wp/wp-admin/includes/export.php
changeset 7 cf61fcea0001
parent 5 5e2f62d02dcd
child 9 177826044cd9
--- a/wp/wp-admin/includes/export.php	Tue Jun 09 11:14:17 2015 +0000
+++ b/wp/wp-admin/includes/export.php	Mon Oct 14 17:39:30 2019 +0200
@@ -18,9 +18,40 @@
 /**
  * Generates the WXR export file for download.
  *
+ * Default behavior is to export all content, however, note that post content will only
+ * be exported for post types with the `can_export` argument enabled. Any posts with the
+ * 'auto-draft' status will be skipped.
+ *
  * @since 2.1.0
  *
- * @param array $args Filters defining what should be included in the export.
+ * @global wpdb    $wpdb WordPress database abstraction object.
+ * @global WP_Post $post Global `$post`.
+ *
+ * @param array $args {
+ *     Optional. Arguments for generating the WXR export file for download. Default empty array.
+ *
+ *     @type string $content        Type of content to export. If set, only the post content of this post type
+ *                                  will be exported. Accepts 'all', 'post', 'page', 'attachment', or a defined
+ *                                  custom post. If an invalid custom post type is supplied, every post type for
+ *                                  which `can_export` is enabled will be exported instead. If a valid custom post
+ *                                  type is supplied but `can_export` is disabled, then 'posts' will be exported
+ *                                  instead. When 'all' is supplied, only post types with `can_export` enabled will
+ *                                  be exported. Default 'all'.
+ *     @type string $author         Author to export content for. Only used when `$content` is 'post', 'page', or
+ *                                  'attachment'. Accepts false (all) or a specific author ID. Default false (all).
+ *     @type string $category       Category (slug) to export content for. Used only when `$content` is 'post'. If
+ *                                  set, only post content assigned to `$category` will be exported. Accepts false
+ *                                  or a specific category slug. Default is false (all categories).
+ *     @type string $start_date     Start date to export content from. Expected date format is 'Y-m-d'. Used only
+ *                                  when `$content` is 'post', 'page' or 'attachment'. Default false (since the
+ *                                  beginning of time).
+ *     @type string $end_date       End date to export content to. Expected date format is 'Y-m-d'. Used only when
+ *                                  `$content` is 'post', 'page' or 'attachment'. Default false (latest publish date).
+ *     @type string $status         Post status to export posts for. Used only when `$content` is 'post' or 'page'.
+ *                                  Accepts false (all statuses except 'auto-draft'), or a specific status, i.e.
+ *                                  'publish', 'pending', 'draft', 'auto-draft', 'future', 'private', 'inherit', or
+ *                                  'trash'. Default false (all statuses except 'auto-draft').
+ * }
  */
 function export_wp( $args = array() ) {
 	global $wpdb, $post;
@@ -40,8 +71,21 @@
 	do_action( 'export_wp', $args );
 
 	$sitename = sanitize_key( get_bloginfo( 'name' ) );
-	if ( ! empty($sitename) ) $sitename .= '.';
-	$filename = $sitename . 'wordpress.' . date( 'Y-m-d' ) . '.xml';
+	if ( ! empty( $sitename ) ) {
+		$sitename .= '.';
+	}
+	$date = date( 'Y-m-d' );
+	$wp_filename = $sitename . 'wordpress.' . $date . '.xml';
+	/**
+	 * Filters the export filename.
+	 *
+	 * @since 4.4.0
+	 *
+	 * @param string $wp_filename The name of the file for download.
+	 * @param string $sitename    The site name.
+	 * @param string $date        Today's date, formatted.
+	 */
+	$filename = apply_filters( 'export_wp_filename', $wp_filename, $sitename, $date );
 
 	header( 'Content-Description: File Transfer' );
 	header( 'Content-Disposition: attachment; filename=' . $filename );
@@ -72,7 +116,7 @@
 		}
 	}
 
-	if ( 'post' == $args['content'] || 'page' == $args['content'] ) {
+	if ( 'post' == $args['content'] || 'page' == $args['content'] || 'attachment' == $args['content'] ) {
 		if ( $args['author'] )
 			$where .= $wpdb->prepare( " AND {$wpdb->posts}.post_author = %d", $args['author'] );
 
@@ -130,9 +174,9 @@
 	 * @return string
 	 */
 	function wxr_cdata( $str ) {
-		if ( seems_utf8( $str ) == false )
+		if ( ! seems_utf8( $str ) ) {
 			$str = utf8_encode( $str );
-
+		}
 		// $str = ent2ncr(esc_html($str));
 		$str = '<![CDATA[' . str_replace( ']]>', ']]]]><![CDATA[>', $str ) . ']]>';
 
@@ -166,7 +210,7 @@
 		if ( empty( $category->name ) )
 			return;
 
-		echo '<wp:cat_name>' . wxr_cdata( $category->name ) . '</wp:cat_name>';
+		echo '<wp:cat_name>' . wxr_cdata( $category->name ) . "</wp:cat_name>\n";
 	}
 
 	/**
@@ -180,7 +224,7 @@
 		if ( empty( $category->description ) )
 			return;
 
-		echo '<wp:category_description>' . wxr_cdata( $category->description ) . '</wp:category_description>';
+		echo '<wp:category_description>' . wxr_cdata( $category->description ) . "</wp:category_description>\n";
 	}
 
 	/**
@@ -194,7 +238,7 @@
 		if ( empty( $tag->name ) )
 			return;
 
-		echo '<wp:tag_name>' . wxr_cdata( $tag->name ) . '</wp:tag_name>';
+		echo '<wp:tag_name>' . wxr_cdata( $tag->name ) . "</wp:tag_name>\n";
 	}
 
 	/**
@@ -208,7 +252,7 @@
 		if ( empty( $tag->description ) )
 			return;
 
-		echo '<wp:tag_description>' . wxr_cdata( $tag->description ) . '</wp:tag_description>';
+		echo '<wp:tag_description>' . wxr_cdata( $tag->description ) . "</wp:tag_description>\n";
 	}
 
 	/**
@@ -222,7 +266,7 @@
 		if ( empty( $term->name ) )
 			return;
 
-		echo '<wp:term_name>' . wxr_cdata( $term->name ) . '</wp:term_name>';
+		echo '<wp:term_name>' . wxr_cdata( $term->name ) . "</wp:term_name>\n";
 	}
 
 	/**
@@ -236,7 +280,38 @@
 		if ( empty( $term->description ) )
 			return;
 
-		echo '<wp:term_description>' . wxr_cdata( $term->description ) . '</wp:term_description>';
+		echo "\t\t<wp:term_description>" . wxr_cdata( $term->description ) . "</wp:term_description>\n";
+	}
+
+	/**
+	 * Output term meta XML tags for a given term object.
+	 *
+	 * @since 4.6.0
+	 *
+	 * @param WP_Term $term Term object.
+	 */
+	function wxr_term_meta( $term ) {
+		global $wpdb;
+
+		$termmeta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->termmeta WHERE term_id = %d", $term->term_id ) );
+
+		foreach ( $termmeta as $meta ) {
+			/**
+			 * Filters whether to selectively skip term meta used for WXR exports.
+			 *
+			 * Returning a truthy value to the filter will skip the current meta
+			 * object from being exported.
+			 *
+			 * @since 4.6.0
+			 *
+			 * @param bool   $skip     Whether to skip the current piece of term meta. Default false.
+			 * @param string $meta_key Current meta key.
+			 * @param object $meta     Current meta object.
+			 */
+			if ( ! apply_filters( 'wxr_export_skip_termmeta', false, $meta->meta_key, $meta ) ) {
+				printf( "\t\t<wp:termmeta>\n\t\t\t<wp:meta_key>%s</wp:meta_key>\n\t\t\t<wp:meta_value>%s</wp:meta_value>\n\t\t</wp:termmeta>\n", wxr_cdata( $meta->meta_key ), wxr_cdata( $meta->meta_value ) );
+			}
+		}
 	}
 
 	/**
@@ -244,6 +319,8 @@
 	 *
 	 * @since 3.1.0
 	 *
+	 * @global wpdb $wpdb WordPress database abstraction object.
+	 *
 	 * @param array $post_ids Array of post IDs to filter the query by. Optional.
 	 */
 	function wxr_authors_list( array $post_ids = null ) {
@@ -265,18 +342,18 @@
 
 		foreach ( $authors as $author ) {
 			echo "\t<wp:author>";
-			echo '<wp:author_id>' . $author->ID . '</wp:author_id>';
-			echo '<wp:author_login>' . $author->user_login . '</wp:author_login>';
-			echo '<wp:author_email>' . $author->user_email . '</wp:author_email>';
+			echo '<wp:author_id>' . intval( $author->ID ) . '</wp:author_id>';
+			echo '<wp:author_login>' . wxr_cdata( $author->user_login ) . '</wp:author_login>';
+			echo '<wp:author_email>' . wxr_cdata( $author->user_email ) . '</wp:author_email>';
 			echo '<wp:author_display_name>' . wxr_cdata( $author->display_name ) . '</wp:author_display_name>';
-			echo '<wp:author_first_name>' . wxr_cdata( $author->user_firstname ) . '</wp:author_first_name>';
-			echo '<wp:author_last_name>' . wxr_cdata( $author->user_lastname ) . '</wp:author_last_name>';
+			echo '<wp:author_first_name>' . wxr_cdata( $author->first_name ) . '</wp:author_first_name>';
+			echo '<wp:author_last_name>' . wxr_cdata( $author->last_name ) . '</wp:author_last_name>';
 			echo "</wp:author>\n";
 		}
 	}
 
 	/**
-	 * Ouput all navigation menu terms
+	 * Output all navigation menu terms
 	 *
 	 * @since 3.1.0
 	 */
@@ -286,7 +363,10 @@
 			return;
 
 		foreach ( $nav_menus as $menu ) {
-			echo "\t<wp:term><wp:term_id>{$menu->term_id}</wp:term_id><wp:term_taxonomy>nav_menu</wp:term_taxonomy><wp:term_slug>{$menu->slug}</wp:term_slug>";
+			echo "\t<wp:term>";
+			echo '<wp:term_id>' . intval( $menu->term_id ) . '</wp:term_id>';
+			echo '<wp:term_taxonomy>nav_menu</wp:term_taxonomy>';
+			echo '<wp:term_slug>' . wxr_cdata( $menu->slug ) . '</wp:term_slug>';
 			wxr_term_name( $menu );
 			echo "</wp:term>\n";
 		}
@@ -310,6 +390,12 @@
 		}
 	}
 
+	/**
+	 *
+	 * @param bool   $return_me
+	 * @param string $meta_key
+	 * @return bool
+	 */
 	function wxr_filter_postmeta( $return_me, $meta_key ) {
 		if ( '_edit_lock' == $meta_key )
 			$return_me = true;
@@ -359,13 +445,34 @@
 <?php wxr_authors_list( $post_ids ); ?>
 
 <?php foreach ( $cats as $c ) : ?>
-	<wp:category><wp:term_id><?php echo $c->term_id ?></wp:term_id><wp:category_nicename><?php echo $c->slug; ?></wp:category_nicename><wp:category_parent><?php echo $c->parent ? $cats[$c->parent]->slug : ''; ?></wp:category_parent><?php wxr_cat_name( $c ); ?><?php wxr_category_description( $c ); ?></wp:category>
+	<wp:category>
+		<wp:term_id><?php echo intval( $c->term_id ); ?></wp:term_id>
+		<wp:category_nicename><?php echo wxr_cdata( $c->slug ); ?></wp:category_nicename>
+		<wp:category_parent><?php echo wxr_cdata( $c->parent ? $cats[$c->parent]->slug : '' ); ?></wp:category_parent>
+		<?php wxr_cat_name( $c );
+		wxr_category_description( $c );
+		wxr_term_meta( $c ); ?>
+	</wp:category>
 <?php endforeach; ?>
 <?php foreach ( $tags as $t ) : ?>
-	<wp:tag><wp:term_id><?php echo $t->term_id ?></wp:term_id><wp:tag_slug><?php echo $t->slug; ?></wp:tag_slug><?php wxr_tag_name( $t ); ?><?php wxr_tag_description( $t ); ?></wp:tag>
+	<wp:tag>
+		<wp:term_id><?php echo intval( $t->term_id ); ?></wp:term_id>
+		<wp:tag_slug><?php echo wxr_cdata( $t->slug ); ?></wp:tag_slug>
+		<?php wxr_tag_name( $t );
+		wxr_tag_description( $t );
+		wxr_term_meta( $t ); ?>
+	</wp:tag>
 <?php endforeach; ?>
 <?php foreach ( $terms as $t ) : ?>
-	<wp:term><wp:term_id><?php echo $t->term_id ?></wp:term_id><wp:term_taxonomy><?php echo $t->taxonomy; ?></wp:term_taxonomy><wp:term_slug><?php echo $t->slug; ?></wp:term_slug><wp:term_parent><?php echo $t->parent ? $terms[$t->parent]->slug : ''; ?></wp:term_parent><?php wxr_term_name( $t ); ?><?php wxr_term_description( $t ); ?></wp:term>
+	<wp:term>
+		<wp:term_id><?php echo wxr_cdata( $t->term_id ); ?></wp:term_id>
+		<wp:term_taxonomy><?php echo wxr_cdata( $t->taxonomy ); ?></wp:term_taxonomy>
+		<wp:term_slug><?php echo wxr_cdata( $t->slug ); ?></wp:term_slug>
+		<wp:term_parent><?php echo wxr_cdata( $t->parent ? $terms[$t->parent]->slug : '' ); ?></wp:term_parent>
+		<?php wxr_term_name( $t );
+		wxr_term_description( $t );
+		wxr_term_meta( $t ); ?>
+	</wp:term>
 <?php endforeach; ?>
 <?php if ( 'all' == $args['content'] ) wxr_nav_menu_terms(); ?>
 
@@ -375,6 +482,9 @@
 	?>
 
 <?php if ( $post_ids ) {
+	/**
+	 * @global WP_Query $wp_query
+	 */
 	global $wp_query;
 
 	// Fake being in the loop.
@@ -402,7 +512,7 @@
 		<description></description>
 		<content:encoded><?php
 			/**
-			 * Filter the post content used for WXR exports.
+			 * Filters the post content used for WXR exports.
 			 *
 			 * @since 2.5.0
 			 *
@@ -412,7 +522,7 @@
 		?></content:encoded>
 		<excerpt:encoded><?php
 			/**
-			 * Filter the post excerpt used for WXR exports.
+			 * Filters the post excerpt used for WXR exports.
 			 *
 			 * @since 2.6.0
 			 *
@@ -420,26 +530,26 @@
 			 */
 			echo wxr_cdata( apply_filters( 'the_excerpt_export', $post->post_excerpt ) );
 		?></excerpt:encoded>
-		<wp:post_id><?php echo $post->ID; ?></wp:post_id>
-		<wp:post_date><?php echo $post->post_date; ?></wp:post_date>
-		<wp:post_date_gmt><?php echo $post->post_date_gmt; ?></wp:post_date_gmt>
-		<wp:comment_status><?php echo $post->comment_status; ?></wp:comment_status>
-		<wp:ping_status><?php echo $post->ping_status; ?></wp:ping_status>
-		<wp:post_name><?php echo $post->post_name; ?></wp:post_name>
-		<wp:status><?php echo $post->post_status; ?></wp:status>
-		<wp:post_parent><?php echo $post->post_parent; ?></wp:post_parent>
-		<wp:menu_order><?php echo $post->menu_order; ?></wp:menu_order>
-		<wp:post_type><?php echo $post->post_type; ?></wp:post_type>
-		<wp:post_password><?php echo $post->post_password; ?></wp:post_password>
-		<wp:is_sticky><?php echo $is_sticky; ?></wp:is_sticky>
+		<wp:post_id><?php echo intval( $post->ID ); ?></wp:post_id>
+		<wp:post_date><?php echo wxr_cdata( $post->post_date ); ?></wp:post_date>
+		<wp:post_date_gmt><?php echo wxr_cdata( $post->post_date_gmt ); ?></wp:post_date_gmt>
+		<wp:comment_status><?php echo wxr_cdata( $post->comment_status ); ?></wp:comment_status>
+		<wp:ping_status><?php echo wxr_cdata( $post->ping_status ); ?></wp:ping_status>
+		<wp:post_name><?php echo wxr_cdata( $post->post_name ); ?></wp:post_name>
+		<wp:status><?php echo wxr_cdata( $post->post_status ); ?></wp:status>
+		<wp:post_parent><?php echo intval( $post->post_parent ); ?></wp:post_parent>
+		<wp:menu_order><?php echo intval( $post->menu_order ); ?></wp:menu_order>
+		<wp:post_type><?php echo wxr_cdata( $post->post_type ); ?></wp:post_type>
+		<wp:post_password><?php echo wxr_cdata( $post->post_password ); ?></wp:post_password>
+		<wp:is_sticky><?php echo intval( $is_sticky ); ?></wp:is_sticky>
 <?php	if ( $post->post_type == 'attachment' ) : ?>
-		<wp:attachment_url><?php echo wp_get_attachment_url( $post->ID ); ?></wp:attachment_url>
+		<wp:attachment_url><?php echo wxr_cdata( wp_get_attachment_url( $post->ID ) ); ?></wp:attachment_url>
 <?php 	endif; ?>
 <?php 	wxr_post_taxonomy(); ?>
 <?php	$postmeta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->postmeta WHERE post_id = %d", $post->ID ) );
 		foreach ( $postmeta as $meta ) :
 			/**
-			 * Filter whether to selectively skip post meta used for WXR exports.
+			 * Filters whether to selectively skip post meta used for WXR exports.
 			 *
 			 * Returning a truthy value to the filter will skip the current meta
 			 * object from being exported.
@@ -454,30 +564,31 @@
 				continue;
 		?>
 		<wp:postmeta>
-			<wp:meta_key><?php echo $meta->meta_key; ?></wp:meta_key>
+			<wp:meta_key><?php echo wxr_cdata( $meta->meta_key ); ?></wp:meta_key>
 			<wp:meta_value><?php echo wxr_cdata( $meta->meta_value ); ?></wp:meta_value>
 		</wp:postmeta>
 <?php	endforeach;
 
-		$comments = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_approved <> 'spam'", $post->ID ) );
+		$_comments = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_approved <> 'spam'", $post->ID ) );
+		$comments = array_map( 'get_comment', $_comments );
 		foreach ( $comments as $c ) : ?>
 		<wp:comment>
-			<wp:comment_id><?php echo $c->comment_ID; ?></wp:comment_id>
+			<wp:comment_id><?php echo intval( $c->comment_ID ); ?></wp:comment_id>
 			<wp:comment_author><?php echo wxr_cdata( $c->comment_author ); ?></wp:comment_author>
-			<wp:comment_author_email><?php echo $c->comment_author_email; ?></wp:comment_author_email>
+			<wp:comment_author_email><?php echo wxr_cdata( $c->comment_author_email ); ?></wp:comment_author_email>
 			<wp:comment_author_url><?php echo esc_url_raw( $c->comment_author_url ); ?></wp:comment_author_url>
-			<wp:comment_author_IP><?php echo $c->comment_author_IP; ?></wp:comment_author_IP>
-			<wp:comment_date><?php echo $c->comment_date; ?></wp:comment_date>
-			<wp:comment_date_gmt><?php echo $c->comment_date_gmt; ?></wp:comment_date_gmt>
+			<wp:comment_author_IP><?php echo wxr_cdata( $c->comment_author_IP ); ?></wp:comment_author_IP>
+			<wp:comment_date><?php echo wxr_cdata( $c->comment_date ); ?></wp:comment_date>
+			<wp:comment_date_gmt><?php echo wxr_cdata( $c->comment_date_gmt ); ?></wp:comment_date_gmt>
 			<wp:comment_content><?php echo wxr_cdata( $c->comment_content ) ?></wp:comment_content>
-			<wp:comment_approved><?php echo $c->comment_approved; ?></wp:comment_approved>
-			<wp:comment_type><?php echo $c->comment_type; ?></wp:comment_type>
-			<wp:comment_parent><?php echo $c->comment_parent; ?></wp:comment_parent>
-			<wp:comment_user_id><?php echo $c->user_id; ?></wp:comment_user_id>
+			<wp:comment_approved><?php echo wxr_cdata( $c->comment_approved ); ?></wp:comment_approved>
+			<wp:comment_type><?php echo wxr_cdata( $c->comment_type ); ?></wp:comment_type>
+			<wp:comment_parent><?php echo intval( $c->comment_parent ); ?></wp:comment_parent>
+			<wp:comment_user_id><?php echo intval( $c->user_id ); ?></wp:comment_user_id>
 <?php		$c_meta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->commentmeta WHERE comment_id = %d", $c->comment_ID ) );
 			foreach ( $c_meta as $meta ) :
 				/**
-				 * Filter whether to selectively skip comment meta used for WXR exports.
+				 * Filters whether to selectively skip comment meta used for WXR exports.
 				 *
 				 * Returning a truthy value to the filter will skip the current meta
 				 * object from being exported.
@@ -493,7 +604,7 @@
 				}
 			?>
 			<wp:commentmeta>
-				<wp:meta_key><?php echo $meta->meta_key; ?></wp:meta_key>
+				<wp:meta_key><?php echo wxr_cdata( $meta->meta_key ); ?></wp:meta_key>
 				<wp:meta_value><?php echo wxr_cdata( $meta->meta_value ); ?></wp:meta_value>
 			</wp:commentmeta>
 <?php		endforeach; ?>