Commit 86485ccd authored by Rob Phillips's avatar Rob Phillips
Browse files

Issue #3324157 by robphillips: Replace tokens before passing through XSS filter.

parent 34d1dbc4
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -189,9 +189,9 @@ function entity_confirmation_form_op_submit(array &$form, FormStateInterface $fo
      \Drupal::theme()->alter('entity_confirmation', $value, $op, $entity);

      // Set customized confirmation message.
      \Drupal::messenger()->addStatus(Markup::create($token->replace(Xss::filterAdmin($value), [
      \Drupal::messenger()->addStatus(Markup::create(Xss::filterAdmin($token->replace($value, [
        $entity->getEntityTypeId() => $entity,
      ])));
      ]))));
    }
  }
}