| @@ -42,11 +42,9 @@ | ||
| 42 | 42 | * |
| 43 | 43 | * @param Redirect_Helper $redirect The redirect helper. |
| 44 | 44 | * @param Robots_Helper $robots The robots helper. |
| 45 | 45 | */ |
| 46 | - public function __construct( | |
| 47 | - Redirect_Helper $redirect, Robots_Helper $robots | |
| 48 | - ) { | |
| 46 | + public function __construct( Redirect_Helper $redirect, Robots_Helper $robots ) { | |
| 49 | 47 | $this->redirect = $redirect; |
| 50 | 48 | $this->robots = $robots; |
| 51 | 49 | } |
| 52 | 50 | |
| @@ -63,9 +61,9 @@ | ||
| 63 | 61 | \add_action( 'template_redirect', [ $this, 'replytocom_redirect' ], 1 ); |
| 64 | 62 | } |
| 65 | 63 | |
| 66 | 64 | // When users view a reply to a comment, this URL parameter is set. These should never be indexed separately. |
| 67 | - if ( $this->has_replytocom_parameter() ) { | |
| 65 | + if ( $this->get_replytocom_parameter() !== null ) { | |
| 68 | 66 | \add_filter( 'wpseo_robots_array', [ $this->robots, 'set_robots_no_index' ] ); |
| 69 | 67 | } |
| 70 | 68 | } |
| 71 | 69 | |
| @@ -73,12 +71,17 @@ | ||
| 73 | 71 | * Checks if the url contains the ?replytocom query parameter. |
| 74 | 72 | * |
| 75 | 73 | * @codeCoverageIgnore Wraps the filter input. |
| 76 | 74 | * |
| 77 | - * @return string The value of replytocom. | |
| 75 | + * @return string|null The value of replytocom or null if it does not exist. | |
| 78 | 76 | */ |
| 79 | - protected function has_replytocom_parameter() { | |
| 80 | - return \filter_input( \INPUT_GET, 'replytocom' ); | |
| 77 | + protected function get_replytocom_parameter() { | |
| 78 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Reason: We are not processing form information. | |
| 79 | + if ( isset( $_GET['replytocom'] ) && \is_string( $_GET['replytocom'] ) ) { | |
| 80 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Reason: We are not processing form information. | |
| 81 | + return \sanitize_text_field( \wp_unslash( $_GET['replytocom'] ) ); | |
| 82 | + } | |
| 83 | + return null; | |
| 81 | 84 | } |
| 82 | 85 | |
| 83 | 86 | /** |
| 84 | 87 | * Removes the ?replytocom variable from the link, replacing it with a #comment-<number> anchor. |