Skip to content

Commit 9444ff6

Browse files
authored
Merge branch 'trunk' into fix/phpstan-callbacks
2 parents 6103aaa + 79ff428 commit 9444ff6

111 files changed

Lines changed: 4943 additions & 315 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎composer.json‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,11 @@
5858
},
5959
"config": {
6060
"audit": { "ignore": [ "GHSA-hmqg-cxww-wqhq", "PKSA-rdkp-vv9z-mjkg" ] },
61+
"policy": {
62+
"advisories": {
63+
"ignore-id": [ "GHSA-hmqg-cxww-wqhq", "PKSA-rdkp-vv9z-mjkg" ]
64+
}
65+
},
6166
"allow-plugins": {
6267
"dealerdirect/phpcodesniffer-composer-installer": true
6368
},

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
"url": "https://develop.svn.wordpress.org/trunk"
88
},
99
"gutenberg": {
10-
"sha": "5715a61334c4d29f21b67cf34b46061dc1b62502",
10+
"sha": "50ad79ef7ebc5f1d2a75def068887e33a15f2634",
1111
"ghcrRepo": "WordPress/gutenberg/gutenberg-wp-develop-build"
1212
},
1313
"engines": {

‎src/js/_enqueues/admin/common.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -692,7 +692,7 @@ $('.contextual-help-tabs').on( 'click', 'a', function(e) {
692692
$('.contextual-help-tabs .active').removeClass('active');
693693
link.parent('li').addClass('active');
694694

695-
panel = $( link.attr('href') );
695+
panel = $( document ).find( link.attr('href') );
696696

697697
// Panels.
698698
$('.help-tab-content').not( panel ).removeClass('active').hide();

‎src/wp-admin/admin-header.php‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,6 +95,10 @@
9595
<title><?php echo esc_html( $admin_title ); ?></title>
9696
<?php
9797

98+
/*
99+
* The dependencies of `colors` and the `utils` script are prefetched from the login screen by
100+
* wp_prefetch_admin_assets(), which needs updating if these change.
101+
*/
98102
wp_enqueue_style( 'colors' );
99103
wp_enqueue_script( 'utils' );
100104
wp_enqueue_script( 'svg-painter' );

‎src/wp-admin/admin.php‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -118,6 +118,10 @@
118118
$date_format = __( 'F j, Y' );
119119
$time_format = __( 'g:i a' );
120120

121+
/*
122+
* The `jquery` dependency of this script is prefetched from the login screen by
123+
* wp_prefetch_admin_assets(), which needs updating if this changes.
124+
*/
121125
wp_enqueue_script( 'common' );
122126

123127
/**

‎src/wp-admin/css/install.css‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -397,8 +397,8 @@ body.language-chooser {
397397
margin-right: 15px;
398398
}
399399

400-
.button.hide-if-no-js,
401-
.hide-if-no-js {
400+
.hide-if-no-js,
401+
.button.wp-hide-pw.user-new-password-toggle.hide-if-no-js {
402402
display: none;
403403
}
404404

‎src/wp-admin/edit-form-blocks.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -342,6 +342,7 @@ static function ( $classes ) {
342342
/**
343343
* Styles
344344
*/
345+
// Prefetched for the block editor by wp_prefetch_admin_assets(), which needs updating if this changes.
345346
wp_enqueue_style( 'wp-edit-post' );
346347

347348
/**

‎src/wp-admin/includes/admin-filters.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@
4848
add_action( 'admin_head', 'wp_admin_canonical_url' );
4949
add_action( 'admin_head', 'wp_site_icon' );
5050
add_action( 'admin_head', 'wp_admin_viewport_meta' );
51+
add_action( 'admin_head', 'wp_prefetch_admin_assets' );
5152
add_action( 'customize_controls_head', 'wp_admin_viewport_meta' );
5253
add_filter( 'nav_menu_meta_box_object', '_wp_nav_menu_meta_box_object' );
5354

‎src/wp-admin/includes/export.php‎

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -183,11 +183,15 @@ function export_wp( $args = array() ) {
183183
)
184184
);
185185

186+
// Cast thumbnail IDs to integers to prevent second-order SQL injection via user-controlled meta values.
187+
$thumbnails_ids = array_filter( array_map( 'absint', $thumbnails_ids ) );
188+
186189
$additional_ids = array_merge( $additional_ids, $attachment_ids, $thumbnails_ids );
187190
}
188191

189-
// Merge the additional IDs back with the original post IDs after processing all posts
190-
$post_ids = array_unique( array_merge( $post_ids, $additional_ids ) );
192+
// Merge the additional IDs back with the original post IDs after processing all posts.
193+
// Cast to integers as defense-in-depth, since $additional_ids may include values sourced from postmeta.
194+
$post_ids = array_unique( array_map( 'absint', array_merge( $post_ids, $additional_ids ) ) );
191195
}
192196

193197
/*
@@ -597,8 +601,10 @@ function wxr_filter_postmeta( $return_me, $meta_key ) {
597601

598602
// Fetch 20 posts at a time rather than loading the entire table into memory.
599603
while ( $next_posts = array_splice( $post_ids, 0, 20 ) ) {
600-
$where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
601-
$posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
604+
// Re-sanitize immediately before use, as defense-in-depth against the IDs being interpolated directly into SQL below.
605+
$next_posts = array_map( 'absint', $next_posts );
606+
$where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
607+
$posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
602608

603609
// Begin Loop.
604610
foreach ( $posts as $post ) {

‎src/wp-admin/includes/meta-boxes.php‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1257,6 +1257,8 @@ function link_target_meta_box( $link ) {
12571257
* if it matches the current link's relationship.
12581258
* Default empty string.
12591259
* @param mixed $deprecated Deprecated. Not used.
1260+
*
1261+
* @phpstan-param '' $deprecated
12601262
*/
12611263
function xfn_check( $xfn_relationship, $xfn_value = '', $deprecated = '' ) {
12621264
global $link;

0 commit comments

Comments
 (0)