| @@ -74,24 +74,29 @@ | ||
| 74 | 74 | if (!$this->is_secured_nonce('upk_additional_features_nonce_action', 'upk_additional_features_nonce_field', $post_id)) { |
| 75 | 75 | return $post_id; |
| 76 | 76 | } |
| 77 | 77 | |
| 78 | - $video_link = isset($_POST['_upk_video_link_meta_key']) ? sanitize_text_field($_POST['_upk_video_link_meta_key']) : ''; | |
| 78 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read. | |
| 79 | + $video_link = isset($_POST['_upk_video_link_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_video_link_meta_key'])) : ''; | |
| 79 | 80 | update_post_meta($post_id, '_upk_video_link_meta_key', $video_link); |
| 80 | 81 | |
| 81 | - $audio_link = isset($_POST['_upk_audio_link_meta_key']) ? sanitize_text_field($_POST['_upk_audio_link_meta_key']) : ''; | |
| 82 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read. | |
| 83 | + $audio_link = isset($_POST['_upk_audio_link_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_audio_link_meta_key'])) : ''; | |
| 82 | 84 | update_post_meta($post_id, '_upk_audio_link_meta_key', $audio_link); |
| 83 | 85 | |
| 84 | - $audio_title = isset($_POST['_upk_audio_title_meta_key']) ? sanitize_text_field($_POST['_upk_audio_title_meta_key']) : ''; | |
| 86 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read. | |
| 87 | + $audio_title = isset($_POST['_upk_audio_title_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_audio_title_meta_key'])) : ''; | |
| 85 | 88 | update_post_meta($post_id, '_upk_audio_title_meta_key', $audio_title); |
| 86 | 89 | |
| 87 | - $artist_name = isset($_POST['_upk_artist_name_meta_key']) ? sanitize_text_field($_POST['_upk_artist_name_meta_key']) : ''; | |
| 90 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in is_secured_nonce() above before any $_POST is read. | |
| 91 | + $artist_name = isset($_POST['_upk_artist_name_meta_key']) ? sanitize_text_field(wp_unslash($_POST['_upk_artist_name_meta_key'])) : ''; | |
| 88 | 92 | update_post_meta($post_id, '_upk_artist_name_meta_key', $artist_name); |
| 89 | 93 | } |
| 90 | 94 | |
| 91 | 95 | |
| 92 | 96 | protected function is_secured_nonce($action, $nonce_field, $post_id) { |
| 93 | - $nonce = isset($_POST[$nonce_field]) ? sanitize_text_field($_POST[$nonce_field]) : ''; | |
| 97 | + // phpcs:ignore WordPress.Security.NonceVerification.Missing -- reading the nonce value itself; it is validated with wp_verify_nonce() immediately below. | |
| 98 | + $nonce = isset($_POST[$nonce_field]) ? sanitize_text_field(wp_unslash($_POST[$nonce_field])) : ''; | |
| 94 | 99 | if ($nonce == '') { |
| 95 | 100 | return false; |
| 96 | 101 | } elseif (!wp_verify_nonce($nonce, $action)) { |
| 97 | 102 | return false; |