Consider wpcom_vip_get_resized_remote_image_url() as auto-escaping if fourth argument is truthy
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 45/100
調査の方向性
まず、issue に記載されている VIP Go ルールセットの XSS 出力エスケープ処理と $customAutoEscapedFunctions 設定を確認し、次にリンク先の vip-deprecated.php の関数の動作を調べます。第 4 引数の条件付き処理を追加し、提示されている true/デフォルトおよび false の例で期待される警告が出力されることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Bug Description
The VIP Go standard uses WordPress.Security.EscapeOutput.OutputNotEscaped but doesn't recognize that the deprecated wpcom_vip_get_resized_remote_image_url() function auto-escapes if it's fourth argument is true (default).
Since it's conditional, we can't just add an entry for it to $customAutoEscapedFunctions in the VIP Go ruleset (see here) as otherwise it wouldn't get flagged if the fourth argument was not truthy.
Minimal Code Snippet
// Should not be flagged.
<img src="<?php echo wpcom_vip_get_resized_remote_image_url($item->image_url, 360,270); ?>" alt="<?php echo esc_attr($item->name) ?>">
// Should be flagged.
<img src="<?php echo wpcom_vip_get_resized_remote_image_url($item->image_url, 360,270, false); ?>" alt="<?php echo esc_attr($item->name) ?>">
Tested Against master branch?
- I have verified the issue still exists in the
masterbranch of VIPCS. - I have verified the issue still exists in the
developbranch of VIPCS.
- 主要言語
- PHP
- スター
- 261
- フォーク
- 44
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
Automattic/VIP-Coding-Standards のほかの issue
-
AlwaysReturnInFilter: isInsideIfConditonal() guards the conditions array after reading it対応中かも @tomjn が 5 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
Bug: PreGetPosts warns when the early is_main_query() return is not the first statement in its if対応中かも @tomjn が 5 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 76/100
-
Suppress filters in get_posts false positive対応中かも @tomjn が 6 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 48/100
-
Breaking Change Type: Maintenance
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
Automattic/VIP-Coding-Standards#849 · コメント 1 件 ·
Automattic/VIP-Coding-Standards の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
coollabsio/shoutrrr#190 ·
-
Bug Enhancement Performance
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
Feature Status: Needs Triage
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
メンテナーはふだん 1 日以内に返信
-
frontend low-priority
難易度 2/5 1〜3時間 初心者へのやさしさ 77/100
mplodowski/dynamicpdf-plugin#336 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
AdvancedCustomFields/acf#1044 ·