From d6648c0affd122407b7567442aa924e9138104e7 Mon Sep 17 00:00:00 2001
From: Tim Almdal
Date: Sat, 4 Jul 2009 08:17:12 -0700
Subject: Fix for ticket #477. Use nl2br method when rendering comment::text
and item::description. In addition add p::clean or p::purify to places that
xss cleaning had missed (i.e. rss feeds)
---
modules/comment/views/comment.mrss.php | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
(limited to 'modules/comment/views/comment.mrss.php')
diff --git a/modules/comment/views/comment.mrss.php b/modules/comment/views/comment.mrss.php
index 4f520144..e27bc44f 100644
--- a/modules/comment/views/comment.mrss.php
+++ b/modules/comment/views/comment.mrss.php
@@ -22,14 +22,14 @@
= $pub_date ?>
foreach ($feed->children as $child): ?>
-
- = p::clean($child->title) ?>
+ = p::purify($child->title) ?>
= p::clean($child->item_uri) ?>
= p::clean($child->author) ?>
= $child->item_uri ?>
= $child->pub_date ?>
= p::clean($child->text) ?>
+ = nl2br(p::purify($child->text)) ?>
--
cgit v1.2.3