Problem/Motivation

Probably strings processing is not in robust secure state, so this has to be thoroughly reviewed.

Steps to reproduce

Proposed resolution

Remaining tasks

  1. Fix [done]
  2. Review once again if fixed well [done]

User interface changes

API changes

Data model changes

Comments

mindaugasd created an issue. See original summary.

mindaugasd’s picture

Assigned: Unassigned » mindaugasd

  • mindaugasd committed cf0803da on 1.0.x
    Issue #3388695 by mindaugasd: Sanitize strings properly
    
mindaugasd’s picture

Issue summary: View changes
mindaugasd’s picture

Core sanitization functions:

  • AIPromptSegmentBase::buildPreview() - returns markup render element with html converted to html entities with new lines (br) preserved
  • AIPromptCommons::prepareStatusMessage() - returns markup render element with html converted to html entities with new lines (br) preserved
  • $aiprompt->buildPreview() - many Markup render elements for display to the user (for example, output prompt as views field)
  • AIPromptSegmentBase::render() - returns raw not sanitized string for sending to AI in its original form
  • AIPromptCommonEngineeringForm::displayOutputSubmit() - helper function to display prompt output for the user. Raw output is displayed either with ksm() function if devel module is enabled, or with $this->messenger()->addMessage($this->prepareStatusMessage($output))

Saving data to the database:

  • Data is saved as either "data" json text basefield for content entity, or individual segment custom configuration values as "ignore" type for configuration entity.
mindaugasd’s picture

Issue summary: View changes
Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.