Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[6.x]: Html::decode() does not decode '

Open Beginner friendly
#19,828 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
php
Domain
backend

Research direction

Start with CraftCms\Cms\Support\Html::decode(), the method named in the issue, and inspect its existing tests. Verify that decoding and re-rendering an apostrophe in an HTML attribute does not leave a literal ' entity in the lightswitch label.

Written by the indexing model from the issue text.

Description

bug repo:cms
What happened?

A lightswitch field with an apostrophe:

{!! FormFields::lightswitchFieldHtml([
    'label' => 'Example Setting',
    'offLabel' => "Don't Save",
]) !!}

Renders the entity:

Don't Save Data

I haven't verified this but if AIs suggestion helps as a starting point:

  1. HTML5 attribute encoding: When the tag is first created, Yiisoft\Html\Html::encodeAttribute() encodes ' as ' (off-label="Don't Save").
  2. Missing ENT_HTML5 in Html::decode(): When Field modifies the tag to attach slot="input", it parses existing attributes and calls Html::decode(). Because Html::decode() uses PHP's default HTML 4.01 charset without ENT_HTML5, it ignores ' and leaves it undecoded.
  3. Double encoding: When the attributes are re-rendered, the & in ' is re-encoded to & (off-label="Don't Save").
  4. The browser parses ' into the literal string Don't Save, which the web component prints directly to the screen.

AI suggests a fix by adding ENT_HTML5 to CraftCms\Cms\Support\Html::decode():

 public static function decode(string $content): string
 {
-    return htmlspecialchars_decode($content, ENT_QUOTES);
+    return htmlspecialchars_decode($content, ENT_QUOTES | ENT_HTML5);
 }
Craft CMS version

6.0.0-alpha.19

PHP version

No response

Operating system and version

No response

Database type and version

No response

Image driver and version

No response

Installed plugins and versions
Dominant language
PHP
Stars
3.6k
Forks
705
Avg merge
15h 41m
Merged PRs (30d)
211

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from craftcms/cms

All issues in craftcms/cms

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.