Automattic / Automattic/VIP-Coding-Standards

Consider wpcom_vip_get_resized_remote_image_url() as auto-escaping if fourth argument is truthy

Abierto
#473 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Type: False positive
Lenguaje dominante
PHP
Estrellas
261
Forks
44
Merge medio
19 min
PR fusionados (30 d)
1

Descripción

## Bug Description

The VIP Go standard uses `WordPress.Security.EscapeOutput.OutputNotEscaped` but doesn't recognize that the deprecated [`wpcom_vip_get_resized_remote_image_url()` function](https://github.com/Automattic/vip-go-mu-plugins/blob/dfc36174ce2274def920a9ed4bf88e7d50303b35/vip-helpers/vip-deprecated.php#L1130-L1139) auto-escapes if it's fourth argument is true (default).

Since it's conditional, we can't just add an entry for it to `$customAutoEscapedFunctions` in the VIP Go ruleset (see [here](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Customizable-sniff-properties#xss-custom-output-escaping-functions)) as otherwise it wouldn't get flagged if the fourth argument was not truthy.

## Minimal Code Snippet

```php
// Should not be flagged.
<?php echo esc_attr($item->name) ?>
```

```php
// Should be flagged.
<?php echo esc_attr($item->name) ?>
```

## Tested Against `master` branch?

- [x] I have verified the issue still exists in the `master` branch of VIPCS.
- [x] I have verified the issue still exists in the `develop` branch of VIPCS.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza con el manejo del escape de salida XSS del conjunto de reglas de VIP Go y la configuración $customAutoEscapedFunctions descrita en el issue; después, inspecciona el comportamiento de la función vinculada en vip-deprecated.php. Añade un manejo condicional para el cuarto argumento y verifica que los ejemplos proporcionados para true/por defecto y false produzcan las advertencias esperadas.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
php, wordpress
Área
tooling
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Estancado
Claridad
Bien especificado
Aptitud para principiantes
45/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.