[5.7] Fix broken email subcopy template escaping #25723
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Laravel 5.6.36 (d3c0a36) introduced a security change to prevent XSS in some situations.
Unfortunately a byproduct of this is a number of breaking changes as documented #25515, #25501, #25408, d3c0a36#commitcomment-30368450, #25716, #25430
One of those breaking changes linked above is email subcopy links do not work out of the box on a fresh Laravel 5.7 install (i.e. email verification subcopy links are broken).
This PR pulls the URL out of the
@lang
section on the email template, and places it immediately after, allowing the raw url to be un-escaped as required to generate a correct URL. Fixes #25716Before PR:
After PR:
p.s. if this PR is accepted we'll need to backport to 5.6