Changeset 63103
- Timestamp:
- 08/06/2026 07:44:27 PM (5 weeks ago)
- Location:
- branches/5.9
- Files:
-
- 11 edited
-
src/js/_enqueues/admin/inline-edit-post.js (modified) (1 diff)
-
src/wp-admin/includes/user.php (modified) (3 diffs)
-
src/wp-includes/canonical.php (modified) (2 diffs)
-
src/wp-includes/http.php (modified) (1 diff)
-
src/wp-includes/kses.php (modified) (1 diff)
-
src/wp-includes/user.php (modified) (9 diffs)
-
src/wp-login.php (modified) (2 diffs)
-
src/wp-signup.php (modified) (1 diff)
-
tests/phpunit/tests/auth.php (modified) (1 diff)
-
tests/phpunit/tests/canonical.php (modified) (2 diffs)
-
tests/phpunit/tests/kses.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/5.9/src/js/_enqueues/admin/inline-edit-post.js
r50547 r63103 278 278 279 279 // The post author no longer has edit capabilities, so we need to add them to the list of authors. 280 $(':input[name="post_author"]', editRow).prepend('<option value="' + $('.post_author', rowData).text() + '">' + $('#' + t.type + '-' + id + ' .author').text() + '</option>'); 280 $(':input[name="post_author"]', editRow).prepend( 281 new Option( 282 $('#' + t.type + '-' + id + ' .author').text(), 283 $('.post_author', rowData).text() 284 ) 285 ); 281 286 } 282 287 if ( $( ':input[name="post_author"] option', editRow ).length === 1 ) { -
branches/5.9/src/wp-admin/includes/user.php
r56875 r63103 45 45 } 46 46 47 $errors = new WP_Error(); 48 47 49 $pass1 = ''; 48 50 $pass2 = ''; … … 79 81 80 82 if ( isset( $_POST['email'] ) ) { 81 $user->user_email = sanitize_text_field( wp_unslash( $_POST['email'] ) ); 83 $maybe_email = wp_unslash( $_POST['email'] ); 84 if ( is_string( $maybe_email ) && is_email( $maybe_email ) ) { 85 $user->user_email = $maybe_email; 86 } else { 87 $errors->add( 'invalid_email', __( '<strong>Error</strong>: The email address isn’t correct.' ), array( 'form-field' => 'email' ) ); 88 } 82 89 } 83 90 if ( isset( $_POST['url'] ) ) { … … 139 146 $user->use_ssl = 1; 140 147 } 141 142 $errors = new WP_Error();143 148 144 149 /* checking that username has been typed */ -
branches/5.9/src/wp-includes/canonical.php
r51125 r63103 913 913 914 914 if ( get_query_var( 'name' ) ) { 915 $publicly_viewable_post_types = array_filter( get_post_types( array( 'exclude_from_search' => false ) ), 'is_post_type_viewable' ); 916 915 917 /** 916 918 * Filters whether to perform a strict guess for a 404 redirect. … … 933 935 if ( get_query_var( 'post_type' ) ) { 934 936 if ( is_array( get_query_var( 'post_type' ) ) ) { 935 // phpcs:ignore WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare 936 $where .= " AND post_type IN ('" . join( "', '", esc_sql( get_query_var( 'post_type' ) ) ) . "')"; 937 $post_types = array_intersect( get_query_var( 'post_type' ), $publicly_viewable_post_types ); 938 if ( empty( $post_types ) ) { 939 return false; 940 } 941 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $post_types ) ) . "')"; 937 942 } else { 943 if ( ! in_array( get_query_var( 'post_type' ), $publicly_viewable_post_types, true ) ) { 944 return false; 945 } 938 946 $where .= $wpdb->prepare( ' AND post_type = %s', get_query_var( 'post_type' ) ); 939 947 } 940 948 } else { 941 $where .= " AND post_type IN ('" . implode( "', '", get_post_types( array( 'public' => true )) ) . "')";949 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $publicly_viewable_post_types ) ) . "')"; 942 950 } 943 951 -
branches/5.9/src/wp-includes/http.php
r52441 r63103 554 554 if ( $ip ) { 555 555 $parts = array_map( 'intval', explode( '.', $ip ) ); 556 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] 557 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) 558 || ( 192 === $parts[0] && 168 === $parts[1] ) 556 557 /* 558 * These IP address ranges are not considered valid external hosts for HTTP requests. 559 * 560 * If the host resolves to an IP address in these ranges, the request will be rejected unless the 'http_request_host_is_external' filter allows it. 561 * 562 * References: 563 * 564 * - IPv4 Special-Purpose Address Space: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml 565 * - IPv4 Multicast Address Assignments: https://www.rfc-editor.org/rfc/rfc5771.html 566 */ 567 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] // 127.0.0.0/8 (loopback), 10.0.0.0/8 (private), 0.0.0.0/8 (this network). 568 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) // 172.16.0.0/12 (private). 569 || ( 192 === $parts[0] && 168 === $parts[1] ) // 192.168.0.0/16 (private). 570 || ( 192 === $parts[0] && 0 === $parts[1] && 0 === $parts[2] ) // 192.0.0.0/24 (IETF protocol assignments). 571 || ( 192 === $parts[0] && 0 === $parts[1] && 2 === $parts[2] ) // 192.0.2.0/24 (TEST-NET-1). 572 || ( 192 === $parts[0] && 88 === $parts[1] && 99 === $parts[2] ) // 192.88.99.0/24 (6to4 relay anycast). 573 || ( 198 === $parts[0] && 51 === $parts[1] && 100 === $parts[2] ) // 198.51.100.0/24 (TEST-NET-2). 574 || ( 203 === $parts[0] && 0 === $parts[1] && 113 === $parts[2] ) // 203.0.113.0/24 (TEST-NET-3). 575 || ( 169 === $parts[0] && 254 === $parts[1] ) // 169.254.0.0/16 (link-local and cloud metadata). 576 || ( 100 === $parts[0] && 64 <= $parts[1] && 127 >= $parts[1] ) // 100.64.0.0/10 (CGNAT). 577 || ( 198 === $parts[0] && 18 <= $parts[1] && 19 >= $parts[1] ) // 198.18.0.0/15 (benchmarking). 578 || ( 224 <= $parts[0] && 239 >= $parts[0] ) // 224.0.0.0/4 (multicast). 579 || 240 <= $parts[0] // 240.0.0.0/4 (reserved, includes 255.255.255.255 broadcast). 559 580 ) { 560 581 // If host appears local, reject unless specifically allowed. -
branches/5.9/src/wp-includes/kses.php
r61951 r63103 2515 2515 // Allow CSS calc(). 2516 2516 $css_test_string = preg_replace( '/calc\(((?:\([^()]*\)?|[^()])*)\)/', '', $css_test_string ); 2517 if ( null === $css_test_string ) { 2518 continue; 2519 } 2520 2517 2521 // Allow CSS var(). 2518 2522 $css_test_string = preg_replace( '/\(?var\(--[a-zA-Z0-9_-]*\)/', '', $css_test_string ); 2523 if ( null === $css_test_string ) { 2524 continue; 2525 } 2519 2526 2520 2527 // Check for any CSS containing \ ( & } = or comments, 2521 2528 // except for url(), calc(), or var() usage checked above. 2522 $allow_css = !preg_match( '%[\\\(&=}]|/\*%', $css_test_string );2529 $allow_css = 0 === preg_match( '%[\\\(&=}]|/\*%', $css_test_string ); 2523 2530 2524 2531 /** -
branches/5.9/src/wp-includes/user.php
r54545 r63103 153 153 /* translators: %s: User name. */ 154 154 __( '<strong>Error</strong>: The username <strong>%s</strong> is not registered on this site. If you are unsure of your username, try your email address instead.' ), 155 $username155 esc_html( $username ) 156 156 ) 157 157 ); … … 178 178 /* translators: %s: User name. */ 179 179 __( '<strong>Error</strong>: The password you entered for the username %s is incorrect.' ), 180 '<strong>' . $username. '</strong>'180 '<strong>' . esc_html( $username ) . '</strong>' 181 181 ) . 182 182 ' <a href="' . wp_lostpassword_url() . '">' . … … 250 250 /* translators: %s: Email address. */ 251 251 __( '<strong>Error</strong>: The password you entered for the email address %s is incorrect.' ), 252 '<strong>' . $email. '</strong>'252 '<strong>' . esc_html( $email ) . '</strong>' 253 253 ) . 254 254 ' <a href="' . wp_lostpassword_url() . '">' . … … 3104 3104 /* translators: %s: Link to the login page. */ 3105 3105 __( '<strong>Error:</strong> This email address is already registered. <a href="%s">Log in</a> with this address or choose another one.' ), 3106 wp_login_url()3106 esc_url( wp_login_url() ) 3107 3107 ) 3108 3108 ); … … 3152 3152 /* translators: %s: Admin email address. */ 3153 3153 __( '<strong>Error</strong>: Couldn’t register you… please contact the <a href="mailto:%s">site admin</a>!' ), 3154 get_option( 'admin_email')3154 esc_attr( get_option( 'admin_email' ) ) 3155 3155 ) 3156 3156 ); … … 3375 3375 * @since 3.0.0 3376 3376 * @since 4.9.0 This function was moved from wp-admin/includes/ms.php so it's no longer Multisite specific. 3377 * @since 7.0.3 Added the `$user_id` parameter, which is sent with the `personal_options_update` action. 3378 * 3379 * @param int $user_id Optional. The ID of the user whose email is being changed. Defaults to `$_POST['user_id']` if set, otherwise 0. 3377 3380 * 3378 3381 * @global WP_Error $errors WP_Error object. 3379 3382 */ 3380 function send_confirmation_on_profile_email( ) {3383 function send_confirmation_on_profile_email( $user_id = 0 ) { 3381 3384 global $errors; 3385 3386 // Maintain backward compatibility for those relying on a check based on $_POST['user_id']. 3387 if ( ! $user_id && isset( $_POST['user_id'] ) ) { 3388 $user_id = (int) $_POST['user_id']; 3389 } 3382 3390 3383 3391 $current_user = wp_get_current_user(); … … 3386 3394 } 3387 3395 3388 if ( $current_user->ID != $_POST['user_id']) {3396 if ( 0 === $current_user->ID || $current_user->ID !== (int) $user_id ) { 3389 3397 return false; 3390 3398 } … … 3400 3408 ); 3401 3409 3410 $_POST['email'] = addslashes( $current_user->user_email ); 3402 3411 return; 3403 3412 } … … 3413 3422 delete_user_meta( $current_user->ID, '_new_email' ); 3414 3423 3424 $_POST['email'] = addslashes( $current_user->user_email ); 3415 3425 return; 3416 3426 } -
branches/5.9/src/wp-login.php
r52435 r63103 1110 1110 /* translators: %s: Link to the login page. */ 1111 1111 __( 'Check your email for the confirmation link, then visit the <a href="%s">login page</a>.' ), 1112 wp_login_url()1112 esc_url( wp_login_url() ) 1113 1113 ), 1114 1114 'message' … … 1120 1120 /* translators: %s: Link to the login page. */ 1121 1121 __( 'Registration complete. Please check your email, then visit the <a href="%s">login page</a>.' ), 1122 wp_login_url()1122 esc_url( wp_login_url() ) 1123 1123 ), 1124 1124 'message' -
branches/5.9/src/wp-signup.php
r51930 r63103 965 965 break; 966 966 case 'gimmeanotherblog': 967 validate_another_blog_signup(); 967 if ( 'all' === $active_signup || 'blog' === $active_signup ) { 968 validate_another_blog_signup(); 969 } else { 970 _e( 'Site registration has been disabled.' ); 971 } 968 972 break; 969 973 case 'default': -
branches/5.9/tests/phpunit/tests/auth.php
r52157 r63103 395 395 $check = check_password_reset_key( '', $this->user->user_login ); 396 396 $this->assertInstanceOf( 'WP_Error', $check ); 397 } 398 399 /** 400 * @dataProvider data_wp_authenticate_username_password_with_invalid_login_messages 401 * 402 * @ticket security-1307 403 * 404 * @param string $username Username to attempt to authenticate with. 405 * @param string $expected_message Expected error message. 406 */ 407 public function test_wp_authenticate_username_password_with_invalid_login_messages( $username, $expected_message ) { 408 $result = wp_authenticate_username_password( null, $username, 'password' ); 409 $this->assertInstanceOf( 'WP_Error', $result ); 410 $this->assertSame( $expected_message, $result->get_error_message() ); 411 } 412 413 public function data_wp_authenticate_username_password_with_invalid_login_messages() { 414 return array( 415 'invalid_username' => array( 416 'invalid_username', 417 '<strong>Error</strong>: The username <strong>invalid_username</strong> is not registered on this site. If you are unsure of your username, try your email address instead.', 418 ), 419 'xxs_username' => array( 420 '<script>alert(1);</script>', 421 '<strong>Error</strong>: The username <strong><script>alert(1);</script></strong> is not registered on this site. If you are unsure of your username, try your email address instead.', 422 ), 423 ); 397 424 } 398 425 -
branches/5.9/tests/phpunit/tests/canonical.php
r52010 r63103 11 11 class Tests_Canonical extends WP_Canonical_UnitTestCase { 12 12 13 public static function wpSetUpBeforeClass( WP_UnitTest_Factory $factory ) { 14 // Set up fixtures in WP_Canonical_UnitTestCase. 15 parent::wpSetUpBeforeClass( $factory ); 16 17 self::set_up_custom_post_types(); 18 19 $factory->post->create( 20 array( 21 'post_type' => 'wp_tests_excluded', 22 'post_title' => 'private-cpt-post', 23 ) 24 ); 25 } 26 13 27 public function set_up() { 14 28 parent::set_up(); 15 29 wp_set_current_user( self::$author_id ); 30 } 31 32 /** 33 * Register custom post types for tests. 34 * 35 * Register non publicly queryable post type with public set to true. 36 * 37 * These arguments are intentionally contradictory for the test associated 38 * with ticket #59795. 39 */ 40 public static function set_up_custom_post_types() { 41 register_post_type( 42 'wp_tests_excluded', 43 array( 44 'publicly_queryable' => true, 45 'exclude_from_search' => true, 46 ) 47 ); 16 48 } 17 49 … … 277 309 278 310 /** 279 * Ensure multiple post types do not throw a notice.311 * Ensure redirect guessing searches only requested, public, searchable post types. 280 312 * 281 313 * @ticket 43056 282 */ 283 public function test_redirect_guess_404_permalink_post_types() { 284 /* 285 * Sample-page is intentionally missspelt as sample-pag to ensure 286 * the 404 post permalink guessing runs. 287 * 288 * Please do not correct the apparent typo. 289 */ 290 291 // String format post type. 292 $this->assertCanonical( '/?name=sample-pag&post_type=page', '/sample-page/' ); 293 // Array formatted post type or types. 294 $this->assertCanonical( '/?name=sample-pag&post_type[]=page', '/sample-page/' ); 295 $this->assertCanonical( '/?name=sample-pag&post_type[]=page&post_type[]=post', '/sample-page/' ); 314 * @ticket 59795 315 * @ticket security-1301 316 * 317 * @dataProvider data_redirect_guess_404_permalink_post_types 318 */ 319 public function test_redirect_guess_404_permalink_post_types( $original_url, $expected ) { 320 $this->assertCanonical( $original_url, $expected ); 321 } 322 323 /** 324 * Data provider for test_redirect_guess_404_permalink_post_types(). 325 * 326 * In the original URLs the post names are intentionally misspelled 327 * to test the redirection. 328 * 329 * Please do not correct the apparent typos. 330 * 331 * @return array[] 332 */ 333 public function data_redirect_guess_404_permalink_post_types() { 334 return array( 335 'single string formatted post type' => array( 336 'original_url' => '/?name=sample-pag&post_type=page', 337 'expected' => '/sample-page/', 338 ), 339 'single array formatted post type' => array( 340 'original_url' => '/?name=sample-pag&post_type[]=page', 341 'expected' => '/sample-page/', 342 ), 343 'do not search unrequested post types' => array( 344 'original_url' => '/?name=sample-pag&post_type[]=post', 345 'expected' => '/?name=sample-pag&post_type[]=post', 346 ), 347 'multiple array formatted post type' => array( 348 'original_url' => '/?name=sample-pag&post_type[]=page&post_type[]=post', 349 'expected' => '/sample-page/', 350 ), 351 'do not redirect to private post type' => array( 352 'original_url' => '/?name=private-cpt-po&post_type[]=wp_tests_private', 353 'expected' => '/?name=private-cpt-po&post_type[]=wp_tests_private', 354 ), 355 'mixed public and excluded post types' => array( 356 'original_url' => '/?name=excluded-cpt-po&post_type[]=post&post_type[]=wp_tests_excluded', 357 'expected' => '/?name=excluded-cpt-po&post_type[]=post&post_type[]=wp_tests_excluded', 358 ), 359 'mixed post types with public match' => array( 360 'original_url' => '/?name=sample-pag&post_type[]=page&post_type[]=wp_tests_excluded', 361 'expected' => '/sample-page/', 362 ), 363 ); 296 364 } 297 365 -
branches/5.9/tests/phpunit/tests/kses.php
r54764 r63103 934 934 935 935 /** 936 * Tests that CSS is rejected when recursive function stripping triggers a PCRE error. 937 * 938 * This preserves the current behavior for normal CSS and only fails closed when 939 * the sanitizer cannot safely evaluate an extreme nested-function payload. 940 * 941 * @ticket security-1186 942 */ 943 public function test_safecss_filter_attr_rejects_css_when_pcre_error_occurs() { 944 // Force the recursive function-stripping regex to fail deterministically, regardless of 945 // whether PCRE JIT is enabled or how large its stack is, by lowering the backtrack limit. 946 $backtrack_limit = ini_set( 'pcre.backtrack_limit', '100' ); 947 $this->assertNotFalse( $backtrack_limit, 'Failed to call ini_set().' ); 948 949 $css = 'color:var(' . str_repeat( '(', 200 ) . str_repeat( ')', 200 ) . ')'; 950 951 try { 952 $this->assertSame( '', safecss_filter_attr( $css ) ); 953 } finally { 954 ini_set( 'pcre.backtrack_limit', $backtrack_limit ); 955 } 956 } 957 958 /** 936 959 * Data Provider for test_safecss_filter_attr(). 937 960 *
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)