Hi,
I'm looking to know when use htmlspecialschars() on PhoenixCart because I'm confused.
Searching inside the code, in admin/catalog.php (via actions) only is used in image on new_product.php, but if I look on catalog
I see that includes\modules\header_tags\ht_product_schema.php uses this function for $product->get(), name, model, gtin...
in includes\modules\navbar\templates\tpl_nb_shopping_cart.php uses in htmlspecialchars($product-oget('name'))
So what's the rule to use htmlspecialschars() on Phoenix?
Thanks in advance
When use htmlspecialschars() on PhoenixCart
- burt
- Core Team
- Posts: 4739
- Joined: Tue Oct 29, 2019 9:37 am
- Phoenix Version: v1.1.0.8
- : Buy Me A Beverage
- Has thanked: 279 times
- Been thanked: 467 times
Re: When use htmlspecialschars() on PhoenixCart
When adding user inputted stuff to source code, it helps security.
Don't know exact why navbar_shopping_cart would need it. The other one, yes.
Don't know exact why navbar_shopping_cart would need it. The other one, yes.
I am not here to build for you.
I am here to build with you. Let's help each other.
I am here to build with you. Let's help each other.
-
PiLLaO
- Contributor
- Posts: 131
- Joined: Thu Nov 05, 2020 9:28 pm
- Phoenix Version: v1.1.0.6
- Has thanked: 65 times
- Been thanked: 17 times
Re: When use htmlspecialschars() on PhoenixCart
I'm looking for products details.
The question is, I don't need to use htmlspecialchars() when get products details from database, is correct?
I think I can remove then from an addon.
I find this on core code:
also in admin/invoice.php
don't use htmlspecialchars(), I only find htmlspecialchars() for image like this
or in product_schema.php.
Regards
The question is, I don't need to use htmlspecialchars() when get products details from database, is correct?
I think I can remove then from an addon.
I find this on core code:
Code: Select all
while ($product = $products_query->fetch_assoc()) {
$product = new Product($product);
$options[] = [
'id' => $product->get('id'),
'text' => sprintf('%s (%s)', $product->get('name'), $product->format()),
];
}Code: Select all
foreach ($order->products as $product) {
echo '<tr>';
echo '<td>' . $product['qty'] . ' x ' . $product['name'];
if (!empty($product['attributes'])) {
foreach ($product['attributes'] as $attribute) {
echo '<br><small> - ' . $attribute['option'] . ': ' . $attribute['value'];
if ($attribute['price'] != '0') {
echo ' (' . $attribute['prefix'] . $currencies->format($attribute['price'] * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . ')';
}
echo '</small>';
}
}
echo '</td>';
echo '<td>' . $product['model'] . ' </td>';
echo '<td class="text-end">' . Tax::format($product['tax']) . '%</td>';
echo '<td class="text-end">' . $currencies->format($product['final_price'], true, $order->info['currency'], $order->info['currency_value']) . '</td>';
echo '<td class="text-end">' . $currencies->format(Tax::add($product['final_price'], $product['tax']), true, $order->info['currency'], $order->info['currency_value']) . '</td>';
echo '<td class="text-end">' . $currencies->format($product['final_price'] * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . '</strong></td>';
echo '<th class="text-end">' . $currencies->format(Tax::add($product['final_price'], $product['tax']) * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . '</th>';
echo '</tr>';
}
Code: Select all
new Image('images/' . $product->get('image'), [], htmlspecialchars($product->get('name')))
Regards
