Commit Graph

38444 Commits

Author SHA1 Message Date
audrasjb
e01c74a11f WordPress 5.0.22.
Built from https://develop.svn.wordpress.org/branches/5.0@58519


git-svn-id: http://core.svn.wordpress.org/branches/5.0@57967 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-06-24 16:32:39 +00:00
audrasjb
cbfe83b3f0 Editor: Fix Path Traversal issue on Windows in Template-Part Block.
Merges [58470] to the 5.0 branch.
Props xknown, jorbin.



Built from https://develop.svn.wordpress.org/branches/5.0@58492


git-svn-id: http://core.svn.wordpress.org/branches/5.0@57941 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-06-24 15:43:42 +00:00
Aaron Jorbin
5bd9c6db17 General: Backport polyfills for str_ends_with() and str_starts_with().
Merges [52040], [56016], and [56015] to 5.0 branch.

Props ocean90, SergeyBiryukov, desrosj, joemcgill, jorbin, mukesh27.

Built from https://develop.svn.wordpress.org/branches/5.0@57457


git-svn-id: http://core.svn.wordpress.org/branches/5.0@56958 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 18:16:44 +00:00
Joe McGill
52953d1f7f WordPress 5.0.21.
Built from https://develop.svn.wordpress.org/branches/5.0@57424


git-svn-id: http://core.svn.wordpress.org/branches/5.0@56930 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 16:20:41 +00:00
Aaron Jorbin
6d4b4f5228 Grouped Backports to the 5.0 branch.
- Install: When populating options, maybe_serialize instead of always serialize.
- Uploads: Check for and verify ZIP archives.

Merges [57388] and [57389] to the 5.0 branch.

Props costdev, peterwilsoncc, azaozz, tykoted, johnbillion, desrosj, afragen, jorbin, xknown.

Built from https://develop.svn.wordpress.org/branches/5.0@57405


git-svn-id: http://core.svn.wordpress.org/branches/5.0@56911 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 15:01:41 +00:00
audrasjb
8fe4a738d9 WordPress 5.0.20.
Built from https://develop.svn.wordpress.org/branches/5.0@56874


git-svn-id: http://core.svn.wordpress.org/branches/5.0@56385 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:21:26 +00:00
davidbaumwald
7587053972 Grouped backports to the 5.0 branch.
- Comments: Prevent users who can not see a post from seeing comments on it.
- Shortcodes: Restrict media shortcode ajax to certain type.
- REST API: Ensure no-cache headers are sent when methods are overridden.
- REST API: Limit `search_columns` for users without `list_users`.
- Prevent unintended behavior when certain objects are unserialized.

Merges [56833], [56834], [56835], [56836], and [56838] to the 5.0 branch.
Props xknown, jorbin, joehoyle, timothyblynjacobs, peterwilsoncc, ehtis, tykoted, antpb, rmccue.
Built from https://develop.svn.wordpress.org/branches/5.0@56871


git-svn-id: http://core.svn.wordpress.org/branches/5.0@56382 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:19:31 +00:00
Sergey Biryukov
cc0aa4e659 Grouped backports to the 5.0 branch.
- Media: Prevent CSRF setting attachment thumbnails.
- Embeds: Add protocol validation for WordPress Embed code.
- I18N: Introduce sanitization function for locale.
- Editor: Ensure block comments are of a valid form.

Merges [55760-55764] to the 5.0 branch
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.
Built from https://develop.svn.wordpress.org/branches/5.0@55791


git-svn-id: http://core.svn.wordpress.org/branches/5.0@55303 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-05-16 16:03:44 +00:00
Peter Wilson
19de4b7238 I18N: Add new strings to about.php for use with end-of-life updates.
This changeset adds two additional translation strings in the changelog file, for use when releasing the final version of WordPress on a particular branch.

Props peterwilsoncc, audrasjb, mukesh27, mukesh27.
Merges [55350] to the 5.0 branch.
Fixes #57216.

Built from https://develop.svn.wordpress.org/branches/5.0@55382


git-svn-id: http://core.svn.wordpress.org/branches/5.0@54915 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-02-21 03:03:40 +00:00
audrasjb
7d26453bc1 WordPress 5.0.18.
Built from https://develop.svn.wordpress.org/branches/5.0@54596


git-svn-id: http://core.svn.wordpress.org/branches/5.0@54150 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 19:56:19 +00:00
Sergey Biryukov
892fb39abc Grouped backports to the 5.0 branch.
- Posts, Post types: Apply KSES to post-by-email content,
- General: Validate host on "Are you sure?" screen,
- Posts, Post types: Remove emails from post-by-email logs,
- Media: Refactor search by filename within the admin,
- Pings/trackbacks: Apply KSES to all trackbacks,
- Comments: Apply kses when editing comments,
- Customize: Escape blogname option in underscores templates,
- REST API: Lockdown post parameter of the terms endpoint,
- Mail: Reset PHPMailer properties between use,
- Query: Validate relation in `WP_Date_Query`,
- Widgets: Escape RSS error messages for display.

Merges [54521], [54522], [54523], [54524], [54525], [54526], [54527], [54528], [54529], [54530], [54541] to the 5.0 branch.
Props voldemortensen, johnbillion, paulkevan, peterwilsoncc, xknown, dd32, audrasjb, martinkrcho, vortfu, davidbaumwald, tykoted, timothyblynjacobs, johnjamesjacoby, ehtis, matveb, talldanwp.

Built from https://develop.svn.wordpress.org/branches/5.0@54571


git-svn-id: http://core.svn.wordpress.org/branches/5.0@54125 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 18:16:15 +00:00
Peter Wilson
3bbf320128 Security: Introduce strings to indicate support status.
Add strings for use in future maintenance/security releases to indicate the security support status of the version of WordPress.

Two strings are introduced:

* indicating the version of WordPress is not receiving security updates, and,
* indicating the version of WordPress will shortly stop receiving security updates.

This change does not make use of the strings, the purpose is to make them available to translators prior to dropping support of selected versions of WordPress.

Props costdev, chesio, robinwpdeveloper, desrosj, rudlinkon, mukesh27, sumitbagthariya16.
Merges [54322] to the 5.0 branch.
See #56532.


Built from https://develop.svn.wordpress.org/branches/5.0@54440


git-svn-id: http://core.svn.wordpress.org/branches/5.0@53999 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-10 05:16:44 +00:00
desrosj
773140bff5 WordPress 5.0.17.
Built from https://develop.svn.wordpress.org/branches/5.0@53997


git-svn-id: http://core.svn.wordpress.org/branches/5.0@53556 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 17:35:07 +00:00
Sergey Biryukov
4ff0f5b186 Grouped backports to the 5.0 branch.
- Posts, Post Types: Escape output within `the_meta()`.
- General: Ensure bookmark query limits are numeric.
- Plugins: Escape output in error messages.
- Build/Test Tools: Allow the PHPCS plugin in Composer configuration.

Merges [52412,53958-53960] to the 5.0 branch.
Props tykoted, martinkrcho, xknown, dd32, peterwilsoncc, paulkevan, timothyblynjacobs.

Built from https://develop.svn.wordpress.org/branches/5.0@53973


git-svn-id: http://core.svn.wordpress.org/branches/5.0@53532 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 15:43:39 +00:00
davidbaumwald
f2d93e9e8f WordPress 5.0.16.
Built from https://develop.svn.wordpress.org/branches/5.0@52878


git-svn-id: http://core.svn.wordpress.org/branches/5.0@52467 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 22:06:37 +00:00
Sergey Biryukov
0963b42950 External Librairies: Update jQuery.query to version 2.2.3.
This updates the "jquery-query" library from version 2.1.7 to 2.2.3.

Props jorbin, peterwilsoncc, xknown, audrasjb, jorgefilipecosta.
Merges [52844] to the 5.0 branch.
Built from https://develop.svn.wordpress.org/branches/5.0@52856


git-svn-id: http://core.svn.wordpress.org/branches/5.0@52445 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 21:25:39 +00:00
desrosj
a2e5bf9057 WordPress 5.0.15.
Built from https://develop.svn.wordpress.org/branches/5.0@52495


git-svn-id: http://core.svn.wordpress.org/branches/5.0@52087 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:52:53 +00:00
desrosj
e84750df64 Grouped backports to the 5.0 branch.
- Query: Improve sanitization within `WP_Tax_Query`.
- Query: Improve sanitization within `WP_Meta_Query`.
- Upgrade/Install: Avoid using `unserialize()` unnecessarily.
- Formatting: Correctly encode ASCII characters in post slugs.

Merges [52454-52457] to the 5.0 branch.
Props vortfu, dd32, ehtis, zieladam, whyisjake, xknown, peterwilsoncc, desrosj, iandunn.
Built from https://develop.svn.wordpress.org/branches/5.0@52473


git-svn-id: http://core.svn.wordpress.org/branches/5.0@52065 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:15:24 +00:00
desrosj
8ab825de51 Block Editor: Additional package updates.
Built from https://develop.svn.wordpress.org/branches/5.0@51833


git-svn-id: http://core.svn.wordpress.org/branches/5.0@51440 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-21 16:49:44 +00:00
desrosj
49925ddb25 Grouped merges for 5.0.14.
Follow up to [51758].
Built from https://develop.svn.wordpress.org/branches/5.0@51769


git-svn-id: http://core.svn.wordpress.org/branches/5.0@51376 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-08 23:31:41 +00:00
desrosj
adb3129097 WordPress 5.0.14.
Built from https://develop.svn.wordpress.org/branches/5.0@51766


git-svn-id: http://core.svn.wordpress.org/branches/5.0@51373 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-08 21:42:36 +00:00
desrosj
5b2a7a5a1f Grouped merges for 5.0.14.
- Update `lodash` to the latest version `4.17.21`.
- Disable some attributes for rich text.
- Use hashed/deterministic moduleIDs in webpack config.

Props ellatrix, peterwilsoncc, get_dave, mcsf, talldanwp, youknowriad, desrosj, nerrad, gziolo.
Merges [50940-50941,50984-50985,51426] to the 5.0 branch.
Built from https://develop.svn.wordpress.org/branches/5.0@51758


git-svn-id: http://core.svn.wordpress.org/branches/5.0@51365 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-08 21:24:36 +00:00
Peter Wilson
10e25cd42a WordPress 5.0.13.
Built from https://develop.svn.wordpress.org/branches/5.0@50876


git-svn-id: http://core.svn.wordpress.org/branches/5.0@50485 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 23:18:36 +00:00
Peter Wilson
ccb7d4060e External libraries: Improve attachment handling in PHPMailer
Props: audrasjb, ayeshrajans, desrosj, peterwilsoncc, xknown.
Partially merges [50799] to the 5.0 branch.


Built from https://develop.svn.wordpress.org/branches/5.0@50854


git-svn-id: http://core.svn.wordpress.org/branches/5.0@50463 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 22:31:06 +00:00
Peter Wilson
cd89adefc2 Version bump for 5.0.12.
Built from https://develop.svn.wordpress.org/branches/5.0@50743


git-svn-id: http://core.svn.wordpress.org/branches/5.0@50352 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:40:22 +00:00
desrosj
9f95a91e28 Grouped merges for 5.0.12.
* REST API: Allow authors to read their own password protected posts.
* About page update.

Merges [50717] to the 5.0 branch.

Built from https://develop.svn.wordpress.org/branches/5.0@50731


git-svn-id: http://core.svn.wordpress.org/branches/5.0@50340 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:13:27 +00:00
desrosj
d07e548037 Build/Test Tools: Backport GitHub Action and build improvements to the 5.0 branch.
This backports several build and test tool improvements to the 5.0 branch. Most notably, this includes:

- The changes required to allow each workflow to be triggered by the `workflow_dispatch` event so that tests can be run on a schedule [50590].
- Splitting single site and multisite tests into parallel jobs [50379].
- Split slow tests into separate, parallel jobs for PHP <= 5.6 [50444].
- Better branch and path scoping for GitHub Action workflows when running on `pull_request` [50432,50479].
- Several `devDependency` updates.

Merges [45317,50267,50379,50387,50413,50416,50432,50435-50436,50444,50446,50473-50474,50476,50479,50485-50487,50545,50579,50590,50598] to the 5.0 branch.
See #50401, #51801, #51802, #52548, #52608, #52612, #52624, #52625, #52645, #52653, #52658, #52660, #52667.
Built from https://develop.svn.wordpress.org/branches/5.0@50624


git-svn-id: http://core.svn.wordpress.org/branches/5.0@50236 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-03-31 19:27:41 +00:00
desrosj
28683975c9 Build/Test Tools: Support NodeJS 14.x in the 5.0 branch.
This updates the 5.0 branch to support the latest LTS version of NodeJS (currently 14.x), allowing the same version to be used across all WordPress branches that receive security updates as a courtesy.

In addition to backporting the package updates that happened after branching 5.0, dependencies that were removed in future releases have also been updated to their latest versions.

Props desrosj, dd32, netweb, jorbin.
Merges [44233,44728,45321,45765,45826,46403-46404,46408,46409,47404,47867-47869,47872-47873,48705,49636,49933,49937,49939,49940,49983,49989,50017,50126,50176,50185,50192] to the 5.0 branch.
See #52341.
Built from https://develop.svn.wordpress.org/branches/5.0@50201


git-svn-id: http://core.svn.wordpress.org/branches/5.0@49875 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-02-05 04:05:04 +00:00
desrosj
4d0d68c942 WordPress 5.0.11.
Built from https://develop.svn.wordpress.org/branches/5.0@49414


git-svn-id: http://core.svn.wordpress.org/branches/5.0@49173 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 19:38:41 +00:00
whyisjake
8428d1077f General: WordPress updates
* XML-RPC: Improve error messages for unprivileged users.
* External Libraries: Disable deserialization in Requests_Utility_FilteredIterator
* Embeds: Disable embeds on deactivated Multisite sites.
* Coding standards: Modify escaping functions to avoid potential false positives.
* XML-RPC: Return error message if attachment ID is incorrect.
* Upgrade/install: Improve logic check when determining installation status.
* Meta: Sanitize meta key before checking protection status.
* Themes: Ensure that only privileged users can set a background image when a theme is using the deprecated custom background page.

Brings the changes from [49380,49382-49388] to the 5.0 branch.

Props xknown, zieladam, peterwilsoncc, whyisjake, desrosj, dd32.

Built from https://develop.svn.wordpress.org/branches/5.0@49396


git-svn-id: http://core.svn.wordpress.org/branches/5.0@49155 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 18:51:46 +00:00
Sergey Biryukov
639a8628e2 Administration: Pass the result of set-screen-option filter to the new set_screen_option_{$option} filter to ensure backward compatibility.
Rename the `$keep` parameter of both filters to `$screen_option` for clarity, update the documentation to better reflect its purpose.

Follow-up to [47951].

Props Chouby, sswells, SergeyBiryukov.
Merges [48241] to the 5.0 branch.
Fixes #50392.
Built from https://develop.svn.wordpress.org/branches/5.0@48248


git-svn-id: http://core.svn.wordpress.org/branches/5.0@48017 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-07-01 09:49:40 +00:00
desrosj
7b299542fd WordPress 5.0.10.
Built from https://develop.svn.wordpress.org/branches/5.0@47993


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47761 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 21:36:36 +00:00
whyisjake
71841d604b Editor: Ensure latest comments can only be viewed from public posts.
This brings the changes from [47984] to the 5.0 branch.

Props: poena, xknown.

Built from https://develop.svn.wordpress.org/branches/5.0@47988


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47756 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 19:32:45 +00:00
desrosj
c5a0caaaae General: Backport several commits for release.
- Embeds: Ensure that the title attribute is set correctly on embeds.
- Editor: Prevent HTML decoding on by setting the proper editor context.
- Formatting: Ensure that `wp_validate_redirect()` sanitizes a wider variety of characters.
- Themes: Ensure a broken theme name is returned properly.
- Administration: Add a new filter to extend set-screen-option. 

Merges [47947-47951] to the 5.0 branch.
Props xknown, sstoqnov, vortfu, SergeyBiryukov, whyisjake.

Built from https://develop.svn.wordpress.org/branches/5.0@47964


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47735 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 18:22:47 +00:00
Sergey Biryukov
82f3f9e8a1 Update the About page for WordPress 5.0.9
Built from https://develop.svn.wordpress.org/branches/5.0@47701


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47478 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 18:38:20 +00:00
desrosj
977206959f WordPress 5.0.9
Built from https://develop.svn.wordpress.org/branches/5.0@47670


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47447 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 18:00:31 +00:00
whyisjake
afc65069bb Customize: Add additional filters to Customizer to prevent JSON corruption.
User: Invalidate `user_activation_key` on password update.
Query: Ensure that only a single post can be returned on date/time based queries.
Cache API: Ensure proper escaping around the stats method in the cache API.
Formatting: Expand `sanitize_file_name` to have better support for utf8 characters.

Brings the changes in [47633], [47634], [47635], [47636], [47637], and [47638] to the 5.0 branch.

Props: aduth, batmoo, ehti, ellatrix, jorgefilipecosta, nickdaugherty, noisysocks, pento, peterwilsoncc, sergeybiryukov, sstoqnov, talldanwp, westi, westonruter, whyisjake, whyisjake, xknown.

Built from https://develop.svn.wordpress.org/branches/5.0@47647


git-svn-id: http://core.svn.wordpress.org/branches/5.0@47422 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 16:14:48 +00:00
Sergey Biryukov
5032f17b37 WordPress 5.0.8
Built from https://develop.svn.wordpress.org/branches/5.0@46923


git-svn-id: http://core.svn.wordpress.org/branches/5.0@46723 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 20:26:46 +00:00
whyisjake
ee92e93f79 Ensure that a user can publish_posts before making a post sticky.
Props: danielbachhuber, whyisjake, peterwilson, xknown.
Prevent  stored XSS through wp_targeted_link_rel().
Props: vortfu, whyisjake, peterwilsoncc, xknown,  SergeyBiryukov, flaviozavan.
Update wp_kses_bad_protocol() to recognize &colon; on uri attributes,
wp_kses_bad_protocol() makes sure to validate that uri attributes don't contain invalid/or not allowed protocols. While this works fine in most cases, there's a risk that by using the colon html5 named entity, one is able to bypass this function.
Brings r46895 to the 5.3 branch.
Props: xknown, nickdaugherty, peterwilsoncc.
Prevent stored XSS in the block editor.
Brings r46896 to the 5.3 branch.
Prevent escaped unicode characters become unescaped in unsafe HTML during JSON decoding.
Props: aduth, epiqueras.


Built from https://develop.svn.wordpress.org/branches/5.0@46915


git-svn-id: http://core.svn.wordpress.org/branches/5.0@46715 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 18:52:47 +00:00
desrosj
970ccf3c73 WordPress 5.0.7.
Built from https://develop.svn.wordpress.org/branches/5.0@46510


git-svn-id: http://core.svn.wordpress.org/branches/5.0@46307 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 20:08:38 +00:00
whyisjake
de7d42ed47 Backporting several bug fixes.
- Query: Remove the static query property.
- HTTP API: Protect against hex interpretation.
- Filesystem API: Prevent directory travelersals when creating new folders.
- Administration: Ensure that admin referer nonce is valid.
- REST API: Send a Vary: Origin header on GET requests.

Backports [46474], [46475], [46476], [46477], [46478], [46483], [46485] to the 5.0 branch.

Built from https://develop.svn.wordpress.org/branches/5.0@46492


git-svn-id: http://core.svn.wordpress.org/branches/5.0@46289 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 18:26:51 +00:00
desrosj
b67804a2a5 WordPress 5.0.6
Built from https://develop.svn.wordpress.org/branches/5.0@46063


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45875 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 23:54:48 +00:00
desrosj
d7e71b0458 WordPress 5.0.5.
Built from https://develop.svn.wordpress.org/branches/5.0@46044


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45856 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 22:06:41 +00:00
whyisjake
a8c16b5330 Update the block library to 2.2.17 to fix an issue with invalid shortcode blocks.
Props aduth, flaviozavan, epiqueras, jorgefilipecosta


Built from https://develop.svn.wordpress.org/branches/5.0@46029


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45841 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:50:46 +00:00
whyisjake
e2ad4d2e2a Update the block library to 2.2.17 to fix an issue with invalid shortcode blocks.
Props aduth, flaviozavan, epiqueras, jorgefilipecosta


Built from https://develop.svn.wordpress.org/branches/5.0@46029


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45840 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:50:35 +00:00
Andrew Ozz
4c7b037229 jQuery: Backport the patch from jQuery 3.4.0.
Merges [45342] to the 5.0 branch.

Props MikeNGarrett, peterwilsoncc, azaozz.
Fixes #47020.
Built from https://develop.svn.wordpress.org/branches/5.0@46017


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45828 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:44:01 +00:00
desrosj
1f26aab97c Fix for URL sanitization in wp_kses_bad_protocol_once().
Merges [45997] to the 5.0 branch.

Props irsdl, sstoqnov, whyisjake.
Built from https://develop.svn.wordpress.org/branches/5.0@46004


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45815 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:38:37 +00:00
whyisjake
f99c8057e0 Update the block library to 2.2.17 to fix an issue with invalid shortcode blocks.
Props aduth, flaviozavan, epiqueras


Built from https://develop.svn.wordpress.org/branches/5.0@46003


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45814 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:37:50 +00:00
Sergey Biryukov
65d7b91757 Improve handling the existing rel attribute in wp_rel_nofollow_callback().
Merges [45990] to the 5.0 branch.
Props xknown, sstoqnov.
Built from https://develop.svn.wordpress.org/branches/5.0@45993


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45804 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 17:47:47 +00:00
Sergey Biryukov
002e75631f Improve URL validation in wp_validate_redirect().
Merges [45971] to the 5.0 branch.
Props vortfu, whyisjake, peterwilsoncc.
Built from https://develop.svn.wordpress.org/branches/5.0@45974


git-svn-id: http://core.svn.wordpress.org/branches/5.0@45785 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 17:05:47 +00:00