Index: tests/phpunit/tests/oembed.php
===================================================================
--- tests/phpunit/tests/oembed.php	(revision 0)
+++ tests/phpunit/tests/oembed.php	(working copy)
@@ -0,0 +1,747 @@
+<?php
+
+class Tests_oEmbed extends WP_UnitTestCase {
+
+	/**
+	 * An HTTP API response.
+	 * 
+	 * @var array
+	 */
+	protected $http_response = array();
+
+	public function setUp() {
+		parent::setUp();
+
+		require_once ABSPATH . WPINC . '/class-oembed.php';
+		$this->oembed = _wp_oembed_get_object();
+	}
+
+	/**
+	 * Test the tests
+	 *
+	 * @group external-oembed
+	 * @ticket 28507
+	 * @ticket 32360
+	 *
+	 * @dataProvider oEmbedProviderData
+	 */
+	public function testOembedTestURLsResolve( $match, array $urls, $supports_https ) {
+
+		if ( empty( $urls ) ) {
+			$this->markTestIncomplete();
+		}
+
+		foreach ( $urls as $url ) {
+
+			$msg = sprintf( 'Test URL: %s', $url );
+
+			$r = wp_remote_head( $url, array(
+				'redirection' => 3,
+			) );
+
+			if ( is_wp_error( $r ) ) {
+				$this->fail( sprintf( "%s (%s)\n%s", $r->get_error_message(), $r->get_error_code(), $msg ) );
+			}
+
+			$this->assertSame( 200, wp_remote_retrieve_response_code( $r ), $msg );
+
+		}
+
+	}
+
+	/**
+	 * Test the response from each oEmbed provider
+	 *
+	 * @group external-oembed
+	 * @ticket 32360
+	 *
+	 * @dataProvider oEmbedProviderData
+	 */
+	public function testOembedProviderReturnsExpectedResponse( $match, array $urls, $supports_https ) {
+
+		if ( empty( $urls ) ) {
+			$this->markTestIncomplete();
+		}
+
+		$this->setup_http_hooks();
+
+		$args = array(
+			'width'  => 500,
+			'height' => 500,
+		);
+		$test_urls = $urls;
+
+		if ( $supports_https ) {
+			foreach ( $urls as $url ) {
+				$test_urls[] = set_url_scheme( $url, 'https' );
+			}
+		}
+
+		foreach ( $test_urls as $url ) {
+
+			$msg = sprintf( "- Test URL: %s", $url );
+
+			$provider = $this->oembed->get_provider( $url, array(
+				'discover' => false,
+			) );
+			$this->assertNotFalse( $provider, $msg );
+
+			$data = $this->oembed->fetch( $provider, $url, $args );
+
+			$r = $this->http_response;
+
+			$msg .= sprintf( "\n- oEmbed URL: %s", $r['url'] );
+
+			$scheme = parse_url( $r['url'], PHP_URL_SCHEME );
+			$query  = parse_url( $r['url'], PHP_URL_QUERY );
+			parse_str( $query, $query_vars );
+
+			// Test request
+			$this->assertInternalType( 'array', $query_vars, $msg );
+			$this->assertArrayHasKey( 'maxheight', $query_vars, $msg );
+			$this->assertArrayHasKey( 'maxwidth', $query_vars, $msg );
+			$this->assertArrayHasKey( 'url', $query_vars, $msg );
+			$this->assertArrayHasKey( 'format', $query_vars, $msg );
+			$this->assertTrue( in_array( $query_vars['format'], array( 'json', 'xml' ), true ), $msg );
+			$this->assertEquals( $args['width'], $query_vars['maxwidth'], $msg );
+			$this->assertEquals( $args['height'], $query_vars['maxheight'], $msg );
+
+			// `WP_oEmbed::fetch()` only returns boolean false, so we need to hook into the HTTP API to get its error
+			if ( is_wp_error( $r['response'] ) ) {
+				$error_message = $r['response']->get_error_message();
+				if ( empty( $error_message ) ) {
+					$error_message = '- no message -';
+				}
+
+				$this->fail( sprintf( "%s (%s)\n%s", $error_message, $r['response']->get_error_code(), $msg ) );
+			}
+
+			$this->assertSame( 200, wp_remote_retrieve_response_code( $r['response'] ), $msg );
+
+			// Test response
+			$this->assertNotFalse( $data, $msg );
+
+			// Check for required response parameters
+			$this->assertObjectHasAttribute( 'type', $data, $msg );
+			$this->assertObjectHasAttribute( 'version', $data, $msg );
+			$this->assertEquals( '1.0', $data->version, $msg );
+
+			switch ( $data->type ) {
+
+				case 'photo':
+
+					// Check for required response parameters
+					$this->assertObjectHasAttribute( 'url', $data, $msg );
+					$this->assertObjectHasAttribute( 'width', $data, $msg );
+					$this->assertObjectHasAttribute( 'height', $data, $msg );
+
+					// Validate response parameters
+					$this->assertNotEmpty( $data->url, $msg );
+					$this->assertInternalType( 'string', $data->url, $msg );
+
+					// Validate response URL scheme
+					if ( 'https' === $scheme ) {
+						$response_scheme = parse_url( $data->url, PHP_URL_SCHEME );
+						if ( ! in_array( $response_scheme, array( null, 'https' ), true ) ) {
+							$this->fail( sprintf( "Invalid scheme in response URL: %s\n%s", $data->url, $msg ) );
+						}
+					}
+
+					break;
+
+				case 'video':
+
+					// Check for required response parameters
+					$this->assertObjectHasAttribute( 'html', $data, $msg );
+					$this->assertObjectHasAttribute( 'width', $data, $msg );
+					$this->assertObjectHasAttribute( 'height', $data, $msg );
+
+					// Validate response parameters
+					$this->assertNotEmpty( $data->html, $msg );
+					$this->assertInternalType( 'string', $data->html, $msg );
+
+					break;
+
+				case 'rich':
+
+					// Check for required response parameters
+					$this->assertObjectHasAttribute( 'html', $data, $msg );
+					$this->assertObjectHasAttribute( 'width', $data, $msg );
+					$this->assertObjectHasAttribute( 'height', $data, $msg );
+
+					// Validate response parameters
+					$this->assertNotEmpty( $data->html, $msg );
+					$this->assertInternalType( 'string', $data->html, $msg );
+
+					// Validate response URL schemes
+					if ( 'https' === $scheme ) {
+
+						if ( preg_match_all( '#src="([^"]+)"#', $data->html, $matches ) ) {
+							foreach ( $matches[1] as $src ) {
+								$src_scheme = parse_url( $src, PHP_URL_SCHEME );
+								if ( ! in_array( $src_scheme, array( null, 'https' ), true ) ) {
+									$this->fail( sprintf( "Invalid src scheme in response: %s\n%s", $src, $msg ) );
+								}
+							}
+						}
+
+					}
+
+					break;
+
+				case 'link':
+
+					// Check for required response parameters
+					$this->assertObjectHasAttribute( 'title', $data, $msg );
+
+					// Validate response parameters
+					$this->assertNotEmpty( $data->title, $msg );
+					$this->assertInternalType( 'string', $data->title, $msg );
+
+					break;
+
+				default:
+
+					$this->fail( sprintf( "Invalid value for the 'type' response parameter\n%s", $msg ) );
+
+					break;
+
+			}
+
+			if ( ! empty( $data->width ) ) {
+
+				// Validate response parameter
+				$this->assertTrue( is_numeric( $data->width ), $msg );
+				$this->assertLessThanOrEqual( intval( $query_vars['maxwidth'] ), $data->width, $msg );
+
+			}
+
+			if ( ! empty( $data->height ) ) {
+
+				// Validate response parameter
+				$this->assertTrue( is_numeric( $data->height ), $msg );
+				$this->assertLessThanOrEqual( intval( $query_vars['maxheight'] ), $data->height, $msg );
+
+			}
+
+			if ( ! empty( $data->thumbnail_url ) ) {
+
+				// Check for required response parameters
+				$this->assertObjectHasAttribute( 'thumbnail_width', $data, $msg );
+				$this->assertObjectHasAttribute( 'thumbnail_height', $data, $msg );
+
+			}
+
+			if ( ! empty( $data->thumbnail_width ) ) {
+
+				// Check for required response parameters
+				$this->assertObjectHasAttribute( 'thumbnail_url', $data, $msg );
+
+				// Validate response parameter
+				$this->assertTrue( is_numeric( $data->thumbnail_width ), $msg );
+				$this->assertLessThanOrEqual( intval( $query_vars['maxwidth'] ), $data->thumbnail_width, $msg );
+
+			}
+
+			if ( ! empty( $data->thumbnail_height ) ) {
+
+				// Check for required response parameters
+				$this->assertObjectHasAttribute( 'thumbnail_url', $data, $msg );
+
+				// Validate response parameter
+				$this->assertTrue( is_numeric( $data->thumbnail_height ), $msg );
+				$this->assertLessThanOrEqual( intval( $query_vars['maxheight'] ), $data->thumbnail_height, $msg );
+
+			}
+
+		}
+
+		$this->teardown_http_hooks();
+
+	}
+
+	/**
+	 * Test the response from each oEmbed provider when provided with invalid data
+	 *
+	 * @group external-oembed
+	 * @ticket 32360
+	 *
+	 * @dataProvider oEmbedProviderData
+	 */
+	public function testOembedProviderHandlesInvalidData( $match, array $urls, $supports_https ) {
+
+		if ( empty( $urls ) ) {
+			$this->markTestIncomplete();
+		}
+
+		$this->setup_http_hooks();
+		add_filter( 'oembed_fetch_url', array( $this, 'filter_oembed_fetch_url' ), 99, 3 );
+
+		$invalid = '500" onmouseover="alert(document.cookie)';
+
+		$args = array(
+			'width'  => $invalid,
+			'height' => $invalid,
+		);
+
+		// Only need to test with one URL for each provider
+		$url = $urls[0];
+
+		$msg = sprintf( "- Test URL: %s", $url );
+
+		$provider = $this->oembed->get_provider( $url, array(
+			'discover' => false,
+		) );
+		$this->assertNotFalse( $provider, $msg );
+		$data = $this->oembed->fetch( $provider, $url, $args );
+
+		$r = $this->http_response;
+
+		$msg .= sprintf( "\n- oEmbed URL: %s", $r['url'] );
+
+		$query = parse_url( $r['url'], PHP_URL_QUERY );
+		parse_str( $query, $query_vars );
+
+		// Test request
+		$this->assertInternalType( 'array', $query_vars, $msg );
+		$this->assertArrayHasKey( 'maxheight', $query_vars, $msg );
+		$this->assertArrayHasKey( 'maxwidth', $query_vars, $msg );
+		$this->assertEquals( $args['width'], $query_vars['maxwidth'], $msg );
+		$this->assertEquals( $args['height'], $query_vars['maxheight'], $msg );
+
+		// `WP_oEmbed::fetch()` only returns boolean false, so we need to hook into the HTTP API to get its error
+		if ( is_wp_error( $r['response'] ) ) {
+			$error_message = $r['response']->get_error_message();
+			if ( empty( $error_message ) ) {
+				$error_message = '- no message -';
+			}
+
+			$this->fail( sprintf( "%s (%s)\n%s", $error_message, $r['response']->get_error_code(), $msg ) );
+		}
+
+		$this->assertTrue( in_array( wp_remote_retrieve_response_code( $r['response'] ), array(
+			200,
+			400,
+			404,
+		), true ), $msg );
+
+		if ( false === $data ) {
+			// For an erroneous request, it's valid to return no data (or no JSON/XML, which evaluates to false) and
+			// therefore the rest of the assertions can be skipped
+			return;
+		}
+
+		// Check invalid data isn't echoed
+		$this->assertNotContains( 'onmouseover', wp_remote_retrieve_body( $r['response'] ), $msg );
+
+		if ( isset( $data->width ) ) {
+			$this->assertTrue( is_numeric( $data->width ), $msg );
+		}
+
+		if ( isset( $data->height ) ) {
+			$this->assertTrue( is_numeric( $data->height ), $msg );
+		}
+
+		if ( isset( $data->thumbnail_width ) ) {
+			$this->assertTrue( is_numeric( $data->thumbnail_width ), $msg );
+		}
+
+		if ( isset( $data->thumbnail_height ) ) {
+			$this->assertTrue( is_numeric( $data->thumbnail_height ), $msg );
+		}
+
+		remove_filter( 'oembed_fetch_url', array( $this, 'filter_oembed_fetch_url' ), 99 );
+		$this->teardown_http_hooks();
+
+	}
+
+	/**
+	 * Test the tests
+	 *
+	 * @group oembed
+	 * @ticket 32360
+	 */
+	public function testOembedTestsCoverAllProviders() {
+
+		$tests     = wp_list_pluck( $this->oEmbedProviderData(), 0 );
+		$providers = array_keys( $this->oembed->providers );
+		$missing   = array_diff( $providers, $tests );
+
+		$this->assertEmpty( $missing, sprintf( "These oEmbed providers are not tested:\n- %s", implode( "\n- ", $missing ) ) );
+
+	}
+
+	/**
+	 * Test the tests
+	 *
+	 * @group oembed
+	 * @ticket 32360
+	 * 
+	 */
+	public function testOembedTestsAreAllUseful() {
+
+		$tests     = wp_list_pluck( $this->oEmbedProviderData(), 0 );
+		$providers = array_keys( $this->oembed->providers );
+		$useless   = array_diff( $tests, $providers );
+
+		$this->assertEmpty( $useless, sprintf( "These tests do not cover any oEmbed provider:\n- %s", implode( "\n- ", $useless ) ) );
+
+	}
+
+	/**
+	 * Data provider for our oEmbed tests
+	 *
+	 * @return array
+	 */
+	public function oEmbedProviderData() {
+		return array(
+			array(
+				'#http://((m|www)\.)?youtube\.com/watch.*#i',
+				array(
+					'http://youtube.com/watch?v=zdtD19tXX30',
+					'http://m.youtube.com/watch?v=QkP_rOCBrpY',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#https://((m|www)\.)?youtube\.com/watch.*#i',
+				array(
+					'https://www.youtube.com/watch?v=bDRQRdFaFEo',
+					'https://m.youtube.com/watch?v=yfUflij74P4',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#http://((m|www)\.)?youtube\.com/playlist.*#i',
+				array(
+					'http://www.youtube.com/playlist?list=PLC7D2959C96B8D27B',
+					'http://m.youtube.com/playlist?list=PLEC422D53B7588DC7',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#https://((m|www)\.)?youtube\.com/playlist.*#i',
+				array(
+					'https://youtube.com/playlist?list=PL93B9F6B77FBB0160',
+					'https://m.youtube.com/playlist?list=PL1AC02C68F976A10F',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#http://youtu\.be/.*#i',
+				array(
+					'http://youtu.be/nfWlot6h_JM?list=PLirAqAtl_h2r5g8xGajEwdXd3x1sZh8hC',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#https://youtu\.be/.*#i',
+				array(
+					'https://youtu.be/U8SYRUYfs_I',
+				),
+				false, // HTTPS handled by different endpoints
+			),
+			array(
+				'#https?://(.+\.)?vimeo\.com/.*#i',
+				array(
+					'http://vimeo.com/12339198',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?dailymotion\.com/.*#i',
+				array(
+					'http://www.dailymotion.com/video/x27bwvb_how-to-wake-up-better_news',
+				),
+				true,
+			),
+			array(
+				'http://dai.ly/*',
+				array(
+					'http://dai.ly/x33exze',
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'#https?://(www\.)?flickr\.com/.*#i',
+				array(
+					'http://www.flickr.com/photos/bon/14004280667/',
+				),
+				true,
+			),
+			array(
+				'#https?://flic\.kr/.*#i',
+				array(
+					'http://flic.kr/p/6BFrbQ',
+				),
+				true,
+			),
+			array(
+				'#https?://(.+\.)?smugmug\.com/.*#i',
+				array(
+					'http://fotoeffects.smugmug.com/Daily-shots-for-the-dailies/Dailies/6928550_9gMRmv/476011624_WhGWpts#!i=476011624&k=WhGWpts',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?hulu\.com/watch/.*#i',
+				array(
+					'http://www.hulu.com/watch/807443',
+				),
+				true,
+			),
+			array(
+				'http://i*.photobucket.com/albums/*',
+				array(
+					'http://i415.photobucket.com/albums/pp236/Keefers_/Keffers%20Animals/funny-cats-a10.jpg',
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'http://gi*.photobucket.com/groups/*',
+				array(
+					// ??
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'#https?://(www\.)?scribd\.com/doc/.*#i',
+				array(
+					'http://www.scribd.com/doc/110799637/Synthesis-of-Knowledge-Effects-of-Fire-and-Thinning-Treatments-on-Understory-Vegetation-in-Dry-U-S-Forests',
+				),
+				true,
+			),
+			array(
+				'#https?://wordpress.tv/.*#i',
+				array(
+					'http://wordpress.tv/2015/08/18/billie/',
+				),
+				true,
+			),
+			array(
+				'#https?://(.+\.)?polldaddy\.com/.*#i',
+				array(
+					'http://polldaddy.com/poll/9066794/',
+				),
+				true,
+			),
+			array(
+				'#https?://poll\.fm/.*#i',
+				array(
+					'http://poll.fm/5ebze',
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'#https?://(www\.)?funnyordie\.com/videos/.*#i',
+				array(
+					'http://www.funnyordie.com/videos/e5ef40bf2a/cute-overload',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?twitter\.com/.+?/status(es)?/.*#i',
+				array(
+					'http://twitter.com/WordPress/status/633718182335922177',
+				),
+				true,
+			),
+			array(
+				'#https?://vine.co/v/.*#i',
+				array(
+					'http://vine.co/v/OjiLun5LuQ6',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?soundcloud\.com/.*#i',
+				array(
+					'http://soundcloud.com/steveaoki/kid-cudi-pursuit-of-happiness',
+				),
+				true,
+			),
+			array(
+				'#https?://(.+?\.)?slideshare\.net/.*#i',
+				array(
+					'http://www.slideshare.net/haraldf/business-quotes-for-2011',
+				),
+				true,
+			),
+			array(
+				'#https?://instagr(\.am|am\.com)/p/.*#i',
+				array(
+					'http://instagram.com/p/68WqXbTcfl/',
+					'https://instagram.com/p/68WqXbTcfl/',
+					'http://instagr.am/p/MRM3HQy6kh/',
+				),
+				false, // No HTTPS support on instagr.am
+			),
+			array(
+				'#https?://(www\.)?rdio\.com/.*#i',
+				array(
+					'http://www.rdio.com/artist/Wolf_Alice/album/My_Love_Is_Cool_1/',
+				),
+				true,
+			),
+			array(
+				'#https?://rd\.io/x/.*#i',
+				array(
+					'http://rd.io/x/Rl4F5xw-bsh5/',
+				),
+				true,
+			),
+			array(
+				'#https?://(open|play)\.spotify\.com/.*#i',
+				array(
+					'http://open.spotify.com/track/2i1KmyEXN3pNLwdxAWSGcg',
+				),
+				true,
+			),
+			array(
+				'#https?://(.+\.)?imgur\.com/.*#i',
+				array(
+					'http://imgur.com/a/WdJim',
+					'http://i.imgur.com/mbOPX2L.png',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?meetu(\.ps|p\.com)/.*#i',
+				array(
+					'http://www.meetup.com/WordPress-Amsterdam/events/224346396/',
+					'http://meetu.ps/2L533w',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?issuu\.com/.+/docs/.+#i',
+				array(
+					'http://issuu.com/vmagazine/docs/v87',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?collegehumor\.com/video/.*#i',
+				array(
+					'http://www.collegehumor.com/video/2862877/jake-and-amir-math',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?mixcloud\.com/.*#i',
+				array(
+					'http://www.mixcloud.com/8_8s/disclosurefriends/',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.|embed\.)?ted\.com/talks/.*#i',
+				array(
+					'http://www.ted.com/talks/rodney_mullen_pop_an_ollie_and_innovate',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?(animoto|video214)\.com/play/.*#i',
+				array(
+					'http://animoto.com/play/MlRRgXHhoT8gOZyHanM6TA',
+					'http://video214.com/play/MlRRgXHhoT8gOZyHanM6TA',
+				),
+				true,
+			),
+			array(
+				'#https?://(.+)\.tumblr\.com/post/.*#i',
+				array(
+					'http://yahoo.tumblr.com/post/50902111638/tumblr-yahoo',
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'#https?://(www\.)?kickstarter\.com/projects/.*#i',
+				array(
+					'http://www.kickstarter.com/projects/zackdangerbrown/potato-salad',
+				),
+				true,
+			),
+			array(
+				'#https?://kck\.st/.*#i',
+				array(
+					'http://kck.st/1ukxHcx',
+				),
+				false, // No HTTPS support
+			),
+			array(
+				'#https?://cloudup\.com/.*#i',
+				array(
+					'http://cloudup.com/cWX2Bi5DmfJ',
+				),
+				true,
+			),
+			array(
+				'#https?://(www\.)?reverbnation\.com/.*#i',
+				array(
+					'http://www.reverbnation.com/enemyplanes/song/16729753-we-want-blood',
+					'http://www.reverbnation.com/enemyplanes',
+				),
+				true,
+			),
+			array(
+				'#https?://(www.)?tunein\.com/.*#i',
+				array(
+					'http://tunein.com/radio/KQED-FM-885-s34804/',
+				),
+				true,
+			),
+			array(
+				'#https?://[^/]+\.wordpress\.com/[\d/]+/.+#i',
+				array(
+					'http://matt.wordpress.com/2014/10/25/wordcamp-san-francisco-wcsf-wcsf14/',
+				),
+				true,
+			),
+			array(
+				'#https?://videopress.com/v/.*#',
+				array(
+					'https://videopress.com/v/kUJmAcSf',
+				),
+				true,
+			),
+		);
+	}
+
+	protected function setup_http_hooks() {
+		add_action( 'http_api_debug', array( $this, 'action_http_api_debug' ), 99, 5 );
+	}
+
+	protected function teardown_http_hooks() {
+		remove_action( 'http_api_debug', array( $this, 'action_http_api_debug' ), 99 );
+		$this->http_response = null;
+	}
+
+	public function filter_oembed_fetch_url( $provider_url, $embed_url, $args ) {
+		// this allows us to test invalid data without it being converted to an integer in `WP_oEmbed::fetch()`
+		$provider_url = add_query_arg( 'maxwidth', $args['width'], $provider_url );
+		$provider_url = add_query_arg( 'maxheight', $args['height'], $provider_url );
+		return $provider_url;
+	}
+
+	/**
+	 * Debugging action for the HTTP API response.
+	 * 
+	 * @param array|WP_Error $response The HTTP response.
+	 * @param string         $action   The debug action.
+	 * @param string         $class    The HTTP transport class name.
+	 * @param array          $args     HTTP request arguments.
+	 * @param string         $url      The request URL.
+	 */
+	public function action_http_api_debug( $response, $action, $class, $args, $url ) {
+
+		if ( 'response' !== $action ) {
+			return;
+		}
+
+		$this->http_response = compact( 'response', 'args', 'url' );
+
+	}
+
+}
