 100644 --- a/core/modules/filter/filter.module +++ b/core/modules/filter/filter.module @@ -354,7 +354,6 @@ function _filter_tips($format_id, $long = FALSE) { $tip = $filter->tips($long); if (isset($tip)) { $tips[$format->label()][$name] = array( - // #markup is filtered for admin XSS automatically. 'tip' => array('#markup' => $tip), 'id' => $name, ); diff --git a/core/modules/forum/forum.module b/core/modules/forum/forum.module index bdfc011..90086a6 100644 --- a/core/modules/forum/forum.module +++ b/core/modules/forum/forum.module @@ -540,7 +540,6 @@ function template_preprocess_forum_list(&$variables) { $row = 0; // Sanitize each forum so that the template can safely print the data. foreach ($variables['forums'] as $id => $forum) { - // #markup is filtered for admin XSS automatically. $variables['forums'][$id]->description = array('#markup' => $forum->description->value); $variables['forums'][$id]->link = forum_uri($forum); $variables['forums'][$id]->name = SafeMarkup::checkPlain($forum->label()); diff --git a/core/modules/language/src/Form/NegotiationConfigureForm.php b/core/modules/language/src/Form/NegotiationConfigureForm.php index ea04bfd..938564e 100644 --- a/core/modules/language/src/Form/NegotiationConfigureForm.php +++ b/core/modules/language/src/Form/NegotiationConfigureForm.php @@ -301,7 +301,6 @@ protected function configureFormTable(array &$form, $type) { $table_form['enabled'][$method_id]['#attributes'] = array('disabled' => 'disabled'); } - // #markup is filtered for admin XSS automatically. $table_form['description'][$method_id] = array('#markup' => $method['description']); $config_op = array(); diff --git a/core/modules/menu_ui/src/MenuListBuilder.php b/core/modules/menu_ui/src/MenuListBuilder.php index 9b5a171..95d029c 100644 --- a/core/modules/menu_ui/src/MenuListBuilder.php +++ b/core/modules/menu_ui/src/MenuListBuilder.php @@ -39,7 +39,6 @@ public function buildRow(EntityInterface $entity) { 'data' => $this->getLabel($entity), 'class' => array('menu-label'), ); - // #markup is filtered for admin XSS automatically. $row['description']['data'] = ['#markup' => $entity->getDescription()]; return $row + parent::buildRow($entity); } diff --git a/core/modules/node/node.module b/core/modules/node/node.module index 6bcd177..062686a 100644 --- a/core/modules/node/node.module +++ b/core/modules/node/node.module @@ -509,7 +509,6 @@ function template_preprocess_node_add_list(&$variables) { 'type' => $type->id(), 'add_link' => \Drupal::l($type->label(), new Url('node.add', array('node_type' => $type->id()))), 'description' => array( - // #markup is filtered for admin XSS automatically. '#markup' => $type->getDescription(), ), ); diff --git a/core/modules/node/src/NodeTypeListBuilder.php b/core/modules/node/src/NodeTypeListBuilder.php index dd1a1d9..89ea825 100644 --- a/core/modules/node/src/NodeTypeListBuilder.php +++ b/core/modules/node/src/NodeTypeListBuilder.php @@ -38,7 +38,6 @@ public function buildRow(EntityInterface $entity) { 'data' => $this->getLabel($entity), 'class' => array('menu-label'), ); - // #markup is filtered for admin XSS automatically. $row['description']['data'] = ['#markup' => $entity->getDescription()]; return $row + parent::buildRow($entity); } diff --git a/core/modules/simpletest/src/Form/SimpletestResultsForm.php b/core/modules/simpletest/src/Form/SimpletestResultsForm.php index ff86b01..49c086c 100644 --- a/core/modules/simpletest/src/Form/SimpletestResultsForm.php +++ b/core/modules/simpletest/src/Form/SimpletestResultsForm.php @@ -313,7 +313,6 @@ public static function addResultForm(array &$form, array $results) { $rows = array(); foreach ($assertions as $assertion) { $row = array(); - // #markup is filtered for admin XSS automatically. $row[] = ['data' => ['#markup' => $assertion->message]]; $row[] = $assertion->message_group; $row[] = \Drupal::service('file_system')->basename(($assertion->file)); diff --git a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php index 88aa877..16b0368 100644 --- a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php +++ b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php @@ -174,7 +174,6 @@ public function build() { ); $build['site_slogan'] = array( - // #markup is filtered for admin XSS automatically. '#markup' => $site_config->get('slogan'), '#access' => $this->configuration['use_site_slogan'], ); diff --git a/core/modules/system/system.admin.inc b/core/modules/system/system.admin.inc index a7cabee..1141a35 100644 --- a/core/modules/system/system.admin.inc +++ b/core/modules/system/system.admin.inc @@ -58,7 +58,6 @@ function template_preprocess_admin_block_content(&$variables) { foreach ($variables['content'] as $key => $item) { $variables['content'][$key]['link'] = \Drupal::l($item['title'], $item['url']); if (!$variables['compact'] && isset($item['description'])) { - // #markup is filtered for admin XSS automatically. $variables['content'][$key]['description'] = ['#markup' => $item['description']]; } else { diff --git a/core/modules/views_ui/views_ui.module b/core/modules/views_ui/views_ui.module index 48d70f6..86add67 100644 --- a/core/modules/views_ui/views_ui.module +++ b/core/modules/views_ui/views_ui.module @@ -129,7 +129,6 @@ function views_ui_preprocess_views_view(&$variables) { // Render title for the admin preview. if (!empty($view->live_preview)) { - // #markup is filtered for admin XSS automatically. $variables['title']['#markup'] = $view->getTitle(); }