| @@ -17,8 +17,12 @@ | ||
| 17 | 17 | * |
| 18 | 18 | * @package automattic/jetpack |
| 19 | 19 | */ |
| 20 | 20 | |
| 21 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 22 | + exit( 0 ); | |
| 23 | +} | |
| 24 | + | |
| 21 | 25 | wp_embed_register_handler( 'github-gist', '#https?://gist\.github\.com/([a-zA-Z0-9/]+)(\#file\-[a-zA-Z0-9\_\-]+)?#', 'github_gist_embed_handler' ); |
| 22 | 26 | add_shortcode( 'gist', 'github_gist_shortcode' ); |
| 23 | 27 | |
| 24 | 28 | /** |
| @@ -83,14 +87,21 @@ | ||
| 83 | 87 | if ( ! empty( $parsed_url['fragment'] ) ) { |
| 84 | 88 | $gist_info['file'] = preg_replace( '/(?:file-)(.+)/', '$1', $parsed_url['fragment'] ); |
| 85 | 89 | } |
| 86 | 90 | |
| 87 | - // Keep the unique identifier without any leading or trailing slashes. | |
| 88 | - if ( ! empty( $parsed_url['path'] ) ) { | |
| 89 | - $gist_info['id'] = trim( $parsed_url['path'], '/' ); | |
| 90 | - // Overwrite $gist with our identifier to clean it up below. | |
| 91 | - $gist = $gist_info['id']; | |
| 91 | + // Validate the path structure - should be either username/gistid or just gistid | |
| 92 | + $path = trim( $parsed_url['path'], '/' ); | |
| 93 | + if ( ! preg_match( '#^([a-zA-Z0-9_-]+/)?([a-f0-9]+)$#', $path ) ) { | |
| 94 | + return array( | |
| 95 | + 'id' => '', | |
| 96 | + 'file' => '', | |
| 97 | + 'ts' => 8, | |
| 98 | + ); | |
| 92 | 99 | } |
| 100 | + | |
| 101 | + $gist_info['id'] = $path; | |
| 102 | + // Reassign $gist with the identifier to clean it up below. | |
| 103 | + $gist = $path; | |
| 93 | 104 | |
| 94 | 105 | // Parse the query args to obtain the tab spacing. |
| 95 | 106 | if ( ! empty( $parsed_url['query'] ) ) { |
| 96 | 107 | $query_args = array(); |