Repository navigation
fix: stop safe mode restarting current user resolution #570
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
TallblokeUK
wants to merge
4
commits into
core-beta
Choose a base branch
from
fix/safe-mode-user-resolution/core
base: core-beta
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
6018c57
fix: stop safe mode restarting current user resolution
TallblokeUK 0d9875d
test: cover safe mode during current user resolution
TallblokeUK 9e93de2
Merge branch 'core-beta' of github.com:codesnippetspro/code-snippets …
TallblokeUK 5eacdce
Merge branch 'core-beta' of github.com:codesnippetspro/code-snippets …
TallblokeUK File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we need to actually check the user here? I feel like we can just pass on the var whenever it's set, and then only check the current user when evaluating snippets.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You're right that it works, and it is simpler. I tried it: with the capability check taken out of this callback, an anonymous request carrying the query var comes back 200 and the recursion is gone without needing the guard at all. It also drops a
current_user_can()call that currently runs on everyhome_url()in the page, which is worth having.One consequence to weigh first.
home_url()is a base that callers append to, so adding the query var to it corrupts anything built by concatenation. Passing the var on unconditionally does that for every visitor:That is the REST URL on plain permalinks, and it is wrong.
Worth saying that this is not caused by either version — it already happens for a user who does hold the capability, on
core-betaas it stands:So safe mode breaks REST URLs for administrators today on plain permalinks, which matters given the manage screen needs the REST API and safe mode is the route in when something is broken. I'll raise that separately. Taking the capability check out here widens it from administrators to everyone, which is the only reason I'd hesitate.
A third option, if you like it: take the simplification and stop filtering
home_urlas well, keeping onlyadmin_url. Safe mode navigation is an admin concern, andrest_url()derives fromhome_url(), so that removes the malformed URLs rather than extending them. No more code than your suggestion.Happy to go whichever way you prefer — it's your integration.