ACF blocks using `acf_inline_toolbar_editing_attrs()` and `acf_inline_text_editing_attrs()` spill internal attributes over into frontend markup
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 52/100
Línea de trabajo
Comienza con acf_inline_toolbar_editing_attrs() y acf_inline_text_editing_attrs(), y luego reproduce el marcado tanto en el editor de bloques como en el frontend usando el ejemplo de PHP proporcionado. Compara los atributos generados y el comportamiento de acf_is_block_editor(). Se considera terminado cuando los atributos internos de edición en línea aparecen solo en el editor de bloques, sin eliminarlos allí.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
When using acf_inline_toolbar_editing_attrs() and acf_inline_text_editing_attrs(), it works as expected in the block editor: all of the html attributes ACF uses are there:
<div data-acf-inline-fields-uid="block_...description2" data-acf-inline-fields="[{...}]" role="button" tabindex="0" class=" text-black/80 prose text-lg" style="pointer-events: all;">...</div>
However, there is no guard against exposing this on the frontend too, making the somewhat sensitive internal ACF info, field names etc. visible to potential malicious actors.
It also messed up screen reader support, as it inserts role="button" and tabindex="0" to divs and other elements that should not be labeled as such.
I believe this to be a regression as this didn't use to happen.
To Reproduce
- Create an ACF Block using the Blocks V3 API and add a wysiwyg field or another unrenderable field in the new inline editing experience
- Use
acf_inline_toolbar_editing_attrs()oracf_inline_text_editing_attrs()to surface an unsupported attribute which would normally require opening the sidebar or expanded editor, like so:
<div <?= acf_inline_toolbar_editing_attrs( [ 'description1' ] ); ?> class=" text-black/80 prose text-lg">
<?= wp_kses_post( get_field( 'description1' ) ?? '' ); ?>
</div>
- Examine the markup generated in the block editor and frontend portions
- See the issue
Expected behavior
There should be a guard to only show these in the block editor. I wrote my own:
function helper_acf_inline_toolbar_attrs( array $fields, array $args = array() ): string
{
if ( ! acf_is_block_editor() )
return '';
return acf_inline_toolbar_editing_attrs( $fields, $args );
}
However, i found that the acf_is_block_editor() function isn't 100% reliable and sometimes fails, fully removing the inline toolbar attributes, but that's probably a separate bug report. But it means that i cannot use it as it breaks, and haven't found a suitable workaround. If someone more knowledgeable in ACF could recommend me what guard method to use instead that works 100% that would solve my issue, however i believe this should be fixed in ACF itself.
Version Information:
- WordPress Version: 7.0.2
- PHP Version: 8.4
- ACF Version: ACF Pro 6.8.5
- Browser: Firefox(Zen Browser) 152.0.6
- Lenguaje dominante
- PHP
- Estrellas
- 946
- Forks
- 197
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de AdvancedCustomFields/acf
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
AdvancedCustomFields/acf#1041 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
AdvancedCustomFields/acf#1038 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
AdvancedCustomFields/acf#1034 · 2 comentarios ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
AdvancedCustomFields/acf#1032 · 1 comentario ·
-
Drop trap, acf_after_titleAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
AdvancedCustomFields/acf#1029 · 1 comentario ·
Todos los issues de AdvancedCustomFields/acf
Issues similares
-
sync-en
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
bug Feature: Kiosk
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
Infrastructure: actions Module: zmscitizenapi Module: zmsentities php Type: Bug unit tests
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
it-at-m/eappointment#3480 ·
Los mantenedores suelen responder en 1 día
-
HttpClient
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
CI: composer install fails — league/flysystem 1.x blocked by security advisory GHSA-cxf4-7mrp-vvprAbiertodevops type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día