Adds a few escapes before echoes for better security.

This commit is contained in:
mateuswetah 2022-05-23 11:45:01 -03:00
parent de76ea0a11
commit a609b6631b
8 changed files with 22 additions and 22 deletions

View File

@ -299,12 +299,12 @@ if ( !function_exists('tainacan_blocksy_item_navigation') ) {
if ($previous !== '' || $next !== '') {
echo '<nav class="' . esc_attr( $container_class ) . '">';
if ( $previous !== '' ) {
echo $previous;
echo wp_kses_post($previous);
} else {
echo '<div class="nav-item-prev"></div>';
}
if ( $next !== '' ) {
echo $next;
echo wp_kses_post($next);
} else {
echo '<div class="nav-item-next"></div>';
}

View File

@ -200,25 +200,25 @@
id="path907"
style="fill:#b3b3b3;fill-opacity:1;stroke-width:1.08129" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect889"
width="78.008156"
height="0.59999913"
x="10.994801"
y="20.186007" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect4054"
width="78.008156"
height="0.59999913"
x="10.994801"
y="49.34071" />
<path
style="fill:#d6d8d9;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="path4078"
d="m 15.850018,17.60136 -0.470371,-0.814706 -0.470371,-0.814706 0.940742,0 0.940741,0 -0.470371,0.814706 z" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect6699"
width="78.008156"
height="0.59999913"
@ -229,7 +229,7 @@
id="path6697"
style="fill:#b3b3b3;fill-opacity:1;stroke-width:1.23198" />
<path
style="fill:#d6d8d9;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="path6701"
transform="translate(0,0.03187731)"
d="m 15.949455,54.361688 -0.470371,-0.814706 -0.47037,-0.814706 0.940741,0 0.940742,0 -0.470371,0.814706 z" />

Before

Width:  |  Height:  |  Size: 14 KiB

After

Width:  |  Height:  |  Size: 14 KiB

View File

@ -140,25 +140,25 @@
id="path907"
style="fill:#b3b3b3;fill-opacity:1;stroke-width:1.08129" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect889"
width="78.008156"
height="0.59999913"
x="10.994801"
y="20.186007" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect4054"
width="78.008156"
height="0.59999913"
x="10.994801"
y="49.34071" />
<path
style="fill:#d6d8d9;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="path4078"
d="m 15.850018,17.60136 -0.470371,-0.814706 -0.470371,-0.814706 0.940742,0 0.940741,0 -0.470371,0.814706 z" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect6699"
width="78.008156"
height="0.59999913"
@ -169,12 +169,12 @@
id="path6697"
style="fill:#b3b3b3;fill-opacity:1;stroke-width:1.23198" />
<path
style="fill:#d6d8d9;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="path6701"
transform="rotate(-90,15.965394,53.291351)"
d="m 15.949455,54.361688 -0.470371,-0.814706 -0.47037,-0.814706 0.940741,0 0.940742,0 -0.470371,0.814706 z" />
<rect
style="fill:#e6e7e8;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="rect954"
width="78.008156"
height="0.59999913"
@ -185,7 +185,7 @@
id="path956"
style="fill:#b3b3b3;fill-opacity:1;stroke-width:0.965364" />
<path
style="fill:#d6d8d9;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
style="fill:#b3b3b3;fill-opacity:1;stroke:#ffca47;stroke-width:0;stroke-opacity:0"
id="path958"
transform="rotate(-90,19.903542,57.229499)"
d="m 15.949455,54.361688 -0.470371,-0.814706 -0.47037,-0.814706 0.940741,0 0.940742,0 -0.470371,0.814706 z" />

Before

Width:  |  Height:  |  Size: 11 KiB

After

Width:  |  Height:  |  Size: 11 KiB

View File

@ -43,12 +43,12 @@ global $post;
?>
<?php get_header(); ?>
<article class="<?php echo $page_container_classes ?>" style="<?php echo $page_container_style ?>">
<article class="<?php echo esc_attr($page_container_classes) ?>" style="<?php echo esc_attr($page_container_style) ?>">
<header
class="tainacan-collection-header"
style="background-image:
<?php if ( get_header_image() ) {
echo('linear-gradient(to bottom, rgba(255, 255, 255, ' . (get_theme_mod($prefix . '_page_header_background_style', 'boxed') == 'boxed' ? '0.3' : '0.8') . '), var(--tainacan-background-color, var(--background-color, #f8f9fb))), url(' . get_header_image() . ')');
echo('linear-gradient(to bottom, rgba(255, 255, 255, ' . (get_theme_mod($prefix . '_page_header_background_style', 'boxed') == 'boxed' ? '0.3' : '0.8') . '), var(--tainacan-background-color, var(--background-color, #f8f9fb))), url(' . esc_url(get_header_image()) . ')');
} else {
echo '';
} ?>"

View File

@ -44,7 +44,7 @@ $page_container_style .= 'background-color: var(--tainacan-background-color, #f8
<?php get_header(); ?>
<article class="<?php echo $page_container_classes ?>" style="<?php echo $page_container_style ?>">
<article class="<?php echo esc_attr($page_container_classes) ?>" style="<?php echo esc_attr($page_container_style) ?>">
<header class="tainacan-collection-header tainacan-collection-header--repository-page">
<div class="tainacan-collection-header__box">
<?php

View File

@ -50,7 +50,7 @@ $thumbnail_src = wp_get_attachment_image_src($image, 'full');
?>
<?php get_header(); ?>
<article class="<?php echo $page_container_classes ?>" style="<?php echo $page_container_style ?>">
<article class="<?php echo esc_attr($page_container_classes) ?>" style="<?php echo esc_attr($page_container_style) ?>">
<header class="tainacan-collection-header tainacan-collection-header--term-page">
<div class="tainacan-collection-header__box">

View File

@ -74,7 +74,7 @@ add_action( 'blocksy:hero:before', function() use ( $page_structure_type, $prefi
});
?>
<div class="<?php echo 'tainacan-item-single tainacan-item-single--layout-'. $page_structure_type ?>" style="<?php echo $template_columns_style ?>">
<div class="<?php echo esc_attr('tainacan-item-single tainacan-item-single--layout-'. $page_structure_type) ?>" style="<?php echo esc_attr($template_columns_style) ?>">
<?php
if ($page_structure_type !== 'type-gtm') {
tainacan_blocksy_get_template_part( 'template-parts/tainacan-item-single-document' );