diff options
author | Joas Schilling <coding@schilljs.com> | 2018-02-26 13:38:39 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2018-02-26 13:38:39 +0100 |
commit | 226e63695f37d54f673fe563ca183ea3cc9b8c7a (patch) | |
tree | 9336aec1c4a2b78686606da480d0d818c6869b57 /lib | |
parent | 695e32d0a66c6c5293291c3f31c5458fd5c248db (diff) | |
parent | a097ecded7e663d983571d272dfed07f890ba4f2 (diff) | |
download | nextcloud-server-226e63695f37d54f673fe563ca183ea3cc9b8c7a.tar.gz nextcloud-server-226e63695f37d54f673fe563ca183ea3cc9b8c7a.zip |
Merge pull request #8026 from nextcloud/feature/noid/allow-custom-html-in-html-emails
Allow custom HTML in HTML Emails
Diffstat (limited to 'lib')
-rw-r--r-- | lib/private/Mail/EMailTemplate.php | 28 | ||||
-rw-r--r-- | lib/private/Share20/Manager.php | 2 | ||||
-rw-r--r-- | lib/public/Mail/IEMailTemplate.php | 12 |
3 files changed, 24 insertions, 18 deletions
diff --git a/lib/private/Mail/EMailTemplate.php b/lib/private/Mail/EMailTemplate.php index 0535dabc13e..38205af366e 100644 --- a/lib/private/Mail/EMailTemplate.php +++ b/lib/private/Mail/EMailTemplate.php @@ -420,7 +420,7 @@ EOF; /** * Adds a paragraph to the body of the email * - * @param string $text + * @param string $text Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email * @param string|bool $plainText Text that is used in the plain text email * if empty the $text is used, if false none will be used */ @@ -430,11 +430,12 @@ EOF; } if ($plainText === '') { $plainText = $text; + $text = htmlspecialchars($text); } $this->ensureBodyIsOpened(); - $this->htmlBody .= vsprintf($this->bodyText, [htmlspecialchars($text)]); + $this->htmlBody .= vsprintf($this->bodyText, [$text]); if ($plainText !== false) { $this->plainBody .= $plainText . PHP_EOL . PHP_EOL; } @@ -443,8 +444,8 @@ EOF; /** * Adds a list item to the body of the email * - * @param string $text - * @param string $metaInfo + * @param string $text Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email + * @param string $metaInfo Note: When $plainMetaInfo falls back to this, HTML is automatically escaped in the HTML email * @param string $icon Absolute path, must be 16*16 pixels * @param string $plainText Text that is used in the plain text email * if empty the $text is used, if false none will be used @@ -457,14 +458,16 @@ EOF; if ($plainText === '') { $plainText = $text; + $text = htmlspecialchars($text); } if ($plainMetaInfo === '') { $plainMetaInfo = $metaInfo; + $metaInfo = htmlspecialchars($metaInfo); } - $htmlText = htmlspecialchars($text); + $htmlText = $text; if ($metaInfo) { - $htmlText = '<em style="color:#777;">' . htmlspecialchars($metaInfo) . '</em><br>' . $htmlText; + $htmlText = '<em style="color:#777;">' . $metaInfo . '</em><br>' . $htmlText; } if ($icon !== '') { $icon = '<img src="' . htmlspecialchars($icon) . '" alt="•">'; @@ -503,9 +506,9 @@ EOF; /** * Adds a button group of two buttons to the body of the email * - * @param string $textLeft Text of left button + * @param string $textLeft Text of left button; Note: When $plainTextLeft falls back to this, HTML is automatically escaped in the HTML email * @param string $urlLeft URL of left button - * @param string $textRight Text of right button + * @param string $textRight Text of right button; Note: When $plainTextRight falls back to this, HTML is automatically escaped in the HTML email * @param string $urlRight URL of right button * @param string $plainTextLeft Text of left button that is used in the plain text version - if unset the $textLeft is used * @param string $plainTextRight Text of right button that is used in the plain text version - if unset the $textRight is used @@ -521,10 +524,12 @@ EOF; } if ($plainTextLeft === '') { $plainTextLeft = $textLeft; + $textLeft = htmlspecialchars($textLeft); } if ($plainTextRight === '') { $plainTextRight = $textRight; + $textRight = htmlspecialchars($textRight); } $this->ensureBodyIsOpened(); @@ -533,7 +538,7 @@ EOF; $color = $this->themingDefaults->getColorPrimary(); $textColor = $this->themingDefaults->getTextColorPrimary(); - $this->htmlBody .= vsprintf($this->buttonGroup, [$color, $color, $urlLeft, $color, $textColor, $textColor, htmlspecialchars($textLeft), $urlRight, htmlspecialchars($textRight)]); + $this->htmlBody .= vsprintf($this->buttonGroup, [$color, $color, $urlLeft, $color, $textColor, $textColor, $textLeft, $urlRight, $textRight]); $this->plainBody .= $plainTextLeft . ': ' . $urlLeft . PHP_EOL; $this->plainBody .= $plainTextRight . ': ' . $urlRight . PHP_EOL . PHP_EOL; @@ -542,7 +547,7 @@ EOF; /** * Adds a button to the body of the email * - * @param string $text Text of button + * @param string $text Text of button; Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email * @param string $url URL of button * @param string $plainText Text of button in plain text version * if empty the $text is used, if false none will be used @@ -559,11 +564,12 @@ EOF; if ($plainText === '') { $plainText = $text; + $text = htmlspecialchars($text); } $color = $this->themingDefaults->getColorPrimary(); $textColor = $this->themingDefaults->getTextColorPrimary(); - $this->htmlBody .= vsprintf($this->button, [$color, $color, $url, $color, $textColor, $textColor, htmlspecialchars($text)]); + $this->htmlBody .= vsprintf($this->button, [$color, $color, $url, $color, $textColor, $textColor, $text]); if ($plainText !== false) { $this->plainBody .= $plainText . ': '; diff --git a/lib/private/Share20/Manager.php b/lib/private/Share20/Manager.php index 0ae96f29ded..cddd8c8d92b 100644 --- a/lib/private/Share20/Manager.php +++ b/lib/private/Share20/Manager.php @@ -735,7 +735,7 @@ class Manager implements IManager { $text = $l->t('%s shared »%s« with you.', [$initiatorDisplayName, $filename]); $emailTemplate->addBodyText( - $text . ' ' . $l->t('Click the button below to open it.'), + htmlspecialchars($text . ' ' . $l->t('Click the button below to open it.')), $text ); $emailTemplate->addBodyButton( diff --git a/lib/public/Mail/IEMailTemplate.php b/lib/public/Mail/IEMailTemplate.php index 3248665a7da..6d37c21ada1 100644 --- a/lib/public/Mail/IEMailTemplate.php +++ b/lib/public/Mail/IEMailTemplate.php @@ -85,7 +85,7 @@ interface IEMailTemplate { /** * Adds a paragraph to the body of the email * - * @param string $text + * @param string $text; Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email * @param string|bool $plainText Text that is used in the plain text email * if empty the $text is used, if false none will be used * @@ -96,8 +96,8 @@ interface IEMailTemplate { /** * Adds a list item to the body of the email * - * @param string $text - * @param string $metaInfo + * @param string $text; Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email + * @param string $metaInfo; Note: When $plainMetaInfo falls back to this, HTML is automatically escaped in the HTML email * @param string $icon Absolute path, must be 16*16 pixels * @param string $plainText Text that is used in the plain text email * if empty the $text is used, if false none will be used @@ -110,9 +110,9 @@ interface IEMailTemplate { /** * Adds a button group of two buttons to the body of the email * - * @param string $textLeft Text of left button + * @param string $textLeft Text of left button; Note: When $plainTextLeft falls back to this, HTML is automatically escaped in the HTML email * @param string $urlLeft URL of left button - * @param string $textRight Text of right button + * @param string $textRight Text of right button; Note: When $plainTextRight falls back to this, HTML is automatically escaped in the HTML email * @param string $urlRight URL of right button * @param string $plainTextLeft Text of left button that is used in the plain text version - if empty the $textLeft is used * @param string $plainTextRight Text of right button that is used in the plain text version - if empty the $textRight is used @@ -124,7 +124,7 @@ interface IEMailTemplate { /** * Adds a button to the body of the email * - * @param string $text Text of button + * @param string $text Text of button; Note: When $plainText falls back to this, HTML is automatically escaped in the HTML email * @param string $url URL of button * @param string $plainText Text of button in plain text version * if empty the $text is used, if false none will be used |