ifnex/03_WordPress/wp-includes/blocks/post-date.php
Kazem Alghasi 56244f14fa fix(wp): update to version 7.0.3 and improve security
Upgrade WordPress core to version 7.0.3 and implement various security
hardening measures, including improved input sanitization, enhanced
URL validation for HTTP requests, and stricter CSS filtering.

- Update version to 7.0.3 in version.php and about.php
- Implement stricter IP address validation in wp_http_validate_url()
- Add escaping to user-related error messages and authentication flows
- Improve sanitization in block rendering (post-content, post-date)
- Enhance CSS filtering in kses.php to handle PCRE errors
- Add validation for tagName attributes in post-content block
- Update emoji loader to use more secure DOM selection patterns
- Enable WP_DEBUG and error logging in wp-config.php
- Add new ifnex theme directory
2026-08-09 01:32:57 +03:30

107 lines
3.6 KiB
PHP

<?php
/**
* Server-side rendering of the `core/post-date` block.
*
* @package WordPress
*/
/**
* Renders the `core/post-date` block on the server.
*
* @since 5.8.0
* @since 6.9.0 Added `datetime` attribute and Block Bindings support.
*
* @param array $attributes Block attributes.
* @param string $content Block default content.
* @param WP_Block $block Block instance.
* @return string Returns the filtered post date for the current post wrapped inside "time" tags.
*/
function render_block_core_post_date( $attributes, $content, $block ) {
$classes = array();
if (
! isset( $attributes['datetime'] ) && ! (
isset( $attributes['metadata']['bindings']['datetime']['source'] ) &&
isset( $attributes['metadata']['bindings']['datetime']['args'] )
)
) {
/*
* This is the legacy version of the block that didn't have the `datetime` attribute.
* This branch needs to be kept for backward compatibility.
*/
$source = get_block_bindings_source( 'core/post-data' );
if ( isset( $attributes['displayType'] ) && 'modified' === $attributes['displayType'] ) {
$source_args = array(
'field' => 'modified',
);
} else {
$source_args = array(
'field' => 'date',
);
}
$attributes['datetime'] = $source->get_value( $source_args, $block, 'datetime' );
}
if ( isset( $source_args['field'] ) && 'modified' === $source_args['field'] ) {
$classes[] = 'wp-block-post-date__modified-date';
}
if ( empty( $attributes['datetime'] ) ) {
// If the `datetime` attribute is set but empty, it could be because Block Bindings
// set it that way. This can happen e.g. if the block is bound to the
// post's last modified date, and the latter lies before the publish date.
// (See https://github.com/WordPress/gutenberg/pull/46839 where this logic was originally
// implemented.)
// In this case, we have to respect and return the empty value.
return '';
}
$unformatted_date = $attributes['datetime'];
$post_timestamp = strtotime( $unformatted_date );
if ( isset( $attributes['format'] ) && 'human-diff' === $attributes['format'] ) {
if ( $post_timestamp > time() ) {
// translators: %s: human-readable time difference.
$formatted_date = sprintf( __( '%s from now' ), human_time_diff( $post_timestamp ) );
} else {
// translators: %s: human-readable time difference.
$formatted_date = sprintf( __( '%s ago' ), human_time_diff( $post_timestamp ) );
}
} else {
$format = empty( $attributes['format'] ) ? get_option( 'date_format' ) : $attributes['format'];
$formatted_date = wp_date( $format, $post_timestamp );
}
if ( isset( $attributes['textAlign'] ) ) {
$classes[] = 'has-text-align-' . $attributes['textAlign'];
}
if ( isset( $attributes['style']['elements']['link']['color']['text'] ) ) {
$classes[] = 'has-link-color';
}
$wrapper_attributes = get_block_wrapper_attributes( array( 'class' => implode( ' ', $classes ) ) );
$time_tag = sprintf( '<time datetime="%1$s">%2$s</time>', esc_attr( $unformatted_date ), esc_html( $formatted_date ) );
if ( isset( $attributes['isLink'] ) && $attributes['isLink'] && isset( $block->context['postId'] ) ) {
$time_tag = sprintf( '<a href="%1$s">%2$s</a>', esc_url( get_the_permalink( $block->context['postId'] ) ), $time_tag );
}
return sprintf( '<div %1$s>%2$s</div>', $wrapper_attributes, $time_tag );
}
/**
* Registers the `core/post-date` block on the server.
*
* @since 5.8.0
*/
function register_block_core_post_date() {
register_block_type_from_metadata(
__DIR__ . '/post-date',
array(
'render_callback' => 'render_block_core_post_date',
)
);
}
add_action( 'init', 'register_block_core_post_date' );