diff --git a/src/MicroweberPackages/Comment/Models/Comment.php b/src/MicroweberPackages/Comment/Models/Comment.php index 20d2625ea6e..4bb3f6d746f 100644 --- a/src/MicroweberPackages/Comment/Models/Comment.php +++ b/src/MicroweberPackages/Comment/Models/Comment.php @@ -25,6 +25,7 @@ class Comment extends Model // 'comment_body'=>MarkdownCast::class // ]; + public function modelFilter() { return $this->provideFilter(ContentFilter::class); diff --git a/src/MicroweberPackages/Comment/Models/CommentsCrud.php b/src/MicroweberPackages/Comment/Models/CommentsCrud.php index 2024169d6a2..a21a469d9a4 100644 --- a/src/MicroweberPackages/Comment/Models/CommentsCrud.php +++ b/src/MicroweberPackages/Comment/Models/CommentsCrud.php @@ -54,7 +54,7 @@ public function get($params = false) if (isset($item['comment_body']) and ($item['comment_body'] != '')) { $surl = site_url(); $item['comment_body'] = str_replace('{SITE_URL}', $surl, $item['comment_body']); - $comments[$i]['comment_body'] = $item['comment_body']; // mw()->format->autolink($item['comment_body']); + $comments[$i]['comment_body'] = htmlentities($item['comment_body']); } if (isset($params['single'])) { diff --git a/src/MicroweberPackages/Comment/resources/views/admin/comments/comment_item.blade.php b/src/MicroweberPackages/Comment/resources/views/admin/comments/comment_item.blade.php index c0816e66df0..28c16a3ea4d 100644 --- a/src/MicroweberPackages/Comment/resources/views/admin/comments/comment_item.blade.php +++ b/src/MicroweberPackages/Comment/resources/views/admin/comments/comment_item.blade.php @@ -55,10 +55,10 @@
-
+
{{ $comment['comment_body'] }}
diff --git a/userfiles/modules/comments/src/Controllers/Admin.php b/userfiles/modules/comments/src/Controllers/Admin.php index 054aa11315a..fbf5f1d2de0 100644 --- a/userfiles/modules/comments/src/Controllers/Admin.php +++ b/userfiles/modules/comments/src/Controllers/Admin.php @@ -46,7 +46,6 @@ function index($params) function comments_list($params) { - if (!user_can_access('module.comments.index')) { return; } @@ -113,12 +112,10 @@ function comment_item($params) $comment = get_comments($data); - if (!$comment) { return; } - $view_file = $this->views_dir . 'comment_item.php'; $view = new View($view_file); $view->assign('params', $params);