Strip unexpected characters from CSS output var names#2135
Conversation
WalkthroughThe pull request introduces a new private static method, Changes
Possibly related PRs
Warning Rate limit exceeded@Crabcyborg has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 12 minutes and 19 seconds before requesting another review. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Actionable comments posted: 0
🧹 Outside diff range and nitpick comments (1)
classes/helpers/FrmStylesHelper.php (1)
453-461: LGTM! Consider adding input validationThe new method effectively sanitizes CSS variable names. However, consider adding input validation to ensure the input is a string.
private static function clean_var_name( $var_name ) { + if ( ! is_string( $var_name ) ) { + return ''; + } return preg_replace( '/[^a-zA-Z0-9_-]/', '', $var_name ); }
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
📒 Files selected for processing (1)
classes/helpers/FrmStylesHelper.php(1 hunks)
🔇 Additional comments (1)
classes/helpers/FrmStylesHelper.php (1)
448-448: LGTM! Security improvement for CSS variable names
The addition of clean_var_name method call improves security by ensuring CSS variable names contain only valid characters.
Related Slack conversation https://strategy11.slack.com/archives/C799A2R61/p1732218176807229
This should help prevent broken CSS issues.