[6.x]: Html::decode() does not decode '
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
Research direction
Start with CraftCms\Cms\Support\Html::decode(), the method named in the issue, and inspect its existing tests. Verify that decoding and re-rendering an apostrophe in an HTML attribute does not leave a literal ' entity in the lightswitch label.
Written by the indexing model from the issue text.
Description
What happened?
A lightswitch field with an apostrophe:
{!! FormFields::lightswitchFieldHtml([
'label' => 'Example Setting',
'offLabel' => "Don't Save",
]) !!}
Renders the entity:
Don't Save Data
I haven't verified this but if AIs suggestion helps as a starting point:
- HTML5 attribute encoding: When the tag is first created, Yiisoft\Html\Html::encodeAttribute() encodes ' as ' (off-label="Don't Save").
- Missing ENT_HTML5 in Html::decode(): When Field modifies the tag to attach slot="input", it parses existing attributes and calls Html::decode(). Because Html::decode() uses PHP's default HTML 4.01 charset without ENT_HTML5, it ignores ' and leaves it undecoded.
- Double encoding: When the attributes are re-rendered, the & in ' is re-encoded to & (off-label="Don't Save").
- The browser parses ' into the literal string Don't Save, which the web component prints directly to the screen.
AI suggests a fix by adding ENT_HTML5 to CraftCms\Cms\Support\Html::decode():
public static function decode(string $content): string
{
- return htmlspecialchars_decode($content, ENT_QUOTES);
+ return htmlspecialchars_decode($content, ENT_QUOTES | ENT_HTML5);
}
Craft CMS version
6.0.0-alpha.19
PHP version
No response
Operating system and version
No response
Database type and version
No response
Image driver and version
No response
Installed plugins and versions
- Dominant language
- PHP
- Stars
- 3.6k
- Forks
- 705
- Avg merge
- 15h 41m
- Merged PRs (30d)
- 211
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from craftcms/cms
-
bug repo:cms
Difficulty 4/5 3-5 days Newbie friendliness 50/100
craftcms/cms#19829 · 1 comment ·
Maintainers usually reply within 1 day
-
bug repo:cms
Difficulty 3/5 1-2 days Newbie friendliness 68/100
craftcms/cms#19809 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 5/5 Over a week Newbie friendliness 25/100
craftcms/cms#19761 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 55/100
craftcms/cms#19675 · 2 comments ·
Maintainers usually reply within 1 day
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 68/100
craftcms/cms#19214 · 4 comments ·
Maintainers usually reply within 1 day
Similar issues
-
Lead create/update: a product row without a "product_id" key passes LeadForm validation and fails in the database (500)Possibly taken @Arslan-TR claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
krayin/laravel-crm#2681 ·
Maintainers usually reply within 2 days
-
[CoreBundle] Migrations are silently skipped on MariaDB with DBAL 4 (AbstractMigration::isMySql())OpenPotential Bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Sylius/Sylius#19270 · 1 comment · 4 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
invoiceninja/invoiceninja#13320 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day