]> git.mxchange.org Git - friendica.git/commitdiff
Escape user name in introduction fields help text
authorHypolite Petovan <hypolite@mrpetovan.com>
Mon, 16 Nov 2020 23:18:11 +0000 (18:18 -0500)
committerHypolite Petovan <hypolite@mrpetovan.com>
Mon, 16 Nov 2020 23:21:11 +0000 (18:21 -0500)
- HTML help text aren't escaped in the template

# Conflicts:
# src/Module/Notifications/Introductions.php

src/Module/Notifications/Introductions.php

index bd0445b07a3754c67d89769791fdd77ed2560624..2a8a6ef44a8bf827a47b1ea4ea6eb60ba9c330fc 100644 (file)
@@ -23,6 +23,7 @@ namespace Friendica\Module\Notifications;
 
 use Friendica\Content\ContactSelector;
 use Friendica\Content\Nav;
+use Friendica\Content\Text\BBCode;
 use Friendica\Core\Protocol;
 use Friendica\Core\Renderer;
 use Friendica\Database\DBA;
@@ -124,9 +125,11 @@ class Introductions extends BaseNotifications
                                                $knowyou = '';
                                        }
 
+                                       $convertedName = BBCode::convert($notification->getName());
+
                                        $helptext  = DI::l10n()->t('Shall your connection be bidirectional or not?');
-                                       $helptext2 = DI::l10n()->t('Accepting %s as a friend allows %s to subscribe to your posts, and you will also receive updates from them in your news feed.', $notification->getName(), $notification->getName());
-                                       $helptext3 = DI::l10n()->t('Accepting %s as a subscriber allows them to subscribe to your posts, but you will not receive updates from them in your news feed.', $notification->getName());
+                                       $helptext2 = DI::l10n()->t('Accepting %s as a friend allows %s to subscribe to your posts, and you will also receive updates from them in your news feed.', $convertedName, $convertedName);
+                                       $helptext3 = DI::l10n()->t('Accepting %s as a subscriber allows them to subscribe to your posts, but you will not receive updates from them in your news feed.', $convertedName);
                
                                        $friend = ['duplex', DI::l10n()->t('Friend'), '1', $helptext2, true];
                                        $follower = ['duplex', DI::l10n()->t('Subscriber'), '0', $helptext3, false];