Dynamic tags can read post, user, term and option data, so GenerateBlocks controls who can add tags and which data a tag can reveal. These hooks change those rules and how meta values are read.
Several of them are security settings. Loosening them can expose private data to visitors or editors, so only change them when you control who can write content. For how tags are output and previewed, see Dynamic tags: output and rendering.
Jump to
- Who can use dynamic tags
- Reading meta
- Restricting data
- Editor (JavaScript)
- Save gate rules
Who can use dynamic tags
Dynamic tags that read protected data are only allowed in content saved by trusted users. GenerateBlocks checks this when content is saved (the save gate) and again when it is rendered.
generateblocks_user_can_author_dynamic_data
GB Free — since GenerateBlocks 2.4. GenerateBlocks Pro also uses it.
The generateblocks_user_can_author_dynamic_data filter chooses whether the current user may author dynamic tags. Users who can’t see the dynamic tag preview in the editor, and their saves are checked by the save gate.
Security: returning true lets the user add tags that can disclose protected meta, other users’ meta, options and data from other posts. Only grant it to fully trusted roles.
Parameters: $can_author (bool). Default: true for users with the unfiltered_html or manage_options capability, otherwise false.
add_filter( 'generateblocks_user_can_author_dynamic_data', function( $can_author ) {
return $can_author || current_user_can( 'edit_others_posts' );
} );
Related: generateblocks_dynamic_tags_preview, Save gate rules Guide: Dynamic Tags
generateblocks_enforce_dynamic_data_save_gate
GB Free — since GenerateBlocks 2.4.
The generateblocks_enforce_dynamic_data_save_gate filter turns the dynamic data save gate on or off. When it’s on, a save from a user who can’t author dynamic data is rejected if it adds dynamic data.
Security: turning it off removes the save-time check for this rule. The render-time check still applies.
Parameters: $enforce (bool), $context (array, the save context with post_id and post_type). Default: true.
add_filter( 'generateblocks_enforce_dynamic_data_save_gate', function( $enforce, $context ) {
// Skip the gate for an import post type.
if ( 'my_import' === ( $context['post_type'] ?? '' ) ) {
return false;
}
return $enforce;
}, 10, 2 );
Related: generateblocks_enforce_save_gate_rule Guide: Dynamic Tags
generateblocks_enforce_save_gate_rule
GB Free — since GenerateBlocks 2.4.
The generateblocks_enforce_save_gate_rule filter turns any single save gate rule on or off by its ID. The dynamic data rule’s ID is dynamic_data.
Parameters: $enforce (bool), $rule_id (string), $context (array with post_id and post_type). Default: true.
add_filter( 'generateblocks_enforce_save_gate_rule', function( $enforce, $rule_id, $context ) {
if ( 'my_rule' === $rule_id && 'my_import' === ( $context['post_type'] ?? '' ) ) {
return false;
}
return $enforce;
}, 10, 3 );
Related: Save gate rules Guide: Dynamic Tags
generateblocks_force_validate_content
GB Free
The generateblocks_force_validate_content filter makes the save gate check content that has no dynamic tag syntax in it. Use it when another plugin adds dynamic data to content in a way GenerateBlocks can’t detect.
Parameters: $force (bool), $content (string, the post content). Default: false.
add_filter( 'generateblocks_force_validate_content', function( $force, $content ) {
return $force || false !== strpos( $content, 'my-plugin/dynamic-block' );
}, 10, 2 );
Related: generateblocks_enforce_dynamic_data_save_gate Guide: Dynamic Tags
generateblocks_allow_dynamic_data_in_event_handlers
GB Free — since GenerateBlocks 2.4.
The generateblocks_allow_dynamic_data_in_event_handlers filter lets dynamic tags resolve inside an inline event handler attribute such as onclick. By default tags in event handlers resolve to nothing, and srcdoc is always stripped.
Security: the browser decodes an attribute before running it as JavaScript, so escaping can’t make a resolved value safe there. Returning true allows stored cross-site scripting, so use it only as a temporary bridge while you move a handler to a data-* attribute read by a delegated listener.
Parameters: $allow (bool), $context (array with attribute (the attribute name), tags (the full tags in the value) and contexts (the resolved tag contexts)). Default: false.
add_filter( 'generateblocks_allow_dynamic_data_in_event_handlers', function( $allow, $context ) {
// Temporary: keep one legacy handler working while it is migrated.
return 'onclick' === $context['attribute'] ? true : $allow;
}, 10, 2 );
Related: generateblocks_dynamic_tag_output Guide: Dynamic Tags
Reading meta
The post meta, user meta, term meta and option tags all read their values through the same handler. Dots in a key read into nested values, such as parent.child.
generateblocks_get_meta_pre_value
GB Free — since GenerateBlocks 2.0. GenerateBlocks Pro uses it for Advanced Custom Fields.
The generateblocks_get_meta_pre_value filter supplies a meta value with your own getter, such as ACF’s get_field(). If you return anything other than null, GenerateBlocks skips the WordPress meta function and uses your value.
Parameters: $pre_value (null by default), $id (int, the entity ID), $key (string, the meta key), $callable (string, the WordPress function it would call, such as get_post_meta), $single_only (bool, whether only string-like values are returned). Default: null.
add_filter( 'generateblocks_get_meta_pre_value', function( $pre_value, $id, $key, $callable, $single_only ) {
if ( 'get_post_meta' === $callable && 'my_computed_value' === $key ) {
return my_plugin_compute_value( $id );
}
return $pre_value;
}, 10, 5 );
Related: generateblocks_get_meta_object, generateblocks_pro_dynamic_tags_is_acf_field Guide: Dynamic Tags
generateblocks_get_meta_object
GB Free
The generateblocks_get_meta_object filter changes the meta object after it is read and before GenerateBlocks picks out the sub keys from the key.
Parameters: $meta (the meta value), $id (int), $key (string), $callable (string). Default: the value read from the first part of the key.
add_filter( 'generateblocks_get_meta_object', function( $meta, $id, $key, $callable ) {
if ( 'get_post_meta' === $callable && is_string( $meta ) && 'my_json_meta' === $key ) {
return json_decode( $meta, true );
}
return $meta;
}, 10, 4 );
Related: generateblocks_get_meta_value Guide: Dynamic Tags
generateblocks_get_meta_value
GB Free — since GenerateBlocks 2.0.
The generateblocks_get_meta_value filter changes the final value of a meta lookup.
Parameters: $value (the value), $id (int|string, the entity ID), $key (string, which may include sub keys separated by dots), $single_only (bool), $callable (string). Default: the value for the full key.
add_filter( 'generateblocks_get_meta_value', function( $value, $id, $key, $single_only, $callable ) {
if ( 'my_price' === $key && is_numeric( $value ) ) {
return number_format_i18n( (float) $value, 2 );
}
return $value;
}, 10, 5 );
Related: generateblocks_get_meta_object Guide: Dynamic Tags
Restricting data
generateblocks_restrict_user_meta_access
GB Free — since GenerateBlocks 2.1.4.
The generateblocks_restrict_user_meta_access filter chooses whether to restrict reading a user’s meta. The filter only runs when none of these apply: the current user can list users, the current user is the user being read, or the key is in the safe list.
Security: returning false can expose sensitive user data to all visitors. Only do it if you have your own access controls.
Parameters: $should_restrict (bool), $user_id (int, the user being read), $current_user_id (int, 0 when logged out). Default: true.
add_filter( 'generateblocks_restrict_user_meta_access', function( $should_restrict, $user_id, $current_user_id ) {
// Let logged in members read each other's meta.
return $current_user_id ? false : $should_restrict;
}, 10, 3 );
Related: generateblocks_safe_user_meta_keys Guide: Dynamic Tags
generateblocks_safe_user_meta_keys
GB Free — since GenerateBlocks 2.1.4.
The generateblocks_safe_user_meta_keys filter changes the user meta keys that any visitor may read through a dynamic tag.
Security: only add keys that are safe to show publicly.
Parameters: $safe_keys (array of meta keys). Default: description, first_name, last_name, nickname, display_name, user_nicename, user_url, locale and show_admin_bar_front.
add_filter( 'generateblocks_safe_user_meta_keys', function( $safe_keys ) {
$safe_keys[] = 'job_title';
return $safe_keys;
} );
Related: generateblocks_restrict_user_meta_access Guide: Dynamic Tags
generateblocks_allowed_option_keys_rest_api
GB Free
The generateblocks_allowed_option_keys_rest_api filter changes the option keys that users who can edit posts but not manage options may read in the editor through generateblocks/v1/meta/get-option. Administrators can read any option.
Parameters: $allowed_keys (array of option names). Default: siteurl, blogname, blogdescription, home, time_format and user_count.
add_filter( 'generateblocks_allowed_option_keys_rest_api', function( $allowed_keys ) {
$allowed_keys[] = 'my_plugin_phone_number';
return $allowed_keys;
} );
Related: generateblocks_dynamic_tags_allowed_options Guide: Dynamic Tags
generateblocks_dynamic_tags_allowed_options
GB Pro — since GenerateBlocks Pro 2.0.
The generateblocks_dynamic_tags_allowed_options filter changes the options that the Site option dynamic tag may output. Keys that aren’t in the list output an empty string.
Parameters: $allowed_options (array of option names). Default: siteurl, blogname, blogdescription, home, time_format and user_count, plus the keys of every ACF options field.
add_filter( 'generateblocks_dynamic_tags_allowed_options', function( $allowed_options ) {
$allowed_options[] = 'my_plugin_phone_number';
return $allowed_options;
} );
Related: generateblocks_dynamic_tags_allowed_options_for_current_user, generateblocks_allowed_option_keys_rest_api Guide: Dynamic Tags
generateblocks_dynamic_tags_allowed_options_for_current_user
GB Pro — since GenerateBlocks Pro 2.7.
The generateblocks_dynamic_tags_allowed_options_for_current_user filter changes the option keys that a user without full dynamic data access may put in newly saved content. Users who can author dynamic data get the full list from generateblocks_dynamic_tags_allowed_options and this filter isn’t used.
Parameters: $allowed (array of option names), $acf_keys (array, the ACF option keys removed from the default list for these users). Default: the allowed options without the ACF option keys.
add_filter( 'generateblocks_dynamic_tags_allowed_options_for_current_user', function( $allowed, $acf_keys ) {
$allowed[] = 'my_plugin_phone_number';
return $allowed;
}, 10, 2 );
Related: generateblocks_dynamic_tags_allowed_options Guide: Dynamic Tags
Editor (JavaScript)
These are wp.hooks filters. Add them with wp.hooks.addFilter() in a script that loads in the block editor.
generateblocks.editor.SelectMetaKeys.keys
GB Free — GenerateBlocks Pro also uses it.
The generateblocks.editor.SelectMetaKeys.keys filter changes the list of meta keys suggested in the meta key select of the dynamic tag modal.
Parameters: keys (array of { label, value }), meta (the meta object the keys come from), type (string: post, author, user or term). Default: every key of the meta object.
wp.hooks.addFilter(
'generateblocks.editor.SelectMetaKeys.keys',
'my-plugin/meta-keys',
( keys, meta, type ) => keys.filter( ( key ) => ! key.value.startsWith( 'my_private_' ) )
);
Related: generateblocks.editor.SelectMetaKeys.options Guide: Dynamic Tags
generateblocks.editor.SelectMetaKeys.options
GB Free — GenerateBlocks Pro also uses it.
The generateblocks.editor.SelectMetaKeys.options filter changes the grouped options of the meta key select, after the keys have been grouped as Post Meta, User Meta or Term Meta.
Parameters: options (array of groups, each { id, label, items }), context (object with user, post, term, type and source). Default: the group for the entity type, or the fallback the control was given for other types.
wp.hooks.addFilter(
'generateblocks.editor.SelectMetaKeys.options',
'my-plugin/meta-key-options',
( options, context ) => options
);
Related: generateblocks.editor.SelectMetaKeys.keys Guide: Dynamic Tags
Save gate rules
GB Free — since GenerateBlocks 2.4.
The save gate checks content as it is saved and rejects a save when it adds material that the user isn’t allowed to author. It covers REST saves from the block editor, autosaves, classic editor, XML-RPC and programmatic saves, and attachments. GenerateBlocks registers one rule, dynamic_data. You can register your own with GenerateBlocks_Save_Gate::get_instance()->register_rule( $rule ).
Register rules on plugins_loaded or later, after checking that GenerateBlocks_Save_Gate exists. Registering an ID that already exists replaces that rule. register_rule() returns false, and a _doing_it_wrong notice is raised, if the rule is malformed.
| Key | Description |
|---|---|
id | Required. A unique string. |
applies | Required. Callable ( $content, $context ) that returns whether the content contains material the rule restricts. $context has post_id and post_type. |
user_can | Required. Callable that returns whether the current user may author that material. |
message | Required. A string, or a callable that returns one, shown to the user when the save is blocked. |
error_code | Required. The WP_Error code returned when the save is blocked. |
enforced | Optional callable ( $context ) that switches enforcement on or off for the rule. |
exempt | Optional callable ( $content, $context ) for a finer exemption, checked after the shared exemption fails. |
A save is exempt when its content is identical to the stored content, unless the save also makes the post more exposed (for example publishing a draft), removes a password, changes the parent or changes the post type.
The gate is an authoring control, not a security boundary on its own, because a save can predate a rule or arrive with the gate switched off. Rules should also be checked when the content is output.
add_action( 'plugins_loaded', function() {
if ( ! class_exists( 'GenerateBlocks_Save_Gate' ) ) {
return;
}
GenerateBlocks_Save_Gate::get_instance()->register_rule( [
'id' => 'my_rule',
'applies' => function( $content, $context ) {
return false !== strpos( $content, '[my_restricted_shortcode' );
},
'user_can' => function() {
return current_user_can( 'manage_options' );
},
'message' => __( 'Only administrators can add this shortcode.', 'my-plugin' ),
'error_code' => 'my_rule_restricted',
] );
} );
Related: generateblocks_enforce_save_gate_rule, generateblocks_enforce_dynamic_data_save_gate Guide: Dynamic Tags