Pass along preview query args only if they are already present. Avoids sloppily appending a preview nonce when there should not be one. See #17157.

Built from https://develop.svn.wordpress.org/trunk@27334


git-svn-id: http://core.svn.wordpress.org/trunk@27186 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
John Blackbourn 2014-02-28 23:29:14 +00:00
parent 9166734ff5
commit be967880e2
1 changed files with 3 additions and 3 deletions

View File

@ -719,10 +719,10 @@ function _wp_link_page( $i ) {
'preview' => 'true'
), $url );
if ( 'draft' !== $post->post_status ) {
if ( ( 'draft' !== $post->post_status ) && isset( $_GET['preview_id'], $_GET['preview_nonce'] ) ) {
$url = add_query_arg( array(
'preview_id' => $post->ID,
'preview_nonce' => wp_create_nonce( 'post_preview_' . $post->ID )
'preview_id' => wp_unslash( $_GET['preview_id'] ),
'preview_nonce' => wp_unslash( $_GET['preview_nonce'] )
), $url );
}
}