Make WordPress Core


Ignore:
Timestamp:
09/24/2026 05:53:51 AM (4 days ago)
Author:
jonsurrell
Message:

Block Processor: Ensure block delimiters align with single HTML comments.

Developed in: ​https://github.com/WordPress/wordpress-develop/pull/13680

Props jonsurrell, dmsnell.
See #66138.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-includes/class-wp-block-processor.php

    r63911 r63913  
    980980                         * even though it allows for matching invalid JSON content.
    981981                         *
     982                         * The delimiter must also be a single complete HTML comment.
     983                         *
    982984                         * <!-- /wp:core/paragraph {"dropCap":true} /-⃨-⃨>⃨
    983985                         */
    984                         $comment_closing_at = strpos( $text, '-->', $json_at );
    985                         if ( false === $comment_closing_at ) {
     986                        $after_comment_end = $this->find_html_comment_end( $comment_opening_at, $end );
     987
     988                        /*
     989                         * The reported end of the comment could be after the end of the document if
     990                         * no actual end was found, so differentiate a comment ending at the end of
     991                         * the document from documents with missing comment ends.
     992                         */
     993                        if ( $after_comment_end >= $end && ! str_ends_with( $text, '-->' ) && ! str_ends_with( $text, '--!>' ) ) {
    986994                                goto incomplete;
    987995                        }
     996
     997                        /*
     998                         * Only normative comment closers are recognized block delimiters,
     999                         * so skip past any HTML comments ending in `--!>`.
     1000                         */
     1001                        if ( '!' === $text[ $after_comment_end - 2 ] ) {
     1002                                $at = $after_comment_end;
     1003                                continue;
     1004                        }
     1005
     1006                        $comment_closing_at = $after_comment_end - 3;
    9881007
    9891008                        // <!-- /wp:core/paragraph {"dropCap":true} /⃨-->
    … …  
    10081027                                }
    10091028
    1010                                 $at = $this->find_html_comment_end( $comment_opening_at, $end );
     1029                                $at = $after_comment_end;
    10111030                                continue;
    10121031                        }
    … …  
    10161035                         *
    10171036                         * @todo It’s likely faster to scan forward instead of in reverse.
     1037                         * @todo Skip ahead with `strcspn()` and decide only on syntax characters.
    10181038                         *
    10191039                         * <!-- /wp:core/paragraph {"dropCap":true}⃨ ⃨/-->
    … …  
    10371057
    10381058                                        default:
    1039                                                 ++$at;
     1059                                                $at = $after_comment_end;
    10401060                                                continue 3;
    10411061                                }
    … …  
    10471067                         */
    10481068                        if ( 0 === $json_length || 0 === $after_json_whitespace_length ) {
    1049                                 $at = $this->find_html_comment_end( $comment_opening_at, $end );
     1069                                $at = $after_comment_end;
    10501070                                continue;
    10511071                        }
    … …  
    10581078                // The end of the document was reached without a match.
    10591079                if ( self::MATCHED !== $this->state ) {
     1080                        // Stop at top-level free-form HTML at the end of the document.
     1081                        if ( $after_prev_delimiter < $end ) {
     1082                                $this->state                    = self::HTML_SPAN;
     1083                                $this->after_previous_delimiter = $after_prev_delimiter;
     1084                                $this->matched_delimiter_at     = $end;
     1085                                $this->matched_delimiter_length = 0;
     1086                                $this->open_blocks_at[]         = $after_prev_delimiter;
     1087                                $this->open_blocks_length[]     = 0;
     1088                                $this->was_void                 = true;
     1089
     1090                                return true;
     1091                        }
     1092
    10601093                        $this->state = self::COMPLETE;
    10611094                        return false;
    … …  
    13371370                        '>' === $text[ $comment_starting_at + 2 + $span_of_dashes ]
    13381371                ) {
    1339                         return $comment_starting_at + $span_of_dashes + 1;
     1372                        return $comment_starting_at + 2 + $span_of_dashes + 1;
    13401373                }
    13411374
Note: See TracChangeset for help on using the changeset viewer.