Skip to content

Comments: Rebuild embed players instead of running kses on them - #53380

Merged
arcangelini merged 6 commits into
trunkfrom
fix/comments-youtube-embed-shortcode
Oct 8, 2026
Merged

arcangelini merged 6 commits into
trunkfrom
fix/comments-youtube-embed-shortcode

Conversation

@arcangelini

@arcangelini arcangelini commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Proposed changes

  • Fix YouTube embeds showing [youtube …] text instead of a player on WordPress.com, in both the editor preview and the posted comment.
  • Cause: since Comments: strip provider scripts from embeds and skip previews in wp-admin #53364 the embed HTML goes through wp_kses(). On WordPress.com, pre_kses reversals turn known players into shortcodes, and nothing expanded them. Those are the Shortcodes module's reversals plus wpcom's Filter_Embedded_HTML_Objects registrations, covering YouTube, Slideshare, SoundCloud, Kickstarter and Flickr.
  • Embeds::sanitize_html() no longer runs kses. It reads the provider's HTML with WP_HTML_Tag_Processor and writes the first <iframe> or <img> as a new tag. Only src (https) plus a short list of attributes come along. Scripts, inline handlers, srcdoc and inline styles never get copied.
  • Embeds that need a provider script, such as TikTok and Reddit, return nothing, so the editor and the posted comment show a link. Since Comments: strip provider scripts from embeds and skip previews in wp-admin #53364 stripped their scripts, they only rendered as a static blockquote anyway.
  • No cleanup needed: posted comments sanitize at render and cached previews sanitize on the way out.

Does this pull request change what data or activity we track or use?

No.

Testing instructions

  • On a WordPress.com Simple site with Jetpack Comments on, open a post and start a comment.
  • Add an embed with "/" > Embed and a YouTube URL. The preview shows a player, not [youtube …] text. Post it and check the comment shows the player.
  • Repeat with Vimeo or Spotify: still a player.
  • Try a TikTok URL: it becomes a link.

@arcangelini arcangelini self-assigned this Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.

  • To test on WoA, go to the Plugins menu on a WoA dev site. Click on the "Upload" button and follow the upgrade flow to be able to upload, install, and activate the Jetpack Beta plugin. Once the plugin is active, go to Jetpack > Jetpack Beta, select your plugin (Jetpack or WordPress.com Site Helper), and enable the fix/comments-youtube-embed-shortcode branch.
  • To test on Simple, run the following command on your sandbox:
bin/jetpack-downloader test jetpack fix/comments-youtube-embed-shortcode
bin/jetpack-downloader test jetpack-mu-wpcom-plugin fix/comments-youtube-embed-shortcode

Interested in more tips and information?

  • In your local development environment, use the jetpack rsync command to sync your changes to a WoA dev blog.
  • Read more about our development workflow here: PCYsg-eg0-p2
  • Figure out when your changes will be shipped to customers here: PCYsg-eg5-p2

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thank you for your PR!

When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:

  • ✅ Include a description of your PR changes.
  • ✅ Add a "[Status]" label (In Progress, Needs Review, ...).
  • ✅ Add testing instructions.
  • ✅ Specify whether this PR includes any changes to data or privacy.
  • ✅ Add changelog entries to affected projects

This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖


Follow this PR Review Process:

  1. Ensure all required checks appearing at the bottom of this PR are passing.
  2. Make sure to test your changes on all platforms that it applies to. You're responsible for the quality of the code you ship.
  3. You can use GitHub's Reviewers functionality to request a review.
  4. When it's reviewed and merged, you will be pinged in Slack to deploy the changes to WordPress.com simple once the build is done.

If you have questions about anything, reach out in #jetpack-developers for guidance!

@arcangelini
arcangelini requested a review from a team October 8, 2026 18:47
@jp-launch-control

jp-launch-control Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Code Coverage Summary

This PR did not change code coverage!

That could be good or bad, depending on the situation. Everything covered before, and still is? Great! Nothing was covered before? Not so great. 🤷

Full summary · PHP report · JS report

@arcangelini arcangelini changed the title Comments: Keep YouTube embeds as players when sanitizing Comments: Rebuild embed players instead of running kses on them Oct 8, 2026
@arcangelini
arcangelini merged commit b557e88 into trunk Oct 8, 2026
79 of 80 checks passed
@arcangelini
arcangelini deleted the fix/comments-youtube-embed-shortcode branch October 8, 2026 20:01
@github-actions github-actions Bot added [Status] UI Changes Add this to PRs that change the UI so documentation can be updated. and removed [Status] Needs Review This PR is ready for review. labels Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Package] Comments [Status] UI Changes Add this to PRs that change the UI so documentation can be updated.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant