WordPress/wp-includes
John Blackbourn a1d61a95e1 Security: Return a `403` instead of a `200` HTTP status when `check_ajax_referer()` fails.
This is, unfortunately, untestable in the current test suite, even in the AJAX tests.

Fixes #36362

Built from https://develop.svn.wordpress.org/trunk@38421


git-svn-id: http://core.svn.wordpress.org/trunk@38362 1a063a9b-81f0-0310-95a4-ce76da25c4cd
2016-08-28 17:31:30 +00:00
..
ID3
IXR XML-RPC: break up `class-IXR.php` into individual class files. 2016-08-26 22:08:33 +00:00
Requests Requests: Update to Requests master (fb5b517) which corrects a logic inversion in the cURL transport checks. 2016-08-18 03:48:31 +00:00
SimplePie
Text
certificates Docs: Standardize on 'backward compatibility/compatible' nomenclature in core inline docs. 2016-05-13 18:41:31 +00:00
css TinyMCE: fix toolbars alignment in RTL. 2016-08-25 01:20:30 +00:00
customize Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
fonts Dashicons: Fix incorrect ID in SVG version of font. 2016-03-18 20:43:26 +00:00
images Embeds: Load the default site icon from the `wp-includes` directory. 2016-02-23 16:55:27 +00:00
js TinyMCE: make sure the temporary id is removed when using the default image dialog and inserting an external image. 2016-08-23 04:43:31 +00:00
pomo Merge the changes to GlotPress's POMO from upstream to WordPress's copy. 2015-11-20 04:34:25 +00:00
random_compat Update Random_Compat from 1.1.6 to 1.2.1. 2016-03-08 17:15:27 +00:00
rest-api Text Changes: Unify/merge two more permission error messages. 2016-07-12 11:45:29 +00:00
theme-compat Embeds: Don't print the HTML for a featured image if a post has no featured image. 2016-07-06 17:08:31 +00:00
widgets Docs: Correct various documentation around `object` and `stdClass` types. 2016-08-26 16:49:45 +00:00
admin-bar.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
atomlib.php External Libraries: After [37402], replace two more instances of `split()` with `explode()` in `wp-includes/atomlib.php`. 2016-05-19 00:06:28 +00:00
author-template.php I18N: Add translator comments for strings in `wp-includes/author-template.php`. 2016-08-23 23:18:29 +00:00
bookmark-template.php Docs: Standardize filter docs in wp-includes/bookmark-template.php to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:24:28 +00:00
bookmark.php Docs: Improve formatting in the DocBlock for `sanitize_bookmark_field()`. 2016-05-27 17:16:27 +00:00
cache.php Cache: in `WP_Object_Cache`, `$cache_misses` is public, but `$cache_hits` is private. They should both be `public`, because they're useful for debugging purposes. 2016-08-23 14:38:29 +00:00
canonical.php Improve category check in `redirect_canonical()` when permastruct contains category slug. 2016-08-08 18:49:28 +00:00
capabilities.php Role/Capability: Only users who can manage options should be able to trash/delete the page for posts or the front page, as they are the only users who can restore it or subsequently alter the "Front page displays" setting. 2016-08-26 18:23:31 +00:00
category-template.php Hooks: Standardize naming of dynamic hooks to use interpolation vs concatenation. 2016-08-22 18:25:31 +00:00
category.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
class-IXR.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-http.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-json.php The the Docs: Fix the the dittography 2015-12-06 21:23:25 +00:00
class-oembed.php Docs: Correct various documentation around `object` and `stdClass` types. 2016-08-26 16:49:45 +00:00
class-phpass.php
class-phpmailer.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-pop3.php
class-requests.php HTTP API: Bump version of Requests to 1.7. 2016-07-27 14:55:28 +00:00
class-simplepie.php Autoload: Introduce shim for SPL autoloading. 2016-06-06 03:24:29 +00:00
class-smtp.php Upgrade PHPMailer from 5.2.10 to 5.2.14. 2015-12-24 01:59:26 +00:00
class-snoopy.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
class-walker-category-dropdown.php Docs: Improve inline documentation in property and method DocBlocks for `Walker_CategoryDropdown`. 2016-03-22 17:22:29 +00:00
class-walker-category.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-walker-comment.php I18N: Add translator comments for strings in `wp-includes/class-walker-comment.php`. 2016-08-23 23:33:28 +00:00
class-walker-nav-menu.php Nav Menus: Move the `Walker_Nav_Menu` class to its own file. 2016-06-06 15:18:31 +00:00
class-walker-page-dropdown.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-walker-page.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
class-wp-admin-bar.php Toolbar: Allow 0 as a value for the `tabindex` property of a menu item. 2016-07-12 11:18:30 +00:00
class-wp-ajax-response.php AJAX: add a new function, `wp_doing_ajax()`, which can replace... (wait for it...) `DOING_AJAX` checks via the constant. 2016-08-23 14:33:30 +00:00
class-wp-comment-query.php Query: use correct description in the docblock for `$number` in `WP_Comment_Query`, `WP_Network_Query`, and `WP_Site_Query`. 2016-08-23 14:41:29 +00:00
class-wp-comment.php Don't improperly cast IDs when fetching post, user, or term objects. 2016-08-26 19:09:27 +00:00
class-wp-customize-control.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-wp-customize-manager.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-wp-customize-nav-menus.php Customize: Link "widget areas" to widgets panel in menu locations section description. 2016-06-28 22:44:30 +00:00
class-wp-customize-panel.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-wp-customize-section.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-wp-customize-setting.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
class-wp-customize-widgets.php Docs: Apply inline `@see` tags to hooks referenced in DocBlocks for core classes. 2016-05-23 18:54:27 +00:00
class-wp-dependency.php Script Loader: move `_WP_Dependency` into its own file. 2016-08-26 18:06:39 +00:00
class-wp-editor.php TinyMCE: fix toolbars alignment in RTL. 2016-08-25 01:20:30 +00:00
class-wp-embed.php Embed: `wp-settings.php` loads `class-wp-embed.php`, which currently produces side effects. Move the `global` instantiation to `wp-settings.php`. `WP_Embed` is then in a file by itself. 2016-08-26 09:53:28 +00:00
class-wp-error.php Load: move `is_wp_error()` to `load.php` so that `WP_Error` is in a file by itself. 2016-08-26 09:58:28 +00:00
class-wp-feed-cache-transient.php Feed: move 'WP_Feed_Cache', 'WP_Feed_Cache_Transient', `WP_SimplePie_File` and `WP_SimplePie_Sanitize_KSES` into their own files via `svn cp`. If we move forard with autoloading, `class-feed.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. `class-feed.php` is an interesting name: there is no `Feed` or `WP_Feed` class. 2016-08-25 18:18:39 +00:00
class-wp-feed-cache.php Feed: move 'WP_Feed_Cache', 'WP_Feed_Cache_Transient', `WP_SimplePie_File` and `WP_SimplePie_Sanitize_KSES` into their own files via `svn cp`. If we move forard with autoloading, `class-feed.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. `class-feed.php` is an interesting name: there is no `Feed` or `WP_Feed` class. 2016-08-25 18:18:39 +00:00
class-wp-http-cookie.php HTTP API: Normalize cookies before passing them to Requests. 2016-07-27 15:32:27 +00:00
class-wp-http-curl.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-encoding.php DOCS: Replace HTTP links with HTTPS. 2016-06-10 04:50:33 +00:00
class-wp-http-ixr-client.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-proxy.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-http-requests-response.php HTTP API: Normalize cookies before passing them to Requests. 2016-07-27 15:32:27 +00:00
class-wp-http-response.php HTTP: in `WP_HTTP_Response`, the `@param` declarations for `$status` and `$headers` were swapped. Let us correct this. 2016-08-22 21:28:27 +00:00
class-wp-http-streams.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-image-editor-gd.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
class-wp-image-editor-imagick.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
class-wp-image-editor.php Media: when calling `pathinfo()`, also pass a `PATHINFO_*` constant to avoid array notices for unset keys. 2016-08-20 23:36:28 +00:00
class-wp-locale.php Locale: declare the `$month_genitive` field on `WP_Locale`. 2016-08-22 21:33:28 +00:00
class-wp-matchesmapregex.php Load: move `WP_MatchesMapRegex` into its own file. 2016-08-26 18:11:39 +00:00
class-wp-meta-query.php Query: add a `protected` field, `$db`, (composition, as it were) to `WP_*_Query` classes to hold the value for the database abstraction, instead of importing the `global $wpdb` into every method that uses it. Reduces the number of global imports by 32. 2016-08-18 18:21:31 +00:00
class-wp-metadata-lazyloader.php Docs: Apply inline `@see` tags to hooks referenced in DocBlocks for core classes. 2016-05-23 18:54:27 +00:00
class-wp-network-query.php Query: use correct description in the docblock for `$number` in `WP_Comment_Query`, `WP_Network_Query`, and `WP_Site_Query`. 2016-08-23 14:41:29 +00:00
class-wp-network.php Docs: Supplement a changelog entry in the DocBlock for the `$id` property in `WP_Network`. 2016-06-29 19:35:28 +00:00
class-wp-oembed-controller.php Docs: Add missing `@access` tags to methods in `WP_oEmbed_Controller`. 2016-05-25 19:22:27 +00:00
class-wp-post-type.php Docs: Correct type of `WP_Post_Type::$cap` from `array` to `object`. 2016-07-18 22:52:29 +00:00
class-wp-post.php Don't improperly cast IDs when fetching post, user, or term objects. 2016-08-26 19:09:27 +00:00
class-wp-query.php Query: collapse several of the `is_*` methods using `__call()`. Add `@method` annotations. 2016-08-25 19:42:43 +00:00
class-wp-rewrite.php Hooks: Standardize naming of dynamic hooks to use interpolation vs concatenation. 2016-08-22 18:25:31 +00:00
class-wp-role.php Docs: Standardize filter docs in core classes in wp-includes/* to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:15:28 +00:00
class-wp-roles.php Roles: set a property, `$db`, on `WP_Roles` to reduce global imports. 2016-08-26 21:16:59 +00:00
class-wp-session-tokens.php Session: move `WP_Session_Tokens` and `WP_User_Meta_Session_Tokens` into their own files via `svn cp`. If we move forard with autoloading, `session.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. 2016-08-25 17:44:31 +00:00
class-wp-simplepie-file.php Feed: move 'WP_Feed_Cache', 'WP_Feed_Cache_Transient', `WP_SimplePie_File` and `WP_SimplePie_Sanitize_KSES` into their own files via `svn cp`. If we move forard with autoloading, `class-feed.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. `class-feed.php` is an interesting name: there is no `Feed` or `WP_Feed` class. 2016-08-25 18:18:39 +00:00
class-wp-simplepie-sanitize-kses.php Feed: move 'WP_Feed_Cache', 'WP_Feed_Cache_Transient', `WP_SimplePie_File` and `WP_SimplePie_Sanitize_KSES` into their own files via `svn cp`. If we move forard with autoloading, `class-feed.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. `class-feed.php` is an interesting name: there is no `Feed` or `WP_Feed` class. 2016-08-25 18:18:39 +00:00
class-wp-site-query.php Query: use correct description in the docblock for `$number` in `WP_Comment_Query`, `WP_Network_Query`, and `WP_Site_Query`. 2016-08-23 14:41:29 +00:00
class-wp-site.php Docs: Correct various documentation around `object` and `stdClass` types. 2016-08-26 16:49:45 +00:00
class-wp-tax-query.php Query: add a `protected` field, `$db`, (composition, as it were) to `WP_*_Query` classes to hold the value for the database abstraction, instead of importing the `global $wpdb` into every method that uses it. Reduces the number of global imports by 32. 2016-08-18 18:21:31 +00:00
class-wp-term-query.php Eliminate unnecessary variable in `WP_Term_Query`. 2016-08-26 18:12:26 +00:00
class-wp-term.php Don't improperly cast IDs when fetching post, user, or term objects. 2016-08-26 19:09:27 +00:00
class-wp-text-diff-renderer-inline.php Diff: move `WP_Text_Diff_Renderer_inline` (behold that lowercase "i") and `WP_Text_Diff_Renderer_Table` into their own files via `svn cp`. 2016-08-25 17:37:30 +00:00
class-wp-text-diff-renderer-table.php Diff: move `WP_Text_Diff_Renderer_inline` (behold that lowercase "i") and `WP_Text_Diff_Renderer_Table` into their own files via `svn cp`. 2016-08-25 17:37:30 +00:00
class-wp-theme.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
class-wp-user-meta-session-tokens.php Session: move `WP_Session_Tokens` and `WP_User_Meta_Session_Tokens` into their own files via `svn cp`. If we move forard with autoloading, `session.php` is useless. We could even remove it now, and just load these new files in `wp-settings.php`. That can be decided post-mortem. 2016-08-25 17:44:31 +00:00
class-wp-user-query.php Query: add a `protected` field, `$db`, (composition, as it were) to `WP_*_Query` classes to hold the value for the database abstraction, instead of importing the `global $wpdb` into every method that uses it. Reduces the number of global imports by 32. 2016-08-18 18:21:31 +00:00
class-wp-user.php Users: after [38317], use a `@property` annotation, instead of a `public` field. 2016-08-22 22:15:29 +00:00
class-wp-walker.php Docs: Standardize on 'backward compatibility/compatible' nomenclature in core inline docs. 2016-05-13 18:41:31 +00:00
class-wp-widget-factory.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
class-wp-widget.php Widgets: `$option_name` and `$alt_option_name` have been used as members ever since `WP_Widget` became an object in 2.8, but never declared. 2016-08-22 21:51:28 +00:00
class-wp-xmlrpc-server.php Query: add a `protected` field, `$db`, (composition, as it were) to `WP_*_Query` classes to hold the value for the database abstraction, instead of importing the `global $wpdb` into every method that uses it. Reduces the number of global imports by 32. 2016-08-18 18:21:31 +00:00
class-wp.php Load: move `WP_MatchesMapRegex` into its own file. 2016-08-26 18:11:39 +00:00
class.wp-dependencies.php Script Loader: move `_WP_Dependency` into its own file. 2016-08-26 18:06:39 +00:00
class.wp-scripts.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
class.wp-styles.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
comment-template.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
comment.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
compat.php Docs: Replace some more HTTP links with HTTPS. 2016-08-10 16:10:31 +00:00
cron.php Cron: clarify descriptions for Cron API functions. 2016-08-26 09:22:30 +00:00
date.php Query: use composition for `$db` in `WP_Date_Query`, removes need to import `global $wpdb` in multiple methods. 2016-08-18 19:48:34 +00:00
default-constants.php Bootstrap: Enhance core's memory limit handling. 2016-07-08 14:37:30 +00:00
default-filters.php Resource Hints: Increase priority of `wp_resource_hints()` so hints get printed before scripts and styles. 2016-07-13 12:54:28 +00:00
default-widgets.php
deprecated.php I18N: Add translator comments for strings in `wp-includes/deprecated.php`. 2016-08-23 23:36:28 +00:00
embed-template.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
embed.php OEmbed: move `_wp_oembed_get_object()` to `embed.php`, where all of the other embed functions live. `WP_oEmbed` is then in a file by itself. Load `class-oembed.php` in `wp-settings.php` and remove extraneous include calls. 2016-08-26 09:49:28 +00:00
feed-atom-comments.php DOCS: Replace HTTP links with HTTPS. 2016-06-10 04:50:33 +00:00
feed-atom.php Feeds: `<comments>` is optional in RSS2, so don't include it when comments aren't present or open. Same for `<wfw:commentRss>` and `<slash:comments>` 2015-11-04 17:47:25 +00:00
feed-rdf.php
feed-rss.php
feed-rss2-comments.php
feed-rss2.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
feed.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
formatting.php Formatting: for a performance boost in `remove_accents()`, convert `chr()` calls to string literals. 2016-08-26 09:35:27 +00:00
functions.php Security: Return a `403` instead of a `200` HTTP status when `check_ajax_referer()` fails. 2016-08-28 17:31:30 +00:00
functions.wp-scripts.php I18N: Add translator comments for strings in `wp-includes/functions.wp-scripts.php`. 2016-08-23 23:53:27 +00:00
functions.wp-styles.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
general-template.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
http.php Docs: Apply inline `@see` tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:01:27 +00:00
kses.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 16:57:32 +00:00
l10n.php i18n: move `is_rtl()` to `l10n.php` (which loads way earlier). Load `WP_Locale` file in `wp-settings.php`. Retire `wp-includes/locale.php` - it only loaded the class and the one function, `is_rtl()`. If someone loaded this file for fun somewhere else, it would be a fatal error. 2016-08-26 10:20:29 +00:00
link-template.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
load.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
media-template.php Customize: Add a RTL version of "browser.png" for the site icon preview. 2016-07-05 11:32:29 +00:00
media.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
meta.php Docs: Fix formatting, tense, verb conjugation, and other syntax for wp-includes/* elements introduced or changed in 4.6. 2016-07-20 19:33:30 +00:00
ms-blogs.php Multisite: move `get_current_site()` to `load.php` so that it can be used in more places, instead of importing `global $current_site`. 2016-08-26 21:35:30 +00:00
ms-default-constants.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
ms-default-filters.php
ms-deprecated.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
ms-files.php
ms-functions.php Multisite: move `get_current_site()` to `load.php` so that it can be used in more places, instead of importing `global $current_site`. 2016-08-26 21:35:30 +00:00
ms-load.php Docs: Correct and clarify various `@since` docs. 2016-08-04 22:54:31 +00:00
ms-settings.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
nav-menu-template.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
nav-menu.php Docs: Correct various documentation around `object` and `stdClass` types. 2016-08-26 16:49:45 +00:00
option.php Multisite: move `get_current_site()` to `load.php` so that it can be used in more places, instead of importing `global $current_site`. 2016-08-26 21:35:30 +00:00
pluggable-deprecated.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
pluggable.php Security: Return a `403` instead of a `200` HTTP status when `check_ajax_referer()` fails. 2016-08-28 17:31:30 +00:00
plugin.php Bootstrap/Load: Include Plugin API via `require_once` 2016-08-19 04:10:30 +00:00
post-formats.php
post-template.php Load: load `class-phpass.php` (`PasswordHash` class) early in `wp-settings.php`, instead of `require_once()`'ing it in several places. 2016-08-26 17:40:35 +00:00
post-thumbnail-template.php Post Thumbnails: Add helper functions for attachment captions. 2016-06-29 17:28:28 +00:00
post.php Media: Add a `$wp_error` parameter to `wp_insert_attachment()` to give it parity with `wp_insert_post()`. 2016-08-27 17:25:29 +00:00
query.php Query: move `WP_Query` into its own file via `svn cp`. 2016-08-25 17:20:38 +00:00
registration-functions.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
registration.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
rest-api.php REST API: remove unnecessary variable assignments in `rest_handle_options_request()`. 2016-08-22 20:56:28 +00:00
revision.php Post Thumbnails: Only update featured images when saving a post. 2016-07-20 16:24:28 +00:00
rewrite.php Docs: Apply inline `@see` tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:02:28 +00:00
rss-functions.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
rss.php Docs: Use 3-digit, x.x.x-style semantic versioning for `_doing_it_wrong()`, `_deprecated_function()`, `_deprecated_argument()`, and `_deprecated_file()` throughout core. 2016-07-06 12:40:29 +00:00
script-loader.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
shortcodes.php Multisite: Change `WP_Network` `id` property to an integer. 2016-06-26 14:26:29 +00:00
taxonomy.php Hooks: Standardize naming of dynamic hooks to use interpolation vs concatenation. 2016-08-22 18:25:31 +00:00
template-loader.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
template.php Themes: Update filter names in the inline documentation for the `get_*_template()` functions. 2016-08-28 16:15:30 +00:00
theme.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
update.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00
user.php Users: Correct the documentation for the `wp_dropdown_users_args` filter description and its parameters. 2016-08-27 16:54:31 +00:00
vars.php Docs: Standardize filter docs in remaining wp-includes/* files to use third-person singular verbs per the inline documentation standards for PHP. 2016-05-22 18:50:28 +00:00
version.php Security: Return a `403` instead of a `200` HTTP status when `check_ajax_referer()` fails. 2016-08-28 17:31:30 +00:00
widgets.php Docs: Apply inline `@see` tags to hooks referenced in DocBlocks in a variety of wp-includes/* files. 2016-05-23 19:02:28 +00:00
wlwmanifest.xml
wp-db.php Database: `WP_Network`, `WP_Network_Query`, and `WP_Site_Query` call `wpdb::_escape()`, thus requiring it to be `public`. It previously had no access modifier. `_` at the beginning of a method, believe it or not, does not enforce visibility constraints. 2016-08-22 21:10:28 +00:00
wp-diff.php Bootstrap: after r38409 and r38410, revert r38402 which reverted r38399. 2016-08-27 22:32:37 +00:00