Skip to content

Commit

Permalink
Escape and sanitise a lot of stuff (#24)
Browse files Browse the repository at this point in the history
  • Loading branch information
Luehrsen authored Aug 23, 2021
1 parent db4bad8 commit 5af612f
Show file tree
Hide file tree
Showing 3 changed files with 18,231 additions and 109 deletions.
8 changes: 4 additions & 4 deletions build/inc/Schema_Honorific/Component.php
Original file line number Diff line number Diff line change
Expand Up @@ -69,11 +69,11 @@ public function extend_user_profile( $user ) {
*/
public function update_user_profile( $user_id ) {
if ( isset( $_POST['wpm-honorific-prefix'] ) ) {
update_user_meta( $user_id, 'wpm-honorific-prefix', $_POST['wpm-honorific-prefix'] );
update_user_meta( $user_id, 'wpm-honorific-prefix', sanitize_text_field( $_POST['wpm-honorific-prefix'] ) );
}

if ( isset( $_POST['wpm-honorific-suffix'] ) ) {
update_user_meta( $user_id, 'wpm-honorific-suffix', $_POST['wpm-honorific-suffix'] );
update_user_meta( $user_id, 'wpm-honorific-suffix', sanitize_text_field( $_POST['wpm-honorific-suffix'] ) );
}
}

Expand All @@ -88,11 +88,11 @@ public function update_user_profile( $user_id ) {
*/
public function extend_schema_person_data( $data, $user_id ) {
if ( ! empty( get_user_meta( $user_id, 'wpm-honorific-prefix', true ) ) ) {
$data['honorificPrefix'] = get_user_meta( $user_id, 'wpm-honorific-prefix', true );
$data['honorificPrefix'] = esc_attr( get_user_meta( $user_id, 'wpm-honorific-prefix', true ) );
}

if ( ! empty( get_user_meta( $user_id, 'wpm-honorific-suffix', true ) ) ) {
$data['honorificSuffix'] = get_user_meta( $user_id, 'wpm-honorific-suffix', true );
$data['honorificSuffix'] = esc_attr( get_user_meta( $user_id, 'wpm-honorific-suffix', true ) );
}

return $data;
Expand Down
2 changes: 1 addition & 1 deletion build/inc/Schema_Spouse/Component.php
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ public function extend_user_profile( $user ) {
* @return void
*/
public function update_user_profile( $user_id ) {
update_user_meta( $user_id, 'wpm-spouse', $_POST['wpm-spouse'] );
update_user_meta( $user_id, 'wpm-spouse', sanitize_text_field( $_POST['wpm-spouse'] ) );
}

/**
Expand Down
Loading

0 comments on commit 5af612f

Please sign in to comment.