Skip to content

get_block_wrapper_attributes: Ensures that user-provided attributes override the attributes generated by block supports#10922

Open
t-hamano wants to merge 20 commits intoWordPress:trunkfrom
t-hamano:64564-get-block-wrapper-attributes
Open

get_block_wrapper_attributes: Ensures that user-provided attributes override the attributes generated by block supports#10922
t-hamano wants to merge 20 commits intoWordPress:trunkfrom
t-hamano:64564-get-block-wrapper-attributes

Conversation

@t-hamano
Copy link
Contributor

@t-hamano t-hamano commented Feb 13, 2026

Note

This PR is the same as #10877. I submitted this new PR because I accidentally closed #10877 and it can no longer be reopened.

Trac ticket: https://core.trac.wordpress.org/ticket/64603


This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.

t-hamano and others added 6 commits February 13, 2026 19:47
…verride the attributes generated by block supports
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
@github-actions
Copy link

github-actions bot commented Feb 13, 2026

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props wildworks, westonruter.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions
Copy link

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.


$attributes[ $attribute_name ] = $extra_attributes[ $attribute_name ] . ' ' . $new_attributes[ $attribute_name ];
if ( $is_merged ) {
$attributes[ $attribute_name ] = $extra_attributes[ $attribute_name ] . ' ' . $new_attributes[ $attribute_name ];
Copy link
Member

@westonruter westonruter Feb 13, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For posterity, #10877 (comment):

In the case of merging style, should special handling be added to ensure that $extra_attributes[ $attribute_name ] ends in a semicolon? The current empty space is only really appropriate for class.

@t-hamano
Copy link
Contributor Author

Sorry for the late reply.

After some consideration, I decided to refactor the get_block_wrapper_attributes() function overall to make it more robust and secure.

  • Define callback functions that define how to merge or override each attribute.
  • Sanitize style and class attribute values
  • More flexibly handle redundant semicolons in style attributes
  • Added a unit test to directly assert the return value of get_block_wrapper_attributes().

Comment on lines +214 to +215
$new_attribute = is_string( $new_attribute ) ? $new_attribute : '';
$extra_attribute = is_string( $extra_attribute ) ? $extra_attribute : '';
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sanitize non-string attribute values here.

);

$expected_classes = 'foo-bar-class wp-block-example has-text-color has-red-color has-background has-black-background-color';
$expected_styles = 'test: style;';
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We shouldn't have used the invalid inline styles in the test in the first place.

t-hamano and others added 6 commits March 12, 2026 16:23
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Co-authored-by: Weston Ruter <westonruter@gmail.com>
Comment on lines +196 to +197
wp_parse_list( $extra_attribute ),
wp_parse_list( $new_attribute )
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While uncommon, a class name can technically contain a comma. It just has to be escaped in CSS. See CodePen.

The use of wp_parse_list() will split on commas too, as seen in PHP Playground.

So I think it would be safer to just use preg_split() directly:

Suggested change
wp_parse_list( $extra_attribute ),
wp_parse_list( $new_attribute )
preg_split( '/\s+/', $extra_attribute, -1, PREG_SPLIT_NO_EMPTY ),
preg_split( '/\s+/', $new_attribute, -1, PREG_SPLIT_NO_EMPTY )

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But I guess sanitize_html_class() will strip out commas anyway.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 66a9169

I also removed sanitize_html_class sanitizing accordingly.

While it's unlikely any developers would include commas in block class names, it's probably best not to introduce new handling for backward compatibility reasons.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants