Changeset 62006
- Timestamp:
- 03/13/2026 01:05:42 PM (4 hours ago)
- Location:
- branches/4.7
- Files:
-
- 11 edited
-
. (modified) (1 prop)
-
src/wp-admin/includes/class-walker-nav-menu-checklist.php (modified) (1 diff)
-
src/wp-admin/includes/class-walker-nav-menu-edit.php (modified) (4 diffs)
-
src/wp-admin/includes/file.php (modified) (1 diff)
-
src/wp-includes/ID3/getid3.lib.php (modified) (1 diff)
-
src/wp-includes/class-wp-http-ixr-client.php (modified) (1 diff)
-
src/wp-includes/js/wp-util.js (modified) (1 diff)
-
src/wp-includes/kses.php (modified) (6 diffs)
-
src/wp-includes/media.php (modified) (2 diffs)
-
src/wp-includes/nav-menu.php (modified) (1 diff)
-
src/wp-includes/template-loader.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/4.7
- Property svn:mergeinfo changed
/trunk merged: 61879-61884,61886-61887,61890,61913
- Property svn:mergeinfo changed
-
branches/4.7/src/wp-admin/includes/class-walker-nav-menu-checklist.php
r35202 r62006 104 104 // Menu item hidden fields 105 105 $output .= '<input type="hidden" class="menu-item-db-id" name="menu-item[' . $possible_object_id . '][menu-item-db-id]" value="' . $possible_db_id . '" />'; 106 $output .= '<input type="hidden" class="menu-item-object" name="menu-item[' . $possible_object_id . '][menu-item-object]" value="' . esc_attr( $item->object ) .'" />';107 $output .= '<input type="hidden" class="menu-item-parent-id" name="menu-item[' . $possible_object_id . '][menu-item-parent-id]" value="' . esc_attr( $item->menu_item_parent ) .'" />';108 $output .= '<input type="hidden" class="menu-item-type" name="menu-item[' . $possible_object_id . '][menu-item-type]" value="' . esc_attr( $item->type ) .'" />';109 $output .= '<input type="hidden" class="menu-item-title" name="menu-item[' . $possible_object_id . '][menu-item-title]" value="' . esc_attr( $item->title ) .'" />';110 $output .= '<input type="hidden" class="menu-item-url" name="menu-item[' . $possible_object_id . '][menu-item-url]" value="' . esc_attr( $item->url ) .'" />';111 $output .= '<input type="hidden" class="menu-item-target" name="menu-item[' . $possible_object_id . '][menu-item-target]" value="' . esc_attr( $item->target ) .'" />';112 $output .= '<input type="hidden" class="menu-item-attr_title" name="menu-item[' . $possible_object_id . '][menu-item-attr _title]" value="'. esc_attr( $item->attr_title ) .'" />';113 $output .= '<input type="hidden" class="menu-item-classes" name="menu-item[' . $possible_object_id . '][menu-item-classes]" value="' . esc_attr( implode( ' ', $item->classes ) ) .'" />';114 $output .= '<input type="hidden" class="menu-item-xfn" name="menu-item[' . $possible_object_id . '][menu-item-xfn]" value="' . esc_attr( $item->xfn ) .'" />';106 $output .= '<input type="hidden" class="menu-item-object" name="menu-item[' . $possible_object_id . '][menu-item-object]" value="' . esc_attr( $item->object ) . '" />'; 107 $output .= '<input type="hidden" class="menu-item-parent-id" name="menu-item[' . $possible_object_id . '][menu-item-parent-id]" value="' . esc_attr( $item->menu_item_parent ) . '" />'; 108 $output .= '<input type="hidden" class="menu-item-type" name="menu-item[' . $possible_object_id . '][menu-item-type]" value="' . esc_attr( $item->type ) . '" />'; 109 $output .= '<input type="hidden" class="menu-item-title" name="menu-item[' . $possible_object_id . '][menu-item-title]" value="' . htmlspecialchars( $item->title, ENT_QUOTES ) . '" />'; 110 $output .= '<input type="hidden" class="menu-item-url" name="menu-item[' . $possible_object_id . '][menu-item-url]" value="' . esc_attr( $item->url ) . '" />'; 111 $output .= '<input type="hidden" class="menu-item-target" name="menu-item[' . $possible_object_id . '][menu-item-target]" value="' . esc_attr( $item->target ) . '" />'; 112 $output .= '<input type="hidden" class="menu-item-attr_title" name="menu-item[' . $possible_object_id . '][menu-item-attr-title]" value="' . htmlspecialchars( $item->attr_title, ENT_QUOTES ) . '" />'; 113 $output .= '<input type="hidden" class="menu-item-classes" name="menu-item[' . $possible_object_id . '][menu-item-classes]" value="' . htmlspecialchars( implode( ' ', $item->classes ), ENT_QUOTES ) . '" />'; 114 $output .= '<input type="hidden" class="menu-item-xfn" name="menu-item[' . $possible_object_id . '][menu-item-xfn]" value="' . htmlspecialchars( $item->xfn, ENT_QUOTES ) . '" />'; 115 115 } 116 116 -
branches/4.7/src/wp-admin/includes/class-walker-nav-menu-edit.php
r38770 r62006 163 163 <label for="edit-menu-item-title-<?php echo $item_id; ?>"> 164 164 <?php _e( 'Navigation Label' ); ?><br /> 165 <input type="text" id="edit-menu-item-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-title" name="menu-item-title[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->title); ?>" />165 <input type="text" id="edit-menu-item-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-title" name="menu-item-title[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->title, ENT_QUOTES ); ?>" /> 166 166 </label> 167 167 </p> … … 169 169 <label for="edit-menu-item-attr-title-<?php echo $item_id; ?>"> 170 170 <?php _e( 'Title Attribute' ); ?><br /> 171 <input type="text" id="edit-menu-item-attr-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-attr-title" name="menu-item-attr-title[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->post_excerpt); ?>" />171 <input type="text" id="edit-menu-item-attr-title-<?php echo $item_id; ?>" class="widefat edit-menu-item-attr-title" name="menu-item-attr-title[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->post_excerpt, ENT_QUOTES ); ?>" /> 172 172 </label> 173 173 </p> … … 181 181 <label for="edit-menu-item-classes-<?php echo $item_id; ?>"> 182 182 <?php _e( 'CSS Classes (optional)' ); ?><br /> 183 <input type="text" id="edit-menu-item-classes-<?php echo $item_id; ?>" class="widefat code edit-menu-item-classes" name="menu-item-classes[<?php echo $item_id; ?>]" value="<?php echo esc_attr( implode(' ', $item->classes )); ?>" />183 <input type="text" id="edit-menu-item-classes-<?php echo $item_id; ?>" class="widefat code edit-menu-item-classes" name="menu-item-classes[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( implode( ' ', $item->classes ), ENT_QUOTES ); ?>" /> 184 184 </label> 185 185 </p> … … 187 187 <label for="edit-menu-item-xfn-<?php echo $item_id; ?>"> 188 188 <?php _e( 'Link Relationship (XFN)' ); ?><br /> 189 <input type="text" id="edit-menu-item-xfn-<?php echo $item_id; ?>" class="widefat code edit-menu-item-xfn" name="menu-item-xfn[<?php echo $item_id; ?>]" value="<?php echo esc_attr( $item->xfn); ?>" />189 <input type="text" id="edit-menu-item-xfn-<?php echo $item_id; ?>" class="widefat code edit-menu-item-xfn" name="menu-item-xfn[<?php echo $item_id; ?>]" value="<?php echo htmlspecialchars( $item->xfn, ENT_QUOTES ); ?>" /> 190 190 </label> 191 191 </p> -
branches/4.7/src/wp-admin/includes/file.php
r41459 r62006 764 764 continue; 765 765 766 // Don't extract invalid files: 767 if ( 0 !== validate_file( $file['filename'] ) ) { 768 continue; 769 } 770 766 771 $uncompressed_size += $file['size']; 767 772 -
branches/4.7/src/wp-includes/ID3/getid3.lib.php
r32979 r62006 524 524 // https://core.trac.wordpress.org/changeset/29378 525 525 $loader = libxml_disable_entity_loader(true); 526 $XMLobject = simplexml_load_string($XMLstring, 'SimpleXMLElement', LIBXML_NOENT);526 $XMLobject = simplexml_load_string($XMLstring, 'SimpleXMLElement', 0); 527 527 $return = self::SimpleXMLelement2array($XMLobject); 528 528 libxml_disable_entity_loader($loader); -
branches/4.7/src/wp-includes/class-wp-http-ixr-client.php
r37492 r62006 87 87 } 88 88 89 $response = wp_ remote_post($url, $args);89 $response = wp_safe_remote_post( $url, $args ); 90 90 91 91 if ( is_wp_error($response) ) { -
branches/4.7/src/wp-includes/js/wp-util.js
r37851 r62006 31 31 32 32 return function ( data ) { 33 compiled = compiled || _.template( $( '#tmpl-' + id ).html(), options ); 33 var el = document.querySelector( 'script#tmpl-' + id ); 34 if ( ! el ) { 35 throw new Error( 'Template not found: ' + '#tmpl-' + id ); 36 } 37 compiled = compiled || _.template( $( el ).html(), options ); 34 38 return compiled( data ); 35 39 }; -
branches/4.7/src/wp-includes/kses.php
r46916 r62006 541 541 $allowed_protocols = wp_allowed_protocols(); 542 542 $string = wp_kses_no_null( $string, array( 'slash_zero' => 'keep' ) ); 543 543 544 544 // Preserve leading and trailing whitespace. 545 545 $matches = array(); … … 553 553 $string = substr( $string, strlen( $lead ), -strlen( $trail ) ); 554 554 } 555 555 556 556 // Parse attribute name and value from input. 557 557 $split = preg_split( '/\s*=\s*/', $string, 2 ); … … 590 590 $vless = 'y'; 591 591 } 592 592 593 593 // Sanitize attribute by name. 594 594 wp_kses_attr_check( $name, $value, $string, $vless, $element, $allowed_html ); … … 1124 1124 $xhtml_slash = ''; 1125 1125 } 1126 1126 1127 1127 // Split it 1128 1128 $attrarr = wp_kses_hair_parse( $attr ); … … 1134 1134 array_unshift( $attrarr, $begin . $slash . $elname ); 1135 1135 array_push( $attrarr, $xhtml_slash . $end ); 1136 1136 1137 1137 return $attrarr; 1138 1138 } … … 1449 1449 $string = str_replace('&', '&', $string); 1450 1450 1451 // Change back the allowed entities in our entity whitelist 1452 $string = preg_replace_callback('/&([A-Za-z]{2,8}[0-9]{0,2});/', 'wp_kses_named_entities', $string); 1453 $string = preg_replace_callback('/&#(0*[0-9]{1,7});/', 'wp_kses_normalize_entities2', $string); 1454 $string = preg_replace_callback('/&#[Xx](0*[0-9A-Fa-f]{1,6});/', 'wp_kses_normalize_entities3', $string); 1451 $string = preg_replace_callback( '/&([A-Za-z]{2,8}[0-9]{0,2});/', 'wp_kses_named_entities', $string ); 1452 $string = preg_replace_callback( '/&#(0*+[1-9][0-9]{0,6});/', 'wp_kses_normalize_entities2', $string ); 1453 $string = preg_replace_callback( '/&#[Xx](0*+[1-9A-Fa-f][0-9A-Fa-f]{0,5});/', 'wp_kses_normalize_entities3', $string ); 1455 1454 1456 1455 return $string; -
branches/4.7/src/wp-includes/media.php
r56862 r62006 3127 3127 } 3128 3128 3129 if ( $post_parent ) {3129 if ( $post_parent && current_user_can( 'read_post', $attachment->post_parent ) ) { 3130 3130 $parent_type = get_post_type_object( $post_parent->post_type ); 3131 3131 … … 3134 3134 } 3135 3135 3136 if ( $parent_type && current_user_can( 'read_post', $attachment->post_parent )) {3136 if ( $parent_type ) { 3137 3137 $response['uploadedToTitle'] = $post_parent->post_title ? $post_parent->post_title : __( '(no title)' ); 3138 3138 } -
branches/4.7/src/wp-includes/nav-menu.php
r38928 r62006 434 434 } 435 435 436 if ( $args['menu-item-title'] == $original_title )436 if ( wp_unslash( $args['menu-item-title'] ) === $original_title ) { 437 437 $args['menu-item-title'] = ''; 438 438 -
branches/4.7/src/wp-includes/template-loader.php
r38755 r62006 71 71 * @param string $template The path of the template to include. 72 72 */ 73 if ( $template = apply_filters( 'template_include', $template ) ) { 74 include( $template ); 73 $template = apply_filters( 'template_include', $template ); 74 $is_stringy = is_string( $template ) || ( is_object( $template ) && method_exists( $template, '__toString' ) ); 75 $template = $is_stringy ? realpath( (string) $template ) : null; 76 if ( 77 is_string( $template ) && 78 ( str_ends_with( $template, '.php' ) || str_ends_with( $template, '.html' ) ) && 79 is_file( $template ) && 80 is_readable( $template ) 81 ) { 82 include $template; 75 83 } elseif ( current_user_can( 'switch_themes' ) ) { 76 84 $theme = wp_get_theme();
Note: See TracChangeset
for help on using the changeset viewer.