diff -r be944660c56a -r 3d72ae0968f4 wp/wp-admin/includes/misc.php --- a/wp/wp-admin/includes/misc.php Wed Sep 21 18:19:35 2022 +0200 +++ b/wp/wp-admin/includes/misc.php Tue Sep 27 16:37:53 2022 +0200 @@ -74,16 +74,20 @@ $markerdata = explode( "\n", implode( '', file( $filename ) ) ); $state = false; + foreach ( $markerdata as $markerline ) { if ( false !== strpos( $markerline, '# END ' . $marker ) ) { $state = false; } + if ( $state ) { if ( '#' === substr( $markerline, 0, 1 ) ) { continue; } + $result[] = $markerline; } + if ( false !== strpos( $markerline, '# BEGIN ' . $marker ) ) { $state = true; } @@ -118,6 +122,7 @@ // Make sure the file is created with a minimum set of permissions. $perms = fileperms( $filename ); + if ( $perms ) { chmod( $filename, $perms | 0644 ); } @@ -142,6 +147,7 @@ ); $instructions = explode( "\n", $instructions ); + foreach ( $instructions as $line => $text ) { $instructions[ $line ] = '# ' . $text; } @@ -166,6 +172,7 @@ $end_marker = "# END {$marker}"; $fp = fopen( $filename, 'r+' ); + if ( ! $fp ) { return false; } @@ -174,6 +181,7 @@ flock( $fp, LOCK_EX ); $lines = array(); + while ( ! feof( $fp ) ) { $lines[] = rtrim( fgets( $fp ), "\r\n" ); } @@ -184,6 +192,7 @@ $existing_lines = array(); $found_marker = false; $found_end_marker = false; + foreach ( $lines as $line ) { if ( ! $found_marker && false !== strpos( $line, $start_marker ) ) { $found_marker = true; @@ -192,6 +201,7 @@ $found_end_marker = true; continue; } + if ( ! $found_marker ) { $pre_lines[] = $line; } elseif ( $found_marker && $found_end_marker ) { @@ -224,9 +234,11 @@ // Write to the start of the file, and truncate it to that length. fseek( $fp, 0 ); $bytes = fwrite( $fp, $new_file_data ); + if ( $bytes ) { ftruncate( $fp, ftell( $fp ) ); } + fflush( $fp ); flock( $fp, LOCK_UN ); fclose( $fp ); @@ -247,12 +259,12 @@ * @return bool|null True on write success, false on failure. Null in multisite. */ function save_mod_rewrite_rules() { + global $wp_rewrite; + if ( is_multisite() ) { return; } - global $wp_rewrite; - // Ensure get_home_path() is declared. require_once ABSPATH . 'wp-admin/includes/file.php'; @@ -263,9 +275,12 @@ * If the file doesn't already exist check for write access to the directory * and whether we have some rules. Else check for write access to the file. */ - if ( ( ! file_exists( $htaccess_file ) && is_writable( $home_path ) && $wp_rewrite->using_mod_rewrite_permalinks() ) || is_writable( $htaccess_file ) ) { + if ( ! file_exists( $htaccess_file ) && is_writable( $home_path ) && $wp_rewrite->using_mod_rewrite_permalinks() + || is_writable( $htaccess_file ) + ) { if ( got_mod_rewrite() ) { $rules = explode( "\n", $wp_rewrite->mod_rewrite_rules() ); + return insert_with_markers( $htaccess_file, 'WordPress', $rules ); } } @@ -284,12 +299,12 @@ * @return bool|null True on write success, false on failure. Null in multisite. */ function iis7_save_url_rewrite_rules() { + global $wp_rewrite; + if ( is_multisite() ) { return; } - global $wp_rewrite; - // Ensure get_home_path() is declared. require_once ABSPATH . 'wp-admin/includes/file.php'; @@ -297,19 +312,24 @@ $web_config_file = $home_path . 'web.config'; // Using win_is_writable() instead of is_writable() because of a bug in Windows PHP. - if ( iis7_supports_permalinks() && ( ( ! file_exists( $web_config_file ) && win_is_writable( $home_path ) && $wp_rewrite->using_mod_rewrite_permalinks() ) || win_is_writable( $web_config_file ) ) ) { + if ( iis7_supports_permalinks() + && ( ! file_exists( $web_config_file ) && win_is_writable( $home_path ) && $wp_rewrite->using_mod_rewrite_permalinks() + || win_is_writable( $web_config_file ) ) + ) { $rule = $wp_rewrite->iis7_url_rewrite_rules( false ); + if ( ! empty( $rule ) ) { return iis7_add_rewrite_rule( $web_config_file, $rule ); } else { return iis7_delete_rewrite_rule( $web_config_file ); } } + return false; } /** - * Update the "recently-edited" file for the plugin or theme editor. + * Updates the "recently-edited" file for the plugin or theme file editor. * * @since 1.5.0 * @@ -317,22 +337,25 @@ */ function update_recently_edited( $file ) { $oldfiles = (array) get_option( 'recently_edited' ); + if ( $oldfiles ) { $oldfiles = array_reverse( $oldfiles ); $oldfiles[] = $file; $oldfiles = array_reverse( $oldfiles ); $oldfiles = array_unique( $oldfiles ); + if ( 5 < count( $oldfiles ) ) { array_pop( $oldfiles ); } } else { $oldfiles[] = $file; } + update_option( 'recently_edited', $oldfiles ); } /** - * Makes a tree structure for the theme editor's file list. + * Makes a tree structure for the theme file editor's file list. * * @since 4.9.0 * @access private @@ -342,19 +365,23 @@ */ function wp_make_theme_file_tree( $allowed_files ) { $tree_list = array(); + foreach ( $allowed_files as $file_name => $absolute_filename ) { $list = explode( '/', $file_name ); $last_dir = &$tree_list; + foreach ( $list as $dir ) { $last_dir =& $last_dir[ $dir ]; } + $last_dir = $file_name; } + return $tree_list; } /** - * Outputs the formatted file list for the theme editor. + * Outputs the formatted file list for the theme file editor. * * @since 4.9.0 * @access private @@ -374,8 +401,10 @@ if ( is_array( $tree ) ) { $index = 0; $size = count( $tree ); + foreach ( $tree as $label => $theme_file ) : $index++; + if ( ! is_array( $theme_file ) ) { wp_print_theme_file_tree( $theme_file, $level, $index, $size ); continue; @@ -408,6 +437,7 @@ aria-posinset=""> (' . esc_html( $filename ) . ')'; } @@ -425,7 +455,7 @@ } /** - * Makes a tree structure for the plugin editor's file list. + * Makes a tree structure for the plugin file editor's file list. * * @since 4.9.0 * @access private @@ -435,19 +465,23 @@ */ function wp_make_plugin_file_tree( $plugin_editable_files ) { $tree_list = array(); + foreach ( $plugin_editable_files as $plugin_file ) { $list = explode( '/', preg_replace( '#^.+?/#', '', $plugin_file ) ); $last_dir = &$tree_list; + foreach ( $list as $dir ) { $last_dir =& $last_dir[ $dir ]; } + $last_dir = $plugin_file; } + return $tree_list; } /** - * Outputs the formatted file list for the plugin editor. + * Outputs the formatted file list for the plugin file editor. * * @since 4.9.0 * @access private @@ -460,11 +494,14 @@ */ function wp_print_plugin_file_tree( $tree, $label = '', $level = 2, $size = 1, $index = 1 ) { global $file, $plugin; + if ( is_array( $tree ) ) { $index = 0; $size = count( $tree ); + foreach ( $tree as $label => $plugin_file ) : $index++; + if ( ! is_array( $plugin_file ) ) { wp_print_plugin_file_tree( $plugin_file, $label, $level, $index, $size ); continue; @@ -529,7 +566,7 @@ /** - * Resets global variables based on $_GET and $_POST + * Resets global variables based on $_GET and $_POST. * * This function resets global variables based on the names passed * in the $vars array to the value of $_POST[$var] or $_GET[$var] or '' @@ -568,6 +605,7 @@ $message = $message->get_error_message(); } } + echo "
$message
\n"; wp_ob_end_flush_all(); flush(); @@ -592,18 +630,20 @@ $count = count( $tokens ); $functions = array(); $ignore_functions = array(); + for ( $t = 0; $t < $count - 2; $t++ ) { if ( ! is_array( $tokens[ $t ] ) ) { continue; } - if ( T_STRING == $tokens[ $t ][0] && ( '(' === $tokens[ $t + 1 ] || '(' === $tokens[ $t + 2 ] ) ) { + if ( T_STRING === $tokens[ $t ][0] && ( '(' === $tokens[ $t + 1 ] || '(' === $tokens[ $t + 2 ] ) ) { // If it's a function or class defined locally, there's not going to be any docs available. if ( ( isset( $tokens[ $t - 2 ][1] ) && in_array( $tokens[ $t - 2 ][1], array( 'function', 'class' ), true ) ) - || ( isset( $tokens[ $t - 2 ][0] ) && T_OBJECT_OPERATOR == $tokens[ $t - 1 ][0] ) + || ( isset( $tokens[ $t - 2 ][0] ) && T_OBJECT_OPERATOR === $tokens[ $t - 1 ][0] ) ) { $ignore_functions[] = $tokens[ $t ][1]; } + // Add this to our stack of unique references. $functions[] = $tokens[ $t ][1]; } @@ -624,10 +664,12 @@ $ignore_functions = array_unique( $ignore_functions ); $out = array(); + foreach ( $functions as $function ) { if ( in_array( $function, $ignore_functions, true ) ) { continue; } + $out[] = $function; } @@ -640,150 +682,163 @@ * @since 2.8.0 */ function set_screen_options() { - - if ( isset( $_POST['wp_screen_options'] ) && is_array( $_POST['wp_screen_options'] ) ) { - check_admin_referer( 'screen-options-nonce', 'screenoptionnonce' ); + if ( ! isset( $_POST['wp_screen_options'] ) || ! is_array( $_POST['wp_screen_options'] ) ) { + return; + } - $user = wp_get_current_user(); - if ( ! $user ) { - return; - } - $option = $_POST['wp_screen_options']['option']; - $value = $_POST['wp_screen_options']['value']; + check_admin_referer( 'screen-options-nonce', 'screenoptionnonce' ); + + $user = wp_get_current_user(); - if ( sanitize_key( $option ) != $option ) { - return; - } + if ( ! $user ) { + return; + } + + $option = $_POST['wp_screen_options']['option']; + $value = $_POST['wp_screen_options']['value']; - $map_option = $option; - $type = str_replace( 'edit_', '', $map_option ); - $type = str_replace( '_per_page', '', $type ); - if ( in_array( $type, get_taxonomies(), true ) ) { - $map_option = 'edit_tags_per_page'; - } elseif ( in_array( $type, get_post_types(), true ) ) { - $map_option = 'edit_per_page'; - } else { - $option = str_replace( '-', '_', $option ); - } + if ( sanitize_key( $option ) !== $option ) { + return; + } + + $map_option = $option; + $type = str_replace( 'edit_', '', $map_option ); + $type = str_replace( '_per_page', '', $type ); - switch ( $map_option ) { - case 'edit_per_page': - case 'users_per_page': - case 'edit_comments_per_page': - case 'upload_per_page': - case 'edit_tags_per_page': - case 'plugins_per_page': - case 'export_personal_data_requests_per_page': - case 'remove_personal_data_requests_per_page': - // Network admin. - case 'sites_network_per_page': - case 'users_network_per_page': - case 'site_users_network_per_page': - case 'plugins_network_per_page': - case 'themes_network_per_page': - case 'site_themes_network_per_page': - $value = (int) $value; - if ( $value < 1 || $value > 999 ) { - return; - } - break; - default: - $screen_option = false; + if ( in_array( $type, get_taxonomies(), true ) ) { + $map_option = 'edit_tags_per_page'; + } elseif ( in_array( $type, get_post_types(), true ) ) { + $map_option = 'edit_per_page'; + } else { + $option = str_replace( '-', '_', $option ); + } - if ( '_page' === substr( $option, -5 ) || 'layout_columns' === $option ) { - /** - * Filters a screen option value before it is set. - * - * The filter can also be used to modify non-standard [items]_per_page - * settings. See the parent function for a full list of standard options. - * - * Returning false from the filter will skip saving the current option. - * - * @since 2.8.0 - * @since 5.4.2 Only applied to options ending with '_page', - * or the 'layout_columns' option. - * - * @see set_screen_options() - * - * @param mixed $screen_option The value to save instead of the option value. - * Default false (to skip saving the current option). - * @param string $option The option name. - * @param int $value The option value. - */ - $screen_option = apply_filters( 'set-screen-option', $screen_option, $option, $value ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores - } + switch ( $map_option ) { + case 'edit_per_page': + case 'users_per_page': + case 'edit_comments_per_page': + case 'upload_per_page': + case 'edit_tags_per_page': + case 'plugins_per_page': + case 'export_personal_data_requests_per_page': + case 'remove_personal_data_requests_per_page': + // Network admin. + case 'sites_network_per_page': + case 'users_network_per_page': + case 'site_users_network_per_page': + case 'plugins_network_per_page': + case 'themes_network_per_page': + case 'site_themes_network_per_page': + $value = (int) $value; + if ( $value < 1 || $value > 999 ) { + return; + } + + break; + + default: + $screen_option = false; + + if ( '_page' === substr( $option, -5 ) || 'layout_columns' === $option ) { /** * Filters a screen option value before it is set. * - * The dynamic portion of the hook, `$option`, refers to the option name. + * The filter can also be used to modify non-standard [items]_per_page + * settings. See the parent function for a full list of standard options. * * Returning false from the filter will skip saving the current option. * - * @since 5.4.2 + * @since 2.8.0 + * @since 5.4.2 Only applied to options ending with '_page', + * or the 'layout_columns' option. * * @see set_screen_options() * - * @param mixed $screen_option The value to save instead of the option value. - * Default false (to skip saving the current option). - * @param string $option The option name. - * @param int $value The option value. + * @param mixed $screen_option The value to save instead of the option value. + * Default false (to skip saving the current option). + * @param string $option The option name. + * @param int $value The option value. */ - $value = apply_filters( "set_screen_option_{$option}", $screen_option, $option, $value ); + $screen_option = apply_filters( 'set-screen-option', $screen_option, $option, $value ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores + } - if ( false === $value ) { - return; - } - break; - } - - update_user_meta( $user->ID, $option, $value ); + /** + * Filters a screen option value before it is set. + * + * The dynamic portion of the hook name, `$option`, refers to the option name. + * + * Returning false from the filter will skip saving the current option. + * + * @since 5.4.2 + * + * @see set_screen_options() + * + * @param mixed $screen_option The value to save instead of the option value. + * Default false (to skip saving the current option). + * @param string $option The option name. + * @param int $value The option value. + */ + $value = apply_filters( "set_screen_option_{$option}", $screen_option, $option, $value ); - $url = remove_query_arg( array( 'pagenum', 'apage', 'paged' ), wp_get_referer() ); - if ( isset( $_POST['mode'] ) ) { - $url = add_query_arg( array( 'mode' => $_POST['mode'] ), $url ); - } + if ( false === $value ) { + return; + } + + break; + } + + update_user_meta( $user->ID, $option, $value ); - wp_safe_redirect( $url ); - exit; + $url = remove_query_arg( array( 'pagenum', 'apage', 'paged' ), wp_get_referer() ); + + if ( isset( $_POST['mode'] ) ) { + $url = add_query_arg( array( 'mode' => $_POST['mode'] ), $url ); } + + wp_safe_redirect( $url ); + exit; } /** - * Check if rewrite rule for WordPress already exists in the IIS 7+ configuration file + * Checks if rewrite rule for WordPress already exists in the IIS 7+ configuration file. * * @since 2.8.0 * + * @param string $filename The file path to the configuration file. * @return bool - * @param string $filename The file path to the configuration file */ function iis7_rewrite_rule_exists( $filename ) { if ( ! file_exists( $filename ) ) { return false; } + if ( ! class_exists( 'DOMDocument', false ) ) { return false; } $doc = new DOMDocument(); + if ( $doc->load( $filename ) === false ) { return false; } + $xpath = new DOMXPath( $doc ); $rules = $xpath->query( '/configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'wordpress\')] | /configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'WordPress\')]' ); - if ( 0 == $rules->length ) { + + if ( 0 === $rules->length ) { return false; - } else { - return true; } + + return true; } /** - * Delete WordPress rewrite rule from web.config file if it exists there + * Deletes WordPress rewrite rule from web.config file if it exists there. * * @since 2.8.0 * - * @param string $filename Name of the configuration file + * @param string $filename Name of the configuration file. * @return bool */ function iis7_delete_rewrite_rule( $filename ) { @@ -802,8 +857,10 @@ if ( $doc->load( $filename ) === false ) { return false; } + $xpath = new DOMXPath( $doc ); $rules = $xpath->query( '/configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'wordpress\')] | /configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'WordPress\')]' ); + if ( $rules->length > 0 ) { $child = $rules->item( 0 ); $parent = $child->parentNode; @@ -811,16 +868,17 @@ $doc->formatOutput = true; saveDomDocument( $doc, $filename ); } + return true; } /** - * Add WordPress rewrite rule to the IIS 7+ configuration file. + * Adds WordPress rewrite rule to the IIS 7+ configuration file. * * @since 2.8.0 * - * @param string $filename The file path to the configuration file - * @param string $rewrite_rule The XML fragment with URL Rewrite rule + * @param string $filename The file path to the configuration file. + * @param string $rewrite_rule The XML fragment with URL Rewrite rule. * @return bool */ function iis7_add_rewrite_rule( $filename, $rewrite_rule ) { @@ -846,41 +904,46 @@ // First check if the rule already exists as in that case there is no need to re-add it. $wordpress_rules = $xpath->query( '/configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'wordpress\')] | /configuration/system.webServer/rewrite/rules/rule[starts-with(@name,\'WordPress\')]' ); + if ( $wordpress_rules->length > 0 ) { return true; } // Check the XPath to the rewrite rule and create XML nodes if they do not exist. - $xmlnodes = $xpath->query( '/configuration/system.webServer/rewrite/rules' ); - if ( $xmlnodes->length > 0 ) { - $rules_node = $xmlnodes->item( 0 ); + $xml_nodes = $xpath->query( '/configuration/system.webServer/rewrite/rules' ); + + if ( $xml_nodes->length > 0 ) { + $rules_node = $xml_nodes->item( 0 ); } else { $rules_node = $doc->createElement( 'rules' ); - $xmlnodes = $xpath->query( '/configuration/system.webServer/rewrite' ); - if ( $xmlnodes->length > 0 ) { - $rewrite_node = $xmlnodes->item( 0 ); + $xml_nodes = $xpath->query( '/configuration/system.webServer/rewrite' ); + + if ( $xml_nodes->length > 0 ) { + $rewrite_node = $xml_nodes->item( 0 ); $rewrite_node->appendChild( $rules_node ); } else { $rewrite_node = $doc->createElement( 'rewrite' ); $rewrite_node->appendChild( $rules_node ); - $xmlnodes = $xpath->query( '/configuration/system.webServer' ); - if ( $xmlnodes->length > 0 ) { - $system_webServer_node = $xmlnodes->item( 0 ); - $system_webServer_node->appendChild( $rewrite_node ); + $xml_nodes = $xpath->query( '/configuration/system.webServer' ); + + if ( $xml_nodes->length > 0 ) { + $system_web_server_node = $xml_nodes->item( 0 ); + $system_web_server_node->appendChild( $rewrite_node ); } else { - $system_webServer_node = $doc->createElement( 'system.webServer' ); - $system_webServer_node->appendChild( $rewrite_node ); + $system_web_server_node = $doc->createElement( 'system.webServer' ); + $system_web_server_node->appendChild( $rewrite_node ); - $xmlnodes = $xpath->query( '/configuration' ); - if ( $xmlnodes->length > 0 ) { - $config_node = $xmlnodes->item( 0 ); - $config_node->appendChild( $system_webServer_node ); + $xml_nodes = $xpath->query( '/configuration' ); + + if ( $xml_nodes->length > 0 ) { + $config_node = $xml_nodes->item( 0 ); + $config_node->appendChild( $system_web_server_node ); } else { $config_node = $doc->createElement( 'configuration' ); $doc->appendChild( $config_node ); - $config_node->appendChild( $system_webServer_node ); + $config_node->appendChild( $system_web_server_node ); } } } @@ -898,7 +961,7 @@ } /** - * Saves the XML document into a file + * Saves the XML document into a file. * * @since 2.8.0 * @@ -908,13 +971,14 @@ function saveDomDocument( $doc, $filename ) { // phpcs:ignore WordPress.NamingConventions.ValidFunctionName.FunctionNameInvalid $config = $doc->saveXML(); $config = preg_replace( "/([^\r])\n/", "$1\r\n", $config ); - $fp = fopen( $filename, 'w' ); + + $fp = fopen( $filename, 'w' ); fwrite( $fp, $config ); fclose( $fp ); } /** - * Display the default admin color scheme picker (Used in user-edit.php) + * Displays the default admin color scheme picker (Used in user-edit.php). * * @since 3.0.0 * @@ -946,7 +1010,6 @@ if ( empty( $current_color ) || ! isset( $_wp_admin_css_colors[ $current_color ] ) ) { $current_color = 'fresh'; } - ?>