| @@ -221,9 +221,9 @@ | ||
| 221 | 221 | * @param string $file Temp file path. |
| 222 | 222 | * |
| 223 | 223 | * @return bool|int |
| 224 | 224 | */ |
| 225 | - protected function sanitize_svg( $file ) { | |
| 225 | + public function sanitize_svg( $file ) { | |
| 226 | 226 | // We can ignore the phpcs warning here as we're reading and writing to the Temp file. |
| 227 | 227 | $dirty = file_get_contents( $file ); // phpcs:ignore |
| 228 | 228 | |
| 229 | 229 | // Is the SVG gzipped? If so we try and decode the string. |
| @@ -252,12 +252,13 @@ | ||
| 252 | 252 | if ( $is_zipped ) { |
| 253 | 253 | $clean = gzencode( $clean ); |
| 254 | 254 | } |
| 255 | 255 | |
| 256 | - // We can ignore the phpcs warning here as we're reading and writing to the Temp file. | |
| 257 | - file_put_contents( $file, $clean ); // phpcs:ignore | |
| 256 | + // We handle the write result below; silence the warning on I/O failure. Reading/writing the temp file is intended. | |
| 257 | + $written = @file_put_contents( $file, $clean ); // phpcs:ignore WordPress.WP.AlternativeFunctions, WordPress.PHP.NoSilencedErrors | |
| 258 | 258 | |
| 259 | - return true; | |
| 259 | + // A failed write leaves the dirty upload in place, so report it as unsanitized. | |
| 260 | + return is_string( $clean ) && strlen( $clean ) === $written; | |
| 260 | 261 | } |
| 261 | 262 | |
| 262 | 263 | /** |
| 263 | 264 | * Check if the contents are gzipped |