- Timestamp:
- 06/24/2024 03:02:41 PM (6 months ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/6.5/src/wp-includes/html-api/class-wp-html-tag-processor.php
r57815 r58474 2969 2969 $updated_attribute = $name; 2970 2970 } else { 2971 $escaped_new_value = esc_attr( $value ); 2971 $comparable_name = strtolower( $name ); 2972 2973 /* 2974 * Escape URL attributes. 2975 * 2976 * @see https://html.spec.whatwg.org/#attributes-3 2977 */ 2978 $escaped_new_value = in_array( $comparable_name, wp_kses_uri_attributes() ) ? esc_url( $value ) : esc_attr( $value ); 2972 2979 $updated_attribute = "{$name}=\"{$escaped_new_value}\""; 2973 2980 }
Note: See TracChangeset
for help on using the changeset viewer.