Make WordPress Core

Opened 10 years ago

Closed 10 years ago

#7379 closed defect (bug) (invalid)

Revisions of Autosaves

Reported by: thomask Owned by:
Milestone: Priority: high
Severity: major Version:
Component: Security Keywords: revisions, autosave
Focuses: Cc:


see http://lesterchan.net/wordpress/2008/07/17/how-to-turn-off-post-revision-in-wordpress-26

This problem does not only affect performance, but also got security issues: you can e.g. copy to the article the partialy secret data and then you want to delete the secret parts, but with this autosave revisions bug, your secret data are stored in the database and everyone (editors/admins...) can reach them!

Both functions are fine, but there should be no revisions of autosaves!

Change History (4)

#1 @ryan
10 years ago

Autosave only ever saves one revision for me, which is as intended.

#2 @ryan
10 years ago

Confirming proper behavior. For draft posts, autosave always overwrites the draft post itself. It does not create new revisions. Explicitly saving a draft will create a revision, as intended. After the explicit save, autosave continues to overwrite the draft. It does not create revisions.

When editing a published post, autosave creates one autosave revision. Autosave always uses this one revision to store autosaves. Explicitly saving the post creates a revision, as intended. After explicit saves, autosave continues to use the designated autosave revision.

So, for drafts, autosave does not create revisions. For published posts, autosave creates one revision and overwrites it for each autosave. A published post will have at most one autosave revision.

If autosaves are creating multiple revisions for you, you have a bug I cannot reproduce. More details are needed. Please note that explicit clicks of the Save and Publish buttons are not autosaves and should indeed create revisions.

#3 @GamerZ
10 years ago

I confirm that Auto Saves does not create a revision, my bad.

#4 @Otto42
10 years ago

  • Milestone 2.6.1 deleted
  • Resolution set to invalid
  • Status changed from new to closed

Closing. Reopen this if anybody figures out how to make autosave make multiple revisions.

Note: See TracTickets for help on using tickets.