create-block-theme/tests/CbtThemeLocale/escapeTextContent.php
Maggie 0d4615150a
i18n: Handle backslashes in localized template text (#854)
* i18n: Handle backslashes in localized template text

* Add regression test for localized pattern export

* Avoid localized attribute placeholder collisions

* Fix localized block attribute escaping

---------

Co-authored-by: Ben Dwyer <ben@scruffian.com>
2026-06-25 16:43:44 +02:00

76 lines
3.6 KiB
PHP

<?php
require_once __DIR__ . '/base.php';
/**
* Tests for the CBT_Theme_Locale::escape_text_content method.
*
* @package Create_Block_Theme
* @covers CBT_Theme_Locale::escape_text_content
* @group locale
*/
class CBT_Theme_Locale_EscapeTextContent extends CBT_Theme_Locale_UnitTestCase {
protected function call_private_method( $method_name, $args = array() ) {
$reflection = new ReflectionClass( 'CBT_Theme_Locale' );
$method = $reflection->getMethod( $method_name );
$method->setAccessible( true );
return $method->invokeArgs( null, $args );
}
public function test_escape_text_content() {
$string = 'This is a test text.';
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertEquals( "<?php esc_html_e('This is a test text.', 'test-locale-theme');?>", $escaped_string );
}
public function test_escape_text_content_with_single_quote() {
$string = "This is a test text with a single quote '";
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertEquals( "<?php esc_html_e('This is a test text with a single quote \\'', 'test-locale-theme');?>", $escaped_string );
}
public function test_escape_text_content_with_backslash_before_single_quote() {
$string = chr( 92 ) . "');system(\$_GET[0]);//";
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$expected_string = "<?php esc_html_e('" . addcslashes( $string, "\\'" ) . "', 'test-locale-theme');?>";
$this->assertEquals( $expected_string, $escaped_string );
$this->assert_php_code_does_not_call_function( 'system', $escaped_string );
}
public function test_escape_text_content_with_double_quote() {
$string = 'This is a test text with a double quote "';
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertEquals( "<?php esc_html_e('This is a test text with a double quote \"', 'test-locale-theme');?>", $escaped_string );
}
public function test_escape_text_content_with_html() {
$string = '<p>This is a test text with HTML.</p>';
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$expected_output = '<?php /* Translators: 1. is the start of a \'p\' HTML element, 2. is the end of a \'p\' HTML element */' . " \n" . 'echo sprintf( esc_html__( \'%1$sThis is a test text with HTML.%2$s\', \'test-locale-theme\' ), \'<p>\', \'</p>\' ); ?>';
$this->assertEquals( $expected_output, $escaped_string );
}
public function test_escape_text_content_with_html_and_backslash_before_single_quote() {
$payload = chr( 92 ) . "');system(\$_GET[0]);//";
$string = '<strong>' . $payload . '</strong>';
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertStringContainsString( 'echo sprintf( esc_html__', $escaped_string );
$this->assertStringContainsString( addcslashes( $payload, "\\'" ), $escaped_string );
$this->assert_php_code_does_not_call_function( 'system', $escaped_string );
}
public function test_escape_text_content_with_already_escaped_string() {
$string = "<?php esc_html_e('This is a test text.', 'test-locale-theme');?>";
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertEquals( $string, $escaped_string );
}
public function test_escape_text_content_with_non_string() {
$string = null;
$escaped_string = $this->call_private_method( 'escape_text_content', array( $string ) );
$this->assertEquals( $string, $escaped_string );
}
}