Automattic / Automattic/VIP-Coding-Standards
Consider wpcom_vip_get_resized_remote_image_url() as auto-escaping if fourth argument is truthy
- Langage dominant
- PHP
- Étoiles
- 261
- Forks
- 44
- Merge moyen
- 19 min
- PR mergées (30 j)
- 1
Description
## Bug Description
The VIP Go standard uses `WordPress.Security.EscapeOutput.OutputNotEscaped` but doesn't recognize that the deprecated [`wpcom_vip_get_resized_remote_image_url()` function](https://github.com/Automattic/vip-go-mu-plugins/blob/dfc36174ce2274def920a9ed4bf88e7d50303b35/vip-helpers/vip-deprecated.php#L1130-L1139) auto-escapes if it's fourth argument is true (default).
Since it's conditional, we can't just add an entry for it to `$customAutoEscapedFunctions` in the VIP Go ruleset (see [here](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Customizable-sniff-properties#xss-custom-output-escaping-functions)) as otherwise it wouldn't get flagged if the fourth argument was not truthy.
## Minimal Code Snippet
```php
// Should not be flagged.
```
```php
// Should be flagged.
```
## Tested Against `master` branch?
- [x] I have verified the issue still exists in the `master` branch of VIPCS.
- [x] I have verified the issue still exists in the `develop` branch of VIPCS.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par le traitement de l’échappement de sortie XSS du ruleset VIP Go et par la configuration $customAutoEscapedFunctions décrite dans l’issue, puis examinez le comportement de la fonction liée dans vip-deprecated.php. Ajoutez une gestion conditionnelle du quatrième argument et vérifiez que les exemples fournis pour true/par défaut et false produisent les avertissements attendus.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- php, wordpress
- Domaine
- tooling
- Type d'issue
- Bug
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Activité
- À l'abandon
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 45/100