<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[60649] trunk: HTML API: Improve script tag escape state processing.</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { white-space: pre-line; overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta" style="font-size: 105%">
<dt style="float: left; width: 6em; font-weight: bold">Revision</dt> <dd><a style="font-weight: bold" href="https://core.trac.wordpress.org/changeset/60649">60649</a><script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","description":"Review this Commit","action":{"@type":"ViewAction","url":"https://core.trac.wordpress.org/changeset/60649","name":"Review Commit"}}</script></dd>
<dt style="float: left; width: 6em; font-weight: bold">Author</dt> <dd>jonsurrell</dd>
<dt style="float: left; width: 6em; font-weight: bold">Date</dt> <dd>2025-08-19 19:07:11 +0000 (Tue, 19 Aug 2025)</dd>
</dl>

<pre style='padding-left: 1em; margin: 2em 0; border-left: 2px solid #ccc; line-height: 1.25; font-size: 105%; font-family: sans-serif'>HTML API: Improve script tag escape state processing.

Addresses some edge cases parsing of script tag contents:

- "<!-->" remains in the unescaped state and does not enter the escaped state.
- Contents in the escaped state that end with "<script" do not enter double-escaped state.
- "\f" (Form Feed) was missing as a tag name terminating character.

Developed in https://github.com/WordPress/wordpress-develop/pull/9397 and https://github.com/WordPress/wordpress-develop/pull/9402.

Props jonsurrell, dmsnell.
See <a href="https://core.trac.wordpress.org/ticket/63738">#63738</a>.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunksrcwpincludeshtmlapiclasswphtmltagprocessorphp">trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php</a></li>
<li><a href="#trunktestsphpunittestshtmlapiwpHtmlTagProcessorphp">trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunksrcwpincludeshtmlapiclasswphtmltagprocessorphp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php    2025-08-19 18:50:05 UTC (rev 60648)
+++ trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php      2025-08-19 19:07:11 UTC (rev 60649)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -1556,24 +1556,33 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                        /*
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                         * Unlike with "-->", the "<!--" only transitions
-                        * into the escaped mode if not already there.
-                        *
-                        * Inside the escaped modes it will be ignored; and
-                        * should never break out of the double-escaped
-                        * mode and back into the escaped mode.
-                        *
-                        * While this requires a mode change, it does not
-                        * impact the parsing otherwise, so continue
-                        * parsing after updating the state.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                  * "<!--" only transitions from _unescaped_ to _escaped_. This byte sequence is only
+                        * significant in the _unescaped_ state and is ignored in any other state.
</ins><span class="cx" style="display: block; padding: 0 10px">                          */
</span><span class="cx" style="display: block; padding: 0 10px">                        if (
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                                'unescaped' === $state &&
</ins><span class="cx" style="display: block; padding: 0 10px">                                 '!' === $html[ $at ] &&
</span><span class="cx" style="display: block; padding: 0 10px">                                '-' === $html[ $at + 1 ] &&
</span><span class="cx" style="display: block; padding: 0 10px">                                '-' === $html[ $at + 2 ]
</span><span class="cx" style="display: block; padding: 0 10px">                        ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                $at   += 3;
-                               $state = 'unescaped' === $state ? 'escaped' : $state;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         $at += 3;
+
+                               /*
+                                * The parser is ready to enter the _escaped_ state, but may remain in the
+                                * _unescaped_ state. This occurs when "<!--" is immediately followed by a
+                                * sequence of 0 or more "-" followed by ">". This is similar to abruptly closed
+                                * HTML comments like "<!-->" or "<!--->".
+                                *
+                                * Note that this check may advance the position significantly and requires a
+                                * length check to prevent bad offsets on inputs like `<script><!---------`.
+                                */
+                               $at += strspn( $html, '-', $at );
+                               if ( $at < $doc_length && '>' === $html[ $at ] ) {
+                                       ++$at;
+                                       continue;
+                               }
+
+                               $state = 'escaped';
</ins><span class="cx" style="display: block; padding: 0 10px">                                 continue;
</span><span class="cx" style="display: block; padding: 0 10px">                        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -1610,8 +1619,30 @@
</span><span class="cx" style="display: block; padding: 0 10px">                         */
</span><span class="cx" style="display: block; padding: 0 10px">                        $at += 6;
</span><span class="cx" style="display: block; padding: 0 10px">                        $c   = $html[ $at ];
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        if ( ' ' !== $c && "\t" !== $c && "\r" !== $c && "\n" !== $c && '/' !== $c && '>' !== $c ) {
-                               ++$at;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 if (
+                               /**
+                                * These characters trigger state transitions of interest:
+                                *
+                                * - @see {https://html.spec.whatwg.org/multipage/parsing.html#script-data-end-tag-name-state}
+                                * - @see {https://html.spec.whatwg.org/multipage/parsing.html#script-data-escaped-end-tag-name-state}
+                                * - @see {https://html.spec.whatwg.org/multipage/parsing.html#script-data-double-escape-start-state}
+                                * - @see {https://html.spec.whatwg.org/multipage/parsing.html#script-data-double-escape-end-state}
+                                *
+                                * The "\r" character is not present in the above references. However, "\r" must be
+                                * treated the same as "\n". This is because the HTML Standard requires newline
+                                * normalization during preprocessing which applies this replacement.
+                                *
+                                * - @see https://html.spec.whatwg.org/multipage/parsing.html#preprocessing-the-input-stream
+                                * - @see https://infra.spec.whatwg.org/#normalize-newlines
+                                */
+                               '>' !== $c &&
+                               ' ' !== $c &&
+                               "\n" !== $c &&
+                               '/' !== $c &&
+                               "\t" !== $c &&
+                               "\f" !== $c &&
+                               "\r" !== $c
+                       ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                                 continue;
</span><span class="cx" style="display: block; padding: 0 10px">                        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span></span></pre></div>
<a id="trunktestsphpunittestshtmlapiwpHtmlTagProcessorphp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php 2025-08-19 18:50:05 UTC (rev 60648)
+++ trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php   2025-08-19 19:07:11 UTC (rev 60649)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -2009,19 +2009,51 @@
</span><span class="cx" style="display: block; padding: 0 10px">        /**
</span><span class="cx" style="display: block; padding: 0 10px">         * Data provider.
</span><span class="cx" style="display: block; padding: 0 10px">         */
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        public static function data_script_tag(): array {
-               return array(
-                       'Basic script tag'                          => array( '<script></script>', true ),
-                       'Script with type attribute'                => array( '<script type="text/javascript"></script>', true ),
-                       'Script data escaped'                       => array( '<script><!--</script>', true ),
-                       'Script data double-escaped exit (comment)' => array( '<script><!--<script>--></script>', true ),
-                       'Script data double-escaped exit (closed)'  => array( '<script><!--<script></script></script>', true ),
-                       'Script data double-escaped exit (closed/truncated)' => array( '<script><!--<script></script </script>', true ),
-                       'Script data no double-escape'              => array( '<script><!-- --><script></script>', true ),
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ public static function data_script_tag(): Generator {
+                       yield 'Basic script tag'                              => array( '<script></script>', true );
+                       yield 'Script tag with </script> close'               => array( '<script></script>', true );
+                       yield 'Script tag with </script/> close'              => array( '<script></script/>', true );
+                       yield 'Script tag with </script > close'              => array( '<script></script >', true );
+                       yield 'Script tag with </script\n> close'             => array( "<script></script\n>", true );
+                       yield 'Script tag with </script\t> close'             => array( "<script></script\t>", true );
+                       yield 'Script tag with </script\f> close'             => array( "<script></script\f>", true );
+                       yield 'Script tag with </script\r> close'             => array( "<script></script\r>", true );
+                       yield 'Script with type attribute'                    => array( '<script type="text/javascript"></script>', true );
+                       yield 'Script data escaped'                           => array( '<script><!--</script>', true );
+                       yield 'Script data double-escaped exit (comment)'     => array( '<script><!--<script>--></script>', true );
+                       yield 'Script data double-escaped exit (closed ">")'  => array( '<script><!--<script></script></script>', true );
+                       yield 'Script data double-escaped exit (closed "/")'  => array( '<script><!--<script></script/</script>', true );
+                       yield 'Script data double-escaped exit (closed " ")'  => array( '<script><!--<script></script </script>', true );
+                       yield 'Script data double-escaped exit (closed "\n")' => array( "<script><!--<script></script\n</script>", true );
+                       yield 'Script data double-escaped exit (closed "\t")' => array( "<script><!--<script></script\t</script>", true );
+                       yield 'Script data double-escaped exit (closed "\f")' => array( "<script><!--<script></script\f</script>", true );
+                       yield 'Script data double-escaped exit (closed "\r")' => array( "<script><!--<script></script\r</script>", true );
+                       yield 'Script data no double-escape'                  => array( '<script><!-- --><script></script>', true );
+                       yield 'Script data no double-escape (short comment)'  => array( '<script><!--><script></script>', true );
+                       yield 'Script data almost double-escaped'             => array( '<script><!--<script</script>', true );
+                       yield 'Script data with complex JavaScript'           => array(
+                               '<script>
+                                       var x = 10;
+                                       x--;
+                                       x < 0 ? x += 100 : x = (x + 1) - 1;
+                               </script>',
+                               true,
+                       );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        'Script tag with self-close flag (ignored)' => array( '<script />', false ),
-                       'Script data double-escaped'                => array( '<script><!--<script></script>', false ),
-               );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 yield 'Script tag with self-close flag (ignored)'     => array( '<script />', false );
+                       yield 'Script data double-escaped'                    => array( '<script><!--<script></script>', false );
+                       yield 'Unclosed script in escaped state'              => array( '<script><!--------------', false );
+                       yield 'Unclosed script in double escaped state'       => array( '<script><!--<script ', false );
+                       yield 'Document end in closer start'                  => array( '<script></', false );
+                       yield 'Document end in script closer'                 => array( '<script></script', false );
+                       yield 'Document end in script closer with attributes' => array( '<script></script attr="val"', false );
+                       yield 'Script tag double-escaped with <script>'       => array( '<script><!--<script></script>', false );
+                       yield 'Script tag double-escaped with <script/'       => array( '<script><!--<script/</script>', false );
+                       yield 'Script tag double-escaped with <script '       => array( '<script><!--<script </script>', false );
+                       yield 'Script tag double-escaped with <script\n'      => array( "<script><!--<script\n</script>", false );
+                       yield 'Script tag double-escaped with <script\t'      => array( "<script><!--<script\t</script>", false );
+                       yield 'Script tag double-escaped with <script\f'      => array( "<script><!--<script\f</script>", false );
+                       yield 'Script tag double-escaped with <script\r'      => array( "<script><!--<script\r</script>", false );
</ins><span class="cx" style="display: block; padding: 0 10px">         }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        /**
</span></span></pre>
</div>
</div>

</body>
</html>