diff --git a/core/modules/filter/src/FilterFormatFormBase.php b/core/modules/filter/src/FilterFormatFormBase.php index e1222b4..37b26e7 100644 --- a/core/modules/filter/src/FilterFormatFormBase.php +++ b/core/modules/filter/src/FilterFormatFormBase.php @@ -79,7 +79,7 @@ public function form(array $form, FormStateInterface $form_state) { $form['roles'] = array( '#type' => 'checkboxes', '#title' => $this->t('Roles'), - '#options' => array_map('\Drupal\Component\Utility\Html::escape', user_role_names()), + '#options' => user_role_names(), '#disabled' => $is_fallback, '#weight' => -10, ); diff --git a/core/modules/system/src/Tests/Form/ElementTest.php b/core/modules/system/src/Tests/Form/ElementTest.php index 1cc6cd8..4917a57 100644 --- a/core/modules/system/src/Tests/Form/ElementTest.php +++ b/core/modules/system/src/Tests/Form/ElementTest.php @@ -55,18 +55,28 @@ function testOptions() { // Verify that all options appear in their defined order. foreach (array('checkbox', 'radio') as $type) { $elements = $this->xpath('//input[@type=:type]', array(':type' => $type)); - $expected_values = array('0', 'foo', '1', 'bar', '>'); + $expected_values = array('0', 'foo', '1', 'bar', 'translated', '>', 'markup'); foreach ($elements as $element) { $expected = array_shift($expected_values); $this->assertIdentical((string) $element['value'], $expected); } } - // Verify that the choices are admin filtered as expected. - $this->assertRaw("Special Charalert('checkboxes');"); - $this->assertRaw("Special Charalert('radios');"); - $this->assertRaw('Bar - checkboxes'); - $this->assertRaw('Bar - radios'); + // Verify that the choices are escaped by default. + $this->assertRaw('<em>Bar - checkboxes</em>'); + $this->assertRaw('<em>Bar - radios</em>'); + $this->assertRaw("<em>Special Char</em><script>alert('checkboxes');</script>"); + $this->assertRaw("<em>Special Char</em><script>alert('radios');</script>"); + + // Verify that safe strings marked safe such as TranslatableString are not + // auto-escaped. + $this->assertRaw('Bar - radios translated'); + $this->assertRaw('Bar - checkboxes translated'); + + // Verify that radio button and checkbox labels can contain markup and are + // admin filtered when using #markup. + $this->assertRaw("Fooalert('radios');"); + $this->assertRaw("Fooalert('checkboxes');"); // Enable customized option sub-elements. $this->drupalGet('form-test/checkboxes-radios/customize'); @@ -75,7 +85,8 @@ function testOptions() { // #weight into account. foreach (array('checkbox', 'radio') as $type) { $elements = $this->xpath('//input[@type=:type]', array(':type' => $type)); - $expected_values = array('0', 'foo', 'bar', '>', '1'); + $this->verbose(print_r($elements, TRUE)); + $expected_values = array('0', 'foo', 'bar', 'translated', '>', 'markup', '1'); foreach ($elements as $element) { $expected = array_shift($expected_values); $this->assertIdentical((string) $element['value'], $expected); diff --git a/core/modules/system/tests/modules/form_test/src/Form/FormTestCheckboxesRadiosForm.php b/core/modules/system/tests/modules/form_test/src/Form/FormTestCheckboxesRadiosForm.php index 318f618..3d1be09 100644 --- a/core/modules/system/tests/modules/form_test/src/Form/FormTestCheckboxesRadiosForm.php +++ b/core/modules/system/tests/modules/form_test/src/Form/FormTestCheckboxesRadiosForm.php @@ -36,8 +36,10 @@ public function buildForm(array $form, FormStateInterface $form_state, $customiz 0 => 'Zero', 'foo' => 'Foo', 1 => 'One', - 'bar' => $this->t('Bar - checkboxes'), + 'bar' => 'Bar - checkboxes', + 'translated' => $this->t('Bar - checkboxes translated'), '>' => "Special Char", + 'markup' => array('#markup' => "Foo"), ), ); if ($customize) { @@ -61,7 +63,9 @@ public function buildForm(array $form, FormStateInterface $form_state, $customiz 'foo' => 'Foo', 1 => 'One', 'bar' => 'Bar - radios', + 'translated' => $this->t('Bar - radios translated'), '>' => "Special Char", + 'markup' => array('#markup' => "Foo"), ), ); if ($customize) { diff --git a/core/modules/user/src/Plugin/Condition/UserRole.php b/core/modules/user/src/Plugin/Condition/UserRole.php index f6ddb87..bd98a75 100644 --- a/core/modules/user/src/Plugin/Condition/UserRole.php +++ b/core/modules/user/src/Plugin/Condition/UserRole.php @@ -33,7 +33,7 @@ public function buildConfigurationForm(array $form, FormStateInterface $form_sta '#type' => 'checkboxes', '#title' => $this->t('When the user has the following roles'), '#default_value' => $this->configuration['roles'], - '#options' => array_map('\Drupal\Component\Utility\Html::escape', user_role_names()), + '#options' => user_role_names(), '#description' => $this->t('If you select no roles, the condition will evaluate to TRUE for all users.'), ); return parent::buildConfigurationForm($form, $form_state); diff --git a/core/modules/user/src/Plugin/views/access/Role.php b/core/modules/user/src/Plugin/views/access/Role.php index 42404ce..cd3c34a 100644 --- a/core/modules/user/src/Plugin/views/access/Role.php +++ b/core/modules/user/src/Plugin/views/access/Role.php @@ -115,7 +115,7 @@ public function buildOptionsForm(&$form, FormStateInterface $form_state) { '#type' => 'checkboxes', '#title' => $this->t('Role'), '#default_value' => $this->options['role'], - '#options' => array_map('\Drupal\Component\Utility\Html::escape', user_role_names()), + '#options' => user_role_names(), '#description' => $this->t('Only the checked roles will be able to access this display.'), ); } diff --git a/core/modules/user/src/Plugin/views/argument_validator/User.php b/core/modules/user/src/Plugin/views/argument_validator/User.php index 416008d..49277c8 100644 --- a/core/modules/user/src/Plugin/views/argument_validator/User.php +++ b/core/modules/user/src/Plugin/views/argument_validator/User.php @@ -65,7 +65,7 @@ public function buildOptionsForm(&$form, FormStateInterface $form_state) { $form['roles'] = array( '#type' => 'checkboxes', '#title' => $this->t('Restrict to the selected roles'), - '#options' => array_map(array('\Drupal\Component\Utility\Html', 'escape'), user_role_names(TRUE)), + '#options' => user_role_names(TRUE), '#default_value' => $this->options['roles'], '#description' => $this->t('If no roles are selected, users from any role will be allowed.'), '#states' => array( diff --git a/core/modules/views/src/Plugin/views/display/Attachment.php b/core/modules/views/src/Plugin/views/display/Attachment.php index ef691be..8a36066 100644 --- a/core/modules/views/src/Plugin/views/display/Attachment.php +++ b/core/modules/views/src/Plugin/views/display/Attachment.php @@ -203,7 +203,7 @@ public function buildOptionsForm(&$form, FormStateInterface $form_state) { '#title' => $this->t('Displays'), '#type' => 'checkboxes', '#description' => $this->t('Select which display or displays this should attach to.'), - '#options' => array_map('\Drupal\Component\Utility\Html::escape', $displays), + '#options' => $displays, '#default_value' => $this->getOption('displays'), ); break; diff --git a/core/modules/views/src/Plugin/views/display/Feed.php b/core/modules/views/src/Plugin/views/display/Feed.php index c78d23b..88915f3 100644 --- a/core/modules/views/src/Plugin/views/display/Feed.php +++ b/core/modules/views/src/Plugin/views/display/Feed.php @@ -255,7 +255,7 @@ public function buildOptionsForm(&$form, FormStateInterface $form_state) { '#title' => $this->t('Displays'), '#type' => 'checkboxes', '#description' => $this->t('The feed icon will be available only to the selected displays.'), - '#options' => array_map('\Drupal\Component\Utility\Html::escape', $displays), + '#options' => $displays, '#default_value' => $this->getOption('displays'), ); break;