In field_group_field_group_to_hook_code(), check_plain() is used to "sanitize" strings for PHP.
It would be better / more robust to use var_export() instead.

The check_plain() is in safe, because every single quote is replaced with "'".
It also does not usually mess up the string, because it is only used for group machine names.

However, check_plain(), which uses htmlspecialchars(), is designed for HTML, not for PHP code generation.
Better to use var_export().

Comments

donquixote created an issue. See original summary.

donquixote’s picture

Status: Active » Needs review
donquixote’s picture

chris matthews’s picture

The year old patch in #3 to field_group.module applied cleanly to the latest field_group 7.x-1.x-dev, but still needs review.

nils.destoop’s picture

Status: Needs review » Closed (won't fix)