Escape messages ipb-sitewide and ipb-partial.
authorBrian Wolff <bawolff+wn@gmail.com>
Sun, 17 Feb 2019 12:49:03 +0000 (12:49 +0000)
committerBrian Wolff <bawolff+wn@gmail.com>
Sun, 17 Feb 2019 12:49:03 +0000 (12:49 +0000)
Radio button htmlform treats options as being raw html

Change-Id: Ia25ed5b88e937414ea7993a1cf29fe44ed8e22d4

includes/specials/SpecialBlock.php

index a6fd55e..59c14fc 100644 (file)
@@ -177,8 +177,8 @@ class SpecialBlock extends FormSpecialPage {
                                'type' => 'radio',
                                'cssclass' => 'mw-block-editing-restriction',
                                'options' => [
-                                       $this->msg( 'ipb-sitewide' )->text() => 'sitewide',
-                                       $this->msg( 'ipb-partial' )->text() => 'partial',
+                                       $this->msg( 'ipb-sitewide' )->escaped() => 'sitewide',
+                                       $this->msg( 'ipb-partial' )->escaped() => 'partial',
                                ],
                                'section' => 'actions',
                        ];