-
Notifications
You must be signed in to change notification settings - Fork 4.5k
fix: update the logic of fetching current url in loginout block #70031
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: update the logic of fetching current url in loginout block #70031
Conversation
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.
To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the PR! Could you update each section of the description according to the actual changes?
// This current url fetching logic matches with the core: https://github.com/WordPress/WordPress/blob/6612d90f6c8ee9e917dc2dfcbcc24e120a5746ea/wp-includes/general-template.php#L528 | ||
// Build the redirect URL. | ||
$current_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
// This current url fetching logic matches with the core: https://github.com/WordPress/WordPress/blob/6612d90f6c8ee9e917dc2dfcbcc24e120a5746ea/wp-includes/general-template.php#L528 | |
// Build the redirect URL. | |
$current_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; | |
/* | |
* Build the redirect URL. This current url fetching logic matches with the core. | |
* | |
* @see https://github.com/WordPress/wordpress-develop/blob/6bf62e58d21739938f3bb3f9e16ba702baf9c2cc/src/wp-includes/general-template.php#L528. | |
*/ | |
$current_url = ( is_ssl() ? 'https://' : 'http://' ) . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; |
- Let's use the PHPDoc format.
- It would be good to reference the development repo (
WordPress/wordpress-develop
), not the mirror repo (WordPress/WordPress
),
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 👍
Co-authored-by: SH4LIN <sh4lin@git.wordpress.org> Co-authored-by: t-hamano <wildworks@git.wordpress.org> Co-authored-by: Mamaduka <mamaduka@git.wordpress.org>
What?
Closes: #70024
Why?
Our current method for retrieving the current URL is as follows:
This approach relies on
is_ssl()
and$_SERVER['HTTP_HOST']
, and it accesses$_SERVER['HTTP_HOST']
without checking if it is set. It also lacks proper usage ofwp_unslash()
and sanitization.What is your proposed solution?
Why rely on
$_SERVER['HTTP_HOST']
andis_ssl()
when we can construct the URL directly using:This provides a more secure and WordPress-native approach.
How?
Testing Instructions