-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Font Library: remove insecure properties #56230
Conversation
This pull request has changed or added PHP files. Please confirm whether these changes need to be synced to WordPress Core, and therefore featured in the next release of WordPress. If so, it is recommended to create a new Trac ticket and submit a pull request to the WordPress Core Github repository soon after this pull request is merged. If you're unsure, you can always ask for help in the #core-editor channel in WordPress Slack. Thank you! ❤️ View changed files❔ lib/experimental/fonts/font-library/class-wp-font-family.php ❔ phpunit/class-wp-theme-json-test.php |
@@ -300,12 +300,17 @@ private function sanitize() { | |||
'version' => '2', | |||
'settings' => array( | |||
'typography' => array( | |||
'fontFamilies' => array( $this->data ), | |||
'fontFamilies' => array( | |||
'custom' => array( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The custom
key is necessary to accommodate the input expected by remove_insecure_properties
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This makes sense to me. Thanks for the enhancement.
What?
Leverages the
remove_insecure_properties
method of WP_Theme_JSON class to further validate the CSS saved to the database and output to the client.The PR also adds a unit test to verify the use case.
Why?
Currently it is possible to include and output non-valid CSS in the font family definition of global styles.
How?
Testing Instructions
Testing Instructions for Keyboard
Screenshots or screencast