Changeset 53455 for trunk/src/wp-includes/rest-api.php
- Timestamp:
- 06/01/2022 06:12:25 PM (3 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/src/wp-includes/rest-api.php
r53441 r53455 711 711 // Requests from file:// and data: URLs send "Origin: null". 712 712 if ( 'null' !== $origin ) { 713 $origin = esc_url_raw( $origin );713 $origin = sanitize_url( $origin ); 714 714 } 715 715 header( 'Access-Control-Allow-Origin: ' . $origin ); … … 994 994 } 995 995 996 header( sprintf( 'Link: <%s>; rel="https://api.w.org/"', esc_url_raw( $api_root ) ), false );996 header( sprintf( 'Link: <%s>; rel="https://api.w.org/"', sanitize_url( $api_root ) ), false ); 997 997 998 998 $resource = rest_get_queried_resource_route(); 999 999 1000 1000 if ( $resource ) { 1001 header( sprintf( 'Link: <%s>; rel="alternate"; type="application/json"', esc_url_raw( rest_url( $resource ) ) ), false );1001 header( sprintf( 'Link: <%s>; rel="alternate"; type="application/json"', sanitize_url( rest_url( $resource ) ) ), false ); 1002 1002 } 1003 1003 } … … 2796 2796 2797 2797 case 'uri': 2798 return esc_url_raw( $value );2798 return sanitize_url( $value ); 2799 2799 2800 2800 case 'ip':
Note: See TracChangeset
for help on using the changeset viewer.