Skip to content

fix(preview): keep the block preview working past a few hundred images - #345

Merged
nk-o merged 2 commits into
masterfrom
claude/visual-portfolio-preview-bug-ef480d
Sep 25, 2026
Merged

nk-o merged 2 commits into
masterfrom
claude/visual-portfolio-preview-bug-ef480d

Conversation

@nk-o

@nk-o nk-o commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

The block editor posted every attribute value as its own form field, and a Media source gallery sends three to five fields per image. At a few hundred images this passes PHP's max_input_vars (1000 by default). PHP then drops everything after images, so the preview renders with default settings. A host that caps the field count, usually through a WAF, rejects the request outright and serves its own error page. That page has no Document-Isolation-Policy, so on the first setting change the editor's read of frameWindow.vp_preview_post_data threw a SecurityError and crashed the block with "This block has encountered an error".

The attributes now go as one JSON field, which print_template() unpacks into the fields it used to get, so the preview POST carries 7 fields at any gallery size. The crashing read is gone. It wrote data.value under data.name, and neither exists on that payload, so it only ever set an undefined key.

211 images, 5 fields each Before After
Preview POST fields 1211 7
Attributes the preview received 19 of 156 all
Preview request rejected, then a setting changed block crashes block stays, frame shows the host's page

Not reproduced here: the reporter's host rejects the request, and wp-env only truncates it. The rejection was modelled by answering the preview POST with a 403, which gives the exact console error from the report. Whether one large JSON field also passes that host's WAF is unproven.

Below the limit nothing changes. For 140 images, vp_preview_post_data and the .vp-portfolio attributes match before and after, apart from the nonce, the post id and the timestamp. Saved layouts and the Elementor preview still post flat fields, and print_template() reads those as before.

gallery-preview-many-images.spec.js fails on the first commit (3 items expected, 6 rendered, and the block crashes) and passes with the fix. Full e2e run: 210 passed.

Reported in https://wordpress.org/support/topic/visual-portfolio-block-preview-breaks-with-211-media-items/

Fails before the fix: the settings after `images` are dropped past
max_input_vars, and a rejected preview request crashes the block.
A field per value ran past max_input_vars on a gallery of a few
hundred images, and PHP dropped every setting after `images`.
Hosts that cap the field count rejected the request outright, and
the error page they served broke the editor's next read of the
preview frame's window, crashing the block. That read only ever
wrote an `undefined` key, so it goes.
@nk-o
nk-o merged commit 604e48d into master Sep 25, 2026
7 checks passed
@nk-o
nk-o deleted the claude/visual-portfolio-preview-bug-ef480d branch September 25, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant