| @@ -410,8 +410,22 @@ | ||
| 410 | 410 | } |
| 411 | 411 | } |
| 412 | 412 | |
| 413 | 413 | /** |
| 414 | + * `options.php` is what registers the "Settings saved." notice and stores it in the | |
| 415 | + * `settings_errors` transient. We bypass it on network installations, so do it here. | |
| 416 | + * | |
| 417 | + * The guard mirrors core: a success notice is only queued when nothing else has | |
| 418 | + * reported a problem during this request, so a real error from another plugin is | |
| 419 | + * never contradicted by a "Settings saved." underneath it. | |
| 420 | + */ | |
| 421 | + if ( ! count( get_settings_errors() ) ) { | |
| 422 | + add_settings_error( 'general', 'settings_updated', __( 'Settings saved.' ), 'success' ); | |
| 423 | + } | |
| 424 | + | |
| 425 | + set_transient( 'settings_errors', get_settings_errors(), 30 ); | |
| 426 | + | |
| 427 | + /** | |
| 414 | 428 | * Redirect back to the settings page that was submitted. |
| 415 | 429 | */ |
| 416 | 430 | imagify_maybe_redirect( false, [ 'settings-updated' => 'true' ] ); |
| 417 | 431 | } |
| @@ -473,9 +487,9 @@ | ||
| 473 | 487 | ?> |
| 474 | 488 | <input type="checkbox" value="1" <?php checked( $current_value, 1 ); ?> <?php echo $args['attributes']; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> /> |
| 475 | 489 | <!-- Empty onclick attribute to make clickable labels on iTruc & Mac --> |
| 476 | 490 | <label for="<?php echo esc_attr( $attributes['id'] ); ?>" onclick=""> |
| 477 | - <?php echo esc_html( $args['label'] ); ?> | |
| 491 | + <?php self::print_text( $args['label'] ); ?> | |
| 478 | 492 | </label> |
| 479 | 493 | <?php |
| 480 | 494 | if ( ! $args['info'] ) { |
| 481 | 495 | return; |
| @@ -482,9 +496,9 @@ | ||
| 482 | 496 | } |
| 483 | 497 | ?> |
| 484 | 498 | <span id="<?php echo esc_attr( $attributes['aria-describedby'] ); ?>" class="imagify-info"> |
| 485 | 499 | <span class="dashicons dashicons-info"></span> |
| 486 | - <?php echo esc_html( $args['info'] ); ?> | |
| 500 | + <?php self::print_text( $args['info'] ); ?> | |
| 487 | 501 | </span> |
| 488 | 502 | <?php |
| 489 | 503 | } |
| 490 | 504 | |
| @@ -552,9 +566,9 @@ | ||
| 552 | 566 | <?php |
| 553 | 567 | if ( $args['legend'] ) { |
| 554 | 568 | ?> |
| 555 | 569 | <legend class="screen-reader-text"> |
| 556 | - <?php echo esc_html( $args['legend'] ); ?> | |
| 570 | + <?php self::print_text( $args['legend'] ); ?> | |
| 557 | 571 | </legend> |
| 558 | 572 | <?php |
| 559 | 573 | } |
| 560 | 574 | |
| @@ -576,9 +590,9 @@ | ||
| 576 | 590 | ?> |
| 577 | 591 | <p> |
| 578 | 592 | <input type="checkbox" value="<?php echo esc_attr( $value ); ?>" id="<?php echo esc_attr( $input_id ); ?>" <?php echo $args['attributes']; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> <?php checked( $checked ); ?> <?php disabled( $disabled ); ?> /> |
| 579 | 593 | <label for="<?php echo esc_attr( $input_id ); ?>" onclick=""> |
| 580 | - <?php echo esc_html( $label ); ?> | |
| 594 | + <?php self::print_text( $label ); ?> | |
| 581 | 595 | </label> |
| 582 | 596 | </p> |
| 583 | 597 | <?php |
| 584 | 598 | } |
| @@ -672,9 +686,9 @@ | ||
| 672 | 686 | if ( $args['legend'] ) { |
| 673 | 687 | ?> |
| 674 | 688 | <legend class="screen-reader-text"> |
| 675 | 689 | <?php |
| 676 | - echo esc_html( $args['legend'] ); | |
| 690 | + self::print_text( $args['legend'] ); | |
| 677 | 691 | ?> |
| 678 | 692 | </legend> |
| 679 | 693 | <?php |
| 680 | 694 | } |
| @@ -683,9 +697,9 @@ | ||
| 683 | 697 | $input_id = sprintf( $id_attribute, sanitize_html_class( $value ) ); |
| 684 | 698 | ?> |
| 685 | 699 | <input type="radio" value="<?php echo esc_attr( $value ); ?>" id="<?php echo esc_attr( $input_id ); ?>" <?php echo $args['attributes']; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> <?php checked( $current_value, $value ); ?> /> |
| 686 | 700 | <label for="<?php echo esc_attr( $input_id ); ?>" onclick=""> |
| 687 | - <?php echo esc_html( $label ); ?> | |
| 701 | + <?php self::print_text( $label ); ?> | |
| 688 | 702 | </label> |
| 689 | 703 | <br/> |
| 690 | 704 | <?php |
| 691 | 705 | } |
| @@ -697,9 +711,9 @@ | ||
| 697 | 711 | } |
| 698 | 712 | ?> |
| 699 | 713 | <span id="<?php echo esc_attr( $attributes['aria-describedby'] ); ?>" class="imagify-info"> |
| 700 | 714 | <span class="dashicons dashicons-info"></span> |
| 701 | - <?php echo esc_html( $args['info'] ); ?> | |
| 715 | + <?php self::print_text( $args['info'] ); ?> | |
| 702 | 716 | </span> |
| 703 | 717 | <?php |
| 704 | 718 | } |
| 705 | 719 | |
| @@ -756,9 +770,9 @@ | ||
| 756 | 770 | foreach ( $args['values'] as $value => $label ) { |
| 757 | 771 | $input_id = sprintf( $id_attribute, sanitize_html_class( $value ) ); |
| 758 | 772 | ?> |
| 759 | 773 | <input type="radio" value="<?php echo esc_attr( $value ); ?>" id="<?php echo esc_attr( $input_id ); ?>"<?php echo $args['attributes']; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> <?php checked( $current_value, $value ); ?> /> |
| 760 | - <label for="<?php echo esc_attr( $input_id ); ?>" onclick=""><?php echo esc_html( $label ); ?></label> | |
| 774 | + <label for="<?php echo esc_attr( $input_id ); ?>" onclick=""><?php self::print_text( $label ); ?></label> | |
| 761 | 775 | <?php |
| 762 | 776 | } |
| 763 | 777 | ?> |
| 764 | 778 | </p> |
| @@ -763,9 +777,9 @@ | ||
| 763 | 777 | ?> |
| 764 | 778 | </p> |
| 765 | 779 | <span id="<?php echo esc_attr( $attributes['aria-describedby'] ); ?>" class="imagify-<?php echo esc_attr( $args['info_class'] ); ?>"> |
| 766 | 780 | <span class="dashicons dashicons-info"></span> |
| 767 | - <?php echo esc_html( $args['info'] ); ?> | |
| 781 | + <?php self::print_text( $args['info'] ); ?> | |
| 768 | 782 | </span> |
| 769 | 783 | </div> |
| 770 | 784 | <?php |
| 771 | 785 | } |
| @@ -821,9 +835,9 @@ | ||
| 821 | 835 | $args['attributes'] = self::build_attributes( $attributes ); |
| 822 | 836 | ?> |
| 823 | 837 | <!-- Empty onclick attribute to make clickable labels on iTruc & Mac --> |
| 824 | 838 | <label for="<?php echo esc_attr( $attributes['id'] ); ?>" onclick=""> |
| 825 | - <?php echo esc_html( $args['label'] ); ?> | |
| 839 | + <?php self::print_text( $args['label'] ); ?> | |
| 826 | 840 | </label> |
| 827 | 841 | <input type="text" value="<?php echo esc_attr( $current_value ); ?>" <?php echo $args['attributes']; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> /> |
| 828 | 842 | <?php |
| 829 | 843 | if ( ! $args['info'] ) { |
| @@ -831,9 +845,9 @@ | ||
| 831 | 845 | } |
| 832 | 846 | ?> |
| 833 | 847 | <span id="<?php echo esc_attr( $attributes['aria-describedby'] ); ?>" class="imagify-info"> |
| 834 | 848 | <span class="dashicons dashicons-info"></span> |
| 835 | - <?php echo esc_html( $args['info'] ); ?> | |
| 849 | + <?php self::print_text( $args['info'] ); ?> | |
| 836 | 850 | </span> |
| 837 | 851 | <?php |
| 838 | 852 | } |
| 839 | 853 | |
| @@ -935,6 +949,46 @@ | ||
| 935 | 949 | $out .= ' ' . $attribute . '="' . esc_attr( $value ) . '"'; |
| 936 | 950 | } |
| 937 | 951 | |
| 938 | 952 | return $out; |
| 953 | + } | |
| 954 | + | |
| 955 | + /** | |
| 956 | + * Print a human-readable field string, keeping the inline formatting it carries. | |
| 957 | + * | |
| 958 | + * The labels, legends and info messages of the field renderers are written as | |
| 959 | + * markup by their callers: a `<br>` separating two sentences, a `<code>` | |
| 960 | + * naming a filter, an `<em>` marking the recommended choice, a link to the | |
| 961 | + * documentation. Passing them through `esc_html()` printed those tags to the | |
| 962 | + * user instead of applying them, so they go through a narrow allow-list of | |
| 963 | + * inline tags. | |
| 964 | + * | |
| 965 | + * Entities survive the allow-list, so a label built with `×` or | |
| 966 | + * `<picture>` renders the character it stands for instead of being | |
| 967 | + * escaped a second time. | |
| 968 | + * | |
| 969 | + * The string is already translated by the time it arrives, which is exactly | |
| 970 | + * why the filtering happens here: whatever a translation introduces is held | |
| 971 | + * to the same allow-list as the original string. | |
| 972 | + * | |
| 973 | + * @since 2.3.3 | |
| 974 | + * | |
| 975 | + * @param string $text The string to print. | |
| 976 | + * @return void | |
| 977 | + */ | |
| 978 | + public static function print_text( $text ) { | |
| 979 | + echo wp_kses( | |
| 980 | + $text, | |
| 981 | + [ | |
| 982 | + 'a' => [ | |
| 983 | + 'href' => true, | |
| 984 | + 'rel' => true, | |
| 985 | + 'target' => true, | |
| 986 | + ], | |
| 987 | + 'br' => [], | |
| 988 | + 'code' => [], | |
| 989 | + 'em' => [], | |
| 990 | + 'strong' => [], | |
| 991 | + ] | |
| 992 | + ); | |
| 939 | 993 | } |
| 940 | 994 | } |