Files
smarty/docs/designers/language-custom-functions/language-function-mailto.md
T
Simon Wisselink 11e69eca68 Security: escape value-context attributes in html_image/html_select_date (CWE-79)
{html_image} already escaped alt and pass-through attributes, but emitted
file, path_prefix, href/link, width and height raw, letting an untrusted
value break out of the generated tag. Escape these at output time; the
unescaped values are still used for getimagesize()/DPI math. Escaping uses
htmlspecialchars with double_encode=false, so existing entities and values
like "100%" are preserved (no BC break for legitimate values).

{html_select_date} treated day_size/month_size/year_size as strings and
emitted them raw into size="…"; cast them to int to match
{html_select_time} and close the breakout.

The remaining flagged parameters (mailto extra; html_table *_attr/
trailpad/caption/loop; html_radios/html_checkboxes separator;
html_select_* *_extra/field_separator and the unrecognised-attribute
pass-through) intentionally emit raw markup as documented, so escaping
them would break backwards compatibility. Add a security note to those
docs pages instead, telling authors to escape untrusted values themselves.

Adds tests for html_image escaping (incl. benign-value/no-double-encode
checks) and the html_select_date size cast.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 00:48:01 +02:00

3.3 KiB

{mailto}

{mailto} automates the creation of a mailto: anchor links and optionally encodes them. Encoding emails makes it more difficult for web spiders to lift email addresses off of a site.

Attributes

Attribute Name Required Description
address Yes The e-mail address
text No The text to display, default is the e-mail address
encode No How to encode the e-mail. Can be one of none, hex, javascript or javascript_charcode.
cc No Email addresses to carbon copy, separate entries by a comma.
bcc No Email addresses to blind carbon copy, separate entries by a comma
subject No Email subject
newsgroups No Newsgroups to post to, separate entries by a comma.
followupto No Addresses to follow up to, separate entries by a comma.
extra No Any extra information you want passed to the link, such as style sheet classes

Note

Javascript is probably the most thorough form of encoding, although you can use hex encoding too.

Security note

The extra attribute is written into the generated <a> tag without escaping, so that you can add attributes such as extra='class="mailto"'. If you pass a value that originates from untrusted input, escape it yourself first (e.g. with the escape modifier) to avoid cross-site scripting (XSS).

Examples

{mailto address="me@example.com"}
<a href="mailto:me@example.com" >me@example.com</a>

{mailto address="me@example.com" text="send me some mail"}
<a href="mailto:me@example.com" >send me some mail</a>

{mailto address="me@example.com" encode="javascript"}
    <script>
   eval(unescape('%64%6f% ... snipped ...%61%3e%27%29%3b'))
</script>

{mailto address="me@example.com" encode="hex"}
<a href="mailto:%6d%65.. snipped..3%6f%6d">&#x6d;&..snipped...#x6f;&#x6d;</a>

{mailto address="me@example.com" subject="Hello to you!"}
<a href="mailto:me@example.com?subject=Hello%20to%20you%21" >me@example.com</a>

{mailto address="me@example.com" cc="you@example.com,they@example.com"}
<a href="mailto:me@example.com?cc=you@example.com,they@example.com" >me@example.com</a>

{mailto address="me@example.com" extra='class="email"'}
<a href="mailto:me@example.com" class="email">me@example.com</a>

{mailto address="me@example.com" encode="javascript_charcode"}
    <script>
    {document.write(String.fromCharCode(60,97, ... snipped ....60,47,97,62))}
</script>

See also escape, {textformat} and obfuscating email addresses.