← All changes
|
modules/gutenberg/dist/blocks/advanced-heading/class-advanced-heading.php
+27
-3
0.0.10
→
2.12.8
View file →
| @@ -4,8 +4,10 @@ | ||
| 4 | 4 | * |
| 5 | 5 | * @package Sureforms |
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | +use SRFM\Inc\Helper; | |
| 9 | + | |
| 8 | 10 | if ( ! defined( 'ABSPATH' ) ) { |
| 9 | 11 | exit; // Exit if accessed directly. |
| 10 | 12 | } |
| 11 | 13 | |
| @@ -661,10 +663,20 @@ | ||
| 661 | 663 | if ( isset( $attributes['headingWrapper'] ) ) { |
| 662 | 664 | $heading_wrapper = $attributes['headingWrapper']; |
| 663 | 665 | } |
| 664 | 666 | |
| 665 | - $element = ! empty( $heading_wrapper ) ? $heading_wrapper : 'div'; | |
| 667 | + // Validate tag-name attributes against the editor UI options to prevent | |
| 668 | + // arbitrary HTML injection in tag-name position (esc_attr() does not strip | |
| 669 | + // `<`, `>`, spaces or `=`, which is unsafe when echoed as a tag name). | |
| 670 | + $allowed_wrapper_tags = [ 'div', 'header' ]; | |
| 671 | + $allowed_heading_tags = [ 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'p', 'div' ]; | |
| 666 | 672 | |
| 673 | + $element = in_array( $heading_wrapper, $allowed_wrapper_tags, true ) ? $heading_wrapper : 'div'; | |
| 674 | + | |
| 675 | + $heading_tag = isset( $attributes['headingTag'] ) && in_array( $attributes['headingTag'], $allowed_heading_tags, true ) | |
| 676 | + ? $attributes['headingTag'] | |
| 677 | + : 'h2'; | |
| 678 | + | |
| 667 | 679 | $seperator = ''; |
| 668 | 680 | |
| 669 | 681 | if ( isset( $attributes['separatorStyle'] ) |
| 670 | 682 | && 'none' !== $attributes['separatorStyle'] |
| @@ -678,9 +690,9 @@ | ||
| 678 | 690 | $heading_text = 'above-heading' === $attributes['separatorPosition'] ? $seperator : ''; |
| 679 | 691 | $attributes['headingId'] = isset( $attributes['headingId'] ) ? "id='{$attributes['headingId']}'" : ''; |
| 680 | 692 | $heading_text .= sprintf( |
| 681 | 693 | '<%1$s class="uagb-heading-text" %3$s>%2$s</%1$s>', |
| 682 | - esc_attr( $attributes['headingTag'] ), | |
| 694 | + esc_attr( $heading_tag ), | |
| 683 | 695 | $attributes['headingTitle'], |
| 684 | 696 | esc_attr( $attributes['headingId'] ) |
| 685 | 697 | ); |
| 686 | 698 | $heading_text .= 'below-heading' === $attributes['separatorPosition'] ? $seperator : ''; |
| @@ -698,13 +710,25 @@ | ||
| 698 | 710 | } |
| 699 | 711 | |
| 700 | 712 | $conditional_class = apply_filters( 'srfm_conditional_logic_classes', $form_id, $block_id ); |
| 701 | 713 | |
| 714 | + $filter_classes = apply_filters( 'srfm_field_classes', '', [ 'attributes' => $attributes ] ); | |
| 715 | + $field_config = apply_filters( | |
| 716 | + 'srfm_field_config', | |
| 717 | + [], | |
| 718 | + [ | |
| 719 | + 'attributes' => $attributes, | |
| 720 | + 'blockName' => 'srfm/advanced-heading', | |
| 721 | + ] | |
| 722 | + ); | |
| 723 | + $field_config = $field_config ? htmlspecialchars( Helper::get_string_value( wp_json_encode( $field_config, JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE ) ), ENT_QUOTES, 'UTF-8' ) : ''; | |
| 724 | + | |
| 702 | 725 | $main_classes = [ |
| 703 | 726 | 'wp-block-uagb-advanced-heading', |
| 704 | 727 | 'uagb-block', |
| 705 | 728 | 'uagb-block-' . $block_id, |
| 706 | 729 | $conditional_class, |
| 730 | + $filter_classes, | |
| 707 | 731 | ]; |
| 708 | 732 | |
| 709 | 733 | if ( isset( $attributes['className'] ) ) { |
| 710 | 734 | $main_classes[] = $attributes['className']; |
| @@ -711,9 +735,9 @@ | ||
| 711 | 735 | } |
| 712 | 736 | |
| 713 | 737 | ob_start(); |
| 714 | 738 | ?> |
| 715 | - <<?php echo esc_attr( $element ); ?> data-block-id="<?php echo esc_attr( $block_id ); ?>" class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>"> | |
| 739 | + <<?php echo esc_attr( $element ); ?> data-block-id="<?php echo esc_attr( $block_id ); ?>" class="<?php echo esc_attr( implode( ' ', $main_classes ) ); ?>" <?php echo ! empty( $field_config ) ? "data-field-config='" . esc_attr( $field_config ) . "'" : ''; ?>> | |
| 716 | 740 | <?php |
| 717 | 741 | if ( $attributes['headingDescToggle'] |
| 718 | 742 | && 'above-heading' === $attributes['headingDescPosition'] |
| 719 | 743 | ) { |