| @@ -119,9 +119,24 @@ | ||
| 119 | 119 | |
| 120 | 120 | echo wp_sprintf( |
| 121 | 121 | '<li>%4$s<a %1$s><span>%2$s</span> %3$s</a></li>', |
| 122 | 122 | $_link_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 123 | - betterdocs()->template_helper->kses( get_the_title() ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 123 | + /** | |
| 124 | + * Filter a doc item's title markup in category/sidebar doc | |
| 125 | + * lists (e.g. to prepend an API method badge). Deliberately | |
| 126 | + * NOT core `the_title` — this must stay scoped to list items. | |
| 127 | + * | |
| 128 | + * SECURITY CONTRACT: the return value is echoed as HTML and | |
| 129 | + * is NOT escaped afterwards — it has to be, or a callback | |
| 130 | + * could not add the markup this filter exists for. The value | |
| 131 | + * passed in is already kses'd; a callback that wraps or | |
| 132 | + * appends to it is responsible for escaping whatever IT | |
| 133 | + * introduces. Never hand this filter unsanitised user input. | |
| 134 | + * | |
| 135 | + * @param string $title_html Kses'd title markup. | |
| 136 | + * @param int $post_id | |
| 137 | + */ | |
| 138 | + apply_filters( 'betterdocs_docs_list_item_title', betterdocs()->template_helper->kses( get_the_title() ), get_the_ID() ), // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 124 | 139 | ( $show_icon && 'right' == $pos ) ? betterdocs()->template_helper->icon( $icon ) : '', // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 125 | 140 | ( $show_icon && 'left' == $pos ) ? betterdocs()->template_helper->icon( $icon ) : '' // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 126 | 141 | ); |
| 127 | 142 | endwhile; |