PluginProbe
Gutenberg / 23.7.2
Gutenberg v23.7.2
23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 12.6.0 7.4.0 All 402 releases
gutenberg / lib / experimental / kses.php

kses.php in Gutenberg 23.7.2, at lib/experimental/kses.php

111 lines 3.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Temporary compatibility shims for kses rules present in Gutenberg.
4 *
5 * The functions in this file should not be backported to core.
6 *
7 * @package gutenberg
8 */
9
10 /**
11 * Sanitizes global styles user content removing unsafe rules.
12 *
13 * This function is identical to the core version, but called the
14 * Gutenberg version of the theme JSON class (`WP_Theme_JSON_Gutenberg`).
15 *
16 * This function should not be backported to core.
17 *
18 * @since 5.9.0
19 *
20 * @param string $data Post content to filter.
21 * @return string Filtered post content with unsafe rules removed.
22 */
23 function gutenberg_filter_global_styles_post( $data ) {
24 $decoded_data = json_decode( wp_unslash( $data ), true );
25 $json_decoding_error = json_last_error();
26 if (
27 JSON_ERROR_NONE === $json_decoding_error &&
28 is_array( $decoded_data ) &&
29 isset( $decoded_data['isGlobalStylesUserThemeJSON'] ) &&
30 $decoded_data['isGlobalStylesUserThemeJSON']
31 ) {
32 unset( $decoded_data['isGlobalStylesUserThemeJSON'] );
33
34 $data_to_encode = WP_Theme_JSON_Gutenberg::remove_insecure_properties( $decoded_data, 'custom' );
35
36 $data_to_encode['isGlobalStylesUserThemeJSON'] = true;
37 /**
38 * JSON encode the data stored in post content.
39 * Escape characters that are likely to be mangled by HTML filters: "<>&".
40 *
41 * This matches the escaping in {@see WP_REST_Global_Styles_Controller_Gutenberg::prepare_item_for_database()}.
42 */
43 return wp_slash( wp_json_encode( $data_to_encode, JSON_UNESCAPED_SLASHES | JSON_HEX_TAG | JSON_HEX_AMP ) );
44 }
45 return $data;
46 }
47
48 /**
49 * Override core's kses_init_filters hooks for global styles,
50 * and use Gutenberg's version instead. This ensures that
51 * Gutenberg's `remove_insecure_properties` function can be called.
52 *
53 * The hooks are only set if they are already added, which ensures
54 * that global styles is only filtered for users without the `unfiltered_html`
55 * capability.
56 *
57 * This function should not be backported to core.
58 */
59 function gutenberg_override_core_kses_init_filters() {
60 if ( has_filter( 'content_save_pre', 'wp_filter_global_styles_post' ) ) {
61 remove_filter( 'content_save_pre', 'wp_filter_global_styles_post', 9 );
62 add_filter( 'content_save_pre', 'gutenberg_filter_global_styles_post', 9 );
63 }
64
65 if ( has_filter( 'content_filtered_save_pre', 'wp_filter_global_styles_post' ) ) {
66 remove_filter( 'content_filtered_save_pre', 'wp_filter_global_styles_post', 9 );
67 add_filter( 'content_filtered_save_pre', 'gutenberg_filter_global_styles_post', 9 );
68 }
69 }
70 // The 'kses_init_filters' is usually initialized with default priority. Use higher priority to override.
71 add_action( 'init', 'gutenberg_override_core_kses_init_filters', 20 );
72 add_action( 'set_current_user', 'gutenberg_override_core_kses_init_filters' );
73
74 if ( ! function_exists( 'allow_filter_in_styles' ) ) {
75 /**
76 * See https://github.com/WordPress/wordpress-develop/pull/4108
77 *
78 * Mark CSS safe if it contains a "filter: url('#wp-duotone-...')" rule.
79 *
80 * This function should not be backported to core.
81 *
82 * @param bool $allow_css Whether the CSS is allowed.
83 * @param string $css_test_string The CSS to test.
84 * @return bool Whether the CSS is allowed.
85 */
86 function allow_filter_in_styles( $allow_css, $css_test_string ) {
87 if ( preg_match(
88 "/^filter:\s*url\((['\"]?)#wp-duotone-[-a-zA-Z0-9]+\\1\)(\s+!important)?$/",
89 $css_test_string
90 ) ) {
91 return true;
92 }
93 return $allow_css;
94 }
95 }
96 add_filter( 'safecss_filter_attr_allow_css', 'allow_filter_in_styles', 10, 2 );
97
98 /**
99 * Update allowed inline style attributes list.
100 *
101 * @param string[] $attrs Array of allowed CSS attributes.
102 * @return string[] CSS attributes.
103 */
104 function gutenberg_safe_grid_attrs( $attrs ) {
105 $attrs[] = 'grid-column';
106 $attrs[] = 'grid-row';
107 $attrs[] = 'container-type';
108 return $attrs;
109 }
110 add_filter( 'safe_style_css', 'gutenberg_safe_grid_attrs' );
111