Make WordPress Core

Ticket #38867: 38867.3.diff

File 38867.3.diff, 6.3 KB (added by westonruter, 10 years ago)

https://github.com/xwp/wordpress-develop/pull/203

  • src/wp-includes/class-wp-customize-manager.php

    diff --git src/wp-includes/class-wp-customize-manager.php src/wp-includes/class-wp-customize-manager.php
    index d047620..d6325ed 100644
    final class WP_Customize_Manager {  
    13531353
    13541354                wp_enqueue_script( 'customize-preview' );
    13551355                add_action( 'wp_head', array( $this, 'customize_preview_loading_style' ) );
     1356                add_action( 'wp_head', array( $this, 'remove_frameless_preview_messenger_channel' ) );
    13561357                add_action( 'wp_footer', array( $this, 'customize_preview_settings' ), 20 );
    13571358                add_filter( 'get_edit_post_link', '__return_empty_string' );
    13581359
    final class WP_Customize_Manager {  
    14881489        }
    14891490
    14901491        /**
     1492         * Remove customize_messenger_channel query parameter from the preview window when it is not in an iframe.
     1493         *
     1494         * This ensures that the admin bar will be shown. It also ensures that link navigation will
     1495         * work as expected since the parent frame is not being sent the URL to navigate to.
     1496         *
     1497         * @since 4.7.0
     1498         * @access public
     1499         */
     1500        public function remove_frameless_preview_messenger_channel( ){
     1501                if ( ! $this->messenger_channel ) {
     1502                        return;
     1503                }
     1504                ?>
     1505                <script>
     1506                ( function() {
     1507                        var urlParser, oldQueryParams, newQueryParams, i;
     1508                        if ( parent !== window ) {
     1509                                return;
     1510                        }
     1511                        urlParser = document.createElement( 'a' );
     1512                        urlParser.href = location.href;
     1513                        oldQueryParams = urlParser.search.substr( 1 ).split( /&/ );
     1514                        newQueryParams = [];
     1515                        for ( i = 0; i < oldQueryParams.length; i += 1 ) {
     1516                                if ( ! /^customize_messenger_channel=/.test( oldQueryParams[ i ] ) ) {
     1517                                        newQueryParams.push( oldQueryParams[ i ] );
     1518                                }
     1519                        }
     1520                        urlParser.search = newQueryParams.join( '&' );
     1521                        if ( urlParser.search !== location.search ) {
     1522                                location.replace( urlParser.href );
     1523                        }
     1524                } )();
     1525                </script>
     1526                <?php
     1527        }
     1528
     1529        /**
    14911530         * Print JavaScript settings for preview frame.
    14921531         *
    14931532         * @since 3.4.0
  • src/wp-includes/js/customize-preview.js

    diff --git src/wp-includes/js/customize-preview.js src/wp-includes/js/customize-preview.js
    index 9a3944f..7a37ba5 100644
     
    106106                        preview.add( 'scheme', urlParser.protocol.replace( /:$/, '' ) );
    107107
    108108                        preview.body = $( document.body );
    109 
    110                         preview.body.on( 'click.preview', 'a', function( event ) {
    111                                 preview.handleLinkClick( event );
    112                         } );
    113 
    114                         preview.body.on( 'submit.preview', 'form', function( event ) {
    115                                 preview.handleFormSubmit( event );
    116                         } );
    117 
    118109                        preview.window = $( window );
    119110
    120111                        if ( api.settings.channel ) {
     112
     113                                // If in an iframe, then intercept the link clicks and form submissions.
     114                                preview.body.on( 'click.preview', 'a', function( event ) {
     115                                        preview.handleLinkClick( event );
     116                                } );
     117                                preview.body.on( 'submit.preview', 'form', function( event ) {
     118                                        preview.handleFormSubmit( event );
     119                                } );
     120
    121121                                preview.window.on( 'scroll.preview', debounce( function() {
    122122                                        preview.send( 'scroll', preview.window.scrollTop() );
    123123                                }, 200 ) );
     
    158158                                return;
    159159                        }
    160160
    161                         // If not in an iframe, then allow the link click to proceed normally since the state query params are added.
    162                         if ( ! api.settings.channel ) {
    163                                 return;
    164                         }
    165 
    166161                        // Prevent initiating navigating from click and instead rely on sending url message to pane.
    167162                        event.preventDefault();
    168163
     
    199194                                return;
    200195                        }
    201196
    202                         // If not in an iframe, then allow the form submission to proceed normally with the state inputs injected.
    203                         if ( ! api.settings.channel ) {
    204                                 return;
    205                         }
    206 
    207197                        /*
    208198                         * If the default wasn't prevented already (in which case the form
    209199                         * submission is already being handled by JS), and if it has a GET
     
    348338                }
    349339
    350340                // Make sure links in preview use HTTPS if parent frame uses HTTPS.
    351                 if ( 'https' === api.preview.scheme.get() && 'http:' === element.protocol && -1 !== api.settings.url.allowedHosts.indexOf( element.host ) ) {
     341                if ( api.settings.channel && 'https' === api.preview.scheme.get() && 'http:' === element.protocol && -1 !== api.settings.url.allowedHosts.indexOf( element.host ) ) {
    352342                        element.protocol = 'https:';
    353343                }
    354344
    355345                if ( ! api.isLinkPreviewable( element ) ) {
    356                         $( element ).addClass( 'customize-unpreviewable' );
     346
     347                        // Style link as unpreviewable only if previewing in iframe; if previewing on frontend, links will be allowed to work normally.
     348                        if ( api.settings.channel ) {
     349                                $( element ).addClass( 'customize-unpreviewable' );
     350                        }
    357351                        return;
    358352                }
    359353                $( element ).removeClass( 'customize-unpreviewable' );
     
    496490                urlParser.href = form.action;
    497491
    498492                // Make sure forms in preview use HTTPS if parent frame uses HTTPS.
    499                 if ( 'https' === api.preview.scheme.get() && 'http:' === urlParser.protocol && -1 !== api.settings.url.allowedHosts.indexOf( urlParser.host ) ) {
     493                if ( api.settings.channel && 'https' === api.preview.scheme.get() && 'http:' === urlParser.protocol && -1 !== api.settings.url.allowedHosts.indexOf( urlParser.host ) ) {
    500494                        urlParser.protocol = 'https:';
    501495                        form.action = urlParser.href;
    502496                }
    503497
    504498                if ( 'GET' !== form.method.toUpperCase() || ! api.isLinkPreviewable( urlParser ) ) {
    505                         $( form ).addClass( 'customize-unpreviewable' );
     499
     500                        // Style form as unpreviewable only if previewing in iframe; if previewing on frontend, all forms will be allowed to work normally.
     501                        if ( api.settings.channel ) {
     502                                $( form ).addClass( 'customize-unpreviewable' );
     503                        }
    506504                        return;
    507505                }
    508506                $( form ).removeClass( 'customize-unpreviewable' );
  • tests/phpunit/tests/customize/manager.php

    diff --git tests/phpunit/tests/customize/manager.php tests/phpunit/tests/customize/manager.php
    index 54128f8..b138a35 100644
    class Tests_WP_Customize_Manager extends WP_UnitTestCase {  
    460460                $this->assertEquals( $did_action_customize_preview_init + 1, did_action( 'customize_preview_init' ) );
    461461
    462462                $this->assertEquals( 10, has_action( 'wp_head', 'wp_no_robots' ) );
     463                $this->assertEquals( 10, has_action( 'wp_head', array( $wp_customize, 'remove_frameless_preview_messenger_channel' ) ) );
    463464                $this->assertEquals( 10, has_filter( 'wp_headers', array( $wp_customize, 'filter_iframe_security_headers' ) ) );
    464465                $this->assertEquals( 10, has_filter( 'wp_redirect', array( $wp_customize, 'add_state_query_params' ) ) );
    465466                $this->assertTrue( wp_script_is( 'customize-preview', 'enqueued' ) );