From #2506195-11: Remove SafeMarkup::set() from Xss::filter().

+++ b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
@@ -173,7 +174,7 @@ public function build() {
-      '#markup' => Xss::filterAdmin($site_config->get('slogan')),
+      '#markup' => SafeMarkup::xssFilterAdmin($site_config->get('slogan')),

Filtering here is redundant since by default #markup is admin filtered. This is removed in #2506195: Remove SafeMarkup::set() from Xss::filter() but we should add an explicit test.

Beta phase evaluation

Reference: https://www.drupal.org/core/beta-changes
Issue category Task
Issue priority Normal
Unfrozen changes Unfrozen because it only changes tests.
CommentFileSizeAuthor
#4 test_xss_filtering_of-2526458-4.patch998 bytescilefen

Comments

alexpott’s picture

alexpott’s picture

Title: Remove XSS filtering from SystemBrandingBlock » Test XSS filtering of slogan in SystemBrandingBlock
Issue summary: View changes
cilefen’s picture

Issue summary: View changes
cilefen’s picture

Status: Active » Needs review
StatusFileSize
new998 bytes
googletorp’s picture

Status: Needs review » Reviewed & tested by the community

Looks good to me.

googletorp’s picture

Issue summary: View changes
googletorp’s picture

Issue summary: View changes
xjm’s picture

Status: Reviewed & tested by the community » Fixed

Test looks great. This issue only changes test code, so per https://www.drupal.org/core/beta-changes, this can be completed any time during the Drupal 8 beta phase. Committed and pushed to 8.0.x. Thanks!

  • xjm committed d404b26 on 8.0.x
    Issue #2526458 by cilefen, googletorp, alexpott: Test XSS filtering of...

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.