Skip to content

Tests: Don't rely on KSES rewriting comment closers - #788

Merged
bor0 merged 1 commit into
trunkfrom
fix/content-validation-test-nightly
Oct 8, 2026
Merged

bor0 merged 1 commit into
trunkfrom
fix/content-validation-test-nightly

Conversation

@bor0

@bor0 bor0 commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

PHP unit tests are failing on every branch (for example #787) because WordPress nightly changed how KSES treats block comment closers with extra dashes.

test_content_rewritten_on_save_is_refused assumed KSES rewrites <!-- wp:wporg/modal /---> to <!-- wp:wporg/modal /-->, which turns text the parser ignored into a block. reject_unstable_blocks exists to refuse content like that. On nightly (7.2-alpha-64238) KSES leaves the comment as it is:

"<!-- wp:wporg/modal /--->" => "<!-- wp:wporg/modal /--->"   blocks before/after: [null] / [null]

So nothing is rewritten, the request is accepted, and the four "extra dash" cases fail. This isn't a security regression: what's stored is what was checked. The guard is still needed on WordPress versions that do rewrite these comments, so it stays.

Changes

The four cases move out of test_content_rewritten_on_save_is_refused into two new tests that share a data provider:

  • test_unstable_block_markup_is_refused applies the old rewrite with a content_save_pre filter, so the check itself is still tested whatever version runs the suite. With the check disabled, all four cases fail.
  • test_block_markup_is_refused_or_stored_unchanged uses the real save filters and asserts the content is either refused or stored with the same blocks that were checked.

The shortcode and control-character cases are unchanged. The member-pattern setup moves into small helpers that the tests share.

Testing

npm run test:php passes against nightly: 317 tests.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Tests
    • Expanded coverage for pattern content validation, including malformed block delimiters, changes to block structure during normalization, reconstructed shortcodes, and control characters.
    • Added checks that unstable markup is rejected or stored without changing its block structure.

`test_content_rewritten_on_save_is_refused` assumed KSES normalizes a block
comment closer with extra dashes (`--->`) to `-->`. WordPress nightly no
longer does, so the content is stored unchanged, nothing is refused, and four
cases fail.

Split those cases out into two tests:
- Apply the rewrite with a `content_save_pre` filter, so the
  `reject_unstable_blocks` check is still tested whatever version runs the suite.
- With the real save filters, assert the content is either refused or stored
  with the blocks that were checked, which is the property the check protects.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0bbe9105-9ea5-488b-8265-410148274be5
📥 Commits

Reviewing files that changed from the base of the PR and between 059f7e1 and 64193ce.

📒 Files selected for processing (1)
  • public_html/wp-content/plugins/pattern-directory/tests/phpunit/pattern-content-validation-test.php

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates pattern content validation tests. It adds save-rewrite cases, tests for block markup affected by comment-closer normalization, and shared helpers for submitting content through REST.

Changes

Pattern content validation

Layer / File(s) Summary
REST save-rewrite validation
public_html/wp-content/plugins/pattern-directory/tests/phpunit/pattern-content-validation-test.php
The tests use shared helpers to create a member-owned draft pattern and submit content through REST. New cases cover a shortcode reconstructed after script removal and control characters in block names or markers.
Block markup stability validation
public_html/wp-content/plugins/pattern-directory/tests/phpunit/pattern-content-validation-test.php
New tests check block markup affected by save-time comment-closer normalization. Cases include an expected rest_pattern_unstable_blocks error and a check that stored content retains the submitted block shape. Malformed closer fixtures include delimiters that change nesting.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Suggested reviewers: obenland

Merge Risk: ⚪ Minimal · up to 64193

This change only updates tests so they no longer depend on KSES rewriting block-comment closers. It has no production behavior impact and is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: updating tests so they do not depend on KSES rewriting block comment closers.
Description check ✅ Passed The description explains the failure, cause, test changes, retained validation, and test result. It does not provide issue references, contributor credits, or the exact template headings, but these om…
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@bor0
bor0 merged commit cd6bb5e into trunk Oct 8, 2026
5 checks passed
@bor0
bor0 deleted the fix/content-validation-test-nightly branch October 8, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant