Opened 3 hours ago
Last modified 66 minutes ago
#66208 new enhancement
KSES: Re-implement using HTML API
| Reported by: | dmsnell | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | 7.2 |
| Component: | HTML API | Version: | 0.71 |
| Severity: | normal | Keywords: | has-patch has-unit-tests |
| Cc: | Focuses: |
Description (last modified by )
Since its initial commit, WordPress has relied on the KSES library to sanitize and normalize and transform content from untrusted sources. Unfortunately, the parsing inside of wp_kses() has never been spec-compliant, leading to numerous challenges in safely, efficiently, and reliably fulfilling its purpose.
The HTML API provides a mechanism for structurally interacting with HTML in an efficient manner, and wp_kses() should be rewritten to lean on that existing capability.
Resolves
- #25851 Large attribute values may crash PCRE patterns and cause content loss.
- #37698 Global pollution in
wp_kses_split()calls. - #48873 CSS contents are corrupted by
wp_kses(). - #51482
wp_kses()turns SCRIPT and STYLE content into renderable text. - #52333
wp_kses()and HTML disagree on the set of named character references. - #58377 Block names with consecutive hyphens are corrupted.
- #58921 Valid tag names are rejected from the allow-list.
- #59310
parse_blocks()called unnecessarily. - #61246
wp_kses()un-comments HTML comments. - #62024
wp_kses_post()incorrectly escapes “<” in attribute values.
Potentially resolves
Related
Change History (19)
This ticket was mentioned in PR #13271 on WordPress/wordpress-develop by @dmsnell.
3 hours ago
#1
- Keywords has-patch has-unit-tests added
#12
@
112 minutes ago
- Description modified (diff)
#13
@
96 minutes ago
#48873 was marked as a duplicate.
#14
@
95 minutes ago
- Description modified (diff)
#15
@
84 minutes ago
- Description modified (diff)
#16
@
83 minutes ago
#51482 was marked as a duplicate.
#17
@
83 minutes ago
- Description modified (diff)
#18
@
71 minutes ago
- Description modified (diff)
#19
@
66 minutes ago
- Description modified (diff)
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
Trac ticket: Core-66208
Trac ticket: Core-65984
Replaces #6577
Description
Rewrites
wp_kses()to rely on the HTML API for structural and reliable application of sanitization rules, normalizing the output for improved downstream parsing.Notables
wp_kses_force_legacy_parserprovides the choice of whether to use this new parser or stick with the legacy code.Fixes
wp_kses()un-comments HTML comments.wp_kses_post()incorrectly escapes "<" attributes values.Todo
~Merge after #13273, which accounts for three of the failing tests.~
wp_kses(), it’s possible to simply wait until an opened element is closed based on depth, and skip that closing element if it exists.wp_kses()with intentionally-incomplete input, for example, a wrapper opening tag with part of the content, separately from the closer. closing open elements does a good job of isolating content, but legacy behaviors depend too much on the more procedural use ofwp_kses()so isolation cannot be reasonably added without mangling websites.pre_ksesfilters but then callpre_ksesNotes