PluginProbe
bBlocks – Essential Gutenberg Blocks & Patterns Collection / 2.1.8
bBlocks – Essential Gutenberg Blocks & Patterns Collection v2.1.8
2.1.8 2.1.7 2.1.6 2.1.5 2.1.4 2.1.3 2.1.2 2.1.1 2.1.0 2.0.43 2.0.42 2.0.41 2.0.40 2.0.39 2.0.38 trunk 1.0 1.1 1.2 1.3 1.4 1.5 1.5.1 1.5.2 1.5.3 All 108 releases
← All changes | build/html/render.php +27 -9 2.0.42 → 2.1.8 View file →
@@ -1,9 +1,27 @@
1 -<?php
2 -$id = wp_unique_id( 'bBlocksHtml-' );
3 -?>
4 -<div
5 - <?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?>
6 - <?php echo get_block_wrapper_attributes(); ?>
7 - id='<?php echo esc_attr( $id ); ?>'
8 - data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>'
9 -></div>
1 +<?php
2 +/**
3 + * HTML block server-side render.
4 + *
5 + * `htmlCode` is raw author markup that view.js injects into the page and then
6 + * activates any <script> inside it. That is exactly the capability WordPress
7 + * gates behind unfiltered_html, so the attribute is filtered here against the
8 + * POST AUTHOR's capability before it is ever handed to the frontend. An author
9 + * who may not publish unfiltered HTML gets a wp_kses_post() copy, which has no
10 + * <script> and no event-handler attributes left in it - so the activation pass
11 + * in view.js finds nothing to run.
12 + *
13 + * @package bBlocks
14 + *
15 + * @var array $attributes Block attributes.
16 + */
17 +
18 +$id = wp_unique_id( 'bBlocksHtml-' );
19 +
20 +$attributes['htmlCode'] = BBlocks\Inc\Sanitize::userHtml( $attributes['htmlCode'] ?? '' );
21 +?>
22 +<div
23 + <?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?>
24 + <?php echo get_block_wrapper_attributes(); ?>
25 + id='<?php echo esc_attr( $id ); ?>'
26 + data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>'
27 +></div>