I have created a flag 'publish', which obviously publishes a created node when clicked. I then use rules to send an email with the flag-link ([node:flag-publish-link]), so the user can click the link in the mail and publish the node.

However, in the mail the link replaces '&' with '&', which creates an invalid link. On the site itself the link is correct, even when I make a rule to generate a system message with the same value ([node:flag-publish-link]) as the mail link.

Why is this happening and how can I solve it? I really need people to click the link in the mail, not on the site.

Comments

fago’s picture

Title: Link to toggle flag returns &amp in mail, but not in link in node » Token "Link to toggle flag" does not respect sanitize option
Component: Rules integration » Token integration

A short look at flag module's token implementation reveals that it doesn't respect the token 'sanitize' option.

quicksketch’s picture

You're right that we don't look at the sanitize parameter, because the link and count should never be sanitized:

        $flag_count_token = 'flag-' . str_replace('_', '-', $flag->name) . '-count';
        $flag_link_token = 'flag-' . str_replace('_', '-', $flag->name) . '-link';
        if ($name == $flag_count_token) {
          $replacements[$original] = $flag->get_count($flag->get_content_id($object));
        }
        elseif ($name == $flag_link_token) {
          $replacements[$original] = flag_create_link($flag->name, $flag->get_content_id($object));
        }

So it looks to me like if anything the link is getting sanitized after the token itself is generated, because whether $sanitize is TRUE or FALSE, we don't sanitize it either way because it's already assumed to be safe output.

joachim’s picture

Status: Active » Closed (works as designed)

Closing in light of above comment.

joachim’s picture

Issue summary: View changes

Added code tag