Skip to content

Posts: Improve display of post titles containing HTML in the admin. - #14019

Open
shail-mehta wants to merge 9 commits into
WordPress:trunkfrom
shail-mehta:fix/66244-admin-post-title-html
Open

shail-mehta wants to merge 9 commits into
WordPress:trunkfrom
shail-mehta:fix/66244-admin-post-title-html

Conversation

@shail-mehta

@shail-mehta shail-mehta commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Trac ticket: #66244

What

Improves how post titles that contain HTML are displayed in the WordPress admin.

Many admin screens use esc_html() on titles (including _draft_or_post_title()). A title such as The <em>page</em> title is shown as encoded markup (&lt;em&gt;page&lt;/em&gt;) instead of rendered formatting.

This PR:

  • Adds wp_kses_post_title() with a limited allowlist of inline formatting tags.
  • Switches admin title output from esc_html() to wp_kses_post_title() where titles are shown in HTML.
  • Strips tags for aria-label / row-action strings so accessibility text stays plain.

Why

Follow-up to Trac #64748 and PR #11088, which scoped the privacy policy link on the front end. Core allows HTML in post titles; the dashboard should render permitted formatting safely instead of showing raw tag text.

How

  • wp_kses_post_title() (src/wp-includes/post-template.php) - wp_kses() allowlist: strong, em, b, i, span (with class), aligned with the privacy policy title approach in trunk.
  • _draft_or_post_title() - returns wp_kses_post_title( $title ) instead of esc_html( $title ).
  • WP_Posts_List_Table / WP_Media_List_Table - the_title filter uses wp_kses_post_title instead of esc_html.
  • Comments admin (comment.php, edit-form-comment.php, WP_Comments_List_Table) - post titles in “In response to” use wp_kses_post_title().
  • Dashboard (dashboard.php) - formatted title in link text; wp_strip_all_tags() for aria-label.
  • A11y / actions - get_primary_column_aria_label(), post/media row actions, and attach labels use stripped titles where attributes must be plain text.

Testing instructions

  1. Create a post titled: The <em class="title">page</em> title.
  2. Posts → All Posts - “page” appears emphasized, not as &lt;em&gt;.
  3. Comments on that post - “In response to” shows formatted title.
  4. Dashboard - Recent drafts/posts show formatted title.
  5. Title with <script>alert(1)</script> - no script in list output.
  6. Confirm row/action aria-label values are plain text (no HTML).

PHPUnit:

  • npm run test:php -- --filter wpKsesPostTitle
  • npm run test:php -- --filter test_post_title_formatting_tags_are_rendered_in_list_table

Use of AI Tools

  • Cursor

Add wp_kses_post_title() and use it for admin title output instead of
esc_html(), allowing a subset of inline formatting tags while stripping
unsafe markup. Strip tags for aria-labels and row action strings.

Fixes #66244.
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

Align wp_kses_post_title unit test expectations with core KSES (script element removed, inner text retained). Simplify the posts list table test title and sanitize before stripping for row aria-labels.

Fixes #66244.
Move wp_kses_post_title tests into Tests_Kses, simplify the posts list table test, and remove the_title filter after list table display_rows to avoid polluting the suite.

Fixes #66244.
Decode entities and strip tags for the posts list primary column aria-label, and drop the ampersand from the list table regression title so CI matches wp_kses behavior.

Fixes #66244.
…dit.

Pass post object explicitly to _draft_or_post_title() in list tables, grant super admin in multisite so HTML formatting attributes in titles are preserved on post save, and scope the unescaped formatting check to the row-title link to avoid false failures on quick-edit inline data.

Fixes #66244.
…st table tests.

setAccessible() is redundant on PHP 8.1+ and deprecated in PHP 8.5+, which causes PHPUnit deprecation errors when run with convertDeprecationsToExceptions enabled. Guard the call with PHP_VERSION_ID < 80100 to match core conventions.

Fixes #66244.
@shail-mehta
shail-mehta marked this pull request as ready for review October 7, 2026 03:27
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props shailu25.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@shail-mehta shail-mehta self-assigned this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant