When use htmlspecialschars() on PhoenixCart

Open to all! Ask other shopowners for help.
PiLLaO
Contributor
Posts: 131
Joined: Thu Nov 05, 2020 9:28 pm
Phoenix Version: v1.1.0.6
Has thanked: 65 times
Been thanked: 17 times

When use htmlspecialschars() on PhoenixCart

Post by PiLLaO »

Hi,

I'm looking to know when use htmlspecialschars() on PhoenixCart because I'm confused.

Searching inside the code, in admin/catalog.php (via actions) only is used in image on new_product.php, but if I look on catalog

I see that includes\modules\header_tags\ht_product_schema.php uses this function for $product->get(), name, model, gtin...
in includes\modules\navbar\templates\tpl_nb_shopping_cart.php uses in htmlspecialchars($product-oget('name'))

So what's the rule to use htmlspecialschars() on Phoenix?
Thanks in advance



Join The Code Co-op to get access to your library in the Code Co-op Forum
User avatar
burt
Core Team
Posts: 4738
Joined: Tue Oct 29, 2019 9:37 am
Phoenix Version: v1.1.0.8
Has thanked: 279 times
Been thanked: 467 times

Re: When use htmlspecialschars() on PhoenixCart

Post by burt »

When adding user inputted stuff to source code, it helps security.
Don't know exact why navbar_shopping_cart would need it. The other one, yes.
I am not here to build for you.
I am here to build with you. Let's help each other.

PiLLaO
Contributor
Posts: 131
Joined: Thu Nov 05, 2020 9:28 pm
Phoenix Version: v1.1.0.6
Has thanked: 65 times
Been thanked: 17 times

Re: When use htmlspecialschars() on PhoenixCart

Post by PiLLaO »

I'm looking for products details.

The question is, I don't need to use htmlspecialchars() when get products details from database, is correct?

I think I can remove then from an addon.

I find this on core code:

Code: Select all

      while ($product = $products_query->fetch_assoc()) {
        $product = new Product($product);
        $options[] = [
          'id' => $product->get('id'),
          'text' => sprintf('%s (%s)', $product->get('name'), $product->format()),
        ];
      }
also in admin/invoice.php

Code: Select all

            foreach ($order->products as $product) {
              echo '<tr>';
                echo '<td>' . $product['qty'] . ' x ' . $product['name'];
                if (!empty($product['attributes'])) {
                  foreach ($product['attributes'] as $attribute) {
                    echo '<br><small> - ' . $attribute['option'] . ': ' . $attribute['value'];
                    if ($attribute['price'] != '0') {
                      echo ' (' . $attribute['prefix'] . $currencies->format($attribute['price'] * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . ')';
                    }
                    echo '</small>';
                  }
                }
                echo '</td>';
                echo '<td>' . $product['model'] . '&nbsp;</td>';
                echo '<td class="text-end">' . Tax::format($product['tax']) . '%</td>';
                echo '<td class="text-end">' . $currencies->format($product['final_price'], true, $order->info['currency'], $order->info['currency_value']) . '</td>';
                echo '<td class="text-end">' . $currencies->format(Tax::add($product['final_price'], $product['tax']), true, $order->info['currency'], $order->info['currency_value']) . '</td>';
                echo '<td class="text-end">' . $currencies->format($product['final_price'] * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . '</strong></td>';
                echo '<th class="text-end">' . $currencies->format(Tax::add($product['final_price'], $product['tax']) * $product['qty'], true, $order->info['currency'], $order->info['currency_value']) . '</th>';
              echo '</tr>';
            }

don't use htmlspecialchars(), I only find htmlspecialchars() for image like this

Code: Select all

new Image('images/' . $product->get('image'), [], htmlspecialchars($product->get('name')))
or in product_schema.php.

Regards



Join The Code Co-op to get access to your library in the Code Co-op Forum
Post Reply