MDL-29440 calendar: iCal export don't allow html in description export
authorDan Poltawski <dan@moodle.com>
Mon, 27 Feb 2012 02:12:10 +0000 (10:12 +0800)
committerDan Poltawski <dan@moodle.com>
Mon, 12 Mar 2012 01:51:43 +0000 (09:51 +0800)
calendar/export_execute.php

index 7f195be..ee0bed8 100644 (file)
@@ -152,7 +152,7 @@ foreach($events as $event) {
     $ev = new iCalendar_event;
     $ev->add_property('uid', $event->id.'@'.$hostaddress);
     $ev->add_property('summary', $event->name);
-    $ev->add_property('description', $event->description);
+    $ev->add_property('description', clean_param($event->description, PARAM_NOTAGS));
     $ev->add_property('class', 'PUBLIC'); // PUBLIC / PRIVATE / CONFIDENTIAL
     $ev->add_property('last-modified', Bennu::timestamp_to_datetime($event->timemodified));
     $ev->add_property('dtstamp', Bennu::timestamp_to_datetime()); // now