Make WordPress Core

Opened 16 months ago

Last modified 12 months ago

#56391 new defect (bug)

safecss_filter_attr(): support rgba background-color

Reported by: wildworks's profile wildworks Owned by:
Milestone: Awaiting Review Priority: normal
Severity: normal Version:
Component: Security Keywords: has-patch has-unit-tests
Focuses: Cc:

Description

This ticket allows rgba-valued background-color in safecss_filter_attr.

It was (https://github.com/WordPress/gutenberg/issues/39402) in Gutenberg that triggered this ticket.

In RichText, when an inline text color is specified, a transparent background color style (background-color:rgba(0, 0, 0, 0)) is generated at the same time.
This is to disable the browser's default style (yellow for Chrome), since highlighted text is wrapped with a mark tag.

However, this background color is sanitized by wp_kes_post, and the browser's default style is restored.

This ticket proposes to allow rgba values only for background-color.
Please check with the additions to the Unit Test to see what values are allowed.

Change History (6)

This ticket was mentioned in PR #3097 on WordPress/wordpress-develop by t-hamano.


16 months ago
#1

  • Keywords has-unit-tests added

#2 @wildworks
16 months ago

I initially submitted a PR that attempted to resolve this problem only in the block where it was occurring.
https://github.com/WordPress/gutenberg/pull/39488

However, it was considered that it would be better to support rgba in safecss_filter_attr, so I submitted a ticket.

t-hamano commented on PR #3097:


16 months ago
#3

I have added support for RGB and allowed some properties, and updated regular expressions.
And I have tried to cover as many variations of the test as possible. Is this enough?

t-hamano commented on PR #3097:


16 months ago
#4

I have relaxed the regex rules and updated the existing tests.
With the relaxed rules, should we reduce the number of test cases a little more?

#5 @desrosj
14 months ago

  • Version trunk deleted

@wildworks commented on PR #3097:


12 months ago
#6

The problem this PR is trying to solve appears to have been fixed by Changeset 54117.
Therefore, I would like to close this PR.

Note: See TracTickets for help on using tickets.