From 54ffea24196e8f5d88cf9d8607455f0f6aab305c Mon Sep 17 00:00:00 2001
From: Tim Almdal
Date: Fri, 3 Jul 2009 21:44:10 -0700
Subject: Split the clean method into two clean and purify. clean is a light
weight approach using html::specialchars and purify uses HTMLPurifier to
intelligently cleanse the output fields. Use purifier for text and title
fields where it is likely that a user would enter html to format their data.
---
modules/comment/views/comments.html.php | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
(limited to 'modules/comment/views/comments.html.php')
diff --git a/modules/comment/views/comments.html.php b/modules/comment/views/comments.html.php
index d9405e5f..2d754791 100644
--- a/modules/comment/views/comments.html.php
+++ b/modules/comment/views/comments.html.php
@@ -21,7 +21,7 @@
"name" => p::clean($comment->author_name()))); ?>
- = p::clean($comment->text) ?>
+ = p::purify($comment->text) ?>
endforeach ?>
--
cgit v1.2.3