Font Library: remove insecure properties #56230
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What?
Leverages the
remove_insecure_properties
method of WP_Theme_JSON class to further validate the CSS saved to the database and output to the client.The PR also adds a unit test to verify the use case.
Why?
Currently it is possible to include and output non-valid CSS in the font family definition of global styles.
How?
Testing Instructions
Testing Instructions for Keyboard
Screenshots or screencast