Skip to content

Commit eaadcbc

Browse files
committed
fix(sharebymail): do not escape the note mail heading twice
addHeading() already escapes its title, so a sharer display name with & or ' showed up as &amp;amp; in the note mail. DefaultShareProvider already passes the heading unescaped. Assisted-by: ClaudeCode:claude-opus-5-5 Signed-off-by: John Molakvoæ <14975046+skjnldsv@users.noreply.github.com>
1 parent 5cbe364 commit eaadcbc

2 files changed

Lines changed: 36 additions & 1 deletion

File tree

‎apps/sharebymail/lib/ShareByMailProvider.php‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -550,7 +550,7 @@ protected function sendNote(IShare $share): void {
550550

551551
$emailTemplate->setSubject($this->l->t('%s added a note to a file shared with you', [$initiatorDisplayName]));
552552
$emailTemplate->addHeader();
553-
$emailTemplate->addHeading(htmlspecialchars($htmlHeading), $plainHeading);
553+
$emailTemplate->addHeading($htmlHeading, $plainHeading);
554554
$emailTemplate->addBodyText(htmlspecialchars($note), $note);
555555

556556
$link = $this->urlGenerator->linkToRouteAbsolute('files_sharing.sharecontroller.showShare',

‎apps/sharebymail/tests/ShareByMailProviderTest.php‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1974,4 +1974,39 @@ public function testSendMailNotificationWithDifferentUserAndNoUserEmailAndReplyT
19741974
[$share]
19751975
);
19761976
}
1977+
1978+
public function testSendNoteDoesNotEscapeHeading(): void {
1979+
$provider = $this->getInstance();
1980+
$initiatorUser = $this->createMock(IUser::class);
1981+
$initiatorUser->method('getDisplayName')->willReturn('Tom & Jerry\'s');
1982+
$initiatorUser->method('getEMailAddress')->willReturn(null);
1983+
$this->userManager->method('get')->with('InitiatorUser')->willReturn($initiatorUser);
1984+
$this->settingsManager->method('replyToInitiator')->willReturn(false);
1985+
$this->defaults->method('getName')->willReturn('UnitTestCloud');
1986+
$this->urlGenerator->method('linkToRouteAbsolute')->willReturn('https://example.com/file.txt');
1987+
1988+
$message = $this->createMock(Message::class);
1989+
$this->mailer->method('createMessage')->willReturn($message);
1990+
$template = $this->createMock(IEMailTemplate::class);
1991+
$this->mailer->method('createEMailTemplate')->willReturn($template);
1992+
$template
1993+
->expects($this->once())
1994+
->method('addHeading')
1995+
->with(
1996+
'Tom & Jerry\'s shared file.txt with you and wants to add',
1997+
'Tom & Jerry\'s shared file.txt with you and wants to add:'
1998+
);
1999+
$this->mailer->expects($this->once())->method('send')->with($message);
2000+
2001+
$node = $this->createMock(File::class);
2002+
$node->method('getName')->willReturn('file.txt');
2003+
$share = $this->createMock(IShare::class);
2004+
$share->method('getSharedBy')->willReturn('InitiatorUser');
2005+
$share->method('getSharedWith')->willReturn('john@doe.com');
2006+
$share->method('getNode')->willReturn($node);
2007+
$share->method('getNote')->willReturn('Some note');
2008+
$share->method('getToken')->willReturn('token');
2009+
2010+
self::invokePrivate($provider, 'sendNote', [$share]);
2011+
}
19772012
}

0 commit comments

Comments
 (0)