[wp-trac] [WordPress Trac] #55966: safecss_filter_attr() returns empty if containing min()

WordPress Trac noreply at wordpress.org
Wed Sep 7 15:45:03 UTC 2022


#55966: safecss_filter_attr() returns empty if containing min()
----------------------------------------------+----------------------------
 Reporter:  uxl                               |       Owner:
                                              |  SergeyBiryukov
     Type:  defect (bug)                      |      Status:  accepted
 Priority:  normal                            |   Milestone:  6.1
Component:  Formatting                        |     Version:  6.0
 Severity:  major                             |  Resolution:
 Keywords:  has-patch early needs-unit-tests  |     Focuses:  css
----------------------------------------------+----------------------------

Comment (by SergeyBiryukov):

 Replying to [comment:19 cbravobernal]:
 > I just added some more use cases, some of them with unsafe fallback
 values. Let me know if we have to add more!

 Thanks! [attachment:"55966.4.diff"] looks good to me.

 I had to revert the original commit for now due the
 `WP_Theme_JSON::remove_insecure_properties()` test failures, see
 comment:17. Remove those tests did not seem like the correct approach, I
 think they would need some new examples of unsafe values. Let's address
 that and re-commit the patch :)

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/55966#comment:20>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list