PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | lib/compat/wordpress-7.1/kses.php +62 -0 23.5.1 → trunk View file →
@@ -96,4 +96,66 @@
96 96
97 97 return array_unique( array_merge( $attr, $svg_properties ) );
98 98 }
99 99 add_filter( 'safe_style_css', 'gutenberg_add_svg_to_safe_style_css' );
100 +
101 +/**
102 + * Allow gradient background-image values, including gradients combined with a
103 + * url() image, in inline styles.
104 + *
105 + * Without this, {@see safecss_filter_attr()} strips gradients that use functions
106 + * beyond rgb()/rgba(), or that are combined with a url() image. This removes each
107 + * gradient from the test string and re-checks the remainder, so those values
108 + * survive sanitization.
109 + *
110 + * @param bool $allow_css Whether the CSS is allowed.
111 + * @param string $css_test_string The CSS declaration to test.
112 + * @return bool Whether the CSS is allowed.
113 + */
114 +function gutenberg_allow_extended_gradient_backgrounds( $allow_css, $css_test_string ) {
115 + if ( $allow_css ) {
116 + return $allow_css;
117 + }
118 +
119 + if ( ! preg_match( '/^background-image\s*:/', $css_test_string ) ) {
120 + return $allow_css;
121 + }
122 +
123 + /*
124 + * Remove each gradient (allowing one level of nested functions such as
125 + * rgb(), hsl(), or calc()) and re-test. Any url() has already been removed
126 + * and protocol-checked by safecss_filter_attr() before this filter runs.
127 + */
128 + $stripped = preg_replace( '/(?:repeating-)?(?:linear|radial|conic)-gradient\((?:[^()]|\([^()]*\))*\)/', '', $css_test_string );
129 +
130 + if ( ! preg_match( '%[\\\(&=}]|/\*%', $stripped ) ) {
131 + return true;
132 + }
133 +
134 + return $allow_css;
135 +}
136 +
137 +add_filter( 'safecss_filter_attr_allow_css', 'gutenberg_allow_extended_gradient_backgrounds', 10, 2 );
138 +
139 +/**
140 + * Allows the `tabindex` attribute on elements that support global attributes.
141 + *
142 + * `tabindex` is a global HTML attribute, but KSES strips it from post content.
143 + * The Tab Panel block saves it to keep the panel focusable.
144 + *
145 + * @param array[] $tags Array of allowed HTML tags and their allowed attributes.
146 + * @return array[] Modified array of allowed HTML tags.
147 + */
148 +function gutenberg_add_tabindex_to_kses_allowed_html( $tags ) {
149 + if ( ! is_array( $tags ) ) {
150 + return $tags;
151 + }
152 +
153 + foreach ( $tags as $tag => $attributes ) {
154 + if ( is_array( $attributes ) ) {
155 + $tags[ $tag ]['tabindex'] = true;
156 + }
157 + }
158 +
159 + return $tags;
160 +}
161 +add_filter( 'wp_kses_allowed_html', 'gutenberg_add_tabindex_to_kses_allowed_html' );