Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Flag incorrectly constructed mailto links

Offen
#556 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
35/100
Issue-Typ
Feature
Klarheit
Größtenteils klar
Aktivitätsstatus
Veraltet
Tech-Stack
php, wordpress
Bereich
tooling

Rechercherichtung

Beginnen Sie mit dem im Issue erwähnten ProperEscapingFunction-Sniff und vergleichen Sie dessen Behandlung der aufgeführten verletzenden und nicht verletzenden PHP-Beispiele. Die Aufgabe ist erledigt, wenn inkorrekt konstruierte mailto-Links gemeldet werden, während mailto-Werte, die durch esc_url() geleitet werden, akzeptiert werden.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Type: Enhancement

What problem would the enhancement address for VIP?

Some developers are not aware that esc_url() supports more than just the http and https protocols. The default list also includes ftp, ftps, mailto, news, irc, gopher, nntp, feed, and telnet as well.

of those extra ones, the most common is mailto, and a common mistake is to split a URL into a static 'mailto:' and a email address variable/string escaped with something that isn't esc_url().

Describe the solution you'd like

Add a new sniff, or consider improving ProperEscapingFunction, so that we look for `'mailto:' string before an escaping function.

What code should be reported as a violation?

<a href="mailto:<?php echo esc_html( $foo ); ?>">Email us</a>

<a href="mailto:<?php echo esc_attr( $foo ); ?>">Email us</a>

<a href="mailto:<?= esc_html( $foo ); ?>">Email us</a>

<a href="mailto:<?= esc_attr( $foo ); ?>">Email us</a>

<a href="<?php echo 'mailto:' . esc_attr( $foo ); ?>">Email us</a>

<a href="<?php echo 'mailto:', esc_attr( $foo ); ?>">Email us</a>

There are likely other ways to get a similar output.

What code should not be reported as a violation?

<a href="<?php echo esc_url( 'mailto:' . $foo ); ?>">Email us</a>

<a href="<?php echo esc_url( "mailto:$foo" ); ?>">Email us</a>
Vorherrschende Sprache
PHP
Sterne
261
Forks
44
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus Automattic/VIP-Coding-Standards

Alle Issues in Automattic/VIP-Coding-Standards

Ähnliche Issues

Weitere Issues zu PHP

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.