Closed (fixed)
Project:
Name Field
Version:
8.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
22 Apr 2026 at 17:31 UTC
Updated:
6 May 2026 at 20:10 UTC
Jump to comment: Most recent
The url is currently created by concating strings.
if (!empty($components['url'])) {
$name = new FormattableMarkup('<a href=":link">' . $name . '</a>', [
':link' => $components['url']->toString(),
]);
}
$name = $this->parser->parse($components, $format_string, $this->settings);
$safe_name = $name instanceof MarkupInterface ? $name : Html::escape((string) $name);
if (!empty($components['url'])) {
$name = new FormattableMarkup('<a href=":link">@name</a>', [
':link' => $components['url']->toString(),
'@name' => $safe_name,
]);
}
Add a regression test that pushes <script>alert(1)</script> through NameFormatter::viewElements() and asserts it's sanitized.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
bluegeek9 commentedComment #3
bluegeek9 commentedComment #6
bluegeek9 commented