[wp-trac] [WordPress Trac] #32816: No or inadequate Custom Link URL validation

WordPress Trac noreply at wordpress.org
Mon Dec 5 12:01:31 UTC 2016


#32816: No or inadequate Custom Link URL validation
-------------------------------------------------+-------------------------
 Reporter:  JanR                                 |       Owner:
     Type:  enhancement                          |      Status:  new
 Priority:  normal                               |   Milestone:  4.8
Component:  Customize                            |     Version:  4.3
 Severity:  normal                               |  Resolution:
 Keywords:  good-first-bug needs-testing needs-  |     Focuses:  ui,
  patch                                          |  javascript
-------------------------------------------------+-------------------------
Changes (by westonruter):

 * keywords:  good-first-bug has-patch needs-testing => good-first-bug
     needs-testing needs-patch


Comment:

 Another reason to defer to PHP-only validation is that calls to
 `esc_url_raw()` will return with the value passed through the `clean_url`
 filter, and so we have no idea at all what ultimately PHP via plugins will
 decide is a valid URL.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/32816#comment:16>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list