Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 28 additions & 1 deletion admin/class-h5p-plugin-admin.php
Original file line number Diff line number Diff line change
Expand Up @@ -168,11 +168,38 @@ function add_settings_link($links) {
* @since 1.3.0
*/
public function embed() {
global $wpdb;
// Allow other sites to embed
header_remove('X-Frame-Options');

// Find content
$id = filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT);
$slug = filter_input(INPUT_GET, 'slug', FILTER_VALIDATE_REGEXP, [
'options' => ['regexp' => '/^[a-z0-9_-]+$/i']
]);

$id = NULL;

if (!empty($slug)) {
$row = $wpdb->get_row($wpdb->prepare(
"SELECT id ".
"FROM {$wpdb->prefix}h5p_contents ".
"WHERE slug = %s",
$slug
));

if ($wpdb->last_error) {
return sprintf(__('Database error: %s.', $this->plugin_slug), $wpdb->last_error);
}

if (isset($row['id'])) {
$id = (int) $row['id'];
}
}

if ($id === NULL) {
$id = filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT);
}

if ($id !== NULL) {
$plugin = H5P_Plugin::get_instance();
$content = $plugin->get_content($id);
Expand Down
12 changes: 8 additions & 4 deletions public/class-h5p-plugin.php
Original file line number Diff line number Diff line change
Expand Up @@ -936,6 +936,8 @@ public function get_content_settings($content) {
global $wpdb;
$core = $this->get_h5p_instance('core');

$insert_method = get_option('h5p_insert_method', 'id');

$safe_parameters = $core->filterParameters($content);
if (has_action('h5p_alter_filtered_parameters')) {
// Parse the JSON parameters
Expand All @@ -962,22 +964,24 @@ public function get_content_settings($content) {
$author_id = (int)(is_array($content) ? $content['user_id'] : $content->user_id);

$metadata = $content['metadata'];
$title = isset($metadata['a11yTitle'])
$title = esc_attr(isset($metadata['a11yTitle'])
? $metadata['a11yTitle']
: (isset($metadata['title'])
? $metadata['title']
: ''
);
));

$identifier = esc_attr(($insert_method === 'slug' and !empty($content['slug'])) ? 'slug=' . $content['slug'] : 'id=' . $content['id']);

// Add JavaScript settings for this content
$settings = array(
'library' => H5PCore::libraryToString($content['library']),
'jsonContent' => $safe_parameters,
'fullScreen' => $content['library']['fullscreen'],
'exportUrl' => get_option('h5p_export', TRUE) ? $this->get_h5p_url() . '/exports/' . ($content['slug'] ? $content['slug'] . '-' : '') . $content['id'] . '.h5p' : '',
'embedCode' => '<iframe src="' . admin_url('admin-ajax.php?action=h5p_embed&id=' . $content['id']) . '" width=":w" height=":h" frameborder="0" allowfullscreen="allowfullscreen" title="' . esc_attr($title) . '"></iframe>',
'embedCode' => '<iframe src="' . admin_url('admin-ajax.php?action=h5p_embed&' . $identifier) . '" width=":w" height=":h" frameborder="0" allowfullscreen="allowfullscreen" title="' . $title . '"></iframe>',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The $title should still be passed through esc_attr to prevent broken HTML from being exploited (to mitigate XSS attacks).

$identifier should be passed through esc_attr as well. I know that the slug will have been processed before anyway, but anything that's user-provided should be sanitized. It's part of automated checks that Automattic runs against plugin code and they will complain about it.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

'resizeCode' => '<script src="' . plugins_url('h5p/h5p-php-library/js/h5p-resizer.js') . '" charset="UTF-8"></script>',
'url' => admin_url('admin-ajax.php?action=h5p_embed&id=' . $content['id']),
'url' => admin_url('admin-ajax.php?action=h5p_embed&' . $identifier),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think $identifier should also run through esc_attr(), see above.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

'title' => $content['title'],
'displayOptions' => $core->getDisplayOptionsForView($content['disable'], $author_id),
'metadata' => $metadata,
Expand Down