[*] BO: Add an option to allow iframes on descriptions
This commit is contained in:
@@ -95,6 +95,14 @@ class AdminPreferencesControllerCore extends AdminController
|
||||
'default' => '0',
|
||||
'visibility' => Shop::CONTEXT_ALL
|
||||
),
|
||||
'PS_ALLOW_HTML_IFRAME' => array(
|
||||
'title' => $this->l('Allow iframes on html fields'),
|
||||
'desc' => $this->l('Allow iframes on fields like product description. We recommend that you leave this option disabled'),
|
||||
'validation' => 'isBool',
|
||||
'cast' => 'intval',
|
||||
'type' => 'bool',
|
||||
'default' => '0'
|
||||
),
|
||||
'PS_PRICE_ROUND_MODE' => array(
|
||||
'title' => $this->l('Round mode'),
|
||||
'desc' => $this->l('You can choose how to round prices: Always round superior, always round inferior or classic rounding.'),
|
||||
|
||||
@@ -2058,17 +2058,28 @@ class AdminProductsControllerCore extends AdminController
|
||||
// Check fields validity
|
||||
foreach ($rules['validate'] as $field => $function)
|
||||
if ($this->isProductFieldUpdated($field) && ($value = Tools::getValue($field)))
|
||||
if (!Validate::$function($value))
|
||||
{
|
||||
$res = true;
|
||||
if (Tools::strtolower($function) == 'isCleanHtml')
|
||||
{
|
||||
if (!Validate::$function($value, (int)Configuration::get('PS_ALLOW_HTML_IFRAME')))
|
||||
$res = false;
|
||||
}
|
||||
else
|
||||
if (!Validate::$function($value))
|
||||
$res = false;
|
||||
|
||||
if (!$res)
|
||||
$this->errors[] = sprintf(
|
||||
Tools::displayError('The %s field is invalid.'),
|
||||
call_user_func(array($className, 'displayFieldName'), $field, $className)
|
||||
);
|
||||
|
||||
}
|
||||
// Check multilingual fields validity
|
||||
foreach ($rules['validateLang'] as $fieldLang => $function)
|
||||
foreach ($languages as $language)
|
||||
if ($this->isProductFieldUpdated('description_short', $language['id_lang']) && ($value = Tools::getValue($fieldLang.'_'.$language['id_lang'])))
|
||||
if (!Validate::$function($value))
|
||||
if (!Validate::$function($value, (int)Configuration::get('PS_ALLOW_HTML_IFRAME')))
|
||||
$this->errors[] = sprintf(
|
||||
Tools::displayError('The %1$s field (%2$s) is invalid.'),
|
||||
call_user_func(array($className, 'displayFieldName'), $fieldLang, $className),
|
||||
|
||||
Reference in New Issue
Block a user