<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[61003] trunk: HTML API: Replace PCRE in `set_attribute()` with new UTF-8 utility.</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { white-space: pre-line; overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta" style="font-size: 105%">
<dt style="float: left; width: 6em; font-weight: bold">Revision</dt> <dd><a style="font-weight: bold" href="https://core.trac.wordpress.org/changeset/61003">61003</a><script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","description":"Review this Commit","action":{"@type":"ViewAction","url":"https://core.trac.wordpress.org/changeset/61003","name":"Review Commit"}}</script></dd>
<dt style="float: left; width: 6em; font-weight: bold">Author</dt> <dd>dmsnell</dd>
<dt style="float: left; width: 6em; font-weight: bold">Date</dt> <dd>2025-10-21 03:48:20 +0000 (Tue, 21 Oct 2025)</dd>
</dl>

<pre style='padding-left: 1em; margin: 2em 0; border-left: 2px solid #ccc; line-height: 1.25; font-size: 105%; font-family: sans-serif'>HTML API: Replace PCRE in `set_attribute()` with new UTF-8 utility.

The HTML API has relied upon a single PCRE to determine whether to allow setting certain attribute names. This was because those names aren't allowed to contain Unicode noncharacters, but detecting noncharacters without a UTF-8 parser is nontrivial.

In this change the direct PCRE has been replaced with a number of `strcpn()` calls and a call to the newer `wp_has_noncharacters()` function. Under the hood, this function will still defer to a PCRE if Unicode support is available, but otherwise will fall back to the UTF-8 pipeline in Core.

This change removes the platform variability, making the HTML API more reliable when Unicode support for PCRE is lacking.

Developed in https://github.com/WordPress/wordpress-develop/pull/9798
Discussed in https://core.trac.wordpress.org/ticket/63863

See <a href="https://core.trac.wordpress.org/ticket/63863">#63863</a>.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunksrcwpincludeshtmlapiclasswphtmltagprocessorphp">trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php</a></li>
<li><a href="#trunktestsphpunittestshtmlapiwpHtmlTagProcessorphp">trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunksrcwpincludeshtmlapiclasswphtmltagprocessorphp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php    2025-10-21 03:31:55 UTC (rev 61002)
+++ trunk/src/wp-includes/html-api/class-wp-html-tag-processor.php      2025-10-21 03:48:20 UTC (rev 61003)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -3930,41 +3930,32 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        return false;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                /*
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         $name_length = strlen( $name );
+
+               /**
</ins><span class="cx" style="display: block; padding: 0 10px">                  * WordPress rejects more characters than are strictly forbidden
</span><span class="cx" style="display: block; padding: 0 10px">                 * in HTML5. This is to prevent additional security risks deeper
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 * in the WordPress and plugin stack. Specifically the
-                * less-than (<) greater-than (>) and ampersand (&) aren't allowed.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+          * in the WordPress and plugin stack. Specifically the following
+                * are not allowed to be set as part of an HTML attribute name:
</ins><span class="cx" style="display: block; padding: 0 10px">                  *
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 * The use of a PCRE match enables looking for specific Unicode
-                * code points without writing a UTF-8 decoder. Whereas scanning
-                * for one-byte characters is trivial (with `strcspn`), scanning
-                * for the longer byte sequences would be more complicated. Given
-                * that this shouldn't be in the hot path for execution, it's a
-                * reasonable compromise in efficiency without introducing a
-                * noticeable impact on the overall system.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+          *  - greater-than “>”
+                *  - ampersand “&”
</ins><span class="cx" style="display: block; padding: 0 10px">                  *
</span><span class="cx" style="display: block; padding: 0 10px">                 * @see https://html.spec.whatwg.org/#attributes-2
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 *
-                * @todo As the only regex pattern maybe we should take it out?
-                *       Are Unicode patterns available broadly in Core?
</del><span class="cx" style="display: block; padding: 0 10px">                  */
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( preg_match(
-                       '~[' .
-                               // Syntax-like characters.
-                               '"\'>&</ =' .
-                               // Control characters.
-                               '\x{00}-\x{1F}' .
-                               // HTML noncharacters.
-                               '\x{FDD0}-\x{FDEF}' .
-                               '\x{FFFE}\x{FFFF}\x{1FFFE}\x{1FFFF}\x{2FFFE}\x{2FFFF}\x{3FFFE}\x{3FFFF}' .
-                               '\x{4FFFE}\x{4FFFF}\x{5FFFE}\x{5FFFF}\x{6FFFE}\x{6FFFF}\x{7FFFE}\x{7FFFF}' .
-                               '\x{8FFFE}\x{8FFFF}\x{9FFFE}\x{9FFFF}\x{AFFFE}\x{AFFFF}\x{BFFFE}\x{BFFFF}' .
-                               '\x{CFFFE}\x{CFFFF}\x{DFFFE}\x{DFFFF}\x{EFFFE}\x{EFFFF}\x{FFFFE}\x{FFFFF}' .
-                               '\x{10FFFE}\x{10FFFF}' .
-                       ']~Ssu',
-                       $name
-               ) ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if (
+                       0 === $name_length ||
+                       // Syntax-like characters.
+                       strcspn( $name, '"\'>&</ =' ) !== $name_length ||
+                       // Control characters.
+                       strcspn(
+                               $name,
+                               "\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F" .
+                               "\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F"
+                       ) !== $name_length ||
+                       // Unicode noncharacters.
+                       wp_has_noncharacters( $name )
+               ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         _doing_it_wrong(
</span><span class="cx" style="display: block; padding: 0 10px">                                __METHOD__,
</span><span class="cx" style="display: block; padding: 0 10px">                                __( 'Invalid attribute name.' ),
</span></span></pre></div>
<a id="trunktestsphpunittestshtmlapiwpHtmlTagProcessorphp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php 2025-10-21 03:31:55 UTC (rev 61002)
+++ trunk/tests/phpunit/tests/html-api/wpHtmlTagProcessor.php   2025-10-21 03:48:20 UTC (rev 61003)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -312,6 +312,68 @@
</span><span class="cx" style="display: block; padding: 0 10px">        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        /**
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         * Ensures that set_attribute doesn’t allow setting an
+        * attribute with an invalid name and thus break syntax.
+        *
+        * @ticket 63863
+        *
+        * @expectedIncorrectUsage WP_HTML_Tag_Processor::set_attribute
+        *
+        * @dataProvider data_invalid_attribute_names
+        *
+        * @param string $invalid_name Invalid attribute name.
+        */
+       public function test_set_attribute_rejects_invalid_names( $invalid_name ) {
+               $processor = new WP_HTML_Tag_Processor( '<div>' );
+               $processor->next_tag();
+
+               $this->assertFalse(
+                       $processor->set_attribute( $invalid_name, true ),
+                       'Should have rejected invalid attribute name.'
+               );
+       }
+
+       /**
+        * Data provider.
+        *
+        * @return array[]
+        */
+       public static function data_invalid_attribute_names() {
+               $invalid_names = array(
+                       'Empty' => array( '' ),
+               );
+
+               // Syntax-like characters.
+               foreach ( str_split( '"\'>&</ =' ) as $c ) {
+                       $invalid_names[ $c ] = array( "too{$c}late" );
+               }
+
+               // C0 controls.
+               for ( $i = 0; $i <= 0x1F; $i++ ) {
+                       $c                                    = chr( $i );
+                       $invalid_names[ "C0 Controls: {$i}" ] = array( "shut{$c}down" );
+               }
+
+               // Noncharacters.
+               for ( $i = 0xFDD0; $i <= 0xFDEF; $i++ ) {
+                       $h                                       = dechex( $i );
+                       $c                                       = mb_chr( $i );
+                       $invalid_names[ "Noncharacter: U+{$h}" ] = array( "shut{$c}down" );
+               }
+
+               for ( $b = 0; $b <= 16; $b++ ) {
+                       for ( $x = 0xFFFE; $x <= 0xFFFF; $x++ ) {
+                               $i                                       = ( $b << 16 ) + $x;
+                               $h                                       = dechex( $i );
+                               $c                                       = mb_chr( $i );
+                               $invalid_names[ "Noncharacter: U+{$h}" ] = array( "shut{$c}down" );
+                       }
+               }
+
+               return $invalid_names;
+       }
+
+       /**
</ins><span class="cx" style="display: block; padding: 0 10px">          * @ticket 56299
</span><span class="cx" style="display: block; padding: 0 10px">         *
</span><span class="cx" style="display: block; padding: 0 10px">         * @covers WP_HTML_Tag_Processor::get_attribute_names_with_prefix
</span></span></pre>
</div>
</div>

</body>
</html>