Skip to content

Commit 664d4e6

Browse files
Merge branch 'trunk' into 66254-sync-gutenberg-24.1
2 parents 764eba0 + 79ff428 commit 664d4e6

37 files changed

Lines changed: 202 additions & 106 deletions

‎src/js/_enqueues/admin/common.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -692,7 +692,7 @@ $('.contextual-help-tabs').on( 'click', 'a', function(e) {
692692
$('.contextual-help-tabs .active').removeClass('active');
693693
link.parent('li').addClass('active');
694694

695-
panel = $( link.attr('href') );
695+
panel = $( document ).find( link.attr('href') );
696696

697697
// Panels.
698698
$('.help-tab-content').not( panel ).removeClass('active').hide();

‎src/wp-admin/includes/export.php‎

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -183,11 +183,15 @@ function export_wp( $args = array() ) {
183183
)
184184
);
185185

186+
// Cast thumbnail IDs to integers to prevent second-order SQL injection via user-controlled meta values.
187+
$thumbnails_ids = array_filter( array_map( 'absint', $thumbnails_ids ) );
188+
186189
$additional_ids = array_merge( $additional_ids, $attachment_ids, $thumbnails_ids );
187190
}
188191

189-
// Merge the additional IDs back with the original post IDs after processing all posts
190-
$post_ids = array_unique( array_merge( $post_ids, $additional_ids ) );
192+
// Merge the additional IDs back with the original post IDs after processing all posts.
193+
// Cast to integers as defense-in-depth, since $additional_ids may include values sourced from postmeta.
194+
$post_ids = array_unique( array_map( 'absint', array_merge( $post_ids, $additional_ids ) ) );
191195
}
192196

193197
/*
@@ -597,8 +601,10 @@ function wxr_filter_postmeta( $return_me, $meta_key ) {
597601

598602
// Fetch 20 posts at a time rather than loading the entire table into memory.
599603
while ( $next_posts = array_splice( $post_ids, 0, 20 ) ) {
600-
$where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
601-
$posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
604+
// Re-sanitize immediately before use, as defense-in-depth against the IDs being interpolated directly into SQL below.
605+
$next_posts = array_map( 'absint', $next_posts );
606+
$where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
607+
$posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
602608

603609
// Begin Loop.
604610
foreach ( $posts as $post ) {

‎src/wp-admin/includes/meta-boxes.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1257,6 +1257,8 @@ function link_target_meta_box( $link ) {
12571257
* if it matches the current link's relationship.
12581258
* Default empty string.
12591259
* @param mixed $deprecated Deprecated. Not used.
1260+
*
1261+
* @phpstan-param '' $deprecated
12601262
*/
12611263
function xfn_check( $xfn_relationship, $xfn_value = '', $deprecated = '' ) {
12621264
global $link;

‎src/wp-admin/includes/plugin-install.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -309,6 +309,8 @@ function install_dashboard() {
309309
* @since 4.6.0 The `$type_selector` parameter was deprecated.
310310
*
311311
* @param bool $deprecated Not used.
312+
*
313+
* @phpstan-param true $deprecated
312314
*/
313315
function install_search_form( $deprecated = true ) {
314316
$type = isset( $_REQUEST['type'] ) ? wp_unslash( $_REQUEST['type'] ) : 'term';

‎src/wp-admin/includes/plugin.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -907,6 +907,7 @@ function activate_plugins( $plugins, $redirect = '', $network_wide = false, $sil
907907
* @return bool|null|WP_Error True on success, false if `$plugins` is empty, `WP_Error` on failure.
908908
* `null` if filesystem credentials are required to proceed.
909909
*
910+
* @phpstan-param '' $deprecated
910911
* @phpstan-return ( $plugins is empty ? false : true|null|WP_Error )
911912
*/
912913
function delete_plugins( $plugins, $deprecated = '' ) {

‎src/wp-admin/includes/template.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2143,6 +2143,8 @@ function _admin_search_query() {
21432143
*
21442144
* @param string $title Optional. Title of the Iframe page. Default empty.
21452145
* @param bool $deprecated Not used.
2146+
*
2147+
* @phpstan-param false $deprecated
21462148
*/
21472149
function iframe_header( $title = '', $deprecated = false ) {
21482150
global $hook_suffix, $admin_body_class, $body_id, $wp_locale;

‎src/wp-admin/includes/upgrade.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,8 @@
4343
* @type string $password The password of the site owner, if their user account didn't already exist.
4444
* @type string $password_message The explanatory message regarding the password.
4545
* }
46+
*
47+
* @phpstan-param '' $deprecated
4648
*/
4749
function wp_install(
4850
$blog_title,

‎src/wp-includes/author-template.php‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,8 @@
2020
*
2121
* @param string $deprecated Deprecated.
2222
* @return string The author's display name, empty string if unknown.
23+
*
24+
* @phpstan-param '' $deprecated
2325
*/
2426
function get_the_author( $deprecated = '' ) {
2527
global $authordata;
@@ -57,6 +59,9 @@ function get_the_author( $deprecated = '' ) {
5759
* @param string $deprecated Deprecated.
5860
* @param bool $deprecated_echo Deprecated. Use get_the_author(). Echo the string or return it.
5961
* @return string The author's display name, from get_the_author().
62+
*
63+
* @phpstan-param '' $deprecated
64+
* @phpstan-param true $deprecated_echo
6065
*/
6166
function the_author( $deprecated = '', $deprecated_echo = true ) {
6267
if ( ! empty( $deprecated ) ) {
@@ -362,6 +367,8 @@ function get_the_author_posts_link() {
362367
* @since 4.4.0 Converted into a wrapper for get_the_author_posts_link()
363368
*
364369
* @param string $deprecated Unused.
370+
*
371+
* @phpstan-param '' $deprecated
365372
*/
366373
function the_author_posts_link( $deprecated = '' ) {
367374
if ( ! empty( $deprecated ) ) {

‎src/wp-includes/block-patterns.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -277,6 +277,8 @@ function wp_normalize_remote_block_pattern( $pattern ) {
277277
* @since 6.3.0 Add 'pattern-directory/core' to the pattern's 'source'.
278278
*
279279
* @param WP_Screen $deprecated Unused. Formerly the screen that the current request was triggered from.
280+
*
281+
* @phpstan-param null $deprecated
280282
*/
281283
function _load_remote_block_patterns( $deprecated = null ) {
282284
if ( ! empty( $deprecated ) ) {

‎src/wp-includes/block-supports/typography.php‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -573,9 +573,11 @@ function wp_get_computed_fluid_typography_value( $args = array() ) {
573573
* @type string $slug Kebab-case, unique identifier for the font size preset.
574574
* @type string|int|float $size CSS font-size value, including units if applicable.
575575
* }
576-
* @param bool|array $settings Optional Theme JSON settings array that overrides any global theme settings.
577-
* Default is false.
576+
* @param bool|array $settings Optional. Theme JSON settings array that overrides any global theme settings.
577+
* Passing a boolean is deprecated. Default empty array.
578578
* @return string|null Font-size value or null if a size is not passed in $preset.
579+
*
580+
* @phpstan-param array $settings
579581
*/
580582
function wp_get_typography_font_size_value( $preset, $settings = array() ) {
581583
if ( ! isset( $preset['size'] ) ) {

0 commit comments

Comments
 (0)