Skip to content

Commit

Permalink
Merge branch 'fix-xss-56' into release-xss-56
Browse files Browse the repository at this point in the history
  • Loading branch information
dennisameling committed Jan 14, 2021
2 parents d230d91 + e3f3f2c commit 20c5dc3
Show file tree
Hide file tree
Showing 7 changed files with 11 additions and 7 deletions.
2 changes: 1 addition & 1 deletion app/bundles/ApiBundle/Form/Type/ClientType.php
Expand Up @@ -73,7 +73,7 @@ public function __construct(
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber([]));
$builder->addEventSubscriber(new FormExitSubscriber('api.client', $options));

if (!$options['data']->getId()) {
Expand Down
2 changes: 1 addition & 1 deletion app/bundles/CategoryBundle/Form/Type/CategoryType.php
Expand Up @@ -37,7 +37,7 @@ public function __construct(Session $session)

public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber([]));
$builder->addEventSubscriber(new FormExitSubscriber('category.category', $options));

if (!$options['data']->getId()) {
Expand Down
6 changes: 5 additions & 1 deletion app/bundles/LeadBundle/Form/Type/CompanyType.php
Expand Up @@ -13,6 +13,7 @@

use Doctrine\ORM\EntityManager;
use Mautic\CoreBundle\Form\DataTransformer\IdToEntityModelTransformer;
use Mautic\CoreBundle\Form\EventListener\CleanFormSubscriber;
use Mautic\CoreBundle\Form\Type\FormButtonsType;
use Mautic\LeadBundle\Entity\Company;
use Mautic\UserBundle\Entity\User;
Expand Down Expand Up @@ -56,7 +57,8 @@ public function __construct(EntityManager $entityManager, RouterInterface $route
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$this->getFormFields($builder, $options, 'company');
$cleaningRules = $this->getFormFields($builder, $options, 'company');
$cleaningRules['companyemail'] = 'email';

$transformer = new IdToEntityModelTransformer($this->em, User::class);

Expand Down Expand Up @@ -138,6 +140,8 @@ public function buildForm(FormBuilderInterface $builder, array $options)
],
]
);

$builder->addEventSubscriber(new CleanFormSubscriber($cleaningRules));
}

/**
Expand Down
Expand Up @@ -27,7 +27,7 @@ class PasswordResetConfirmType extends AbstractType
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber([]));

$builder->add(
'identifier',
Expand Down
2 changes: 1 addition & 1 deletion app/bundles/UserBundle/Form/Type/PasswordResetType.php
Expand Up @@ -25,7 +25,7 @@ class PasswordResetType extends AbstractType
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber([]));

$builder->add(
'identifier',
Expand Down
2 changes: 1 addition & 1 deletion app/bundles/UserBundle/Form/Type/UserType.php
Expand Up @@ -65,7 +65,7 @@ public function __construct(
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber(['signature' => 'html', 'email' => 'email']));
$builder->addEventSubscriber(new FormExitSubscriber('user.user', $options));

$builder->add(
Expand Down
2 changes: 1 addition & 1 deletion plugins/MauticSocialBundle/Form/Type/MonitoringType.php
Expand Up @@ -40,7 +40,7 @@ public function __construct(MonitoringModel $monitoringModel)
*/
public function buildForm(FormBuilderInterface $builder, array $options)
{
$builder->addEventSubscriber(new CleanFormSubscriber());
$builder->addEventSubscriber(new CleanFormSubscriber(['description' => 'html']));

$builder->add('title', TextType::class, [
'label' => 'mautic.core.name',
Expand Down

0 comments on commit 20c5dc3

Please sign in to comment.