Zen Cart Logo
Forums / Bug Reports / [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Locked

Views: 61,663

Results 1 to 20 of 225
This thread is locked. New replies are disabled.
25 Sep 2010, 9:10 PM
#1
hara avatar

hara

Zen Follower

Join Date:
Sep 2008
Posts:
397
Plugin Contributions:
0

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

NOTE: v1.3.9h has been released, which FIXES the issue, and makes the following workaround UNNECESSARY. The best solution is to upgrade.

THE (now obsolete and overly complicated) WORKAROUND IS POSTED HERE: http://www.zen-cart.com/forum/showthread.php?p=941839#post941839 (Remember: Upgrading is simpler and smarter!)

I try to edit on define_main_page.php but shown all html code on the site. My current version is 1.3.8a.

How to write correct code on this page?
How to have image shown on home page?

Thanks in advance.

30 Sep 2010, 11:36 AM
#2
p1lot avatar

p1lot

New Zenner

Join Date:
May 2009
Posts:
69
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Hello,

I updated to 139g and experienced a very weird error.

In the html pages editor I often use html tags.

The < and > get converted to « and &raquo though and mess all my pages up. Some for the preview of the product pages.

Really need help to make this look right again.

thanks in advance,
Peter

30 Sep 2010, 3:29 PM
#3
yosemirza avatar

yosemirza

New Zenner

Join Date:
Aug 2009
Posts:
25
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I have the same issue

30 Sep 2010, 4:36 PM
#4
petek avatar

petek

Zen Follower

Join Date:
Jan 2008
Location:
Chevreuse, France
Posts:
278
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I upgraded to 1.3.9g this morning. Now, when I amend the description of a programme in the text editor (I use HTML), the html tags show up in the preview window. I've obviously not validated the changes otherwise they'll probably show up in the store front. What could be causing this ?

Pete
zc 1.3.9h
www.gardenserre.fr

30 Sep 2010, 4:42 PM
#5
p1lot avatar

p1lot

New Zenner

Join Date:
May 2009
Posts:
69
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Well,

I use a lot of HTML tags in my define pages as well as in my product descriptions.

And all < and >'s turn into < or >.

I fixed it already for the define pages, not for the product previews though.

Here the fix for "admin/define_pages_editor.php":
I added line 77 -> http://pastie.org/1191676

30 Sep 2010, 6:19 PM
#6
nfm avatar

nfm

New Zenner

Join Date:
Jan 2008
Posts:
90
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I'm having the same issue. However I can confirm that even if you are seeing the HTML on the preview page it posts to the store just fine. It does need to be fixed though because I have to post things live just to see if they look right since the preview isn't showing it.

30 Sep 2010, 6:34 PM
#7
petek avatar

petek

Zen Follower

Join Date:
Jan 2008
Location:
Chevreuse, France
Posts:
278
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

NFM:

I'm having the same issue. However I can confirm that even if you are seeing the HTML on the preview page it posts to the store just fine. It does need to be fixed though because I have to post things live just to see if they look right since the preview isn't showing it.

You're right, that's a relief ! But this needs fixing asap.

Pete
zc 1.3.9h
www.gardenserre.fr

30 Sep 2010, 9:42 PM
#8
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,904
Plugin Contributions:
3

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Hi,

The define pages editor does look like it has fallen victim to code added to 139g to protect against a 'theoretical' xss exploit that some security scanners might pick up on.

There is a way of whitelisting entry boxes against the xss cleansing and this can be done by creating an override file in admin/includes/extra_configures

and that file should contain
NOTE: THE FOLLOWING CODE HAS BEEN SUPERCEDED BY THIS POST: http://www.zen-cart.com/forum/showthread.php?p=941839#post941839

<?php
$global_xss_whitelist = isset($global_xss_whitelist) ? $global_xss_whitelist : array();
$my_whitelist  = array('file_contents');
$global_xss_whitelist = array_merge($my_whitelist, $global_xss_whitelist);

note the fix above is for the define pages editor only, and wil not fix content that has been edited since upgrade.

The product names/descriptions should not be affected

Some contributions may be affected, and if so the entry boxes affected in those contributions may need whitelisting in a similar manner to the above, but array('file_contents'); will need to be changed to add the name attribute of the form entry box

30 Sep 2010, 9:44 PM
#9
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,904
Plugin Contributions:
3

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

petek:

I upgraded to 1.3.9g this morning. Now, when I amend the description of a programme in the text editor (I use HTML), the html tags show up in the preview window. I've obviously not validated the changes otherwise they'll probably show up in the store front. What could be causing this ?

Don't understand what you mean by the programme description, do you mean the product description ??

30 Sep 2010, 9:46 PM
#10
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,904
Plugin Contributions:
3

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

NFM:

I'm having the same issue. However I can confirm that even if you are seeing the HTML on the preview page it posts to the store just fine. It does need to be fixed though because I have to post things live just to see if they look right since the preview isn't showing it.

Are you talking about the define pages, or some other preview ???

30 Sep 2010, 10:30 PM
#11
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Define page are no longer printing html to the page but printing out the source code. I did copy changed files over into the zip file I have been using for 1.3.f. Someone please check to see if it's something I did or something in this new release.

The language file itself does not contain pure html. the brackets are not < or > but the < tags instead/

It's fine until you go to edit the page.

The full-time Zen Cart Guru. WizTech4ZC.com
New template for 2.0 viewable here: 2.0 Demo

30 Sep 2010, 10:52 PM
#12
p1lot avatar

p1lot

New Zenner

Join Date:
May 2009
Posts:
69
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

wilt:

Are you talking about the define pages, or some other preview ???

As NFM, I've got the same problem. Your whitelist fix works fine for define pages, but not for the preview of product pages (when adding or updating a product).

When I add/update a product it's really helpful to see the "real" version, not the HTML-clutter.

30 Sep 2010, 10:53 PM
#13
p1lot avatar

p1lot

New Zenner

Join Date:
May 2009
Posts:
69
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

delia:

Define page are no longer printing html to the page but printing out the source code. I did copy changed files over into the zip file I have been using for 1.3.f. Someone please check to see if it's something I did or something in this new release.

The language file itself does not contain pure html. the brackets are not < or > but the < tags instead/

It's fine until you go to edit the page.

http://www.zen-cart.com/forum/showpost.php?p=941208&postcount=8

Just create a file called xss_whitelist.php in "admin/includes/extra_configures" and paste that code above. Works fine for me.

30 Sep 2010, 11:06 PM
#14
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I got 8 sites I upgraded already today. Creating a whole 'nother file that will be obsolete soon is not a great option for me. The question is whether the permanent fix will be posted here so I can do it right.

I jumped on this release and have quite a few other sites to upgrade since there seemed to be so many security fixes in it. I'm now in limbo.

The full-time Zen Cart Guru. WizTech4ZC.com
New template for 2.0 viewable here: 2.0 Demo

30 Sep 2010, 11:11 PM
#15
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

And reading back thru this thread (I had started a new thread) I also need to say that this is affecting my sites on the pages themselves:

for example

http://soldierhollowclassic.com/shop/index.php?main_page=contact_us

The full-time Zen Cart Guru. WizTech4ZC.com
New template for 2.0 viewable here: 2.0 Demo

1 Oct 2010, 1:08 AM
#16
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

After adding the patch ... what happens if you just edit and save the:
/includes/languages/english/html_includes/your_template_dir/define_contact_us.php

in your Tools ... Define Page Editor ...

NOTE: you should be using template and overrides for these

Linda McGrath
If you have to think ... you haven't been zenned ...

**Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!**

Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
Officially PayPal-Certified! Just click here

Try our Zen Cart Recommended Services - Hosting, Payment and more ...
Signup for our Announcements Forums to stay up to date on important changes and updates!

1 Oct 2010, 3:18 AM
#17
justin2010 avatar

justin2010

New Zenner

Join Date:
May 2010
Posts:
52
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Hi, all,

My situation is a little bit different from yours.

When I made changed in the define_main_page.php by using the define pages editor in the admin panel, it was fine in the editor ( I was using "HTML body" option instead of the "plaint text" ) but it show HTML source code in the store front. It is the plaint HTML code, like <, and >, and they are not converted to < nor &gt like what p1lot mentioned in post #5.

The other thing is I copied the original define_main_page.php from the zen-cart classic theme to replace my custom override template, it still showed HTML code.

I noticed, whatever I put inside the define pages editor, everything will show up as plain text, even as simple as "Welcome to my store" then a "Enter" key, it will show to the front page "Welcome to my store </br>".

I agree with delia. I will wait until a permanent fix from zen-cart. Hopefully it will come out very, very, very soon.

A little suggestion: can I just upgrade other files but leave that particular file that cause this trouble behind? Of course this need to be confirm by zen-cart developpers.

1 Oct 2010, 4:19 AM
#18
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Did you create a file like:
/admin/includes/extra_configures/extra_white_list.php

and put into that file the code:
NOTE: THE FOLLOWING CODE HAS BEEN SUPERCEDED BY THIS POST: http://www.zen-cart.com/forum/showthread.php?p=941839#post941839

snip

and then try to edit the define_main_page.php once more and save it to see if this displays correctly now?

Linda McGrath
If you have to think ... you haven't been zenned ...

**Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!**

Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
Officially PayPal-Certified! Just click here

Try our Zen Cart Recommended Services - Hosting, Payment and more ...
Signup for our Announcements Forums to stay up to date on important changes and updates!

1 Oct 2010, 4:48 AM
#19
justin2010 avatar

justin2010

New Zenner

Join Date:
May 2010
Posts:
52
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I tried on a fresh installed zen-cart, and it WORKS!!!:clap:

1 Oct 2010, 8:36 AM
#20
neit avatar

neit

Zen Follower

Join Date:
Feb 2010
Posts:
140
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I have a little ajax calling in my own php file when certain options are selected on the main page.
This stop working after the upgrade and it does not display the second drop down option that the
ajax calls in. I checked the define_main_page in the editor and when I save it got the html rather than
just the text on the main page. i applied the fix post above using the using the $global_xss_whitelist instructions and it removed
the html and it went back to displaying the text, but it is not retrieving my php file using ajax as it did previously.