PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / trunk
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization vtrunk
4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 3.11.3 All 136 releases
← All changes | vendor/enshrined/svg-sanitize/src/Helper.php +23 -2 4.2.12 → trunk View file →
@@ -2,9 +2,19 @@
2 2 namespace enshrined\svgSanitize;
3 3
4 4 class Helper
5 5 {
6 + const XLINK_NAMESPACE_URI = 'http://www.w3.org/1999/xlink';
7 +
6 8 /**
9 + * Resolves the `href`/`xlink:href` value of an element.
10 + *
11 + * The lookup is case insensitive on purpose: `Sanitizer::cleanHrefAttributes()`
12 + * normalizes names such as `HrEf`/`xlink:HrEf` back to `href`/`xlink:href`,
13 + * so anything consuming this helper has to see those attributes as well -
14 + * otherwise a mixed-case name hides the reference from e.g. the `<use>`
15 + * reference graph, which is built before that normalization happens.
16 + *
7 17 * @param \DOMElement $element
8 18 * @return string|null
9 19 */
10 20 public static function getElementHref(\DOMElement $element)
@@ -11,10 +21,21 @@
11 21 {
12 22 if ($element->hasAttribute('href')) {
13 23 return $element->getAttribute('href');
14 24 }
15 - if ($element->hasAttributeNS('http://www.w3.org/1999/xlink', 'href')) {
16 - return $element->getAttributeNS('http://www.w3.org/1999/xlink', 'href');
25 + if ($element->hasAttributeNS(self::XLINK_NAMESPACE_URI, 'href')) {
26 + return $element->getAttributeNS(self::XLINK_NAMESPACE_URI, 'href');
27 + }
28 + foreach ($element->attributes as $attribute) {
29 + if (!$attribute instanceof \DOMAttr
30 + || strtolower($attribute->localName) !== 'href'
31 + ) {
32 + continue;
33 + }
34 + $prefix = strtolower((string)$attribute->prefix);
35 + if ($prefix === '' || $prefix === 'xlink') {
36 + return $attribute->value;
37 + }
17 38 }
18 39 return null;
19 40 }
20 41