PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / 4.2.15
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization v4.2.15
4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 3.11.3 All 136 releases
← All changes | vendor/enshrined/svg-sanitize/src/ElementReference/Resolver.php +6 -1 4.2.5 → 4.2.15 View file →
@@ -95,12 +95,17 @@
95 95 * their occurrence in `<use ... xlink:href="#identifier">` statements.
96 96 */
97 97 protected function processReferences()
98 98 {
99 + // Note: the href attribute is deliberately not filtered in the XPath predicate.
100 + // XPath attribute matching is case sensitive, so `[@href or @xlink:href]` would
101 + // skip `<use HrEf="#id">`/`<use xlink:HrEf="#id">` - names that
102 + // `Sanitizer::cleanHrefAttributes()` normalizes back to `href`/`xlink:href`
103 + // afterwards, which would hand back a live reference the graph never saw.
99 104 $useNodeName = $this->xPath->createNodeName('use');
100 105 foreach ($this->subjects as $subject) {
101 106 $useElements = $this->xPath->query(
102 - $useNodeName . '[@href or @xlink:href]',
107 + $useNodeName,
103 108 $subject->getElement()
104 109 );
105 110
106 111 /** @var \DOMElement $useElement */