| Server IP : 104.26.2.156 / Your IP : 216.73.216.185 Web Server : nginx/1.27.1 System : Linux us-1 5.15.0-131-generic #141-Ubuntu SMP Fri Jan 10 21:18:28 UTC 2025 x86_64 User : vinodai ( 3134) PHP Version : 7.4.33 Disable Function : exec,passthru,shell_exec,system,proc_open,popen,parse_ini_file,show_source MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /storage/v1396/themastermynd/public_html/wp-content/plugins/mailpoet/lib/Form/ |
Upload File : |
<?php // phpcs:ignore SlevomatCodingStandard.TypeHints.DeclareStrictTypes.DeclareStrictTypesMissing
namespace MailPoet\Form;
if (!defined('ABSPATH')) exit;
use MailPoet\WP\Functions as WPFunctions;
class FormHtmlSanitizer {
/**
* @var array
* Configuration of allowed tags for form blocks that may contain some html.
* Covers all tags available in the form editor's Rich Text component and which we allow in checkbox label.
* This doesn't cover CustomHTML block.
*/
const ALLOWED_HTML = [
'a' => [
'class' => true,
'href' => true,
'title' => true,
'data-id' => true,
'data-type' => true,
'target' => true,
'rel' => true,
],
'br' => [],
'code' => [],
'em' => [],
'img' => [
'class' => true,
'style' => true,
'src' => true,
'alt' => true,
],
'kbd' => [],
'span' => [
'style' => true,
'data-font' => true,
'class' => true,
],
'mark' => [
'style' => true,
'class' => true,
],
'strong' => [],
'sub' => [],
'sup' => [],
's' => [],
];
/** @var WPFunctions */
private $wp;
public function __construct(
WPFunctions $wp
) {
$this->wp = $wp;
}
public function sanitize(string $html): string {
return $this->wp->wpKses($html, self::ALLOWED_HTML);
}
}