Skip to content

PoC: Using wp_kses to allow-list expected markup - #237

Draft
matt-bernhardt wants to merge 2 commits into
lnhu-225from
lnhu-225-alt-b
Draft

matt-bernhardt wants to merge 2 commits into
lnhu-225from
lnhu-225-alt-b

Conversation

@matt-bernhardt

Copy link
Copy Markdown
Member

This shows how we can use wp_kses() to allowlist specific markup, while dropping everything we don't want/support/expect. There are three parts:

  1. We define what tags and attributes we expect to exist in the markup. Here, we populate $allowed_html with two things: an anchor tag, and an href attribute. If we expected more complex markup (class or rel attributes, for example), we would add those entries.
  2. We add wp_kses() to the existing echo statement, supplying 1. the variable to be rendered, and the $allowed_html array that defines what is allowed to pass through.
  3. Because we're now using a supported protection strategy, we can remove the phpcs:disable call, because the constraint is now satisfied.

I've found this a helpful strategy for small pieces of content where we know there will be markup present, but that markup is extremely limited. It wouldn't be as good a fit for something like echo $page_body because there is a nearly unlimited amount of markup that might be present on some page, so the allowlist would be unworkably large.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant