Automattic / Automattic/VIP-Coding-Standards
Flag incorrectly constructed mailto links
- Dominant language
- PHP
- Stars
- 261
- Forks
- 44
- Avg merge
- 19m
- Merged PRs (30d)
- 1
Description
## What problem would the enhancement address for VIP?
Some developers are not aware that `esc_url()` supports more than just the `http` and `https` protocols. The default list also includes ftp, ftps, mailto, news, irc, gopher, nntp, feed, and telnet as well.
of those extra ones, the most common is `mailto`, and a common mistake is to split a URL into a static `'mailto:'` and a email address variable/string escaped with something that isn't `esc_url()`.
## Describe the solution you'd like
Add a new sniff, or consider improving ProperEscapingFunction, so that we look for `'mailto:' string before an escaping function.
## What code should be reported as a violation?
```php
Email us
Email us
```
There are likely other ways to get a similar output.
## What code should *not* be reported as a violation?
```php
Email us
">Email us
```
Contributor guide
Research direction
Start with the ProperEscapingFunction sniff mentioned in the issue and compare its handling of the listed violating and non-violating PHP examples. Done means incorrectly constructed mailto links are reported while mailto values passed through esc_url() are accepted.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php, wordpress
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100