<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[31609] trunk/src: PressThis:</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta" style="font-size: 105%">
<dt style="float: left; width: 6em; font-weight: bold">Revision</dt> <dd><a style="font-weight: bold" href="https://core.trac.wordpress.org/changeset/31609">31609</a><script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","description":"Review this Commit","action":{"@type":"ViewAction","url":"https://core.trac.wordpress.org/changeset/31609","name":"Review Commit"}}</script></dd>
<dt style="float: left; width: 6em; font-weight: bold">Author</dt> <dd>azaozz</dd>
<dt style="float: left; width: 6em; font-weight: bold">Date</dt> <dd>2015-03-04 19:28:53 +0000 (Wed, 04 Mar 2015)</dd>
</dl>

<pre style='padding-left: 1em; margin: 2em 0; border-left: 2px solid #ccc; line-height: 1.25; font-size: 105%; font-family: sans-serif'>PressThis:
- Improve handling of the data, both from the bookmarklet and from server-side parsing.
- Standardize on processing the data in PHP and remove duplicate code from JS.
- Improve the bookmarklet code and remove pre-filtering of the data.
Part props stephdau, see <a href="https://core.trac.wordpress.org/ticket/31373">#31373</a>.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunksrcwpadminincludesclasswppressthisphp">trunk/src/wp-admin/includes/class-wp-press-this.php</a></li>
<li><a href="#trunksrcwpadminjsbookmarkletjs">trunk/src/wp-admin/js/bookmarklet.js</a></li>
<li><a href="#trunksrcwpadminjsbookmarkletminjs">trunk/src/wp-admin/js/bookmarklet.min.js</a></li>
<li><a href="#trunksrcwpadminjspressthisjs">trunk/src/wp-admin/js/press-this.js</a></li>
<li><a href="#trunksrcwpincludeslinktemplatephp">trunk/src/wp-includes/link-template.php</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunksrcwpadminincludesclasswppressthisphp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-admin/includes/class-wp-press-this.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-admin/includes/class-wp-press-this.php       2015-03-04 09:50:34 UTC (rev 31608)
+++ trunk/src/wp-admin/includes/class-wp-press-this.php 2015-03-04 19:28:53 UTC (rev 31609)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -40,7 +40,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">                return array(
</span><span class="cx" style="display: block; padding: 0 10px">                        // Used to trigger the bookmarklet update notice.
</span><span class="cx" style="display: block; padding: 0 10px">                        // Needs to be set here and in get_shortcut_link() in wp-includes/link-template.php.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        'version' => '5',
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 'version' => '6',
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                        /**
</span><span class="cx" style="display: block; padding: 0 10px">                         * Filter whether or not Press This should redirect the user in the parent window upon save.
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -278,7 +278,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">         */
</span><span class="cx" style="display: block; padding: 0 10px">        public function fetch_source_html( $url ) {
</span><span class="cx" style="display: block; padding: 0 10px">                // Download source page to tmp file.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                $source_tmp_file = ( ! empty( $url ) ) ? download_url( $url ) : '';
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         $source_tmp_file = ( ! empty( $url ) ) ? download_url( $url, 30 ) : '';
</ins><span class="cx" style="display: block; padding: 0 10px">                 $source_content  = '';
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                if ( ! is_wp_error( $source_tmp_file ) && file_exists( $source_tmp_file ) ) {
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -318,6 +318,162 @@
</span><span class="cx" style="display: block; padding: 0 10px">                return $source_content;
</span><span class="cx" style="display: block; padding: 0 10px">        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+        private function _limit_array( $value ) {
+               if ( is_array( $value ) ) {
+                       if ( count( $value ) > 50 ) {
+                               return array_slice( $value, 0, 50 );
+                       }
+
+                       return $value;
+               }
+
+               return array();
+       }
+
+       private function _limit_string( $value ) {
+               $return = '';
+
+               if ( is_numeric( $value ) || is_bool( $value ) ) {
+                       $return = (string) $value;
+               } else if ( is_string( $value ) ) {
+                       if ( mb_strlen( $value ) > 5000 ) {
+                               $return = mb_substr( $value, 0, 5000 );
+                       } else {
+                               $return = $value;
+                       }
+
+                       $return = html_entity_decode( $return, ENT_QUOTES, 'UTF-8' );
+                       $return = sanitize_text_field( trim( $return ) );
+               }
+
+               return $return;
+       }
+
+       private function _limit_url( $url ) {
+               if ( ! is_string( $url ) ) {
+                       return '';
+               }
+               
+               $url = $this->_limit_string( $url );
+
+               // HTTP 1.1 allows 8000 chars but the "de-facto" standard supported in all current browsers is 2048.
+               if ( mb_strlen( $url ) > 2048 ) {
+                       return ''; // Return empty rather than a trunacted/invalid URL
+               }
+
+               // Only allow http(s) or protocol relative URLs.
+               if ( ! preg_match( '%^(https?:)?//%i', $url ) ) {
+                       return '';
+               }
+
+               if ( strpos( $url, '"' ) !== false || strpos( $url, ' ' ) !== false ) {
+                       return '';
+               }
+
+               return $url;
+       }
+
+       private function _limit_img( $src ) {
+               $src = $this->_limit_url( $src );
+
+               if ( preg_match( '/\/ad[sx]{1}?\//', $src ) ) {
+                       // Ads
+                       return '';
+               } else if ( preg_match( '/(\/share-?this[^\.]+?\.[a-z0-9]{3,4})(\?.*)?$/', $src ) ) {
+                       // Share-this type button
+                       return '';
+               } else if ( preg_match( '/\/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)/', $src ) ) {
+                       // Loaders, spinners, spacers
+                       return '';
+               } else if ( preg_match( '/\/([^\.\/]+[-_]{1})?(spinner|loading|spacer|blank)s?([-_]{1}[^\.\/]+)?\.[a-z0-9]{3,4}/', $src ) ) {
+                       // Fancy loaders, spinners, spacers
+                       return '';
+               } else if ( preg_match( '/([^\.\/]+[-_]{1})?thumb[^.]*\.(gif|jpg|png)$/', $src ) ) {
+                       // Thumbnails, too small, usually irrelevant to context
+                       return '';
+               } else if ( preg_match( '/\/wp-includes\//', $src ) ) {
+                       // Classic WP interface images
+                       return '';
+               } else if ( preg_match( '/[^\d]{1}\d{1,2}x\d+\.(gif|jpg|png)$/', $src ) ) {
+                       // Most often tiny buttons/thumbs (< 100px wide)
+                       return '';
+               } else if ( preg_match( '/\/pixel\.(mathtag|quantserve)\.com/', $src ) ) {
+                       // See mathtag.com and https://www.quantcast.com/how-we-do-it/iab-standard-measurement/how-we-collect-data/
+                       return '';
+               } else if ( false !== strpos( $src, '/g.gif' ) ) {
+                       // Classic WP stats gif
+                       return '';
+               }
+
+               return $src;
+       }
+
+       private function _limit_embed( $src ) {
+               $src = $this->_limit_url( $src );
+
+               if ( preg_match( '/\/\/www\.youtube\.com\/(embed|v)\/([^\?]+)\?.+$/', $src, $src_matches ) ) {
+                       $src = 'https://www.youtube.com/watch?v=' . $src_matches[2];
+               } else if ( preg_match( '/\/\/player\.vimeo\.com\/video\/([\d]+)([\?\/]{1}.*)?$/', $src, $src_matches ) ) {
+                       $src = 'https://vimeo.com/' . (int) $src_matches[1];
+               } else if ( preg_match( '/\/\/vimeo\.com\/moogaloop\.swf\?clip_id=([\d]+)$/', $src, $src_matches ) ) {
+                       $src = 'https://vimeo.com/' . (int) $src_matches[1];
+               } else if ( preg_match( '/\/\/vine\.co\/v\/([^\/]+)\/embed/', $src, $src_matches ) ) {
+                       $src = 'https://vine.co/v/' . $src_matches[1];
+               } else if ( ! preg_match( '/\/\/(m\.|www\.)?youtube\.com\/watch\?/', $src )
+                           && ! preg_match( '/\/youtu\.be\/.+$/', $src )
+                           && ! preg_match( '/\/\/vimeo\.com\/[\d]+$/', $src )
+                           && ! preg_match( '/\/\/(www\.)?dailymotion\.com\/video\/.+$/', $src )
+                           && ! preg_match( '/\/\/soundcloud\.com\/.+$/', $src )
+                           && ! preg_match( '/\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/', $src )
+                           && ! preg_match( '/\/\/vine\.co\/v\/[^\/]+/', $src ) ) {
+                       $src = '';
+               }
+
+               return $src;
+       }
+
+       private function _process_meta_entry( $meta_name, $meta_value, $data ) {
+               if ( preg_match( '/:?(title|description|keywords)$/', $meta_name ) ) {
+                       $data['_meta'][ $meta_name ] = $meta_value;
+               } else {
+                       switch ( $meta_name ) {
+                               case 'og:url':
+                               case 'og:video':
+                               case 'og:video:secure_url':
+                                       $meta_value = $this->_limit_embed( $meta_value );
+
+                                       if ( ! isset( $data['_embed'] ) ) {
+                                               $data['_embed'] = array();
+                                       }
+
+                                       if ( ! empty( $meta_value ) && ! in_array( $meta_value, $data['_embed'] ) ) {
+                                               $data['_embed'][] = $meta_value;
+                                       }
+
+                                       break;
+                               case 'og:image':
+                               case 'og:image:secure_url':
+                               case 'twitter:image0:src':
+                               case 'twitter:image0':
+                               case 'twitter:image:src':
+                               case 'twitter:image':
+                                       $meta_value = $this->_limit_img( $meta_value );
+
+                                       if ( ! isset( $data['_img'] ) ) {
+                                               $data['_img'] = array();
+                                       }
+
+                                       if ( ! empty( $meta_value ) && ! in_array( $meta_value, $data['_img'] ) ) {
+                                               $data['_img'][] = $meta_value;
+                                       }
+
+                                       break;
+                       }
+               }
+               
+               return $data;
+       }
+
</ins><span class="cx" style="display: block; padding: 0 10px">         /**
</span><span class="cx" style="display: block; padding: 0 10px">         * Fetches and parses _meta, _img, and _links data from the source.
</span><span class="cx" style="display: block; padding: 0 10px">         *
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -339,18 +495,42 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        return array( 'errors' => $source_content->get_error_messages() );
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                // Fetch and gather <meta> data first, so discovered media is offered 1st to user.
+               if ( empty( $data['_meta'] ) ) {
+                       $data['_meta'] = array();
+               }
+
+               if ( preg_match_all( '/<meta [^>]+>/', $source_content, $matches ) ) {
+                       $items = $this->_limit_array( $matches[0] );
+
+                       foreach ( $items as $value ) {
+                               if ( preg_match( '/(property|name)="([^"]+)"[^>]+content="([^"]+)"/', $value, $new_matches ) ) {
+                                       $meta_name  = $this->_limit_string( $new_matches[2] );
+                                       $meta_value = $this->_limit_string( $new_matches[3] );
+
+                                       // Sanity check. $key is usually things like 'title', 'description', 'keywords', etc.
+                                       if ( strlen( $meta_name ) > 100 ) {
+                                               continue;
+                                       }
+
+                                       $data = $this->_process_meta_entry( $meta_name, $meta_value, $data );
+                               }
+                       }
+               }
+
</ins><span class="cx" style="display: block; padding: 0 10px">                 // Fetch and gather <img> data.
</span><span class="cx" style="display: block; padding: 0 10px">                if ( empty( $data['_img'] ) ) {
</span><span class="cx" style="display: block; padding: 0 10px">                        $data['_img'] = array();
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( preg_match_all( '/<img (.+)[\s]?\/>/', $source_content, $matches ) ) {
-                       if ( ! empty( $matches[0] ) ) {
-                               foreach ( $matches[0] as $value ) {
-                                       if ( preg_match( '/<img[^>]+src="([^"]+)"[^>]+\/>/', $value, $new_matches ) ) {
-                                               if ( ! in_array( $new_matches[1], $data['_img'] ) ) {
-                                                       $data['_img'][] = $new_matches[1];
-                                               }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( preg_match_all( '/<img [^>]+>/', $source_content, $matches ) ) {
+                       $items = $this->_limit_array( $matches[0] );
+
+                       foreach ( $items as $value ) {
+                               if ( preg_match( '/src=(\'|")([^\'"]+)\\1/', $value, $new_matches ) ) {
+                                       $src = $this->_limit_img( $new_matches[2] );
+                                       if ( ! empty( $src ) && ! in_array( $src, $data['_img'] ) ) {
+                                               $data['_img'][] = $src;
</ins><span class="cx" style="display: block; padding: 0 10px">                                         }
</span><span class="cx" style="display: block; padding: 0 10px">                                }
</span><span class="cx" style="display: block; padding: 0 10px">                        }
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -361,66 +541,15 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        $data['_embed'] = array();
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( preg_match_all( '/<iframe (.+)[\s][^>]*>/', $source_content, $matches ) ) {
-                       if ( ! empty( $matches[0] ) ) {
-                               foreach ( $matches[0] as $value ) {
-                                       if ( preg_match( '/<iframe[^>]+src=(\'|")([^"]+)(\'|")/', $value, $new_matches ) ) {
-                                               if ( ! in_array( $new_matches[2], $data['_embed'] ) ) {
-                                                       if ( preg_match( '/\/\/www\.youtube\.com\/embed\/([^\?]+)\?.+$/', $new_matches[2], $src_matches ) ) {
-                                                               $data['_embed'][] = 'https://www.youtube.com/watch?v=' . $src_matches[1];
-                                                       } else if ( preg_match( '/\/\/player\.vimeo\.com\/video\/([\d]+)([\?\/]{1}.*)?$/', $new_matches[2], $src_matches ) ) {
-                                                               $data['_embed'][] = 'https://vimeo.com/' . (int) $src_matches[1];
-                                                       } else if ( preg_match( '/\/\/vine\.co\/v\/([^\/]+)\/embed/', $new_matches[2], $src_matches ) ) {
-                                                               $data['_embed'][] = 'https://vine.co/v/' . $src_matches[1];
-                                                       }
-                                               }
-                                       }
-                               }
-                       }
-               }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( preg_match_all( '/<iframe [^>]+>/', $source_content, $matches ) ) {
+                       $items = $this->_limit_array( $matches[0] );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                // Fetch and gather <meta> data.
-               if ( empty( $data['_meta'] ) ) {
-                       $data['_meta'] = array();
-               }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 foreach ( $items as $value ) {
+                               if ( preg_match( '/src=(\'|")([^\'"]+)\\1/', $value, $new_matches ) ) {
+                                       $src = $this->_limit_embed( $new_matches[2] );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( preg_match_all( '/<meta ([^>]+)[\s]?\/?>/', $source_content, $matches ) ) {
-                       if ( ! empty( $matches[0] ) ) {
-                               foreach ( $matches[0] as $key => $value ) {
-                                       if ( preg_match( '/<meta[^>]+(property|name)="(.+)"[^>]+content="(.+)"/', $value, $new_matches ) ) {
-                                               if ( empty( $data['_meta'][ $new_matches[2] ] ) ) {
-                                                       if ( preg_match( '/:?(title|description|keywords)$/', $new_matches[2] ) ) {
-                                                               $data['_meta'][ $new_matches[2] ] = str_replace( '&#039;', "'", str_replace( '&#034;', '', html_entity_decode( $new_matches[3] ) ) );
-                                                       } else {
-                                                               $data['_meta'][ $new_matches[2] ] = $new_matches[3];
-                                                               if ( 'og:url' == $new_matches[2] ) {
-                                                                       if ( false !== strpos( $new_matches[3], '//www.youtube.com/watch?' )
-                                                                            || false !== strpos( $new_matches[3], '//www.dailymotion.com/video/' )
-                                                                            || preg_match( '/\/\/vimeo\.com\/[\d]+$/', $new_matches[3] )
-                                                                            || preg_match( '/\/\/soundcloud\.com\/.+$/', $new_matches[3] )
-                                                                            || preg_match( '/\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/', $new_matches[3] )
-                                                                            || preg_match( '/\/\/vine\.co\/v\/[^\/]+/', $new_matches[3] ) ) {
-                                                                               if ( ! in_array( $new_matches[3], $data['_embed'] ) ) {
-                                                                                       $data['_embed'][] = $new_matches[3];
-                                                                               }
-                                                                       }
-                                                               } else if ( 'og:video' == $new_matches[2] || 'og:video:secure_url' == $new_matches[2] ) {
-                                                                       if ( preg_match( '/\/\/www\.youtube\.com\/v\/([^\?]+)/', $new_matches[3], $src_matches ) ) {
-                                                                               if ( ! in_array( 'https://www.youtube.com/watch?v=' . $src_matches[1], $data['_embed'] ) ) {
-                                                                                       $data['_embed'][] = 'https://www.youtube.com/watch?v=' . $src_matches[1];
-                                                                               }
-                                                                       } else if ( preg_match( '/\/\/vimeo.com\/moogaloop\.swf\?clip_id=([\d]+)$/', $new_matches[3], $src_matches ) ) {
-                                                                               if ( ! in_array( 'https://vimeo.com/' . $src_matches[1], $data['_embed'] ) ) {
-                                                                                       $data['_embed'][] = 'https://vimeo.com/' . $src_matches[1];
-                                                                               }
-                                                                       }
-                                                               } else if ( 'og:image' == $new_matches[2] || 'og:image:secure_url' == $new_matches[2] ) {
-                                                                       if ( ! in_array( $new_matches[3], $data['_img'] ) ) {
-                                                                               $data['_img'][] = $new_matches[3];
-                                                                       }
-                                                               }
-                                                       }
-                                               }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                                 if ( ! empty( $src ) && ! in_array( $src, $data['_embed'] ) ) {
+                                               $data['_embed'][] = $src;
</ins><span class="cx" style="display: block; padding: 0 10px">                                         }
</span><span class="cx" style="display: block; padding: 0 10px">                                }
</span><span class="cx" style="display: block; padding: 0 10px">                        }
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -431,14 +560,16 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        $data['_links'] = array();
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( preg_match_all( '/<link ([^>]+)[\s]?\/>/', $source_content, $matches ) ) {
-                       if ( ! empty( $matches[0] ) ) {
-                               foreach ( $matches[0] as $key => $value ) {
-                                       if ( preg_match( '/<link[^>]+(rel|itemprop)="([^"]+)"[^>]+href="([^"]+)"[^>]+\/>/', $value, $new_matches ) ) {
-                                               if ( 'alternate' == $new_matches[2] || 'thumbnailUrl' == $new_matches[2] || 'url' == $new_matches[2] ) {
-                                                       if ( empty( $data['_links'][ $new_matches[2] ] ) ) {
-                                                               $data['_links'][ $new_matches[2] ] = $new_matches[3];
-                                                       }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( preg_match_all( '/<link [^>]+>/', $source_content, $matches ) ) {
+                       $items = $this->_limit_array( $matches[0] );
+
+                       foreach ( $items as $value ) {
+                               if ( preg_match( '/(rel|itemprop)="([^"]+)"[^>]+href="([^"]+)"/', $value, $new_matches ) ) {
+                                       if ( 'alternate' === $new_matches[2] || 'thumbnailUrl' === $new_matches[2] || 'url' === $new_matches[2] ) {
+                                               $url = $this->_limit_url( $new_matches[3] );
+
+                                               if ( ! empty( $url ) && empty( $data['_links'][ $new_matches[2] ] ) ) {
+                                                       $data['_links'][ $new_matches[2] ] = $url;
</ins><span class="cx" style="display: block; padding: 0 10px">                                                 }
</span><span class="cx" style="display: block; padding: 0 10px">                                        }
</span><span class="cx" style="display: block; padding: 0 10px">                                }
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -457,14 +588,30 @@
</span><span class="cx" style="display: block; padding: 0 10px">         * @return array
</span><span class="cx" style="display: block; padding: 0 10px">         */
</span><span class="cx" style="display: block; padding: 0 10px">        public function merge_or_fetch_data() {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                // Merge $_POST and $_GET, as appropriate ($_POST > $_GET), to remain backward compatible.
-               $data = array_merge_recursive( $_POST, $_GET );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         // Get data from $_POST and $_GET, as appropriate ($_POST > $_GET), to remain backward compatible.
+               $data = array();
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                // Get the legacy QS params, or equiv POST data
-               $data['u'] = ( ! empty( $data['u'] ) && preg_match( '/^https?:/', $data['u'] ) ) ? $data['u'] : '';
-               $data['s'] = ( ! empty( $data['s'] ) ) ? $data['s'] : '';
-               $data['t'] = ( ! empty( $data['t'] ) ) ? $data['t'] : '';
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         // Only instantiate the keys we want. Sanity check and sanitize each one.
+               foreach ( array( 'u', 's', 't', 'v', '_version' ) as $key ) {
+                       if ( ! empty( $_POST[ $key ] ) ) {
+                               $value = wp_unslash( $_POST[ $key ] );
+                       } else if ( ! empty( $_GET[ $key ] ) ) {
+                               $value = wp_unslash( $_GET[ $key ] );
+                       } else {
+                               continue;
+                       }
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                        if ( 'u' === $key ) {
+                               $value = $this->_limit_url( $value );
+                       } else {
+                               $value = $this->_limit_string( $value );
+                       }
+
+                       if ( ! empty( $value ) ) {
+                               $data[ $key ] = $value;
+                       }
+               }
+
</ins><span class="cx" style="display: block; padding: 0 10px">                 /**
</span><span class="cx" style="display: block; padding: 0 10px">                 * Filter whether to enable in-source media discovery in Press This.
</span><span class="cx" style="display: block; padding: 0 10px">                 *
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -474,22 +621,51 @@
</span><span class="cx" style="display: block; padding: 0 10px">                 */
</span><span class="cx" style="display: block; padding: 0 10px">                if ( apply_filters( 'enable_press_this_media_discovery', true ) ) {
</span><span class="cx" style="display: block; padding: 0 10px">                        /*
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                         * If no _meta (a new thing) was passed via $_POST, fetch data from source as fallback,
-                        * makes PT fully backward compatible
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                  * If no title, _img, _embed, and _meta was passed via $_POST, fetch data from source as fallback,
+                        * making PT fully backward compatible with the older bookmarklet.
</ins><span class="cx" style="display: block; padding: 0 10px">                          */
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        if ( empty( $data['_meta'] ) && ! empty( $data['u'] ) ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 if ( empty( $_POST ) && ! empty( $data['u'] ) ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                                 $data = $this->source_data_fetch_fallback( $data['u'], $data );
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                        } else {
+                               foreach ( array( '_img', '_embed', '_meta' ) as $type ) {
+                                       if ( empty( $_POST[ $type ] ) ) {
+                                               continue;
+                                       }
+
+                                       $data[ $type ] = array();
+                                       $items = $this->_limit_array( $_POST[ $type ] );
+                                       $items = wp_unslash( $items );
+
+                                       foreach ( $items as $key => $value ) {
+                                               $key = $this->_limit_string( wp_unslash( $key ) );
+
+                                               // Sanity check. $key is usually things like 'title', 'description', 'keywords', etc.
+                                               if ( empty( $key ) || strlen( $key ) > 100 ) {
+                                                       continue;
+                                               }
+
+                                               if ( $type === '_meta' ) {
+                                                       $value = $this->_limit_string( $value );
+
+                                                       if ( ! empty( $value ) ) {
+                                                               $data = $this->_process_meta_entry( $key, $value, $data );
+                                                       }
+                                               } else if ( $type === '_img' ) {
+                                                       $value = $this->_limit_img( $value );
+
+                                                       if ( ! empty( $value ) ) {
+                                                               $data[ $type ][] = $value;
+                                                       }
+                                               } else if ( $type === '_embed' ) {
+                                                       $value = $this->_limit_embed( $value );
+
+                                                       if ( ! empty( $value ) ) {
+                                                               $data[ $type ][] = $value;
+                                                       }
+                                               }
+                                       }
+                               }
</ins><span class="cx" style="display: block; padding: 0 10px">                         }
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                } else {
-                       if ( ! empty( $data['_img'] ) ) {
-                               $data['_img'] = array();
-                       }
-                       if ( ! empty( $data['_embed'] ) ) {
-                               $data['_embed'] = array();
-                       }
-                       if ( ! empty( $data['_meta'] ) ) {
-                               $data['_meta'] = array();
-                       }
</del><span class="cx" style="display: block; padding: 0 10px">                 }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                /**
</span></span></pre></div>
<a id="trunksrcwpadminjsbookmarkletjs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-admin/js/bookmarklet.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-admin/js/bookmarklet.js      2015-03-04 09:50:34 UTC (rev 31608)
+++ trunk/src/wp-admin/js/bookmarklet.js        2015-03-04 19:28:53 UTC (rev 31609)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -7,7 +7,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">                canPost = true,
</span><span class="cx" style="display: block; padding: 0 10px">                windowWidth, windowHeight,
</span><span class="cx" style="display: block; padding: 0 10px">                metas, links, content, imgs, ifrs,
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                vid, selection, newWin;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         selection;
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        if ( ! pt_url ) {
</span><span class="cx" style="display: block; padding: 0 10px">                return;
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -28,17 +28,19 @@
</span><span class="cx" style="display: block; padding: 0 10px">        } else if ( document.getSelection ) {
</span><span class="cx" style="display: block; padding: 0 10px">                selection = document.getSelection() + '';
</span><span class="cx" style="display: block; padding: 0 10px">        } else if ( document.selection ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                selection = document.selection.createRange().text;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         selection = document.selection.createRange().text || '';
</ins><span class="cx" style="display: block; padding: 0 10px">         }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        pt_url += ( pt_url.indexOf( '?' ) > -1 ? '&' : '?' ) + 'buster=' + ( new Date().getTime() );
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        if ( document.title.length && ( document.title.length <= 256 || ! canPost ) ) {
-               pt_url += '&t=' + encURI( document.title.substr( 0, 256 ) );
-       }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ if ( ! canPost ) {
+               if ( document.title ) {
+                       pt_url += '&t=' + encURI( document.title.substr( 0, 256 ) );
+               }
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        if ( selection && ( selection.length <= 512 || ! canPost ) ) {
-               pt_url += '&s=' + encURI( selection.substr( 0, 512 ) );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( selection ) {
+                       pt_url += '&s=' + encURI( selection.substr( 0, 512 ) );
+               }
</ins><span class="cx" style="display: block; padding: 0 10px">         }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        windowWidth  = window.outerWidth || document.documentElement.clientWidth || 600;
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -48,8 +50,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">        windowHeight = ( windowHeight < 800 || windowHeight > 3000 ) ? 700 : ( windowHeight * 0.9 );
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        if ( ! canPost ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                newWin = window.open( pt_url, target, 'location,resizable,scrollbars,width=' + windowWidth + ',height=' + windowHeight );
-               newWin.focus();
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         window.open( pt_url, target, 'location,resizable,scrollbars,width=' + windowWidth + ',height=' + windowHeight );
</ins><span class="cx" style="display: block; padding: 0 10px">                 return;
</span><span class="cx" style="display: block; padding: 0 10px">        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -135,7 +136,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">        imgs = content.getElementsByTagName( 'img' ) || [];
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        for ( var n = 0; n < imgs.length; n++ ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( n >= 100 ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( n >= 50 ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         break;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -153,34 +154,18 @@
</span><span class="cx" style="display: block; padding: 0 10px">        ifrs = document.body.getElementsByTagName( 'iframe' ) || [];
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        for ( var p = 0; p < ifrs.length; p++ ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( p >= 100 ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( p >= 50 ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         break;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                vid = ifrs[ p ].src.match(/\/\/www\.youtube\.com\/embed\/([^\?]+)\?.+$/);
-
-               if ( vid && 2 === vid.length ) {
-                       add( '_embed[]', 'https://www.youtube.com/watch?v=' + vid[1] );
-               }
-
-               vid = ifrs[ p ].src.match( /\/\/player\.vimeo\.com\/video\/([\d]+)$/ );
-
-               if ( vid && 2 === vid.length ) {
-                       add( '_embed[]', 'https://vimeo.com/' + vid[1] );
-               }
-
-               vid = ifrs[ p ].src.match( /\/\/vine\.co\/v\/([^\/]+)\/embed/ );
-
-               if ( vid && 2 === vid.length ) {
-                       add( '_embed[]', 'https://vine.co/v/' + vid[1] );
-               }
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         add( '_embed[]', ifrs[ p ].src );
</ins><span class="cx" style="display: block; padding: 0 10px">         }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        if ( document.title && document.title > 512 ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ if ( document.title ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                 add( 't', document.title );
</span><span class="cx" style="display: block; padding: 0 10px">        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        if ( selection && selection.length > 512 ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ if ( selection ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                 add( 's', selection );
</span><span class="cx" style="display: block; padding: 0 10px">        }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -189,10 +174,8 @@
</span><span class="cx" style="display: block; padding: 0 10px">        form.setAttribute( 'target', target );
</span><span class="cx" style="display: block; padding: 0 10px">        form.setAttribute( 'style', 'display: none;' );
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        newWin = window.open( 'about:blank', target, 'location,resizable,scrollbars,width=' + windowWidth + ',height=' + windowHeight );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ window.open( 'about:blank', target, 'location,resizable,scrollbars,width=' + windowWidth + ',height=' + windowHeight );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        document.body.appendChild( form );
</span><span class="cx" style="display: block; padding: 0 10px">        form.submit();
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-
-       newWin.focus();
</del><span class="cx" style="display: block; padding: 0 10px"> } )( window, document, top.location.href, window.pt_url );
</span></span></pre></div>
<a id="trunksrcwpadminjsbookmarkletminjs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-admin/js/bookmarklet.min.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-admin/js/bookmarklet.min.js  2015-03-04 09:50:34 UTC (rev 31608)
+++ trunk/src/wp-admin/js/bookmarklet.min.js    2015-03-04 19:28:53 UTC (rev 31609)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -1 +1 @@
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-(function(a,b,c,d){function e(a,c){if("undefined"!=typeof c){var d=b.createElement("input");d.name=a,d.value=c,d.type="hidden",q.appendChild(d)}}var f,g,h,i,j,k,l,m,n,o,p=a.encodeURIComponent,q=b.createElement("form"),r=b.getElementsByTagName("head")[0],s=new Image,t="_press_this_app",u=!0;if(d){if(!c.match(/^https?:/))return void(top.location.href=d);if(d+="&u="+p(c),c.match(/^https:/)&&d.match(/^http:/)&&(u=!1),a.getSelection?n=a.getSelection()+"":b.getSelection?n=b.getSelection()+"":b.selection&&(n=b.selection.createRange().text),d+=(d.indexOf("?")>-1?"&":"?")+"buster="+(new Date).getTime(),b.title.length&&(b.title.length<=256||!u)&&(d+="&t="+p(b.title.substr(0,256))),n&&(n.length&l
 t;=512||!u)&&(d+="&s="+p(n.substr(0,512))),f=a.outerWidth||b.documentElement.clientWidth||600,g=a.outerHeight||b.documentElement.clientHeight||700,f=800>f||f>5e3?600:.7*f,g=800>g||g>3e3?700:.9*g,!u)return o=a.open(d,t,"location,resizable,scrollbars,width="+f+",height="+g),void o.focus();c.match(/\/\/www\.youtube\.com\/watch/)?e("_embed[]",c):c.match(/\/\/vimeo\.com\/(.+\/)?([\d]+)$/)?e("_embed[]",c):c.match(/\/\/(www\.)?dailymotion\.com\/video\/.+$/)?e("_embed[]",c):c.match(/\/\/soundcloud\.com\/.+$/)?e("_embed[]",c):c.match(/\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/)?e("_embed[]",c):c.match(/\/\/vine\.co\/v\/[^\/]+/)&&e("_embed[]",c),h=r.getElementsByTagName("meta")||[];for(var v=0;v<h.length&&!(v>=50);v++){var w=h[v],x=w.getAttribute("name"),y=w.getAttribute("property"),z=w.getAttribute("content");x?e("
 _meta["+x+"]",z):y&&e("_meta["+y+"]",z)}i=r.getElementsByTagName("link")||[];for(var A=0;A<i.length&&!(A>=50);A++){var B=i[A],C=B.getAttribute("rel");if(C)switch(C){case"canonical":case"icon":case"shortlink":e("_links["+C+"]",B.getAttribute("href"));break;case"alternate":"application/json+oembed"===B.getAttribute("type")?e("_links["+C+"]",B.getAttribute("href")):"handheld"===B.getAttribute("media")&&e("_links["+C+"]",B.getAttribute("href"))}}b.body.getElementsByClassName&&(j=b.body.getElementsByClassName("hfeed")[0]),j=b.getElementById("content")||j||b.body,k=j.getElementsByTagName("img")||[];for(var D=0;D<k.length&&!(D>=100);D++)k[D].src.indexOf("avatar")>-1||k[D].cla
 ssName.indexOf("avatar")>-1||(s.src=k[D].src,s.width>=256&&s.height>=128&&e("_img[]",s.src));l=b.body.getElementsByTagName("iframe")||[];for(var E=0;E<l.length&&!(E>=100);E++)m=l[E].src.match(/\/\/www\.youtube\.com\/embed\/([^\?]+)\?.+$/),m&&2===m.length&&e("_embed[]","https://www.youtube.com/watch?v="+m[1]),m=l[E].src.match(/\/\/player\.vimeo\.com\/video\/([\d]+)$/),m&&2===m.length&&e("_embed[]","https://vimeo.com/"+m[1]),m=l[E].src.match(/\/\/vine\.co\/v\/([^\/]+)\/embed/),m&&2===m.length&&e("_embed[]","https://vine.co/v/"+m[1]);b.title&&b.title>512&&e("t",b.title),n&&n.length>512&&e("s",n),q.setAttribute("method","POST"),q.setAttribute("action",d),q.setAttribute("target",t),q.setAttribute("style",&qu
 ot;display: none;"),o=a.open("about:blank",t,"location,resizable,scrollbars,width="+f+",height="+g),b.body.appendChild(q),q.submit(),o.focus()}})(window,document,top.location.href,window.pt_url);
</del><span class="cx" style="display: block; padding: 0 10px">\ No newline at end of file
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+(function(a,b,c,d){function e(a,c){if("undefined"!=typeof c){var d=b.createElement("input");d.name=a,d.value=c,d.type="hidden",o.appendChild(d)}}var f,g,h,i,j,k,l,m,n=a.encodeURIComponent,o=b.createElement("form"),p=b.getElementsByTagName("head")[0],q=new Image,r="_press_this_app",s=!0;if(d){if(!c.match(/^https?:/))return void(top.location.href=d);if(d+="&u="+n(c),c.match(/^https:/)&&d.match(/^http:/)&&(s=!1),a.getSelection?m=a.getSelection()+"":b.getSelection?m=b.getSelection()+"":b.selection&&(m=b.selection.createRange().text||""),d+=(d.indexOf("?")>-1?"&":"?")+"buster="+(new Date).getTime(),s||(b.title&&(d+="&t="+n(b.title.substr(0,256))),m&&(d+="&s="+n(m.substr(0,512))
 )),f=a.outerWidth||b.documentElement.clientWidth||600,g=a.outerHeight||b.documentElement.clientHeight||700,f=800>f||f>5e3?600:.7*f,g=800>g||g>3e3?700:.9*g,!s)return void a.open(d,r,"location,resizable,scrollbars,width="+f+",height="+g);c.match(/\/\/www\.youtube\.com\/watch/)?e("_embed[]",c):c.match(/\/\/vimeo\.com\/(.+\/)?([\d]+)$/)?e("_embed[]",c):c.match(/\/\/(www\.)?dailymotion\.com\/video\/.+$/)?e("_embed[]",c):c.match(/\/\/soundcloud\.com\/.+$/)?e("_embed[]",c):c.match(/\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/)?e("_embed[]",c):c.match(/\/\/vine\.co\/v\/[^\/]+/)&&e("_embed[]",c),h=p.getElementsByTagName("meta")||[];for(var t=0;t<h.length&&!(t>=50);t++){var u=h[t],v=u.getAttribute("name"),w=u.getAttribute("property"),x=u.getAttribute("content");v?e("_meta["+v+"]",x):w&&e("_meta["+w+"]&
 quot;,x)}i=p.getElementsByTagName("link")||[];for(var y=0;y<i.length&&!(y>=50);y++){var z=i[y],A=z.getAttribute("rel");if(A)switch(A){case"canonical":case"icon":case"shortlink":e("_links["+A+"]",z.getAttribute("href"));break;case"alternate":"application/json+oembed"===z.getAttribute("type")?e("_links["+A+"]",z.getAttribute("href")):"handheld"===z.getAttribute("media")&&e("_links["+A+"]",z.getAttribute("href"))}}b.body.getElementsByClassName&&(j=b.body.getElementsByClassName("hfeed")[0]),j=b.getElementById("content")||j||b.body,k=j.getElementsByTagName("img")||[];for(var B=0;B<k.length&&!(B>=50);B++)k[B].src.indexOf("avatar")>-1||k[B].className.indexOf("avatar")>-1||(q.src=k[B].src,q.width>=256&a
 mp;&q.height>=128&&e("_img[]",q.src));l=b.body.getElementsByTagName("iframe")||[];for(var C=0;C<l.length&&!(C>=50);C++)e("_embed[]",l[C].src);b.title&&e("t",b.title),m&&e("s",m),o.setAttribute("method","POST"),o.setAttribute("action",d),o.setAttribute("target",r),o.setAttribute("style","display: none;"),a.open("about:blank",r,"location,resizable,scrollbars,width="+f+",height="+g),b.body.appendChild(o),o.submit()}})(window,document,top.location.href,window.pt_url);
</ins><span class="cx" style="display: block; padding: 0 10px">\ No newline at end of file
</span></span></pre></div>
<a id="trunksrcwpadminjspressthisjs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-admin/js/press-this.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-admin/js/press-this.js       2015-03-04 09:50:34 UTC (rev 31608)
+++ trunk/src/wp-admin/js/press-this.js 2015-03-04 19:28:53 UTC (rev 31609)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -6,6 +6,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">        var PressThis = function() {
</span><span class="cx" style="display: block; padding: 0 10px">                var editor,
</span><span class="cx" style="display: block; padding: 0 10px">                        saveAlert             = false,
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                        textarea              = document.createElement( 'textarea' ),
</ins><span class="cx" style="display: block; padding: 0 10px">                         siteConfig            = window.wpPressThisConfig || {},
</span><span class="cx" style="display: block; padding: 0 10px">                        data                  = window.wpPressThisData || {},
</span><span class="cx" style="display: block; padding: 0 10px">                        smallestWidth         = 128,
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -60,24 +61,20 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        return string
</span><span class="cx" style="display: block; padding: 0 10px">                                .replace( /<!--[\s\S]*?(-->|$)/g, '' )
</span><span class="cx" style="display: block; padding: 0 10px">                                .replace( /<(script|style)[^>]*>[\s\S]*?(<\/\1>|$)/ig, '' )
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                .replace( /<\/?[a-z][^>]*>/ig, '' );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         .replace( /<\/?[a-z][\s\S]*?(>|$)/ig, '' );
</ins><span class="cx" style="display: block; padding: 0 10px">                 }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                /**
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 * Strip HTML tags and entity encode some of the HTML special chars.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+          * Strip HTML tags and convert HTML entities.
</ins><span class="cx" style="display: block; padding: 0 10px">                  *
</span><span class="cx" style="display: block; padding: 0 10px">                 * @param text string Text.
</span><span class="cx" style="display: block; padding: 0 10px">                 * @returns string Sanitized text.
</span><span class="cx" style="display: block; padding: 0 10px">                 */
</span><span class="cx" style="display: block; padding: 0 10px">                function sanitizeText( text ) {
</span><span class="cx" style="display: block; padding: 0 10px">                        text = stripTags( text );
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                        textarea.innerHTML = text;
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        return text
-                               .replace( /\\/, '' )
-                               .replace( /</g, '&lt;' )
-                               .replace( />/g, '&gt;' )
-                               .replace( /"/g, '&quot;' )
-                               .replace( /'/g, '&#039;' );
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                 return stripTags( textarea.value );
</ins><span class="cx" style="display: block; padding: 0 10px">                 }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                /**
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -214,70 +211,6 @@
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                /**
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 * Tests if what was passed as an embed URL is deemed to be embeddable in the editor.
-                *
-                * @param url string Passed URl, usually from WpPressThis_App.data._embed
-                * @returns boolean
-                */
-               function isEmbeddable( url ) {
-                       if ( ! url ) {
-                               return false;
-                       } else if ( url.match( /\/\/(m\.|www\.)?youtube\.com\/watch\?/ ) || url.match( /\/youtu\.be\/.+$/ ) ) {
-                               return true;
-                       } else if ( url.match( /\/\/vimeo\.com\/(.+\/)?[\d]+$/ ) ) {
-                               return true;
-                       } else if ( url.match( /\/\/(www\.)?dailymotion\.com\/video\/.+$/ ) ) {
-                               return true;
-                       } else if ( url.match( /\/\/soundcloud\.com\/.+$/ ) ) {
-                               return true;
-                       } else if ( url.match( /\/\/twitter\.com\/[^\/]+\/status\/[\d]+$/ ) ) {
-                               return true;
-                       } else if ( url.match( /\/\/vine\.co\/v\/[^\/]+/ ) ) {
-                               return true;
-                       }
-
-                       return false;
-               }
-
-               /**
-                * Tests if what was passed as an image URL is deemed to be interesting enough to offer to the user for selection.
-                *
-                * @param src string Passed URl, usually from WpPressThis_App.data._ing
-                * @returns boolean Test for false
-                */
-               function isSrcUninterestingPath( src ) {
-                       if ( src.match( /\/ad[sx]{1}?\// ) ) {
-                               // Ads
-                               return true;
-                       } else if ( src.match( /(\/share-?this[^\.]+?\.[a-z0-9]{3,4})(\?.*)?$/ ) ) {
-                               // Share-this type button
-                               return true;
-                       } else if ( src.match( /\/(spinner|loading|spacer|blank|rss)\.(gif|jpg|png)/ ) ) {
-                               // Loaders, spinners, spacers
-                               return true;
-                       } else if ( src.match( /\/([^\.\/]+[-_]{1})?(spinner|loading|spacer|blank)s?([-_]{1}[^\.\/]+)?\.[a-z0-9]{3,4}/ ) ) {
-                               // Fancy loaders, spinners, spacers
-                               return true;
-                       } else if ( src.match( /([^\.\/]+[-_]{1})?thumb[^.]*\.(gif|jpg|png)$/ ) ) {
-                               // Thumbnails, too small, usually irrelevant to context
-                               return true;
-                       } else if ( src.match( /\/wp-includes\// ) ) {
-                               // Classic WP interface images
-                               return true;
-                       } else if ( src.match( /[^\d]{1}\d{1,2}x\d+\.(gif|jpg|png)$/ ) ) {
-                               // Most often tiny buttons/thumbs (< 100px wide)
-                               return true;
-                       } else if ( src.indexOf( '/g.gif' ) > -1 ) {
-                               // Classic WP stats gif
-                               return true;
-                       } else if ( src.indexOf( '/pixel.mathtag.com' ) > -1 ) {
-                               // See mathtag.com
-                               return true;
-                       }
-                       return false;
-               }
-
-               /**
</del><span class="cx" style="display: block; padding: 0 10px">                  * Get a list of valid embeds from what was passed via WpPressThis_App.data._embed on page load.
</span><span class="cx" style="display: block; padding: 0 10px">                 *
</span><span class="cx" style="display: block; padding: 0 10px">                 * @returns array
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -292,9 +225,6 @@
</span><span class="cx" style="display: block; padding: 0 10px">                                        if ( !src || !src.length ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                                // Skip: no src value
</span><span class="cx" style="display: block; padding: 0 10px">                                                return;
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                        } else if ( !isEmbeddable( src ) ) {
-                                               // Skip: not deemed embeddable
-                                               return;
</del><span class="cx" style="display: block; padding: 0 10px">                                         }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                                        var schemelessSrc = src.replace( /^https?:/, '' );
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -313,52 +243,15 @@
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                /**
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                 * Get what is likely the most valuable image from what was passed via WpPressThis_App.data._img and WpPressThis_App.data._meta on page load.
-                *
-                * @returns array
-                */
-               function getFeaturedImage( data ) {
-                       var featured = '';
-
-                       if ( ! data || ! data._meta ) {
-                               return '';
-                       }
-
-                       if ( data._meta['twitter:image0:src'] && data._meta['twitter:image0:src'].length ) {
-                               featured = data._meta['twitter:image0:src'];
-                       } else if ( data._meta['twitter:image0'] && data._meta['twitter:image0'].length ) {
-                               featured = data._meta['twitter:image0'];
-                       } else if ( data._meta['twitter:image:src'] && data._meta['twitter:image:src'].length ) {
-                               featured = data._meta['twitter:image:src'];
-                       } else if ( data._meta['twitter:image'] && data._meta['twitter:image'].length ) {
-                               featured = data._meta['twitter:image'];
-                       } else if ( data._meta['og:image'] && data._meta['og:image'].length ) {
-                               featured = data._meta['og:image'];
-                       } else if ( data._meta['og:image:secure_url'] && data._meta['og:image:secure_url'].length ) {
-                               featured = data._meta['og:image:secure_url'];
-                       }
-
-                       featured = checkUrl( featured );
-
-                       return ( isSrcUninterestingPath( featured ) ) ? '' : featured;
-               }
-
-               /**
</del><span class="cx" style="display: block; padding: 0 10px">                  * Get a list of valid images from what was passed via WpPressThis_App.data._img and WpPressThis_App.data._meta on page load.
</span><span class="cx" style="display: block; padding: 0 10px">                 *
</span><span class="cx" style="display: block; padding: 0 10px">                 * @returns array
</span><span class="cx" style="display: block; padding: 0 10px">                 */
</span><span class="cx" style="display: block; padding: 0 10px">                function getInterestingImages( data ) {
</span><span class="cx" style="display: block; padding: 0 10px">                        var imgs             = data._img || [],
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                featuredPict     = getFeaturedImage( data ) || '',
</del><span class="cx" style="display: block; padding: 0 10px">                                 interestingImgs  = [],
</span><span class="cx" style="display: block; padding: 0 10px">                                alreadySelected  = [];
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                        if ( featuredPict.length ) {
-                               interestingImgs.push( featuredPict );
-                               alreadySelected.push( featuredPict.replace(/^https?:/, '') );
-                       }
-
</del><span class="cx" style="display: block; padding: 0 10px">                         if ( imgs.length ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                $.each( imgs, function ( i, src ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                        src = src.replace( /http:\/\/[\d]+\.gravatar\.com\//, 'https://secure.gravatar.com/' );
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -374,9 +267,6 @@
</span><span class="cx" style="display: block; padding: 0 10px">                                        if ( Array.prototype.indexOf && alreadySelected.indexOf( schemelessSrc ) > -1 ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                                // Skip: already shown
</span><span class="cx" style="display: block; padding: 0 10px">                                                return;
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                        } else if ( isSrcUninterestingPath( src ) ) {
-                                               // Skip: spinner, stat, ad, or spacer pict
-                                               return;
</del><span class="cx" style="display: block; padding: 0 10px">                                         } else if ( src.indexOf( 'avatar' ) > -1 && interestingImgs.length >= 15 ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                                // Skip:  some type of avatar and we've already gathered more than 23 diff images to show
</span><span class="cx" style="display: block; padding: 0 10px">                                                return;
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -665,10 +555,6 @@
</span><span class="cx" style="display: block; padding: 0 10px">                                $.each( interestingEmbeds, function ( i, src ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                        src = checkUrl( src );
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                        if ( ! isEmbeddable( src ) ) {
-                                               return;
-                                       }
-
</del><span class="cx" style="display: block; padding: 0 10px">                                         var displaySrc = '',
</span><span class="cx" style="display: block; padding: 0 10px">                                                cssClass   = 'suggested-media-thumbnail suggested-media-embed';
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span></span></pre></div>
<a id="trunksrcwpincludeslinktemplatephp"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-includes/link-template.php</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-includes/link-template.php   2015-03-04 09:50:34 UTC (rev 31608)
+++ trunk/src/wp-includes/link-template.php     2015-03-04 19:28:53 UTC (rev 31609)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -2596,7 +2596,7 @@
</span><span class="cx" style="display: block; padding: 0 10px"> function get_shortcut_link() {
</span><span class="cx" style="display: block; padding: 0 10px">        global $is_IE, $wp_version;
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-        $bookmarklet_version = '5';
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+ $bookmarklet_version = '6';
</ins><span class="cx" style="display: block; padding: 0 10px">         $link = '';
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">        if ( $is_IE ) {
</span></span></pre>
</div>
</div>

</body>
</html>