| @@ -1,9 +1,27 @@ | ||
| 1 | -<?php | |
| 2 | -$id = wp_unique_id( 'bBlocksHtml-' ); | |
| 3 | -?> | |
| 4 | -<div | |
| 5 | - <?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?> | |
| 6 | - <?php echo get_block_wrapper_attributes(); ?> | |
| 7 | - id='<?php echo esc_attr( $id ); ?>' | |
| 8 | - data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>' | |
| 9 | -></div> | |
| 1 | +<?php | |
| 2 | +/** | |
| 3 | + * HTML block server-side render. | |
| 4 | + * | |
| 5 | + * `htmlCode` is raw author markup that view.js injects into the page and then | |
| 6 | + * activates any <script> inside it. That is exactly the capability WordPress | |
| 7 | + * gates behind unfiltered_html, so the attribute is filtered here against the | |
| 8 | + * POST AUTHOR's capability before it is ever handed to the frontend. An author | |
| 9 | + * who may not publish unfiltered HTML gets a wp_kses_post() copy, which has no | |
| 10 | + * <script> and no event-handler attributes left in it - so the activation pass | |
| 11 | + * in view.js finds nothing to run. | |
| 12 | + * | |
| 13 | + * @package bBlocks | |
| 14 | + * | |
| 15 | + * @var array $attributes Block attributes. | |
| 16 | + */ | |
| 17 | + | |
| 18 | +$id = wp_unique_id( 'bBlocksHtml-' ); | |
| 19 | + | |
| 20 | +$attributes['htmlCode'] = BBlocks\Inc\Sanitize::userHtml( $attributes['htmlCode'] ?? '' ); | |
| 21 | +?> | |
| 22 | +<div | |
| 23 | + <?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?> | |
| 24 | + <?php echo get_block_wrapper_attributes(); ?> | |
| 25 | + id='<?php echo esc_attr( $id ); ?>' | |
| 26 | + data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>' | |
| 27 | +></div> | |