frm
Well-known member
- Affected version
- 2.1.2
It took me a while (a while too long) to realize that I had
If I add certain HTML to descriptions, such as
I'm pretty sure that this is "as designed" so that people can notate things with bold, italics, etc., but, shouldn't HTML be escaped (or converted to
<title>
in a custom field description on an addon that broke the template; however, it behaves the exact way XF does with custom field descriptions too.If I add certain HTML to descriptions, such as
<title>
as it was somewhat "necessary" to have as a description in the addon as a note to self, the template would fail to load, as it does in custom thread fields too. (I probably would've noticed this much much sooner had the HTML been <b>
instead).I'm pretty sure that this is "as designed" so that people can notate things with bold, italics, etc., but, shouldn't HTML be escaped (or converted to
<
and >
rather) and possibly BB Code used for that instead? Just my opinion...