Commit Graph

39177 Commits

Author SHA1 Message Date
audrasjb be3794d3b5 WordPress 5.1.19.
Built from https://develop.svn.wordpress.org/branches/5.1@58517


git-svn-id: http://core.svn.wordpress.org/branches/5.1@57965 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-06-24 16:30:47 +00:00
audrasjb 96cdea312b Editor: Fix Path Traversal issue on Windows in Template-Part Block.
Merges [58470] to the 5.1 branch.
Props xknown, jorbin.



Built from https://develop.svn.wordpress.org/branches/5.1@58491


git-svn-id: http://core.svn.wordpress.org/branches/5.1@57940 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-06-24 15:41:46 +00:00
Aaron Jorbin 1d0534adf3 General: Backport polyfills for `str_ends_with()` and `str_starts_with()`.
Merges [52040], [56016], and [56015] to 5.1 branch.

Props ocean90, SergeyBiryukov, desrosj, joemcgill, jorbin, mukesh27.

Built from https://develop.svn.wordpress.org/branches/5.1@57459


git-svn-id: http://core.svn.wordpress.org/branches/5.1@56960 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 18:23:45 +00:00
Joe McGill 238ab873be WordPress 5.1.18.
Built from https://develop.svn.wordpress.org/branches/5.1@57425


git-svn-id: http://core.svn.wordpress.org/branches/5.1@56931 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 16:21:46 +00:00
Aaron Jorbin 5abcc8cec5 Grouped Backports to the 5.1 branch
- Install: When populating options, maybe_serialize instead of always serialize.
- Uploads: Check for and verify ZIP archives.

Merges [57388] and [57389] to the 5.1 branch.

Props costdev, peterwilsoncc, azaozz, tykoted, johnbillion, desrosj, afragen, jorbin, xknown.

Built from https://develop.svn.wordpress.org/branches/5.1@57404


git-svn-id: http://core.svn.wordpress.org/branches/5.1@56910 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2024-01-30 15:00:47 +00:00
audrasjb d25076284a WordPress 5.1.17.
Built from https://develop.svn.wordpress.org/branches/5.1@56879


git-svn-id: http://core.svn.wordpress.org/branches/5.1@56390 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:25:54 +00:00
davidbaumwald 27cb9e55ea Grouped backports to the 5.1 branch.
- Comments: Prevent users who can not see a post from seeing comments on it.
- Shortcodes: Restrict media shortcode ajax to certain type.
- REST API: Ensure no-cache headers are sent when methods are overridden.
- REST API: Limit `search_columns` for users without `list_users`.
- Prevent unintended behavior when certain objects are unserialized.

Merges [56833], [56834], [56835], [56836], and [56838] to the 5.1 branch.
Props xknown, jorbin, joehoyle, timothyblynjacobs, peterwilsoncc, ehtis, tykoted, antpb, rmccue.
Built from https://develop.svn.wordpress.org/branches/5.1@56873


git-svn-id: http://core.svn.wordpress.org/branches/5.1@56384 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-10-12 18:20:45 +00:00
audrasjb 17438da419 Grouped backports to the 5.1 branch.
- Media: Prevent CSRF setting attachment thumbnails.
- Embeds: Add protocol validation for WordPress Embed code.
- I18N: Introduce sanitization function for locale.
- Editor: Ensure block comments are of a valid form.

Merges [55760-55764] to the 5.1 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.


Built from https://develop.svn.wordpress.org/branches/5.1@55790


git-svn-id: http://core.svn.wordpress.org/branches/5.1@55302 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-05-16 16:02:49 +00:00
Peter Wilson 09eda8a2a9 I18N: Add new strings to `about.php` for use with end-of-life updates.
This changeset adds two additional translation strings in the changelog file, for use when releasing the final version of WordPress on a particular branch.

Props peterwilsoncc, audrasjb, mukesh27, mukesh27.
Merges [55350] to the 5.1 branch.
Fixes #57216.

Built from https://develop.svn.wordpress.org/branches/5.1@55381


git-svn-id: http://core.svn.wordpress.org/branches/5.1@54914 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2023-02-21 02:58:44 +00:00
audrasjb 158cb3d440 WordPress 5.1.15.
Built from https://develop.svn.wordpress.org/branches/5.1@54593


git-svn-id: http://core.svn.wordpress.org/branches/5.1@54147 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 19:54:50 +00:00
audrasjb 6a2168a131 Grouped backports to the 5.1 branch.
- Media: Refactor search by filename within the admin,
- REST API: Lockdown post parameter of the terms endpoint,
- Customize: Escape blogname option in underscores templates,
- Query: Validate relation in `WP_Date_Query`,
- Posts, Post types: Apply KSES to post-by-email content,
- General: Validate host on "Are you sure?" screen,
- Posts, Post types: Remove emails from post-by-email logs,
- Pings/trackbacks: Apply KSES to all trackbacks,
- Mail: Reset PHPMailer properties between use,
- Widgets: Escape RSS error messages for display.

Merges [54521-54530] to the 5.1 branch.
Props voldemortensen, johnbillion, paulkevan, peterwilsoncc, xknown, dd32, audrasjb, martinkrcho, vortfu, davidbaumwald, tykoted, timothyblynjacobs, johnjamesjacoby, ehtis, matveb, talldanwp.

Built from https://develop.svn.wordpress.org/branches/5.1@54570


git-svn-id: http://core.svn.wordpress.org/branches/5.1@54124 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-17 18:15:35 +00:00
Peter Wilson a8c63cc51c Security: Introduce strings to indicate support status.
Add strings for use in future maintenance/security releases to indicate the security support status of the version of WordPress.

Two strings are introduced:

* indicating the version of WordPress is not receiving security updates, and,
* indicating the version of WordPress will shortly stop receiving security updates.

This change does not make use of the strings, the purpose is to make them available to translators prior to dropping support of selected versions of WordPress.

Props costdev, chesio, robinwpdeveloper, desrosj, rudlinkon, mukesh27, sumitbagthariya16.
Merges [54322] to the 5.1 branch.
See #56532.


Built from https://develop.svn.wordpress.org/branches/5.1@54439


git-svn-id: http://core.svn.wordpress.org/branches/5.1@53998 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-10-10 05:11:49 +00:00
desrosj ed6d8dc7dd WordPress 5.1.14.
Built from https://develop.svn.wordpress.org/branches/5.1@53996


git-svn-id: http://core.svn.wordpress.org/branches/5.1@53555 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 17:34:27 +00:00
Sergey Biryukov f5cc02c70c Grouped backports to the 5.1 branch.
- Posts, Post Types: Escape output within `the_meta()`.
- General: Ensure bookmark query limits are numeric.
- Plugins: Escape output in error messages.
- Build/Test Tools: Allow the PHPCS plugin in Composer configuration.

Merges [52412,53958-53960] to the 5.1 branch.
Props tykoted, martinkrcho, xknown, dd32, peterwilsoncc, paulkevan, timothyblynjacobs.

Built from https://develop.svn.wordpress.org/branches/5.1@53972


git-svn-id: http://core.svn.wordpress.org/branches/5.1@53531 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-08-30 15:41:44 +00:00
davidbaumwald 2108a32b6b WordPress 5.1.13.
Built from https://develop.svn.wordpress.org/branches/5.1@52877


git-svn-id: http://core.svn.wordpress.org/branches/5.1@52466 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 22:04:43 +00:00
Sergey Biryukov 5123ad719e External Librairies: Update jQuery.query to version 2.2.3.
This updates the "jquery-query" library from version 2.1.7 to 2.2.3.

Props jorbin, peterwilsoncc, xknown, audrasjb, jorgefilipecosta.
Merges [52844] to the 5.1 branch.
Built from https://develop.svn.wordpress.org/branches/5.1@52855


git-svn-id: http://core.svn.wordpress.org/branches/5.1@52444 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-03-10 21:20:43 +00:00
desrosj 706a922c0b WordPress 5.1.12.
Built from https://develop.svn.wordpress.org/branches/5.1@52494


git-svn-id: http://core.svn.wordpress.org/branches/5.1@52086 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:52:14 +00:00
desrosj 68c2c7fd67 Grouped backports to the 5.1 branch.
- Query: Improve sanitization within `WP_Tax_Query`.
- Query: Improve sanitization within `WP_Meta_Query`.
- Upgrade/Install: Avoid using `unserialize()` unnecessarily.
- Formatting: Correctly encode ASCII characters in post slugs.

Merges [52454-52457] to the 5.1 branch.
Props vortfu, dd32, ehtis, zieladam, whyisjake, xknown, peterwilsoncc, desrosj, iandunn.
Built from https://develop.svn.wordpress.org/branches/5.1@52472


git-svn-id: http://core.svn.wordpress.org/branches/5.1@52064 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2022-01-06 18:14:44 +00:00
desrosj 0fa98b27df Block Editor: Additional package updates.
Built from https://develop.svn.wordpress.org/branches/5.1@51834


git-svn-id: http://core.svn.wordpress.org/branches/5.1@51441 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-21 16:54:46 +00:00
desrosj 15135a859f WordPress 5.1.11.
Built from https://develop.svn.wordpress.org/branches/5.1@51765


git-svn-id: http://core.svn.wordpress.org/branches/5.1@51372 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-08 21:41:41 +00:00
desrosj ce24651a68 Grouped merges for 5.1.11.
- Update `lodash` to the latest version `4.17.21`.
- Disable some attributes for rich text.
- Use hashed/deterministic moduleIDs in webpack config.

Props ellatrix, peterwilsoncc, get_dave, mcsf, talldanwp, youknowriad, desrosj, nerrad, gziolo.
Merges [50940-50941,50984-50985,51426] to the 5.1 branch.
Built from https://develop.svn.wordpress.org/branches/5.1@51757


git-svn-id: http://core.svn.wordpress.org/branches/5.1@51364 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-09-08 21:23:50 +00:00
Peter Wilson 8b1d8dcec2 WordPress 5.1.10.
Built from https://develop.svn.wordpress.org/branches/5.1@50875


git-svn-id: http://core.svn.wordpress.org/branches/5.1@50484 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 23:17:23 +00:00
Peter Wilson ddc05a4949 External libraries: Improve attachment handling in PHPMailer
Props: audrasjb, ayeshrajans, desrosj, peterwilsoncc, xknown.
Partially merges [50799] to the 5.1 branch.


Built from https://develop.svn.wordpress.org/branches/5.1@50853


git-svn-id: http://core.svn.wordpress.org/branches/5.1@50462 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-05-12 22:30:28 +00:00
Peter Wilson 4dc4456159 Version bump for 5.1.9.
Built from https://develop.svn.wordpress.org/branches/5.1@50742


git-svn-id: http://core.svn.wordpress.org/branches/5.1@50351 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:39:44 +00:00
Peter Wilson 081990972e Grouped merges for 5.1.9.
* REST API: Allow authors to read their own password protected posts.
* About page update

Merges [50717] to the 5.1 branch.

Built from https://develop.svn.wordpress.org/branches/5.1@50730


git-svn-id: http://core.svn.wordpress.org/branches/5.1@50339 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-04-15 01:12:45 +00:00
desrosj ec8147c8dd Build/Test Tools: Backport GitHub Action and build improvements to the 5.1 branch.
This backports several build and test tool improvements to the 5.1 branch. Most notably, this includes:

- The changes required to allow each workflow to be triggered by the `workflow_dispatch` event so that tests can be run on a schedule [50590].
- Splitting single site and multisite tests into parallel jobs [50379].
- Split slow tests into separate, parallel jobs for PHP <= 5.6 [50444].
- Better branch and path scoping for GitHub Action workflows when running on `pull_request` [50432,50479].
- Several `devDependency` updates.

Merges [45317,50267,50379,50387,50413,50416,50432,50435-50436,50444,50446,50473-50474,50476,50479,50485-50487,50545,50579,50590,50598] to the 5.1 branch.
See #50401, #51801, #51802, #52548, #52608, #52612, #52624, #52625, #52645, #52653, #52658, #52660, #52667.
Built from https://develop.svn.wordpress.org/branches/5.1@50622


git-svn-id: http://core.svn.wordpress.org/branches/5.1@50235 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-03-31 19:21:47 +00:00
desrosj e9eb025275 Build/Test Tools: Support NodeJS 14.x in the 5.1 branch.
This updates the 5.1 branch to support the latest LTS version of NodeJS (currently 14.x), allowing the same version to be used across all WordPress branches that receive security updates as a courtesy.

In addition to backporting the package updates that happened after branching 5.1, dependencies that were removed in future releases have also been updated to their latest versions.

Props desrosj, dd32, netweb, jorbin.
Merges [44233,44728,45321,45765,45826,46403-46404,46408-46409,47404,47867-47869,47872-47873,48705,49636,49933,49937,49939,49940,49983,49989,50017,50126,50176,50185] to the 5.1 branch.
See #52341.
Built from https://develop.svn.wordpress.org/branches/5.1@50199


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49874 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2021-02-05 03:55:07 +00:00
desrosj c8be9b87f9 Build Tools: Fix running installing Composer dependencies using Composer 2.0.
This updates the `dealerdirect/phpcodesniffer-composer-installer` package to allow installing version `0.7.0` which supports Composer 2.0.

It also includes several minor spacing/alignment coding standards fixes that are made as a result of the package update.

Props itowhid06, jrf.
Merges [49306] to the 5.1 branch.
See #51624, #48301.
Built from https://develop.svn.wordpress.org/branches/5.1@49516


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49271 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-11-06 16:40:53 +00:00
Sergey Biryukov 0f0bf0e2ee WordPress 5.1.8.
Built from https://develop.svn.wordpress.org/branches/5.1@49462


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49221 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-30 19:51:51 +00:00
whyisjake 594508b339 Upgrade/Install: During the install process, add additional checking for exising tables.
This commit brings the changes in [49452] to the 5.1 branch.

If reinstalling WordPress, there is a condition where tables would exist in the database. Ensures that$

Fixes #51676.

Props xknown, garubi, mukesh27, desrosj, johnbillion, metalandcoffee, davidbaumwald, whyisjake.

Built from https://develop.svn.wordpress.org/branches/5.1@49457


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49216 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-30 18:33:53 +00:00
desrosj c44ac9428f WordPress 5.1.7.
Built from https://develop.svn.wordpress.org/branches/5.1@49413


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49172 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 19:37:56 +00:00
whyisjake 9d6a01d804 General: WordPress updates
* XML-RPC: Improve error messages for unprivileged users.
* External Libraries: Disable deserialization in Requests_Utility_FilteredIterator
* Embeds: Disable embeds on deactivated Multisite sites.
* Coding standards: Modify escaping functions to avoid potential false positives.
* XML-RPC: Return error message if attachment ID is incorrect.
* Upgrade/install: Improve logic check when determining installation status.
* Meta: Sanitize meta key before checking protection status.
* Themes: Ensure that only privileged users can set a background image when a theme is using the deprecated custom background page.

Brings the changes from [49380,49382-49388] to the 5.1 branch.

Props xknown, zieladam, peterwilsoncc, whyisjake, desrosj, dd32.

Built from https://develop.svn.wordpress.org/branches/5.1@49395


git-svn-id: http://core.svn.wordpress.org/branches/5.1@49154 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-10-29 18:49:51 +00:00
Sergey Biryukov 8256864d9a Administration: Pass the result of `set-screen-option` filter to the new `set_screen_option_{$option}` filter to ensure backward compatibility.
Rename the `$keep` parameter of both filters to `$screen_option` for clarity, update the documentation to better reflect its purpose.

Follow-up to [47951].

Props Chouby, sswells, SergeyBiryukov.
Merges [48241] to the 5.1 branch.
Fixes #50392.
Built from https://develop.svn.wordpress.org/branches/5.1@48247


git-svn-id: http://core.svn.wordpress.org/branches/5.1@48016 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-07-01 09:48:52 +00:00
desrosj a51c4a5bda WordPress 5.1.6.
Built from https://develop.svn.wordpress.org/branches/5.1@47992


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47760 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 21:35:51 +00:00
whyisjake f985a042ad Editor: Ensure latest comments can only be viewed from public posts.
This brings the changes from [47984] to the 5.1 branch.

Props: poena, xknown.

Built from https://develop.svn.wordpress.org/branches/5.1@47987


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47755 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 19:30:52 +00:00
desrosj 8fc9dbc55b General: Backport several commits for release.
- Embeds: Ensure that the title attribute is set correctly on embeds.
- Editor: Prevent HTML decoding on by setting the proper editor context.
- Formatting: Ensure that wp_validate_redirect() sanitizes a wider variety of characters.
- Themes: Ensure a broken theme name is returned properly.
- Administration: Add a new filter to extend set-screen-option. 

Merges [47947-47951] to the 5.1 branch.
Props xknown, sstoqnov, vortfu, SergeyBiryukov, whyisjake.

Built from https://develop.svn.wordpress.org/branches/5.1@47963


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47734 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-10 18:19:52 +00:00
Sergey Biryukov 6ee378fa7a Comments: Ensure that unmoderated comments won't be search indexed.
After a comment is submitted, only allow a brief window where the comment is live on the site.

Props jonkolbert, ayeshrajans, Asif2BD, peterwilsoncc, imath, audrasjb, jonoaldersonwp, whyisjake, SergeyBiryukov.
Merges [47887] and [47889] to the 5.1 branch.
Fixes #49956.
Built from https://develop.svn.wordpress.org/branches/5.1@47918


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47692 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-06-06 10:08:53 +00:00
Sergey Biryukov 545691722c Update the About page for WordPress 5.1.5
Built from https://develop.svn.wordpress.org/branches/5.1@47703


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47480 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 18:40:50 +00:00
desrosj 6479010890 WordPress 5.1.5
Built from https://develop.svn.wordpress.org/branches/5.1@47669


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47446 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 17:59:43 +00:00
whyisjake 29b77be4ae Customize: Add additional filters to Customizer to prevent JSON corruption.
User: Invalidate `user_activation_key` on password update.
Query: Ensure that only a single post can be returned on date/time based queries.
Block Editor: Coding standards, properly escape class names.
Cache API: Ensure proper escaping around the stats method in the cache API.
Formatting: Expand `sanitize_file_name` to have better support for utf8 characters.

Brings the changes in [47633], [47634], [47635], [47636], [47637], and [47638] to the 5.1 branch.

Props: aduth, batmoo, ehti, ellatrix, jorgefilipecosta, nickdaugherty, noisysocks, pento, peterwilsoncc, sergeybiryukov, sstoqnov, talldanwp, westi, westonruter, whyisjake, whyisjake, xknown.

Built from https://develop.svn.wordpress.org/branches/5.1@47646


git-svn-id: http://core.svn.wordpress.org/branches/5.1@47421 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2020-04-29 16:08:48 +00:00
Sergey Biryukov 3c792a65d4 WordPress 5.1.4
Built from https://develop.svn.wordpress.org/branches/5.1@46922


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46722 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 20:25:50 +00:00
Sergey Biryukov 68b20a5136 Formatting: Use `wp_list_pluck()` instead of `array_column()` in `wp_targeted_link_rel_callback()`.
`array_column()` requires PHP >= 5.5.

Follow-up to [46894].
Built from https://develop.svn.wordpress.org/branches/5.1@46919


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46719 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 19:49:52 +00:00
whyisjake e391320b73 Ensure that a user can publish_posts before making a post sticky.
Props: danielbachhuber, whyisjake, peterwilson, xknown.
Prevent  stored XSS through wp_targeted_link_rel().
Props: vortfu, whyisjake, peterwilsoncc, xknown,  SergeyBiryukov, flaviozavan.
Update wp_kses_bad_protocol() to recognize &colon; on uri attributes,
wp_kses_bad_protocol() makes sure to validate that uri attributes don't contain invalid/or not allowed protocols. While this works fine in most cases, there's a risk that by using the colon html5 named entity, one is able to bypass this function.
Brings r46895 to the 5.3 branch.
Props: xknown, nickdaugherty, peterwilsoncc.
Prevent stored XSS in the block editor.
Brings r46896 to the 5.3 branch.
Prevent escaped unicode characters become unescaped in unsafe HTML during JSON decoding.
Props: aduth, epiqueras.

Built from https://develop.svn.wordpress.org/branches/5.1@46907


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46707 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-12-12 18:37:53 +00:00
desrosj a9af0d7917 Coding Standards: Fix indentation issues introduced in [46509].
Built from https://develop.svn.wordpress.org/branches/5.1@46541


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46338 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 22:05:53 +00:00
desrosj 5fb5d9dc8e WordPress 5.1.3
Built from https://develop.svn.wordpress.org/branches/5.1@46509


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46306 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 20:07:48 +00:00
whyisjake 2fc33ef47d Backporting several bug fixes.
- Query: Remove the static query property.
- HTTP API: Protect against hex interpretation.
- Filesystem API: Prevent directory travelersals when creating new folders.
- Administration: Ensure that admin referer nonce is valid.
- REST API: Send a Vary: Origin header on GET requests.

Backports [46474], [46475], [46476], [46477], [46478], [46483], [46485] to the 5.1 branch.


Built from https://develop.svn.wordpress.org/branches/5.1@46490


git-svn-id: http://core.svn.wordpress.org/branches/5.1@46288 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-10-14 18:17:55 +00:00
desrosj a3d6e4b11a WordPress 5.1.2.
Built from https://develop.svn.wordpress.org/branches/5.1@46045


git-svn-id: http://core.svn.wordpress.org/branches/5.1@45857 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 22:07:33 +00:00
whyisjake b008a6924d Update the block library to 2.2.17 to fix an issue with invalid shortcode blocks.
Props aduth, flaviozavan, epiqueras, jorgefilipecosta

Built from https://develop.svn.wordpress.org/branches/5.1@46030


git-svn-id: http://core.svn.wordpress.org/branches/5.1@45842 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:51:31 +00:00
Andrew Ozz dbcb67b675 jQuery: bring jquery.js back into the WordPress SVN repo and backport the patch from 3.4.0.
Merges [45342] to the 5.1 branch.

Props MikeNGarrett, peterwilsoncc, azaozz.
Fixes #47020.
Built from https://develop.svn.wordpress.org/branches/5.1@46014


git-svn-id: http://core.svn.wordpress.org/branches/5.1@45825 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 21:42:46 +00:00
desrosj a85f164654 Fix for URL sanitization in `wp_kses_bad_protocol_once()`.
Merges [45997] to the 5.1 branch.

Props irsdl, sstoqnov, whyisjake.
Built from https://develop.svn.wordpress.org/branches/5.1@46002


git-svn-id: http://core.svn.wordpress.org/branches/5.1@45813 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2019-09-04 18:01:52 +00:00