| 1 |
<?php |
| 2 |
/** |
| 3 |
* HTML block server-side render. |
| 4 |
* |
| 5 |
* `htmlCode` is raw author markup that view.js injects into the page and then |
| 6 |
* activates any <script> inside it. That is exactly the capability WordPress |
| 7 |
* gates behind unfiltered_html, so the attribute is filtered here against the |
| 8 |
* POST AUTHOR's capability before it is ever handed to the frontend. An author |
| 9 |
* who may not publish unfiltered HTML gets a wp_kses_post() copy, which has no |
| 10 |
* <script> and no event-handler attributes left in it - so the activation pass |
| 11 |
* in view.js finds nothing to run. |
| 12 |
* |
| 13 |
* @package bBlocks |
| 14 |
* |
| 15 |
* @var array $attributes Block attributes. |
| 16 |
*/ |
| 17 |
|
| 18 |
$id = wp_unique_id( 'bBlocksHtml-' ); |
| 19 |
|
| 20 |
$attributes['htmlCode'] = BBlocks\Inc\Sanitize::userHtml( $attributes['htmlCode'] ?? '' ); |
| 21 |
?> |
| 22 |
<div |
| 23 |
<?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?> |
| 24 |
<?php echo get_block_wrapper_attributes(); ?> |
| 25 |
id='<?php echo esc_attr( $id ); ?>' |
| 26 |
data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>' |
| 27 |
></div> |
| 28 |
|