'; return; } $currency = $receipt_data['order']['currency'] ?? 'USD'; $formatted_data = Receipt_Data_Schema::format_money_fields( $receipt_data, $currency ); // Safety net: if a template uses {{#t}}...{{/t}} markers (from gallery source), // setting t = true makes Mustache pass the inner text through unchanged. $formatted_data['t'] = true; // Strip HTML comments — wp_kses_post removes the delimiters but leaves the text. $content = preg_replace( '//s', '', $content ); $flags = ENT_QUOTES | ENT_SUBSTITUTE; $mustache = new Mustache_Engine( array( 'entity_flags' => $flags, 'escape' => function ( $value ) use ( $flags ) { if ( \is_array( $value ) ) { return ''; } return htmlspecialchars( (string) $value, $flags, 'UTF-8' ); }, ) ); $output = $mustache->render( $content, $formatted_data ); // Swap / markup for placeholder tokens before sanitizing // (wp_kses_post would otherwise strip the unknown elements, leaving only the // bare value as text). The rasterized PNG tags are spliced back in // after sanitization, so their data: image URI never has to be whitelisted // in kses. Mirrors the client-side preview renderer. $barcode_images = array(); $output = Barcode_Image::replace_markup( $output, $barcode_images ); // Allow print-color-adjust in inline styles so background fills survive print. // wp_kses_post drops CSS properties not on the safe_style_css allowlist by default. $allow_print_color_adjust = function ( array $styles ): array { $styles[] = 'print-color-adjust'; $styles[] = '-webkit-print-color-adjust'; return $styles; }; add_filter( 'safe_style_css', $allow_print_color_adjust ); try { $sanitized = wp_kses_post( $output ); echo $barcode_images ? strtr( $sanitized, $barcode_images ) : $sanitized; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $sanitized is kses'd; spliced values are self-generated PNG tags. } finally { remove_filter( 'safe_style_css', $allow_print_color_adjust ); } } }