Details
-
Bug
-
Resolution: Fixed
-
Major
-
None
-
None
-
None
Description
Currently (as of Rev 15008), Syslog alert emails generated by Observium display apostrophes as the literal HTML entity ' instead of rendering them as '.
Example alert content:
Alert Commit - ALL
|
Conditions /User '[^']+', command 'commit/
|
Metrics User 'user66', command 'commit comment "syslog test" '
|
Expected output:
Alert Commit - ALL
|
Conditions /User '[^']+', command 'commit/
|
Metrics User 'user66', command 'commit comment "syslog test" '
|
It looks like CONDITIONS and METRICS are HTML-escaped in includes/transports/email.inc.php in the following lines:
$message_tags_html['CONDITIONS'] = nl2br(escape_html($message_tags['CONDITIONS']));
|
$message_tags_html['METRICS'] = nl2br(escape_html($message_tags['METRICS']));
|
Suggested fix:
$message_tags_html['CONDITIONS'] = nl2br(htmlspecialchars($message_tags['CONDITIONS'], ENT_QUOTES | ENT_HTML401, 'UTF-8'));
|
$message_tags_html['METRICS'] = nl2br(htmlspecialchars($message_tags['METRICS'], ENT_QUOTES | ENT_HTML401, 'UTF-8'));
|
There is another small issue with plain text template (includes/templates/notification/email_text.tpl) where CONDITIONS already uses non-escaped syntax but METRICS does not:
Metrics: {{METRICS}}
|
Conditions: {{{CONDITIONS}}}
|
The suggested fix also includes "METRICS" to be "{{
{METRICS}}}"