Make WordPress Core


Ignore:
Timestamp:
10/17/2022 06:03:55 PM (4 years ago)
Author:
audrasjb
Message:

Grouped backports to the 5.3 branch.

  • Editor: Bump @wordpress packages for the branch,
  • Media: Refactor search by filename within the admin,
  • REST API: Lockdown post parameter of the terms endpoint,
  • Customize: Escape blogname option in underscores templates,
  • Query: Validate relation in WP_Date_Query,
  • Posts, Post types: Apply KSES to post-by-email content,
  • General: Validate host on "Are you sure?" screen,
  • Posts, Post types: Remove emails from post-by-email logs,
  • Pings/trackbacks: Apply KSES to all trackbacks,
  • Mail: Reset PHPMailer properties between use,
  • Comments: Apply kses when editing comments,
  • Widgets: Escape RSS error messages for display.

Merges [54521-54530] to the 5.3 branch.
Props audrasjb, costdev, cu121, dd32, davidbaumwald, ehtis, johnbillion, johnjamesjacoby, martinkrcho, matveb, oztaser, paulkevan, peterwilsoncc, ravipatel, SergeyBiryukov, talldanwp, timothyblynjacobs, tykoted, voldemortensen, vortfu, xknown.

Location:
branches/5.3
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • branches/5.3

  • branches/5.3/tests/phpunit/tests/query/search.php

    r43571 r54562  
    456456
    457457                add_post_meta( $attachment, '_wp_attached_file', 'some-image1.png', true );
    458                 add_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
     458                add_filter( 'wp_allow_query_attachment_by_filename', '__return_true' );
    459459
    460460                // Pass post_type a string value.
     
    486486
    487487                add_post_meta( $attachment, '_wp_attached_file', 'some-image2.png', true );
    488                 add_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
     488                add_filter( 'wp_allow_query_attachment_by_filename', '__return_true' );
    489489
    490490                // Pass post_type an array value.
     
    545545                add_post_meta( $attachment, '_wp_attached_file', 'some-image4.png', true );
    546546                add_post_meta( $attachment, '_test_meta_key', 'value', true );
    547                 add_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
     547                add_filter( 'wp_allow_query_attachment_by_filename', '__return_true' );
    548548
    549549                // Pass post_type a string value.
     
    585585
    586586                add_post_meta( $attachment, '_wp_attached_file', 'some-image5.png', true );
    587                 add_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
     587                add_filter( 'wp_allow_query_attachment_by_filename', '__return_true' );
    588588
    589589                // Pass post_type a string value.
     
    610610         * @ticket 22744
    611611         */
    612         public function test_filter_query_attachment_filenames_unhooks_itself() {
    613                 add_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
    614 
    615                 apply_filters(
    616                         'posts_clauses',
    617                         array(
    618                                 'where'    => '',
    619                                 'groupby'  => '',
    620                                 'join'     => '',
    621                                 'orderby'  => '',
    622                                 'distinct' => '',
    623                                 'fields'   => '',
    624                                 'limit'    => '',
    625                         )
    626                 );
    627 
    628                 $result = has_filter( 'posts_clauses', '_filter_query_attachment_filenames' );
    629 
    630                 $this->assertFalse( $result );
     612        public function test_wp_query_removes_filter_wp_allow_query_attachment_by_filename() {
     613                $attachment = self::factory()->post->create(
     614                        array(
     615                                'post_type'    => 'attachment',
     616                                'post_status'  => 'publish',
     617                                'post_title'   => 'bar foo',
     618                                'post_content' => 'foo bar',
     619                                'post_excerpt' => 'This post has foo',
     620                        )
     621                );
     622
     623                add_post_meta( $attachment, '_wp_attached_file', 'some-image1.png', true );
     624                add_filter( 'wp_allow_query_attachment_by_filename', '__return_true' );
     625
     626                $q = new WP_Query(
     627                        array(
     628                                's'           => 'image1',
     629                                'fields'      => 'ids',
     630                                'post_type'   => 'attachment',
     631                                'post_status' => 'inherit',
     632                        )
     633                );
     634
     635                $this->assertSame( array( $attachment ), $q->posts );
     636
     637                /*
     638                 * WP_Query should have removed the wp_allow_query_attachment_by_filename filter
     639                 * and thus not match the attachment created above
     640                 */
     641                $q->get_posts();
     642                $this->assertEmpty( $q->posts );
    631643        }
    632644
Note: See TracChangeset for help on using the changeset viewer.