[wp-trac] [WordPress Trac] #56504: `sanitize_html_class()` is both too restrictive, and too permissive so it may return an invalid class name

WordPress Trac noreply at wordpress.org
Sat Sep 3 15:39:34 UTC 2022


#56504: `sanitize_html_class()` is both too restrictive, and too permissive so it
may return an invalid class name
--------------------------+------------------------------
 Reporter:  anrghg        |       Owner:  (none)
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  General       |     Version:
 Severity:  normal        |  Resolution:
 Keywords:                |     Focuses:
--------------------------+------------------------------

Comment (by joyously):

 I discovered the leading digit part of this in my testing of my theme,
 which adds body classes using page slugs.
 Since my theme has options that are class names, changing the sanitizing
 function can cause user input to not match, so any change to this function
 needs a prominent Dev Note or some way to be backward compatible.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/56504#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list