Skip to content

XML-RPC: Honor menu_order when creating and editing posts - #14189

Open
salvatorecorsi wants to merge 1 commit into
WordPress:trunkfrom
salvatorecorsi:fix/40863-xmlrpc-menu-order
Open

salvatorecorsi wants to merge 1 commit into
WordPress:trunkfrom
salvatorecorsi:fix/40863-xmlrpc-menu-order

Conversation

@salvatorecorsi

@salvatorecorsi salvatorecorsi commented Oct 11, 2026 •

Copy link
Copy Markdown

wp.newPost and wp.editPost silently discard a supplied menu_order: _insert_post() intersects the content struct with defaults that do not include this field. For example, creating a page with menu_order: 5 stores 0, and editing a page whose order is 10 to menu_order: 0 leaves 10.

Add menu_order with a default of 0 to the existing whitelist and document the parameter. The existing edit merge preserves the stored order when it is omitted. Add integration tests for posts and pages, positive/zero/negative values, and an edit that omits the field.

This follows the whitelist approach in the earlier patch by iworks on the ticket, focusing on the menu_order bug confirmed by the reporter.

Trac ticket: https://core.trac.wordpress.org/ticket/40863

Reproduction

  1. Call wp.newPost as an editor with post_title: "Menu order test", post_type: "page", and menu_order: 5. The saved order should be 5.
  2. Start with a page whose menu_order is 10 and call wp.editPost with menu_order: 0. The saved order should be 0.
  3. Edit that page with only post_title and confirm that its saved order is preserved.

Validation

  • Before the implementation change, the new wp.newPost tests had 3 failures in 4 cases, and the wp.editPost tests had 4 failures in 5 cases.
  • Native PHPUnit on PHP 8.3.28 and private MariaDB: the full XML-RPC classes passed 359 tests and 1,355 assertions. The create/edit classes separately passed 58 tests and 167 assertions.
  • WordPress PHPCS scan of the three changed files: no errors; one existing PreparedSQL.NotPrepared warning also reproduced on unchanged trunk. The error-only scan passed.
  • PHP compatibility scan, PHP syntax checks for all changed files, and git diff --check passed.
  • No JavaScript/assets changed; build and E2E checks were not run.

The local serialized PHPUnit runner invokes php vendor/bin/phpunit -c phpunit.xml.dist --filter '^Tests_XMLRPC_'. Coding standards and compatibility used php vendor/bin/phpcs --standard=phpcs.xml.dist --parallel=1 <three changed files> and php vendor/bin/phpcs --standard=phpcompat.xml.dist --parallel=1 <three changed files>.

GitHub CI

The full PHPUnit workflow passed all 64 configured PHP/database combinations, including single-site, multisite and memcached. Both E2E configurations, all six build configurations, PHPStan, PHP compatibility and coding standards also passed.

Five upgrade checks failed during WP-CLI installation: setup-php reported Could not setup wp-cli, then the initial wp core download failed with wp: command not found (exit 127), before executing the modified PR implementation. These setup failures leave overall CI failing; their logs and the passing PHPUnit matrix are recorded above for review.

Use of AI Tools

AI assistance: Yes
Tool(s): OpenAI Codex
Model(s): GPT-6
Used for: Ticket investigation, implementation, regression tests, local validation, this description, and an independent automated review. No human review is claimed; this PR is submitted for contributor and maintainer review.


This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.

Include menu_order in the existing post field whitelist and document the accepted parameter. Add regression coverage for posts and pages, zero and negative order values, and preservation when omitted from an edit.

See https://core.trac.wordpress.org/ticket/40863.
@github-actions

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props salvatorecorsi.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@salvatorecorsi

Copy link
Copy Markdown
Author

The full PHPUnit workflow passed all 64 PHP/database configurations, including multisite and memcached. E2E, build, PHPStan, compatibility and coding standards also passed.

The five failed upgrade jobs in this run failed during tool setup: setup-php reported Could not setup wp-cli, then the initial wp core download exited 127 with wp: command not found, before the modified implementation ran.

Could a maintainer rerun only those failed jobs? The targeted gh run rerun 38125458556 --failed attempt was denied with Must have admin rights to Repository. The logs do not indicate a code correction for this patch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant