Koha/Koha/Template/Plugin/To.pm
Jonathan Druart bdf0d85c1d Bug 20891: Escape html then JSON
To my understanding we need to escape first html chars then to JSON.

If this patch works we will need to rethink the 'To' TT plugin.
It was originally designed to have several escape methods, but with
these changes it will not make sense to name it 'To' if used only to
escape JSON

IIRC we should keep the 2 different ways to use it:
 * [% To.json( string ) %]
 * [% string | $To %]
otherwise it will be hard to use it when called in argument of
patron-title.inc (`git grep To.json`)

Signed-off-by: Liz Rea <wizzyrea@gmail.com>

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
2019-04-25 10:27:27 +00:00

44 lines
1.3 KiB
Perl

package Koha::Template::Plugin::To;
# This file is part of Koha.
#
# Copyright BibLibre 2014
#
# Koha is free software; you can redistribute it and/or modify it under the
# terms of the GNU General Public License as published by the Free Software
# Foundation; either version 3 of the License, or (at your option) any later
# version.
#
# Koha is distributed in the hope that it will be useful, but WITHOUT ANY
# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
# A PARTICULAR PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License along
# with Koha; if not, write to the Free Software Foundation, Inc.,
# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
use Modern::Perl;
use Template::Plugin::Filter;
use base qw( Template::Plugin::Filter );
use JSON qw( to_json );
our $DYNAMIC = 1;
sub json {
my ( $self, $value ) = @_;
my $json = JSON->new->allow_nonref(1);
$json = $json->encode($value);
$json =~ s/^"|"$//g; # Remove quotes around the strings
$json =~ s/\\r/\\\\r/g; # Convert newlines to escaped newline characters
$json =~ s/\\n/\\\\n/g;
return $json;
}
sub filter {
my ( $self, $value ) = @_;
return $self->json($value);
}
1;