Opened 3 years ago
Last modified 21 hours ago
#59851 new task (blessed)
test for send_frame_options_header
| Reported by: | pbearne | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | Awaiting Review |
| Component: | Build/Test Tools | Version: | |
| Severity: | normal | Keywords: | has-patch has-unit-tests |
| Cc: | Focuses: | tests |
Description
Change History (6)
This ticket was mentioned in PR #5638 on WordPress/wordpress-develop by @pbearne.
3 years ago
#2
- Keywords has-patch has-unit-tests added
#5
@
3 months ago
- Focuses tests added
Adding the tests focus, which is used to indicate a ticket is solely focused on adding tests.
This ticket was mentioned in PR #12922 on WordPress/wordpress-develop by @irozum.
21 hours ago
#6
- Keywords needs-refresh removed
Adds PHPUnit coverage for send_frame_options_header() in wp-includes/functions.php, which currently has no test coverage. This change is test-only and adds no production behaviour — it does not touch any file under src/. The new test calls the function directly and asserts, via xdebug_get_headers(), that both the X-Frame-Options: SAMEORIGIN and Content-Security-Policy: frame-ancestors 'self'; headers are sent — the function's entire observable behaviour, since it takes no parameters and returns nothing. The test is marked @requires function xdebug_get_headers and runs in a separate process (@runTestsInSeparateProcesses), following the existing precedent for header assertions in tests/phpunit/tests/oembed/headers.php, so it is skipped rather than failing on environments without the Xdebug extension loaded. I verified the test is meaningful by temporarily changing the X-Frame-Options value sent in send_frame_options_header() and confirming the test failed, then reverted the change and confirmed it passes again. I did not add a test for the headers_sent() guard clause (the early return when headers were already sent) — PHPUnit's beStrictAboutOutputDuringTests buffers test output internally, so producing real output from within a test does not actually flip headers_sent() to true in this harness, and I did not want to force a fragile workaround for that branch.
## Use of AI Tools
AI assistance: Yes
Tool(s): Claude Code
Model(s): Claude Sonnet 5
Used for: Ticket triage/selection, reading the existing implementation and test conventions, writing the test file, and running the verification loop (green/red/green). All output was reviewed by me before committing.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
I can't workout how to check the header value as the header is already written so just checking for function for now
Maybe some else can point me in the direction