The message content does not seem to get passed through any filters.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

tom_buytaert’s picture

FileSize
384 bytes

I attached a patch, in which the message is sent through filter_xss()

tom_buytaert’s picture

FileSize
486 bytes

Same patch, but this one also allows the use of images.

Or should check_markup() be used instead of filter_xss() ?

Kars-T’s picture

Assigned: Unassigned » Kars-T

Hi thanks for the patch. In D5 I used check_markup but with always the default filter applied. For the next D6 patch I will alter the data structure and apply check_markup() sothe user can use any allowed filters to his role. I will do this probably next week.

tom_buytaert’s picture

Okay, thanks.

Great module, by the way!

Kars-T’s picture

Status: Needs review » Fixed

Latest dev fixes this. Please test it.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.