strip out mailto: from author email uri with wp_parse_url #229
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
WordPress has an is_email function. We probably should validate the output as an email address and if not, reject it.
|
It doesn't look like the $author['url'] is validated either? |
|
I agree, we should improve both. |
|
What if it has no |
|
is_email has a warning: Does not grok i18n domains. Not RFC compliant. I wrote quick test: |
|
We can use filter_var, I just think we should start validating urls and emails properly. |
|
I didn't look at filter_var details. What should the behavior be when it's an invalid email? |
|
It should not save the parameter |
…tic-linkbacks into remotes/origin/mailto-bugfixes2
unicode emails non available until PHP 7.1.0 requiresFILTER_FLAG_EMAIL_UNICODE (integer) Accepts Unicode characters in the local part in "validate_email" filter. (Available as of PHP 7.1.0)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
validate email with filter_var FILTER_VALIDATE_EMAIL. unicode emails will fail validation (requires PHP 7.1.0 to turn it on)
|
I'm not convinced this is working right... do the tests cover any of this code? |
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
No description provided.