You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 

60 lines
1.8 KiB

  1. <?php
  2. /**
  3. * Feed API: WP_SimplePie_Sanitize_KSES class
  4. *
  5. * @package WordPress
  6. * @subpackage Feed
  7. * @since 4.7.0
  8. */
  9. /**
  10. * Core class used to implement SimpliePie feed sanitization.
  11. *
  12. * Extends the SimplePie_Sanitize class to use KSES, because
  13. * we cannot universally count on DOMDocument being available.
  14. *
  15. * @since 3.5.0
  16. *
  17. * @see SimplePie_Sanitize
  18. */
  19. class WP_SimplePie_Sanitize_KSES extends SimplePie_Sanitize {
  20. /**
  21. * WordPress SimplePie sanitization using KSES.
  22. *
  23. * Sanitizes the incoming data, to ensure that it matches the type of data expected, using KSES.
  24. *
  25. * @since 3.5.0
  26. * @access public
  27. *
  28. * @param mixed $data The data that needs to be sanitized.
  29. * @param integer $type The type of data that it's supposed to be.
  30. * @param string $base Optional. The `xml:base` value to use when converting relative
  31. * URLs to absolute ones. Default empty.
  32. * @return mixed Sanitized data.
  33. */
  34. public function sanitize( $data, $type, $base = '' ) {
  35. $data = trim( $data );
  36. if ( $type & SIMPLEPIE_CONSTRUCT_MAYBE_HTML ) {
  37. if (preg_match('/(&(#(x[0-9a-fA-F]+|[0-9]+)|[a-zA-Z0-9]+)|<\/[A-Za-z][^\x09\x0A\x0B\x0C\x0D\x20\x2F\x3E]*' . SIMPLEPIE_PCRE_HTML_ATTRIBUTE . '>)/', $data)) {
  38. $type |= SIMPLEPIE_CONSTRUCT_HTML;
  39. }
  40. else {
  41. $type |= SIMPLEPIE_CONSTRUCT_TEXT;
  42. }
  43. }
  44. if ( $type & SIMPLEPIE_CONSTRUCT_BASE64 ) {
  45. $data = base64_decode( $data );
  46. }
  47. if ( $type & ( SIMPLEPIE_CONSTRUCT_HTML | SIMPLEPIE_CONSTRUCT_XHTML ) ) {
  48. $data = wp_kses_post( $data );
  49. if ( $this->output_encoding !== 'UTF-8' ) {
  50. $data = $this->registry->call( 'Misc', 'change_encoding', array( $data, 'UTF-8', $this->output_encoding ) );
  51. }
  52. return $data;
  53. } else {
  54. return parent::sanitize( $data, $type, $base );
  55. }
  56. }
  57. }