Closed (fixed)
Project:
Mailchimp
Version:
7.x-3.x-dev
Component:
General
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
1 May 2015 at 18:02 UTC
Updated:
3 Oct 2018 at 22:17 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
Anonymous (not verified) commentedThe form description in being passed to the filter_xss function on line 253 in mailchimp.module file like this :
This function does not allow the
<div>tag. The full allowed tag list is described on the function documentation page (linked above).I altered the
$form['description']['#markup']infunction template_form_alter(&$form)to obtain what I wanted. Hope that helps a bit.Comment #2
eojthebraveI wonder if the more permissive filter_xss_admin() would be better here? This would allow an admin to place more HTML tags into the description. And is probably pretty safe because this is a field that only site administrators will be putting data into so the risk of them wanting to do something nefarious is lowered. And, filter_xss_admin() will still protect from anything really bad.
Comment #3
drikc commentedThe attached patch use text formats for the description field; then the admin is free to choose the text format he want...
Comment #4
drikc commentedFinally, I think it isn't that useful to have text format as proposed in #3. @eojthebrave solution with filter_xss_admin() is much better and should be sufficient!...
Comment #5
Anonymous (not verified) commentedWouldn't the use of a text format allowing a rich text editor to be used ? In that case anyone would be able to change the description without html knowledge I guess.
Otherwise I agree switching to filter_xss_admin() as proposed in #2 seems to be a good and simple idea.
Comment #6
BabaYaga64 commentedMany thanks to eojthebrave for your suggestion! I have added "filter_xss_admin()" to allow admin users to place additional HTML tags in the signup form description text.
Comment #7
ragnarkurm commented#6 solved the issue for the project I'm working on. Patch is simple and elegant.
filter_xss_admin()is certainly way better than what we have now. If there is really need for #3 (text formats), then we can create another issue for it.Comment #8
ragnarkurm commentedWhile we wait for the patch to be incorporated ...
Workaround
Comment #10
jami commentedApplied. Thanks all!
Comment #11
ragnarkurm commentedYou marked version as 3.4 which is already released on 2015-Jun-22.
The fix is currently available in 7.x-3.x-dev.
I understand the fix will eventually be available in 3.5.
Comment #12
jami commentedThanks. Fixed!
Comment #14
Bensbury commentedIt looks like this fix has been changed back. I am using 7.x-5.1
I am unable to use HTML in the description as per this thread.
Checking the module code in mailchimp_signup.module the description is being passed through
filter_xssas previously written but now at line 264Changing the code to use the filter
filter_xss_admin()fixes the problem as per the fix in this issue.So... is there a reason it was changed back?
I think this is really important to be able to style the sign up form without wrecking tpls or writing module hooks.
Thanks.
Comment #15
brunodboSince I can't reopen this issue, I created #3004180: Allow HTML in signup form description with a patch for 7.x-5.x.