Conversation
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
dmsnell
force-pushed
the
kses/dual-with-tag-processor
branch
22 times, most recently
from
August 27, 2026 17:00
c784058 to
fdc5e96
Compare
dmsnell
force-pushed
the
kses/dual-with-tag-processor
branch
5 times, most recently
from
August 28, 2026 04:31
bd15b3e to
38470b2
Compare
…alues." This reverts commit ba325c1.
Co-Authored-By: Jon Surrell <jonsurrell@git.wordpress.org>
Notably, contents of SCRIPT elements _should not_ be extracted and rendered as HTML text nodes. These are SCRIPT contents, and should be hidden from the page.
…ng the original content.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Trac ticket: Core-66208
Trac ticket: Core-65984
Replaces #6577
Description
Rewrites
wp_kses()to rely on the HTML API for structural and reliable application of sanitization rules, normalizing the output for improved downstream parsing.Notables
wp_kses_force_legacy_parserprovides the choice of whether to use this new parser or stick with the legacy code.Fixes
wp_kses_split()calls.wp_kses().wp_kses()turns SCRIPT and STYLE content into renderable text.wp_kses()and HTML disagree on the set of named character references.parse_blocks()called unnecessarily.wp_kses()un-comments HTML comments.wp_kses_post()incorrectly escapes "<" attributes values.Todo
Merge after #13273, which accounts for three of the failing tests.wp_kses(), it’s possible to simply wait until an opened element is closed based on depth, and skip that closing element if it exists.wp_kses()with intentionally-incomplete input, for example, a wrapper opening tag with part of the content, separately from the closer. closing open elements does a good job of isolating content, but legacy behaviors depend too much on the more procedural use ofwp_kses()so isolation cannot be reasonably added without mangling websites.pre_ksesfilters but then callpre_ksesserialize_to_xml()instead).xmlcontext, it only leaves the five syntax characters as names, and decodes everything else. This is correlated with the default behavior for the new implementation for XML and HTML.wp_kses()is entirely inappropriate for XML inputs or XML outputs. That requiresserialize_to_xml().Notes