Repository navigation
Comments: Rebuild embed players instead of running kses on them - #53380
Conversation
|
Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.
Interested in more tips and information?
|
|
Thank you for your PR! When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:
This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖 Follow this PR Review Process:
If you have questions about anything, reach out in #jetpack-developers for guidance! |
Code Coverage SummaryThis PR did not change code coverage! That could be good or bad, depending on the situation. Everything covered before, and still is? Great! Nothing was covered before? Not so great. 🤷 |
Proposed changes
[youtube …]text instead of a player on WordPress.com, in both the editor preview and the posted comment.wp_kses(). On WordPress.com,pre_ksesreversals turn known players into shortcodes, and nothing expanded them. Those are the Shortcodes module's reversals plus wpcom'sFilter_Embedded_HTML_Objectsregistrations, covering YouTube, Slideshare, SoundCloud, Kickstarter and Flickr.Embeds::sanitize_html()no longer runs kses. It reads the provider's HTML withWP_HTML_Tag_Processorand writes the first<iframe>or<img>as a new tag. Onlysrc(https) plus a short list of attributes come along. Scripts, inline handlers,srcdocand inline styles never get copied.Does this pull request change what data or activity we track or use?
No.
Testing instructions
[youtube …]text. Post it and check the comment shows the player.