Repository navigation
Pattern directory: extend validation test coverage - #773
Conversation
The directive checks already scan both the submitted markup and its sanitised form, but the data providers only exercised elements the tokenizer skips in the HTML namespace. Add the foreign-content equivalent, where a nested raw-text element hides its contents from the tokenizer for a different reason, and cover the same shape on the translated-content path that shares the helper. Tests only; no change to validation behaviour. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Late to this one (already merged), but a note for whoever touches these providers next. The rows do what the description says — they fail if the sanitised-markup pass is removed — so the coverage is real. The stated reason isn't, though: While looking at it I found the shape that genuinely isn't covered, which I'd rather not spell out here. Short version: the two-pass approach works because the sanitiser removes the element that did the hiding, and that isn't true for every such element — for the ones it keeps, both passes miss. Sent the detail and a suggested fix through the usual channel; happy to open a follow-up PR if that's easier. |
|
@bor0 Please feel free to just fix it |
|
Done — #777. It turned out the cleanest fix was to stop reading the content as markup at all. The rule is that a pattern may not carry Your rows are kept as regression coverage, with the explanations corrected. CI is green. One thing worth your call in the PR: it widens the rule, so prose that merely mentions |
…arkup (#777) `content_has_block_directives()` tokenized the content, and the sanitised copy of it, looking for a tag with a `data-wp-*` attribute. That is narrower than the rule it enforces: a pattern may not carry the marker at all. `WP_HTML_Tag_Processor` does not descend into an element whose contents are text, so a tag inside one is invisible to it. Scanning the `wp_kses_post()` form as well covers that only where KSES removes the element that did the hiding. It removes `<script>` and `<style>`, which is why the existing cases are caught, and it keeps `<title>` and `<textarea>`, which hold their contents as text just the same -- so for those, neither pass ever reads the tag and the check returns false. Test the marker directly. It is what the helper already did as a fast-path negative, it cannot be hidden by an element boundary, and it drops the sanitise-and-tokenize pass. The widening this brings is deliberate: content that merely mentions `data-wp-` in prose is now refused too. Checked against the fields the validator reads (`post_content`, `post_title`, `post_excerpt`) on 600 published patterns from the public API and the 1,858 in the seed exports -- none carries the marker. The 40 of 600 that do carry it hold it in the rendered output core emits for blocks like `core/details`, which this never reads. Tests: rows for `<title>`, `<textarea>` and the marker in plain prose, in both the submission and translated-content providers; the first two fail before this change. The comments on the existing rows described tokenizer behaviour that no longer decides the outcome, and the two added in #773 described it incorrectly -- `<svg>` is not a raw-text element and the tag processor reads straight into it; the nested `<script>` was doing the hiding. Rows kept as regression coverage, explanations corrected. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Follow-up test coverage for the content validation helpers in
pattern-validation.php.content_has_block_directives()scans both the submitted markup and its sanitisedform, since some elements hide their contents from
WP_HTML_Tag_Processorwhile KSESdrops the wrapper on save and keeps what it held. The data providers covered that for
raw-text elements in the HTML namespace, but not for the foreign-content case, which
reaches the same end state by a different route and so is worth pinning separately.
pattern-content-validation-test.php— two cases covering the foreign-content shape,closed and unclosed.
pattern-translated-content-test.php— the same shape on the translated-content path,which shares the helper but is a separate entry point.
Both cases fail if the sanitised-markup pass is removed from the helper, so they pin the
current behaviour rather than restating it.
Tests only; no change to validation behaviour. Full PHPUnit suite (226 tests) and
phpcsboth pass locally.
🤖 Generated with Claude Code