WordPress/wp-includes
davidbaumwald 69e59764eb Grouped backports to the 4.6 branch.
- Comments: Prevent users who can not see a post from seeing comments on it.
- Shortcodes: Restrict media shortcode ajax to certain type.
- REST API: Ensure no-cache headers are sent when methods are overridden.
- Prevent unintended behavior when certain objects are unserialized.

Merges [56834], [56835], [56836], and [56838] to the 4.6 branch.
Props xknown, jorbin, joehoyle, timothyblynjacobs, peterwilsoncc, ehtis, tykoted, antpb, rmccue.
Built from https://develop.svn.wordpress.org/branches/4.6@56859


git-svn-id: http://core.svn.wordpress.org/branches/4.6@56370 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:10:52 +00:00
..
certificates Docs: Standardize on 'backward compatibility/compatible' nomenclature in core inline docs. 2016-05-13 18:41:31 +00:00
css Build/Test Tools: Backport GitHub Action and build improvements to the 4.6 branch. 2021-04-02 15:34:24 +00:00
customize Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
fonts Dashicons: Fix incorrect ID in SVG version of font. 2016-03-18 20:43:26 +00:00
ID3
images
js Grouped backports to the 4.6 branch. 2023-05-16 15:45:21 +00:00
pomo
random_compat Update Random_Compat from 1.1.6 to 1.2.1. 2016-03-08 17:15:27 +00:00
Requests Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
rest-api Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
SimplePie
Text
theme-compat Embeds: Don't print the HTML for a featured image if a post has no featured image. 2016-07-06 17:08:31 +00:00
widgets Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
admin-bar.php Docs: Apply inline @see tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 18:59:27 +00:00
atomlib.php External Libraries: After [37402], replace two more instances of split() with explode() in wp-includes/atomlib.php. 2016-05-19 00:06:28 +00:00
author-template.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
bookmark-template.php Docs: Standardize filter docs in wp-includes/bookmark-template.php to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:24:28 +00:00
bookmark.php Grouped backports to the 4.6 branch. 2022-08-30 15:48:21 +00:00
cache.php Cache API: Ensure proper escaping around the stats method in the cache API. 2020-04-29 16:45:22 +00:00
canonical.php Improve category check in redirect_canonical() when permastruct contains category slug. 2016-08-09 00:13:31 +00:00
capabilities.php Introduce an expanded meta registration API. 2016-06-30 01:02:29 +00:00
category-template.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
category.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
class-feed.php Docs: Add missing class, method, and property DocBlocks for feed classes. 2016-07-20 07:33:29 +00:00
class-http.php Improve redirect handling 2017-05-16 08:41:33 +00:00
class-IXR.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-json.php
class-oembed.php Embeds: In WP_oEmbed::get_provider() and WP_oEmbed::get_html(), parse the $args string to an array, as we treat it as an array later. 2016-06-15 18:52:28 +00:00
class-phpass.php
class-phpmailer.php External libraries: Improve attachment handling in PHPMailer 2021-05-12 22:33:35 +00:00
class-pop3.php
class-requests.php HTTP: Update Requests to master (0048f3c) which fixes a number of outstanding issues. 2016-10-05 03:27:31 +00:00
class-simplepie.php Autoload: Introduce shim for SPL autoloading. 2016-06-06 03:24:29 +00:00
class-smtp.php Update PHPMailer to 5.2.22. 2017-01-11 05:22:39 +00:00
class-snoopy.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
class-walker-category-dropdown.php Docs: Improve inline documentation in property and method DocBlocks for Walker_CategoryDropdown. 2016-03-22 17:22:29 +00:00
class-walker-category.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-walker-comment.php Comments: pass $comment to comment_text() in Walker_Comment::comment() instead of using a function which can skip the cache. 2016-04-29 15:47:27 +00:00
class-walker-nav-menu.php Nav Menus: Move the Walker_Nav_Menu class to its own file. 2016-06-06 15:18:31 +00:00
class-walker-page-dropdown.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-walker-page.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-wp-admin-bar.php Toolbar: Allow 0 as a value for the tabindex property of a menu item. 2016-07-12 11:18:30 +00:00
class-wp-ajax-response.php Docs: Standardize capitalization of Ajax throughout core documentation per the core spelling guide. 2016-07-10 00:51:30 +00:00
class-wp-comment-query.php Comments: Revert [38497] 2016-09-07 13:41:34 +00:00
class-wp-comment.php Comments: Correct description of comment_author property in WP_Comment class. 2016-01-17 15:00:27 +00:00
class-wp-customize-control.php Docs: Standardize filter docs in the Customizer classes to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:10:29 +00:00
class-wp-customize-manager.php Customize: Ensure valid themes in the preview. 2017-09-19 11:51:38 +00:00
class-wp-customize-nav-menus.php Customize: Link "widget areas" to widgets panel in menu locations section description. 2016-06-28 22:44:30 +00:00
class-wp-customize-panel.php Docs: Standardize filter docs in the Customizer classes to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:10:29 +00:00
class-wp-customize-section.php Docs: Standardize filter docs in the Customizer classes to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:10:29 +00:00
class-wp-customize-setting.php Docs: Correct and clarify various @since docs. 2016-08-04 22:56:41 +00:00
class-wp-customize-widgets.php Docs: Apply inline @see tags to hooks referenced in DocBlocks for core classes. 2016-05-23 18:54:27 +00:00
class-wp-editor.php TinyMCE: fix toolbars alignment in RTL. 2016-08-31 23:43:29 +00:00
class-wp-embed.php Docs: Standardize capitalization of Ajax throughout core documentation per the core spelling guide. 2016-07-10 00:51:30 +00:00
class-wp-error.php Docs: Remove/replace invalid inline @link tags in DocBlocks in wp-includes/*. 2016-05-22 17:39:28 +00:00
class-wp-http-cookie.php HTTP API: Normalize cookies before passing them to Requests. 2016-07-27 15:32:27 +00:00
class-wp-http-curl.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-encoding.php DOCS: Replace HTTP links with HTTPS. 2016-06-10 04:50:33 +00:00
class-wp-http-ixr-client.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-proxy.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-requests-response.php HTTP API: Normalize cookies before passing them to Requests. 2016-07-27 15:32:27 +00:00
class-wp-http-response.php
class-wp-http-streams.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-image-editor-gd.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
class-wp-image-editor-imagick.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
class-wp-image-editor.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-locale.php I18N: Move the WP_Locale class to its own file. 2016-06-28 11:53:28 +00:00
class-wp-meta-query.php Grouped backports to the 4.6 branch. 2022-01-06 18:18:21 +00:00
class-wp-metadata-lazyloader.php Docs: Apply inline @see tags to hooks referenced in DocBlocks for core classes. 2016-05-23 18:54:27 +00:00
class-wp-network-query.php Docs: Clarify the fields argument description in WP_Network_Query::__construct(). 2016-07-19 13:18:28 +00:00
class-wp-network.php Docs: Supplement a changelog entry in the DocBlock for the $id property in WP_Network. 2016-06-29 19:35:28 +00:00
class-wp-oembed-controller.php Docs: Add missing @access tags to methods in WP_oEmbed_Controller. 2016-05-25 19:22:27 +00:00
class-wp-post-type.php Docs: Correct type of WP_Post_Type::$cap from array to object. 2016-07-18 22:52:29 +00:00
class-wp-post.php
class-wp-rewrite.php Docs: Apply inline @see tags to hooks referenced in DocBlocks for core classes. 2016-05-23 18:54:27 +00:00
class-wp-role.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-roles.php Docs: Standardize on 'backward compatibility/compatible' nomenclature in core inline docs. 2016-05-13 18:41:31 +00:00
class-wp-site-query.php Docs: Clarify the fields argument description in WP_Site_Query::__construct(). 2016-07-19 13:15:28 +00:00
class-wp-site.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
class-wp-tax-query.php Grouped backports to the 4.6 branch. 2022-01-06 18:18:21 +00:00
class-wp-term-query.php Taxononmy: Set WP_Term_Query::terms when returning terms from the cache in WP_Term_Query::get_terms(). 2016-08-08 13:14:37 +00:00
class-wp-term.php Text Changes: Add a full stop to "Invalid taxonomy" and "Invalid term ID" strings, for consistency with similar post-related messages. 2016-07-17 16:15:34 +00:00
class-wp-theme.php Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
class-wp-user-query.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-user.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
class-wp-walker.php Docs: Standardize on 'backward compatibility/compatible' nomenclature in core inline docs. 2016-05-13 18:41:31 +00:00
class-wp-widget-factory.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
class-wp-widget.php Widgets: Revert [37425] and [37427]. 2016-06-06 21:51:28 +00:00
class-wp-xmlrpc-server.php General: WordPress updates 2020-10-29 19:00:24 +00:00
class-wp.php Backporting several bug fixes. 2019-10-14 19:02:25 +00:00
class.wp-dependencies.php Docs: Re-add a @param that went missing in [36993]. 2016-03-14 22:39:26 +00:00
class.wp-scripts.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
class.wp-styles.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
comment-template.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
comment.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
compat.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
cron.php Docs: In wp_schedule_single_event(), add a note about scheduling an event to occur within 10 minutes of another event with the same action hook. 2016-07-25 12:23:30 +00:00
date.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
default-constants.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
default-filters.php Resource Hints: Increase priority of wp_resource_hints() so hints get printed before scripts and styles. 2016-07-13 12:54:28 +00:00
default-widgets.php
deprecated.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
embed-template.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
embed.php Grouped backports to the 4.6 branch. 2023-05-16 15:45:21 +00:00
feed-atom-comments.php DOCS: Replace HTTP links with HTTPS. 2016-06-10 04:50:33 +00:00
feed-atom.php
feed-rdf.php
feed-rss2-comments.php
feed-rss2.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
feed-rss.php
feed.php Hardening: Ensure the attributes of enclosures are correctly escaped in RSS and Atom feeds. 2017-11-29 16:23:06 +00:00
formatting.php Grouped backports to the 4.6 branch. 2022-01-06 18:18:21 +00:00
functions.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
functions.wp-scripts.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
functions.wp-styles.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
general-template.php Multisite: Improve messaging for previously activated users. 2018-12-13 00:45:21 +00:00
http.php Backporting several bug fixes. 2019-10-14 19:02:25 +00:00
kses.php Update wp_kses_bad_protocol() to recognize : on uri attributes, 2019-12-12 18:46:23 +00:00
l10n.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
link-template.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 19:33:30 +00:00
load.php Bootstrap: Check that ini_get_all() exists before calling it, allows us to work around hosts who disable the function for "security purposes". 2016-08-31 06:06:32 +00:00
locale.php I18N: Move the WP_Locale class to its own file. 2016-06-28 11:53:28 +00:00
media-template.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
media.php Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
meta.php General: WordPress updates 2020-10-29 19:00:24 +00:00
ms-blogs.php Multisite: Remove unnecessary reference parameters. 2016-08-09 18:13:31 +00:00
ms-default-constants.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
ms-default-filters.php
ms-deprecated.php Multisite: Validate activation links. 2018-12-13 01:42:20 +00:00
ms-files.php
ms-functions.php Multisite: Use wp_rand() in signup key creation. 2017-01-11 05:32:07 +00:00
ms-load.php Docs: Correct and clarify various @since docs. 2016-08-04 22:56:41 +00:00
ms-settings.php Multisite: Fire the ms_loaded action after multisite's bootstrap has finished. 2016-06-29 19:00:28 +00:00
nav-menu-template.php Nav Menus: Move the Walker_Nav_Menu class to its own file. 2016-06-06 15:18:31 +00:00
nav-menu.php Docs: Improve the summaries and return descriptions for get_registered_nav_menus() and get_nav_menu_locations(). 2016-06-20 08:26:29 +00:00
option.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
pluggable-deprecated.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
pluggable.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
plugin.php Bootstrap/Load: Revert Plugin Global restoration around advance-cache.php. 2016-08-13 16:02:31 +00:00
post-formats.php
post-template.php Grouped backports to the 4.6 branch. 2022-08-30 15:48:21 +00:00
post-thumbnail-template.php Post Thumbnails: Add helper functions for attachment captions. 2016-06-29 17:28:28 +00:00
post.php Grouped backports to the 4.6 branch. 2022-01-06 18:18:21 +00:00
query.php User: Invalidate user_activation_key on password update. 2020-04-29 16:25:25 +00:00
registration-functions.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
registration.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
rest-api.php Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
revision.php Post Thumbnails: Prevent post thumbnail previews from spilling into other images. 2016-08-31 18:44:29 +00:00
rewrite.php Docs: Apply inline @see tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:02:28 +00:00
rss-functions.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
rss.php Docs: Use 3-digit, x.x.x-style semantic versioning for _doing_it_wrong(), _deprecated_function(), _deprecated_argument(), and _deprecated_file() throughout core. 2016-07-06 12:40:29 +00:00
script-loader.php External Librairies: Update jQuery.query to version 2.2.3. 2022-03-10 21:33:21 +00:00
session.php Docs: Apply inline @see tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:02:28 +00:00
shortcodes.php Grouped backports to the 4.6 branch. 2023-10-12 18:10:52 +00:00
taxonomy.php In is_object_in_term(), return error object rather than caching it. 2016-08-24 09:20:36 +00:00
template-loader.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
template.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
theme.php Backporting several bug fixes. 2019-10-14 19:02:25 +00:00
update.php Upgrade: Allow update checks on upgrader_process_complete to be run during Ajax requests. 2016-05-25 19:36:28 +00:00
user.php User: Invalidate user_activation_key on password update. 2020-04-29 16:25:25 +00:00
vars.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
version.php Grouped backports to the 4.6 branch. 2023-05-16 15:45:21 +00:00
widgets.php Grouped backports to the 4.6 branch. 2022-10-17 18:04:22 +00:00
wlwmanifest.xml
wp-db.php WPDB: Check that AUTH_SALT is not empty, Fix a PHP notice when AUTH_SALT is undefined. 2017-11-27 01:09:36 +00:00
wp-diff.php Docs: Apply inline @see tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:02:28 +00:00