Quotation marks not escaped in name in group members block and when masquerading

Bug #1694874 reported by Kristina Hoeppner
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
Medium
Rebecca Blundell

Bug Description

When a user's name (first or last or display name) contains double quotation marks, they are not escaped and shown as " in the "Members" block on the group homepage.

It's not a problem on the "Members" page, but just in the "Members" block on the group homepage.

To replicate:

1. Set up a group and make sure that the group members block is displayed on the group homepage.
2. Add double quotation marks to your
a) first name
b) last name
c) display name (in a separate test)
3. Go to the group homepage and check your name.

Expected result: The double quotation marks are shown.
Actual result: Instead they are displayed as "

Tags: bite-sized
Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

Also, quotation marks are not properly escaped when the user with the quotation marks masquerades as another user. This is visible in the notification bar at the top of the screen for "Become ... again" and in the user profile sideblock "Become ... again".

summary: - Quotation marks not escaped in name in group members block
+ Quotation marks not escaped in name in group members block and when
+ masquerading
Robert Lyon (robertl-9)
Changed in mahara:
milestone: 17.10.0 → 18.04.0
Changed in mahara:
assignee: nobody → Rebecca Blundell (rjb-dev)
Changed in mahara:
status: Confirmed → In Progress
Revision history for this message
Mahara Bot (dev-mahara) wrote : A patch has been submitted for review

Patch for "master" branch: https://reviews.mahara.org/8407

Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/8407
Committed: https://git.mahara.org/mahara/mahara/commit/76017fb7f0d69936567535d959ad624ba5998e02
Submitter: Robert Lyon (<email address hidden>)
Branch: master

commit 76017fb7f0d69936567535d959ad624ba5998e02
Author: Rebecca Blundell <email address hidden>
Date: Fri Jan 5 11:22:10 2018 +1300

Bug 1694874: Changing html escaping

-Become parentuser when masquerading now displays unescaped quotes
-User name on groupmember thumbnail now displays unescaped quotes

behatnotneeded

Change-Id: Idca76c9e31c0a7794416cafc8e8d66f6315611be

Robert Lyon (robertl-9)
Changed in mahara:
status: In Progress → Fix Committed
Robert Lyon (robertl-9)
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.