Changeset 63115
- Timestamp:
- 08/06/2026 07:59:05 PM (5 weeks ago)
- Location:
- branches/4.7/src
- Files:
-
- 8 edited
-
wp-admin/includes/ms.php (modified) (3 diffs)
-
wp-admin/includes/user.php (modified) (3 diffs)
-
wp-admin/js/inline-edit-post.js (modified) (1 diff)
-
wp-includes/canonical.php (modified) (1 diff)
-
wp-includes/http.php (modified) (1 diff)
-
wp-includes/kses.php (modified) (1 diff)
-
wp-includes/user.php (modified) (3 diffs)
-
wp-signup.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/4.7/src/wp-admin/includes/ms.php
r49399 r63115 331 331 * @since 3.0.0 332 332 * 333 * @param int $user_id Optional. The ID of the user whose email is being changed. Defaults to `$_POST['user_id']` if set, otherwise 0. 334 * 333 335 * @global WP_Error $errors WP_Error object. 334 336 * @global wpdb $wpdb WordPress database object. 335 337 */ 336 function send_confirmation_on_profile_email( ) {338 function send_confirmation_on_profile_email( $user_id = 0 ) { 337 339 global $errors, $wpdb; 340 341 // Maintain backward compatibility for those relying on a check based on $_POST['user_id']. 342 if ( ! $user_id && isset( $_POST['user_id'] ) ) { 343 $user_id = (int) $_POST['user_id']; 344 } 345 338 346 $current_user = wp_get_current_user(); 339 347 if ( ! is_object($errors) ) 340 348 $errors = new WP_Error(); 341 349 342 if ( $current_user->ID != $_POST['user_id'])350 if ( 0 === $current_user->ID || $current_user->ID !== (int) $user_id ) 343 351 return false; 344 352 … … 346 354 if ( !is_email( $_POST['email'] ) ) { 347 355 $errors->add( 'user_email', __( "<strong>ERROR</strong>: The email address isn’t correct." ), array( 'form-field' => 'email' ) ); 356 $_POST['email'] = addslashes( $current_user->user_email ); 348 357 return; 349 358 } … … 352 361 $errors->add( 'user_email', __( "<strong>ERROR</strong>: The email address is already used." ), array( 'form-field' => 'email' ) ); 353 362 delete_user_meta( $current_user->ID, '_new_email' ); 363 $_POST['email'] = addslashes( $current_user->user_email ); 354 364 return; 355 365 } -
branches/4.7/src/wp-admin/includes/user.php
r39269 r63115 43 43 $user->user_login = sanitize_user($_POST['user_login'], true); 44 44 45 $errors = new WP_Error(); 46 45 47 $pass1 = $pass2 = ''; 46 48 if ( isset( $_POST['pass1'] ) ) … … 63 65 } 64 66 65 if ( isset( $_POST['email'] )) 66 $user->user_email = sanitize_text_field( wp_unslash( $_POST['email'] ) ); 67 if ( isset( $_POST['email'] ) ) { 68 $maybe_email = wp_unslash( $_POST['email'] ); 69 if ( is_string( $maybe_email ) && is_email( $maybe_email ) ) { 70 $user->user_email = $maybe_email; 71 } else { 72 $errors->add( 'invalid_email', __( '<strong>ERROR</strong>: The email address isn’t correct.' ), array( 'form-field' => 'email' ) ); 73 } 74 } 67 75 if ( isset( $_POST['url'] ) ) { 68 76 if ( empty ( $_POST['url'] ) || $_POST['url'] == 'http://' ) { … … 116 124 if ( !empty($_POST['use_ssl']) ) 117 125 $user->use_ssl = 1; 118 119 $errors = new WP_Error();120 126 121 127 /* checking that username has been typed */ -
branches/4.7/src/wp-admin/js/inline-edit-post.js
r40365 r63115 154 154 if ( !$(':input[name="post_author"] option[value="' + $('.post_author', rowData).text() + '"]', editRow).val() ) { 155 155 // author no longer has edit caps, so we need to add them to the list of authors 156 $(':input[name="post_author"]', editRow).prepend('<option value="' + $('.post_author', rowData).text() + '">' + $('#' + t.type + '-' + id + ' .author').text() + '</option>'); 156 $(':input[name="post_author"]', editRow).prepend( 157 new Option( 158 $('#' + t.type + '-' + id + ' .author').text(), 159 $('.post_author', rowData).text() 160 ) 161 ); 157 162 } 158 163 if ( $( ':input[name="post_author"] option', editRow ).length === 1 ) { -
branches/4.7/src/wp-includes/canonical.php
r38216 r63115 590 590 591 591 if ( get_query_var('name') ) { 592 $publicly_viewable_post_types = array_filter( get_post_types( array( 'exclude_from_search' => false ) ), 'is_post_type_viewable' ); 593 592 594 $where = $wpdb->prepare("post_name LIKE %s", $wpdb->esc_like( get_query_var('name') ) . '%'); 593 595 594 596 // if any of post_type, year, monthnum, or day are set, use them to refine the query 595 if ( get_query_var('post_type') ) 596 $where .= $wpdb->prepare(" AND post_type = %s", get_query_var('post_type')); 597 else 598 $where .= " AND post_type IN ('" . implode( "', '", get_post_types( array( 'public' => true ) ) ) . "')"; 597 if ( get_query_var( 'post_type' ) ) { 598 if ( is_array( get_query_var( 'post_type' ) ) ) { 599 $post_types = array_intersect( get_query_var( 'post_type' ), $publicly_viewable_post_types ); 600 if ( empty( $post_types ) ) { 601 return false; 602 } 603 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $post_types ) ) . "')"; 604 } else { 605 if ( ! in_array( get_query_var( 'post_type' ), $publicly_viewable_post_types, true ) ) { 606 return false; 607 } 608 $where .= $wpdb->prepare( ' AND post_type = %s', get_query_var( 'post_type' ) ); 609 } 610 } else { 611 $where .= " AND post_type IN ('" . implode( "', '", esc_sql( $publicly_viewable_post_types ) ) . "')"; 612 } 599 613 600 614 if ( get_query_var('year') ) -
branches/4.7/src/wp-includes/http.php
r46495 r63115 548 548 if ( $ip ) { 549 549 $parts = array_map( 'intval', explode( '.', $ip ) ); 550 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] 551 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) 552 || ( 192 === $parts[0] && 168 === $parts[1] ) 550 551 /* 552 * These IP address ranges are not considered valid external hosts for HTTP requests. 553 * 554 * If the host resolves to an IP address in these ranges, the request will be rejected unless the 'http_request_host_is_external' filter allows it. 555 * 556 * References: 557 * 558 * - IPv4 Special-Purpose Address Space: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml 559 * - IPv4 Multicast Address Assignments: https://www.rfc-editor.org/rfc/rfc5771.html 560 */ 561 if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] // 127.0.0.0/8 (loopback), 10.0.0.0/8 (private), 0.0.0.0/8 (this network). 562 || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) // 172.16.0.0/12 (private). 563 || ( 192 === $parts[0] && 168 === $parts[1] ) // 192.168.0.0/16 (private). 564 || ( 192 === $parts[0] && 0 === $parts[1] && 0 === $parts[2] ) // 192.0.0.0/24 (IETF protocol assignments). 565 || ( 192 === $parts[0] && 0 === $parts[1] && 2 === $parts[2] ) // 192.0.2.0/24 (TEST-NET-1). 566 || ( 192 === $parts[0] && 88 === $parts[1] && 99 === $parts[2] ) // 192.88.99.0/24 (6to4 relay anycast). 567 || ( 198 === $parts[0] && 51 === $parts[1] && 100 === $parts[2] ) // 198.51.100.0/24 (TEST-NET-2). 568 || ( 203 === $parts[0] && 0 === $parts[1] && 113 === $parts[2] ) // 203.0.113.0/24 (TEST-NET-3). 569 || ( 169 === $parts[0] && 254 === $parts[1] ) // 169.254.0.0/16 (link-local and cloud metadata). 570 || ( 100 === $parts[0] && 64 <= $parts[1] && 127 >= $parts[1] ) // 100.64.0.0/10 (CGNAT). 571 || ( 198 === $parts[0] && 18 <= $parts[1] && 19 >= $parts[1] ) // 198.18.0.0/15 (benchmarking). 572 || ( 224 <= $parts[0] && 239 >= $parts[0] ) // 224.0.0.0/4 (multicast). 573 || 240 <= $parts[0] // 240.0.0.0/4 (reserved, includes 255.255.255.255 broadcast). 553 574 ) { 554 575 // If host appears local, reject unless specifically allowed. -
branches/4.7/src/wp-includes/kses.php
r62006 r63115 1748 1748 $css = str_replace(array("\n","\r","\t"), '', $css); 1749 1749 1750 if ( preg_match( '%[\\\\(&=}]|/\*%', $css ) ) // remove any inline css containing \ ( & } = or comments1750 if ( 0 !== preg_match( '%[\\\\(&=}]|/\*%', $css ) ) // remove any inline css containing \ ( & } = or comments 1751 1751 return ''; 1752 1752 -
branches/4.7/src/wp-includes/user.php
r47650 r63115 165 165 /* translators: %s: user name */ 166 166 __( '<strong>ERROR</strong>: The password you entered for the username %s is incorrect.' ), 167 '<strong>' . $username. '</strong>'167 '<strong>' . esc_html( $username ) . '</strong>' 168 168 ) . 169 169 ' <a href="' . wp_lostpassword_url() . '">' . … … 237 237 /* translators: %s: email address */ 238 238 __( '<strong>ERROR</strong>: The password you entered for the email address %s is incorrect.' ), 239 '<strong>' . $email. '</strong>'239 '<strong>' . esc_html( $email ) . '</strong>' 240 240 ) . 241 241 ' <a href="' . wp_lostpassword_url() . '">' . … … 2339 2339 $user_id = wp_create_user( $sanitized_user_login, $user_pass, $user_email ); 2340 2340 if ( ! $user_id || is_wp_error( $user_id ) ) { 2341 $errors->add( 'registerfail', sprintf( __( '<strong>ERROR</strong>: Couldn’t register you… please contact the <a href="mailto:%s">webmaster</a> !' ), get_option( 'admin_email') ) );2341 $errors->add( 'registerfail', sprintf( __( '<strong>ERROR</strong>: Couldn’t register you… please contact the <a href="mailto:%s">webmaster</a> !' ), esc_attr( get_option( 'admin_email' ) ) ) ); 2342 2342 return $errors; 2343 2343 } -
branches/4.7/src/wp-signup.php
r38814 r63115 853 853 break; 854 854 case 'gimmeanotherblog': 855 validate_another_blog_signup(); 855 if ( 'all' === $active_signup || 'blog' === $active_signup ) { 856 validate_another_blog_signup(); 857 } else { 858 _e( 'Site registration has been disabled.' ); 859 } 856 860 break; 857 861 case 'default':
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)