PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / 4.2.16
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization v4.2.16
4.2.16 4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 All 137 releases
← All changes | inc/admin.php +57 -14 4.2.13 → 4.2.16 View file →
@@ -109,8 +109,9 @@
109 109 'allow_svg',
110 110 ]
111 111 ); // phpcs:ignore WordPressVIPMinimum.Hooks.RestrictedHooks.upload_mimes
112 112 add_filter( 'wp_handle_upload_prefilter', [ $this, 'check_svg_and_sanitize' ] );
113 + add_filter( 'wp_handle_sideload_prefilter', [ $this, 'sanitize_sideloaded_svg' ] );
113 114 }
114 115
115 116 add_filter( 'themeisle-sdk/survey/' . OPTML_PRODUCT_SLUG, [ $this, 'get_survey_metadata' ], 10, 2 );
116 117 add_action( 'admin_init', [ $this, 'mark_user_with_offload' ] );
@@ -191,26 +192,67 @@
191 192 *
192 193 * @return mixed
193 194 */
194 195 public function check_svg_and_sanitize( $file ) {
196 + if ( ! is_array( $file ) || ! $this->is_svg_file( $file ) ) {
197 + return $file;
198 + }
199 +
200 + if ( ! current_user_can( 'upload_files' ) ) {
201 + $file['error'] = 'Invalid';
202 + return $file;
203 + }
204 +
205 + return $this->sanitize_svg_file( $file );
206 + }
207 +
208 + /**
209 + * Sanitize an SVG stored through wp_handle_sideload().
210 + *
211 + * Sideload callers authorize themselves (the REST media endpoint checks upload_files) and
212 + * background restores run without a user, so only sanitization is applied here.
213 + *
214 + * @param array<string, mixed> $file An array of data for a single file.
215 + *
216 + * @return array<string, mixed>
217 + */
218 + public function sanitize_sideloaded_svg( array $file ): array {
219 + if ( ! $this->is_svg_file( $file ) ) {
220 + return $file;
221 + }
222 +
223 + return $this->sanitize_svg_file( $file );
224 + }
225 +
226 + /**
227 + * Check whether an upload/sideload file array is an SVG.
228 + *
229 + * @param array<string, mixed> $file An array of data for a single file.
230 + *
231 + * @return bool
232 + */
233 + private function is_svg_file( array $file ): bool {
195 234 // Ensure we have a proper file path before processing.
196 235 if ( ! isset( $file['tmp_name'] ) ) {
197 - return $file;
236 + return false;
198 237 }
199 238
200 239 $file_name = isset( $file['name'] ) ? $file['name'] : '';
201 240 $wp_filetype = wp_check_filetype_and_ext( $file['tmp_name'], $file_name );
202 - $type = ! empty( $wp_filetype['type'] ) ? $wp_filetype['type'] : '';
203 241
204 - if ( 'image/svg+xml' === $type ) {
205 - if ( ! current_user_can( 'upload_files' ) ) {
206 - $file['error'] = 'Invalid';
207 - return $file;
208 - }
242 + return ! empty( $wp_filetype['type'] ) && 'image/svg+xml' === $wp_filetype['type'];
243 + }
209 244
210 - if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) {
211 - $file['error'] = 'Invalid';
212 - }
245 + /**
246 + * Sanitize the SVG temp file in place, flagging the upload when it cannot be sanitized.
247 + *
248 + * @param array<string, mixed> $file An array of data for a single file.
249 + *
250 + * @return array<string, mixed>
251 + */
252 + private function sanitize_svg_file( array $file ): array {
253 + if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) {
254 + $file['error'] = 'Invalid';
213 255 }
214 256
215 257 return $file;
216 258 }
@@ -221,9 +263,9 @@
221 263 * @param string $file Temp file path.
222 264 *
223 265 * @return bool|int
224 266 */
225 - protected function sanitize_svg( $file ) {
267 + public function sanitize_svg( $file ) {
226 268 // We can ignore the phpcs warning here as we're reading and writing to the Temp file.
227 269 $dirty = file_get_contents( $file ); // phpcs:ignore
228 270
229 271 // Is the SVG gzipped? If so we try and decode the string.
@@ -252,12 +294,13 @@
252 294 if ( $is_zipped ) {
253 295 $clean = gzencode( $clean );
254 296 }
255 297
256 - // We can ignore the phpcs warning here as we're reading and writing to the Temp file.
257 - file_put_contents( $file, $clean ); // phpcs:ignore
298 + // We handle the write result below; silence the warning on I/O failure. Reading/writing the temp file is intended.
299 + $written = @file_put_contents( $file, $clean ); // phpcs:ignore WordPress.WP.AlternativeFunctions, WordPress.PHP.NoSilencedErrors
258 300
259 - return true;
301 + // A failed write leaves the dirty upload in place, so report it as unsanitized.
302 + return is_string( $clean ) && strlen( $clean ) === $written;
260 303 }
261 304
262 305 /**
263 306 * Check if the contents are gzipped