Raw HTML in ‘Latest Activity’ block
-
I’m running WP 6.8.1 wih bbp 2.6.13 and bbp style pack 6.3.0 on the Twenty Twenty-Four theme.
When I view my forum as a logged in user, I see this under the Last Activity section:
Last Activity: <a href="https://scottishpolicy.org/forums/topic/right-to-privacy/" title="Right to privacy">1 day, 9 hours ago</a>I’ve used Inspector to look at the code in the browser (Firefox and Brave – both are affected) and I can’t spot anything obvious.
Is this a known issue?
Is there a fix?
-
can I have a link to see the issue please
I’d need to make a login for you, since only logged in users can see the private forums…
Can you make up a dummy email (or pm me a working email) and I’ll set that up?
For the record, this is the page giving the problem:
https://scottishpolicy.org/forums/forum/constitution/It’s all in the process of development just now, so there’s not content as yet…
I’d need to make a login for you, since only logged in users can see the private forums…
Can you make up a dummy email (or pm me a working email) and I’ll set that up?
For the record, this is the page giving the problem:
https://scottishpolicy.org/forums/forum/constitution/It’s all in the process of development just now, so there’s not content as yet…
I’d send a screenshot, but I don’t actually think that’d be a great deal of help.
Sorry for the duplicate post…
I realised I don’t need a real email for you, so I made up an alias.
I’ll only keep that up for a couple of days for obvious reasons!
Thanks.
ok, thanks I can can now see the problem. I am away for a few days, but I’ll take a look when I can
Thanks – and thanks for your discretion over credentials.
Appreciated.
I’ve tried installing several different themes (Twenty Twenty-Three, Twenty Twenty-Two, Twenty Twenty-One, Astra). The block themes all had the same problem. the Twenty Twenty-One theme didn’t display the troublesome blocks at all, missing out the problem.
In fairness, the block editor does inform me that the blocks are not supported in any of the themes above, so perhaps I can just delete these blocks and wait until support is available: they are not essential for the running of the site, just a nice wee convenience!
Like I said, please don’t prioritise this – I’ll happily work with the forums minus these two blocks.
Cheers!
should be fixed in style pack 6.3.1 just released
Wow – perfect!
Well, almost…
The site works as it should, there’s no raw html showing, which is great.
The theme still complains that the block is unsupported though, which is minor but might put off developers.
Thanks – much appreciated.
You do amazing work!
Thanks, the ‘unsupported’ is on my list to fix.
thank you
I just found the issue, and fixed it in 6.3.2 just released.
Can you test and confirm please?
We’re part of the way there…
I’ve updated to your 6.3.2, cleared caches on WP and my browsers.
I’m using Brave for development, Firefox to test.
The raw html doesn’t appear if I log in to the WP dashboard and preview the site (Brave), but if I log in as a user (Firefox) the problem reappears. Still only for the ‘Last Reply’ and ‘Last Activity’ links.
Brave on my phone is also displaying the raw html.
Thanks.
OK – if I go to the Forums root folder, Latest Actity displays correctly.
If I go to a topic within a forum, the raw HTML appears again.
I guess you’ll need to propagate the fix to the next level down.
Cheers.
Also, when the raw html doesn’t show, the ‘topic by’ field is blank.
Sorry – and thanks!
no problem, I did some fixes a while ago in this area, and think I have messed some up !!
I’ll have a further go at these later today, and try and get them all working again !
ok, I think this is now working in 6.3.4 just released, but again can I ask you to check, that would be very helpful 🙂
Aha!
Fixed it!
All seems good, both on the development dashboard using Brave and on the testing site using Firefox.
Android phone is happy too.
Top work – thanks!
That’s great – thanks for testing and your help in finding the issues 🙂
View page source / Inspect element — is the HTML escaped (e.g. <div>) or raw text?
Check your template engine: is auto-escaping enabled or disabled? https://avatarworldmodapk.org/
See how the string is inserted in the DOM: textContent vs innerHTML vs server-side echo.
Search code for escape, htmlspecialchars, |raw, |safe, dangerouslySetInnerHTML etc.
If HTML should be allowed, confirm it’s sanitized (avoid XSS). If it shouldn’t be allowed, ensure it’s escaped.
- You must be logged in to reply to this topic.