MDL-60331 questions: prevent double escaping question categories.

This commit is contained in:
Luca Bösch
2021-04-28 17:16:31 +02:00
parent 5b315fa595
commit 003d17d98b
6 changed files with 51 additions and 18 deletions
+36 -11
View File
@@ -5529,9 +5529,11 @@ abstract class context extends stdClass implements IteratorAggregate {
* type of context, e.g. User, Course, Forum, etc.
* @param boolean $short whether to use the short name of the thing. Only applies
* to course contexts
* @param boolean $escape Whether the returned name of the thing is to be
* HTML escaped or not.
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
// must be implemented in all context levels
throw new coding_exception('can not get name of abstract context');
}
@@ -6236,9 +6238,10 @@ class context_system extends context {
*
* @param boolean $withprefix does not apply to system context
* @param boolean $short does not apply to system context
* @param boolean $escape does not apply to system context
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
return self::get_level_name();
}
@@ -6490,9 +6493,10 @@ class context_user extends context {
*
* @param boolean $withprefix whether to prefix the name of the context with User
* @param boolean $short does not apply to user context
* @param boolean $escape does not apply to user context
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
global $DB;
$name = '';
@@ -6673,9 +6677,10 @@ class context_coursecat extends context {
*
* @param boolean $withprefix whether to prefix the name of the context with Category
* @param boolean $short does not apply to course categories
* @param boolean $escape Whether the returned name of the context is to be HTML escaped or not.
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
global $DB;
$name = '';
@@ -6683,7 +6688,11 @@ class context_coursecat extends context {
if ($withprefix){
$name = get_string('category').': ';
}
$name .= format_string($category->name, true, array('context' => $this));
if (!$escape) {
$name .= format_string($category->name, true, array('context' => $this, 'escape' => false));
} else {
$name .= format_string($category->name, true, array('context' => $this));
}
}
return $name;
}
@@ -6904,9 +6913,10 @@ class context_course extends context {
*
* @param boolean $withprefix whether to prefix the name of the context with Course
* @param boolean $short whether to use the short name of the thing.
* @param bool $escape Whether the returned category name is to be HTML escaped or not.
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
global $DB;
$name = '';
@@ -6918,9 +6928,18 @@ class context_course extends context {
$name = get_string('course').': ';
}
if ($short){
$name .= format_string($course->shortname, true, array('context' => $this));
if (!$escape) {
$name .= format_string($course->shortname, true, array('context' => $this, 'escape' => false));
} else {
$name .= format_string($course->shortname, true, array('context' => $this));
}
} else {
$name .= format_string(get_course_display_name_for_list($course));
if (!$escape) {
$name .= format_string(get_course_display_name_for_list($course), true, array('context' => $this,
'escape' => false));
} else {
$name .= format_string(get_course_display_name_for_list($course), true, array('context' => $this));
}
}
}
}
@@ -7125,9 +7144,10 @@ class context_module extends context {
* @param boolean $withprefix whether to prefix the name of the context with the
* module name, e.g. Forum, Glossary, etc.
* @param boolean $short does not apply to module context
* @param boolean $escape Whether the returned name of the context is to be HTML escaped or not.
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
global $DB;
$name = '';
@@ -7139,7 +7159,11 @@ class context_module extends context {
if ($withprefix){
$name = get_string('modulename', $cm->modname).': ';
}
$name .= format_string($mod->name, true, array('context' => $this));
if (!$escape) {
$name .= format_string($mod->name, true, array('context' => $this, 'escape' => false));
} else {
$name .= format_string($mod->name, true, array('context' => $this));
}
}
}
return $name;
@@ -7400,9 +7424,10 @@ class context_block extends context {
*
* @param boolean $withprefix whether to prefix the name of the context with Block
* @param boolean $short does not apply to block context
* @param boolean $escape does not apply to block context
* @return string the human readable context name.
*/
public function get_context_name($withprefix = true, $short = false) {
public function get_context_name($withprefix = true, $short = false, $escape = true) {
global $DB, $CFG;
$name = '';
+1 -1
View File
@@ -60,7 +60,7 @@ class MoodleQuickForm_questioncategory extends MoodleQuickForm_selectgroups {
$this->_options = $options + $this->_options;
$this->loadArrayOptGroups(
question_category_options($this->_options['contexts'], $this->_options['top'], $this->_options['currentcat'],
false, $this->_options['nochildrenof']));
false, $this->_options['nochildrenof'], false));
}
}
+2
View File
@@ -1831,6 +1831,8 @@ class html_writer {
/**
* Generates a simple select form field
*
* Note this function does HTML escaping on the optgroup labels, but not on the choice labels.
*
* @param array $options associative array value=>label ex.:
* array(1=>'One, 2=>Two)
* it is also possible to specify optgroup as complex label array ex.:
+7 -5
View File
@@ -1222,7 +1222,7 @@ function add_indented_names($categories, $nochildrenof = -1) {
function question_category_select_menu($contexts, $top = false, $currentcat = 0,
$selected = "", $nochildrenof = -1) {
$categoriesarray = question_category_options($contexts, $top, $currentcat,
false, $nochildrenof);
false, $nochildrenof, false);
if ($selected) {
$choose = '';
} else {
@@ -1386,10 +1386,11 @@ function get_categories_for_contexts($contexts, $sortorder = 'parent, sortorder,
* @param int $currentcat
* @param bool $popupform
* @param int $nochildrenof
* @param boolean $escapecontextnames Whether the returned name of the thing is to be HTML escaped or not.
* @return array
*/
function question_category_options($contexts, $top = false, $currentcat = 0,
$popupform = false, $nochildrenof = -1) {
$popupform = false, $nochildrenof = -1, $escapecontextnames = true) {
global $CFG;
$pcontexts = array();
foreach ($contexts as $context) {
@@ -1410,7 +1411,7 @@ function question_category_options($contexts, $top = false, $currentcat = 0,
$categoriesarray = array();
foreach ($pcontexts as $contextid) {
$context = context::instance_by_id($contextid);
$contextstring = $context->get_context_name(true, true);
$contextstring = $context->get_context_name(true, true, $escapecontextnames);
foreach ($categories as $category) {
if ($category->contextid == $contextid) {
$cid = $category->id;
@@ -1468,14 +1469,15 @@ function question_add_context_in_key($categories) {
* Finds top categories in the given categories hierarchy and replace their name with a proper localised string.
*
* @param array $categories An array of question categories.
* @param boolean $escape Whether the returned name of the thing is to be HTML escaped or not.
* @return array The same question category list given to the function, with the top category names being translated.
*/
function question_fix_top_names($categories) {
function question_fix_top_names($categories, $escape = true) {
foreach ($categories as $id => $category) {
if ($category->parent == 0) {
$context = context::instance_by_id($category->contextid);
$categories[$id]->name = get_string('topfor', 'question', $context->get_context_name(false));
$categories[$id]->name = get_string('topfor', 'question', $context->get_context_name(false, false, $escape));
}
}
+4
View File
@@ -119,6 +119,10 @@ information provided here is intended especially for developers.
'methodname' property should not be specified in db/services.php file.
* The core_grades_create_gradecategory webservice has been deprecated in favour of core_grades_create_gradecategories, which is
functionally identical but allows for parallel gradecategory creations by supplying a data array to the webservice.
* The signature of the get_context_name() function in the abstract class context and all extending classes (such as context_course)
has been extended. The new parameter allows the to get the name without escaped characters.
* The signature of the question_category_options() has been extended. The new parameter allows the to get the categories name
in the returned array without escaped characters.
=== 3.10 ===
* PHPUnit has been upgraded to 8.5. That comes with a few changes:
@@ -131,7 +131,7 @@ class category_condition extends condition {
*/
protected function display_category_form($contexts, $pageurl, $current) {
echo \html_writer::start_div('choosecategory');
$catmenu = question_category_options($contexts, true, 0, true);
$catmenu = question_category_options($contexts, true, 0, true, -1, false);
echo \html_writer::label(get_string('selectacategory', 'question'), 'id_selectacategory', true, array("class" => "mr-1"));
echo \html_writer::select($catmenu, 'category', $current, array(),
array('class' => 'searchoptions custom-select', 'id' => 'id_selectacategory'));