MDL-57596 forms: CLEANHTML in persistent forms
Add special handling for text fields with the CLEANHTML type. This should be used when students and teachers can edit the same field (you can't trust those students). Applies cleaning on submitted data, and on data stored in the DB before it is put back in an editing form.
This commit is contained in:
committed by
Dan Poltawski
parent
6e65554ea1
commit
ac40d8b589
@@ -223,9 +223,14 @@ abstract class persistent extends moodleform {
|
||||
$data = $this->get_persistent()->to_record();
|
||||
$class = static::$persistentclass;
|
||||
$properties = $class::get_formatted_properties();
|
||||
$allproperties = $class::properties_definition();
|
||||
|
||||
foreach ($data as $field => $value) {
|
||||
// Convert formatted properties.
|
||||
// Clean data if it is to be displayed in a form.
|
||||
if (isset($allproperties[$field]['type'])) {
|
||||
$data->$field = clean_param($data->$field, $allproperties[$field]['type']);
|
||||
}
|
||||
|
||||
if (isset($properties[$field])) {
|
||||
$data->$field = array(
|
||||
'text' => $data->$field,
|
||||
|
||||
Reference in New Issue
Block a user