mirror of
https://github.com/SuiteCRM/SuiteCRM.git
synced 2026-03-02 19:16:58 -05:00
Webforms strip the "<script>" tag in the last wizard step #4709
Labels
No labels
Area: API
Area: Campaigns
Area: Cases
Area: Clean Up
Area: Clean Up: Performance
Area: Dashlets
Area: Databases
Area: Developer Tools
Area: Elasticsearch
Area: Elasticsearch
Area: Emails
Area: Emails:Campaigns
Area: Emails:Cases
Area: Emails:Compose
Area: Emails:Config
Area: Emails:Templates
Area: Environment
Area: Installation
Area: Language
Area: Mobile
Area: Module
Area: PDFs
Area: PHP8
Area: Reports
Area: Studio
Area: Styling
Area: Upgrading
Area: Workflow
Area:Activity Stream
Area:Calls
Area:Import
Area:Projects
Area:Search
Area:Surveys
Area:Themes
Area:Users
Branch:Hotfix
Good First Issue
Hacktoberfest
Help Wanted
PR:Community Contribution
PR:Type:Enhancement
Priority:Critical
Priority:Important
Priority:Moderate
Severity: Major
Severity: Minor
Severity: Moderate
Status: Requires Code Review
Status: Requires Updates
Status: Stale
Status: Team Investigating
Status:Assessed
Status:Fix Proposed
Status:Needs Assessed
Status:Requires Automated Tests
Type: Bug
Type:Deprecated
Type:Discussion
Type:Duplicate
Type:Invalid
Type:Question
Type:Suggestion
Type:Suggestion
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/SuiteCRM-SuiteCRM#4709
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @SinergiaCRM on GitHub (Jan 26, 2022).
Tested in last version of SuiteCRM and https://demo.suiteondemand.com/
After creating a form, the javascript code is displayed in the HTML as normal text, this is due that the "
@Mac-Rae commented on GitHub (Feb 1, 2022):
Hi @SinergiaCRM,
There appears to be a simple enough workaround for these issues so I'd say marking as critical would not be required;
For those concerned inserting the following above and below the script section of code before submitting it to your website will fix it;
Can confirm however this is a bug in the latest verisions! 👍
@SuiteBot commented on GitHub (Dec 27, 2023):
This issue has been mentioned on SuiteCRM. There might be relevant details there:
https://community.suitecrm.com/t/problem-mit-angezeigtem-javascript-code-im-web-to-lead-formular/91359/6
@SuiteBot commented on GitHub (Dec 28, 2023):
This issue has been mentioned on SuiteCRM. There might be relevant details there:
https://community.suitecrm.com/t/issue-with-displayed-javascript-code-in-web-to-lead-form/91360/3
@chris001 commented on GitHub (Dec 28, 2023):
The offending line that strips the
<script>tags is likely this one:github.com/salesagility/SuiteCRM@54bc56c3bd/modules/Campaigns/WebToLeadFormSave.php (L88)Obviously it wants to strip the
<script>tags in order to safely display in the browser without injecting active javascript onto the page.A solution: generate 2 version: Non-cleaned, and Cleaned.