diff --git a/packages/infolists/docs/03-entries/02-text.md b/packages/infolists/docs/03-entries/02-text.md index ebb11aa384..09c9849350 100644 --- a/packages/infolists/docs/03-entries/02-text.md +++ b/packages/infolists/docs/03-entries/02-text.md @@ -259,6 +259,29 @@ TextEntry::make('description') ->html() ``` +If you use this method, then the HTML will be sanitized to remove any potentially unsafe content before it is rendered. If you'd like to opt out of this behavior, you can wrap the HTML in an `HtmlString` object by formatting it: + +```php +use Filament\Infolists\Components\TextEntry; +use Illuminate\Support\HtmlString; + +TextEntry::make('description') + ->formatStateUsing(fn (string $state): HtmlString => new HtmlString($state)) +``` + +Or, you can return a `view()` object from the `formatStateUsing()` method, which will also not be sanitized: + +```php +use Filament\Infolists\Components\TextEntry; +use Illuminate\Contracts\View\View; + +TextEntry::make('description') + ->formatStateUsing(fn (string $state): View => view( + 'filament.infolists.components.description-entry-content', + ['state' => $state], + )) +``` + ### Rendering Markdown as HTML If your entry value is Markdown, you may render it using `markdown()`: diff --git a/packages/infolists/src/Components/Concerns/CanFormatState.php b/packages/infolists/src/Components/Concerns/CanFormatState.php index 5e0de6a1d0..7b23b3cc5b 100644 --- a/packages/infolists/src/Components/Concerns/CanFormatState.php +++ b/packages/infolists/src/Components/Concerns/CanFormatState.php @@ -9,6 +9,7 @@ use Filament\Support\Contracts\HasLabel as LabelInterface; use Filament\Support\Enums\ArgumentValue; use Illuminate\Contracts\Support\Htmlable; use Illuminate\Support\Carbon; +use Illuminate\Support\HtmlString; use Illuminate\Support\Number; use Illuminate\Support\Str; @@ -228,6 +229,10 @@ trait CanFormatState 'state' => $state, ]); + if ($isHtml) { + $state = Str::sanitizeHtml($state); + } + if ($state instanceof Htmlable) { $isHtml = true; $state = $state->toHtml(); @@ -263,6 +268,8 @@ trait CanFormatState if (filled($prefix)) { if ($prefix instanceof Htmlable) { $prefix = $prefix->toHtml(); + } elseif ($isHtml) { + $prefix = e($prefix); } $state = $prefix . $state; @@ -271,16 +278,14 @@ trait CanFormatState if (filled($suffix)) { if ($suffix instanceof Htmlable) { $suffix = $suffix->toHtml(); + } elseif ($isHtml) { + $suffix = e($suffix); } $state = $state . $suffix; } - if ($isHtml) { - return str($state)->sanitizeHtml()->toHtmlString(); - } - - return $state; + return $isHtml ? new HtmlString($state) : $state; } public function getCharacterLimit(): ?int diff --git a/packages/tables/docs/03-columns/02-text.md b/packages/tables/docs/03-columns/02-text.md index 816b7a2610..37a03c66fe 100644 --- a/packages/tables/docs/03-columns/02-text.md +++ b/packages/tables/docs/03-columns/02-text.md @@ -304,6 +304,29 @@ TextColumn::make('description') ->html() ``` +If you use this method, then the HTML will be sanitized to remove any potentially unsafe content before it is rendered. If you'd like to opt out of this behavior, you can wrap the HTML in an `HtmlString` object by formatting it: + +```php +use Filament\Tables\Columns\TextColumn; +use Illuminate\Support\HtmlString; + +TextColumn::make('description') + ->formatStateUsing(fn (string $state): HtmlString => new HtmlString($state)) +``` + +Or, you can return a `view()` object from the `formatStateUsing()` method, which will also not be sanitized: + +```php +use Filament\Tables\Columns\TextColumn; +use Illuminate\Contracts\View\View; + +TextColumn::make('description') + ->formatStateUsing(fn (string $state): View => view( + 'filament.tables.columns.description-entry-content', + ['state' => $state], + )) +``` + ### Rendering Markdown as HTML If your column contains Markdown, you may render it using `markdown()`: diff --git a/packages/tables/src/Columns/Concerns/CanFormatState.php b/packages/tables/src/Columns/Concerns/CanFormatState.php index 6ad3f642c6..a57dbd0848 100644 --- a/packages/tables/src/Columns/Concerns/CanFormatState.php +++ b/packages/tables/src/Columns/Concerns/CanFormatState.php @@ -9,6 +9,7 @@ use Filament\Tables\Columns\TextColumn; use Filament\Tables\Table; use Illuminate\Contracts\Support\Htmlable; use Illuminate\Support\Carbon; +use Illuminate\Support\HtmlString; use Illuminate\Support\Number; use Illuminate\Support\Str; @@ -228,6 +229,10 @@ trait CanFormatState 'state' => $state, ]); + if ($isHtml) { + $state = Str::sanitizeHtml($state); + } + if ($state instanceof Htmlable) { $isHtml = true; $state = $state->toHtml(); @@ -263,6 +268,8 @@ trait CanFormatState if (filled($prefix)) { if ($prefix instanceof Htmlable) { $prefix = $prefix->toHtml(); + } elseif ($isHtml) { + $prefix = e($prefix); } $state = $prefix . $state; @@ -271,16 +278,14 @@ trait CanFormatState if (filled($suffix)) { if ($suffix instanceof Htmlable) { $suffix = $suffix->toHtml(); + } elseif ($isHtml) { + $suffix = e($suffix); } $state = $state . $suffix; } - if ($isHtml) { - return str($state)->sanitizeHtml()->toHtmlString(); - } - - return $state; + return $isHtml ? new HtmlString($state) : $state; } public function getCharacterLimit(): ?int