In order to format the subscription block, I added <div class="dg-mailchimp-div"> (and a /div) to the Description in Mailchimp|Signup Forms. I could then manipulate the description text. With the 7.3 update, the class definition is missing. Is it being scrubbed as part of the update? If a user-defined class is a problem, can mailchimp assign a unique class to the Description text?

Comments

Anonymous’s picture

The form description in being passed to the filter_xss function on line 253 in mailchimp.module file like this :

  $form['description'] = array(
    '#markup' => filter_xss($signup->settings['description']),
  );

This function does not allow the <div> tag. The full allowed tag list is described on the function documentation page (linked above).

I altered the $form['description']['#markup'] in function template_form_alter(&$form) to obtain what I wanted. Hope that helps a bit.

eojthebrave’s picture

I wonder if the more permissive filter_xss_admin() would be better here? This would allow an admin to place more HTML tags into the description. And is probably pretty safe because this is a field that only site administrators will be putting data into so the risk of them wanting to do something nefarious is lowered. And, filter_xss_admin() will still protect from anything really bad.

drikc’s picture

Status: Active » Needs review
StatusFileSize
new2.67 KB

The attached patch use text formats for the description field; then the admin is free to choose the text format he want...

drikc’s picture

Finally, I think it isn't that useful to have text format as proposed in #3. @eojthebrave solution with filter_xss_admin() is much better and should be sufficient!...

Anonymous’s picture

Wouldn't the use of a text format allowing a rich text editor to be used ? In that case anyone would be able to change the description without html knowledge I guess.

Otherwise I agree switching to filter_xss_admin() as proposed in #2 seems to be a good and simple idea.

BabaYaga64’s picture

Many thanks to eojthebrave for your suggestion! I have added "filter_xss_admin()" to allow admin users to place additional HTML tags in the signup form description text.

ragnarkurm’s picture

Status: Needs review » Reviewed & tested by the community

#6 solved the issue for the project I'm working on. Patch is simple and elegant. filter_xss_admin() is certainly way better than what we have now. If there is really need for #3 (text formats), then we can create another issue for it.

ragnarkurm’s picture

While we wait for the patch to be incorporated ...

Workaround

function mymodule_form_mailchimp_signup_subscribe_block_join_list_form_alter(&$form, $form_state, $form_id) {
  $desc = &$form['description']['#markup'];
  $desc = <<<HTML
<div class="my-class">$desc</div>
HTML;
}

  • 136b6bf committed on 7.x-3.x
    Issue #2481545 by BabaYaga64: 7.x-3.3 scrubs html from subscription...
jami’s picture

Version: 7.x-3.3 » 7.x-3.4
Status: Reviewed & tested by the community » Fixed

Applied. Thanks all!

ragnarkurm’s picture

You marked version as 3.4 which is already released on 2015-Jun-22.
The fix is currently available in 7.x-3.x-dev.
I understand the fix will eventually be available in 3.5.

jami’s picture

Version: 7.x-3.4 » 7.x-3.x-dev

Thanks. Fixed!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

Bensbury’s picture

It looks like this fix has been changed back. I am using 7.x-5.1
I am unable to use HTML in the description as per this thread.

Checking the module code in mailchimp_signup.module the description is being passed through filter_xss as previously written but now at line 264

function mailchimp_signup_subscribe_form($form, &$form_state, $signup, $type) {
  $form['#attributes'] = array('class' => array('mailchimp-signup-subscribe-form'));
  $form['description'] = array(
    '#markup' => mailchimp_signup_tt("mailchimp_signup:mailchimp_signup:$signup->name:description", filter_xss($signup->settings['description'])),
    '#prefix' => '<div class="mailchimp-signup-subscribe-form-description">',
    '#suffix' => '</div>',
  );

Changing the code to use the filter filter_xss_admin() fixes the problem as per the fix in this issue.

So... is there a reason it was changed back?
I think this is really important to be able to style the sign up form without wrecking tpls or writing module hooks.

Thanks.

brunodbo’s picture

Since I can't reopen this issue, I created #3004180: Allow HTML in signup form description with a patch for 7.x-5.x.