--- a/wp/wp-admin/post.php Tue Jun 09 11:14:17 2015 +0000
+++ b/wp/wp-admin/post.php Mon Oct 14 17:39:30 2019 +0200
@@ -23,6 +23,11 @@
else
$post_id = $post_ID = 0;
+/**
+ * @global string $post_type
+ * @global object $post_type_object
+ * @global WP_Post $post
+ */
global $post_type, $post_type_object, $post;
if ( $post_id )
@@ -33,55 +38,6 @@
$post_type_object = get_post_type_object( $post_type );
}
-/**
- * Redirect to previous page.
- *
- * @param int $post_id Optional. Post ID.
- */
-function redirect_post($post_id = '') {
- if ( isset($_POST['save']) || isset($_POST['publish']) ) {
- $status = get_post_status( $post_id );
-
- if ( isset( $_POST['publish'] ) ) {
- switch ( $status ) {
- case 'pending':
- $message = 8;
- break;
- case 'future':
- $message = 9;
- break;
- default:
- $message = 6;
- }
- } else {
- $message = 'draft' == $status ? 10 : 1;
- }
-
- $location = add_query_arg( 'message', $message, get_edit_post_link( $post_id, 'url' ) );
- } elseif ( isset($_POST['addmeta']) && $_POST['addmeta'] ) {
- $location = add_query_arg( 'message', 2, wp_get_referer() );
- $location = explode('#', $location);
- $location = $location[0] . '#postcustom';
- } elseif ( isset($_POST['deletemeta']) && $_POST['deletemeta'] ) {
- $location = add_query_arg( 'message', 3, wp_get_referer() );
- $location = explode('#', $location);
- $location = $location[0] . '#postcustom';
- } else {
- $location = add_query_arg( 'message', 4, get_edit_post_link( $post_id, 'url' ) );
- }
-
- /**
- * Filter the post redirect destination URL.
- *
- * @since 2.9.0
- *
- * @param string $location The destination URL.
- * @param int $post_id The post ID.
- */
- wp_redirect( apply_filters( 'redirect_post_location', $location, $post_id ) );
- exit;
-}
-
if ( isset( $_POST['deletepost'] ) )
$action = 'delete';
elseif ( isset($_POST['wp-preview']) && 'dopreview' == $_POST['wp-preview'] )
@@ -115,8 +71,9 @@
if ( ! wp_verify_nonce( $nonce, 'add-post' ) )
$error_msg = __( 'Unable to submit this form, please refresh and try again.' );
- if ( ! current_user_can( 'edit_posts' ) )
- $error_msg = __( 'Oops, you don’t have access to add new drafts.' );
+ if ( ! current_user_can( get_post_type_object( 'post' )->cap->create_posts ) ) {
+ exit;
+ }
if ( $error_msg )
return wp_dashboard_quick_press( $error_msg );
@@ -124,8 +81,8 @@
$post = get_post( $_REQUEST['post_ID'] );
check_admin_referer( 'add-' . $post->post_type );
- $_POST['comment_status'] = get_option( 'default_comment_status' );
- $_POST['ping_status'] = get_option( 'default_ping_status' );
+ $_POST['comment_status'] = get_default_comment_status( $post->post_type );
+ $_POST['ping_status'] = get_default_comment_status( $post->post_type, 'pingback' );
edit_post();
wp_dashboard_quick_press();
@@ -150,15 +107,20 @@
wp_die( __( 'You attempted to edit an item that doesn’t exist. Perhaps it was deleted?' ) );
if ( ! $post_type_object )
- wp_die( __( 'Unknown post type.' ) );
+ wp_die( __( 'Invalid post type.' ) );
+
+ if ( ! in_array( $typenow, get_post_types( array( 'show_ui' => true ) ) ) ) {
+ wp_die( __( 'Sorry, you are not allowed to edit posts in this post type.' ) );
+ }
if ( ! current_user_can( 'edit_post', $post_id ) )
- wp_die( __( 'You are not allowed to edit this item.' ) );
+ wp_die( __( 'Sorry, you are not allowed to edit this item.' ) );
if ( 'trash' == $post->post_status )
wp_die( __( 'You can’t edit this item because it is in the Trash. Please restore it and try again.' ) );
if ( ! empty( $_GET['get-post-lock'] ) ) {
+ check_admin_referer( 'lock-post_' . $post_id );
wp_set_post_lock( $post_id );
wp_redirect( get_edit_post_link( $post_id, 'url' ) );
exit();
@@ -182,6 +144,18 @@
$post_new_file = "post-new.php?post_type=$post_type";
}
+ /**
+ * Allows replacement of the editor.
+ *
+ * @since 4.9.0
+ *
+ * @param boolean Whether to replace the editor. Default false.
+ * @param object $post Post object.
+ */
+ if ( apply_filters( 'replace_editor', false, $post ) === true ) {
+ break;
+ }
+
if ( ! wp_check_post_lock( $post->ID ) ) {
$active_post_lock = wp_set_post_lock( $post->ID );
@@ -189,17 +163,6 @@
wp_enqueue_script('autosave');
}
- if ( is_multisite() ) {
- add_action( 'admin_footer', '_admin_notice_post_locked' );
- } else {
- $check_users = get_users( array( 'fields' => 'ID', 'number' => 2 ) );
-
- if ( count( $check_users ) > 1 )
- add_action( 'admin_footer', '_admin_notice_post_locked' );
-
- unset( $check_users );
- }
-
$title = $post_type_object->labels->edit_item;
$post = get_post($post_id, OBJECT, 'edit');
@@ -232,7 +195,7 @@
// Session cookie flag that the post was saved
if ( isset( $_COOKIE['wp-saving-post'] ) && $_COOKIE['wp-saving-post'] === $post_id . '-check' ) {
- setcookie( 'wp-saving-post', $post_id . '-saved', time() + DAY_IN_SECONDS );
+ setcookie( 'wp-saving-post', $post_id . '-saved', time() + DAY_IN_SECONDS, ADMIN_COOKIE_PATH, COOKIE_DOMAIN, is_ssl() );
}
redirect_post($post_id); // Send user on their way while we keep working
@@ -246,10 +209,10 @@
wp_die( __( 'The item you are trying to move to the Trash no longer exists.' ) );
if ( ! $post_type_object )
- wp_die( __( 'Unknown post type.' ) );
+ wp_die( __( 'Invalid post type.' ) );
if ( ! current_user_can( 'delete_post', $post_id ) )
- wp_die( __( 'You are not allowed to move this item to the Trash.' ) );
+ wp_die( __( 'Sorry, you are not allowed to move this item to the Trash.' ) );
if ( $user_id = wp_check_post_lock( $post_id ) ) {
$user = get_userdata( $user_id );
@@ -269,10 +232,10 @@
wp_die( __( 'The item you are trying to restore from the Trash no longer exists.' ) );
if ( ! $post_type_object )
- wp_die( __( 'Unknown post type.' ) );
+ wp_die( __( 'Invalid post type.' ) );
if ( ! current_user_can( 'delete_post', $post_id ) )
- wp_die( __( 'You are not allowed to move this item out of the Trash.' ) );
+ wp_die( __( 'Sorry, you are not allowed to restore this item from the Trash.' ) );
if ( ! wp_untrash_post( $post_id ) )
wp_die( __( 'Error in restoring from Trash.' ) );
@@ -287,18 +250,17 @@
wp_die( __( 'This item has already been deleted.' ) );
if ( ! $post_type_object )
- wp_die( __( 'Unknown post type.' ) );
+ wp_die( __( 'Invalid post type.' ) );
if ( ! current_user_can( 'delete_post', $post_id ) )
- wp_die( __( 'You are not allowed to delete this item.' ) );
+ wp_die( __( 'Sorry, you are not allowed to delete this item.' ) );
- $force = ! EMPTY_TRASH_DAYS;
if ( $post->post_type == 'attachment' ) {
- $force = ( $force || ! MEDIA_TRASH );
+ $force = ( ! MEDIA_TRASH );
if ( ! wp_delete_attachment( $post_id, $force ) )
wp_die( __( 'Error in deleting.' ) );
} else {
- if ( ! wp_delete_post( $post_id, $force ) )
+ if ( ! wp_delete_post( $post_id, true ) )
wp_die( __( 'Error in deleting.' ) );
}
@@ -314,6 +276,17 @@
exit();
default:
+ /**
+ * Fires for a given custom post action request.
+ *
+ * The dynamic portion of the hook name, `$action`, refers to the custom post action.
+ *
+ * @since 4.6.0
+ *
+ * @param int $post_id Post ID sent with the request.
+ */
+ do_action( "post_action_{$action}", $post_id );
+
wp_redirect( admin_url('edit.php') );
exit();
} // end switch