← All changes
|
src/Campaigns/Shortcodes/CampaignGridShortcode.php
+13
-4
4.15.1
→
4.18.0
View file →
| @@ -64,8 +64,9 @@ | ||
| 64 | 64 | wp_enqueue_style('givewp-design-system-foundation'); |
| 65 | 65 | } |
| 66 | 66 | |
| 67 | 67 | /** |
| 68 | + * @since 4.18.0 Sanitize string attributes and restrict enumerated values. | |
| 68 | 69 | * @since 4.2.0 |
| 69 | 70 | */ |
| 70 | 71 | private function parseAttributes($atts): array |
| 71 | 72 | { |
| @@ -81,16 +82,24 @@ | ||
| 81 | 82 | 'filter_by' => null, |
| 82 | 83 | ], $atts, 'givewp_campaign_grid'); |
| 83 | 84 | |
| 84 | 85 | return [ |
| 85 | - 'layout' => $atts['layout'], | |
| 86 | + 'layout' => $this->pickAllowed($atts['layout'], ['full', 'double', 'triple'], 'full'), | |
| 86 | 87 | 'showImage' => filter_var($atts['show_image'], FILTER_VALIDATE_BOOLEAN), |
| 87 | 88 | 'showDescription' => filter_var($atts['show_description'], FILTER_VALIDATE_BOOLEAN), |
| 88 | 89 | 'showGoal' => filter_var($atts['show_goal'], FILTER_VALIDATE_BOOLEAN), |
| 89 | - 'sortBy' => $atts['sort_by'], | |
| 90 | - 'orderBy' => $atts['order_by'], | |
| 91 | - 'filterBy' => $atts['filter_by'], | |
| 90 | + 'sortBy' => $this->pickAllowed($atts['sort_by'], ['date', 'amount', 'donations', 'donors'], 'date'), | |
| 91 | + 'orderBy' => $this->pickAllowed($atts['order_by'], ['asc', 'desc'], 'desc'), | |
| 92 | + 'filterBy' => $atts['filter_by'] ? sanitize_text_field($atts['filter_by']) : $atts['filter_by'], | |
| 92 | 93 | 'perPage' => (int)$atts['per_page'], |
| 93 | 94 | 'showPagination' => filter_var($atts['show_pagination'], FILTER_VALIDATE_BOOLEAN), |
| 94 | 95 | ]; |
| 96 | + } | |
| 97 | + | |
| 98 | + /** | |
| 99 | + * @since 4.18.0 | |
| 100 | + */ | |
| 101 | + private function pickAllowed($value, array $allowed, $default): string | |
| 102 | + { | |
| 103 | + return in_array($value, $allowed, true) ? $value : $default; | |
| 95 | 104 | } |
| 96 | 105 | } |