Skip to content

Commit 295771a

Browse files
Always escape insecure content when rendering HTML
1 parent cf3f5e6 commit 295771a

File tree

11 files changed

+17
-17
lines changed

11 files changed

+17
-17
lines changed

Resources/doc/cookbook/modal-with-fields.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ You can simply do it by adding modal with the field:
2727
</div>
2828
</div>
2929
<div class="modal-footer">
30-
<button type="button" class="btn btn-default cancel" data-dismiss="modal">{{ 'action.custom.cancel'|trans({}, "Admingenerator")|raw }}</button>
31-
<button type="submit" class="btn btn-primary confirm">{{ 'action.custom.confirm'|trans({}, "Admingenerator")|raw }}</button>
30+
<button type="button" class="btn btn-default cancel" data-dismiss="modal">{{ 'action.custom.cancel'|trans({}, "Admingenerator") }}</button>
31+
<button type="submit" class="btn btn-primary confirm">{{ 'action.custom.confirm'|trans({}, "Admingenerator") }}</button>
3232
</div>
3333
</form>
3434
</div>

Resources/views/flash.html.twig

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
<div class="alert alert-dismissable alert-success fade in">
33
<i class="fa fa-check"></i>
44
<button type="button" class="close" data-dismiss="alert" aria-hidden="true">×</button>
5-
{{ flashMessage|raw }}
5+
{{ flashMessage }}
66
</div>
77
{% endblock %}
88

99
{% block flash_message_error %}
1010
<div class="alert alert-dismissable alert-danger fade in">
1111
<i class="fa fa-ban"></i>
1212
<button type="button" class="close" data-dismiss="alert" aria-hidden="true">×</button>
13-
{{ flashMessage|raw }}
13+
{{ flashMessage }}
1414
</div>
1515
{% endblock %}
1616

Resources/views/templates/CommonAdmin/EditTemplate/fieldsets.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
{{ echo_block("form_fieldset_" ~ fieldsetName|classify|replace({'.': '_'})) }}
1414
<fieldset class="form-model-tab-pane tab-pane-model-{{ fieldsetName|classify|replace({'.': '-'}) }} tab-pane">
1515
{% if "NONE" != fieldsetName[:4] and "!" != fieldsetName[:1] %}
16-
<legend><span>{{ echo_trans(fieldsetName,{}, i18n_catalog|default("Admin") ) }}</span></legend>
16+
<legend><span>{{ echo_trans(fieldsetName,{}, i18n_catalog|default("Admin"), 'html' ) }}</span></legend>
1717
{% endif %}
1818

1919
{% for rowName,row in fieldset %}

Resources/views/templates/CommonAdmin/ListTemplate/scopes.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
"{ 'group': '" ~ (groupName|classify|lower) ~ "', 'scope': '" ~ (scopeName|classify|lower) ~ "' }") }}
1212
">
1313
{%- if params.icon is defined %}<i class="fa {{ params.icon }}"></i> {% endif -%}
14-
{{- echo_trans(scopeName, {}, i18n_catalog|default("Admin")) -}}
14+
{{- echo_trans(scopeName, {}, i18n_catalog|default("Admin"), 'html') -}}
1515
</a>
1616
{% endfor %}
1717
</div>

Resources/views/templates/CommonAdmin/ShowTemplate/show.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313

1414
<div class="show-model-tab-pane tab-pane-model-{{ fieldsetName|classify|replace({'.': '-'}) }} tab-pane">
1515
{% if "NONE" != fieldsetName[:4] and "!" != fieldsetName[:1] %}
16-
<h2>{{ echo_trans(fieldsetName,{}, i18n_catalog is defined ? i18n_catalog : "Admin" ) }}</h2>
16+
<h2>{{ echo_trans(fieldsetName,{}, i18n_catalog is defined ? i18n_catalog : "Admin", 'html' ) }}</h2>
1717
{% endif %}
1818

1919
{% for row in fieldset %}

Resources/views/templates/CommonAdmin/ShowTemplate/sidebar.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<div class="col-md-12 sidebar-widget-{{ name|classify|replace({'.': '-'})|lower }}">
99
<div class="box box-primary">
1010
<div class="box-header">
11-
<h3 class="box-title">{{ echo_trans(name,{}, i18n_catalog|default("Admin") ) }}</h3>
11+
<h3 class="box-title">{{ echo_trans(name,{}, i18n_catalog|default("Admin"), 'html' ) }}</h3>
1212
</div>
1313
<div class="box-body">
1414
{% if widget.partial is defined %}

Resources/views/templates/CommonAdmin/batch_actions.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@
4646
{% endif -%}
4747
>
4848
{% if action.icon %}<i class="{% if action.icon is defined and action.icon|length > 0 %}fa {{ action.icon }}{% endif %}"></i> {% endif %}
49-
{{ echo_trans(action.label, {}, translationDomain) }}
49+
{{ echo_trans(action.label, {}, translationDomain, 'html') }}
5050
</option>
5151
{% endblock %}
5252

Resources/views/templates/CommonAdmin/generic_actions.php.twig

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@
5252
data-toggle="modal"
5353
{% endif %}
5454
>
55-
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain) }}
55+
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain, 'html') }}
5656
</button>
5757
{% else %}
5858
<a class="generic-action btn {{ action.class|default('btn-default') }}" href="{{ echo_path(actionRoute, actionParams) }}"
@@ -61,7 +61,7 @@
6161
data-toggle="modal"
6262
{% endif %}
6363
{%- if action.csrfProtected %} data-csrf-token="{{ echo_path(actionRoute, actionParams, ['csrf_token']) }}" {% endif -%}>
64-
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain) }}
64+
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain, 'html') }}
6565
</a>
6666
{% endif %}
6767
{% endblock %}
@@ -80,7 +80,7 @@
8080
<li><a class="generic-action btn {{ action.class|default('btn-default') }}" href="{{ echo_path(actionRoute, actionParams) }}"
8181
{%- if action.confirm %} data-confirm="{{ echo_trans(action.confirm, {}, translationDomain, 'html_attr') }}"{% endif %}
8282
{%- if action.csrfProtected %} data-csrf-token="{{ echo_path(actionRoute, actionParams, ['csrf_token']) }}" {% endif -%}>
83-
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain) }}</a></li>
83+
{%- if action.icon %}<i class="fa fa-fw {{ action.icon|default }}"></i> {% endif %}{{ echo_trans(action.label, {}, translationDomain, 'html') }}</a></li>
8484

8585
{% for keyName, eaction in excelActions %}
8686

@@ -90,7 +90,7 @@
9090

9191
<li><a class="generic-action btn {{ eaction.class|default('btn-default') }}" href="{{ echo_path(actionRoute, echo_twig_assoc({ key: keyName })) }}"
9292
{%- if action.confirm %} data-confirm="{{ echo_trans(action.confirm, {}, translationDomain, 'html_attr') }}"{% endif -%}>
93-
{%- if eaction.icon %}<i class="fa fa-fw {{ eaction.icon|default }}"></i> {% endif %}{{ echo_trans(eaction.label, {}, translationDomain) }}
93+
{%- if eaction.icon %}<i class="fa fa-fw {{ eaction.icon|default }}"></i> {% endif %}{{ echo_trans(eaction.label, {}, translationDomain, 'html') }}
9494
</a></li>
9595

9696
{% if eaction.credentials %}

Resources/views/templates/CommonAdmin/object_actions.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@
4545
{% endif -%}
4646
{%- if action.csrfProtected and not action.forceIntermediate %} data-csrf-token="{{ echo_path(actionRoute, actionParams, ['csrf_token']) }}" {% endif -%}>
4747
<i class="fa fa-fw {{ action.icon|default('fa-square fa-regular') }}"></i>
48-
<span>{{ echo_trans(action.label, {}, translationDomain) }}</span>
48+
<span>{{ echo_trans(action.label, {}, translationDomain, 'html') }}</span>
4949
</a>
5050
{{ echo_endspaceless() }}
5151
{% endapply %}

Resources/views/templates/CommonAdmin/tabs.php.twig

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<li>
2121
<a data-toggle="tab" href="#"
2222
data-target="{%- for fieldsetName,fieldset in tab -%}{{ '.tab-pane-model-'~fieldsetName|classify|replace({'.': '-'}) }}{%if not loop.last%},{% endif %}{% endfor %}">
23-
{{ echo_trans(name, {}, i18n_catalog|default("Admin") ) }}
23+
{{ echo_trans(name, {}, i18n_catalog|default("Admin"), 'html' ) }}
2424
</a>
2525
</li>
2626
{% if tabCredentials is not empty %}

0 commit comments

Comments
 (0)