Skip to content

Export: Stabilize pattern sanitization - #865

Open
MaggieCabrera wants to merge 1 commit into
trunkfrom
codex/export-stabilize-pattern-sanitization
Open

Export: Stabilize pattern sanitization#865
MaggieCabrera wants to merge 1 commit into
trunkfrom
codex/export-stabilize-pattern-sanitization

Conversation

@MaggieCabrera

Copy link
Copy Markdown
Contributor

Summary

Repeat pattern sanitization until the exported content is stable.

This keeps adjacent fragments from forming a new removable sequence after an earlier replacement.

Test plan

  • vendor/bin/phpunit -c phpunit.xml.dist --verbose --filter Test_Create_Block_Theme_Patterns
  • vendor/bin/phpcs --standard=phpcs.xml.dist includes/create-theme/theme-patterns.php tests/test-theme-patterns.php
  • Confirmed overlapping and legacy-script variants remain parse-clean while ordinary block markup is preserved.

@MaggieCabrera
MaggieCabrera requested review from scruffian and a lite review from Copilot August 20, 2026 15:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves the export pipeline’s defense-in-depth for wp_block pattern bodies by ensuring PHP-tag sanitization is applied repeatedly until the content no longer changes, preventing adjacent fragments from combining into newly-detectable PHP open-tag sequences after earlier removals.

Changes:

  • Update CBT_Theme_Patterns::strip_php_tags() to iterate sanitization passes until the output is stable.
  • Add PHPUnit coverage for overlapping <? fragments and for cases where legacy <script language="php">…</script> removal can expose new <? sequences.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
includes/create-theme/theme-patterns.php Makes strip_php_tags() repeat sanitization passes until no further changes occur, preventing bypass via adjacent-fragment recombination.
tests/test-theme-patterns.php Adds tests that assert sanitization stability for overlapping-open-tag and legacy-script-removal edge cases.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants