You are here

protected function Renderer::xssFilterAdminIfUnsafe in Zircon Profile 8.0

Same name and namespace in other branches
  1. 8 core/lib/Drupal/Core/Render/Renderer.php \Drupal\Core\Render\Renderer::xssFilterAdminIfUnsafe()

Applies a very permissive XSS/HTML filter for admin-only use.

Note: This method only filters if $string is not marked safe already. This ensures that HTML intended for display is not filtered.

Parameters

string|\Drupal\Core\Render\Markup $string: A string.

Return value

\Drupal\Core\Render\Markup The escaped string wrapped in a Markup object. If SafeMarkup::isSafe($string) returns TRUE, it won't be escaped again.

1 call to Renderer::xssFilterAdminIfUnsafe()
Renderer::doRender in core/lib/Drupal/Core/Render/Renderer.php
See the docs for ::render().

File

core/lib/Drupal/Core/Render/Renderer.php, line 681
Contains \Drupal\Core\Render\Renderer.

Class

Renderer
Turns a render array into a HTML string.

Namespace

Drupal\Core\Render

Code

protected function xssFilterAdminIfUnsafe($string) {
  if (!SafeMarkup::isSafe($string)) {
    $string = Xss::filterAdmin($string);
  }
  return Markup::create($string);
}