#description should escape by default

Created on 24 September 2015, almost 10 years ago
Updated 20 August 2025, 3 days ago

#description is only XSS admin filtered by default. This makes it akin to #markup, #prefix and #suffix - but it is not the same at all. Let's make it auto-escape like most other things.

πŸ› Bug report
Status

Needs work

Version

11.0 πŸ”₯

Component

render system

Created by

πŸ‡¬πŸ‡§United Kingdom alexpott πŸ‡ͺπŸ‡ΊπŸŒ

Live updates comments and jobs are added and updated live.
  • Needs issue summary update

    Issue summaries save everyone time if they are kept up-to-date. See Update issue summary task instructions.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡ΊπŸ‡ΈUnited States smustgrave

    This came up as a daily BSI target

    This definitely appears to be relevant, from checking a few of the ['#description'] instances in core.

    This will need an issue summary update but @alexpott would you say this also just needs a reroll?

Production build 0.71.5 2024