PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | lib/experimental/kses.php +1 -53 23.4.0 → trunk View file →
@@ -78,9 +78,9 @@
78 78 * Mark CSS safe if it contains a "filter: url('#wp-duotone-...')" rule.
79 79 *
80 80 * This function should not be backported to core.
81 81 *
82 - * @param bool $allow_css Whether the CSS is allowed.
82 + * @param bool $allow_css Whether the CSS is allowed.
83 83 * @param string $css_test_string The CSS to test.
84 84 * @return bool Whether the CSS is allowed.
85 85 */
86 86 function allow_filter_in_styles( $allow_css, $css_test_string ) {
@@ -93,60 +93,8 @@
93 93 return $allow_css;
94 94 }
95 95 }
96 96 add_filter( 'safecss_filter_attr_allow_css', 'allow_filter_in_styles', 10, 2 );
97 -
98 -/**
99 - * Allow combined gradient and url() background-image values in inline styles.
100 - *
101 - * WordPress's safecss_filter_attr() handles gradient and url() values
102 - * separately for background-image, but fails when both appear in a single
103 - * comma-separated declaration. The url() portion is stripped from the test
104 - * string before the filter runs, but the gradient regex in core expects the
105 - * gradient to be the only value and doesn't match when a trailing comma and
106 - * whitespace remain. This leaves parentheses in the test string, which
107 - * triggers the unsafe-character check.
108 - *
109 - * This filter catches that case: the test string still contains a valid
110 - * gradient function with only commas and whitespace remaining after the
111 - * url() was removed.
112 - *
113 - * @param bool $allow_css Whether the CSS is allowed.
114 - * @param string $css_test_string The CSS declaration to test.
115 - * @return bool Whether the CSS is allowed.
116 - */
117 -function gutenberg_allow_background_image_combined( $allow_css, $css_test_string ) {
118 - if ( $allow_css ) {
119 - return $allow_css;
120 - }
121 - /*
122 - * The test string at this point has url() values already removed by
123 - * safecss_filter_attr. What remains is a gradient with comma/whitespace
124 - * residue where the url() was stripped. Two possible forms:
125 - *
126 - * Gradient first: "background-image:<gradient>(...), "
127 - * URL first: "background-image:, <gradient>(...)"
128 - *
129 - * A trailing or leading comma (with optional whitespace) must be present
130 - * to confirm a url() was actually removed. Without that residue, the
131 - * gradient alone would already pass core's own check.
132 - */
133 - $gradient_pattern = '(?:linear|radial|conic|repeating-linear|repeating-radial|repeating-conic)-gradient\((?:[^()]|\([^()]*\))*\)';
134 - $var_pattern = 'var\(--[a-zA-Z0-9_-]+(?:--[a-zA-Z0-9_-]+)*\)';
135 - $value_pattern = "(?:$gradient_pattern|$var_pattern)";
136 -
137 - // Gradient/var first, then comma+whitespace residue from stripped url().
138 - $pattern_gradient_first = '/^background-image\s*:\s*' . $value_pattern . '\s*,[\s,]*$/';
139 - // Stripped url() first (comma+whitespace residue), then gradient/var.
140 - $pattern_url_first = '/^background-image\s*:[\s,]*,\s*' . $value_pattern . '\s*$/';
141 -
142 - if ( preg_match( $pattern_gradient_first, $css_test_string ) || preg_match( $pattern_url_first, $css_test_string ) ) {
143 - return true;
144 - }
145 -
146 - return $allow_css;
147 -}
148 -add_filter( 'safecss_filter_attr_allow_css', 'gutenberg_allow_background_image_combined', 10, 2 );
149 97
150 98 /**
151 99 * Update allowed inline style attributes list.
152 100 *