Skip to content

Strip html from customer comment #761

@brosua

Description

@brosua

Bug Report

Current Behavior
Currently a customer can insert HTML like <a href="any adress">Link</a> into the comment textarea.
This link will be rendered inside the backend module.

Expected behavior/output
I would expect all html entities to be removed from the comment. I think there´s no use case a customer needs to add html.

Environment

  • TYPO3 version(s): 13.4
  • cart version: 11.7.2
  • Is your TYPO3 installation set up with Composer (Composer Mode): yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions