KamoCRM

Stop HTML-escaping the package title in the four HR subjects

Fixkamo-shared-library
Shipped
7 ஆகஸ்ட், 2026 அன்று 12:57 AM UTC
Author
Kamo
Commit
2b63262

EmailTemplateService renders a template's SUBJECT and BODY from ONE variable map, and all four canonical HR subjects carry {{packageTitle}} — which LegalNotificationRecorder HTML-escapes, because the same variable is substituted into the HTML body where an HR-authored title is untrusted markup. The result shipped markup in a mail header: "Employee's Handbook" arrived as "Employee's Handbook" and "Health & Safety" as "Health & Safety", in the Subject line of a legally significant message. The two uses need two different values, so there are now two variables. The bodies keep the escaped packageTitle. The subjects take packageTitlePlain, which is unescaped — and CR/LF-stripped, because the subject is the one place a package title reaches a header and a newline there is RFC 5322 header injection, something HTML escaping does nothing about. Resources and a test only; no schema, no version change.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing