[wp-trac] [WordPress Trac] #41215: Escaping the value of the srcset attribute

WordPress Trac noreply at wordpress.org
Wed Jul 26 13:21:39 UTC 2017


#41215: Escaping the value of the srcset attribute
--------------------------+-----------------------------
 Reporter:  henry.wright  |       Owner:  SergeyBiryukov
     Type:  defect (bug)  |      Status:  closed
 Priority:  normal        |   Milestone:  4.9
Component:  Users         |     Version:
 Severity:  normal        |  Resolution:  fixed
 Keywords:  has-patch     |     Focuses:
--------------------------+-----------------------------
Changes (by SergeyBiryukov):

 * owner:   => SergeyBiryukov
 * status:  new => closed
 * resolution:   => fixed


Comment:

 In [changeset:"41156"]:
 {{{
 #!CommitTicketReference repository="" revision="41156"
 Users: Use `esc_url()` instead of `esc_attr()` to escape the value of the
 `srcset` attribute in `get_avatar()`.

 Props joemcgill, henry.wright.
 Fixes #41215.
 }}}

--
Ticket URL: <https://core.trac.wordpress.org/ticket/41215#comment:7>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list