I’ve posted a task on Flyspray for this and I’m posting it here because I found
nothing anywhere about this issue.
The file ditto.class.inc.php features this on line 962:
962: return str_replace("&","&",$url);
This line of code should
not be called if XHTML URLs is set to TRUE in the System Config. This is because makeURL already does this on line 961:
961: $url = $modx->makeURL(trim($cID), ’’, $queryString);
That’s how URL ampersands get escaped
twice resulting in this effect:
&
What effect does this have? Completely busted URLs via Ditto/Reflect.
The solution would be to perform
no entity escaping on URLs outside makeURL.
My current hack is to comment line 962 out and replace it with this:
return $url;