From 71a6aab25a0ad3adc56345a3d91b546653c28088 Mon Sep 17 00:00:00 2001
From: Alex Kirk
- content ),
- array(
- 'a' => array( 'href' => array() ),
- 'img' => array( 'src' => array() ),
- )
- );
- ?>
-
+
+ content );
+ ?>
+
+
+
+ date ); ?> (author: author ); ?>, type: post_format ); ?>):
+
+ content ) ) ); ?> words
+
+
Refresh
this feed now.', 'friends' ), esc_url( wp_nonce_url( add_query_arg( 'user', $args['friend']->user_login, self_admin_url( 'admin.php?page=friends-refresh' ) ), 'friends-refresh' ) ) ); + echo wp_kses( sprintf( __( 'Refresh this feed now.', 'friends' ), esc_url( wp_nonce_url( add_query_arg( 'user', $args['friend']->user_login, self_admin_url( 'admin.php?page=friends-refresh' ) ), 'friends-refresh' ) ) ), array( 'a' => array( 'href' => array() ) ) ); ?> diff --git a/templates/admin/edit-friend.php b/templates/admin/edit-friend.php index 3918699a..0b58c5a9 100644 --- a/templates/admin/edit-friend.php +++ b/templates/admin/edit-friend.php @@ -24,7 +24,7 @@ $_title ) { ?> -@@ -44,7 +44,7 @@
@@ -57,7 +57,7 @@
diff --git a/templates/email/accepted-friend-request-text.php b/templates/email/accepted-friend-request-text.php index 39e457d2..0e7a5c10 100644 --- a/templates/email/accepted-friend-request-text.php +++ b/templates/email/accepted-friend-request-text.php @@ -6,6 +6,9 @@ * @package Friends */ +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped + // translators: %s is a user display name. printf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ); echo PHP_EOL; diff --git a/templates/email/accepted-friend-request.php b/templates/email/accepted-friend-request.php index 1a2f0652..8d0b3c48 100644 --- a/templates/email/accepted-friend-request.php +++ b/templates/email/accepted-friend-request.php @@ -10,20 +10,20 @@
display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
display_name ) ); + echo esc_html( sprintf( __( 'Good news, %s has accepted your friend request.', 'friends' ), $args['friend_user']->display_name ) ); ?>
friends page and look at their posts.', 'friends' ), esc_url( $args['friend_user']->get_local_friends_page_url() ) ); + echo wp_kses( sprintf( __( 'Go to your friends page and look at their posts.', 'friends' ), esc_url( $args['friend_user']->get_local_friends_page_url() ) ), array( 'a' => array( 'href' => true ) ) ); ?>
diff --git a/templates/email/footer-text.php b/templates/email/footer-text.php index 0d0ede71..8fd0a66f 100644 --- a/templates/email/footer-text.php +++ b/templates/email/footer-text.php @@ -6,6 +6,9 @@ * @package Friends */ +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped + echo PHP_EOL . PHP_EOL; // translators: %1$s is a site name, %2$s is a site url. diff --git a/templates/email/friend-message-received-text.php b/templates/email/friend-message-received-text.php index 18361f5a..99aea8b4 100644 --- a/templates/email/friend-message-received-text.php +++ b/templates/email/friend-message-received-text.php @@ -11,6 +11,9 @@ $normalized_whitespace = preg_replace( '/(' . PHP_EOL . '\s*' . PHP_EOL . ')+/m', PHP_EOL . PHP_EOL, $plain_text ); $quoted_text = '> ' . str_replace( PHP_EOL, PHP_EOL . '> ', trim( $normalized_whitespace ) ); +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped + // translators: %s is a user display name. printf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ); echo PHP_EOL; diff --git a/templates/email/friend-message-received.php b/templates/email/friend-message-received.php index 811dc56d..0cef0551 100644 --- a/templates/email/friend-message-received.php +++ b/templates/email/friend-message-received.php @@ -10,14 +10,14 @@display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
display_name ) ); + echo esc_html( sprintf( __( 'We just received a message from %s:', 'friends' ), $args['friend_user']->display_name ) ); ?>
@@ -31,6 +31,6 @@friends page to respond.', 'friends' ), esc_url( $args['friend_user']->get_local_friends_page_url() ) ); + echo wp_kses( sprintf( __( 'Go to your friends page to respond.', 'friends' ), esc_url( $args['friend_user']->get_local_friends_page_url() ) ), array( 'a' => array( 'href' => true ) ) ); ?>
diff --git a/templates/email/keyword-match-post-text.php b/templates/email/keyword-match-post-text.php index ff8fac74..007f5ab0 100644 --- a/templates/email/keyword-match-post-text.php +++ b/templates/email/keyword-match-post-text.php @@ -11,6 +11,9 @@ $normalized_whitespace = preg_replace( '/(' . PHP_EOL . '\s*' . PHP_EOL . ')+/m', PHP_EOL . PHP_EOL, $plain_text ); $quoted_text = '> ' . str_replace( PHP_EOL, PHP_EOL . '> ', trim( $normalized_whitespace ) ); +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped + // translators: %s is a keyword string specified by the user. printf( __( 'Keyword matched: %s', 'friends' ), $args['keyword'] ); diff --git a/templates/email/keyword-match-post.php b/templates/email/keyword-match-post.php index f4f7d212..7213ba4b 100644 --- a/templates/email/keyword-match-post.php +++ b/templates/email/keyword-match-post.php @@ -64,13 +64,20 @@display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
@@ -24,7 +24,7 @@
display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
@@ -24,7 +24,7 @@
friends page to see what they recently posted about.', 'friends' ), esc_url( $args['following']->get_local_friends_page_url() ) ), array( 'a' => array( 'href' => array() ) ) ); diff --git a/templates/email/new-friend-post-text.php b/templates/email/new-friend-post-text.php index 050b610e..95c86dcd 100644 --- a/templates/email/new-friend-post-text.php +++ b/templates/email/new-friend-post-text.php @@ -1,6 +1,6 @@ ' . str_replace( PHP_EOL, PHP_EOL . '> ', trim( $normalized_whitespace ) ); +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped echo $quoted_text; echo PHP_EOL, PHP_EOL; diff --git a/templates/email/new-friend-post.php b/templates/email/new-friend-post.php index daf1c28e..b15318f9 100644 --- a/templates/email/new-friend-post.php +++ b/templates/email/new-friend-post.php @@ -56,13 +56,19 @@
display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
display_name ) ); + echo esc_html( sprintf( __( 'You have received a new friend request from %s.', 'friends' ), $args['friend_user']->display_name ) ); ?>
admin page to review the request and approve or delete it.', 'friends' ), esc_url( self_admin_url( 'users.php?role=friend_request' ) ) ); + echo wp_kses( sprintf( __( 'Go to your admin page to review the request and approve or delete it.', 'friends' ), esc_url( self_admin_url( 'users.php?role=friend_request' ) ) ), array( 'a' => array( 'href' => true ) ) ); ?>
diff --git a/templates/email/unknown-friend-message-received-text.php b/templates/email/unknown-friend-message-received-text.php index 7f3e1c78..039b5913 100644 --- a/templates/email/unknown-friend-message-received-text.php +++ b/templates/email/unknown-friend-message-received-text.php @@ -1,6 +1,6 @@ ' . str_replace( PHP_EOL, PHP_EOL . '> ', trim( $normalized_whitespace ) ); +// This is a text e-mail, not a place for HTML escaping. +// phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped + // translators: %s is a user display name. -printf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ); +printf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped echo PHP_EOL; // translators: %s is a username. -printf( __( 'We just received a message from %s:', 'friends' ), $args['sender_name'] ); +printf( __( 'We just received a message from %s:', 'friends' ), $args['sender_name'] ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped echo PHP_EOL . PHP_EOL; echo $quoted_text; // translators: %s is a URL. -printf( wp_strip_all_tags( __( 'Maybe you want to follow them to respond?', 'friends' ) ) ); +printf( wp_strip_all_tags( __( 'Maybe you want to follow them to respond?', 'friends' ) ) ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped echo PHP_EOL . PHP_EOL; -echo home_url( '?add-friend=' . esc_url( $args['feed_url'] ) ); +echo home_url( '?add-friend=' . esc_url( $args['feed_url'] ) ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped diff --git a/templates/email/unknown-friend-message-received.php b/templates/email/unknown-friend-message-received.php index 475ae3c1..8926cdb0 100644 --- a/templates/email/unknown-friend-message-received.php +++ b/templates/email/unknown-friend-message-received.php @@ -10,14 +10,14 @@display_name ) ); + echo esc_html( sprintf( __( 'Hi %s!', 'friends' ), $args['user']->display_name ) ); ?>
@@ -31,6 +31,6 @@
follow them to respond?', 'friends' ), esc_attr( home_url( '?add-friend=' . esc_url( $args['feed_url'] ) ) ) ); + echo wp_kses( sprintf( __( 'Maybe you want to follow them to respond?', 'friends' ), esc_attr( home_url( '?add-friend=' . esc_url( $args['feed_url'] ) ) ) ), array( 'a' => array( 'href' => true ) ) ); ?>
diff --git a/templates/embed/embed-content.php b/templates/embed/embed-content.php index ac0d4e0a..770ac675 100644 --- a/templates/embed/embed-content.php +++ b/templates/embed/embed-content.php @@ -31,7 +31,7 @@