Webform module let's a form creator add tokens in a few places (e.g., for description field of a component). This may not always wanted.

How can this be prevented? I have not found any module that let me grant permissions by roles. I ask in the webform issue queue and not in the token one because this is not a problem usually (in Drupal core fields) but rather in components.

Thanks!

Comments

danchadwick’s picture

Status: Active » Fixed

Assuming you want to stop them for everyone, you can implement hook_token_alter to remove any tokens you don't want used. It would be a hideous hack, but you could look at the URL and the global $user to decide if this is a situation where you want to disable the tokens.

Another option would be to implement HOOK_webform_component_edit_form_alter() to add a validation handler to strip off or sanitize any unwanted tokens.

And last, I would update to the latest version.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

drumm’s picture