Notes: Render @ mentions as span chips and narrow the kses class allowance - #80528
Conversation
…wance Mentions are tokens rendered as chips, not links: a span keeps them out of the Link format UI (which destroyed the mention markup on edit) and needs no author-page href. Since the markup no longer carries an open class allowance - a companion pre_comment_content pass reduces span classes to the two mention tokens - the per-note kses arm/disarm machinery collapses to two small always-on filters.
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
|
Size Change: -532 B (-0.01%) Total Size: 7.75 MB 📦 View Changed
|
Mamaduka
left a comment
There was a problem hiding this comment.
Thanks, @adamsilverstein!
The client-side code looks good, and mentions are testing well for me.
@westonruter, might have more feedback regarding the PHP-side, but here's one thing I noticed.
The gutenberg_notes_sanitize_mention_classes could use HTML APIs class_list, add_class and remove_class methods.
Good suggestion, I'll work on it. |
Per review: class_list() already handles token parsing and dedup, and remove_class() drops the attribute when the last class goes, so the manual get_attribute/preg_split/set_attribute handling is unnecessary.
|
Thanks for the review and testing! Switched to |
Match the reworked Gutenberg approach (WordPress/gutenberg#80528): mentions are span.wp-note-mention.user-N chips rather than links, so the allowance becomes two always-on filters - span.class in the comment kses context plus a post-kses pass reducing span classes to the two mention tokens - and the per-note arming inside wp_filter_comment() is no longer needed.
|
Note that starting on the 22nd at around 9:00 UTC tomorrow, I plan to release Gutenberg 23.6 RC3, followed by the official release, and then synchronize core and Gutenberg. If we intend to ship this PR to WP 7.1 Beta3 and Gutenberg 23.6, it should be fine as long as this PR is merged by then. |
The HTML API's whitespace handling when removing the final attribute is not part of its contract, so asserting the exact '<span >' spacing is brittle. Flagged by review on the Core backport (wordpress-develop#12503).
|
One more passing thought here: what about using a custom element? There could be a |
|
Flaky tests detected in ff3e2c6. 🔍 Workflow run URL: https://github.com/WordPress/gutenberg/actions/runs/29850844616
|
Co-authored-by: Weston Ruter <westonruter@git.wordpress.org>
Probably easier to deal with native elements at this point. Then there's React's handling of custom elements to consider, which just added better support in React 19, and it's not shipping until next release |
Co-authored-by: Weston Ruter <westonruter@gmail.com>
…tion An uppercase <SPAN> survives kses with its casing preserved, so the str_contains( ..., '<span' ) early return skipped the class reduction entirely for such tags. The filter only runs when comment content is written, so the optimization is unnecessary - run the tag processor unconditionally and cover the uppercase case with a test.
Align with the Core backport (wordpress-develop#12503). The callback is attached to wp_kses_allowed_html, which fires on nearly every sanitization path, so a third-party apply_filters() passing a non-string context would turn a bad argument into a fatal. The body compares with a strict !==, so the hint buys no correctness, and $allowed in the same signature is already untyped with a runtime guard.
Co-authored-by: Weston Ruter <westonruter@git.wordpress.org>
westonruter
left a comment
There was a problem hiding this comment.
Assuming this is synchronized with the latest from the core PR.
…wance (#80528) Co-authored-by: adamsilverstein <adamsilverstein@git.wordpress.org> Co-authored-by: Mamaduka <mamaduka@git.wordpress.org> Co-authored-by: westonruter <westonruter@git.wordpress.org> Co-authored-by: t-hamano <wildworks@git.wordpress.org>
|
I just cherry-picked this PR to the wp/7.1 branch to get it included in the next release: fa3ebec |
…wance (#80528) Co-authored-by: adamsilverstein <adamsilverstein@git.wordpress.org> Co-authored-by: Mamaduka <mamaduka@git.wordpress.org> Co-authored-by: westonruter <westonruter@git.wordpress.org> Co-authored-by: t-hamano <wildworks@git.wordpress.org>
|
I just cherry-picked this PR to the release/23.6 branch to get it included in the next release: 15f9943 |
This updates the pinned commit hash of the Gutenberg repository from `e73c3c481db0650183f092af157f6e42efe9ee2d` to `4997026b75c922d8a6f77a03d72ed7cad04c7073`. A full list of changes included in this commit can be found on GitHub: WordPress/gutenberg@e73c3c4...4997026 - Notes: Replace blur-deselect bookkeeping with useFocusOutside (WordPress/gutenberg#80222) - Playlist: Update @SInCE tags to 7.1.0 (WordPress/gutenberg#80317) - fix playlist block Dimensions Design (WordPress/gutenberg#80312) - UI: Backport compat overlay fixes to WordPress 7.1 (WordPress/gutenberg#80322) - Editor: allow selecting which block styles to apply globally (WordPress/gutenberg#79839) - Global Styles: Reject non-string custom CSS in the REST controller (WordPress/gutenberg#80338) - Open inspector sidebar when toggling responsive editing (WordPress/gutenberg#80307) - Client Side Media: Honor image_strip_meta and image_max_bit_depth on the client upload path (WordPress/gutenberg#80218) - Hide block style variations when state is enabled in global styles (WordPress/gutenberg#80341) - Media REST API: Fix sideload and finalize for EXIF rotated images (WordPress/gutenberg#80295) - Fix upload snackbar stuck in uploading state on server-side uploads (WordPress/gutenberg#80345) - Try fixing responsive layout in Nav block (WordPress/gutenberg#80305) - Responsive styles: Use viewport dropdown to control states for in-editor global styles sidebar (WordPress/gutenberg#80339) - RichTextControl: Replace DOM focus tracking with a single React-tree focus boundary (WordPress/gutenberg#80324) - Notes: Finish WPDS treatment for mention chips (WordPress/gutenberg#80300) - Notes: Add placeholders to the RichText fields (WordPress/gutenberg#80296) - Fix upload hang when converting long animated GIFs: decode only the first frame for still outputs (WordPress/gutenberg#80260) (WordPress/gutenberg#80342) - Device preview dropdown: use active color for device icon when responsive styles are active (WordPress/gutenberg#80346) - Fix default aspect ratio for lazy loaded Featured image (WordPress/gutenberg#80386) - Vips/upload-media: consolidate optional params into options objects (WordPress/gutenberg#80330) - Autocompleters: Don't pre-encode mention search terms (WordPress/gutenberg#80377) - Animated GIF uploads: generate sub-sizes from the first frame, matching core (WordPress/gutenberg#80268) - Custom CSS: Fix cascade order against block style variations (WordPress/gutenberg#80340) - Rich Text: Restore the selection when focus returns to the editable (WordPress/gutenberg#80396) - Notes: Arm the mention kses allowance on REST note creation (WordPress/gutenberg#80221) - Fix upload snackbar double-counting a single HEIC upload in Safari (WordPress/gutenberg#80436) - ContentEditableControl: fix invalid label association with contenteditable div (WordPress/gutenberg#80441) - Editor: Disable canvas resizing while zoomed out (WordPress/gutenberg#80391) - Fix Color Picker Cursor Shaking Issue (WordPress/gutenberg#80205) (WordPress/gutenberg#80435) - Misc fixes for WordPress-Develop 7.0 merges (WordPress/gutenberg#80444) - Style Book: Restore live global styles updates on the styles route (WordPress/gutenberg#80459) - Worker threads: reject pending RPC calls on worker failure or termination (WordPress/gutenberg#79955) (WordPress/gutenberg#80421) - Media: Add timeout and size guardrails to client-side GIF to video conversion (WordPress/gutenberg#80420) - Post Content: Use the default block appender for empty content (WordPress/gutenberg#80026) - Block Supports: Handle nested array block gap values properly (WordPress/gutenberg#80464) - Editor: Restore fixed device preview height for mobile and tablet (WordPress/gutenberg#80466) - Block Editor: Guard against non-string spacing preset values (WordPress/gutenberg#80467) - Writing flow: fully select the ancestor when a text selection crosses a nesting boundary (WordPress/gutenberg#80462) - Block Editor: Reflect inherited Global Styles values in block inspector controls (WordPress/gutenberg#80481) - Autocomplete: Reference the suggestions list with `aria-controls` and `aria-haspopup` (WordPress/gutenberg#80403) (WordPress/gutenberg#80499) - Media: Remove the redundant __heicUploadSupport flag (WordPress/gutenberg#80486) - State control - avoid tertiary variant on toggle to match style of other dropdown toggles (WordPress/gutenberg#80505) - Icons: Store the sanitized SVG content when registering an icon (WordPress/gutenberg#80508) - Fix `useHomeEnd` on tabs in mac testing (WordPress/gutenberg#80374) - Playlist: Fix playback of tracks served without CORS headers (WordPress/gutenberg#80533) - Redirect editing events to extension handlers under editableRoot (WordPress/gutenberg#80287) - Writing flow: fully select the items when a selection extends down into a nested item (WordPress/gutenberg#80492) - Global Styles panels: fix wrong preset committed and shown when two color presets share a hex (WordPress/gutenberg#80497) - Replaces the `title` attributes used by revision inline diff annotations with `aria-describedby` (WordPress/gutenberg#80440) - Notes: Remove "Add note" from the inline styles dropdown (WordPress/gutenberg#80531) - Global Styles: Resolve per-level heading element styles in block inspector controls (WordPress/gutenberg#80495) - Notes: Render @ mentions as span chips and narrow the kses class allowance (WordPress/gutenberg#80528) - Revisions: Specify block level diff status via aria-label (WordPress/gutenberg#77779) - Backport from Core: improve icon name unit tests (WordPress/gutenberg#80552) - Device type preview: fix collapsing to content height (WordPress/gutenberg#80553) - Wrap notices in ThemeProvider with 0 corner radius (WordPress/gutenberg#80557) - Global Styles: Limit the inherited value treatment to the Gutenberg plugin (WordPress/gutenberg#80555) - Fix crashes when manipulating locked blocks (WordPress/gutenberg#80509) - Notes: align floating threads with their inline marker (WordPress/gutenberg#79877) Props wildworks. See #65529. git-svn-id: https://develop.svn.wordpress.org/trunk@62824 602fd350-edb4-49c9-b593-d223f7449a82
This updates the pinned commit hash of the Gutenberg repository from `e73c3c481db0650183f092af157f6e42efe9ee2d` to `4997026b75c922d8a6f77a03d72ed7cad04c7073`. A full list of changes included in this commit can be found on GitHub: WordPress/gutenberg@e73c3c4...4997026 - Notes: Replace blur-deselect bookkeeping with useFocusOutside (WordPress/gutenberg#80222) - Playlist: Update @SInCE tags to 7.1.0 (WordPress/gutenberg#80317) - fix playlist block Dimensions Design (WordPress/gutenberg#80312) - UI: Backport compat overlay fixes to WordPress 7.1 (WordPress/gutenberg#80322) - Editor: allow selecting which block styles to apply globally (WordPress/gutenberg#79839) - Global Styles: Reject non-string custom CSS in the REST controller (WordPress/gutenberg#80338) - Open inspector sidebar when toggling responsive editing (WordPress/gutenberg#80307) - Client Side Media: Honor image_strip_meta and image_max_bit_depth on the client upload path (WordPress/gutenberg#80218) - Hide block style variations when state is enabled in global styles (WordPress/gutenberg#80341) - Media REST API: Fix sideload and finalize for EXIF rotated images (WordPress/gutenberg#80295) - Fix upload snackbar stuck in uploading state on server-side uploads (WordPress/gutenberg#80345) - Try fixing responsive layout in Nav block (WordPress/gutenberg#80305) - Responsive styles: Use viewport dropdown to control states for in-editor global styles sidebar (WordPress/gutenberg#80339) - RichTextControl: Replace DOM focus tracking with a single React-tree focus boundary (WordPress/gutenberg#80324) - Notes: Finish WPDS treatment for mention chips (WordPress/gutenberg#80300) - Notes: Add placeholders to the RichText fields (WordPress/gutenberg#80296) - Fix upload hang when converting long animated GIFs: decode only the first frame for still outputs (WordPress/gutenberg#80260) (WordPress/gutenberg#80342) - Device preview dropdown: use active color for device icon when responsive styles are active (WordPress/gutenberg#80346) - Fix default aspect ratio for lazy loaded Featured image (WordPress/gutenberg#80386) - Vips/upload-media: consolidate optional params into options objects (WordPress/gutenberg#80330) - Autocompleters: Don't pre-encode mention search terms (WordPress/gutenberg#80377) - Animated GIF uploads: generate sub-sizes from the first frame, matching core (WordPress/gutenberg#80268) - Custom CSS: Fix cascade order against block style variations (WordPress/gutenberg#80340) - Rich Text: Restore the selection when focus returns to the editable (WordPress/gutenberg#80396) - Notes: Arm the mention kses allowance on REST note creation (WordPress/gutenberg#80221) - Fix upload snackbar double-counting a single HEIC upload in Safari (WordPress/gutenberg#80436) - ContentEditableControl: fix invalid label association with contenteditable div (WordPress/gutenberg#80441) - Editor: Disable canvas resizing while zoomed out (WordPress/gutenberg#80391) - Fix Color Picker Cursor Shaking Issue (WordPress/gutenberg#80205) (WordPress/gutenberg#80435) - Misc fixes for WordPress-Develop 7.0 merges (WordPress/gutenberg#80444) - Style Book: Restore live global styles updates on the styles route (WordPress/gutenberg#80459) - Worker threads: reject pending RPC calls on worker failure or termination (WordPress/gutenberg#79955) (WordPress/gutenberg#80421) - Media: Add timeout and size guardrails to client-side GIF to video conversion (WordPress/gutenberg#80420) - Post Content: Use the default block appender for empty content (WordPress/gutenberg#80026) - Block Supports: Handle nested array block gap values properly (WordPress/gutenberg#80464) - Editor: Restore fixed device preview height for mobile and tablet (WordPress/gutenberg#80466) - Block Editor: Guard against non-string spacing preset values (WordPress/gutenberg#80467) - Writing flow: fully select the ancestor when a text selection crosses a nesting boundary (WordPress/gutenberg#80462) - Block Editor: Reflect inherited Global Styles values in block inspector controls (WordPress/gutenberg#80481) - Autocomplete: Reference the suggestions list with `aria-controls` and `aria-haspopup` (WordPress/gutenberg#80403) (WordPress/gutenberg#80499) - Media: Remove the redundant __heicUploadSupport flag (WordPress/gutenberg#80486) - State control - avoid tertiary variant on toggle to match style of other dropdown toggles (WordPress/gutenberg#80505) - Icons: Store the sanitized SVG content when registering an icon (WordPress/gutenberg#80508) - Fix `useHomeEnd` on tabs in mac testing (WordPress/gutenberg#80374) - Playlist: Fix playback of tracks served without CORS headers (WordPress/gutenberg#80533) - Redirect editing events to extension handlers under editableRoot (WordPress/gutenberg#80287) - Writing flow: fully select the items when a selection extends down into a nested item (WordPress/gutenberg#80492) - Global Styles panels: fix wrong preset committed and shown when two color presets share a hex (WordPress/gutenberg#80497) - Replaces the `title` attributes used by revision inline diff annotations with `aria-describedby` (WordPress/gutenberg#80440) - Notes: Remove "Add note" from the inline styles dropdown (WordPress/gutenberg#80531) - Global Styles: Resolve per-level heading element styles in block inspector controls (WordPress/gutenberg#80495) - Notes: Render @ mentions as span chips and narrow the kses class allowance (WordPress/gutenberg#80528) - Revisions: Specify block level diff status via aria-label (WordPress/gutenberg#77779) - Backport from Core: improve icon name unit tests (WordPress/gutenberg#80552) - Device type preview: fix collapsing to content height (WordPress/gutenberg#80553) - Wrap notices in ThemeProvider with 0 corner radius (WordPress/gutenberg#80557) - Global Styles: Limit the inherited value treatment to the Gutenberg plugin (WordPress/gutenberg#80555) - Fix crashes when manipulating locked blocks (WordPress/gutenberg#80509) - Notes: align floating threads with their inline marker (WordPress/gutenberg#79877) Props wildworks. See #65529. Built from https://develop.svn.wordpress.org/trunk@62824 git-svn-id: http://core.svn.wordpress.org/trunk@62104 1a063a9b-81f0-0310-95a4-ce76da25c4cd
|
Just noting I didn't manage to hit the cutoff to commit the PHP backport PR - WordPress/wordpress-develop#12503 for Beta 3, so the kses change won't land in core until Beta 4. I'll commit it as soon as Beta 3 release is complete. |
The Notes @mention completer stores a mention as a non-interactive chip, `<span class="wp-note-mention user-N">@name</span>`, the `user-N` class token carrying the mentioned user's ID. Fix an issue where the default comment kses allowlist does not permit `span`, so for users without the `unfiltered_html` capability the mention markup is stripped when the note is saved. See related Gutenberg pull requests: WordPress/gutenberg#79604 and WordPress/gutenberg#80528. Props mamaduka, westonruter, t-hamano, luisdavid01, vedantere. Fixes #65622. git-svn-id: https://develop.svn.wordpress.org/trunk@62832 602fd350-edb4-49c9-b593-d223f7449a82
The Notes @mention completer stores a mention as a non-interactive chip, `<span class="wp-note-mention user-N">@name</span>`, the `user-N` class token carrying the mentioned user's ID. Fix an issue where the default comment kses allowlist does not permit `span`, so for users without the `unfiltered_html` capability the mention markup is stripped when the note is saved. See related Gutenberg pull requests: WordPress/gutenberg#79604 and WordPress/gutenberg#80528. Props mamaduka, westonruter, t-hamano, luisdavid01, vedantere. Fixes #65622. Built from https://develop.svn.wordpress.org/trunk@62832 git-svn-id: http://core.svn.wordpress.org/trunk@62112 1a063a9b-81f0-0310-95a4-ce76da25c4cd
The mention parser still looked for `<a class="wp-note-mention user-N">` anchors, but mentions have been stored as `<span>` chips since #80528, so no mention was ever found and no email was sent. Match the span markup. Drop the `note=` deep link and its editor handler: focusing a thread from the email is a separate enhancement, so the notification email now links to the post editor via get_edit_post_link(), the same way core's own note notification does. Also remove the function_exists() wrappers, which a plugin-specific `gutenberg_` prefix does not need, and the notification subject and text filters, leaving the recipients filter as the single extension point.
This updates the pinned commit hash of the Gutenberg repository from `2872d71cde528d82675f14862a1b84e2b8abbaea` to `5a0417990a9404cc2562cdd35e3054cb0d3e546e` (version `23.7.0`). A full list of changes included in this commit can be found on GitHub: https://github.com/WordPress/gutenberg/compare/2872d71cde528d82675f14862a1b84e2b8abbaea..v23.7.0. - Release: Fix cherry-pick success detection (WordPress/gutenberg#80249) - Add Table of Contents e2e user story coverage (WordPress/gutenberg#80199) - Only include icon library SVGs listed as `public` in the Zip file published to GitHub Container Registry for `wordpress-develop` (WordPress/gutenberg#79338) - fix: set dataviews popover hover text color (WordPress/gutenberg#80105) - added missing doc (WordPress/gutenberg#80172) - DataViews: Fix the unintended gap between `list` layout items when `groupBy` is set (WordPress/gutenberg#80254) - Social Link: Fix stray closing tag in Tumblr icon markup (WordPress/gutenberg#80257) - DataViews: Fix the `list` layout ignoring some settings when `groupBy` is set (WordPress/gutenberg#80255) - Icon block: Show text and background color controls by default. (WordPress/gutenberg#80251) - DataViews: Add shift-click range selection (WordPress/gutenberg#80046) - UI: Remove unused direction factor CSS property (WordPress/gutenberg#80269) - theme: Disallow src in published package (WordPress/gutenberg#80213) - Fix: stale post edit message in modal (WordPress/gutenberg#79997) - Icons: Validate SVG icons include viewBox (WordPress/gutenberg#80273) - Remove obsolete __unstable-large size props (WordPress/gutenberg#80081) - Responsive Editing: support editing pattern styles (WordPress/gutenberg#80233) - Tab List: Add toolbar buttons to reorder tabs (WordPress/gutenberg#80107) - Move image editor styles to the block editor package (WordPress/gutenberg#80165) - Cover/Accordion: Exit on Enter (WordPress/gutenberg#77301) - Hide color controls for Navigation and Social Icons when viewport states are active (WordPress/gutenberg#80289) - Icons: Fix collection unregister not removing icons after core added its own registry (WordPress/gutenberg#80292) - Widget Dashboard: collapse inline attribute controls into a dropdown (WordPress/gutenberg#80208) - Notes: increase contrast between avatar border colors (WordPress/gutenberg#80285) - Playlist: Fix track insertion (WordPress/gutenberg#80200) - Fix: Allow icon labels to wrap with word breaks and no ellipsis (WordPress/gutenberg#80256) - Dedupe deprecated prop types in composite components (WordPress/gutenberg#80277) - Core Abilities: Restore the ready promise and lazy-load via dynamic import (WordPress/gutenberg#79155) - Notes: Replace blur-deselect bookkeeping with useFocusOutside (WordPress/gutenberg#80222) - UI: Hook Popover into the wp compat overlay slot (WordPress/gutenberg#80278) - Playlist: Update @SInCE tags to 7.1.0 (WordPress/gutenberg#80317) - Remove unused useDeprecated36pxDefaultSizeProp helper. (WordPress/gutenberg#80311) - fix playlist block Dimensions Design (WordPress/gutenberg#80312) - UI: Keep the compat overlay slot accessible inside Modal (WordPress/gutenberg#80310) - Theme: Add typography token showcase (WordPress/gutenberg#80212) - Cover: Create the initial paragraph when the block gains a background (WordPress/gutenberg#80028) - Notes: Arm the mention kses allowance on REST note creation (WordPress/gutenberg#80221) - Check for post lock modal and text, not specific title and button (WordPress/gutenberg#79979) - Worker threads: reject pending RPC calls on worker failure or termination (WordPress/gutenberg#79955) - RTC: Fix empty revision from peer autosave (WordPress/gutenberg#79911) - Client Side Media: Honor image_strip_meta and image_max_bit_depth on the client upload path (WordPress/gutenberg#80218) - Vips/upload-media: consolidate optional params into options objects (WordPress/gutenberg#80330) - Editor: allow selecting which block styles to apply globally (WordPress/gutenberg#79839) - Global Styles: Reject non-string custom CSS in the REST controller (WordPress/gutenberg#80338) - Open inspector sidebar when toggling responsive editing (WordPress/gutenberg#80307) - Fix upload hang when converting long animated GIFs: decode only the first frame for still outputs (WordPress/gutenberg#80260) - Fix: Critical error related to simple-git (WordPress/gutenberg#80102) - Hide block style variations when state is enabled in global styles (WordPress/gutenberg#80341) - Media REST API: Fix sideload and finalize for EXIF rotated images (WordPress/gutenberg#80295) - Fix upload snackbar stuck in uploading state on server-side uploads (WordPress/gutenberg#80345) - Try fixing responsive layout in Nav block (WordPress/gutenberg#80305) - tools: Remove redundant parseArgs arguments (WordPress/gutenberg#80327) - Responsive styles: Use viewport dropdown to control states for in-editor global styles sidebar (WordPress/gutenberg#80339) - Use Add track instead of only Add (WordPress/gutenberg#80336) - Interactivity API: refactor directives into self-registering modules (WordPress/gutenberg#79975) - Fix: Critical error websocket-driver fix (WordPress/gutenberg#80348) - Release: Resolve commander from the test file in the release CLI test (WordPress/gutenberg#80357) - Release: Extract npm release lifecycle (WordPress/gutenberg#80190) - Fix multiple MP3 playlist uploads (WordPress/gutenberg#80101) - Table of Contents: render front-end list from current post headings (WordPress/gutenberg#80318) - UI: improve component code readability in Storybook by using arrays for children (WordPress/gutenberg#80352) - Infra: Use devEngines in root package.json and pin npm version in CI (WordPress/gutenberg#80188) - Automated Testing: Skip type-checking in bundle size comparison build (WordPress/gutenberg#80366) - Theme: Update colorjs.io dependency and drop bug workaround (WordPress/gutenberg#80272) - RichTextControl: Replace DOM focus tracking with a single React-tree focus boundary (WordPress/gutenberg#80324) - Notes: Finish WPDS treatment for mention chips (WordPress/gutenberg#80300) - Notes: Add placeholders to the RichText fields (WordPress/gutenberg#80296) - Fix flaky test in `tabs.spec.js` (WordPress/gutenberg#80373) - Packages: Update exports to avoid deprecated folder export syntax (WordPress/gutenberg#80270) - Theme: Widen peer dependency ranges to support new versions of Vite, ESBuild, and Stylelint (WordPress/gutenberg#80267) - Components: Skip polymorphism prop typings on intersection (WordPress/gutenberg#80364) - Post Content: Use the default block appender for empty content (WordPress/gutenberg#80026) - Device preview dropdown: use active color for device icon when responsive styles are active (WordPress/gutenberg#80346) - Fix default aspect ratio for lazy loaded Featured image (WordPress/gutenberg#80386) - Docs: Add client-side media processing documentation (WordPress/gutenberg#75895) - Autocompleters: Don't pre-encode mention search terms (WordPress/gutenberg#80377) - Animated GIF uploads: generate sub-sizes from the first frame, matching core (WordPress/gutenberg#80268) - Media: Add timeout and size guardrails to client-side GIF to video conversion (WordPress/gutenberg#80379) - Widget Primitives: Ship as a script module (WordPress/gutenberg#80149) - SearchControl: Render the suffix only if there's one. (WordPress/gutenberg#80356) - Custom CSS: Fix cascade order against block style variations (WordPress/gutenberg#80340) - React 19: add e2e compat test for boolean inert attribute (WordPress/gutenberg#80397) - Fix post excerpt rendering to conditionally include space before more… (WordPress/gutenberg#70217) - Add wp-theme as a style dependency of wp-components (WordPress/gutenberg#80362) - Dashboard Widgets: declarative actions in the widget schema (WordPress/gutenberg#80363) - @wordpress/ui: Add Button Storybook example for keyboard shortcut composition (WordPress/gutenberg#80353) - SlotFill: Validate cross-document SCSS module styles (WordPress/gutenberg#80384) - Components: migrate ConfirmDialog to SCSS module (WordPress/gutenberg#80394) - SearchControl: Remove redundant conditional and prop. (WordPress/gutenberg#80406) - Tools: resolve dependencies independently of the node_modules layout (WordPress/gutenberg#80414) - Components: Migrate ToggleGroupControl to SCSS Modules (WordPress/gutenberg#80381) - Rich Text: Restore the selection when focus returns to the editable (WordPress/gutenberg#80396) - RTC: Use requestAnimationFrame for awareness cursor resize redraws (WordPress/gutenberg#79685) - Remove __shouldNotWarnDeprecated36pxSize internal prop (WordPress/gutenberg#80323) - Fix upload snackbar double-counting a single HEIC upload in Safari (WordPress/gutenberg#80371) - Fix Root `.prettierrc.js` override issue (WordPress/gutenberg#80422) - Fix Color Picker Cursor Shaking Issue (WordPress/gutenberg#80205) - Storybook: pre-bundle CJS deps (WordPress/gutenberg#80426) - ContentEditableControl: fix invalid label association with contenteditable div (WordPress/gutenberg#80344) - Writing flow: use isMultiSelecting for shift+click (WordPress/gutenberg#80286) - Added Missing Global Documentation (WordPress/gutenberg#80442) - Editor: Disable canvas resizing while zoomed out (WordPress/gutenberg#80391) - Misc fixes for WordPress-Develop 7.0 merges (WordPress/gutenberg#75985) - RTC: Preserve collaborators' unsaved edits when another user saves (WordPress/gutenberg#79936) - RTC: Disable Quick Edit while a post is being edited (WordPress/gutenberg#80016) - Storybook: build the resolve specifier as a URL-style string (WordPress/gutenberg#80416) - Style Book: Restore live global styles updates on the styles route (WordPress/gutenberg#80459) - Editor: Restore fixed device preview height for mobile and tablet (WordPress/gutenberg#80271) - Block Supports: Handle nested array block gap values properly (WordPress/gutenberg#80464) - Block Editor: Guard against non-string spacing preset values (WordPress/gutenberg#80467) - Move real-time collaboration code to lib/experimental/collaboration (WordPress/gutenberg#80469) - RTC: Fix deleted-user test on multisite (WordPress/gutenberg#80463) - Build: add independent react-18 vendor package (WordPress/gutenberg#80367) - Fix `useHomeEnd` on tabs in mac testing (WordPress/gutenberg#80374) - Block Editor: Reflect inherited Global Styles values in block inspector controls (WordPress/gutenberg#77894) - Media: Remove the redundant __heicUploadSupport flag (WordPress/gutenberg#80452) - Writing flow: fully select the ancestor when a text selection crosses a nesting boundary (WordPress/gutenberg#80462) - fix: show add block button when editing a template part inside a template (WordPress/gutenberg#78427) - Autocomplete: Reference the suggestions list with `aria-controls` and `aria-haspopup` (WordPress/gutenberg#80403) - Dashboard Widgets: Sanitize help link hrefs. (WordPress/gutenberg#80409) - State control - avoid tertiary variant on toggle to match style of other dropdown toggles (WordPress/gutenberg#80505) - Widget Dashboard: measure the header fit and document the chrome (WordPress/gutenberg#80423) - DataViews/Font Library: Give search fields a fixed width to stop layout shift (WordPress/gutenberg#80315) - Fix crashes when manipulating locked blocks (WordPress/gutenberg#80509) - RTC: Use str_contains() in WP_Sync_Config type parsing (WordPress/gutenberg#80476) - Table of Contents: Use str_contains() instead of strpos() check (WordPress/gutenberg#80418) - Build: Handle project paths containing spaces in dev script (WordPress/gutenberg#80519) - Components: migrate SearchControl to SCSS module (WordPress/gutenberg#80474) - Icons: Store the sanitized SVG content when registering an icon (WordPress/gutenberg#80508) - Resolve Prettier explicitly for isolated layout (WordPress/gutenberg#80529) - Playlist: Fix playback of tracks served without CORS headers (WordPress/gutenberg#80533) - Remove unnecessary __next40pxDefaultSize props from form controls (WordPress/gutenberg#80540) - GitHub workflows: Fix changelog checks for forked PRs (WordPress/gutenberg#80538) - Redirect editing events to extension handlers under editableRoot (WordPress/gutenberg#80287) - Writing flow: fully select the items when a selection extends down into a nested item (WordPress/gutenberg#80492) - Global Styles panels: fix wrong preset committed and shown when two color presets share a hex (WordPress/gutenberg#80497) - Replaces the `title` attributes used by revision inline diff annotations with `aria-describedby` (WordPress/gutenberg#80440) - Account for non-lowercase VIDEO tag in render_block filter (WordPress/gutenberg#80537) - Components: migrate FormTokenField to SCSS module (WordPress/gutenberg#80472) - Revisions: Specify block level diff status via aria-label (WordPress/gutenberg#77779) - Notes: Remove "Add note" from the inline styles dropdown (WordPress/gutenberg#80531) - Global Styles: Resolve per-level heading element styles in block inspector controls (WordPress/gutenberg#80495) - Notes: Render @ mentions as span chips and narrow the kses class allowance (WordPress/gutenberg#80528) - Backport from Core: improve icon name unit tests (WordPress/gutenberg#80552) - Read the contentEditable attribute in ownsSelection, not isContentEditable (WordPress/gutenberg#80549) - Device type preview: fix collapsing to content height (WordPress/gutenberg#80553) - Wrap notices in ThemeProvider with 0 corner radius (WordPress/gutenberg#79523) - Perf Tests: Fix 'Selecting blocks' metric reporting 0 ms (WordPress/gutenberg#80524) - Global Styles: Limit the inherited value treatment to the Gutenberg plugin (WordPress/gutenberg#80555) - RTC: Use array_any() for newer-compaction check in polling sync server (WordPress/gutenberg#80522) - Fix: Update webpack-dev-server to ^5.2.1 to help with dep alerts (WordPress/gutenberg#80347) - Notes: align floating threads with their inline marker (WordPress/gutenberg#79877) - WP Build: avoid infinite worker build loop (WordPress/gutenberg#80361) - Update view config API versioning (WordPress/gutenberg#80319) - Docs: Update plugin release docs for GitHub's Release label UI (WordPress/gutenberg#80567) - Release: Require a working GitHub CLI for cherry-picking (WordPress/gutenberg#80568) - Improve the various Alignment controls props handling (WordPress/gutenberg#63696) - Reduce duplicated preset utility implementations (WordPress/gutenberg#80245) - Dashboard Widgets: harden action `href` sanitization (WordPress/gutenberg#80510) - Notes: Register the inline note format at import time (WordPress/gutenberg#80576) - Fix preset round-trip test imports after preset utils consolidation (WordPress/gutenberg#80589) - ExternalLink: Use shared focus ring mixin (WordPress/gutenberg#80573) - Combobox, Select, SelectControl: Add Group and GroupLabel (WordPress/gutenberg#80574) - Query Loop: Add translation context to the 'Offset' setting label (WordPress/gutenberg#80582) - Media: Stop forcing crossorigin on IMG tags in media templates (WordPress/gutenberg#80532) - GradientPicker: select by slug so two presets sharing a gradient keep their identity (WordPress/gutenberg#80554) - Media Editor: Show a loading state while the cropped file loads (WordPress/gutenberg#80460) - Remove default paragraph from tab-panel template (WordPress/gutenberg#80565) - Global Styles: Resolve link element styles in block inspector controls for blocks that are links (WordPress/gutenberg#80607) - Math: Use ValidatedTextareaControl for LaTeX input (WordPress/gutenberg#80500) - Navigation: Fixes `aria-expanded` not updating on hover submenu inside overlay (WordPress/gutenberg#77563) - Core Data: Move EntitiesSavedState component out of editor (rebase of WordPress/gutenberg#71948) (WordPress/gutenberg#80485) - Fix: Pullquote custom line height in the editor. (WordPress/gutenberg#80586) - Block Tools: Fix empty block appender position inside blocks that capture toolbars (WordPress/gutenberg#80592) - Editor: Avoid unnecessary term re-fetches in FlatTermSelector (WordPress/gutenberg#80623) - DependencyExtractionWebpackPlugin: Include extracted styles in the asset version hash (WordPress/gutenberg#80601) - Base styles: Allow overriding focus ring color in outset-ring__focus (WordPress/gutenberg#80587) - UI: Add Autocomplete.Row primitive (WordPress/gutenberg#80490) - Site Editor: Add E2E coverage for view config extensibility (WordPress/gutenberg#80577) - View config: reject shape-mismatched merges, define empty-array semantics, strip nulls from appended members (WordPress/gutenberg#80571) - Theme: Update Storybook admin color scheme examples (WordPress/gutenberg#80569) - Detach core's note mention kses filter in the baseline strip test (WordPress/gutenberg#80656) - Media REST API: Backport sideload from url path upload size check (WordPress/gutenberg#80659) - Rich text: remove tabIndex from editable elements again to fix shift+click selection (WordPress/gutenberg#80651) - Storybook: Remove Emotion as JSX import source (WordPress/gutenberg#80647) - Gallery: make dynamic mode conversion a single undo level (WordPress/gutenberg#80665) - Docs: Update iframe guidance for Gutenberg 23.6 (WordPress/gutenberg#80629) - Background image control: Remove duplicated focus ring (WordPress/gutenberg#80671) - DataViewsPicker: Add Shift+Click range selection to the `picker-table`, `picker-grid`, and `picker-activity` layouts (WordPress/gutenberg#80413) - Docs: Require view config filter callbacks to return the container (WordPress/gutenberg#80642) - Duotone: Dedupe duotone utils into global-styles-engine (WordPress/gutenberg#80598) - Input: Hide native spin controls for `type="number"` (WordPress/gutenberg#80646) - Make `useSelectionProps` hook layout agnostic (WordPress/gutenberg#80677) - Remove redundant @jest-environment jsdom pragma and lint against it (WordPress/gutenberg#80676) - Base Styles: Remove accent color parameter from input-control (WordPress/gutenberg#80595) - wp-build: sync the page template preload field list with core-data (WordPress/gutenberg#80648) - Add progressive-discovery pattern for agent instructions and skills and general guidelines (WordPress/gutenberg#80650) - Writing flow: extend block selections with shift+arrow when there is no native selection (WordPress/gutenberg#80687) - Fix cursor position during forward delete of empty blocks (WordPress/gutenberg#77525) - Global Styles: Extract shared preset management from shadows and font sizes (WordPress/gutenberg#79810) - Notes: Capture the target block before saving a block-level note (WordPress/gutenberg#80690) - Rename unit tests, removing `spec.js` to match the convention. (WordPress/gutenberg#80711) - Used @link for url in inline documentation (WordPress/gutenberg#80716) - Block Library: Guards against error throwing attribute values (WordPress/gutenberg#80558) - Theme JSON: Level block-level preset class specificity with :where() (WordPress/gutenberg#80657) - Notes: Sync the sidebar selection to the inline marker under the caret (WordPress/gutenberg#80610) - Page List: Use null coalescing operator for parentPageID attribute (WordPress/gutenberg#80728) - Fix font library navigation page select font size to match DataViews. (WordPress/gutenberg#80617) - Meta boxes: Match heading styles with Gutenberg panels (WordPress/gutenberg#80670) - Edit Site: Replace Theme usage in canvas loader with CSS (WordPress/gutenberg#80688) - Jest: Fix ignore patterns with dots (WordPress/gutenberg#80737) - Components: Migrate Disabled to SCSS module (WordPress/gutenberg#80643) - Enhance sandbox component to accept sandbox prop (WordPress/gutenberg#69617) - Docs: Expand the back-porting to WP Core guide (WordPress/gutenberg#80593) - Add nvm use instructions to AGENTS.md (WordPress/gutenberg#80755) - Docs: Clarify agent guidance discovery (WordPress/gutenberg#80753) - Block Editor: Fix floated blocks overlapping sticky blocks (WordPress/gutenberg#80749) - Shorten playlist track toolbar button label (WordPress/gutenberg#80759) - Block supports: Return from layout support before resolving global settings (WordPress/gutenberg#80771) - Notes: Report save success consistently from note actions (WordPress/gutenberg#80748) - Dynamic Gallery: Rename toolbar button to Detach and add a modal explaining what will happen (WordPress/gutenberg#80727) - Docs: Clarify getBlock behavior with inner block controllers (WordPress/gutenberg#80773) - Update docs for server-side view config filters (WordPress/gutenberg#80744) - createInterpolateElement: handle unmatched closing tags gracefully (WordPress/gutenberg#80618) - Components: Remove private Theme component (WordPress/gutenberg#80691) - Block Editor: Refactor 'URLInput' to function component (WordPress/gutenberg#80721) - UI: add Dialog vs Drawer design guidance (WordPress/gutenberg#80783) - Packages: Update date-fns to 4.4.0 (WordPress/gutenberg#80763) - Theme: Update Color.js to 0.7.1 (WordPress/gutenberg#80762) - ESLint: Add missing not-recommended components to denylist (WordPress/gutenberg#80754) - Jest: Update to v30 (breaking) (WordPress/gutenberg#80767) - Packages: Update memize to 2.1.1 (WordPress/gutenberg#80764) - ToolsPanel: Migrate styles to an SCSS Module (WordPress/gutenberg#80445) - RTC: Prevent controlled block synchronization from intercepting undo (WordPress/gutenberg#80503) - Build Plugin ZIP: don't abort when changelog can't be generated (WordPress/gutenberg#80791) - RTC: Compact during serialization (WordPress/gutenberg#80707) - DataForm: Stop card and details validation from hijacking focus (WordPress/gutenberg#80685) - Only use Flakiness.io in canonical Gutenberg repo. (WordPress/gutenberg#80816) - Global Styles: Put the inheritance UI behind a Gutenberg experiment (WordPress/gutenberg#80815) - Add a responsiveEditingEnabled editor setting to hide the Responsive styles option (WordPress/gutenberg#80814) - iOS: remove jumping hack, add typewriter (WordPress/gutenberg#74596) - Writing flow: stop the page scrolling on caret moves within blocks taller than the viewport (WordPress/gutenberg#80708) - List Block: Preserve ordered type on indent (WordPress/gutenberg#75353) - Block Editor: Try to fix typing performance regression (WordPress/gutenberg#80507) - Notes: Cancel in-flight hover highlight when focus leaves a note thread (WordPress/gutenberg#80752) - Make editableRoot a private block setting Symbol, not a public support (WordPress/gutenberg#80820) - Editor: leave undo to the browser in fields that handle their own undo (WordPress/gutenberg#80768) - Improve pre-flight npm access checks (WordPress/gutenberg#80334) Fixes #66065. git-svn-id: https://develop.svn.wordpress.org/trunk@63533 602fd350-edb4-49c9-b593-d223f7449a82
This updates the pinned commit hash of the Gutenberg repository from `2872d71cde528d82675f14862a1b84e2b8abbaea` to `5a0417990a9404cc2562cdd35e3054cb0d3e546e` (version `23.7.0`). A full list of changes included in this commit can be found on GitHub: https://github.com/WordPress/gutenberg/compare/2872d71cde528d82675f14862a1b84e2b8abbaea..v23.7.0. - Release: Fix cherry-pick success detection (WordPress/gutenberg#80249) - Add Table of Contents e2e user story coverage (WordPress/gutenberg#80199) - Only include icon library SVGs listed as `public` in the Zip file published to GitHub Container Registry for `wordpress-develop` (WordPress/gutenberg#79338) - fix: set dataviews popover hover text color (WordPress/gutenberg#80105) - added missing doc (WordPress/gutenberg#80172) - DataViews: Fix the unintended gap between `list` layout items when `groupBy` is set (WordPress/gutenberg#80254) - Social Link: Fix stray closing tag in Tumblr icon markup (WordPress/gutenberg#80257) - DataViews: Fix the `list` layout ignoring some settings when `groupBy` is set (WordPress/gutenberg#80255) - Icon block: Show text and background color controls by default. (WordPress/gutenberg#80251) - DataViews: Add shift-click range selection (WordPress/gutenberg#80046) - UI: Remove unused direction factor CSS property (WordPress/gutenberg#80269) - theme: Disallow src in published package (WordPress/gutenberg#80213) - Fix: stale post edit message in modal (WordPress/gutenberg#79997) - Icons: Validate SVG icons include viewBox (WordPress/gutenberg#80273) - Remove obsolete __unstable-large size props (WordPress/gutenberg#80081) - Responsive Editing: support editing pattern styles (WordPress/gutenberg#80233) - Tab List: Add toolbar buttons to reorder tabs (WordPress/gutenberg#80107) - Move image editor styles to the block editor package (WordPress/gutenberg#80165) - Cover/Accordion: Exit on Enter (WordPress/gutenberg#77301) - Hide color controls for Navigation and Social Icons when viewport states are active (WordPress/gutenberg#80289) - Icons: Fix collection unregister not removing icons after core added its own registry (WordPress/gutenberg#80292) - Widget Dashboard: collapse inline attribute controls into a dropdown (WordPress/gutenberg#80208) - Notes: increase contrast between avatar border colors (WordPress/gutenberg#80285) - Playlist: Fix track insertion (WordPress/gutenberg#80200) - Fix: Allow icon labels to wrap with word breaks and no ellipsis (WordPress/gutenberg#80256) - Dedupe deprecated prop types in composite components (WordPress/gutenberg#80277) - Core Abilities: Restore the ready promise and lazy-load via dynamic import (WordPress/gutenberg#79155) - Notes: Replace blur-deselect bookkeeping with useFocusOutside (WordPress/gutenberg#80222) - UI: Hook Popover into the wp compat overlay slot (WordPress/gutenberg#80278) - Playlist: Update @SInCE tags to 7.1.0 (WordPress/gutenberg#80317) - Remove unused useDeprecated36pxDefaultSizeProp helper. (WordPress/gutenberg#80311) - fix playlist block Dimensions Design (WordPress/gutenberg#80312) - UI: Keep the compat overlay slot accessible inside Modal (WordPress/gutenberg#80310) - Theme: Add typography token showcase (WordPress/gutenberg#80212) - Cover: Create the initial paragraph when the block gains a background (WordPress/gutenberg#80028) - Notes: Arm the mention kses allowance on REST note creation (WordPress/gutenberg#80221) - Check for post lock modal and text, not specific title and button (WordPress/gutenberg#79979) - Worker threads: reject pending RPC calls on worker failure or termination (WordPress/gutenberg#79955) - RTC: Fix empty revision from peer autosave (WordPress/gutenberg#79911) - Client Side Media: Honor image_strip_meta and image_max_bit_depth on the client upload path (WordPress/gutenberg#80218) - Vips/upload-media: consolidate optional params into options objects (WordPress/gutenberg#80330) - Editor: allow selecting which block styles to apply globally (WordPress/gutenberg#79839) - Global Styles: Reject non-string custom CSS in the REST controller (WordPress/gutenberg#80338) - Open inspector sidebar when toggling responsive editing (WordPress/gutenberg#80307) - Fix upload hang when converting long animated GIFs: decode only the first frame for still outputs (WordPress/gutenberg#80260) - Fix: Critical error related to simple-git (WordPress/gutenberg#80102) - Hide block style variations when state is enabled in global styles (WordPress/gutenberg#80341) - Media REST API: Fix sideload and finalize for EXIF rotated images (WordPress/gutenberg#80295) - Fix upload snackbar stuck in uploading state on server-side uploads (WordPress/gutenberg#80345) - Try fixing responsive layout in Nav block (WordPress/gutenberg#80305) - tools: Remove redundant parseArgs arguments (WordPress/gutenberg#80327) - Responsive styles: Use viewport dropdown to control states for in-editor global styles sidebar (WordPress/gutenberg#80339) - Use Add track instead of only Add (WordPress/gutenberg#80336) - Interactivity API: refactor directives into self-registering modules (WordPress/gutenberg#79975) - Fix: Critical error websocket-driver fix (WordPress/gutenberg#80348) - Release: Resolve commander from the test file in the release CLI test (WordPress/gutenberg#80357) - Release: Extract npm release lifecycle (WordPress/gutenberg#80190) - Fix multiple MP3 playlist uploads (WordPress/gutenberg#80101) - Table of Contents: render front-end list from current post headings (WordPress/gutenberg#80318) - UI: improve component code readability in Storybook by using arrays for children (WordPress/gutenberg#80352) - Infra: Use devEngines in root package.json and pin npm version in CI (WordPress/gutenberg#80188) - Automated Testing: Skip type-checking in bundle size comparison build (WordPress/gutenberg#80366) - Theme: Update colorjs.io dependency and drop bug workaround (WordPress/gutenberg#80272) - RichTextControl: Replace DOM focus tracking with a single React-tree focus boundary (WordPress/gutenberg#80324) - Notes: Finish WPDS treatment for mention chips (WordPress/gutenberg#80300) - Notes: Add placeholders to the RichText fields (WordPress/gutenberg#80296) - Fix flaky test in `tabs.spec.js` (WordPress/gutenberg#80373) - Packages: Update exports to avoid deprecated folder export syntax (WordPress/gutenberg#80270) - Theme: Widen peer dependency ranges to support new versions of Vite, ESBuild, and Stylelint (WordPress/gutenberg#80267) - Components: Skip polymorphism prop typings on intersection (WordPress/gutenberg#80364) - Post Content: Use the default block appender for empty content (WordPress/gutenberg#80026) - Device preview dropdown: use active color for device icon when responsive styles are active (WordPress/gutenberg#80346) - Fix default aspect ratio for lazy loaded Featured image (WordPress/gutenberg#80386) - Docs: Add client-side media processing documentation (WordPress/gutenberg#75895) - Autocompleters: Don't pre-encode mention search terms (WordPress/gutenberg#80377) - Animated GIF uploads: generate sub-sizes from the first frame, matching core (WordPress/gutenberg#80268) - Media: Add timeout and size guardrails to client-side GIF to video conversion (WordPress/gutenberg#80379) - Widget Primitives: Ship as a script module (WordPress/gutenberg#80149) - SearchControl: Render the suffix only if there's one. (WordPress/gutenberg#80356) - Custom CSS: Fix cascade order against block style variations (WordPress/gutenberg#80340) - React 19: add e2e compat test for boolean inert attribute (WordPress/gutenberg#80397) - Fix post excerpt rendering to conditionally include space before more… (WordPress/gutenberg#70217) - Add wp-theme as a style dependency of wp-components (WordPress/gutenberg#80362) - Dashboard Widgets: declarative actions in the widget schema (WordPress/gutenberg#80363) - @wordpress/ui: Add Button Storybook example for keyboard shortcut composition (WordPress/gutenberg#80353) - SlotFill: Validate cross-document SCSS module styles (WordPress/gutenberg#80384) - Components: migrate ConfirmDialog to SCSS module (WordPress/gutenberg#80394) - SearchControl: Remove redundant conditional and prop. (WordPress/gutenberg#80406) - Tools: resolve dependencies independently of the node_modules layout (WordPress/gutenberg#80414) - Components: Migrate ToggleGroupControl to SCSS Modules (WordPress/gutenberg#80381) - Rich Text: Restore the selection when focus returns to the editable (WordPress/gutenberg#80396) - RTC: Use requestAnimationFrame for awareness cursor resize redraws (WordPress/gutenberg#79685) - Remove __shouldNotWarnDeprecated36pxSize internal prop (WordPress/gutenberg#80323) - Fix upload snackbar double-counting a single HEIC upload in Safari (WordPress/gutenberg#80371) - Fix Root `.prettierrc.js` override issue (WordPress/gutenberg#80422) - Fix Color Picker Cursor Shaking Issue (WordPress/gutenberg#80205) - Storybook: pre-bundle CJS deps (WordPress/gutenberg#80426) - ContentEditableControl: fix invalid label association with contenteditable div (WordPress/gutenberg#80344) - Writing flow: use isMultiSelecting for shift+click (WordPress/gutenberg#80286) - Added Missing Global Documentation (WordPress/gutenberg#80442) - Editor: Disable canvas resizing while zoomed out (WordPress/gutenberg#80391) - Misc fixes for WordPress-Develop 7.0 merges (WordPress/gutenberg#75985) - RTC: Preserve collaborators' unsaved edits when another user saves (WordPress/gutenberg#79936) - RTC: Disable Quick Edit while a post is being edited (WordPress/gutenberg#80016) - Storybook: build the resolve specifier as a URL-style string (WordPress/gutenberg#80416) - Style Book: Restore live global styles updates on the styles route (WordPress/gutenberg#80459) - Editor: Restore fixed device preview height for mobile and tablet (WordPress/gutenberg#80271) - Block Supports: Handle nested array block gap values properly (WordPress/gutenberg#80464) - Block Editor: Guard against non-string spacing preset values (WordPress/gutenberg#80467) - Move real-time collaboration code to lib/experimental/collaboration (WordPress/gutenberg#80469) - RTC: Fix deleted-user test on multisite (WordPress/gutenberg#80463) - Build: add independent react-18 vendor package (WordPress/gutenberg#80367) - Fix `useHomeEnd` on tabs in mac testing (WordPress/gutenberg#80374) - Block Editor: Reflect inherited Global Styles values in block inspector controls (WordPress/gutenberg#77894) - Media: Remove the redundant __heicUploadSupport flag (WordPress/gutenberg#80452) - Writing flow: fully select the ancestor when a text selection crosses a nesting boundary (WordPress/gutenberg#80462) - fix: show add block button when editing a template part inside a template (WordPress/gutenberg#78427) - Autocomplete: Reference the suggestions list with `aria-controls` and `aria-haspopup` (WordPress/gutenberg#80403) - Dashboard Widgets: Sanitize help link hrefs. (WordPress/gutenberg#80409) - State control - avoid tertiary variant on toggle to match style of other dropdown toggles (WordPress/gutenberg#80505) - Widget Dashboard: measure the header fit and document the chrome (WordPress/gutenberg#80423) - DataViews/Font Library: Give search fields a fixed width to stop layout shift (WordPress/gutenberg#80315) - Fix crashes when manipulating locked blocks (WordPress/gutenberg#80509) - RTC: Use str_contains() in WP_Sync_Config type parsing (WordPress/gutenberg#80476) - Table of Contents: Use str_contains() instead of strpos() check (WordPress/gutenberg#80418) - Build: Handle project paths containing spaces in dev script (WordPress/gutenberg#80519) - Components: migrate SearchControl to SCSS module (WordPress/gutenberg#80474) - Icons: Store the sanitized SVG content when registering an icon (WordPress/gutenberg#80508) - Resolve Prettier explicitly for isolated layout (WordPress/gutenberg#80529) - Playlist: Fix playback of tracks served without CORS headers (WordPress/gutenberg#80533) - Remove unnecessary __next40pxDefaultSize props from form controls (WordPress/gutenberg#80540) - GitHub workflows: Fix changelog checks for forked PRs (WordPress/gutenberg#80538) - Redirect editing events to extension handlers under editableRoot (WordPress/gutenberg#80287) - Writing flow: fully select the items when a selection extends down into a nested item (WordPress/gutenberg#80492) - Global Styles panels: fix wrong preset committed and shown when two color presets share a hex (WordPress/gutenberg#80497) - Replaces the `title` attributes used by revision inline diff annotations with `aria-describedby` (WordPress/gutenberg#80440) - Account for non-lowercase VIDEO tag in render_block filter (WordPress/gutenberg#80537) - Components: migrate FormTokenField to SCSS module (WordPress/gutenberg#80472) - Revisions: Specify block level diff status via aria-label (WordPress/gutenberg#77779) - Notes: Remove "Add note" from the inline styles dropdown (WordPress/gutenberg#80531) - Global Styles: Resolve per-level heading element styles in block inspector controls (WordPress/gutenberg#80495) - Notes: Render @ mentions as span chips and narrow the kses class allowance (WordPress/gutenberg#80528) - Backport from Core: improve icon name unit tests (WordPress/gutenberg#80552) - Read the contentEditable attribute in ownsSelection, not isContentEditable (WordPress/gutenberg#80549) - Device type preview: fix collapsing to content height (WordPress/gutenberg#80553) - Wrap notices in ThemeProvider with 0 corner radius (WordPress/gutenberg#79523) - Perf Tests: Fix 'Selecting blocks' metric reporting 0 ms (WordPress/gutenberg#80524) - Global Styles: Limit the inherited value treatment to the Gutenberg plugin (WordPress/gutenberg#80555) - RTC: Use array_any() for newer-compaction check in polling sync server (WordPress/gutenberg#80522) - Fix: Update webpack-dev-server to ^5.2.1 to help with dep alerts (WordPress/gutenberg#80347) - Notes: align floating threads with their inline marker (WordPress/gutenberg#79877) - WP Build: avoid infinite worker build loop (WordPress/gutenberg#80361) - Update view config API versioning (WordPress/gutenberg#80319) - Docs: Update plugin release docs for GitHub's Release label UI (WordPress/gutenberg#80567) - Release: Require a working GitHub CLI for cherry-picking (WordPress/gutenberg#80568) - Improve the various Alignment controls props handling (WordPress/gutenberg#63696) - Reduce duplicated preset utility implementations (WordPress/gutenberg#80245) - Dashboard Widgets: harden action `href` sanitization (WordPress/gutenberg#80510) - Notes: Register the inline note format at import time (WordPress/gutenberg#80576) - Fix preset round-trip test imports after preset utils consolidation (WordPress/gutenberg#80589) - ExternalLink: Use shared focus ring mixin (WordPress/gutenberg#80573) - Combobox, Select, SelectControl: Add Group and GroupLabel (WordPress/gutenberg#80574) - Query Loop: Add translation context to the 'Offset' setting label (WordPress/gutenberg#80582) - Media: Stop forcing crossorigin on IMG tags in media templates (WordPress/gutenberg#80532) - GradientPicker: select by slug so two presets sharing a gradient keep their identity (WordPress/gutenberg#80554) - Media Editor: Show a loading state while the cropped file loads (WordPress/gutenberg#80460) - Remove default paragraph from tab-panel template (WordPress/gutenberg#80565) - Global Styles: Resolve link element styles in block inspector controls for blocks that are links (WordPress/gutenberg#80607) - Math: Use ValidatedTextareaControl for LaTeX input (WordPress/gutenberg#80500) - Navigation: Fixes `aria-expanded` not updating on hover submenu inside overlay (WordPress/gutenberg#77563) - Core Data: Move EntitiesSavedState component out of editor (rebase of WordPress/gutenberg#71948) (WordPress/gutenberg#80485) - Fix: Pullquote custom line height in the editor. (WordPress/gutenberg#80586) - Block Tools: Fix empty block appender position inside blocks that capture toolbars (WordPress/gutenberg#80592) - Editor: Avoid unnecessary term re-fetches in FlatTermSelector (WordPress/gutenberg#80623) - DependencyExtractionWebpackPlugin: Include extracted styles in the asset version hash (WordPress/gutenberg#80601) - Base styles: Allow overriding focus ring color in outset-ring__focus (WordPress/gutenberg#80587) - UI: Add Autocomplete.Row primitive (WordPress/gutenberg#80490) - Site Editor: Add E2E coverage for view config extensibility (WordPress/gutenberg#80577) - View config: reject shape-mismatched merges, define empty-array semantics, strip nulls from appended members (WordPress/gutenberg#80571) - Theme: Update Storybook admin color scheme examples (WordPress/gutenberg#80569) - Detach core's note mention kses filter in the baseline strip test (WordPress/gutenberg#80656) - Media REST API: Backport sideload from url path upload size check (WordPress/gutenberg#80659) - Rich text: remove tabIndex from editable elements again to fix shift+click selection (WordPress/gutenberg#80651) - Storybook: Remove Emotion as JSX import source (WordPress/gutenberg#80647) - Gallery: make dynamic mode conversion a single undo level (WordPress/gutenberg#80665) - Docs: Update iframe guidance for Gutenberg 23.6 (WordPress/gutenberg#80629) - Background image control: Remove duplicated focus ring (WordPress/gutenberg#80671) - DataViewsPicker: Add Shift+Click range selection to the `picker-table`, `picker-grid`, and `picker-activity` layouts (WordPress/gutenberg#80413) - Docs: Require view config filter callbacks to return the container (WordPress/gutenberg#80642) - Duotone: Dedupe duotone utils into global-styles-engine (WordPress/gutenberg#80598) - Input: Hide native spin controls for `type="number"` (WordPress/gutenberg#80646) - Make `useSelectionProps` hook layout agnostic (WordPress/gutenberg#80677) - Remove redundant @jest-environment jsdom pragma and lint against it (WordPress/gutenberg#80676) - Base Styles: Remove accent color parameter from input-control (WordPress/gutenberg#80595) - wp-build: sync the page template preload field list with core-data (WordPress/gutenberg#80648) - Add progressive-discovery pattern for agent instructions and skills and general guidelines (WordPress/gutenberg#80650) - Writing flow: extend block selections with shift+arrow when there is no native selection (WordPress/gutenberg#80687) - Fix cursor position during forward delete of empty blocks (WordPress/gutenberg#77525) - Global Styles: Extract shared preset management from shadows and font sizes (WordPress/gutenberg#79810) - Notes: Capture the target block before saving a block-level note (WordPress/gutenberg#80690) - Rename unit tests, removing `spec.js` to match the convention. (WordPress/gutenberg#80711) - Used @link for url in inline documentation (WordPress/gutenberg#80716) - Block Library: Guards against error throwing attribute values (WordPress/gutenberg#80558) - Theme JSON: Level block-level preset class specificity with :where() (WordPress/gutenberg#80657) - Notes: Sync the sidebar selection to the inline marker under the caret (WordPress/gutenberg#80610) - Page List: Use null coalescing operator for parentPageID attribute (WordPress/gutenberg#80728) - Fix font library navigation page select font size to match DataViews. (WordPress/gutenberg#80617) - Meta boxes: Match heading styles with Gutenberg panels (WordPress/gutenberg#80670) - Edit Site: Replace Theme usage in canvas loader with CSS (WordPress/gutenberg#80688) - Jest: Fix ignore patterns with dots (WordPress/gutenberg#80737) - Components: Migrate Disabled to SCSS module (WordPress/gutenberg#80643) - Enhance sandbox component to accept sandbox prop (WordPress/gutenberg#69617) - Docs: Expand the back-porting to WP Core guide (WordPress/gutenberg#80593) - Add nvm use instructions to AGENTS.md (WordPress/gutenberg#80755) - Docs: Clarify agent guidance discovery (WordPress/gutenberg#80753) - Block Editor: Fix floated blocks overlapping sticky blocks (WordPress/gutenberg#80749) - Shorten playlist track toolbar button label (WordPress/gutenberg#80759) - Block supports: Return from layout support before resolving global settings (WordPress/gutenberg#80771) - Notes: Report save success consistently from note actions (WordPress/gutenberg#80748) - Dynamic Gallery: Rename toolbar button to Detach and add a modal explaining what will happen (WordPress/gutenberg#80727) - Docs: Clarify getBlock behavior with inner block controllers (WordPress/gutenberg#80773) - Update docs for server-side view config filters (WordPress/gutenberg#80744) - createInterpolateElement: handle unmatched closing tags gracefully (WordPress/gutenberg#80618) - Components: Remove private Theme component (WordPress/gutenberg#80691) - Block Editor: Refactor 'URLInput' to function component (WordPress/gutenberg#80721) - UI: add Dialog vs Drawer design guidance (WordPress/gutenberg#80783) - Packages: Update date-fns to 4.4.0 (WordPress/gutenberg#80763) - Theme: Update Color.js to 0.7.1 (WordPress/gutenberg#80762) - ESLint: Add missing not-recommended components to denylist (WordPress/gutenberg#80754) - Jest: Update to v30 (breaking) (WordPress/gutenberg#80767) - Packages: Update memize to 2.1.1 (WordPress/gutenberg#80764) - ToolsPanel: Migrate styles to an SCSS Module (WordPress/gutenberg#80445) - RTC: Prevent controlled block synchronization from intercepting undo (WordPress/gutenberg#80503) - Build Plugin ZIP: don't abort when changelog can't be generated (WordPress/gutenberg#80791) - RTC: Compact during serialization (WordPress/gutenberg#80707) - DataForm: Stop card and details validation from hijacking focus (WordPress/gutenberg#80685) - Only use Flakiness.io in canonical Gutenberg repo. (WordPress/gutenberg#80816) - Global Styles: Put the inheritance UI behind a Gutenberg experiment (WordPress/gutenberg#80815) - Add a responsiveEditingEnabled editor setting to hide the Responsive styles option (WordPress/gutenberg#80814) - iOS: remove jumping hack, add typewriter (WordPress/gutenberg#74596) - Writing flow: stop the page scrolling on caret moves within blocks taller than the viewport (WordPress/gutenberg#80708) - List Block: Preserve ordered type on indent (WordPress/gutenberg#75353) - Block Editor: Try to fix typing performance regression (WordPress/gutenberg#80507) - Notes: Cancel in-flight hover highlight when focus leaves a note thread (WordPress/gutenberg#80752) - Make editableRoot a private block setting Symbol, not a public support (WordPress/gutenberg#80820) - Editor: leave undo to the browser in fields that handle their own undo (WordPress/gutenberg#80768) - Improve pre-flight npm access checks (WordPress/gutenberg#80334) Fixes #66065. Built from https://develop.svn.wordpress.org/trunk@63533 git-svn-id: http://core.svn.wordpress.org/trunk@62709 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Closes #80502.
Supersedes #80496 with the approach agreed in its discussion.
What
Switch the Notes
@mention markup from a link to a non-interactivespanchip:and replace the per-note kses arm/disarm machinery in
lib/compat/wordpress-7.1/block-comments.phpwith two small always-on filters:wp_kses_allowed_htmlfilter that allowsspanwithclassin thepre_comment_contentcontext, andpre_comment_contentfilter at priority 11 (right afterwp_filter_kses) that reduces every span'sclassto the only two tokens the mention markup uses:wp-note-mentionanduser-N.Why
This lands the consensus from #80496:
spantakes them out of the Link format UI entirely, which fixes the behavior in Mamaduka's screencast where editing a mention through the Link UI destroyed the mention markup. Thewp-note-mentionclass stays so no registered format claims the element (formats are differentiated by tag name and class), and per Mamaduka's testing RichText preserves the unregistered span without a dedicated mention format.data-*is not allowed by default inpre_comment_content, see the Notes: Carry mention user IDs in a data attribute instead of classes #80496 write-up), a data attribute has no security edge over a class whose tokens are strictly allowlisted. The class also keeps working as the format-differentiation and styling hook.classhole without stateful kses arming (@westonruter's original concern): the previous approach allowed any class on note links, guarded by ~120 lines of per-write arm/disarm across two request paths. Now the allowance is unconditional but reduced to exactly two inert tokens, so there is no styling/scripting selector surface to protect and no kses state to arm and disarm.Behavior change
All commenters (including anonymous ones) can now persist
<span>elements whoseclassis limited towp-note-mentionand/oruser-Nin comment content. This is inert:spanis semantics-free, the two tokens are not styling or scripting hooks outside the notes sidebar, and mention notification parsing (#79606) only processesnote-type comments.The class reduction only runs while the restrictive comment allowlist (
wp_filter_kses) is active: users withunfiltered_htmlare filtered throughwp_filter_post_kses, where arbitrary classes are already permitted, and narrowing their markup would restrict what core allows them to post.Coordination follow-ups
user-Nclass parsing itself is unchanged), and per Mamaduka's last review note it should add an identity check before notifying - the chip text can be partially edited while the span retains itsuser-Nclass, so the parser should verify the remaining text still matches the mentioned user before emailing.function_exists( '_wp_kses_allow_note_mention_span' )guard here disables this plugin copy.Testing instructions
unfiltered_html(e.g. an author), open a post, select a block, and add a note.@and pick a teammate. The mention renders as a chip.<span class="wp-note-mention user-<id>">(inspect the element). This is the case the kses allowance exists for.Automated coverage:
phpunit/tests/notes-mention-kses-test.phpMentions in the note formdescribe intest/e2e/specs/editor/various/block-notes.spec.js