Skip to content
Snippets Groups Projects
Commit 7062802b authored by Marcin Kolanko's avatar Marcin Kolanko
Browse files

fix(templates): remove wp_kses_post for parent templates

parent d6c43c76
Branches
Tags
1 merge request!21Bugfix/remove invalid escaping
Pipeline #6311 passed
...@@ -33,3 +33,4 @@ ...@@ -33,3 +33,4 @@
readonly="readonly"<?php endif; ?> readonly="readonly"<?php endif; ?>
><?php echo \esc_html( $field->get_label() ); ?></button> ><?php echo \esc_html( $field->get_label() ); ?></button>
...@@ -11,22 +11,12 @@ ...@@ -11,22 +11,12 @@
<tr valign="top"> <tr valign="top">
<?php if ( $field->has_label() ) : ?> <?php if ( $field->has_label() ) : ?>
<?php echo wp_kses_post( $renderer->render( 'form-label', [ 'field' => $field ] ) ); ?> <?php echo $renderer->render( 'form-label', [ 'field' => $field ] ); // phpcs:ignore ?>
<?php endif; ?> <?php endif; ?>
<td class="forminp"> <td class="forminp">
<?php <?php
echo wp_kses_post( echo $renderer->render( $template_name, [ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ]); // phpcs:ignore
$renderer->render(
$template_name,
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
?> ?>
<?php if ( $field->has_description() ) : ?> <?php if ( $field->has_description() ) : ?>
......
...@@ -9,7 +9,7 @@ ...@@ -9,7 +9,7 @@
<th class="titledesc" scope="row"> <th class="titledesc" scope="row">
<label for="<?php echo \esc_attr( $field->get_id() ); ?>"><?php echo \esc_html( $field->get_label() ); ?> <label for="<?php echo \esc_attr( $field->get_id() ); ?>"><?php echo \esc_html( $field->get_label() ); ?>
<?php if ( $field->has_description_tip() ) : ?> <?php if ( $field->has_description_tip() ) : ?>
<?php echo esc_html( wc_help_tip( $field->get_description_tip() ) ); ?> <?php echo wp_kses_post( wc_help_tip( $field->get_description_tip() ) ); ?>
<?php endif ?> <?php endif ?>
</label> </label>
</th> </th>
...@@ -10,14 +10,4 @@ ...@@ -10,14 +10,4 @@
?> ?>
<?php <?php
echo wp_kses_post( echo $renderer->render( 'input', [ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ] ); // phpcs:ignore;
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
...@@ -7,14 +7,5 @@ ...@@ -7,14 +7,5 @@
* @var string $template_name Real field template. * @var string $template_name Real field template.
*/ */
echo wp_kses_post( echo $renderer->render( 'input',[ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ]); // phpcs:ignore
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
...@@ -9,14 +9,4 @@ ...@@ -9,14 +9,4 @@
?> ?>
<?php <?php
echo wp_kses_post( echo $renderer->render( 'input', [ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ] ); // phpcs:ignore
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
...@@ -13,15 +13,23 @@ $media_container_id = 'media_' . sanitize_key( $field->get_id() ); ...@@ -13,15 +13,23 @@ $media_container_id = 'media_' . sanitize_key( $field->get_id() );
id="<?php echo \esc_attr( $field->get_id() ); ?>"/> id="<?php echo \esc_attr( $field->get_id() ); ?>"/>
<div class="custom-img-container"> <div class="custom-img-container">
<?php if ( $value ) : ?> <?php if ( $value ) : ?>
<img src="<?php echo \esc_url( $value ) ?>" alt="" width="100"/> <img src="<?php echo \esc_url( $value ); ?>" alt="" width="100"/>
<?php endif; ?> <?php endif; ?>
</div> </div>
<p class="hide-if-no-js"> <p class="hide-if-no-js">
<a class="upload-custom-img <?php if ( $value ): ?>hidden<?php endif ?>" href="<?php echo \esc_url( $value ) ?>"> <a class="upload-custom-img
<?php \esc_html_e( 'Set image', 'wp-forms' ) ?> <?php
if ( $value ) :
?>
hidden<?php endif ?>" href="<?php echo \esc_url( $value ); ?>">
<?php \esc_html_e( 'Set image', 'wp-forms' ); ?>
</a> </a>
<a class="delete-custom-img <?php if ( ! $value ): ?>hidden<?php endif ?>" href="#"> <a class="delete-custom-img
<?php \esc_html_e( 'Remove image', 'wp-forms' ) ?> <?php
if ( ! $value ) :
?>
hidden<?php endif ?>" href="#">
<?php \esc_html_e( 'Remove image', 'wp-forms' ); ?>
</a> </a>
</p> </p>
</div> </div>
......
...@@ -7,14 +7,4 @@ ...@@ -7,14 +7,4 @@
* @var string $template_name Real field template. * @var string $template_name Real field template.
*/ */
echo wp_kses_post( echo $renderer->render( 'input', ['field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix,'value' => $value ] ); // phpcs:ignore
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
...@@ -9,14 +9,4 @@ ...@@ -9,14 +9,4 @@
?> ?>
<?php <?php
echo wp_kses_post( echo $renderer->render( 'input', [ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ] ); // phpcs:ignore
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
...@@ -7,14 +7,4 @@ ...@@ -7,14 +7,4 @@
* @var string $template_name Real field template. * @var string $template_name Real field template.
*/ */
echo wp_kses_post( echo $renderer->render( 'input', [ 'field' => $field, 'renderer' => $renderer, 'name_prefix' => $name_prefix, 'value' => $value ] ); // phpcs:ignore
$renderer->render(
'input',
[
'field' => $field,
'renderer' => $renderer,
'name_prefix' => $name_prefix,
'value' => $value,
]
)
);
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment