The following is part of a larger snippet but this part is causing me some problems.
I’m passing a link as a url parameter which is pulled into the snippet via $_GET.
Example url: www.mysite.com/page?link=
http://www.google.com
<?php
$output = '';
$link = $_GET['link'];
if (isset($link)) {
$output .= 'Continue to ' . $link;
}
return $output;
Result: Continue to
http://www.google.com
The above worked exactly as I intended, but...
When I insert
$link inside an html link tag:
$output .= '<a href="' . $link . '">Continue to ' . $link . '</a>';
Result: <a href="page?link=http%3A%2F%2Fwww.google.com">Continue to page?link=http%3A%2F%2Fwww.google.com</a>
The google link is removed and replaced with a relative link for the current page, including parameters.
I’ve tested this outside of modx and the link is
not stripped, I get the expected output. So I’m guessing it’s a security feature built into modx.
Am I making a basic mistake here or is there a way around this?