Skip to content

WP_Theme_JSON: Add nested indexed array schema sanitization capabilities.#5957

Closed
matiasbenedetto wants to merge 2 commits intoWordPress:trunkfrom
matiasbenedetto:add/wp-theme-json-indexed-array-sanitization
Closed

WP_Theme_JSON: Add nested indexed array schema sanitization capabilities.#5957
matiasbenedetto wants to merge 2 commits intoWordPress:trunkfrom
matiasbenedetto:add/wp-theme-json-indexed-array-sanitization

Conversation

@matiasbenedetto
Copy link
Copy Markdown

@matiasbenedetto matiasbenedetto commented Jan 26, 2024

What?

  • Add nested indexed array schema sanitization capabilities to the WP_Theme_JSON class.
  • Add settings.typography.fontFamilies validation in WP_Theme_JSON
  • Add unit tests.

Why?

Currently, WP_Theme_JSON sanitization is not able to sanitize data contained on indexed arrays. So certain data from theme.json, for example, settings.typography.fontFamilies which is a JSON array, cannot be sanitized. Why? because when parsing the JSON data WP_Theme_JSON class translates JSON arrays into PHP indexed arrays and the it is not capable of sanitizing that kind of data.


Trac ticket: https://core.trac.wordpress.org/ticket/60360#


This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.

@github-actions
Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • The Plugin and Theme Directories cannot be accessed within Playground.
  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

Copy link
Copy Markdown
Member

@mukeshpanchal27 mukeshpanchal27 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fix PHPCS

Co-authored-by: Mukesh Panchal <mukeshpanchal27@users.noreply.github.com>
@youknowriad
Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants