| @@ -109,8 +109,9 @@ | ||
| 109 | 109 | 'allow_svg', |
| 110 | 110 | ] |
| 111 | 111 | ); // phpcs:ignore WordPressVIPMinimum.Hooks.RestrictedHooks.upload_mimes |
| 112 | 112 | add_filter( 'wp_handle_upload_prefilter', [ $this, 'check_svg_and_sanitize' ] ); |
| 113 | + add_filter( 'wp_handle_sideload_prefilter', [ $this, 'sanitize_sideloaded_svg' ] ); | |
| 113 | 114 | } |
| 114 | 115 | |
| 115 | 116 | add_filter( 'themeisle-sdk/survey/' . OPTML_PRODUCT_SLUG, [ $this, 'get_survey_metadata' ], 10, 2 ); |
| 116 | 117 | add_action( 'admin_init', [ $this, 'mark_user_with_offload' ] ); |
| @@ -191,26 +192,67 @@ | ||
| 191 | 192 | * |
| 192 | 193 | * @return mixed |
| 193 | 194 | */ |
| 194 | 195 | public function check_svg_and_sanitize( $file ) { |
| 196 | + if ( ! is_array( $file ) || ! $this->is_svg_file( $file ) ) { | |
| 197 | + return $file; | |
| 198 | + } | |
| 199 | + | |
| 200 | + if ( ! current_user_can( 'upload_files' ) ) { | |
| 201 | + $file['error'] = 'Invalid'; | |
| 202 | + return $file; | |
| 203 | + } | |
| 204 | + | |
| 205 | + return $this->sanitize_svg_file( $file ); | |
| 206 | + } | |
| 207 | + | |
| 208 | + /** | |
| 209 | + * Sanitize an SVG stored through wp_handle_sideload(). | |
| 210 | + * | |
| 211 | + * Sideload callers authorize themselves (the REST media endpoint checks upload_files) and | |
| 212 | + * background restores run without a user, so only sanitization is applied here. | |
| 213 | + * | |
| 214 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 215 | + * | |
| 216 | + * @return array<string, mixed> | |
| 217 | + */ | |
| 218 | + public function sanitize_sideloaded_svg( array $file ): array { | |
| 219 | + if ( ! $this->is_svg_file( $file ) ) { | |
| 220 | + return $file; | |
| 221 | + } | |
| 222 | + | |
| 223 | + return $this->sanitize_svg_file( $file ); | |
| 224 | + } | |
| 225 | + | |
| 226 | + /** | |
| 227 | + * Check whether an upload/sideload file array is an SVG. | |
| 228 | + * | |
| 229 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 230 | + * | |
| 231 | + * @return bool | |
| 232 | + */ | |
| 233 | + private function is_svg_file( array $file ): bool { | |
| 195 | 234 | // Ensure we have a proper file path before processing. |
| 196 | 235 | if ( ! isset( $file['tmp_name'] ) ) { |
| 197 | - return $file; | |
| 236 | + return false; | |
| 198 | 237 | } |
| 199 | 238 | |
| 200 | 239 | $file_name = isset( $file['name'] ) ? $file['name'] : ''; |
| 201 | 240 | $wp_filetype = wp_check_filetype_and_ext( $file['tmp_name'], $file_name ); |
| 202 | - $type = ! empty( $wp_filetype['type'] ) ? $wp_filetype['type'] : ''; | |
| 203 | 241 | |
| 204 | - if ( 'image/svg+xml' === $type ) { | |
| 205 | - if ( ! current_user_can( 'upload_files' ) ) { | |
| 206 | - $file['error'] = 'Invalid'; | |
| 207 | - return $file; | |
| 208 | - } | |
| 242 | + return ! empty( $wp_filetype['type'] ) && 'image/svg+xml' === $wp_filetype['type']; | |
| 243 | + } | |
| 209 | 244 | |
| 210 | - if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) { | |
| 211 | - $file['error'] = 'Invalid'; | |
| 212 | - } | |
| 245 | + /** | |
| 246 | + * Sanitize the SVG temp file in place, flagging the upload when it cannot be sanitized. | |
| 247 | + * | |
| 248 | + * @param array<string, mixed> $file An array of data for a single file. | |
| 249 | + * | |
| 250 | + * @return array<string, mixed> | |
| 251 | + */ | |
| 252 | + private function sanitize_svg_file( array $file ): array { | |
| 253 | + if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) { | |
| 254 | + $file['error'] = 'Invalid'; | |
| 213 | 255 | } |
| 214 | 256 | |
| 215 | 257 | return $file; |
| 216 | 258 | } |