Problem/Motivation
group_notify_mail() is currently doing this:
$message['body'][] = Html::escape($params['content']);
$message['body'][] = Html::escape($params['link']);
That means that the emails being sent out are full of escaped HTML. If you 'View source' on a message, you see this:
Posted by: Admin Root
<article id="node-1839" data-history-node-id="1839" data-quickedit-entity-id="node/1839" role="article" class="contextual-region" about="/private-audio/test-audio-august-13-2020">
<div>dww was here</div>
<h2><span data-quickedit-field-id="node/1839/title/en/group_notify_email" class="field field--name-title field--type-string field--label-hidden">Test audio - August 13, 2020</span>
</h2>
...
And the message appears like so in your inbox:
Posted by: Admin Root <article id="node-1839" data-history-node-id="1839" data-quickedit-entity-id="node/1839" role="article" class="contextual-region" about="/private-audio/test-audio-august-13-2020"> <div>dww was here</div> <h2><span data-quickedit-field-id="node/1839/title/en/group_notify_email" class="field field--name-title field--type-string field--label-hidden">Test audio - August 13, 2020</span> </h2>...
Calling this a 'major' bug, since it seems to break the fundamental feature of this module, and there seems to be no work-around other than patching it.
Steps to reproduce
- Configure a node type to send emails.
- Configure the group_notify_email view mode for this node type to include markup.
- Generate a notification.
- Look at the results.
Proposed resolution
Don't use Html::escape(). Rely on the fact that the text format on the nodes should already be configured to prevent unsafe markup, or that only folks we trust have access to create them. We don't need to escape the HTML again, we need to send it off to the mailer system just like we were sending it to a browser. Then the raw message source looks like this:
Posted by: Admin Root
<article id="node-1839" data-history-node-id="1839" data-quickedit-entity-id="node/1839" role="article" class="contextual-region" about="http://dev.breema.com/private-audio/test-audio-august-13-2020"><div>dww was here</div>
<h2><span data-quickedit-field-id="node/1839/title/en/group_notify_email" class="field field--name-title field--type-string field--label-hidden">Test audio - August 13, 2020</span>
</h2>
And the e-mail looks like it's supposed to in your inbox (see screenshots below).
Remaining tasks
Agree this is the right move. I don't understand how/why it's been like this all along. Maybe I'm missing something?Upload the patch.Reviews / refinements.Commit.
User interface changes
HTML emails will now actually contain renderable HTML, not escaped tags that end up looking like raw HTML.
Before

After

API changes
Nope.
Data model changes
N/A
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | 3165156-2.patch | 707 bytes | dww |
| normal-html-email.png | 18.65 KB | dww | |
| escaped-html-email.png | 62.64 KB | dww |
Comments
Comment #2
dwwComment #3
gregcube commentedDefinitely the right move. Bonehead oversight on my part.
Comment #5
dwwCool, thanks for confirming! I'm not sure I'd call it "bonehead" -- always better safe than sorry. 😉 Would much rather have bugs from being too paranoid and safe, than to have sec holes...
But good to know this is agreeable, since it'll make the emails much more useful.
Thanks for the quick commit!
-Derek