Commit Graph

36793 Commits

Author SHA1 Message Date
Aaron Jorbin 1cf28f381b General: Backport polyfills for str_ends_with() and str_starts_with().
Uses src/wp-includes/functions.php becouse commiting to src/wp-includes/compat.php fails due to the presence of __autoload.

Merges [52040], [56016], and [56015] to 4.8 branch.

Props ocean90, SergeyBiryukov, desrosj, joemcgill, jorbin, mukesh27.

Built from https://develop.svn.wordpress.org/branches/4.8@57453


git-svn-id: http://core.svn.wordpress.org/branches/4.8@56954 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 18:07:23 +00:00
Joe McGill afd1e6770e WordPress 4.8.24.
Built from https://develop.svn.wordpress.org/branches/4.8@57422


git-svn-id: http://core.svn.wordpress.org/branches/4.8@56928 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 16:17:23 +00:00
Aaron Jorbin 3609ec4f2e Grouped Backports to the 4.8 branch.
- Install: When populating options, maybe_serialize instead of always serialize.
- Uploads: Check for and verify ZIP archives.

Merges [57388] and [57389] to the 4.8 branch.

Props costdev, peterwilsoncc, azaozz, tykoted, johnbillion, desrosj, afragen, jorbin, xknown.

Built from https://develop.svn.wordpress.org/branches/4.8@57407


git-svn-id: http://core.svn.wordpress.org/branches/4.8@56913 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 15:05:23 +00:00
audrasjb 66e18dcb6e WordPress 4.8.23.
Built from https://develop.svn.wordpress.org/branches/4.8@56869


git-svn-id: http://core.svn.wordpress.org/branches/4.8@56380 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:17:34 +00:00
davidbaumwald 9fd0b00c91 Grouped backports to the 4.8 branch.
- Comments: Prevent users who can not see a post from seeing comments on it.
- Shortcodes: Restrict media shortcode ajax to certain type.
- REST API: Ensure no-cache headers are sent when methods are overridden.
- REST API: Limit `search_columns` for users without `list_users`.
- Prevent unintended behavior when certain objects are unserialized.

Merges [56834], [56835], [56836], [56838], and [56840] to the 4.8 branch.
Props xknown, jorbin, joehoyle, timothyblynjacobs, peterwilsoncc, ehtis, tykoted, antpb, rmccue.
Built from https://develop.svn.wordpress.org/branches/4.8@56864


git-svn-id: http://core.svn.wordpress.org/branches/4.8@56375 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:14:39 +00:00
Sergey Biryukov 70a0960dff Grouped backports to the 4.8 branch.
- Media: Prevent CSRF setting attachment thumbnails.
- Embeds: Add protocol validation for WordPress Embed code.

Merges [55763] and [55764] to the 4.8 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.
Built from https://develop.svn.wordpress.org/branches/4.8@55786


git-svn-id: http://core.svn.wordpress.org/branches/4.8@55298 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-05-16 15:52:27 +00:00
Peter Wilson 7cd8649bbe I18N: Add new strings to `about.php` for use with end-of-life updates.
This changeset adds two additional translation strings in the changelog file, for use when releasing the final version of WordPress on a particular branch.

Props peterwilsoncc, audrasjb, mukesh27.
Merges [55350] to the 4.8 branch.
Fixes #57216.

Built from https://develop.svn.wordpress.org/branches/4.8@55384


git-svn-id: http://core.svn.wordpress.org/branches/4.8@54917 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-02-21 03:06:23 +00:00
Sergey Biryukov 9c48bd85e4 WordPress 4.8.21.
Built from https://develop.svn.wordpress.org/branches/4.8@54594


git-svn-id: http://core.svn.wordpress.org/branches/4.8@54148 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 19:55:14 +00:00
Sergey Biryukov 92a93cd9be Grouped backports to the 4.8 branch.
- Posts, Post types: Apply KSES to post-by-email content,
- General: Validate host on "Are you sure?" screen,
- Posts, Post types: Remove emails from post-by-email logs,
- Media: Refactor search by filename within the admin,
- Pings/trackbacks: Apply KSES to all trackbacks,
- Comments: Apply kses when editing comments,
- Customize: Escape blogname option in underscores templates,
- REST API: Lockdown post parameter of the terms endpoint,
- Mail: Reset PHPMailer properties between use,
- Query: Validate relation in `WP_Date_Query`,
- Widgets: Escape RSS error messages for display.

Merges [54521], [54522], [54523], [54524], [54525], [54526], [54527], [54528], [54529], [54530], [54541] to the 4.8 branch.
Props voldemortensen, johnbillion, paulkevan, peterwilsoncc, xknown, dd32, audrasjb, martinkrcho, vortfu, davidbaumwald, tykoted, timothyblynjacobs, johnjamesjacoby, ehtis, matveb, talldanwp.

Built from https://develop.svn.wordpress.org/branches/4.8@54568


git-svn-id: http://core.svn.wordpress.org/branches/4.8@54122 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 18:14:23 +00:00
Peter Wilson 65b7a0e48b Security: Introduce strings to indicate support status.
Add strings for use in future maintenance/security releases to indicate the security support status of the version of WordPress.

Two strings are introduced:

* indicating the version of WordPress is not receiving security updates, and,
* indicating the version of WordPress will shortly stop receiving security updates.

This change does not make use of the strings, the purpose is to make them available to translators prior to dropping support of selected versions of WordPress.

Props costdev, chesio, robinwpdeveloper, desrosj, rudlinkon, mukesh27, sumitbagthariya16.
Merges [54322] to the 4.8 branch.
See #56532.

Built from https://develop.svn.wordpress.org/branches/4.8@54452


git-svn-id: http://core.svn.wordpress.org/branches/4.8@54011 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-10 22:07:23 +00:00
desrosj 61be176e5a WordPress 4.8.20.
Built from https://develop.svn.wordpress.org/branches/4.8@53999


git-svn-id: http://core.svn.wordpress.org/branches/4.8@53558 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 17:35:59 +00:00
Sergey Biryukov 7a558af3c8 Grouped backports to the 4.8 branch.
- Posts, Post Types: Escape output within `the_meta()`.
- General: Ensure bookmark query limits are numeric.
- Plugins: Escape output in error messages.

Merges [53958-53960] to the 4.8 branch.
Props tykoted, martinkrcho, xknown, dd32, peterwilsoncc, paulkevan, timothyblynjacobs.

Built from https://develop.svn.wordpress.org/branches/4.8@53975


git-svn-id: http://core.svn.wordpress.org/branches/4.8@53534 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 15:45:23 +00:00
davidbaumwald 12bfb972db WordPress 4.8.19.
Built from https://develop.svn.wordpress.org/branches/4.8@52883


git-svn-id: http://core.svn.wordpress.org/branches/4.8@52472 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 22:10:23 +00:00
Sergey Biryukov f595bcfd36 External Librairies: Update jQuery.query to version 2.2.3.
This updates the "jquery-query" library from version 2.1.7 to 2.2.3.

Props jorbin, peterwilsoncc, xknown, audrasjb, jorgefilipecosta.
Merges [52844] to the 4.8 branch.
Built from https://develop.svn.wordpress.org/branches/4.8@52858


git-svn-id: http://core.svn.wordpress.org/branches/4.8@52447 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 21:31:23 +00:00
desrosj cf7dbdbdca WordPress 4.8.18.
Built from https://develop.svn.wordpress.org/branches/4.8@52497


git-svn-id: http://core.svn.wordpress.org/branches/4.8@52089 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:53:41 +00:00
desrosj 02a98204d7 Grouped backports to the 4.8 branch.
- Query: Improve sanitization within `WP_Tax_Query`.
- Query: Improve sanitization within `WP_Meta_Query`.
- Upgrade/Install: Avoid using `unserialize()` unnecessarily.
- Formatting: Correctly encode ASCII characters in post slugs.

Merges [52454-52457] to the 4.8 branch.
Props vortfu, dd32, ehtis, zieladam, whyisjake, xknown, peterwilsoncc, desrosj, iandunn.
Built from https://develop.svn.wordpress.org/branches/4.8@52475


git-svn-id: http://core.svn.wordpress.org/branches/4.8@52067 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:16:48 +00:00
Peter Wilson e68cfb41cd WordPress 4.8.17.
Built from https://develop.svn.wordpress.org/branches/4.8@50878


git-svn-id: http://core.svn.wordpress.org/branches/4.8@50487 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 23:19:24 +00:00
Peter Wilson 452efae4e3 External libraries: Improve attachment handling in PHPMailer
Props: audrasjb, ayeshrajans, desrosj, peterwilsoncc, xknown.
Partially merges [50799] to the 4.8 branch.


Built from https://develop.svn.wordpress.org/branches/4.8@50856


git-svn-id: http://core.svn.wordpress.org/branches/4.8@50465 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 22:32:48 +00:00
Peter Wilson 75f3b8205b Version bump for 4.8.16.
Built from https://develop.svn.wordpress.org/branches/4.8@50745


git-svn-id: http://core.svn.wordpress.org/branches/4.8@50354 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:41:13 +00:00
desrosj 0632e81b28 Grouped merges for 4.8.16.
* REST API: Allow authors to read their own password protected posts.
* About page update

Merges [50717] to the 4.8 branch.


Built from https://develop.svn.wordpress.org/branches/4.8@50734


git-svn-id: http://core.svn.wordpress.org/branches/4.8@50343 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:15:24 +00:00
desrosj 8ebf24672f Build/Test Tools: Backport GitHub Action and build improvements to the 4.8 branch.
This backports several build and test tool improvements to the 4.8 branch. Most notably, this includes:

- The changes required to allow each workflow to be triggered by the `workflow_dispatch` event so that tests can be run on a schedule [50590].
- Splitting single site and multisite tests into parallel jobs [50379].
- Split slow tests into separate, parallel jobs for PHP <= 5.6 [50444].
- Better branch and path scoping for GitHub Action workflows when running on `pull_request` [50432,50479].
- Several `devDependency` updates.

Merges [50379,50387,50413,50416,50432,50435,50436,50444,50446,50473,50474,50476,50479,50485,50486,50487,50545,50579,50590] to the 4.8 branch.
See #50401, #51801, #51802, #52548, #52608, #52612, #52624, #52625, #52645, #52653, #52658, #52660, #52667.
Built from https://develop.svn.wordpress.org/branches/4.8@50635


git-svn-id: http://core.svn.wordpress.org/branches/4.8@50247 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-02 15:25:25 +00:00
desrosj a68590b382 Build/Test Tools: Support NodeJS 14.x in the 4.8 branch.
This updates the 4.8 branch to support the latest LTS version of NodeJS (currently 14.x), allowing the same version to be used across all WordPress branches that receive security updates as a courtesy.

This also replaces the `npm-shrinkwrap.json` with a `package-lock.json` file. Lock files were not supported in earlier versions of NPM, but can now be used.

In addition to backporting the package updates that happened after branching 4.8, dependencies that were removed in future releases have also been updated to their latest versions.

Props desrosj, dd32, netweb, jorbin.
Merges [42460-42461,42463,42887,43320,43323,43977,44219,44233,44728,45321,45765,46404,46408-46409,47404,47867-47869,47872-47873,48705,49636,49933,49937,49939,50017,50126,50176,50185,50192] to the 4.8 branch.
See #52341.
Built from https://develop.svn.wordpress.org/branches/4.8@50203


git-svn-id: http://core.svn.wordpress.org/branches/4.8@49877 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-02-05 04:10:38 +00:00
desrosj 03c2d89d0a WordPress 4.8.15.
Built from https://develop.svn.wordpress.org/branches/4.8@49416


git-svn-id: http://core.svn.wordpress.org/branches/4.8@49175 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 19:39:27 +00:00
whyisjake 2544e89df4 General: WordPress updates
* XML-RPC: Improve error messages for unprivileged users.
* External Libraries: Disable deserialization in Requests_Utility_FilteredIterator
* Embeds: Disable embeds on deactivated Multisite sites.
* Coding standards: Modify escaping functions to avoid potential false positives.
* XML-RPC: Return error message if attachment ID is incorrect.
* Upgrade/install: Improve logic check when determining installation status.
* Meta: Sanitize meta key before checking protection status.
* Themes: Ensure that only privileged users can set a background image when a theme is using the deprecated custom background page.

Brings the changes from [49380,49382-49388] to the 4.8 branch.

Props xknown, zieladam, peterwilsoncc, whyisjake, desrosj, dd32.

Built from https://develop.svn.wordpress.org/branches/4.8@49398


git-svn-id: http://core.svn.wordpress.org/branches/4.8@49157 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 18:55:23 +00:00
Sergey Biryukov f175cf83a7 Administration: Pass the result of `set-screen-option` filter to the new `set_screen_option_{$option}` filter to ensure backward compatibility.
Rename the `$keep` parameter of both filters to `$screen_option` for clarity, update the documentation to better reflect its purpose.

Follow-up to [47951].

Props Chouby, sswells, SergeyBiryukov.
Merges [48241] to the 4.8 branch.
Fixes #50392.
Built from https://develop.svn.wordpress.org/branches/4.8@48250


git-svn-id: http://core.svn.wordpress.org/branches/4.8@48019 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-07-01 09:50:46 +00:00
desrosj 499c907011 WordPress 4.8.14.
Built from https://develop.svn.wordpress.org/branches/4.8@47995


git-svn-id: http://core.svn.wordpress.org/branches/4.8@47763 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 21:37:26 +00:00
whyisjake 27f0839d04 General: Backport several commits for release.
- Embeds: Ensure that the title attribute is set correctly on embeds.
- Editor: Prevent HTML decoding on by setting the proper editor context.
- Formatting: Ensure that wp_validate_redirect() sanitizes a wider variety of characters.
- Themes: Ensure a broken theme name is returned properly.
- Administration: Add a new filter to extend set-screen-option.

Merges [47947-47951] to the 4.8 branch.

Props xknown, sstoqnov, vortfu, SergeyBiryukov, whyisjake.

Built from https://develop.svn.wordpress.org/branches/4.8@47980


git-svn-id: http://core.svn.wordpress.org/branches/4.8@47749 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 18:56:52 +00:00
Sergey Biryukov f501f7d79b Update the About page for WordPress 4.8.13
Built from https://develop.svn.wordpress.org/branches/4.8@47698


git-svn-id: http://core.svn.wordpress.org/branches/4.8@47475 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 18:35:07 +00:00
desrosj 049d99e977 WordPress 4.8.13
Built from https://develop.svn.wordpress.org/branches/4.8@47672


git-svn-id: http://core.svn.wordpress.org/branches/4.8@47449 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 18:01:18 +00:00
whyisjake 166492f860 Customize: Add additional filters to Customizer to prevent JSON corruption.
User: Invalidate `user_activation_key` on password update.
Query: Ensure that only a single post can be returned on date/time based queries.
Cache API: Ensure proper escaping around the stats method in the cache API.
Formatting: Expand `sanitize_file_name` to have better support for utf8 characters.

Brings the changes in [47633], [47634], [47635], [47637], and [47638] to the 4.8 branch.

Props: batmoo, ehti, nickdaugherty, peterwilsoncc, sergeybiryukov, sstoqnov, westi, westonruter, whyisjake, whyisjake, xknown.

Built from https://develop.svn.wordpress.org/branches/4.8@47649


git-svn-id: http://core.svn.wordpress.org/branches/4.8@47424 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 16:19:21 +00:00
Sergey Biryukov 9548cae7ec WordPress 4.8.12
Built from https://develop.svn.wordpress.org/branches/4.8@46925


git-svn-id: http://core.svn.wordpress.org/branches/4.8@46725 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 20:28:21 +00:00
Sergey Biryukov b12e78ee0b Ensure that a user can publish_posts before making a post sticky.
Props: danielbachhuber, whyisjake, peterwilson, xknown.

Brings r46893 to the 4.8 branch.

Update `wp_kses_bad_protocol()` to recognize `&colon;` on uri attributes,

`wp_kses_bad_protocol()` makes sure to validate that uri attributes don’t contain invalid/or not allowed protocols. While this works fine in most cases, there’s a risk that by using the colon html5 named entity, one is able to bypass this function.

Brings r46895 to the 4.8 branch.

Props: xknown, nickdaugherty, peterwilsoncc.
Built from https://develop.svn.wordpress.org/branches/4.8@46917


git-svn-id: http://core.svn.wordpress.org/branches/4.8@46717 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 18:54:21 +00:00
desrosj c359dde932 WordPress 4.8.11.
Built from https://develop.svn.wordpress.org/branches/4.8@46512


git-svn-id: http://core.svn.wordpress.org/branches/4.8@46309 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 20:09:50 +00:00
whyisjake 20821b59c0 Backporting several bug fixes.
- Query: Remove the static query property.
- HTTP API: Protect against hex interpretation.
- Filesystem API: Prevent directory travelersals when creating new folders.
- Administration: Ensure that admin referer nonce is valid.
- REST API: Send a Vary: Origin header on GET requests.

Backports [46474], [46475], [46476], [46477], [46478], [46483], [46485] to the 4.8 branch.

Built from https://develop.svn.wordpress.org/branches/4.8@46494


git-svn-id: http://core.svn.wordpress.org/branches/4.8@46291 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 18:45:23 +00:00
desrosj 0f9e4ca0a2 WordPress 4.8.10.
Built from https://develop.svn.wordpress.org/branches/4.8@46042


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45854 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 22:05:29 +00:00
Andrew Ozz 8c59b4a3c2 jQuery: Backport the patch from jQuery 3.4.0.
Merges [45342] to the 4.8 branch.

Props MikeNGarrett, peterwilsoncc, azaozz.
Fixes #47020.
Built from https://develop.svn.wordpress.org/branches/4.8@46021


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45832 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:45:54 +00:00
desrosj fdc41b55e7 Fix for URL sanitization in `wp_kses_bad_protocol_once()`.
Merges [45997] to the 4.8 branch.

Props irsdl, sstoqnov, whyisjake.
Built from https://develop.svn.wordpress.org/branches/4.8@46006


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45817 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:39:27 +00:00
Sergey Biryukov f76869ca2f Improve handling the existing `rel` attribute in `wp_rel_nofollow_callback()`.
Merges [45990] to the 4.8 branch.
Props xknown, sstoqnov.
Built from https://develop.svn.wordpress.org/branches/4.8@45995


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45806 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 17:48:46 +00:00
Sergey Biryukov 7b4f9a5118 Improve URL validation in `wp_validate_redirect()`.
Merges [45971] to the 4.8 branch.
Props vortfu, whyisjake, peterwilsoncc.
Built from https://develop.svn.wordpress.org/branches/4.8@45976


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45787 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 17:11:21 +00:00
whyisjake 1242539c0e Remove _convert_urlencoded_to_entities() from the get_the_content() callback.
Merges [45937] to the 4.8 branch.

Props vortfu, whyisjake, peterwilsoncc

Built from https://develop.svn.wordpress.org/branches/4.8@45949


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45760 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 16:36:45 +00:00
Sergey Biryukov 33f4539c6e Escape the output in `wp_ajax_upload_attachment()`.
Merges [45936] to the 4.8 branch.
Props whyisjake, sstoqnov.
Built from https://develop.svn.wordpress.org/branches/4.8@45944


git-svn-id: http://core.svn.wordpress.org/branches/4.8@45755 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 16:31:23 +00:00
Gary Pendergast b3a9479bd3 WordPress 4.8.9
Built from https://develop.svn.wordpress.org/branches/4.8@44870


git-svn-id: http://core.svn.wordpress.org/branches/4.8@44701 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-03-13 01:05:20 +00:00
Sergey Biryukov a32075cd83 Comments: Improve comment content filtering.
Merges [44842] to the 4.8 branch.
Built from https://develop.svn.wordpress.org/branches/4.8@44846


git-svn-id: http://core.svn.wordpress.org/branches/4.8@44678 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-03-12 22:35:20 +00:00
Sergey Biryukov 010a30cf09 Formatting: Improve `rel="nofollow"` handling in comments.
Merges [44833] to the 4.8 branch.
Built from https://develop.svn.wordpress.org/branches/4.8@44837


git-svn-id: http://core.svn.wordpress.org/branches/4.8@44669 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-03-12 22:21:23 +00:00
Jeremy Felt d86c7ad402 Bump 4.8 branch to version 4.8.8.
Built from https://develop.svn.wordpress.org/branches/4.8@44079


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43909 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-13 02:13:20 +00:00
Gary Pendergast 7bd776bdb3 Editor: Remove unwanted fields before saving posts.
The `meta_input`, `file`, and `guid` fields are not intended to be updated through user input.

Merges [44047] to the 4.8 branch.


Built from https://develop.svn.wordpress.org/branches/4.8@44055


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43885 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-13 01:40:21 +00:00
Peter Wilson dfc71aee34 Multisite: Validate activation links.
Merges [44048] to the 4.8 branch.

Built from https://develop.svn.wordpress.org/branches/4.8@44052


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43882 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-13 01:35:21 +00:00
Peter Wilson a5be721238 Multisite: Improve messaging for previously activated users.
Ensure activation of a site is not attempted multiple times and users are shown the correct message if they follow the link a second time.

Merges [44021] to the 4.8 branch.

Built from https://develop.svn.wordpress.org/branches/4.8@44025


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43855 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-13 00:37:22 +00:00
iandunn 1bb4687f0b KSES: Make the URI attributes DRY.
This commit introduces the `wp_kses_uri_attributes` function and filter. The function centralizes the list of attributes, in order to prevent inconsistency, and the filter provides a way for plugins to customize the attributes.

Merges [44014] and [44017] to the 4.8 branch.

Built from https://develop.svn.wordpress.org/branches/4.8@44023


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43853 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-13 00:33:20 +00:00
Gary Pendergast e00499f8df KSES: Conditionally remove the `<form>` element from `$allowedposttags`.
To avoid backwards compatibility issues, `<form>` is re-added if a custom filter has added the `<input>` or `<select>` elements to `$allowedposttags`.

Merges [43994] to the 4.8 branch.

Built from https://develop.svn.wordpress.org/branches/4.8@43999


git-svn-id: http://core.svn.wordpress.org/branches/4.8@43831 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2018-12-12 23:20:23 +00:00