We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26982
    • 75 Posts
    The default install of MODx calls eform with a template field type of "textarea" for the message contents.
    This does not seem to be mentioned in the docs, and I’m guessing it is now obsolete?
    Leaving it as-is causes a problem where new line characters are not escaped to HTML, so the site admin is mailed a block of text in a single unbroken paragraph.

    So, I changed it to type "html", which according to the docs is "Same as string except that it converts line endings (\n) to
    tags".
    However, once I did this I noticed that now visitors could submit unescaped HTML markup, which personally I don’t want (spam is bad enough without inline images smiley *)
    So, I explicitly set allowhtml=`0` but this still didn’t fix the problem.

    In my opinion this is a bug, but as I’m unsure of the author’s intentions I don’t know the best place to fix it.
    One way is to alter approx line 165 of eform.inc.php from:

    $fields[$name]	= stripslashes(($allowhtml || $formats[$name][2]=='html')? $value:$modx->stripTags($value));


    to

    $fields[$name]	= stripslashes(($allowhtml)? $value:$modx->stripTags($value));


    Another way would be to always call stripslashes() or htmlentities() on a "string" type field.

    If I have overlooked something in the docs about this I apologise, but hopefully this will be useful to someone.

    /\dam

    * Yes, I enable CAPTCHAs, but some spammers just seem to have too much time on their hands and submit stuff manually sad