Skip to content

Fix: do not strip special characters from labels - #1287

Open
AdamoLeKing wants to merge 3 commits into
pluginsGLPI:mainfrom
AdamoLeKing:fix/label-special-chars
Open

AdamoLeKing wants to merge 3 commits into
pluginsGLPI:mainfrom
AdamoLeKing:fix/label-special-chars

Conversation

@AdamoLeKing

Copy link
Copy Markdown

Description

Since commit 999e1c1, PluginFieldsToolbox::sanitizeLabel() is applied to every
label written in PluginFieldsLabelTranslation and to container labels.
It strips every character that is not a letter, digit, space, -, _ or .,
so a field labelled "N° d'inventaire / site" is displayed as "N dinventaire site".

Labels are plain data:

  • stored through parameterized queries,
  • escaped on output (htmlspecialchars, Twig autoescape),
  • injected into generated class files only through var_export(), which is safe
    for any string.

System names (table, column, class and file names) are still restricted by
sanitizeSystemName() / getSystemNameFromLabel(), so the security fix is preserved.

Changes

  • Stop calling sanitizeLabel() on labels in PluginFieldsLabelTranslation,
    PluginFieldsToolbox::prepareLabel(), PluginFieldsContainer and PluginFieldsDropdown
    (labels are only trimmed).
  • name and id sanitization is unchanged.

Note

Labels already saved since 999e1c1 remain truncated in
glpi_plugin_fields_labeltranslations and glpi_plugin_fields_containers.
Field labels can be restored from glpi_plugin_fields_fields.label; a migration
could be added if maintainers want it.

@stonebuzz stonebuzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Many fix about this, please add unit test
Bestr egards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants