| @@ -76,10 +76,10 @@ | ||
| 76 | 76 | } |
| 77 | 77 | |
| 78 | 78 | /** |
| 79 | 79 | * Put one person's footprint over the body. The id is validated (the |
| 80 | - * payload route re-checks the viewer); the name is only ever a | |
| 81 | - * breadcrumb placeholder until the payload lands. | |
| 80 | + * payload route re-checks the viewer); the name is only ever breadcrumb | |
| 81 | + * text, so the entities the sanitiser writes for a `<` are decoded. | |
| 82 | 82 | * |
| 83 | 83 | * @param State $state State. |
| 84 | 84 | * @param int $user User id; 0 or unknown opens nothing. |
| 85 | 85 | * @param string $name Display name, or ''. |
| @@ -89,9 +89,9 @@ | ||
| 89 | 89 | if ( $user <= 0 || false === get_userdata( $user ) ) { |
| 90 | 90 | return; |
| 91 | 91 | } |
| 92 | 92 | $state->set( 'footprint', $user ) |
| 93 | - ->set( 'fpName', sanitize_text_field( $name ) ) | |
| 93 | + ->set( 'fpName', openstation_plain_text_title( sanitize_text_field( $name ) ) ) | |
| 94 | 94 | ->set( 'item', 0 )->set( 'into', 0 )->set( 'relation', '' ); |
| 95 | 95 | } |
| 96 | 96 | |
| 97 | 97 | /** |