Commit 9b89fa9c authored by Drew Webber's avatar Drew Webber
Browse files

Issue #2990723 by poker10, tatarbj, DamienMcKenna: Security improvement for l() function

parent b807051f
Loading
Loading
Loading
Loading
+1 −0
Changes for includes/common.inc: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -2570,6 +2570,7 @@ function l($text, $path, array $options = array()) {
      $use_theme = FALSE;
    }
  }
  $path = drupal_strip_dangerous_protocols((string) $path);
  if ($use_theme) {
    return theme('link', array('text' => $text, 'path' => $path, 'options' => $options));
  }
+6 −0
Changes for modules/simpletest/tests/common.test: 6 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -91,6 +91,12 @@ class CommonURLUnitTest extends DrupalWebTestCase {
    $link = l($text, $path);
    $sanitized_path = check_url(url($path));
    $this->assertTrue(strpos($link, $sanitized_path) !== FALSE, format_string('XSS attack @path was filtered', array('@path' => $path)));

    // Verify that a dangerous protocol is sanitized.
    $text = $this->randomName();
    $path = "javascript:alert('XSS')";
    $link = l($text, $path, array('external' => TRUE));
    $this->assertTrue(strpos($link, 'javascript:') === FALSE, 'Dangerous protocol javascript: was sanitized.');
  }

  /*