Script Loader: Enable wp_script_attributes filter in _print_scripts() - #11702
Script Loader: Enable wp_script_attributes filter in _print_scripts()#11702Sukhendu2002 wants to merge 8 commits into
Conversation
…ag() in _print_scripts()
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
|
I'll pick this up for 7.1 when |
Replace the manually constructed `<script>` markup in `_print_scripts()` with `wp_print_inline_script_tag()` and `wp_print_script_tag()`. The merged inline script holding the concatenated `wp_localize_script()` data, and the `load-scripts.php` tag itself, are now passed through the `wp_inline_script_attributes` and `wp_script_attributes` filters, as every other script tag in core already is. Themes and plugins can therefore add attributes to them, such as the nonce needed to serve the admin under a Content-Security-Policy that disallows `unsafe-inline`. The emitted markup is otherwise unchanged, aside from the attribute quoting and entity encoding applied by `WP_HTML_Tag_Processor`. Developed in #11702. Follow-up to r56687, r60719. Props sukhendu2002, galaxor, wildworks, westonruter. See #51407, #57548, #58664, #59446. Fixes #64683. git-svn-id: https://develop.svn.wordpress.org/trunk@62723 602fd350-edb4-49c9-b593-d223f7449a82
Replace the manually constructed `<script>` markup in `_print_scripts()` with `wp_print_inline_script_tag()` and `wp_print_script_tag()`. The merged inline script holding the concatenated `wp_localize_script()` data, and the `load-scripts.php` tag itself, are now passed through the `wp_inline_script_attributes` and `wp_script_attributes` filters, as every other script tag in core already is. Themes and plugins can therefore add attributes to them, such as the nonce needed to serve the admin under a Content-Security-Policy that disallows `unsafe-inline`. The emitted markup is otherwise unchanged, aside from the attribute quoting and entity encoding applied by `WP_HTML_Tag_Processor`. Developed in WordPress/wordpress-develop#11702. Follow-up to r56687, r60719. Props sukhendu2002, galaxor, wildworks, westonruter. See #51407, #57548, #58664, #59446. Fixes #64683. Built from https://develop.svn.wordpress.org/trunk@62723 git-svn-id: http://core.svn.wordpress.org/trunk@62007 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Trac ticket: https://core.trac.wordpress.org/ticket/64683
This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.