| @@ -16,13 +16,16 @@ | ||
| 16 | 16 | */ |
| 17 | 17 | public static function async_script($href, $print = true) { |
| 18 | 18 | $wpo_minify_options = wp_optimize_minify_config()->get(); |
| 19 | 19 | $tag = '<script>' . "\n"; |
| 20 | + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : ''; | |
| 21 | + $tag .= 'var wpo_server_info_js = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n"; | |
| 22 | + | |
| 20 | 23 | $exclude_js_from_page_speed_tools = $wpo_minify_options['exclude_js_from_page_speed_tools']; |
| 21 | 24 | $enable_defer_js = $wpo_minify_options['enable_defer_js']; |
| 22 | 25 | $is_conditional_loading = $exclude_js_from_page_speed_tools && 'all' !== $enable_defer_js; |
| 23 | 26 | if ($is_conditional_loading) { |
| 24 | - $tag .= 'if (!navigator.userAgent.match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 27 | + $tag .= 'if (!(navigator.userAgent + " " + wpo_server_info_js.user_agent).match(/' . implode("|", $wpo_minify_options['ualist']) .'/i)) {' . "\n"; | |
| 25 | 28 | } |
| 26 | 29 | $tag .= " loadAsync('$href', null);" . "\n"; |
| 27 | 30 | if ($is_conditional_loading) { |
| 28 | 31 | $tag .= '}'; |
| @@ -29,9 +32,9 @@ | ||
| 29 | 32 | } |
| 30 | 33 | $tag .= '</script>' . "\n"; |
| 31 | 34 | |
| 32 | 35 | if ($print) { |
| 33 | - echo $tag; | |
| 36 | + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 34 | 37 | } else { |
| 35 | 38 | return $tag; |
| 36 | 39 | } |
| 37 | 40 | } |
| @@ -43,13 +46,15 @@ | ||
| 43 | 46 | * @param string $media |
| 44 | 47 | * @return void |
| 45 | 48 | */ |
| 46 | 49 | public static function async_style($href, $media = 'all') { |
| 47 | - echo '<link rel="preload" href="'.$href.'" as="style" media="'.$media.'" onload="this.onload=null;this.rel=\'stylesheet\'">' . "\n"; | |
| 50 | + // phpcs:disable WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable for this function | |
| 51 | + echo '<link rel="preload" href="'.esc_url($href).'" as="style" media="'.esc_attr($media).'" onload="this.onload=null;this.rel=\'stylesheet\'">' . "\n"; | |
| 48 | 52 | // fix for firefox not supporting preload |
| 49 | - echo '<link rel="stylesheet" href="'.$href.'" media="'.$media.'">' . "\n"; | |
| 50 | - echo '<noscript><link rel="stylesheet" href="'.$href.'" media="'.$media.'"></noscript>' . "\n"; | |
| 51 | - echo '<!--[if IE]><link rel="stylesheet" href="'.$href.'" media="'.$media.'"><![endif]-->' . "\n"; | |
| 53 | + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'">' . "\n"; | |
| 54 | + echo '<noscript><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"></noscript>' . "\n"; | |
| 55 | + echo '<!--[if IE]><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"><![endif]-->' . "\n"; | |
| 56 | + // phpcs:enable | |
| 52 | 57 | } |
| 53 | 58 | |
| 54 | 59 | /** |
| 55 | 60 | * Print a style that will be loaded by JS |
| @@ -61,11 +66,14 @@ | ||
| 61 | 66 | $wpo_minify_options = wp_optimize_minify_config()->get(); |
| 62 | 67 | // make a stylesheet, hide from PageSpeedIndex |
| 63 | 68 | $cssguid = 'wpo_min'.hash('adler32', $href); |
| 64 | 69 | $tag = '<script>' . "\n"; |
| 70 | + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : ''; | |
| 71 | + $tag .= 'var wpo_server_info_css = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n"; | |
| 72 | + | |
| 65 | 73 | $exclude_css_from_page_speed_tools = $wpo_minify_options['exclude_css_from_page_speed_tools']; |
| 66 | 74 | if ($exclude_css_from_page_speed_tools) { |
| 67 | - $tag .= 'if (!navigator.userAgent.match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 75 | + $tag .= 'if (!(navigator.userAgent + " " + wpo_server_info_css.user_agent).match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 68 | 76 | } |
| 69 | 77 | $tag .= ' var '.$cssguid.'=document.createElement("link");'.$cssguid.'.rel="stylesheet",'.$cssguid.'.type="text/css",'.$cssguid.'.media="async",'.$cssguid.'.href="'.$href.'",'.$cssguid.'.onload=function() {'.$cssguid.'.media="all"},document.getElementsByTagName("head")[0].appendChild('.$cssguid.');' . "\n"; |
| 70 | 78 | if ($exclude_css_from_page_speed_tools) { |
| 71 | 79 | $tag .= '}'; |
| @@ -70,9 +78,9 @@ | ||
| 70 | 78 | if ($exclude_css_from_page_speed_tools) { |
| 71 | 79 | $tag .= '}'; |
| 72 | 80 | } |
| 73 | 81 | $tag .= '</script>' . "\n"; |
| 74 | - echo $tag; | |
| 82 | + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 75 | 83 | } |
| 76 | 84 | |
| 77 | 85 | /** |
| 78 | 86 | * Inline a single style |
| @@ -90,9 +98,9 @@ | ||
| 90 | 98 | $json = WP_Optimize_Minify_Cache_Functions::get_transient($tkey); |
| 91 | 99 | if (false === $json) { |
| 92 | 100 | $json = WP_Optimize_Minify_Functions::download_and_minify($href, null, $wpo_minify_options['enable_css_minification'], 'css', $handle); |
| 93 | 101 | if ($wpo_minify_options['debug']) { |
| 94 | - echo "<!-- wpo_min DEBUG: Uncached file processing now for $href -->" . "\n"; | |
| 102 | + echo "<!-- wpo_min DEBUG: Uncached file processing now for " . esc_html($href) . " -->" . "\n"; | |
| 95 | 103 | } |
| 96 | 104 | WP_Optimize_Minify_Cache_Functions::set_transient($tkey, $json); |
| 97 | 105 | } |
| 98 | 106 | |
| @@ -103,11 +111,11 @@ | ||
| 103 | 111 | // https://developers.google.com/web/updates/2016/02/font-display |
| 104 | 112 | $res['code'] = str_ireplace('font-style:normal;', 'font-display:block;font-style:normal;', $res['code']); |
| 105 | 113 | |
| 106 | 114 | // inline css or fail |
| 107 | - if (false != $res['status']) { | |
| 115 | + if ($res['status']) { | |
| 108 | 116 | echo '<style type="text/css" media="all">' . "\n"; |
| 109 | - echo $res['code'] . "\n"; | |
| 117 | + echo $res['code'] . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- This is already escaped | |
| 110 | 118 | echo '</style>' . "\n"; |
| 111 | 119 | return true; |
| 112 | 120 | } else { |
| 113 | 121 | return false; |
| @@ -120,9 +128,9 @@ | ||
| 120 | 128 | * @param string $href |
| 121 | 129 | * @return void |
| 122 | 130 | */ |
| 123 | 131 | public static function style($href) { |
| 124 | - echo '<link rel="stylesheet" href="'.$href.'" media="all">' . "\n"; | |
| 132 | + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="all">' . "\n"; // phpcs:ignore WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable here | |
| 125 | 133 | } |
| 126 | 134 | |
| 127 | 135 | /** |
| 128 | 136 | * Write header |
| @@ -140,13 +148,13 @@ | ||
| 140 | 148 | * Write CSS |
| 141 | 149 | * |
| 142 | 150 | * @param string $file |
| 143 | 151 | * @param string $code |
| 144 | - * @param string $log | |
| 152 | + * @param array $log | |
| 145 | 153 | * @return void |
| 146 | 154 | */ |
| 147 | 155 | public static function write_combined_asset($file, $code, $log) { |
| 148 | - file_put_contents($file.'.json', json_encode($log)); | |
| 156 | + file_put_contents($file.'.json', wp_json_encode($log)); | |
| 149 | 157 | file_put_contents($file, $code); |
| 150 | 158 | // permissions |
| 151 | 159 | WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file.'.json'); |
| 152 | 160 | WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file); |
| @@ -169,9 +177,9 @@ | ||
| 169 | 177 | */ |
| 170 | 178 | public static function add_load_async() { |
| 171 | 179 | $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string(); |
| 172 | 180 | $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadAsync$min_or_not_internal.js"); |
| 173 | - echo "<script>$contents</script>\n"; | |
| 181 | + echo "<script>$contents</script>\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 174 | 182 | } |
| 175 | 183 | |
| 176 | 184 | /** |
| 177 | 185 | * Defer CSS globally from the header (order matters) |
| @@ -181,7 +189,7 @@ | ||
| 181 | 189 | */ |
| 182 | 190 | public static function add_load_css() { |
| 183 | 191 | $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string(); |
| 184 | 192 | $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadCSS$min_or_not_internal.js"); |
| 185 | - echo "<script>$contents</script>" . "\n"; | |
| 193 | + echo "<script>$contents</script>" . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 186 | 194 | } |
| 187 | 195 | } |