| @@ -1,7 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | - $current_category = get_queried_object(); | |
| 2 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 3 | 3 | |
| 4 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | + exit; | |
| 6 | +} | |
| 7 | +$current_category = get_queried_object(); | |
| 8 | + | |
| 4 | 9 | if ( $current_category != null && $layout == 'layout-1' ) : |
| 5 | 10 | |
| 6 | 11 | ?> |
| 7 | 12 | <div class='betterdocs-content-area block-archive-list <?php echo esc_attr( $blockId ); ?>'> |
| @@ -7,12 +12,13 @@ | ||
| 7 | 12 | <div class='betterdocs-content-area block-archive-list <?php echo esc_attr( $blockId ); ?>'> |
| 8 | 13 | <div class="betterdocs-content-inner-area"> |
| 9 | 14 | <div class="betterdocs-entry-title"> |
| 10 | 15 | <?php |
| 16 | + $title_tag = tag_escape( betterdocs()->template_helper->is_valid_tag( isset( $title_tag ) ? $title_tag : 'h2' ) ); | |
| 11 | 17 | echo wp_sprintf( |
| 12 | 18 | '<%1$s class="betterdocs-entry-heading">%2$s</%1$s>', |
| 13 | 19 | $title_tag, //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 14 | - $current_category->name //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 20 | + esc_html( $current_category->name ) | |
| 15 | 21 | ); |
| 16 | 22 | echo wp_sprintf( '<p>%s</p>', wp_kses_post( $current_category->description ) ); |
| 17 | 23 | ?> |
| 18 | 24 | </div> |
| @@ -22,8 +28,10 @@ | ||
| 22 | 28 | </div> |
| 23 | 29 | </div> |
| 24 | 30 | <?php |
| 25 | 31 | elseif ( $current_category != null && $layout == 'layout-2' ) : |
| 32 | + // Public action name predates the prefix convention; renaming would break third-party integrations. | |
| 33 | + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound | |
| 26 | 34 | do_action( 'archive_handbook_list' ); |
| 27 | 35 | elseif ( $current_category != null && ( $layout == 'layout-3' || $layout == 'layout-4' ) ) : |
| 28 | 36 | $post_query = new WP_Query( $query_args ); |
| 29 | 37 | |
| @@ -31,9 +39,9 @@ | ||
| 31 | 39 | // Determine CSS class and template based on layout |
| 32 | 40 | $css_class = $layout == 'layout-3' ? 'doc-category-layout-7' : 'doc-category-layout-4'; |
| 33 | 41 | $template = $layout == 'layout-3' ? 'template-parts/archive-doc-list' : 'template-parts/archive-doc-list-2'; |
| 34 | 42 | |
| 35 | - echo '<div class="' . $blockId . ' ' . $css_class . '">'; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 43 | + echo '<div class="' . esc_attr( $blockId ) . ' ' . esc_attr( $css_class ) . '">'; | |
| 36 | 44 | betterdocs()->views->get( |
| 37 | 45 | $template, |
| 38 | 46 | [ |
| 39 | 47 | 'current_category' => $current_category, |