| @@ -15,14 +15,26 @@ | ||
| 15 | 15 | * @return string|void |
| 16 | 16 | */ |
| 17 | 17 | public static function async_script($href, $print = true) { |
| 18 | 18 | $wpo_minify_options = wp_optimize_minify_config()->get(); |
| 19 | - $tag = '<script>if (!navigator.userAgent.match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 19 | + $tag = '<script>' . "\n"; | |
| 20 | + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : ''; | |
| 21 | + $tag .= 'var wpo_server_info_js = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n"; | |
| 22 | + | |
| 23 | + $exclude_js_from_page_speed_tools = $wpo_minify_options['exclude_js_from_page_speed_tools']; | |
| 24 | + $enable_defer_js = $wpo_minify_options['enable_defer_js']; | |
| 25 | + $is_conditional_loading = $exclude_js_from_page_speed_tools && 'all' !== $enable_defer_js; | |
| 26 | + if ($is_conditional_loading) { | |
| 27 | + $tag .= 'if (!(navigator.userAgent + " " + wpo_server_info_js.user_agent).match(/' . implode("|", $wpo_minify_options['ualist']) .'/i)) {' . "\n"; | |
| 28 | + } | |
| 20 | 29 | $tag .= " loadAsync('$href', null);" . "\n"; |
| 21 | - $tag .= '}</script>' . "\n"; | |
| 30 | + if ($is_conditional_loading) { | |
| 31 | + $tag .= '}'; | |
| 32 | + } | |
| 33 | + $tag .= '</script>' . "\n"; | |
| 22 | 34 | |
| 23 | 35 | if ($print) { |
| 24 | - echo $tag; | |
| 36 | + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 25 | 37 | } else { |
| 26 | 38 | return $tag; |
| 27 | 39 | } |
| 28 | 40 | } |
| @@ -34,13 +46,15 @@ | ||
| 34 | 46 | * @param string $media |
| 35 | 47 | * @return void |
| 36 | 48 | */ |
| 37 | 49 | public static function async_style($href, $media = 'all') { |
| 38 | - echo '<link rel="preload" href="'.$href.'" as="style" media="'.$media.'" onload="this.onload=null;this.rel=\'stylesheet\'" />' . "\n"; | |
| 50 | + // phpcs:disable WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable for this function | |
| 51 | + echo '<link rel="preload" href="'.esc_url($href).'" as="style" media="'.esc_attr($media).'" onload="this.onload=null;this.rel=\'stylesheet\'">' . "\n"; | |
| 39 | 52 | // fix for firefox not supporting preload |
| 40 | - echo '<link rel="stylesheet" href="'.$href.'" media="'.$media.'" />' . "\n"; | |
| 41 | - echo '<noscript><link rel="stylesheet" href="'.$href.'" media="'.$media.'" /></noscript>' . "\n"; | |
| 42 | - echo '<!--[if IE]><link rel="stylesheet" href="'.$href.'" media="'.$media.'" /><![endif]-->' . "\n"; | |
| 53 | + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'">' . "\n"; | |
| 54 | + echo '<noscript><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"></noscript>' . "\n"; | |
| 55 | + echo '<!--[if IE]><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"><![endif]-->' . "\n"; | |
| 56 | + // phpcs:enable | |
| 43 | 57 | } |
| 44 | 58 | |
| 45 | 59 | /** |
| 46 | 60 | * Print a style that will be loaded by JS |
| @@ -51,11 +65,22 @@ | ||
| 51 | 65 | public static function exclude_style($href) { |
| 52 | 66 | $wpo_minify_options = wp_optimize_minify_config()->get(); |
| 53 | 67 | // make a stylesheet, hide from PageSpeedIndex |
| 54 | 68 | $cssguid = 'wpo_min'.hash('adler32', $href); |
| 55 | - echo '<script>if (!navigator.userAgent.match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 56 | - echo ' var '.$cssguid.'=document.createElement("link");'.$cssguid.'.rel="stylesheet",'.$cssguid.'.type="text/css",'.$cssguid.'.media="async",'.$cssguid.'.href="'.$href.'",'.$cssguid.'.onload=function() {'.$cssguid.'.media="all"},document.getElementsByTagName("head")[0].appendChild('.$cssguid.');' . "\n"; | |
| 57 | - echo '}</script>' . "\n"; | |
| 69 | + $tag = '<script>' . "\n"; | |
| 70 | + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : ''; | |
| 71 | + $tag .= 'var wpo_server_info_css = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n"; | |
| 72 | + | |
| 73 | + $exclude_css_from_page_speed_tools = $wpo_minify_options['exclude_css_from_page_speed_tools']; | |
| 74 | + if ($exclude_css_from_page_speed_tools) { | |
| 75 | + $tag .= 'if (!(navigator.userAgent + " " + wpo_server_info_css.user_agent).match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n"; | |
| 76 | + } | |
| 77 | + $tag .= ' var '.$cssguid.'=document.createElement("link");'.$cssguid.'.rel="stylesheet",'.$cssguid.'.type="text/css",'.$cssguid.'.media="async",'.$cssguid.'.href="'.$href.'",'.$cssguid.'.onload=function() {'.$cssguid.'.media="all"},document.getElementsByTagName("head")[0].appendChild('.$cssguid.');' . "\n"; | |
| 78 | + if ($exclude_css_from_page_speed_tools) { | |
| 79 | + $tag .= '}'; | |
| 80 | + } | |
| 81 | + $tag .= '</script>' . "\n"; | |
| 82 | + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 58 | 83 | } |
| 59 | 84 | |
| 60 | 85 | /** |
| 61 | 86 | * Inline a single style |
| @@ -73,9 +98,9 @@ | ||
| 73 | 98 | $json = WP_Optimize_Minify_Cache_Functions::get_transient($tkey); |
| 74 | 99 | if (false === $json) { |
| 75 | 100 | $json = WP_Optimize_Minify_Functions::download_and_minify($href, null, $wpo_minify_options['enable_css_minification'], 'css', $handle); |
| 76 | 101 | if ($wpo_minify_options['debug']) { |
| 77 | - echo "<!-- wpo_min DEBUG: Uncached file processing now for $href -->" . "\n"; | |
| 102 | + echo "<!-- wpo_min DEBUG: Uncached file processing now for " . esc_html($href) . " -->" . "\n"; | |
| 78 | 103 | } |
| 79 | 104 | WP_Optimize_Minify_Cache_Functions::set_transient($tkey, $json); |
| 80 | 105 | } |
| 81 | 106 | |
| @@ -86,11 +111,11 @@ | ||
| 86 | 111 | // https://developers.google.com/web/updates/2016/02/font-display |
| 87 | 112 | $res['code'] = str_ireplace('font-style:normal;', 'font-display:block;font-style:normal;', $res['code']); |
| 88 | 113 | |
| 89 | 114 | // inline css or fail |
| 90 | - if (false != $res['status']) { | |
| 115 | + if ($res['status']) { | |
| 91 | 116 | echo '<style type="text/css" media="all">' . "\n"; |
| 92 | - echo $res['code'] . "\n"; | |
| 117 | + echo $res['code'] . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- This is already escaped | |
| 93 | 118 | echo '</style>' . "\n"; |
| 94 | 119 | return true; |
| 95 | 120 | } else { |
| 96 | 121 | return false; |
| @@ -103,9 +128,9 @@ | ||
| 103 | 128 | * @param string $href |
| 104 | 129 | * @return void |
| 105 | 130 | */ |
| 106 | 131 | public static function style($href) { |
| 107 | - echo '<link rel="stylesheet" href="'.$href.'" media="all">' . "\n"; | |
| 132 | + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="all">' . "\n"; // phpcs:ignore WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable here | |
| 108 | 133 | } |
| 109 | 134 | |
| 110 | 135 | /** |
| 111 | 136 | * Write header |
| @@ -123,13 +148,13 @@ | ||
| 123 | 148 | * Write CSS |
| 124 | 149 | * |
| 125 | 150 | * @param string $file |
| 126 | 151 | * @param string $code |
| 127 | - * @param string $log | |
| 152 | + * @param array $log | |
| 128 | 153 | * @return void |
| 129 | 154 | */ |
| 130 | 155 | public static function write_combined_asset($file, $code, $log) { |
| 131 | - file_put_contents($file.'.json', json_encode($log)); | |
| 156 | + file_put_contents($file.'.json', wp_json_encode($log)); | |
| 132 | 157 | file_put_contents($file, $code); |
| 133 | 158 | // permissions |
| 134 | 159 | WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file.'.json'); |
| 135 | 160 | WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file); |
| @@ -150,11 +175,11 @@ | ||
| 150 | 175 | * |
| 151 | 176 | * @return void |
| 152 | 177 | */ |
| 153 | 178 | public static function add_load_async() { |
| 154 | - $min_or_not_internal = (defined('SCRIPT_DEBUG') && SCRIPT_DEBUG) ? '' : '-'. str_replace('.', '-', WPO_VERSION). '.min'; | |
| 179 | + $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string(); | |
| 155 | 180 | $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadAsync$min_or_not_internal.js"); |
| 156 | - echo "<script>$contents</script>\n"; | |
| 181 | + echo "<script>$contents</script>\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 157 | 182 | } |
| 158 | 183 | |
| 159 | 184 | /** |
| 160 | 185 | * Defer CSS globally from the header (order matters) |
| @@ -162,9 +187,9 @@ | ||
| 162 | 187 | * |
| 163 | 188 | * @return void |
| 164 | 189 | */ |
| 165 | 190 | public static function add_load_css() { |
| 166 | - $min_or_not_internal = (defined('SCRIPT_DEBUG') && SCRIPT_DEBUG) ? '' : '-'. str_replace('.', '-', WPO_VERSION). '.min'; | |
| 191 | + $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string(); | |
| 167 | 192 | $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadCSS$min_or_not_internal.js"); |
| 168 | - echo "<script>$contents</script>" . "\n"; | |
| 193 | + echo "<script>$contents</script>" . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped | |
| 169 | 194 | } |
| 170 | 195 | } |