| @@ -140,14 +140,10 @@ | ||
| 140 | 140 | $html = new \WP_HTML_Tag_Processor($htmlContent); |
| 141 | 141 | $html->next_tag('img'); |
| 142 | 142 | $src = $html->get_attribute('src'); |
| 143 | 143 | |
| 144 | - return $src && preg_match( | |
| 145 | - '(' . implode('|', array_map('preg_quote', ImageUploader::$imagesDomains, ['/'])) . ')i', | |
| 146 | - $src | |
| 147 | - ) | |
| 148 | - ? $src | |
| 149 | - : ''; | |
| 144 | + // Feeds a server-side fetch, so a path-matched domain would let any host through. | |
| 145 | + return ($src && ImageUploader::isAllowedImageHost($src)) ? $src : ''; | |
| 150 | 146 | } |
| 151 | 147 | |
| 152 | 148 | /** |
| 153 | 149 | * Update the content of the block to remove the targeted class attribute. |