Updated to Drupal 8.5. Core Media not yet in use.
[yaffs-website] / web / modules / contrib / devel / src / Plugin / Devel / Dumper / DoctrineDebug.php
index 54e8aaea433c711a486cc7986251f2e31f25571e..9df1aec5cf24623daa7d5b2fbd308aeb001a971d 100644 (file)
@@ -3,6 +3,7 @@
 namespace Drupal\devel\Plugin\Devel\Dumper;
 
 use Doctrine\Common\Util\Debug;
+use Drupal\Component\Utility\Xss;
 use Drupal\devel\DevelDumperBase;
 
 /**
@@ -28,6 +29,10 @@ class DoctrineDebug extends DevelDumperBase {
     $dump = ob_get_contents();
     ob_end_clean();
 
+    // Run Xss::filterAdmin on the resulting string to prevent
+    // cross-site-scripting (XSS) vulnerabilities.
+    $dump = Xss::filterAdmin($dump);
+
     $dump = '<pre>' . $name . $dump . '</pre>';
 
     return $this->setSafeMarkup($dump);