X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/53f4633144ed68c8b8fb5861f992b5489894a940..d3947bc013df7edd54b46deed8230d2eeafc5ecb:/wp-admin/includes/class-wp-press-this.php diff --git a/wp-admin/includes/class-wp-press-this.php b/wp-admin/includes/class-wp-press-this.php index 58ed2866..0288ed05 100644 --- a/wp-admin/includes/class-wp-press-this.php +++ b/wp-admin/includes/class-wp-press-this.php @@ -46,7 +46,7 @@ class WP_Press_This { * * @since 4.2.0 * - * @param bool false Whether to redirect in parent window or not. Default false. + * @param bool $redirect Whether to redirect in parent window or not. Default false. */ 'redirInParent' => apply_filters( 'press_this_redirect_in_parent', false ), ); @@ -91,7 +91,7 @@ class WP_Press_This { } } - // Edxpected slashed + // Expected slashed return wp_slash( $content ); } @@ -112,7 +112,7 @@ class WP_Press_This { wp_send_json_error( array( 'errorMessage' => __( 'Invalid post.' ) ) ); } - $post = array( + $post_data = array( 'ID' => $post_id, 'post_title' => ( ! empty( $_POST['post_title'] ) ) ? sanitize_text_field( trim( $_POST['post_title'] ) ) : '', 'post_content' => ( ! empty( $_POST['post_content'] ) ) ? trim( $_POST['post_content'] ) : '', @@ -125,23 +125,33 @@ class WP_Press_This { if ( ! empty( $_POST['post_status'] ) && 'publish' === $_POST['post_status'] ) { if ( current_user_can( 'publish_posts' ) ) { - $post['post_status'] = 'publish'; + $post_data['post_status'] = 'publish'; } else { - $post['post_status'] = 'pending'; + $post_data['post_status'] = 'pending'; } } - $post['post_content'] = $this->side_load_images( $post_id, $post['post_content'] ); + $post_data['post_content'] = $this->side_load_images( $post_id, $post_data['post_content'] ); - $updated = wp_update_post( $post, true ); + /** + * Filter the post data of a Press This post before saving/updating, after + * side_load_images action had run. + * + * @since 4.5.0 + * + * @param array $post_data The post data. + */ + $post_data = apply_filters( 'press_this_save_post', $post_data ); + + $updated = wp_update_post( $post_data, true ); if ( is_wp_error( $updated ) ) { wp_send_json_error( array( 'errorMessage' => $updated->get_error_message() ) ); } else { - if ( isset( $post['post_format'] ) ) { - if ( current_theme_supports( 'post-formats', $post['post_format'] ) ) { - set_post_format( $post_id, $post['post_format'] ); - } elseif ( $post['post_format'] ) { + if ( isset( $post_data['post_format'] ) ) { + if ( current_theme_supports( 'post-formats', $post_data['post_format'] ) ) { + set_post_format( $post_id, $post_data['post_format'] ); + } elseif ( $post_data['post_format'] ) { set_post_format( $post_id, false ); } } @@ -167,7 +177,7 @@ class WP_Press_This { * @param int $post_id Post ID. * @param string $status Post status. */ - $redirect = apply_filters( 'press_this_save_redirect', $redirect, $post_id, $post['post_status'] ); + $redirect = apply_filters( 'press_this_save_redirect', $redirect, $post_id, $post_data['post_status'] ); if ( $redirect ) { wp_send_json_success( array( 'redirect' => $redirect, 'force' => $forceRedirect ) ); @@ -272,7 +282,7 @@ class WP_Press_This { return $remote_url; } - $useful_html_elements = array( + $allowed_elements = array( 'img' => array( 'src' => true, 'width' => true, @@ -294,7 +304,7 @@ class WP_Press_This { ); $source_content = wp_remote_retrieve_body( $remote_url ); - $source_content = wp_kses( $source_content, $useful_html_elements ); + $source_content = wp_kses( $source_content, $allowed_elements ); return $source_content; } @@ -369,7 +379,7 @@ class WP_Press_This { return ''; // Return empty rather than a truncated/invalid URL } - // Does not look like an URL. + // Does not look like a URL. if ( ! preg_match( '/^([!#$&-;=?-\[\]_a-z~]|%[0-9a-fA-F]{2})+$/', $url ) ) { return ''; } @@ -390,8 +400,8 @@ class WP_Press_This { /** * Utility method to limit image source URLs. * - * Excluded URLs include share-this type buttons, loaders, spinners, spacers, WP interface images, - * tiny buttons or thumbs, mathtag.com or quantserve.com images, or the WP stats gif. + * Excluded URLs include share-this type buttons, loaders, spinners, spacers, WordPress interface images, + * tiny buttons or thumbs, mathtag.com or quantserve.com images, or the WordPress.com stats gif. * * @ignore * @since 4.2.0 @@ -402,32 +412,32 @@ class WP_Press_This { private function _limit_img( $src ) { $src = $this->_limit_url( $src ); - if ( preg_match( '/\/ad[sx]{1}?\//', $src ) ) { + if ( preg_match( '!/ad[sx]?/!i', $src ) ) { // Ads return ''; - } else if ( preg_match( '/(\/share-?this[^\.]+?\.[a-z0-9]{3,4})(\?.*)?$/', $src ) ) { + } else if ( preg_match( '!(/share-?this[^.]+?\.[a-z0-9]{3,4})(\?.*)?$!i', $src ) ) { // Share-this type button return ''; - } else if ( preg_match( '/\/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)/', $src ) ) { + } else if ( preg_match( '!/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)!i', $src ) ) { // Loaders, spinners, spacers return ''; - } else if ( preg_match( '/\/([^\.\/]+[-_]{1})?(spinner|loading|spacer|blank)s?([-_]{1}[^\.\/]+)?\.[a-z0-9]{3,4}/', $src ) ) { + } else if ( preg_match( '!/([^./]+[-_])?(spinner|loading|spacer|blank)s?([-_][^./]+)?\.[a-z0-9]{3,4}!i', $src ) ) { // Fancy loaders, spinners, spacers return ''; - } else if ( preg_match( '/([^\.\/]+[-_]{1})?thumb[^.]*\.(gif|jpg|png)$/', $src ) ) { + } else if ( preg_match( '!([^./]+[-_])?thumb[^.]*\.(gif|jpg|png)$!i', $src ) ) { // Thumbnails, too small, usually irrelevant to context return ''; - } else if ( preg_match( '/\/wp-includes\//', $src ) ) { - // Classic WP interface images + } else if ( false !== stripos( $src, '/wp-includes/' ) ) { + // Classic WordPress interface images return ''; - } else if ( preg_match( '/[^\d]{1}\d{1,2}x\d+\.(gif|jpg|png)$/', $src ) ) { + } else if ( preg_match( '![^\d]\d{1,2}x\d+\.(gif|jpg|png)$!i', $src ) ) { // Most often tiny buttons/thumbs (< 100px wide) return ''; - } else if ( preg_match( '/\/pixel\.(mathtag|quantserve)\.com/', $src ) ) { + } else if ( preg_match( '!/pixel\.(mathtag|quantserve)\.com!i', $src ) ) { // See mathtag.com and https://www.quantcast.com/how-we-do-it/iab-standard-measurement/how-we-collect-data/ return ''; - } else if ( preg_match( '/\/[gb]\.gif(\?.+)?$/', $src ) ) { - // Classic WP stats gif + } else if ( preg_match( '!/[gb]\.gif(\?.+)?$!i', $src ) ) { + // WordPress.com stats gif return ''; } @@ -452,19 +462,19 @@ class WP_Press_This { if ( empty( $src ) ) return ''; - if ( preg_match( '/\/\/(m|www)\.youtube\.com\/(embed|v)\/([^\?]+)\?.+$/', $src, $src_matches ) ) { + if ( preg_match( '!//(m|www)\.youtube\.com/(embed|v)/([^?]+)\?.+$!i', $src, $src_matches ) ) { // Embedded Youtube videos (www or mobile) $src = 'https://www.youtube.com/watch?v=' . $src_matches[3]; - } else if ( preg_match( '/\/\/player\.vimeo\.com\/video\/([\d]+)([\?\/]{1}.*)?$/', $src, $src_matches ) ) { + } else if ( preg_match( '!//player\.vimeo\.com/video/([\d]+)([?/].*)?$!i', $src, $src_matches ) ) { // Embedded Vimeo iframe videos $src = 'https://vimeo.com/' . (int) $src_matches[1]; - } else if ( preg_match( '/\/\/vimeo\.com\/moogaloop\.swf\?clip_id=([\d]+)$/', $src, $src_matches ) ) { + } else if ( preg_match( '!//vimeo\.com/moogaloop\.swf\?clip_id=([\d]+)$!i', $src, $src_matches ) ) { // Embedded Vimeo Flash videos $src = 'https://vimeo.com/' . (int) $src_matches[1]; - } else if ( preg_match( '/\/\/vine\.co\/v\/([^\/]+)\/embed/', $src, $src_matches ) ) { + } else if ( preg_match( '!//vine\.co/v/([^/]+)/embed!i', $src, $src_matches ) ) { // Embedded Vine videos $src = 'https://vine.co/v/' . $src_matches[1]; - } else if ( preg_match( '/\/\/(www\.)?dailymotion\.com\/embed\/video\/([^\/\?]+)([\/\?]{1}.+)?/', $src, $src_matches ) ) { + } else if ( preg_match( '!//(www\.)?dailymotion\.com/embed/video/([^/?]+)([/?].+)?!i', $src, $src_matches ) ) { // Embedded Daily Motion videos $src = 'https://www.dailymotion.com/video/' . $src_matches[2]; } else { @@ -876,7 +886,7 @@ class WP_Press_This { if ( current_user_can( $taxonomy->cap->edit_terms ) ) { ?> -