Flag incorrectly constructed mailto links
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 35/100
Rechercherichtung
Beginnen Sie mit dem im Issue erwähnten ProperEscapingFunction-Sniff und vergleichen Sie dessen Behandlung der aufgeführten verletzenden und nicht verletzenden PHP-Beispiele. Die Aufgabe ist erledigt, wenn inkorrekt konstruierte mailto-Links gemeldet werden, während mailto-Werte, die durch esc_url() geleitet werden, akzeptiert werden.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
What problem would the enhancement address for VIP?
Some developers are not aware that esc_url() supports more than just the http and https protocols. The default list also includes ftp, ftps, mailto, news, irc, gopher, nntp, feed, and telnet as well.
of those extra ones, the most common is mailto, and a common mistake is to split a URL into a static 'mailto:' and a email address variable/string escaped with something that isn't esc_url().
Describe the solution you'd like
Add a new sniff, or consider improving ProperEscapingFunction, so that we look for `'mailto:' string before an escaping function.
What code should be reported as a violation?
<a href="mailto:<?php echo esc_html( $foo ); ?>">Email us</a>
<a href="mailto:<?php echo esc_attr( $foo ); ?>">Email us</a>
<a href="mailto:<?= esc_html( $foo ); ?>">Email us</a>
<a href="mailto:<?= esc_attr( $foo ); ?>">Email us</a>
<a href="<?php echo 'mailto:' . esc_attr( $foo ); ?>">Email us</a>
<a href="<?php echo 'mailto:', esc_attr( $foo ); ?>">Email us</a>
There are likely other ways to get a similar output.
What code should not be reported as a violation?
<a href="<?php echo esc_url( 'mailto:' . $foo ); ?>">Email us</a>
<a href="<?php echo esc_url( "mailto:$foo" ); ?>">Email us</a>
- Vorherrschende Sprache
- PHP
- Sterne
- 261
- Forks
- 44
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus Automattic/VIP-Coding-Standards
-
AlwaysReturnInFilter: isInsideIfConditonal() guards the conditions array after reading itEvtl. vergeben @tomjn hat das vor 5 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
-
Bug: PreGetPosts warns when the early is_main_query() return is not the first statement in its ifEvtl. vergeben @tomjn hat das vor 5 Tagen übernommen. Offen
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 76/100
-
Suppress filters in get_posts false positiveEvtl. vergeben @tomjn hat das vor 6 Tagen übernommen. Offen
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 68/100
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 48/100
-
Breaking Change Type: Maintenance
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 35/100
Automattic/VIP-Coding-Standards#849 · 1 Kommentar ·
Alle Issues in Automattic/VIP-Coding-Standards
Ähnliche Issues
-
Schwierigkeit 2/5 Unter einer Stunde Anfängerfreundlichkeit 78/100
opencart/opencart#15763 · 2 Kommentare · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
L: github:actions L: php:composer
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
dependabot/dependabot-core#16493 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
api-platform/core#8649 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 84/100
open-telemetry/opentelemetry-php#2071 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
Maintainer antworten meist innerhalb von 1 Tag