WordPress.org

Make WordPress Core

Changeset 37527


Ignore:
Timestamp:
05/23/2016 09:32:47 AM (3 years ago)
Author:
ocean90
Message:

Customize: Make sure that preview and return URLs are URLs.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-includes/class-wp-customize-manager.php

    r37520 r37527  
    16321632     */
    16331633    public function set_preview_url( $preview_url ) {
     1634        $preview_url = esc_url_raw( $preview_url );
    16341635        $this->preview_url = wp_validate_redirect( $preview_url, home_url( '/' ) );
    16351636    }
     
    16631664     */
    16641665    public function set_return_url( $return_url ) {
     1666        $return_url = esc_url_raw( $return_url );
    16651667        $return_url = remove_query_arg( wp_removable_query_args(), $return_url );
    16661668        $return_url = wp_validate_redirect( $return_url );
Note: See TracChangeset for help on using the changeset viewer.