Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 4 additions & 5 deletions plugins/optimization-detective/detect-loader.js
Original file line number Diff line number Diff line change
Expand Up @@ -26,13 +26,12 @@ async function load() {
} );
}

const argsScript = document.getElementById(
'optimization-detective-detect-args'
);
const jsonScriptSelector = 'script#optimization-detective-detect-args';
const argsScript = document.querySelector( jsonScriptSelector );
if ( ! ( argsScript instanceof HTMLScriptElement ) ) {
throw new Error( 'Missing: SCRIPT#optimization-detective-detect-args' );
throw new Error( `Missing: ${ jsonScriptSelector }` );
}
const data = JSON.parse( argsScript.textContent );
const data = JSON.parse( argsScript.text );
if (
! Array.isArray( data ) ||
data.length !== 2 ||
Expand Down
4 changes: 2 additions & 2 deletions plugins/optimization-detective/load.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* Description: Provides a framework for leveraging real user metrics to detect optimizations for improving page performance.
* Requires at least: 6.9
* Requires PHP: 7.4
* Version: 1.0.0-beta5
* Version: 1.0.0-beta6
* Author: WordPress Performance Team
* Author URI: https://make.wordpress.org/performance/
* License: GPLv2 or later
Expand Down Expand Up @@ -73,7 +73,7 @@ static function ( string $global_var_name, string $version, Closure $load ): voi
}
)(
'optimization_detective_pending_plugin',
'1.0.0-beta5',
'1.0.0-beta6',
static function ( string $version ): void {
if ( defined( 'OPTIMIZATION_DETECTIVE_VERSION' ) ) {
return;
Expand Down
8 changes: 7 additions & 1 deletion plugins/optimization-detective/readme.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

Contributors: wordpressdotorg
Tested up to: 7.0
Stable tag: 1.0.0-beta5
Stable tag: 1.0.0-beta6
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
Tags: performance, optimization, rum
Expand Down Expand Up @@ -55,6 +55,12 @@ The [plugin source code](https://github.com/WordPress/performance/tree/trunk/plu

== Changelog ==

= 1.0.0-beta6 =

**Security**

* Add validation of the SCRIPT element containing the detection args JSON. This fixes a DOM clobbering vulnerability in which an injected element with a colliding `id` could shadow the script and cause an arbitrary module to be imported, which required an authenticated user with at least a contributor role. Props to Asaf Mozes (amosec) for [responsible disclosure](https://github.com/WordPress/performance/blob/trunk/SECURITY.md).

= 1.0.0-beta5 =

**Bug Fixes**
Expand Down
Loading