HTML API: Preserve raw text in serialize, allow setting - #12289
Conversation
The serializer was discarding the raw-text contents of IFRAME, NOEMBED, and NOFRAMES even though get_modifiable_text() already returns the browser-equivalent raw text for those elements. Let those elements follow the same raw emission path as SCRIPT and STYLE, preserving contents while retaining existing NUL and newline normalization. See #65372.
|
Hi there! 👋 Thank you for your contribution to WordPress! 💖 It looks like this is your first pull request to No one monitors this repository for new pull requests. Pull requests must be attached to a Trac ticket to be considered for inclusion in WordPress Core. To attach a pull request to a Trac ticket, please include the ticket's full URL in your pull request description. Pull requests are never merged on GitHub. The WordPress codebase continues to be managed through the SVN repository that this GitHub repository mirrors. Please feel free to open pull requests to work on any contribution you are making. More information about how GitHub pull requests can be used to contribute to WordPress can be found in the Core Handbook. Please include automated tests. Including tests in your pull request is one way to help your patch be considered faster. To learn about WordPress' test suites, visit the Automated Testing page in the handbook. If you have not had a chance, please review the Contribute with Code page in the WordPress Core Handbook. The Developer Hub also documents the various coding standards that are followed:
Thank you, |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
Co-authored-by: Jon Surrell <sirreal@users.noreply.github.com>
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
| 'STYLE content' => array( "<style>\x00 {}</style>", "<style>\u{FFFD} {}</style>" ), | ||
| 'IFRAME content' => array( "<iframe>a\x00b</iframe>", "<iframe>a\u{FFFD}b</iframe>" ), | ||
| 'NOEMBED content' => array( "<noembed>a\x00b</noembed>", "<noembed>a\u{FFFD}b</noembed>" ), | ||
| 'NOFRAMES content' => array( "<noframes>a\x00b</noframes>", "<noframes>a\u{FFFD}b</noframes>" ), |
There was a problem hiding this comment.
we don’t currently allow setting modifiable text in these, so it may be appropriate to toggle that in this same change, and follow what we do with SCRIPT and TITLE etc... and start rejecting updates which otherwise would contain closing tags for these.
although they are special atomic elements, we can find isolated closing tags. to make it easier we could reject strings containing </iframe, for example, which might be good enough for this upcoming release.
There was a problem hiding this comment.
Addressed in 7a5300d by enabling set_modifiable_text() for IFRAME, NOEMBED, and NOFRAMES, and rejecting updates containing their own closing tags such as </iframe.
Verified with PHPCS, the focused modifiable-text tests, the HTML Processor serialization class, and the full html-api group.
There was a problem hiding this comment.
Pull request overview
This PR updates the HTML API normalization/serialization behavior so that rawtext element contents are preserved (instead of being omitted) for IFRAME, NOEMBED, and NOFRAMES, aligning output with the HTML fragment serialization rules in the WHATWG spec and the linked Trac ticket.
Changes:
- Preserve and serialize rawtext contents for
IFRAME,NOEMBED, andNOFRAMESinstead of dropping them during normalization. - Extend
WP_HTML_Tag_Processor::set_modifiable_text()support/tests for rawtext replacements inside those elements. - Update and expand PHPUnit coverage for rawtext preservation and NULL-byte handling in these elements.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| tests/phpunit/tests/html-api/wpHtmlTagProcessorModifiableText.php | Adds test coverage for setting modifiable text inside IFRAME/NOEMBED/NOFRAMES, including rejection cases. |
| tests/phpunit/tests/html-api/wpHtmlProcessor-serialize.php | Replaces the XMP-only test with a shared rawtext test provider and adds NULL-byte cases for the new elements. |
| src/wp-includes/html-api/class-wp-html-tag-processor.php | Adds set_modifiable_text() handling for IFRAME/NOEMBED/NOFRAMES rawtext content. |
| src/wp-includes/html-api/class-wp-html-processor.php | Stops blanking IFRAME/NOEMBED/NOFRAMES contents during serialize_token(), so rawtext is emitted verbatim. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
The contents of `iframe`, `noembed`, and `noframes` elements are parsed as raw text and must be appended literally when serializing rather than escaped or omitted. Setting the modifiable text of these elements, as well as `xmp`, is now supported. Developed in #12289. Follow-up to [62542]. Props jonsurrell, dmsnell. See #65372. git-svn-id: https://develop.svn.wordpress.org/trunk@62715 602fd350-edb4-49c9-b593-d223f7449a82
The contents of `iframe`, `noembed`, and `noframes` elements are parsed as raw text and must be appended literally when serializing rather than escaped or omitted. Setting the modifiable text of these elements, as well as `xmp`, is now supported. Developed in WordPress/wordpress-develop#12289. Follow-up to [62542]. Props jonsurrell, dmsnell. See #65372. Built from https://develop.svn.wordpress.org/trunk@62715 git-svn-id: http://core.svn.wordpress.org/trunk@61999 1a063a9b-81f0-0310-95a4-ce76da25c4cd
|
Merged in r62715. |
IFRAME,NOEMBED, andNOFRAMEScontents were omitted from normalized HTML. Print their rawtext contents verbatim according to the standard for serializing HTML fragments.Allow setting their modifiable text (and
XMP) accordingly.Trac ticket: https://core.trac.wordpress.org/ticket/65372
Use of AI Tools
AI assistance: Yes
Tool(s): Codex
Model(s): GPT-5.5
Used for: Detection and initial implementation.
This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.