From f996cc3209f0324e540049b05d56a4226ba0ca73 Mon Sep 17 00:00:00 2001 From: Antoine M Date: Wed, 14 May 2025 15:39:29 +0200 Subject: [PATCH] FIX enhance sanitization of chapter index titles and anchors by removing non-alphanumeric characters --- includes/utilities.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/includes/utilities.php b/includes/utilities.php index 5867914..49e090d 100644 --- a/includes/utilities.php +++ b/includes/utilities.php @@ -196,8 +196,8 @@ function build_page_chapter_index($blocks) if ($block['blockName'] == 'homegrade-content-blocks/content-heading' && isset($block['attrs']['title']) && isset($block['attrs']['headingLevel']) && $block['attrs']['headingLevel'] == "h2") { array_push($chapterBlockIndex, [ 'block-type' => $block['blockName'], - 'anchor' => "#" . strip_tags($block['attrs']['idName']), - 'title' => strip_tags($block['attrs']['title']), + 'anchor' => "#" . preg_replace('/[^a-zA-Z0-9]/', '', strip_tags($block['attrs']['idName'])), // remove html tags all non-alphanumeric characters + 'title' => preg_replace('/[^a-zA-Z0-9\s]/', '', strip_tags($block['attrs']['title'])), // remove html tags all non-alphanumeric characters ]); } if ($block['blockName'] == 'homegrade-content-blocks/chapitrage-thematique') {