Make WordPress Core

Opened 3 years ago

Last modified 21 hours ago

#59851 new task (blessed)

test for send_frame_options_header

Reported by: pbearne Owned by:
Priority: normal Milestone: Awaiting Review
Component: Build/Test Tools Version:
Severity: normal Keywords: has-patch has-unit-tests
Cc: Focuses: tests

Description


Change History (6)

#1 @pbearne
3 years ago

I can't workout how to check the header value as the header is already written so just checking for function for now

Maybe some else can point me in the direction

This ticket was mentioned in PR #5638 on WordPress/wordpress-develop by @pbearne.


3 years ago
#2

  • Keywords has-patch has-unit-tests added

#3 @swissspidy
2 years ago

  • Keywords needs-refresh added
  • Type defect (bug)task (blessed)

#4 @pbearne
2 years ago

It took a while to work out how to run xdebug tests.

But all done

#5 @desrosj
3 months ago

  • Focuses tests added

Adding the tests focus, which is used to indicate a ticket is solely focused on adding tests.

This ticket was mentioned in PR #12922 on WordPress/wordpress-develop by @irozum.


21 hours ago
#6

  • Keywords needs-refresh removed

Adds PHPUnit coverage for send_frame_options_header() in wp-includes/functions.php, which currently has no test coverage. This change is test-only and adds no production behaviour — it does not touch any file under src/. The new test calls the function directly and asserts, via xdebug_get_headers(), that both the X-Frame-Options: SAMEORIGIN and Content-Security-Policy: frame-ancestors 'self'; headers are sent — the function's entire observable behaviour, since it takes no parameters and returns nothing. The test is marked @requires function xdebug_get_headers and runs in a separate process (@runTestsInSeparateProcesses), following the existing precedent for header assertions in tests/phpunit/tests/oembed/headers.php, so it is skipped rather than failing on environments without the Xdebug extension loaded. I verified the test is meaningful by temporarily changing the X-Frame-Options value sent in send_frame_options_header() and confirming the test failed, then reverted the change and confirmed it passes again. I did not add a test for the headers_sent() guard clause (the early return when headers were already sent) — PHPUnit's beStrictAboutOutputDuringTests buffers test output internally, so producing real output from within a test does not actually flip headers_sent() to true in this harness, and I did not want to force a fragile workaround for that branch.

## Use of AI Tools

AI assistance: Yes
Tool(s): Claude Code
Model(s): Claude Sonnet 5
Used for: Ticket triage/selection, reading the existing implementation and test conventions, writing the test file, and running the verification loop (green/red/green). All output was reviewed by me before committing.

Note: See TracTickets for help on using tickets.