PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / trunk
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization vtrunk
4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 3.11.3 All 136 releases
← All changes | vendor/enshrined/svg-sanitize/src/ElementReference/Resolver.php +6 -1 4.2.11 → trunk View file →
@@ -95,12 +95,17 @@
95 95 * their occurrence in `<use ... xlink:href="#identifier">` statements.
96 96 */
97 97 protected function processReferences()
98 98 {
99 + // Note: the href attribute is deliberately not filtered in the XPath predicate.
100 + // XPath attribute matching is case sensitive, so `[@href or @xlink:href]` would
101 + // skip `<use HrEf="#id">`/`<use xlink:HrEf="#id">` - names that
102 + // `Sanitizer::cleanHrefAttributes()` normalizes back to `href`/`xlink:href`
103 + // afterwards, which would hand back a live reference the graph never saw.
99 104 $useNodeName = $this->xPath->createNodeName('use');
100 105 foreach ($this->subjects as $subject) {
101 106 $useElements = $this->xPath->query(
102 - $useNodeName . '[@href or @xlink:href]',
107 + $useNodeName,
103 108 $subject->getElement()
104 109 );
105 110
106 111 /** @var \DOMElement $useElement */