← All changes
|
src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php
+7
-5
4.15.4
→
4.16.9
View file →
| @@ -9,8 +9,9 @@ | ||
| 9 | 9 | */ |
| 10 | 10 | class BlockRenderController |
| 11 | 11 | { |
| 12 | 12 | /** |
| 13 | + * @since 4.16.1 escape attribute values in block markup | |
| 13 | 14 | * @since 4.0.0 |
| 14 | 15 | */ |
| 15 | 16 | public function render(array $attributes, string $secondaryColor): string |
| 16 | 17 | { |
| @@ -15,11 +16,12 @@ | ||
| 15 | 16 | public function render(array $attributes, string $secondaryColor): string |
| 16 | 17 | { |
| 17 | 18 | $blockAttributes = BlockAttributes::fromArray($attributes); |
| 18 | 19 | |
| 19 | - $encodedAttributes = json_encode($blockAttributes->toArray()); | |
| 20 | - | |
| 21 | - $blockId = $blockAttributes->blockId; | |
| 22 | - | |
| 23 | - return "<div id='givewp-campaign-comments-block-{$blockId}' data-secondary-color='{$secondaryColor}' data-givewp-campaign-comments data-attributes='{$encodedAttributes}'></div>"; | |
| 20 | + return sprintf( | |
| 21 | + "<div id='givewp-campaign-comments-block-%s' data-secondary-color='%s' data-givewp-campaign-comments data-attributes='%s'></div>", | |
| 22 | + esc_attr((string) $blockAttributes->blockId), | |
| 23 | + esc_attr($secondaryColor), | |
| 24 | + esc_attr((string) json_encode($blockAttributes->toArray())) | |
| 25 | + ); | |
| 24 | 26 | } |
| 25 | 27 | } |