Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -175,6 +175,11 @@ public function data_invalid_content() {
// An unclosed one stops the tokenizer reporting at all, and nesting hides the wrapper from itself.
array( 'rest_pattern_interactivity_directive', "$two_paragraphs\n\n<!-- wp:paragraph -->\n<p>Three.<script><span data-wp-interactive=\"wporg/patterns\" data-wp-init=\"actions.go\">x</span></p>\n<!-- /wp:paragraph -->" ),
array( 'rest_pattern_interactivity_directive', "$two_paragraphs\n\n<!-- wp:paragraph -->\n<p>Three.<style><style><style><span data-wp-interactive=\"wporg/patterns\" data-wp-init=\"actions.go\">x</span></style></p>\n<!-- /wp:paragraph -->" ),

// `<svg>` is foreign content rather than a raw-text element, so the nested `<script>` hides the anchor too.
array( 'rest_pattern_interactivity_directive', "$two_paragraphs\n\n<!-- wp:html -->\n<svg><script><a href=\"#\" data-wp-interactive=\"core/query\" data-wp-context='{\"url\":\"javascript:alert(1)\"}' data-wp-bind--href=\"context.url\">x</a></svg>\n<!-- /wp:html -->" ),
array( 'rest_pattern_interactivity_directive', "$two_paragraphs\n\n<!-- wp:html -->\n<svg><script><a href=\"#\" data-wp-interactive=\"core/query\" data-wp-bind--href=\"context.url\">x</a></script></svg>\n<!-- /wp:html -->" ),

// A block delimiter is a comment, so the directive in its attribute JSON is not a tag either.
array( 'rest_pattern_interactivity_directive', "$two_paragraphs\n\n<!-- wp:categories {\"displayAsDropdown\":true,\"showLabel\":true,\"label\":\"<span data-wp-interactive=\\u0022wporg/patterns\\u0022 data-wp-init=\\u0022actions.go\\u0022>x</span>\"} /-->" ),
// The same attribute with its angle brackets JSON-escaped, so the stored delimiter holds no markup.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,10 +47,12 @@ public function test_ordinary_content_is_allowed( string $html ): void {
*/
public function data_disallowed_content(): array {
return array(
'directive in inner HTML' => array( "<!-- wp:paragraph -->\n<p><span data-wp-interactive=\"x\" data-wp-init=\"actions.go\">t</span></p>\n<!-- /wp:paragraph -->" ),
'directive in a raw-text el' => array( "<!-- wp:paragraph -->\n<p><style><span data-wp-interactive=\"x\" data-wp-init=\"actions.go\">t</span></style></p>\n<!-- /wp:paragraph -->" ),
'directive in an attribute' => array( '<!-- wp:heading {"placeholder":"<span data-wp-interactive="x" data-wp-init="actions.go">t</span>"} -->' . "\n<h2>t</h2>\n<!-- /wp:heading -->" ),
'disallowed block' => array( '<!-- wp:shortcode -->[gallery]<!-- /wp:shortcode -->' ),
'directive in inner HTML' => array( "<!-- wp:paragraph -->\n<p><span data-wp-interactive=\"x\" data-wp-init=\"actions.go\">t</span></p>\n<!-- /wp:paragraph -->" ),
'directive in a raw-text el' => array( "<!-- wp:paragraph -->\n<p><style><span data-wp-interactive=\"x\" data-wp-init=\"actions.go\">t</span></style></p>\n<!-- /wp:paragraph -->" ),
// `<svg>` opens foreign content, so the tokenizer reads the nested `<script>` as text while KSES keeps what it held.
'directive in foreign content' => array( "<!-- wp:html -->\n<svg><script><a href=\"#\" data-wp-interactive=\"x\" data-wp-bind--href=\"context.url\">t</a></svg>\n<!-- /wp:html -->" ),
'directive in an attribute' => array( '<!-- wp:heading {"placeholder":"<span data-wp-interactive="x" data-wp-init="actions.go">t</span>"} -->' . "\n<h2>t</h2>\n<!-- /wp:heading -->" ),
'disallowed block' => array( '<!-- wp:shortcode -->[gallery]<!-- /wp:shortcode -->' ),
);
}

Expand Down