Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Consider wpcom_vip_get_resized_remote_image_url() as auto-escaping if fourth argument is truthy

オープン
#473 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
45/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
停滞
技術スタック
php, wordpress
領域
tooling

調査の方向性

まず、issue に記載されている VIP Go ルールセットの XSS 出力エスケープ処理と $customAutoEscapedFunctions 設定を確認し、次にリンク先の vip-deprecated.php の関数の動作を調べます。第 4 引数の条件付き処理を追加し、提示されている true/デフォルトおよび false の例で期待される警告が出力されることを確認します。

索引モデルが issue の本文から書いたものです。

説明

Type: False positive

Bug Description

The VIP Go standard uses WordPress.Security.EscapeOutput.OutputNotEscaped but doesn't recognize that the deprecated wpcom_vip_get_resized_remote_image_url() function auto-escapes if it's fourth argument is true (default).

Since it's conditional, we can't just add an entry for it to $customAutoEscapedFunctions in the VIP Go ruleset (see here) as otherwise it wouldn't get flagged if the fourth argument was not truthy.

Minimal Code Snippet

// Should not be flagged.
<img src="<?php echo wpcom_vip_get_resized_remote_image_url($item->image_url, 360,270); ?>" alt="<?php echo esc_attr($item->name) ?>">
// Should be flagged.
<img src="<?php echo wpcom_vip_get_resized_remote_image_url($item->image_url, 360,270, false); ?>" alt="<?php echo esc_attr($item->name) ?>">

Tested Against master branch?

  • I have verified the issue still exists in the master branch of VIPCS.
  • I have verified the issue still exists in the develop branch of VIPCS.
主要言語
PHP
スター
261
フォーク
44
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Automattic/VIP-Coding-Standards のほかの issue

Automattic/VIP-Coding-Standards の issue をすべて見る

似ている issue

PHP の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。