Closed (fixed)
Project:
Monitoring
Version:
8.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
16 Sep 2015 at 14:43 UTC
Updated:
1 Oct 2015 at 06:55 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
giancarlosotelo commentedComment #3
giancarlosotelo commentedHere is a patch and a screenshot.
Comment #4
miro_dietikerThe current formatter has a setting "Formatter" that only allows to select "Plain text".
Instead of offering a new formatter, can we not just annotate in views data that the field is HTML aware and switch to something liks "Restricted HTML"?
Comment #5
miro_dietikerExtending a test to write some message with a tag and check that it is not output double encoded might be worth doing.
Comment #6
berdirNo, this isn't a format, it doesn't make sense to use one. Formats are configurable and might or might not exist and we have no idea what they allow.
Wondering if there isn't a default field plugin that can print this correctly?
Agreed on tests.
Comment #7
dawehnerSo in other words its a field we already trust its value ... and yeah XSS::filter then ensures that. It could be a helpful core field I guess.
Comment #8
miro_dietikerYeah, that would be great.
Comment #9
giancarlosotelo commentedAdded test.
Comment #10
miro_dietikerHmm... Yeah i want it in core, but i guess the feature dreams are over for 8.0.x.. :-)
@giancarlo Please file a core issue and pass the plugin there too.
Since this is not a 8.0.x core subject, i committed to Monitoring.
Note though that once this is in core, we will need to write an update function before we can drop the plugin otherwise things will break hard...
Committed, with some comment improvements.
I find it strange we are not testing for a test message, but a requirements message instead.
Comment #14
juanse254 commentedComment #17
giancarlosotelo commented