Fix disabled block allowlist handling - #228
Open
dknauss wants to merge 2 commits into
Open
Conversation
dknauss
force-pushed
the
pr/comment-blocks-preserve-disallow
branch
from
July 5, 2026 02:44
e9dbda1 to
3a7bcb1
Compare
dknauss
force-pushed
the
pr/comment-blocks-preserve-disallow
branch
from
July 5, 2026 02:59
3a7bcb1 to
550e2f8
Compare
dknauss
marked this pull request as ready for review
July 5, 2026 03:14
There was a problem hiding this comment.
Pull request overview
This PR adjusts the allowed_block_types_all filter callback used by the comments-disabling feature to preserve WordPress’s “no blocks allowed” semantics when earlier filters disable blocks, instead of rebuilding an allowlist and accidentally re-enabling blocks.
Changes:
- Updates the PHPDoc for
remove_comment_blocks()to reflect boolean/array semantics. - Preserves upstream
falsevalues by returningfalseearly. - Only builds an allowlist from the registry when blocks are otherwise allowed (e.g.,
true/ unset list cases).
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The expansion guard treated empty( $allowed_block_types ) as 'no list set' and expanded it to every registered block. But an explicit empty array is a deliberate deny-all — WordPress treats [] the same as false — so an earlier filter disabling all blocks was silently overridden and every block re-allowed. Drop the empty() clause: [] is an array and not true, so it now flows through the filter loop unchanged (returns []).
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of the Change
Fixes an edge case in the disabled-comments block allowlist filter.
When another
allowed_block_types_allfilter has already returnedfalse, WordPress interprets that as "no blocks allowed." The current comments filter replaces that value with a full registered-block allowlist minus comment blocks, which unintentionally re-enables blocks that an earlier filter disabled.This change preserves
falseand only builds a filtered block list when blocks are otherwise allowed.Benefits
trueor array allowlists.Possible Drawbacks
None expected. This only changes behavior when a previous filter has already disabled all blocks.
Verification Process
php -l includes/classes/Comments/Comments.phpcomposer run lintgit diff --checkChangelog Entry
Checklist:
A note on tests
This change has unit-testable logic, but the plugin currently ships no test harness (no PHPUnit or e2e setup; CI runs lint only), so there's nothing here to add coverage to. I'm happy to contribute a minimal test setup plus coverage for this in a separate PR if that's welcome.
AI assistance was used in drafting and reviewing this change; final authorship and verification are mine.