Closed (fixed)
Project:
Easy Breadcrumb
Version:
2.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
4 Sep 2026 at 15:33 UTC
Updated:
23 Sep 2026 at 06:05 UTC
Jump to comment: Most recent, Most recent file


Comments
Comment #2
loopduplicate commentedoof, thanks for the report. We'll be looking into fixing this soon.
Comment #3
loopduplicate commentedComment #4
loopduplicate commentedComment #5
loopduplicate commentedI added a failing test in the issue branch.
Comment #6
loopduplicate commentedI will work on a fix now. I am pressed for time today. We'll see how it goes.
Comment #7
loopduplicate commentedSorry, just ran out of time and couldn't figure it out yet.
Comment #10
andres alvarez commentedI dug into the regression and found the root cause. Commit
4307e2d(which fixed #3568508) bundled two unrelated changes intoformatTitle():is_string($title)case so plain strings also go throughHtml::decodeEntities()(previously onlyMarkupInterfaceobjects did, causing double/triple-encoded entities on alternate title fields).MarkupInterfacecase, it switched from stripping all HTML tags (strip_tags()) to preserving an allowed-tags whitelist (Xss::filter()).Change #2 is what causes this issue. Core wraps
%placeholdervalues int()as<em class="placeholder">...</em>— this is exactly the title Drupal generates for routes like the taxonomy vocabulary edit form. Before 2.0.10,strip_tags()removed that markup, leaving plain "Edit Tags". Since 2.0.10,Xss::filter()preserves the<em>tag in the string — but nothing downstream (the Capitalizator's word-splitting, or the finalnew Link($title, $url)construction) treats the result as safe markup. So the raw tag leaks into the rendered breadcrumb as literal text.I reproduced this exactly using the failing test already on this branch: instead of
Edit Tags, the actual output wasEdit <em Class="placeholder">Tags</em>— note even theclassattribute got capitalized toClass, because the Capitalizator's word-splitting logic treated the tag fragment as a regular word and applieducfirst()to it. That confirms nothing in the pipeline is prepared to handle preserved HTML.Fix: reverted just that one branch back to
strip_tags(Html::decodeEntities($title)), keeping the real #3568508 fix (entity decoding for plain strings) intact. The#markuprender-array branch was left untouched since it isn't part of this regression.Validated on a real Drupal 11 install (not just code review):
EasyBreadcrumbTermHierarchyTest) now passes (11 assertions).EasyBreadcrumbAlternateTitleFieldTest) still passes (13 assertions) — confirming this fix doesn't reintroduce that bug.Edit <em Class="placeholder">Tags</em>). Restoring the fix made it pass again.This looks correct and ready for review.
Comment #11
andres alvarez commentedComment #13
csakiistvanComment #14
csakiistvan✅ Tested and works — MR !235. Reproduced the escaped markup on the taxonomy admin paths in Claro, confirmed the fix restores Edit Tags, checked that the added test really fails without it and that the #3568508 entity-decoding fix is not reintroduced as a bug. The pipeline was red on two lint issues, so I pushed those fixes to the branch as well; it is green now.
Comment #15
loopduplicate commentedI'm going to split the test into two so that the new assertions are not lumped in with the TERM_HEIRARCHY test, something I should have done in the first commit in this branch but ran out of time.
Comment #16
loopduplicate commentedComment #18
loopduplicate commentedThanks justcaldwell, andres alvarez, csakiistvan, and greg boggs (behind the scenes).