X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/53f4633144ed68c8b8fb5861f992b5489894a940..4feeb71a9d812a9ae371c28a3d8b442a4394ded7:/wp-includes/shortcodes.php diff --git a/wp-includes/shortcodes.php b/wp-includes/shortcodes.php index c63958b1..132d63a5 100644 --- a/wp-includes/shortcodes.php +++ b/wp-includes/shortcodes.php @@ -88,6 +88,20 @@ $shortcode_tags = array(); */ function add_shortcode($tag, $func) { global $shortcode_tags; + + if ( '' == trim( $tag ) ) { + $message = __( 'Invalid shortcode name: Empty name given.' ); + _doing_it_wrong( __FUNCTION__, $message, '4.4.0' ); + return; + } + + if ( 0 !== preg_match( '@[<>&/\[\]\x00-\x20=]@', $tag ) ) { + /* translators: 1: shortcode name, 2: space separated list of reserved characters */ + $message = sprintf( __( 'Invalid shortcode name: %1$s. Do not use spaces or reserved characters: %2$s' ), $tag, '& / < > [ ] =' ); + _doing_it_wrong( __FUNCTION__, $message, '4.4.0' ); + return; + } + $shortcode_tags[ $tag ] = $func; } @@ -155,7 +169,7 @@ function has_shortcode( $content, $tag ) { } if ( shortcode_exists( $tag ) ) { - preg_match_all( '/' . get_shortcode_regex() . '/s', $content, $matches, PREG_SET_ORDER ); + preg_match_all( '/' . get_shortcode_regex() . '/', $content, $matches, PREG_SET_ORDER ); if ( empty( $matches ) ) return false; @@ -195,19 +209,18 @@ function do_shortcode( $content, $ignore_html = false ) { if (empty($shortcode_tags) || !is_array($shortcode_tags)) return $content; - $tagnames = array_keys($shortcode_tags); - $tagregexp = join( '|', array_map('preg_quote', $tagnames) ); - $pattern = "/\\[($tagregexp)/s"; + // Find all registered tag names in $content. + preg_match_all( '@\[([^<>&/\[\]\x00-\x20=]++)@', $content, $matches ); + $tagnames = array_intersect( array_keys( $shortcode_tags ), $matches[1] ); - if ( 1 !== preg_match( $pattern, $content ) ) { - // Avoids parsing HTML when there are no shortcodes or embeds anyway. + if ( empty( $tagnames ) ) { return $content; } - $content = do_shortcodes_in_html_tags( $content, $ignore_html ); + $content = do_shortcodes_in_html_tags( $content, $ignore_html, $tagnames ); - $pattern = get_shortcode_regex(); - $content = preg_replace_callback( "/$pattern/s", 'do_shortcode_tag', $content ); + $pattern = get_shortcode_regex( $tagnames ); + $content = preg_replace_callback( "/$pattern/", 'do_shortcode_tag', $content ); // Always restore square braces so we don't break things like