From 444d768694c5b8868ecf283dc34b226f063c8a79 Mon Sep 17 00:00:00 2001 From: Fomafix Date: Fri, 30 Dec 2016 16:01:03 +0100 Subject: [PATCH] Add ->text() to prevent double HTML escaping wfMessage() without ->text() makes an automatic HTML escaping. Html::element() makes also a HTML escaping of the content. This leads to a double escaping and raw HTML in shown on the rendered page. Change-Id: I68165492c828837f842e7885f557644ca1bb0a8c --- includes/specials/SpecialChangeCredentials.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/includes/specials/SpecialChangeCredentials.php b/includes/specials/SpecialChangeCredentials.php index ff70848e25..f22d5f3c33 100644 --- a/includes/specials/SpecialChangeCredentials.php +++ b/includes/specials/SpecialChangeCredentials.php @@ -135,9 +135,9 @@ class SpecialChangeCredentials extends AuthManagerSpecialPage { $form->addPreText( Html::openElement( 'dl' ) - . Html::element( 'dt', [], wfMessage( 'credentialsform-provider' ) ) + . Html::element( 'dt', [], wfMessage( 'credentialsform-provider' )->text() ) . Html::element( 'dd', [], $info['provider'] ) - . Html::element( 'dt', [], wfMessage( 'credentialsform-account' ) ) + . Html::element( 'dt', [], wfMessage( 'credentialsform-account' )->text() ) . Html::element( 'dd', [], $info['account'] ) . Html::closeElement( 'dl' ) ); -- 2.20.1