Changeset 62005
- Timestamp:
- 03/13/2026 01:03:05 PM (6 hours ago)
- Location:
- branches/4.8
- Files:
-
- 11 edited
-
. (modified) (1 prop)
-
src/wp-admin/includes/class-walker-nav-menu-checklist.php (modified) (1 diff)
-
src/wp-admin/includes/class-walker-nav-menu-edit.php (modified) (4 diffs)
-
src/wp-admin/includes/file.php (modified) (1 diff)
-
src/wp-includes/ID3/getid3.lib.php (modified) (1 diff)
-
src/wp-includes/class-wp-http-ixr-client.php (modified) (1 diff)
-
src/wp-includes/js/wp-util.js (modified) (1 diff)
-
src/wp-includes/kses.php (modified) (6 diffs)
-
src/wp-includes/media.php (modified) (2 diffs)
-
src/wp-includes/nav-menu.php (modified) (1 diff)
-
src/wp-includes/template-loader.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/4.8
- Property svn:mergeinfo changed
/trunk merged: 61879-61884,61886-61887,61890,61913
- Property svn:mergeinfo changed
-
branches/4.8/src/wp-admin/includes/class-walker-nav-menu-checklist.php
r35202 r62005 104 104 // Menu item hidden fields 105 105 $output .= '<input type="hidden" class="menu-item-db-id" name="menu-item[' . $possible_object_id . '][menu-item-db-id]" value="' . $possible_db_id . '" />'; 106 $output .= '<input type="hidden" class="menu-item-object" name="menu-item[' . $possible_object_id . '][menu-item-object]" value="' . esc_attr( $item->object ) .'" />';107 $output .= '<input type="hidden" class="menu-item-parent-id" name="menu-item[' . $possible_object_id . '][menu-item-parent-id]" value="' . esc_attr( $item->menu_item_parent ) .'" />';108 $output .= '<input type="hidden" class="menu-item-type" name="menu-item[' . $possible_object_id . '][menu-item-type]" value="' . esc_attr( $item->type ) .'" />';109 $output .= '<input type="hidden" class="menu-item-title" name="menu-item[' . $possible_object_id . '][menu-item-title]" value="' . esc_attr( $item->title ) .'" />';110 $output .= '<input type="hidden" class="menu-item-url" name="menu-item[' . $possible_object_id . '][menu-item-url]" value="' . esc_attr( $item->url ) .'" />';111 $output .= '<input type="hidden" class="menu-item-target" name="menu-item[' . $possible_object_id . '][menu-item-target]" value="' . esc_attr( $item->target ) .'" />';112 $output .= '<input type="hidden" class="menu-item-attr_title" name="menu-item[' . $possible_object_id . '][menu-item-attr _title]" value="'. esc_attr( $item->attr_title ) .'" />';113 $output .= '<input type="hidden" class="menu-item-classes" name="menu-item[' . $possible_object_id . '][menu-item-classes]" value="' . esc_attr( implode( ' ', $item->classes ) ) .'" />';114 $output .= '<input type="hidden" class="menu-item-xfn" name="menu-item[' . $possible_object_id . '][menu-item-xfn]" value="' . esc_attr( $item->xfn ) .'" />';106 $output .= '<input type="hidden" class="menu-item-object" name="menu-item[' . $possible_object_id . '][menu-item-object]" value="' . esc_attr( $item->object ) . '" />'; 107 $output .= '<input type="hidden" class="menu-item-parent-id" name="menu-item[' . $possible_object_id . '][menu-item-parent-id]" value="' . esc_attr( $item->menu_item_parent ) . '" />'; 108 $output .= '<input type="hidden" class="menu-item-type" name="menu-item[' . $possible_object_id . '][menu-item-type]" value="' . esc_attr( $item->type ) . '" />'; 109 $output .= '<input type="hidden" class="menu-item-title" name="menu-item[' . $possible_object_id . '][menu-item-title]" value="' . htmlspecialchars( $item->title, ENT_QUOTES ) . '" />'; 110 $output .= '<input type="hidden" class="menu-item-url" name="menu-item[' . $possible_object_id . '][menu-item-url]" value="' . esc_attr( $item->url ) . '" />'; 111 $output .= '<input type="hidden" class="menu-item-target" name="menu-item[' . $possible_object_id . '][menu-item-target]" value="' . esc_attr( $item->target ) . '" />'; 112 $output .= '<input type="hidden" class="menu-item-attr_title" name="menu-item[' . $possible_object_id . '][menu-item-attr-title]" value="' . htmlspecialchars( $item->attr_title, ENT_QUOTES ) . '" />'; 113 $output .= '<input type="hidden" class="menu-item-classes" name="menu-item[' . $possible_object_id . '][menu-item-classes]" value="' . htmlspecialchars( implode( ' ', $item->classes ), ENT_QUOTES ) . '" />'; 114 $output .= '<input type="hidden" class="menu-item-xfn" name="menu-item[' . $possible_object_id . '][menu-item-xfn]" value="' . htmlspecialchars( $item->xfn, ENT_QUOTES ) . '" />'; 115 115 } 116 116 -
branches/4.8/src/wp-admin/includes/class-walker-nav-menu-edit.php
r38770 r62005 163 163 <label for="edit-menu-item-title-<?php echo $item_id; ?>"> 164 164 <?php _e( 'Navigation Label' ); ?><br /> 165 <input type="text" id="edit-menu-item-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-title" name="menu-item-title[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->title); ?>" />165 <input type="text" id="edit-menu-item-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-title" name="menu-item-title[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->title, ENT_QUOTES ); ?>" /> 166 166 </label> 167 167 </p> … … 169 169 <label for="edit-menu-item-attr-title-<?php echo $item_id; ?>"> 170 170 <?php _e( 'Title Attribute' ); ?><br /> 171 <input type="text" id="edit-menu-item-attr-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-attr-title" name="menu-item-attr-title[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->post_excerpt); ?>" />171 <input type="text" id="edit-menu-item-attr-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-attr-title" name="menu-item-attr-title[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->post_excerpt, ENT_QUOTES ); ?>" /> 172 172 </label> 173 173 </p> … … 181 181 <label for="edit-menu-item-classes-<?php echo $item_id; ?>"> 182 182 <?php _e( 'CSS Classes (optional)' ); ?><br /> 183 <input type="text" id="edit-menu-item-classes-<?php echo $item_id; ?>" class="widefat code edit-menu-item-classes" name="menu-item-classes[<?php echo $item_id; ?>]" value="<?php echo esc_attr( implode(' ', $item->classes )); ?>" />183 <input type="text" id="edit-menu-item-classes-<?php echo $item_id; ?>" class="widefat code edit-menu-item-classes" name="menu-item-classes[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( implode( ' ', $item->classes ), ENT_QUOTES ); ?>" /> 184 184 </label> 185 185 </p> … … 187 187 <label for="edit-menu-item-xfn-<?php echo $item_id; ?>"> 188 188 <?php _e( 'Link Relationship (XFN)' ); ?><br /> 189 <input type="text" id="edit-menu-item-xfn-<?php echo $item_id; ?>" class="widefat code edit-menu-item-xfn" name="menu-item-xfn[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->xfn); ?>" />189 <input type="text" id="edit-menu-item-xfn-<?php echo $item_id; ?>" class="widefat code edit-menu-item-xfn" name="menu-item-xfn[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->xfn, ENT_QUOTES ); ?>" /> 190 190 </label> 191 191 </p> -
branches/4.8/src/wp-admin/includes/file.php
r41458 r62005 764 764 continue; 765 765 766 // Don't extract invalid files: 767 if ( 0 !== validate_file( $file['filename'] ) ) { 768 continue; 769 } 770 766 771 $uncompressed_size += $file['size']; 767 772 -
branches/4.8/src/wp-includes/ID3/getid3.lib.php
r32979 r62005 524 524 // https://core.trac.wordpress.org/changeset/29378 525 525 $loader = libxml_disable_entity_loader(true); 526 $XMLobject = simplexml_load_string($XMLstring, 'SimpleXMLElement', LIBXML_NOENT);526 $XMLobject = simplexml_load_string($XMLstring, 'SimpleXMLElement', 0); 527 527 $return = self::SimpleXMLelement2array($XMLobject); 528 528 libxml_disable_entity_loader($loader); -
branches/4.8/src/wp-includes/class-wp-http-ixr-client.php
r37492 r62005 87 87 } 88 88 89 $response = wp_ remote_post($url, $args);89 $response = wp_safe_remote_post( $url, $args ); 90 90 91 91 if ( is_wp_error($response) ) { -
branches/4.8/src/wp-includes/js/wp-util.js
r37851 r62005 31 31 32 32 return function ( data ) { 33 compiled = compiled || _.template( $( '#tmpl-' + id ).html(), options ); 33 var el = document.querySelector( 'script#tmpl-' + id ); 34 if ( ! el ) { 35 throw new Error( 'Template not found: ' + '#tmpl-' + id ); 36 } 37 compiled = compiled || _.template( $( el ).html(), options ); 34 38 return compiled( data ); 35 39 }; -
branches/4.8/src/wp-includes/kses.php
r46917 r62005 541 541 $allowed_protocols = wp_allowed_protocols(); 542 542 $string = wp_kses_no_null( $string, array( 'slash_zero' => 'keep' ) ); 543 543 544 544 // Preserve leading and trailing whitespace. 545 545 $matches = array(); … … 553 553 $string = substr( $string, strlen( $lead ), -strlen( $trail ) ); 554 554 } 555 555 556 556 // Parse attribute name and value from input. 557 557 $split = preg_split( '/\s*=\s*/', $string, 2 ); … … 590 590 $vless = 'y'; 591 591 } 592 592 593 593 // Sanitize attribute by name. 594 594 wp_kses_attr_check( $name, $value, $string, $vless, $element, $allowed_html ); … … 1125 1125 $xhtml_slash = ''; 1126 1126 } 1127 1127 1128 1128 // Split it 1129 1129 $attrarr = wp_kses_hair_parse( $attr ); … … 1135 1135 array_unshift( $attrarr, $begin . $slash . $elname ); 1136 1136 array_push( $attrarr, $xhtml_slash . $end ); 1137 1137 1138 1138 return $attrarr; 1139 1139 } … … 1450 1450 $string = str_replace('&', '&', $string); 1451 1451 1452 // Change back the allowed entities in our entity whitelist 1453 $string = preg_replace_callback('/&([A-Za-z]{2,8}[0-9]{0,2});/', 'wp_kses_named_entities', $string); 1454 $string = preg_replace_callback('/&#(0*[0-9]{1,7});/', 'wp_kses_normalize_entities2', $string); 1455 $string = preg_replace_callback('/&#[Xx](0*[0-9A-Fa-f]{1,6});/', 'wp_kses_normalize_entities3', $string); 1452 $string = preg_replace_callback( '/&([A-Za-z]{2,8}[0-9]{0,2});/', 'wp_kses_named_entities', $string ); 1453 $string = preg_replace_callback( '/&#(0*+[1-9][0-9]{0,6});/', 'wp_kses_normalize_entities2', $string ); 1454 $string = preg_replace_callback( '/&#[Xx](0*+[1-9A-Fa-f][0-9A-Fa-f]{0,5});/', 'wp_kses_normalize_entities3', $string ); 1456 1455 1457 1456 return $string; -
branches/4.8/src/wp-includes/media.php
r56864 r62005 3151 3151 } 3152 3152 3153 if ( $post_parent ) {3153 if ( $post_parent && current_user_can( 'read_post', $attachment->post_parent ) ) { 3154 3154 $parent_type = get_post_type_object( $post_parent->post_type ); 3155 3155 … … 3158 3158 } 3159 3159 3160 if ( $parent_type && current_user_can( 'read_post', $attachment->post_parent )) {3160 if ( $parent_type ) { 3161 3161 $response['uploadedToTitle'] = $post_parent->post_title ? $post_parent->post_title : __( '(no title)' ); 3162 3162 } -
branches/4.8/src/wp-includes/nav-menu.php
r40676 r62005 435 435 } 436 436 437 if ( $args['menu-item-title'] == $original_title )437 if ( wp_unslash( $args['menu-item-title'] ) === $original_title ) { 438 438 $args['menu-item-title'] = ''; 439 } 439 440 440 441 // hack to get wp to create a post object when too many properties are empty -
branches/4.8/src/wp-includes/template-loader.php
r38755 r62005 71 71 * @param string $template The path of the template to include. 72 72 */ 73 if ( $template = apply_filters( 'template_include', $template ) ) { 74 include( $template ); 73 $template = apply_filters( 'template_include', $template ); 74 $is_stringy = is_string( $template ) || ( is_object( $template ) && method_exists( $template, '__toString' ) ); 75 $template = $is_stringy ? realpath( (string) $template ) : null; 76 if ( 77 is_string( $template ) && 78 ( str_ends_with( $template, '.php' ) || str_ends_with( $template, '.html' ) ) && 79 is_file( $template ) && 80 is_readable( $template ) 81 ) { 82 include $template; 75 83 } elseif ( current_user_can( 'switch_themes' ) ) { 76 84 $theme = wp_get_theme();
Note: See TracChangeset
for help on using the changeset viewer.