Skip to content

fix: escape calendar item action link hrefs with esc_url() and link text with esc_html__() - #1016

Open
thisismyurl wants to merge 9 commits into
Automattic:developfrom
thisismyurl:fix/calendar-item-action-link-escaping
Open

thisismyurl wants to merge 9 commits into
Automattic:developfrom
thisismyurl:fix/calendar-item-action-link-escaping

Conversation

@thisismyurl

Copy link
Copy Markdown
Contributor

`EF_Calendar::get_inner_information()` builds five action links for each calendar item — Edit, Trash, Preview, View, and Save. Three of those hrefs came from functions that return plain URLs (`get_edit_post_link()`, `get_delete_post_link()`, `get_permalink()`), and all five link text strings used `__()` directly. Neither set went through an escape function.

PR #993 made the same fix for `story-budget.php`; the calendar module's `item_actions` block was the parallel section that was missed.

This PR wraps the three hrefs in `esc_url()` and changes all five link-text calls to `esc_html__()`. The Preview branch already had `esc_url()` on its href — only the link text needed updating there.

The new test class `CalendarEscapingTest` injects a URL with a bare `&` via a WordPress filter (`get_edit_post_link`, `post_link`) and asserts the output contains `&` (what `esc_url()` produces for `&`) rather than the raw `&`. A separate assertion confirms no raw `&` survives in any href attribute. `test_calendar_view_link_href_is_url_escaped` uses a published post so `get_permalink()` is the active code path (not the preview branch). The trash link is omitted from integration coverage because `get_delete_post_link()` routes through `wp_nonce_url()` which pre-encodes `&` as `&` — an integration test for that path cannot distinguish "esc_url() ran" from "wp_nonce_url() pre-encoded the value."

Tests reviewed by inspection; not executed locally (no integration harness in my environment) — relying on CI for the first run.

No visual or interaction change; escaping only, link text and structure unchanged, no a11y impact.

(props @thisismyurl)

(full disclosure: AI helped me identify the issue and verify my work)

@thisismyurl
thisismyurl requested a review from a team as a code owner June 22, 2026 12:54
@GaryJones

Copy link
Copy Markdown
Contributor

Reviewed — fix is correct, CI green. The escaping is right and the mutation-style tests (assert &, deny raw &) are a solid regression guard; good call documenting why the trash path can't be covered at the integration layer.

One scope question: the item_actions block is fully handled, but two other spots still pass a URL into an href without esc_url() — calendar.php:110 and story-budget.php:105, both admin_url() inside a translated short_description. They're static/safe so not blocking, but if this is meant to close out the escaping sweep rather than just this block, worth folding in (here or a follow-up).

Copilot AI review requested due to automatic review settings July 13, 2026 14:17
@thisismyurl

Copy link
Copy Markdown
Contributor Author

Thanks @GaryJones — folded both in (63b1e7d). calendar.php and story-budget.php now wrap their admin_url() short-description hrefs with esc_url(), and the changelog has a matching entry. That should close out the escaping sweep for this surface rather than leaving a follow-up dangling.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens output escaping in the Calendar module’s per-item action links and in module “short_description” admin links, and adds integration coverage to prevent regressions in calendar item action link escaping.

Changes:

  • Escape Calendar item action link href values with esc_url() and action link text with esc_html__() in EF_Calendar::get_inner_information().
  • Escape admin_url()-based links embedded in the Calendar and Story Budget module short descriptions.
  • Add a new integration test (CalendarEscapingTest) to assert href URLs are escaped (specifically, bare & becomes &).

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
modules/calendar/calendar.php Escapes calendar action link URLs and link text; escapes module short-description URL.
modules/story-budget/story-budget.php Escapes the short-description link URL with esc_url().
tests/Integration/CalendarEscapingTest.php New regression test for calendar action link URL escaping.
CHANGELOG.md Adds Unreleased security notes documenting these escaping fixes.

Comment thread tests/Integration/CalendarEscapingTest.php
Comment thread tests/Integration/CalendarEscapingTest.php
@thisismyurl
thisismyurl force-pushed the fix/calendar-item-action-link-escaping branch from 63b1e7d to 5539153 Compare September 22, 2026 18:04
Failing checks: WP latest and PHP latest
@GaryJones

Copy link
Copy Markdown
Contributor

Thanks @thisismyurl, the escaping changes look good and CI is green. There are two things I'd like to sort out before merging:

  1. Please drop the CHANGELOG.md changes. We write the changelog when we cut a release, not in individual PRs, so the [Unreleased] section shouldn't be here. Removing a7ac605 and 39d07b4, or reverting the file to match develop, is fine.

  2. The UserGroupsAjaxTest change in e717259. That test doesn't fail on develop, so I'd like to know why the administrator lost edit_usergroups on this branch before we patch the test around it. Did you see it fail more than once, or was it a single failure on the "WP latest" job? If it's a real order dependency, I'd rather fix that in its own PR with a commit message that explains it. Could you take it out of this one for now?

Both Copilot comments can be resolved as they stand. PHP closures ignore extra arguments, so the "too many arguments" warning won't happen. The test case also restores hooks after each test, so remove_all_filters() is harmless here.

@GaryJones

Copy link
Copy Markdown
Contributor

One more thing: the develop branch only accepts commits with a verified signature, and none of the commits here are signed yet. While you're making the changes above, could you re-sign the commits on the branch? GitHub's guide to signing commits covers the setup. Once that's configured, git rebase --exec 'git commit --amend --no-edit -S' origin/develop followed by a force push will re-sign everything in one go. There's more detail in CONTRIBUTING.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants