- π³πΏNew Zealand quietone
There has been no activity here for in the 6 years this issue has been opened. And, of course, things get fixed in the meantime.
Is there anything in the issue summary that is still relevant and needs work?
I asked about this in #bugsmash. lendude pointed out that t($user_input) should never happen. So perhaps the whole premise here is outdated?
Since we need more information to move forward with this issue, I am setting the status at Postponed (maintainer needs more info). If we don't receive additional information to help with the issue, it may be closed after three months.
Thanks!
- Status changed to Active
almost 2 years ago 7:32am 16 March 2023 - π¨πSwitzerland berdir Switzerland
As mentioned in slack, I fully agree it _should_ not happen but it does frequently enough in contrib and custom code. http://grep.xnddx.ru/search?text=-%3Et%28%24&filename= has 30 pages of results. Not all of that is user input, but a fair share is going to be. One common pattern is translating widget and formatter configuration like that as core still lacks a UI to do that.
I tried reporting this once as a security issue as well and it was decided to make it public.
Agreed it's a task though and not a bug.
- π³πΏNew Zealand quietone
@Berdir, thank you!
So this needs an issue summary update to identify the next steps here.