Make WordPress Core

Changeset 40192


Ignore:
Timestamp:
03/06/2017 01:44:57 PM (10 years ago)
Author:
aaroncampbell
Message:

Strip control characters before validating redirect.

Merges [40183] to 3.9 branch.

Location:
branches/3.9
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • branches/3.9

  • branches/3.9/src/wp-includes/pluggable.php

    r37764 r40192  
    11861186 **/
    11871187function wp_validate_redirect($location, $default = '') {
    1188         $location = trim( $location );
     1188        $location = trim( $location, " \t\n\r\0\x08\x0B" );
    11891189        // browsers will assume 'http' is your protocol, and will obey a redirect to a URL starting with '//'
    11901190        if ( substr($location, 0, 2) == '//' )
  • branches/3.9/tests/phpunit/tests/formatting/redirect.php

    r36452 r40192  
    5454                        array( 'http://user:@example.com/', 'http://user:@example.com/' ),
    5555                        array( 'http://user:pass@example.com/', 'http://user:pass@example.com/' ),
     56                        array( " \t\n\r\0\x08\x0Bhttp://example.com", 'http://example.com' ),
     57                        array( " \t\n\r\0\x08\x0B//example.com", 'http://example.com' ),
    5658                );
    5759        }
     
    6567                        // non-safelisted domain
    6668                        array( 'http://non-safelisted.example/' ),
     69
     70                        // non-safelisted domain (leading whitespace)
     71                        array( " \t\n\r\0\x08\x0Bhttp://non-safelisted.example.com" ),
     72                        array( " \t\n\r\0\x08\x0B//non-safelisted.example.com" ),
    6773
    6874                        // unsupported schemes
Note: See TracChangeset for help on using the changeset viewer.