Zen Cart Logo
Forums / Bug Reports / [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Locked

Views: 61,664

Results 21 to 40 of 225
This thread is locked. New replies are disabled.
1 Oct 2010, 12:21 PM
#21
petek avatar

petek

Zen Follower

Join Date:
Jan 2008
Location:
Chevreuse, France
Posts:
278
Plugin Contributions:
0

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I reinstalled the language paypal.php file from 1.3.9f and all is back in order.

Pete
zc 1.3.9h
www.gardenserre.fr

1 Oct 2010, 12:58 PM
#22
nfm avatar

nfm

New Zenner

Join Date:
Jan 2008
Posts:
90
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

wilt:

Are you talking about the define pages, or some other preview ???

I haven't used the Define Pages since the update yet. Honestly, I'm a little hesitant to do so. I'm referring to the Product Preview page that you get after you add a new product.

Will your whitelist fix that or should I just wait for something more permanent?

1 Oct 2010, 1:19 PM
#23
dutchy avatar

dutchy

Zen Follower

Join Date:
May 2010
Location:
London
Posts:
324
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Hello

I just downloaded and installed a clean copy of 1.3.9g.
Same problem of HTML tags showing on the product preview pages (admin side) and define_main_pages (store side)

I installed CKEditor by: Kuroi
same problmes outlined above

I then applied Wilts patch.
This fixed the problems of HTML tags appearing on define_main_pages (store side) when using both HTMLarea and CKEditor.

One thing that worried me is delia's comment of "Creating a whole 'nother file that will be obsolete soon is not a great option for me". Is the Wilt patch just a quick fix?
If so, i think i will wait for 1.3.9g1 or 1.3.9h before upgrading my live shop.

Because "Some contributions may be affected, and if so the entry boxes affected in those contributions may need whitelisting in a similar manner to the above, but array('file_contents'); will need to be changed to add the name attribute of the form entry box - wilt" goes over my head, and i have about 30+ add-ons installed.

1 Oct 2010, 1:53 PM
#24
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Folks, the PRODUCT PREVIEW page display issue is NOT a bug.
While you may dislike the way the preview shows, it is unfortunately necessary in order to protect YOU against XSS attacks on your admin area.
Clicking Save on the product-preview screen SAVES IT PROPERLY.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

1 Oct 2010, 2:06 PM
#25
dutchy avatar

dutchy

Zen Follower

Join Date:
May 2010
Location:
London
Posts:
324
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Mr Byte, is the Wilt fix a permanent fix for the define_main_pages bug and going to be added to 1.3.9g or 1.3.9h fileset, therefore upgrading to 1.3.9g now is OK.

Or should I wait a while for further news on this?

Thanks
Michael

1 Oct 2010, 2:06 PM
#26
delia avatar

delia

Totally Zenned

Join Date:
May 2006
Location:
Gardiner, Maine
Posts:
2,383
Plugin Contributions:
7

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Dr. Byte, please speak to the problem of the define pages not showing correctly on the client side. What I'm hearing so far is that the extra file has to be added for the define pages. Is this a permanent solution? A bug? Please clarify because this has made using the define pages impossible for the average cart owner.

The full-time Zen Cart Guru. WizTech4ZC.com
New template for 2.0 viewable here: 2.0 Demo

1 Oct 2010, 2:12 PM
#27
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

dutchy:

Mr Byte, is the Wilt fix a permanent fix for the define_main_pages bug
delia:

Dr. Byte, please speak to the problem of the define pages not showing correctly on the client side.
I think this is clear...
DrByte:

While you may dislike the way the preview shows, it is unfortunately necessary in order to protect YOU against XSS attacks on your admin area.
Clicking Save on the product-preview screen SAVES IT PROPERLY.

Zen-Venom Get Bitten

1 Oct 2010, 2:19 PM
#28
dutchy avatar

dutchy

Zen Follower

Join Date:
May 2010
Location:
London
Posts:
324
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Sorry Kobra. I don't mean to be rude, but if it were clear, two of use would not have felt the need to ask if this fix is permanent and we are good to go.

"yes/no this is/isn't a permanent fix for the define_main_pages " is clear

1 Oct 2010, 2:27 PM
#29
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Yes. Treat it as a "permanent" fix.

For now.

There are numerous other far more important fixes in 1.3.9g that warrant the upgrade. Don't hold it off just for this trivial issue. Use the fix supplied.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

1 Oct 2010, 2:36 PM
#30
dutchy avatar

dutchy

Zen Follower

Join Date:
May 2010
Location:
London
Posts:
324
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

brilliant, thanks for the top work!
I shall not delay in 1.3.9g upgrade.

1 Oct 2010, 2:42 PM
#31
simplycatt avatar

simplycatt

New Zenner

Join Date:
Oct 2010
Posts:
4
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Thank you guys! I added that extra cofig file per the instructions and working great! Just wanted to let you know you are appreciated! :clap:

1 Oct 2010, 2:57 PM
#32
petek avatar

petek

Zen Follower

Join Date:
Jan 2008
Location:
Chevreuse, France
Posts:
278
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

petek:

I reinstalled the language paypal.php file from 1.3.9f and all is back in order.

Why did I type paypal.php ? What I meant is that I reinstalled admin/includes/modules/product/preview_info.php.

Pete
zc 1.3.9h
www.gardenserre.fr

1 Oct 2010, 3:31 PM
#33
neit avatar

neit

Zen Follower

Join Date:
Feb 2010
Posts:
140
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Everything for me is now working fine.
Great thankyou

1 Oct 2010, 4:19 PM
#34
simplycatt avatar

simplycatt

New Zenner

Join Date:
Oct 2010
Posts:
4
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Hello,
Sorry guys, all fixed up on the front page showing html, yeehaw, but now my html on my banners are showing in the side boxes. No images ,just the code pops up on front end. What should I do to fix it.
Thanks!

1 Oct 2010, 5:00 PM
#35
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

NOTE: THE FOLLOWING CODE HAS BEEN SUPERCEDED BY THIS POST: http://www.zen-cart.com/forum/showthread.php?p=941839#post941839

Try using for the extra_white_list.php file:
/admin/includes/extra_configures/extra_white_list.php

and put into that file the code:

<?php
$global_xss_whitelist = isset($global_xss_whitelist) ? $global_xss_whitelist : array();
$my_whitelist  = array('file_contents', 'banners_html_text');
$global_xss_whitelist = array_merge($my_whitelist, $global_xss_whitelist); 

and then try to edit the define_main_page.php or Banner HTML once more and save it to see if this displays correctly now?

NOTE: the file
/admin/includes/extra_configures/extra_white_list.php

is a file that you create for this code ...

Linda McGrath
If you have to think ... you haven't been zenned ...

**Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!**

Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
Officially PayPal-Certified! Just click here

Try our Zen Cart Recommended Services - Hosting, Payment and more ...
Signup for our Announcements Forums to stay up to date on important changes and updates!

1 Oct 2010, 5:28 PM
#36
simplycatt avatar

simplycatt

New Zenner

Join Date:
Oct 2010
Posts:
4
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Not just yea but hell yea! Thanks! All good here. I saw I needed to edit something in the array line but I do not know code very well. But I do follow instructions well lol. Gimme something to copy and paste and tell me where to paste it and Im good. Thank you for your help.

1 Oct 2010, 6:14 PM
#37
azimpact avatar

azimpact

New Zenner

Join Date:
Oct 2010
Posts:
33
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I've applied the patch as outline but now my banners on the front page no longer interpate the HTML code:

It works for the other pages, but not the banner.

http://www.daisygirlstshirts.com/index.php?main_page=index

Any idea what to do here?

1 Oct 2010, 6:27 PM
#38
azimpact avatar

azimpact

New Zenner

Join Date:
Oct 2010
Posts:
33
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

It seems my only alternative is to load all the old files that were replaced for the upgrade since this newest fubard my site.

1 Oct 2010, 6:39 PM
#39
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

azimpact:

I've applied the patch as outline but now my banners on the front page no longer interpate the HTML code:

It works for the other pages, but not the banner.

http://www.daisygirlstshirts.com/index.php?main_page=index

Any idea what to do here?
Um ... the fix Ajeh posted above will handle banners.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

1 Oct 2010, 6:43 PM
#40
azimpact avatar

azimpact

New Zenner

Join Date:
Oct 2010
Posts:
33
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I applied the fix and it worked for everything except the front page banner.

If I use HTML text instead of the image, all that displays is the actually HTML, not the output of the HTML.