| @@ -7,25 +7,40 @@ | ||
| 7 | 7 | */ |
| 8 | 8 | class EmailAddressWhiteList |
| 9 | 9 | { |
| 10 | 10 | /** |
| 11 | - * @var array | |
| 11 | + * @var string[] | |
| 12 | 12 | */ |
| 13 | - protected $whitelistEmails; | |
| 13 | + protected array $whitelistEmails; | |
| 14 | 14 | |
| 15 | 15 | /** |
| 16 | + * @since 4.16.0 Normalize whitelisted emails so comparisons are case- and whitespace-insensitive. | |
| 16 | 17 | * @since 3.15.1 Add array type to enforce type. |
| 17 | 18 | * @since 3.15.0 |
| 18 | 19 | */ |
| 19 | 20 | public function __construct(array $whitelistEmails = []) |
| 20 | 21 | { |
| 21 | - $this->whitelistEmails = $whitelistEmails; | |
| 22 | + $this->whitelistEmails = array_map([$this, 'normalize'], $whitelistEmails); | |
| 22 | 23 | } |
| 23 | 24 | |
| 24 | 25 | /** |
| 26 | + * @since 4.16.0 Compare against the normalized whitelist so casing/whitespace don't cause a miss. | |
| 25 | 27 | * @since 3.15.0 |
| 26 | 28 | */ |
| 27 | - public function validate($email): bool | |
| 29 | + public function validate(string $email): bool | |
| 28 | 30 | { |
| 29 | - return in_array($email, $this->whitelistEmails, true); | |
| 31 | + return in_array($this->normalize($email), $this->whitelistEmails, true); | |
| 32 | + } | |
| 33 | + | |
| 34 | + /** | |
| 35 | + * Whitelist entries originate from the give_akismet_whitelist_emails filter, so they aren't | |
| 36 | + * guaranteed to be strings — cast defensively before normalizing. | |
| 37 | + * | |
| 38 | + * @since 4.16.0 | |
| 39 | + * | |
| 40 | + * @param mixed $email | |
| 41 | + */ | |
| 42 | + private function normalize($email): string | |
| 43 | + { | |
| 44 | + return strtolower(trim((string)$email)); | |
| 30 | 45 | } |
| 31 | 46 | } |