Repository navigation
Posts: Improve display of post titles containing HTML in the admin. - #14019
shail-mehta wants to merge 9 commits into
Conversation
Add wp_kses_post_title() and use it for admin title output instead of esc_html(), allowing a subset of inline formatting tags while stripping unsafe markup. Strip tags for aria-labels and row action strings. Fixes #66244.
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
Align wp_kses_post_title unit test expectations with core KSES (script element removed, inner text retained). Simplify the posts list table test title and sanitize before stripping for row aria-labels. Fixes #66244.
Move wp_kses_post_title tests into Tests_Kses, simplify the posts list table test, and remove the_title filter after list table display_rows to avoid polluting the suite. Fixes #66244.
Decode entities and strip tags for the posts list primary column aria-label, and drop the ampersand from the list table regression title so CI matches wp_kses behavior. Fixes #66244.
…dit. Pass post object explicitly to _draft_or_post_title() in list tables, grant super admin in multisite so HTML formatting attributes in titles are preserved on post save, and scope the unescaped formatting check to the row-title link to avoid false failures on quick-edit inline data. Fixes #66244.
…st table tests. setAccessible() is redundant on PHP 8.1+ and deprecated in PHP 8.5+, which causes PHPUnit deprecation errors when run with convertDeprecationsToExceptions enabled. Guard the call with PHP_VERSION_ID < 80100 to match core conventions. Fixes #66244.
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Trac ticket: #66244
What
Improves how post titles that contain HTML are displayed in the WordPress admin.
Many admin screens use
esc_html()on titles (including_draft_or_post_title()). A title such asThe <em>page</em> titleis shown as encoded markup (<em>page</em>) instead of rendered formatting.This PR:
wp_kses_post_title()with a limited allowlist of inline formatting tags.esc_html()towp_kses_post_title()where titles are shown in HTML.aria-label/ row-action strings so accessibility text stays plain.Why
Follow-up to Trac #64748 and PR #11088, which scoped the privacy policy link on the front end. Core allows HTML in post titles; the dashboard should render permitted formatting safely instead of showing raw tag text.
How
wp_kses_post_title()(src/wp-includes/post-template.php) -wp_kses()allowlist:strong,em,b,i,span(withclass), aligned with the privacy policy title approach in trunk._draft_or_post_title()- returnswp_kses_post_title( $title )instead ofesc_html( $title ).WP_Posts_List_Table/WP_Media_List_Table-the_titlefilter useswp_kses_post_titleinstead ofesc_html.comment.php,edit-form-comment.php,WP_Comments_List_Table) - post titles in “In response to” usewp_kses_post_title().dashboard.php) - formatted title in link text;wp_strip_all_tags()foraria-label.get_primary_column_aria_label(), post/media row actions, and attach labels use stripped titles where attributes must be plain text.Testing instructions
The <em class="title">page</em> title.<em>.<script>alert(1)</script>- no script in list output.aria-labelvalues are plain text (no HTML).PHPUnit:
npm run test:php -- --filter wpKsesPostTitlenpm run test:php -- --filter test_post_title_formatting_tags_are_rendered_in_list_tableUse of AI Tools