Zen Cart Logo
Forums / Bug Reports / [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Locked

Views: 61,664

Results 101 to 120 of 225
This thread is locked. New replies are disabled.
8 Oct 2010, 2:50 AM
#101
looper avatar

looper

New Zenner

Join Date:
Aug 2006
Posts:
52
Plugin Contributions:
0

[Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

DrByte,
I understand that. I simply was stating that on loading newest vers. of xamp, there was problem in where the php.ini files was located. And that maybe the (my) problem with the HTML situation could be related to xampp. IDK, my bad if i am reaching. I am just trying to work the editor problem. Is there a problem? I keep searching for the problem on my end.

Thanks!!

MBP loaded
Zen Cart 1.5.6
XAMPP 7.3.1 Includes: Apache 2.4.37, MariaDB 10.1.37, PHP 7.3.1, phpMyAdmin 4.8.4,

8 Oct 2010, 2:59 AM
#102
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Personally I think using ANY upload tool in an HTML editor is a BAD thing. It leaves you open to security problems, and is really just the wrong way to put content on your site.
Thus I have no interest in even trying to figure out what might be causing you troubles with it.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

8 Oct 2010, 3:20 AM
#103
looper avatar

looper

New Zenner

Join Date:
Aug 2006
Posts:
52
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

DrByte,

Ok. I understand. I am not trying to upload anything. I am simply trying to add images to the define_page_editor, etc. on my test server. It use to work, now it does not. that's all

I am just a newbe, a nobody, so if my pm pissed you off, I apologize, which i thought i already did. I was a little slow in forum etiquette. Thanks for all your post which I try to learn by.

regards,

MBP loaded
Zen Cart 1.5.6
XAMPP 7.3.1 Includes: Apache 2.4.37, MariaDB 10.1.37, PHP 7.3.1, phpMyAdmin 4.8.4,

8 Oct 2010, 3:23 AM
#104
countrycharm avatar

countrycharm

Totally Zenned

Join Date:
Jul 2007
Posts:
2,179
Plugin Contributions:
2

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Ajeh:

I don't know off the top of my head I do not use that Best Seller scrolling Add On ...
Thanks for your help. I'm not going to worry about it to much. I can away switch the bread crumbs off. I really don't need them any way. Thanks again

Is your site Upgraded to the current version 1.5.4 Yet?
zencart-upgrades-website-installation

8 Oct 2010, 4:08 AM
#105
darkangel avatar

darkangel

Totally Zenned

Join Date:
Oct 2007
Location:
Emporia, Kansas
Posts:
1,729
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

so far so good, i still need to install this file into another site i did the update at but it has worked in my own too...had html showing instead of what the define page was supposed to be. It showed the html on the main page NOT just in the admin editing place...as well as the product description pages...when done they would show html not the regular people talk...lol

happy it was not me messing up the update.:clap:

8 Oct 2010, 4:40 AM
#106
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Looper:

DrByte,

Ok. I understand. I am not trying to upload anything. I am simply trying to add images to the define_page_editor, etc. on my test server. It use to work, now it does not. that's all

I am just a newbe, a nobody, so if my pm pissed you off, I apologize, which i thought i already did. I was a little slow in forum etiquette. Thanks for all your post which I try to learn by.

regards,Not pissed off. Just stating a point of view. Sorry - I could have worded it differently. Apologies.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

8 Oct 2010, 5:08 AM
#107
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Looper:

DrByte,

Ok. I understand. I am not trying to upload anything. I am simply trying to add images to the define_page_editor, etc. on my test server. It use to work, now it does not. that's all
Personal opinions aside, I just downloaded the FCKeditor addon from the Free Addons area and installed it on my clean v1.3.9g site (with the whitelisting patch discussed in this thread). I then opened the Define Pages Editor, selected FCKeditor, and then define_main_page.php
I clicked in a spot where I wanted to insert an image, and then clicked the Image button in the button bar. I then entered the path to an image on the server: /store/images/free.gif ... and it immediately showed me that image and when I saved it the image shows just fine on the storefront.

So, unless the problem is related to you not correctly applying the whitelist update discussed at length in this thread, then it's something else you've got busted on your site.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

8 Oct 2010, 7:55 AM
#108
neit avatar

neit

Zen Follower

Join Date:
Feb 2010
Posts:
140
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Is there a list of variables that someone could posted that we could potentialy add to the whitelist to reduce the number of people asking how to add certain variables.
This would allow people to add and remove as needed and have all the information easy to find, also how would you do this with easy pages.

An example:
file_contents : ( description of what it affects)
banners_html_text: ( description of what it affects)

8 Oct 2010, 2:14 PM
#109
looper avatar

looper

New Zenner

Join Date:
Aug 2006
Posts:
52
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

DrByte,

Thanks. Actually that helps me, I applied the whitelist patch and corrected the showing html tags, etc. so it has to be something i am doing wrong. Somewhere I saw and learned to use the FCKeditor, browse to image folder, and click the upload to server (meaning my local server). Having said that, I'll go back and make sure I know how to use the editors. That could be a bigger problem. LOL

Thanks for all,

Looper

MBP loaded
Zen Cart 1.5.6
XAMPP 7.3.1 Includes: Apache 2.4.37, MariaDB 10.1.37, PHP 7.3.1, phpMyAdmin 4.8.4,

8 Oct 2010, 7:15 PM
#110
celtic avatar

celtic

Zen Follower

Join Date:
Feb 2010
Posts:
154
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

neit:

Is there a list of variables that someone could posted that we could potentialy add to the whitelist to reduce the number of people asking how to add certain variables.
This would allow people to add and remove as needed and have all the information easy to find, also how would you do this with easy pages.

An example:
file_contents : ( description of what it affects)
banners_html_text: ( description of what it affects)

Neit, I already asked for this, but it doesn't look like it's going to happen :(

Admittedly I've only been a ZC user for about 8 months now, but it's the first time I've seen a balls-up in an upgrade. The devs normally do an awesome job. Maybe they need some more coffee bought for them :wink:

8 Oct 2010, 9:01 PM
#111
poorfarm avatar

poorfarm

New Zenner

Join Date:
Jul 2010
Posts:
5
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Ajeh:

Try using for the extra_white_list.php file:
/admin/includes/extra_configures/extra_white_list.php

and put into that file the code:

<?php $global_xss_whitelist = isset($global_xss_whitelist) ? $global_xss_whitelist : array(); $my_whitelist = array('file_contents', 'banners_html_text', 'pages_title', 'message_html'); $global_xss_whitelist = array_merge($my_whitelist, $global_xss_whitelist); ``` > > and then try to edit the **Define Page** or **Banner HTML** or **EZPage Title** or **Send Email** once more and save it to see if this displays correctly ... > > NOTE: the file > /admin/includes/extra_configures/extra_white_list.php > > is a file that you create for this code ... Please, please help me to understand...Stop talking greek, please.. Now if I take this right... The reason my defines pages are talking html crap all over it, has to do with some coding problem that got messed up in this 1.39g upgrade. So if I want to fix the problem until someone figures we should have a 1.39h upgrade, then I need to what? Make a folder? Then insert this code into the folder? Then upload this folder to my .... admin/includes/extra_configures/....??????? And give it the name:::: extra_white_list.php ????? Just pretend I have a box of rocks for a brain, so I need more detail please. And why doesn't someone just create this file and fix the problem? Okay, I am a box of rocks....
8 Oct 2010, 9:18 PM
#112
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

The current release v1.3.9g was just released with the added Protection and, unfortunately, is too good ... so there is the need for the "white list" at this time ...

This will all be addressed in the next release ...

It takes two seconds to open a blank file and save it as:
/admin/includes/extra_configures/extra_white_list.php

You already have the directory:
/admin/includes/extra_configures/

You want to make a file called:
extra_white_list.php

and load it to the directory:
/admin/includes/extra_configures/

and in that file copy and paste the code posted in thread #52 ...

What this code is doing is excluding certain parts of the code from the extra protection that has been added in v1.3.9g from being applied to certain areas of the Admin so that when you edit the data and enter the HTML code it is not getting this extra protection as it also is protecting you against HTML code that you need to enter in some areas of the Admin ...

Linda McGrath
If you have to think ... you haven't been zenned ...

**Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!**

Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
Officially PayPal-Certified! Just click here

Try our Zen Cart Recommended Services - Hosting, Payment and more ...
Signup for our Announcements Forums to stay up to date on important changes and updates!

8 Oct 2010, 10:53 PM
#113
poorfarm avatar

poorfarm

New Zenner

Join Date:
Jul 2010
Posts:
5
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Ajeh:

The current release v1.3.9g was just released with the added Protection and, unfortunately, is too good ... so there is the need for the "white list" at this time ...

This will all be addressed in the next release ...

It takes two seconds to open a blank file and save it as:
/admin/includes/extra_configures/extra_white_list.php

You already have the directory:
/admin/includes/extra_configures/

You want to make a file called:
extra_white_list.php

and load it to the directory:
/admin/includes/extra_configures/

and in that file copy and paste the code posted in thread #52 ...

What this code is doing is excluding certain parts of the code from the extra protection that has been added in v1.3.9g from being applied to certain areas of the Admin so that when you edit the data and enter the HTML code it is not getting this extra protection as it also is protecting you against HTML code that you need to enter in some areas of the Admin ...

I thank you very kindly for your straight forward instructions..
This did the trick, so I shall apply it to my second store also..

8 Oct 2010, 10:59 PM
#114
frilansreklam avatar

frilansreklam

New Zenner

Join Date:
Sep 2008
Location:
Sweden
Posts:
99
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

I tried to find info about install sql patches.

for me it change " to " sp the array was not working.

Swedish Zen Cart Support page http://www.zencart.nu

9 Oct 2010, 3:33 AM
#115
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Could you give an example of what you are having a problem with? :unsure:

Linda McGrath
If you have to think ... you haven't been zenned ...

**Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!**

Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
Officially PayPal-Certified! Just click here

Try our Zen Cart Recommended Services - Hosting, Payment and more ...
Signup for our Announcements Forums to stay up to date on important changes and updates!

9 Oct 2010, 5:02 AM
#116
jasong42122 avatar

jasong42122

New Zenner

Join Date:
Oct 2010
Posts:
1
Plugin Contributions:
0

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Did anyone not try the new version before making it available to the public because I have 2 broken websites that I will gladly let you practice on next time? Also why did you change the name of the admin folder?

I assume your going to say for security reasons BUT don't you think if a person is smart enough to hack a website they probably have downloaded zen cart to figure out how to hack it. Which would mean they would already know the name of the "secret admin folder" any way.
A month from now their will probably be a big yellow warning saying change your admin name to something other than zc_admin.

It just makes me mad that every other week their is a so called "critical update" that needs to be done and if it's not done their is all this garbage in my admin that won't go away, telling me how I need this important update, and then we do the update and it breaks our site.

Then I read one of the admin talking about not wanting a billion patches, but it's sure ok for us to have a billion updates every week. If it wasn't such a pain to do the updates that would probably help too.

9 Oct 2010, 5:07 AM
#117
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

Installed the Rewards Points mod today, first on my local store and then on the live site. This mod requires the installation of the included new.sql patch which adds extra boxes to Admin > Configuration.

Part of this sql is shown here:

.....

REPLACE INTO configuration
(configuration_id ,configuration_title ,configuration_key ,configuration_value ,configuration_description ,configuration_group_id ,sort_order ,last_modified ,date_added ,use_function ,set_function)
VALUES (NULL , 'Reward Point Status Track', 'REWARD_POINTS_STATUS_TRACK', '', '<b>Simple mode:</b> All new reward points are set to Pending and are changed to Earned when the Order Status changes. If the Order Status is then changed back to Pending then the reward points are transferred back from Earned.<br /><br /><b>Advanced mode:</b> Set the order status ....etc etc

The highlighted html tags are all showing just as in the quote above, no breaks are inserted into the text and no bold items show up.

Manually fixed this on my local site by editing relevant DB entries. In the DB the brackets were showing as < or >

The extra_white_list.php file is installed, it fixed the EZ Pages issue as expected but has not addressed this issue.

I know this is only of a 'cosmetic' nature and does not affect the operation of the store but is worth noting for the next upgrade.

NOTE: We are sorry that Frank is no longer with us.
We are grateful for all his contributions to the Zen Cart community.

9 Oct 2010, 5:20 AM
#118
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

jasong42122:

... but it's sure ok for us to have a billion updates every week.
You must be referring to some other software. I've never seen Zen Cart release a billion updates. Ever.
Come to think of it we don't even have that many lines of code in Zen Cart yet.
But, thanks for cluttering our forum with your rant. I hope you feel better after you got that off your chest.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

9 Oct 2010, 5:20 AM
#119
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

frank, it's noted.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

9 Oct 2010, 5:23 AM
#120
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: [Done v1.3.9h] HTML tags show after upgrade to 1.3.9g

DrByte:

frank, it's noted.

Thanks DrByte

NOTE: We are sorry that Frank is no longer with us.
We are grateful for all his contributions to the Zen Cart community.