Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Connect flow: sanitize "from" parameter when building connect url #12380

Merged
merged 3 commits into from
May 21, 2019

Conversation

jeherve
Copy link
Member

@jeherve jeherve commented May 15, 2019

Follow-up from #12351

Changes proposed in this Pull Request:

Since one can currently pass any "from" parameter when building that URL, let's sanitize that value.

Testing instructions:

  • Start on a brand new site that has not been connected yet.
  • Go to Jetpack > Dashboard.
  • Make sure the "set up Jetpack" link still includes the landing-page-bottom from parameter.

Proposed changelog entry for your changes:

  • Connect Flow: sanitize from parameter when building connection URL.

Follow-up from #12351

Since one can currently pass any "from" parameter when building that URL, let's sanitize that value.
@jeherve jeherve added [Type] Enhancement Changes to an existing feature — removing, adding, or changing parts of it [Status] Needs Review To request a review from Crew. Label will be renamed soon. [Pri] Normal Connect Flow Connection banners, buttons, ... labels May 15, 2019
@jeherve jeherve added this to the 7.4 milestone May 15, 2019
@jeherve jeherve requested a review from tyxla May 15, 2019 13:18
@jeherve jeherve requested a review from a team as a code owner May 15, 2019 13:18
@jeherve jeherve self-assigned this May 15, 2019
@jetpackbot
Copy link

jetpackbot commented May 15, 2019

Thank you for the great PR description!

When this PR is ready for review, please apply the [Status] Needs Review label. If you are an a11n, please have someone from your team review the code if possible. The Jetpack team will also review this PR and merge it to be included in the next Jetpack release.

Scheduled Jetpack release: June 4, 2019.
Scheduled code freeze: May 28, 2019

Generated by 🚫 dangerJS against 71974ba

class.jetpack.php Outdated Show resolved Hide resolved
See #12380 (comment)

Co-Authored-By: Marin Atanasov <8436925+tyxla@users.noreply.github.com>
tyxla
tyxla previously approved these changes May 15, 2019
Copy link
Member

@tyxla tyxla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you 🚢

class.jetpack.php Outdated Show resolved Hide resolved
Copy link
Member

@tyxla tyxla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good to me 👍

@@ -4535,7 +4535,7 @@ function build_connect_url( $raw = false, $redirect = false, $from = false, $reg
$url = add_query_arg( 'calypso_env', $calypso_env, $url );
}

return $raw ? $url : esc_url( $url );
return $raw ? esc_url_raw( $url ) : esc_url( $url );
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's even better 👍

@kraftbj kraftbj added [Status] Ready to Merge Go ahead, you can push that green button! and removed [Status] Needs Review To request a review from Crew. Label will be renamed soon. labels May 20, 2019
@jeherve jeherve merged commit 5dfd71c into master May 21, 2019
@jeherve jeherve deleted the update/connect-url-sanitize-from branch May 21, 2019 07:29
@matticbot matticbot added [Status] Needs Changelog and removed [Status] Ready to Merge Go ahead, you can push that green button! labels May 21, 2019
jeherve added a commit that referenced this pull request May 23, 2019
jeherve added a commit that referenced this pull request May 27, 2019
* Kick off the changelog

* Add 7.3.1

* Update date and post link

* changelog: add #12219

* changelog: add #12170

* changelog: add #12184

* Changelog: add #12268

* Changelog: add #12081

* Changelog: add #12323

* Changelog: add #12204

* Changelog: add #12269

* Changelog: add #12332

* changelog: add #12339

* changelog: add #12209

* Changelog: add #12319

* Changelog: add #12357

* Changelog: add #12124

* Changelog: add #12373

* Changelog: add #12252

* Changelog: add #12383

* Changelog: add #12372

* changelog: add #12337

* Changelog: add #12290

* Changelog: add #12301

* Changelog: add #12061

* Testing list: add instructions for #12061

* Changelog: add #12393

* Update minimum supported version

See #12287

* Changelog: add #12406

* Testing list: add #12406

* Changelog: add #12277

* Changelog: add #12412

* Changelog: add #11318

* Changelog: add #12328

* Changelog: add #12425

* Changelog: add #12380

* Changelog: add #12428

* Changelog: add #12414

* Changelog: add #12395

* Changelog & Testing list: add #12416, #12417, #12418, and #12348

* changelog: add #12379

* Changelog: add #12341

* changelog: add #12444

* Changelog: add #12434

* Changelog: add #12454

* Changelog: add #12460

* Changelog: add #12463

* Changelog: add #12457

* Changelog / testing list: add #10333

* Changelog: add #12467


Co-authored-by: Jeremy Herve <jeremy@jeremy.hu>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connect Flow Connection banners, buttons, ... [Pri] Normal [Type] Enhancement Changes to an existing feature — removing, adding, or changing parts of it
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants