← All changes
|
lib/class-wp-rest-global-styles-controller-gutenberg.php
+11
-1
23.3.2
→
trunk
View file →
| @@ -11,8 +11,10 @@ | ||
| 11 | 11 | */ |
| 12 | 12 | |
| 13 | 13 | /** |
| 14 | 14 | * Base Global Styles REST API Controller. |
| 15 | + * | |
| 16 | + * @since 5.9.0 | |
| 15 | 17 | */ |
| 16 | 18 | class WP_REST_Global_Styles_Controller_Gutenberg extends WP_REST_Posts_Controller { |
| 17 | 19 | |
| 18 | 20 | /** |
| @@ -697,12 +699,20 @@ | ||
| 697 | 699 | * @since 7.0.0 Only restricts contents which risk prematurely closing the STYLE element, |
| 698 | 700 | * either through a STYLE end tag or a prefix of one which might become a |
| 699 | 701 | * full end tag when combined with the contents of other styles. |
| 700 | 702 | * |
| 701 | - * @param string $css CSS to validate. | |
| 703 | + * @param mixed $css CSS to validate. | |
| 702 | 704 | * @return true|WP_Error True if the input was validated, otherwise WP_Error. |
| 703 | 705 | */ |
| 704 | 706 | protected function validate_custom_css( $css ) { |
| 707 | + if ( ! is_string( $css ) ) { | |
| 708 | + return new WP_Error( | |
| 709 | + 'rest_custom_css_invalid_type', | |
| 710 | + __( 'CSS must be a string.', 'gutenberg' ), | |
| 711 | + array( 'status' => 400 ) | |
| 712 | + ); | |
| 713 | + } | |
| 714 | + | |
| 705 | 715 | $length = strlen( $css ); |
| 706 | 716 | for ( |
| 707 | 717 | $at = strcspn( $css, '<' ); |
| 708 | 718 | $at < $length; |