We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Add-on description field in the store parses EE code

Developer Preview

Brian Litzinger's avatar
Brian Litzinger
693 posts
6 years ago
Brian Litzinger's avatar Brian Litzinger

My URL Helper extension has a {current_url} variable, which appears to be parsing. You can see “https://expressionengine.com/add-ons/url-helper” just after the {page_number} var in the docs. I haven’t tried it yet, but I wonder if it means {exp:channel:entries} tags could be rendered? Could be a security issue.

       
Derek Jones's avatar
Derek Jones
7,561 posts
6 years ago
Derek Jones's avatar Derek Jones

Globals are parsed in entries if they are in the clear, which enables things like path variables. If you put it in backticks or code blocks, it should display as code properly.

       
Brian Litzinger's avatar
Brian Litzinger
693 posts
6 years ago
Brian Litzinger's avatar Brian Litzinger

I added back ticks and it’s still parsing :(

       
Derek Jones's avatar
Derek Jones
7,561 posts
6 years ago
Derek Jones's avatar Derek Jones

Looks like a bug in the Markdown parser, on it.

       
Derek Jones's avatar
Derek Jones
7,561 posts
6 years ago
Derek Jones's avatar Derek Jones

Should be fixed including another bug I found while I was there. Thanks!

       
Brian Litzinger's avatar
Brian Litzinger
693 posts
6 years ago
Brian Litzinger's avatar Brian Litzinger

The change you made might have broken HTML https://expressionengine.com/add-ons/freeform

       
Derek Jones's avatar
Derek Jones
7,561 posts
6 years ago
Derek Jones's avatar Derek Jones

Ah, unrelated. I changed to Safe HTML so people couldn’t enter any old markup. I’ve restored it to All HTML and will work with Kelsey next week on an alternative.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.