summaryrefslogtreecommitdiff
path: root/modules/comment/helpers
diff options
context:
space:
mode:
authorTim Almdal <tnalmdal@shaw.ca>2009-07-04 08:17:12 -0700
committerTim Almdal <tnalmdal@shaw.ca>2009-07-04 08:17:12 -0700
commitd6648c0affd122407b7567442aa924e9138104e7 (patch)
tree015f10205d96618edcf210ad93c672a74956d979 /modules/comment/helpers
parent54ffea24196e8f5d88cf9d8607455f0f6aab305c (diff)
Fix for ticket #477. Use nl2br method when rendering comment::text and
item::description. In addition add p::clean or p::purify to places that xss cleaning had missed (i.e. rss feeds)
Diffstat (limited to 'modules/comment/helpers')
-rw-r--r--modules/comment/helpers/comment_rss.php6
1 files changed, 3 insertions, 3 deletions
diff --git a/modules/comment/helpers/comment_rss.php b/modules/comment/helpers/comment_rss.php
index 746c6161..ab3d2283 100644
--- a/modules/comment/helpers/comment_rss.php
+++ b/modules/comment/helpers/comment_rss.php
@@ -53,13 +53,13 @@ class comment_rss_Core {
$item = $comment->item();
$feed->children[] = new ArrayObject(
array("pub_date" => date("D, d M Y H:i:s T", $comment->created),
- "text" => $comment->text,
+ "text" => nl2br(p::purify($comment->text)),
"thumb_url" => $item->thumb_url(),
"thumb_height" => $item->thumb_height,
"thumb_width" => $item->thumb_width,
"item_uri" => url::abs_site("{$item->type}s/$item->id"),
- "title" => $item->title,
- "author" => $comment->author_name()),
+ "title" => p::purify($item->title),
+ "author" => p::clean($comment->author_name())),
ArrayObject::ARRAY_AS_PROPS);
}