-
Notifications
You must be signed in to change notification settings - Fork 9.4k
Fix appearance of HTML entities in the name of attribute groups when editing or after saving #33024
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: 2.4-develop
Are you sure you want to change the base?
Conversation
Hi @blmage. Thank you for your contribution
❗ Automated tests can be triggered manually with an appropriate comment:
You can find more information about the builds here ℹ️ Please run only needed test builds instead of all when developing. Please run all test builds before sending your PR for review. For more details, please, review the Magento Contributor Guide documentation. 🕙 You can find the schedule on the Magento Community Calendar page. 📞 The triage of Pull Requests happens in the queue order. If you want to speed up the delivery of your contribution, please join the Community Contributions Triage session to discuss the appropriate ticket. 🎥 You can find the recording of the previous Community Contributions Triage on the Magento Youtube Channel ✏️ Feel free to post questions/proposals/feedback related to the Community Contributions Triage process to the corresponding Slack Channel |
@magento run all tests |
The requested builds are added to the queue. You should be able to see them here within a few minutes. Please re-request them if they don't show in a reasonable amount of time. |
app/code/Magento/Catalog/view/adminhtml/templates/catalog/product/attribute/set/main.phtml
Show resolved
Hide resolved
@magento run Functional Tests B2B |
The requested builds are added to the queue. You should be able to see them here within a few minutes. Please re-request them if they don't show in a reasonable amount of time. |
Description (*)
This PR fixes the appearance of HTML entities in the names of attribute groups when editing them, or after saving the corresponding attribute set.
Related Pull Requests
Fixed Issues (if relevant)
Manual testing scenarios (*)
Questions or comments
The problem is located deep within the library code: the same
text
variable is used both when displaying and when editing the node labels, but the library does not take care of (un)escaping them, so there is always one case that is handled incorrectly (we either get a potential XSS, or unwanted HTML entities in the edit input).The PR ensures that the HTML entities contained in the group names are decoded (only) when the names are edited, or when the attribute set is saved.
Also, directly updating the
ext-tree.js
file was preferred over a monkey-patch, because:Contribution checklist (*)