Skip to content

Commit 7c9b76b

Browse files
committed
Privacy: Correctly escape page title in get_the_privacy_policy_link().
Update the escaping of the page title used in `get_the_privacy_policy_link()` to use a sub-set of permitted tags via `wp_kses()` rather than `esc_html()`. WordPress permits the use of HTML tags within a page title so `esc_html()` isn't appropriate as it renders the HTML tags with html encoded characters. Props shailu25, huzaifaalmesbah, mukesh27, hbhalodia, joedolson, masteradhoc, noruzzaman, ozgursar, sabernhardt, westonruter, wildworks. Fixes #64748. git-svn-id: https://develop.svn.wordpress.org/trunk@64092 602fd350-edb4-49c9-b593-d223f7449a82
1 parent 4b2afb9 commit 7c9b76b

2 files changed

Lines changed: 46 additions & 1 deletion

File tree

‎src/wp-includes/link-template.php‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4848,7 +4848,16 @@ function get_the_privacy_policy_link( $before = '', $after = '' ) {
48484848
$link = sprintf(
48494849
'<a class="privacy-policy-link" href="%s" rel="privacy-policy">%s</a>',
48504850
esc_url( $privacy_policy_url ),
4851-
esc_html( $page_title )
4851+
wp_kses(
4852+
$page_title,
4853+
array(
4854+
'strong' => array( 'class' => true ),
4855+
'em' => array( 'class' => true ),
4856+
'b' => array( 'class' => true ),
4857+
'i' => array( 'class' => true ),
4858+
'span' => array( 'class' => true ),
4859+
)
4860+
)
48524861
);
48534862
}
48544863

‎tests/phpunit/tests/link/getThePrivacyPolicyLink.php‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,42 @@ public function test_get_the_privacy_policy_link_should_return_valid_link_when_p
7878
$this->assertStringEndsWith( '>' . WP_TESTS_DOMAIN . ' Privacy Policy</a>', $actual_link );
7979
}
8080

81+
/**
82+
* The function should allow only supported formatting in the privacy policy page title.
83+
*
84+
* Supported tags may include a class attribute; other tags and attributes are stripped.
85+
*
86+
* @ticket 64748
87+
*/
88+
public function test_get_the_privacy_policy_link_should_allow_supported_title_markup() {
89+
$privacy_policy_page_id = self::$privacy_policy_page_id;
90+
91+
/*
92+
* Run after core `the_title` formatting filters (e.g. wptexturize).
93+
*
94+
* A filter is used rather than updating the post to ensure that the script tag is
95+
* stripped from the output by KSES as intended.
96+
*/
97+
$filter = static function ( $title, $post_id ) use ( $privacy_policy_page_id ) {
98+
if ( (int) $privacy_policy_page_id === (int) $post_id ) {
99+
return '<strong class="privacy">Privacy</strong> <em class="policy">Policy</em> <b class="bold">Bold</b> <i class="italic">Italic</i> <span class="page-title">Page</span> <script>alert("test")</script>';
100+
}
101+
102+
return $title;
103+
};
104+
105+
add_filter( 'the_title', $filter, 20, 2 );
106+
107+
update_option( 'wp_page_for_privacy_policy', self::$privacy_policy_page_id );
108+
109+
$actual_link = get_the_privacy_policy_link();
110+
111+
$this->assertStringEndsWith(
112+
'><strong class="privacy">Privacy</strong> <em class="policy">Policy</em> <b class="bold">Bold</b> <i class="italic">Italic</i> <span class="page-title">Page</span> alert("test")</a>',
113+
$actual_link
114+
);
115+
}
116+
81117
/**
82118
* The function should prepend the supplied `$before` markup and append the
83119
* supplied `$after` markup when the `wp_page_for_privacy_policy` is configured.

0 commit comments

Comments
 (0)