The default install of MODx calls eform with a template field type of "textarea" for the message contents.
This does not seem to be mentioned in the docs, and I’m guessing it is now obsolete?
Leaving it as-is causes a problem where new line characters are not escaped to HTML, so the site admin is mailed a block of text in a single unbroken paragraph.
So, I changed it to type "html", which according to the docs is "Same as string except that it converts line endings (\n) to
tags".
However, once I did this I noticed that now visitors could submit unescaped HTML markup, which personally I don’t want (spam is bad enough without inline images
*)
So, I explicitly set allowhtml=`0` but this still didn’t fix the problem.
In my opinion this is a bug, but as I’m unsure of the author’s intentions I don’t know the best place to fix it.
One way is to alter approx line 165 of eform.inc.php from:
$fields[$name] = stripslashes(($allowhtml || $formats[$name][2]=='html')? $value:$modx->stripTags($value));
to
$fields[$name] = stripslashes(($allowhtml)? $value:$modx->stripTags($value));
Another way would be to always call stripslashes() or htmlentities() on a "string" type field.
If I have overlooked something in the docs about this I apologise, but hopefully this will be useful to someone.
/\dam
* Yes, I enable CAPTCHAs, but some spammers just seem to have too much time on their hands and submit stuff manually