Changeset 63099
- Timestamp:
- 08/06/2026 07:37:16 PM (5 weeks ago)
- Location:
- branches/6.1
- Files:
-
- 11 edited
-
package-lock.json (modified) (1 diff)
-
package.json (modified) (1 diff)
-
src/js/_enqueues/admin/inline-edit-post.js (modified) (1 diff)
-
src/wp-admin/includes/user.php (modified) (3 diffs)
-
src/wp-includes/blocks/post-date.php (modified) (1 diff)
-
src/wp-includes/canonical.php (modified) (2 diffs)
-
src/wp-includes/http.php (modified) (1 diff)
-
src/wp-includes/kses.php (modified) (1 diff)
-
src/wp-includes/user.php (modified) (9 diffs)
-
src/wp-login.php (modified) (2 diffs)
-
src/wp-signup.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/6.1/package-lock.json
r61960 r63099 4313 4313 }, 4314 4314 "@wordpress/block-library": { 4315 "version": "7.14.1 5",4316 "resolved": "https://registry.npmjs.org/@wordpress/block-library/-/block-library-7.14.1 5.tgz",4317 "integrity": "sha512- YXPXX3ZwZP5i6/iLZMEjEgAhEsEbc92cWGO/VPmmk1/YEjdAyp2gvOHcstJVAnq8Qz1pcRnctKyKiC5I/uHS+g==",4315 "version": "7.14.16", 4316 "resolved": "https://registry.npmjs.org/@wordpress/block-library/-/block-library-7.14.16.tgz", 4317 "integrity": "sha512-gi01kh+LEPC4hfKYwdlyWk4gvm9OiuvhfaJbufp1VTXs2dQEjS9XLUb44muQnTIw5eOiFxT2b4H5u39WThpnxQ==", 4318 4318 "requires": { 4319 4319 "@babel/runtime": "^7.16.0", -
branches/6.1/package.json
r61960 r63099 84 84 "@wordpress/block-directory": "3.15.15", 85 85 "@wordpress/block-editor": "10.0.10", 86 "@wordpress/block-library": "7.14.1 5",86 "@wordpress/block-library": "7.14.16", 87 87 "@wordpress/block-serialization-default-parser": "4.17.1", 88 88 "@wordpress/blocks": "11.16.4", -
branches/6.1/src/js/_enqueues/admin/inline-edit-post.js
r53352 r63099 306 306 307 307 // The post author no longer has edit capabilities, so we need to add them to the list of authors. 308 $(':input[name="post_author"]', editRow).prepend('<option value="' + $('.post_author', rowData).text() + '">' + $('#' + t.type + '-' + id + ' .author').text() + '</option>'); 308 $(':input[name="post_author"]', editRow).prepend( 309 new Option( 310 $('#' + t.type + '-' + id + ' .author').text(), 311 $('.post_author', rowData).text() 312 ) 313 ); 309 314 } 310 315 if ( $( ':input[name="post_author"] option', editRow ).length === 1 ) { -
branches/6.1/src/wp-admin/includes/user.php
r56867 r63099 45 45 } 46 46 47 $errors = new WP_Error(); 48 47 49 $pass1 = ''; 48 50 $pass2 = ''; … … 79 81 80 82 if ( isset( $_POST['email'] ) ) { 81 $user->user_email = sanitize_text_field( wp_unslash( $_POST['email'] ) ); 83 $maybe_email = wp_unslash( $_POST['email'] ); 84 if ( is_string( $maybe_email ) && is_email( $maybe_email ) ) { 85 $user->user_email = $maybe_email; 86 } else { 87 $errors->add( 'invalid_email', __( '<strong>Error:</strong> The email address is not correct.' ), array( 'form-field' => 'email' ) ); 88 } 82 89 } 83 90 if ( isset( $_POST['url'] ) ) { … … 139 146 $user->use_ssl = 1; 140 147 } 141 142 $errors = new WP_Error();143 148 144 149 /* checking that username has been typed */ -
branches/6.1/src/wp-includes/blocks/post-date.php
r54257 r63099 32 32 33 33 if ( isset( $attributes['isLink'] ) && $attributes['isLink'] ) { 34 $formatted_date = sprintf( '<a href="%1s">%2s</a>', get_the_permalink( $post_ID ), $formatted_date ); 34 $formatted_date = sprintf( '<a href="%1$s">%2$s</a>', esc_url( get_the_permalink( $post_ID ) ), esc_html( $formatted_date ) ); 35 } else { 36 $formatted_date = esc_html( $formatted_date ); 35 37 } 36 38 -
branches/6.1/src/wp-includes/canonical.php
r54793 r63099 921 921 922 922 if ( get_query_var( 'name' ) ) { 923 $publicly_viewable_post_types = array_filter( get_post_types( array( 'exclude_from_search' => false ) ), 'is_post_type_viewable' ); 924 923 925 /** 924 926 * Filters whether to perform a strict guess for a 404 redirect. … … 941 943 if ( get_query_var( 'post_type' ) ) { 942 944 if ( is_array( get_query_var( 'post_type' ) ) ) { 943 // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare 944 $where .= " AND post_type IN ('" . join( "', '", esc_sql( get_query_var( 'post_type' ) ) ) . "')"; 945 $post_types = array_intersect( get_query_var( 'post_type' ), $publicly_viewable_post_types ); 946 if ( empty( $post_types ) ) { 947 return false; 948 } 949 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $post_types ) ) . "')"; 945 950 } else { 951 if ( ! in_array( get_query_var( 'post_type' ), $publicly_viewable_post_types, true ) ) { 952 return false; 953 } 946 954 $where .= $wpdb->prepare( ' AND post_type = %s', get_query_var( 'post_type' ) ); 947 955 } 948 956 } else { 949 $where .= " AND post_type IN ('" . implode( "', '", get_post_types( array( 'public' => true )) ) . "')";957 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $publicly_viewable_post_types ) ) . "')"; 950 958 } 951 959 -
branches/6.1/src/wp-includes/http.php
r54157 r63099 558 558 if ( $ip ) { 559 559 $parts = array_map( 'intval', explode( '.', $ip ) ); 560 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] 561 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) 562 || ( 192 === $parts[0] && 168 === $parts[1] ) 560 561 /* 562 * These IP address ranges are not considered valid external hosts for HTTP requests. 563 * 564 * If the host resolves to an IP address in these ranges, the request will be rejected unless the 'http_request_host_is_external' filter allows it. 565 * 566 * References: 567 * 568 * - IPv4 Special-Purpose Address Space: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml 569 * - IPv4 Multicast Address Assignments: https://www.rfc-editor.org/rfc/rfc5771.html 570 */ 571 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] // 127.0.0.0/8 (loopback), 10.0.0.0/8 (private), 0.0.0.0/8 (this network). 572 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) // 172.16.0.0/12 (private). 573 || ( 192 === $parts[0] && 168 === $parts[1] ) // 192.168.0.0/16 (private). 574 || ( 192 === $parts[0] && 0 === $parts[1] && 0 === $parts[2] ) // 192.0.0.0/24 (IETF protocol assignments). 575 || ( 192 === $parts[0] && 0 === $parts[1] && 2 === $parts[2] ) // 192.0.2.0/24 (TEST-NET-1). 576 || ( 192 === $parts[0] && 88 === $parts[1] && 99 === $parts[2] ) // 192.88.99.0/24 (6to4 relay anycast). 577 || ( 198 === $parts[0] && 51 === $parts[1] && 100 === $parts[2] ) // 198.51.100.0/24 (TEST-NET-2). 578 || ( 203 === $parts[0] && 0 === $parts[1] && 113 === $parts[2] ) // 203.0.113.0/24 (TEST-NET-3). 579 || ( 169 === $parts[0] && 254 === $parts[1] ) // 169.254.0.0/16 (link-local and cloud metadata). 580 || ( 100 === $parts[0] && 64 <= $parts[1] && 127 >= $parts[1] ) // 100.64.0.0/10 (CGNAT). 581 || ( 198 === $parts[0] && 18 <= $parts[1] && 19 >= $parts[1] ) // 198.18.0.0/15 (benchmarking). 582 || ( 224 <= $parts[0] && 239 >= $parts[0] ) // 224.0.0.0/4 (multicast). 583 || 240 <= $parts[0] // 240.0.0.0/4 (reserved, includes 255.255.255.255 broadcast). 563 584 ) { 564 585 // If host appears local, reject unless specifically allowed. -
branches/6.1/src/wp-includes/kses.php
r61950 r63099 2513 2513 ); 2514 2514 2515 // Bail if the recursive function stripping hit a PCRE error (e.g. stack/backtrack limit). 2516 if ( null === $css_test_string ) { 2517 continue; 2518 } 2519 2515 2520 /* 2516 2521 * Disallow CSS containing \ ( & } = or comments, except for within url(), var(), calc(), etc. 2517 2522 * which were removed from the test string above. 2518 2523 */ 2519 $allow_css = !preg_match( '%[\\\(&=}]|/\*%', $css_test_string );2524 $allow_css = 0 === preg_match( '%[\\\(&=}]|/\*%', $css_test_string ); 2520 2525 2521 2526 /** -
branches/6.1/src/wp-includes/user.php
r54477 r63099 153 153 /* translators: %s: User name. */ 154 154 __( '<strong>Error:</strong> The username <strong>%s</strong> is not registered on this site. If you are unsure of your username, try your email address instead.' ), 155 $username155 esc_html( $username ) 156 156 ) 157 157 ); … … 178 178 /* translators: %s: User name. */ 179 179 __( '<strong>Error:</strong> The password you entered for the username %s is incorrect.' ), 180 '<strong>' . $username. '</strong>'180 '<strong>' . esc_html( $username ) . '</strong>' 181 181 ) . 182 182 ' <a href="' . wp_lostpassword_url() . '">' . … … 250 250 /* translators: %s: Email address. */ 251 251 __( '<strong>Error:</strong> The password you entered for the email address %s is incorrect.' ), 252 '<strong>' . $email. '</strong>'252 '<strong>' . esc_html( $email ) . '</strong>' 253 253 ) . 254 254 ' <a href="' . wp_lostpassword_url() . '">' . … … 3347 3347 /* translators: %s: Link to the login page. */ 3348 3348 __( '<strong>Error:</strong> This email address is already registered. <a href="%s">Log in</a> with this address or choose another one.' ), 3349 wp_login_url()3349 esc_url( wp_login_url() ) 3350 3350 ) 3351 3351 ); … … 3395 3395 /* translators: %s: Admin email address. */ 3396 3396 __( '<strong>Error:</strong> Could not register you… please contact the <a href="mailto:%s">site admin</a>!' ), 3397 get_option( 'admin_email')3397 esc_attr( get_option( 'admin_email' ) ) 3398 3398 ) 3399 3399 ); … … 3618 3618 * @since 3.0.0 3619 3619 * @since 4.9.0 This function was moved from wp-admin/includes/ms.php so it's no longer Multisite specific. 3620 * @since 7.0.3 Added the `$user_id` parameter, which is sent with the `personal_options_update` action. 3621 * 3622 * @param int $user_id Optional. The ID of the user whose email is being changed. Defaults to `$_POST['user_id']` if set, otherwise 0. 3620 3623 * 3621 3624 * @global WP_Error $errors WP_Error object. 3622 3625 */ 3623 function send_confirmation_on_profile_email( ) {3626 function send_confirmation_on_profile_email( $user_id = 0 ) { 3624 3627 global $errors; 3628 3629 // Maintain backward compatibility for those relying on a check based on $_POST['user_id']. 3630 if ( ! $user_id && isset( $_POST['user_id'] ) ) { 3631 $user_id = (int) $_POST['user_id']; 3632 } 3625 3633 3626 3634 $current_user = wp_get_current_user(); … … 3629 3637 } 3630 3638 3631 if ( $current_user->ID != $_POST['user_id']) {3639 if ( 0 === $current_user->ID || $current_user->ID !== (int) $user_id ) { 3632 3640 return false; 3633 3641 } … … 3643 3651 ); 3644 3652 3653 $_POST['email'] = addslashes( $current_user->user_email ); 3645 3654 return; 3646 3655 } … … 3656 3665 delete_user_meta( $current_user->ID, '_new_email' ); 3657 3666 3667 $_POST['email'] = addslashes( $current_user->user_email ); 3658 3668 return; 3659 3669 } -
branches/6.1/src/wp-login.php
r54224 r63099 1130 1130 /* translators: %s: Link to the login page. */ 1131 1131 __( 'Check your email for the confirmation link, then visit the <a href="%s">login page</a>.' ), 1132 wp_login_url()1132 esc_url( wp_login_url() ) 1133 1133 ), 1134 1134 'message' … … 1140 1140 /* translators: %s: Link to the login page. */ 1141 1141 __( 'Registration complete. Please check your email, then visit the <a href="%s">login page</a>.' ), 1142 wp_login_url()1142 esc_url( wp_login_url() ) 1143 1143 ), 1144 1144 'message' -
branches/6.1/src/wp-signup.php
r54192 r63099 990 990 break; 991 991 case 'gimmeanotherblog': 992 validate_another_blog_signup(); 992 if ( 'all' === $active_signup || 'blog' === $active_signup ) { 993 validate_another_blog_signup(); 994 } else { 995 _e( 'Site registration has been disabled.' ); 996 } 993 997 break; 994 998 case 'default':
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)