[BUGFIX] Accept JS spam protected email addresses
When TYPO3 is configured to spam protect email addresses using an offset, then the HTML sanitizer introduced in #94375 will remove the generated JavaScript in the href link attribute. This change makes the HTML sanitizer aware of the `javascript:linkTo_UnCryptMailto` pattern for href attribute. Resolves: #94776 Releases: master, 11.3, 10.4, 9.5 Change-Id: If5f4ab22a686274401390a66b580a24e6d5a8f0c Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/70411 Tested-by:Oliver Hader <oliver.hader@typo3.org> Tested-by:
core-ci <typo3@b13.com> Tested-by:
Oliver Bartsch <bo@cedev.de> Tested-by:
Georg Ringer <georg.ringer@gmail.com> Reviewed-by:
Oliver Hader <oliver.hader@typo3.org> Reviewed-by:
Oliver Bartsch <bo@cedev.de> Reviewed-by:
Georg Ringer <georg.ringer@gmail.com>
Showing
- typo3/sysext/core/Classes/Html/DefaultSanitizerBuilder.php 4 additions, 1 deletiontypo3/sysext/core/Classes/Html/DefaultSanitizerBuilder.php
- typo3/sysext/core/Tests/Functional/Html/DefaultSanitizerBuilderTest.php 12 additions, 0 deletions...ore/Tests/Functional/Html/DefaultSanitizerBuilderTest.php
Please register or sign in to comment