General: Add a sanitize_textarea_field() function.

Like its predecessor (`sanitize_text_field()`), `sanitize_textarea_field()` is a helper function to sanitise user input. As the name suggests, this function is for sanitising input from `textarea` fields - it strips tags and invalid UTF-8 characters, like `sanitize_text_field()`, but retains newlines and extra inline whitespace.

Props ottok, nbachiyski, chriscct7, pento.
Fixes #32257.



git-svn-id: https://develop.svn.wordpress.org/trunk@38944 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Gary Pendergast
2016-10-26 05:16:09 +00:00
parent e06b7111e5
commit 85eb52669d
2 changed files with 167 additions and 48 deletions
@@ -4,44 +4,111 @@
* @group formatting
*/
class Tests_Formatting_SanitizeTextField extends WP_UnitTestCase {
// #11528
function test_sanitize_text_field() {
$inputs = array(
'оРангутанг', //Ensure UTF8 text is safe the Р is D0 A0 and A0 is the non-breaking space.
'САПР', //Ensure UTF8 text is safe the Р is D0 A0 and A0 is the non-breaking space.
'one is < two',
'tags <span>are</span> <em>not allowed</em> here',
' we should trim leading and trailing whitespace ',
'we also trim extra internal whitespace',
'tabs get removed too',
'newlines are not welcome
here',
'We also %AB remove %ab octets',
'We don\'t need to wory about %A
B removing %a
b octets even when %a B they are obscured by whitespace',
'%AB%BC%DE', //Just octets
'Invalid octects remain %II',
'Nested octects %%%ABABAB %A%A%ABBB',
);
$expected = array(
'оРангутанг',
'САПР',
'one is &lt; two',
'tags are not allowed here',
'we should trim leading and trailing whitespace',
'we also trim extra internal whitespace',
'tabs get removed too',
'newlines are not welcome here',
'We also remove octets',
'We don\'t need to wory about %A B removing %a b octets even when %a B they are obscured by whitespace',
'', //Emtpy as we strip all the octets out
'Invalid octects remain %II',
'Nested octects',
function data_sanitize_text_field() {
return array(
array(
'оРангутанг', //Ensure UTF8 text is safe the Р is D0 A0 and A0 is the non-breaking space.
'оРангутанг',
),
array(
'САПР', //Ensure UTF8 text is safe the Р is D0 A0 and A0 is the non-breaking space.
'САПР',
),
array(
'one is < two',
'one is &lt; two',
),
array(
"one is <\n two",
array(
'oneline' => 'one is &lt; two',
'multiline' => "one is &lt;\n two",
),
),
array(
"foo <div\n> bar",
array(
'oneline' => 'foo bar',
'multiline' => "foo bar",
),
),
array(
"foo <\ndiv\n> bar",
array(
'oneline' => 'foo &lt; div > bar',
'multiline' => "foo &lt;\ndiv\n> bar",
),
),
array(
'tags <span>are</span> <em>not allowed</em> here',
'tags are not allowed here',
),
array(
' we should trim leading and trailing whitespace ',
'we should trim leading and trailing whitespace',
),
array(
'we trim extra internal whitespace only in single line texts',
array(
'oneline' => 'we trim extra internal whitespace only in single line texts',
'multiline' => 'we trim extra internal whitespace only in single line texts',
),
),
array(
"tabs \tget removed in single line texts",
array(
'oneline' => 'tabs get removed in single line texts',
'multiline' => "tabs \tget removed in single line texts",
),
),
array(
"newlines are allowed only\n in multiline texts",
array(
'oneline' => 'newlines are allowed only in multiline texts',
'multiline' => "newlines are allowed only\n in multiline texts",
),
),
array(
'We also %AB remove %ab octets',
'We also remove octets',
),
array(
'We don\'t need to wory about %A
B removing %a
b octets even when %a B they are obscured by whitespace',
array (
'oneline' => 'We don\'t need to wory about %A B removing %a b octets even when %a B they are obscured by whitespace',
'multiline' => "We don't need to wory about %A\n B removing %a\n b octets even when %a B they are obscured by whitespace",
),
),
array(
'%AB%BC%DE', //Just octets
'', //Emtpy as we strip all the octets out
),
array(
'Invalid octects remain %II',
'Invalid octects remain %II',
),
array(
'Nested octects %%%ABABAB %A%A%ABBB',
'Nested octects',
),
);
}
foreach ($inputs as $key => $input) {
$this->assertEquals($expected[$key], sanitize_text_field($input));
/**
* @ticket 32257
* @dataProvider data_sanitize_text_field
*/
function test_sanitize_text_field( $string, $expected ) {
if ( is_array( $expected ) ) {
$expected_oneline = $expected['oneline'];
$expected_multiline = $expected['multiline'];
} else {
$expected_oneline = $expected_multiline = $expected;
}
$this->assertEquals( $expected_oneline, sanitize_text_field( $string ) );
$this->assertEquals( $expected_multiline, sanitize_textarea_field( $string ) );
}
}