Skip to content

Conversation

@emfluenceindia
Copy link

Hi,
I have applied some security refinements based on PHPCS report using WordPress-Extra standards.
It would be nice if you please review them.

Thank you!

File: SettingsPage.php
Ignored issues are at line numbers 608 and 665
Resons: explained with corresposing lines.
File: aad-sso-wordpress.php
Igonred issues are at line nos. 628 through 631
Reason: var_export function returns mized output.
File: view/settings.php
Issue: unescaped wp_nonce_url function.
@bradkovach
Copy link
Contributor

@psignoret this looks like a really welcome improvement. Pretty straightforward. Nice work @emfluenceindia :-)

@emfluenceindia
Copy link
Author

emfluenceindia commented Oct 22, 2018 via email

@bradkovach
Copy link
Contributor

FWIW, these will escape raw HTML, so instead of a formatted code tag, you will see verbatim <code>AADSSO_SETTINGS_PATH</code> on the rendered page.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants