From ebf9383d34902dd51d3a0ba85ee1bd43ec4fbaa7 Mon Sep 17 00:00:00 2001 From: Graham Ollis Date: Wed, 23 Sep 2026 21:42:08 -0600 Subject: [PATCH 1/3] Silence uninitialized warnings for fields without a name (RT#106557) A Submit or Button element with a value but no name triggered "Use of uninitialized value $root in hash element" on every submitted form, because Button sets force_default(1) and Field::process_input passed the undefined nested_name to set_nested_hash_value. The string renderers for Select, Textarea, Checkboxgroup (and so Radiogroup) and ContentButton also emitted name="" with a sprintf warning when the field had no name, and Date built sub-field names from the undefined parent name. They now omit the name attribute, matching the existing behaviour of the Input role. The name() setter also accepts undef without a pattern-match warning. Adds t/elements/unnamed_fields.t which traps warnings while processing and rendering a form containing each affected element type. Co-Authored-By: Claude Fable 5.1 --- Changes | 7 ++ lib/HTML/FormFu/Element.pm | 2 +- lib/HTML/FormFu/Element/Checkboxgroup.pm | 13 +++- lib/HTML/FormFu/Element/ContentButton.pm | 11 ++- lib/HTML/FormFu/Element/Date.pm | 14 ++-- lib/HTML/FormFu/Element/Select.pm | 10 ++- lib/HTML/FormFu/Element/Textarea.pm | 11 ++- lib/HTML/FormFu/Role/Element/Field.pm | 3 + t/elements/unnamed_fields.t | 94 ++++++++++++++++++++++++ 9 files changed, 144 insertions(+), 21 deletions(-) create mode 100644 t/elements/unnamed_fields.t diff --git a/Changes b/Changes index a4a9db8d..0a1b59c4 100644 --- a/Changes +++ b/Changes @@ -1,5 +1,12 @@ {{$NEXT}} + - Fields without a name no longer emit "Use of uninitialized value" + warnings when a form is processed or rendered: an unnamed Submit or + Button with a value triggered one via force_default, and the Select, + Textarea, Checkboxgroup, Radiogroup, ContentButton and Date string + renderers emitted name="" with a warning. The name attribute is now + omitted, matching the other Input elements. RT#106557 + - Migrate from List::MoreUtils to List::SomeUtils - Fix CVE-2026-19873: bound the Repeatable element's counter_name diff --git a/lib/HTML/FormFu/Element.pm b/lib/HTML/FormFu/Element.pm index 660b1458..39c6930f 100644 --- a/lib/HTML/FormFu/Element.pm +++ b/lib/HTML/FormFu/Element.pm @@ -65,7 +65,7 @@ sub name { if ( @_ > 1 ) { - if ( $name =~ /[\.\[\]]/ ) { + if ( defined $name && $name =~ /[\.\[\]]/ ) { croak <<'ERROR_MESSAGE'; element names may not contain periods or square brackets see documentation on nested_names() for details diff --git a/lib/HTML/FormFu/Element/Checkboxgroup.pm b/lib/HTML/FormFu/Element/Checkboxgroup.pm index 5a547cd1..0c7e5825 100644 --- a/lib/HTML/FormFu/Element/Checkboxgroup.pm +++ b/lib/HTML/FormFu/Element/Checkboxgroup.pm @@ -150,6 +150,11 @@ sub _string_field { # radiogroup_tag template + my $name_attr + = defined $render->{nested_name} + ? sprintf( qq{ name="%s"}, $render->{nested_name} ) + : q{}; + my $html .= sprintf "\n", process_attrs( $render->{attributes} ); for my $option ( @{ $render->{options} } ) { @@ -174,8 +179,8 @@ sub _string_field { ; my $input = sprintf - qq{\n}, - $render->{nested_name}, + qq{\n}, + $name_attr, $render->{input_type}, $item->{value}, process_attrs( $item->{attributes} ), @@ -205,8 +210,8 @@ sub _string_field { ; my $input = sprintf - qq{\n}, - $render->{nested_name}, + qq{\n}, + $name_attr, $render->{input_type}, $option->{value}, process_attrs( $option->{attributes} ), diff --git a/lib/HTML/FormFu/Element/ContentButton.pm b/lib/HTML/FormFu/Element/ContentButton.pm index 5f5c032f..64ef1b4d 100644 --- a/lib/HTML/FormFu/Element/ContentButton.pm +++ b/lib/HTML/FormFu/Element/ContentButton.pm @@ -46,10 +46,13 @@ sub _string_field { # content_button template - my $html .= sprintf qq{