Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions app/Hametuha/Thread/UI/CommentForm.php
Original file line number Diff line number Diff line change
Expand Up @@ -84,8 +84,7 @@ public function comment_display( $comment, $args, $depth, $close = false, $echo
$html .= "</{$tag}>";
}
if ( $echo ) {
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML composed from comment_class() and the escaped comment-loop template part.
echo $html;
echo wp_kses_post( $html );

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

懸念点

wp_kses_post( $html ) を $html 全体に対して適用すると、コメント本文(comment_text())に含まれる oEmbed(YouTube や Vimeo などの <iframe> 埋め込み) や、特定の安全な HTML 要素・属性がすべて削除されてしまいます。
WordPress のデフォルトの post コンテキスト(wp_kses_post)では、セキュリティ上の理由から <iframe> タグが許可されていないためです。

また、comment-loop.php 内の各パーツはすでに個別に適切にエスケープされているため、結合された $html 全体に対して再度 wp_kses_post() を実行することは、パフォーマンス面でも不要なオーバーヘッド(二重サニタイズ)となります。

解決策

WordPress.org の late escape 指摘に対応しつつ、oEmbed などの <iframe> 埋め込みを壊さないようにするためには、wp_kses() を使用して iframe タグを明示的に許可したカスタム許可リストを渡す方法が推奨されます。

			$allowed_html = wp_kses_allowed_html( 'post' );
			$allowed_html['iframe'] = [
				'src'             => true,
				'width'           => true,
				'height'          => true,
				'frameborder'     => true,
				'allowfullscreen' => true,
				'allow'           => true,
				'style'           => true,
				'class'           => true,
				'id'              => true,
			];
			echo wp_kses( $html, $allowed_html );

}
return $html;
}
Expand Down
5 changes: 1 addition & 4 deletions template-parts/button-comment-post.php
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,7 @@
<div class="hamethread-post-comment">
<?php if ( hamethread_current_user_can_comment() ) : ?>
<button class="button hamethread-post-button" data-hamethread="comment" data-end-point="<?php echo esc_attr( sprintf( 'comment/%d/new', get_the_ID() ) ); ?>">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'plus-alt' );
?>
<?php echo wp_kses_post( hamethread_icon( 'plus-alt' ) ); ?>
<?php esc_html_e( 'Post Comment', 'hamethread' ); ?>
</button>
<?php else : ?>
Expand Down
6 changes: 2 additions & 4 deletions template-parts/button-thread-controller.php
Original file line number Diff line number Diff line change
Expand Up @@ -58,16 +58,14 @@
<div class="hamethread-controller-dropdown">
<button class="hamethread-controller-toggle" type="button" aria-expanded="false" aria-haspopup="true">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'cog' );
echo wp_kses_post( hamethread_icon( 'cog' ) );
?>
<span class="screen-reader-text"><?php esc_html_e( 'Thread actions', 'hamethread' ); ?></span>
</button>
<ul class="hamethread-controller-menu">
<?php
foreach ( $lists as $list ) {
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Composed list-item HTML escaped at source above (esc_url/esc_attr/esc_html).
echo $list;
echo wp_kses_post( $list );
}
?>
</ul>
Expand Down
20 changes: 5 additions & 15 deletions template-parts/comment-loop.php
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,7 @@
<div class="hamethread-controller">
<div class="hamethread-controller-dropdown">
<button class="hamethread-controller-toggle" type="button" aria-expanded="false" aria-haspopup="true">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'cog' );
?>
<?php echo wp_kses_post( hamethread_icon( 'cog' ) ); ?>
<span class="screen-reader-text"><?php esc_html_e( 'Comment actions', 'hamethread' ); ?></span>
</button>
<ul class="hamethread-controller-menu">
Expand Down Expand Up @@ -42,11 +39,8 @@
<header class="hamethread-comment-header">
<span class="hamethread-comment-author"><?php comment_author( $comment ); ?></span>
<?php $hamethread_label_class = hamethread_commentor_label_class( $comment, 'hamethread-comment-role' ); ?>
<span class="<?php echo $hamethread_label_class; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Already escaped via esc_attr() in hamethread_commentor_label_class(). ?>">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_commentor_label().
echo hamethread_commentor_label( $comment );
?>
<span class="<?php echo esc_attr( $hamethread_label_class ); ?>">
<?php echo wp_kses_post( hamethread_commentor_label( $comment ) ); ?>
</span>
<span class="hamethread-comment-date">
<?php comment_date( '', $comment ); ?>
Expand All @@ -58,10 +52,7 @@
<div class="hamethread-comment-content">
<?php if ( hamethread_is_best_answer( $comment ) ) : ?>
<p class="hamethread-comment-best-answer">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'star' );
?>
<?php echo wp_kses_post( hamethread_icon( 'star' ) ); ?>
<strong><?php esc_html_e( 'Best Answer', 'hamethread' ); ?></strong>
</p>
<?php endif; ?>
Expand All @@ -70,8 +61,7 @@
<footer class="hamethread-comment-actions">
<?php
foreach ( hamethread_comment_actions( $comment ) as $action ) {
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML (incl. data-* attrs) escaped at source in hamethread_comment_actions().
echo $action;
echo wp_kses_post( $action );
}
?>
</footer>
Expand Down
3 changes: 1 addition & 2 deletions template-parts/comments.php
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,7 @@
?>

<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_pagination_html() (via hamethread_comment_links()).
echo hamethread_comment_links();
echo wp_kses_post( hamethread_comment_links() );
?>
<?php endif; ?>
</ul>
Expand Down
3 changes: 1 addition & 2 deletions template-parts/form-comment.php
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,7 @@
</cite>
<div class="hamethread-form-quote-content">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Content escaped via esc_html() before wpautop() wraps it in safe <p> tags.
echo wpautop( esc_html( $parent_comment->comment_content ) );
echo wp_kses_post( wpautop( esc_html( $parent_comment->comment_content ) ) );
?>
</div>
</blockquote>
Expand Down
15 changes: 5 additions & 10 deletions template-parts/woocommerce-my-account.php
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,7 @@
<h5 class="hamethread-my-threads-title">
<?php if ( 'private' === get_post_status() ) : ?>
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'lock' );
echo wp_kses_post( hamethread_icon( 'lock' ) );
?>
<?php endif; ?>
<a href="<?php the_permalink(); ?>"><?php the_title(); ?></a>
Expand All @@ -35,22 +34,19 @@
</div>
<p class="hamethread-my-threads-meta">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'admin-comments' );
echo wp_kses_post( hamethread_icon( 'admin-comments' ) );
?>
<?php comments_number(); ?>
<?php if ( hamethread_is_resolved() ) : ?>
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'yes-alt' );
echo wp_kses_post( hamethread_icon( 'yes-alt' ) );
?>
<?php esc_html_e( 'Resolved', 'hamethread' ); ?>
<?php endif; ?>
</p>
<small class="hamethread-my-threads-updated">
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Safe HTML escaped in hamethread_icon().
echo hamethread_icon( 'clock' );
echo wp_kses_post( hamethread_icon( 'clock' ) );
?>
<?php
esc_html_e( 'Last Updated: ', 'hamethread' );
Expand All @@ -64,8 +60,7 @@
?>
</ul>
<?php
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Trusted pagination HTML provided via the hamethread_pagination filter.
echo apply_filters( 'hamethread_pagination', '', $query );
echo wp_kses_post( apply_filters( 'hamethread_pagination', '', $query ) );
?>
<?php
// Query has no post.
Expand Down
Loading