Repository navigation
Conversation
Prevents `WP_Theme_JSON` from throwing fatal `TypeError`s when theme.json or global styles data contains values of the wrong type. Sanitization keeps schema leaves such as `css` and `spacingScale` whatever their type, so, for example, an array `css` value reached `explode()` in `process_blocks_custom_css()`. Values of unexpected types are now ignored: non-string `css` and `ref` values, a non-array `spacingScale` or non-string `spacingScale.unit`, shared block style variations that are not arrays, and `blockTypes` items that are not strings. Backports WordPress/gutenberg#84523. See #66286.
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
Trac ticket: https://core.trac.wordpress.org/ticket/66286
Backports WordPress/gutenberg#84523.
What
Stops
WP_Theme_JSONfrom throwing fatalTypeErrors when theme.json or global styles data contains values of the wrong type.Why
The Gutenberg report came from a live site where every front-end page fatalled:
sanitize()keeps schema leaves such ascssandspacingScalewhatever their type, so an arraycssvalue reachesexplode()inprocess_blocks_custom_css(). The same gap fatals in a few other places.What changed
Values of unexpected types are now ignored instead of crashing:
cssthat isn't a string produces no output (the reported crash).refthat isn't a string is ignored.spacingScalethat isn't an array, or aspacingScale.unitthat isn't a string, is ignored.blockTypesitems that aren't strings, are skipped.Valid data is unaffected.
Each case has a test. All nine new cases fail on trunk with a
TypeError.