wp_die( __( 'Multisite support is not enabled.' ) );
if ( ! current_user_can( 'manage_sites' ) )
- wp_die( __( 'You do not have permission to access this page.' ) );
+ wp_die( __( 'You do not have permission to access this page.' ), 403 );
$wp_list_table = _get_list_table( 'WP_MS_Sites_List_Table' );
$pagenum = $wp_list_table->get_pagenum();
$title = __( 'Sites' );
$parent_file = 'sites.php';
-add_screen_option( 'per_page', array( 'label' => _x( 'Sites', 'sites per page (screen options)' ) ) );
+add_screen_option( 'per_page' );
get_current_screen()->add_help_tab( array(
'id' => 'overview',
get_current_screen()->set_help_sidebar(
'<p><strong>' . __('For more information:') . '</strong></p>' .
- '<p>' . __('<a href="http://codex.wordpress.org/Network_Admin_Sites_Screen" target="_blank">Documentation on Site Management</a>') . '</p>' .
- '<p>' . __('<a href="http://wordpress.org/support/forum/multisite/" target="_blank">Support Forums</a>') . '</p>'
+ '<p>' . __('<a href="https://codex.wordpress.org/Network_Admin_Sites_Screen" target="_blank">Documentation on Site Management</a>') . '</p>' .
+ '<p>' . __('<a href="https://wordpress.org/support/forum/multisite/" target="_blank">Support Forums</a>') . '</p>'
);
$id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
/** This action is documented in wp-admin/network/edit.php */
do_action( 'wpmuadminedit' );
+ // A list of valid actions and their associated messaging for confirmation output.
+ $manage_actions = array(
+ 'activateblog' => __( 'You are about to activate the site %s' ),
+ 'deactivateblog' => __( 'You are about to deactivate the site %s' ),
+ 'unarchiveblog' => __( 'You are about to unarchive the site %s.' ),
+ 'archiveblog' => __( 'You are about to archive the site %s.' ),
+ 'unspamblog' => __( 'You are about to unspam the site %s.' ),
+ 'spamblog' => __( 'You are about to mark the site %s as spam.' ),
+ 'deleteblog' => __( 'You are about to delete the site %s.' ),
+ 'unmatureblog' => __( 'You are about to mark the site %s as mature.' ),
+ 'matureblog' => __( 'You are about to mark the site %s as not mature.' ),
+ );
+
if ( 'confirm' === $_GET['action'] ) {
- check_admin_referer( 'confirm' );
+ // The action2 parameter contains the action being taken on the site.
+ $site_action = $_GET['action2'];
+
+ if ( ! array_key_exists( $site_action, $manage_actions ) ) {
+ wp_die( __( 'The requested action is not valid.' ) );
+ }
+
+ // The mature/unmature UI exists only as external code. Check the "confirm" nonce for backward compatibility.
+ if ( 'matureblog' === $site_action || 'unmatureblog' === $site_action ) {
+ check_admin_referer( 'confirm' );
+ } else {
+ check_admin_referer( $site_action . '_' . $id );
+ }
if ( ! headers_sent() ) {
nocache_headers();
header( 'Content-Type: text/html; charset=utf-8' );
}
- if ( $current_site->blog_id == $id )
+
+ if ( $current_site->blog_id == $id ) {
wp_die( __( 'You are not allowed to change the current site.' ) );
+ }
+
+ $site_details = get_blog_details( $id );
+ $site_address = untrailingslashit( $site_details->domain . $site_details->path );
+
+ require_once( ABSPATH . 'wp-admin/admin-header.php' );
?>
- <!DOCTYPE html>
- <html xmlns="http://www.w3.org/1999/xhtml" <?php language_attributes(); ?>>
- <head>
- <meta name="viewport" content="width=device-width" />
- <title><?php _e( 'WordPress › Confirm your action' ); ?></title>
-
- <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
- <?php
- wp_admin_css( 'install', true );
- wp_admin_css( 'ie', true );
- ?>
- </head>
- <body class="wp-core-ui">
- <h1 id="logo"><a href="<?php echo esc_url( __( 'http://wordpress.org/' ) ); ?>"><?php _e( 'WordPress' ); ?></a></h1>
- <form action="sites.php?action=<?php echo esc_attr( $_GET['action2'] ) ?>" method="post">
- <input type="hidden" name="action" value="<?php echo esc_attr( $_GET['action2'] ) ?>" />
+ <div class="wrap">
+ <h1><?php _e( 'Confirm your action' ); ?></h1>
+ <form action="sites.php?action=<?php echo esc_attr( $site_action ); ?>" method="post">
+ <input type="hidden" name="action" value="<?php echo esc_attr( $site_action ); ?>" />
<input type="hidden" name="id" value="<?php echo esc_attr( $id ); ?>" />
<input type="hidden" name="_wp_http_referer" value="<?php echo esc_attr( wp_get_referer() ); ?>" />
- <?php wp_nonce_field( $_GET['action2'], '_wpnonce', false ); ?>
- <p><?php echo esc_html( wp_unslash( $_GET['msg'] ) ); ?></p>
- <?php submit_button( __('Confirm'), 'button' ); ?>
+ <?php wp_nonce_field( $site_action . '_' . $id, '_wpnonce', false ); ?>
+ <p><?php echo sprintf( $manage_actions[ $site_action ], $site_address ); ?></p>
+ <?php submit_button( __( 'Confirm' ), 'button' ); ?>
</form>
- </body>
- </html>
+ </div>
<?php
+ require_once( ABSPATH . 'wp-admin/admin-footer.php' );
exit();
+ } elseif ( array_key_exists( $_GET['action'], $manage_actions ) ) {
+ $action = $_GET['action'];
+ check_admin_referer( $action . '_' . $id );
+ } elseif ( 'allblogs' === $_GET['action'] ) {
+ check_admin_referer( 'bulk-sites' );
}
$updated_action = '';
- $manage_actions = array( 'deleteblog', 'allblogs', 'archiveblog', 'unarchiveblog', 'activateblog', 'deactivateblog', 'unspamblog', 'spamblog', 'unmatureblog', 'matureblog' );
- if ( in_array( $_GET['action'], $manage_actions ) ) {
- $action = $_GET['action'];
- if ( 'allblogs' === $action )
- $action = 'bulk-sites';
-
- check_admin_referer( $action );
- }
-
switch ( $_GET['action'] ) {
case 'deleteblog':
if ( ! current_user_can( 'delete_sites' ) )
- wp_die( __( 'You do not have permission to access this page.' ) );
+ wp_die( __( 'You do not have permission to access this page.' ), '', array( 'response' => 403 ) );
$updated_action = 'not_deleted';
if ( $id != '0' && $id != $current_site->blog_id && current_user_can( 'delete_site', $id ) ) {
case 'activateblog':
update_blog_status( $id, 'deleted', '0' );
+
+ /**
+ * Fires after a network site is activated.
+ *
+ * @since MU
+ *
+ * @param string $id The ID of the activated site.
+ */
do_action( 'activate_blog', $id );
break;
case 'deactivateblog':
+ /**
+ * Fires before a network site is deactivated.
+ *
+ * @since MU
+ *
+ * @param string $id The ID of the site being deactivated.
+ */
do_action( 'deactivate_blog', $id );
update_blog_status( $id, 'deleted', '1' );
break;
break;
}
- if ( empty( $updated_action ) && in_array( $_GET['action'], $manage_actions ) )
+ if ( empty( $updated_action ) && array_key_exists( $_GET['action'], $manage_actions ) ) {
$updated_action = $_GET['action'];
+ }
if ( ! empty( $updated_action ) ) {
wp_safe_redirect( add_query_arg( array( 'updated' => $updated_action ), wp_get_referer() ) );
$msg = __( 'Site marked as spam.' );
break;
default:
+ /**
+ * Filter a specific, non-default site-updated message in the Network admin.
+ *
+ * The dynamic portion of the hook name, `$_GET['updated']`, refers to the
+ * non-default site update action.
+ *
+ * @since 3.1.0
+ *
+ * @param string $msg The update message. Default 'Settings saved'.
+ */
$msg = apply_filters( 'network_sites_updated_message_' . $_GET['updated'], __( 'Settings saved.' ) );
break;
}
if ( ! empty( $msg ) )
- $msg = '<div class="updated" id="message"><p>' . $msg . '</p></div>';
+ $msg = '<div class="updated" id="message notice is-dismissible"><p>' . $msg . '</p></div>';
}
$wp_list_table->prepare_items();
?>
<div class="wrap">
-<h2><?php _e( 'Sites' ) ?>
+<h1><?php _e( 'Sites' ); ?>
<?php if ( current_user_can( 'create_sites') ) : ?>
- <a href="<?php echo network_admin_url('site-new.php'); ?>" class="add-new-h2"><?php echo esc_html_x( 'Add New', 'site' ); ?></a>
+ <a href="<?php echo network_admin_url('site-new.php'); ?>" class="page-title-action"><?php echo esc_html_x( 'Add New', 'site' ); ?></a>
<?php endif; ?>
<?php if ( isset( $_REQUEST['s'] ) && $_REQUEST['s'] ) {
printf( '<span class="subtitle">' . __( 'Search results for “%s”' ) . '</span>', esc_html( $s ) );
} ?>
-</h2>
+</h1>
<?php echo $msg; ?>
-<form action="" method="get" id="ms-search">
+<form method="get" id="ms-search">
<?php $wp_list_table->search_box( __( 'Search Sites' ), 'site' ); ?>
<input type="hidden" name="action" value="blogs" />
</form>