<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[38890] trunk/src: Customize: Harden url matching to account for varying ports and ensuring matching base pathname for allowed urls</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta" style="font-size: 105%">
<dt style="float: left; width: 6em; font-weight: bold">Revision</dt> <dd><a style="font-weight: bold" href="https://core.trac.wordpress.org/changeset/38890">38890</a><script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","description":"Review this Commit","action":{"@type":"ViewAction","url":"https://core.trac.wordpress.org/changeset/38890","name":"Review Commit"}}</script></dd>
<dt style="float: left; width: 6em; font-weight: bold">Author</dt> <dd>westonruter</dd>
<dt style="float: left; width: 6em; font-weight: bold">Date</dt> <dd>2016-10-24 20:06:06 +0000 (Mon, 24 Oct 2016)</dd>
</dl>

<pre style='padding-left: 1em; margin: 2em 0; border-left: 2px solid #ccc; line-height: 1.25; font-size: 105%; font-family: sans-serif'>Customize: Harden url matching to account for varying ports and ensuring matching base pathname for allowed urls

Fixes <a href="https://core.trac.wordpress.org/ticket/38409">#38409</a>.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunksrcwpadminjscustomizecontrolsjs">trunk/src/wp-admin/js/customize-controls.js</a></li>
<li><a href="#trunksrcwpincludesjscustomizebasejs">trunk/src/wp-includes/js/customize-base.js</a></li>
<li><a href="#trunksrcwpincludesjscustomizepreviewjs">trunk/src/wp-includes/js/customize-preview.js</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunksrcwpadminjscustomizecontrolsjs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-admin/js/customize-controls.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-admin/js/customize-controls.js       2016-10-24 19:14:26 UTC (rev 38889)
+++ trunk/src/wp-admin/js/customize-controls.js 2016-10-24 20:06:06 UTC (rev 38890)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -4040,7 +4040,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        // ssl certs.
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                        previewer.add( 'previewUrl', params.previewUrl ).setter( function( to ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                var result, urlParser, newPreviewUrl, schemeMatchingPreviewUrl, queryParams;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         var result = null, urlParser, queryParams, parsedAllowedUrl, parsedCandidateUrls = [];
</ins><span class="cx" style="display: block; padding: 0 10px">                                 urlParser = document.createElement( 'a' );
</span><span class="cx" style="display: block; padding: 0 10px">                                urlParser.href = to;
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -4062,31 +4062,30 @@
</span><span class="cx" style="display: block; padding: 0 10px">                                        }
</span><span class="cx" style="display: block; padding: 0 10px">                                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                newPreviewUrl = urlParser.href;
-                               urlParser.protocol = previewer.scheme.get() + ':';
-                               schemeMatchingPreviewUrl = urlParser.href;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         parsedCandidateUrls.push( urlParser );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                                // Prepend list with URL that matches the scheme/protocol of the iframe.
+                               if ( previewer.scheme.get() + ':' !== urlParser.protocol ) {
+                                       urlParser = document.createElement( 'a' );
+                                       urlParser.href = parsedCandidateUrls[0].href;
+                                       urlParser.protocol = previewer.scheme.get() + ':';
+                                       parsedCandidateUrls.unshift( urlParser );
+                               }
+
</ins><span class="cx" style="display: block; padding: 0 10px">                                 // Attempt to match the URL to the control frame's scheme
</span><span class="cx" style="display: block; padding: 0 10px">                                // and check if it's allowed. If not, try the original URL.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                $.each( [ schemeMatchingPreviewUrl, newPreviewUrl ], function( i, url ) {
-                                       $.each( previewer.allowedUrls, function( i, allowed ) {
-                                               var path;
-
-                                               allowed = allowed.replace( /\/+$/, '' );
-                                               path = url.replace( allowed, '' );
-
-                                               if ( 0 === url.indexOf( allowed ) && /^([/#?]|$)/.test( path ) ) {
-                                                       result = url;
-                                                       return false;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         parsedAllowedUrl = document.createElement( 'a' );
+                               _.find( parsedCandidateUrls, function( parsedCandidateUrl ) {
+                                       return ! _.isUndefined( _.find( previewer.allowedUrls, function( allowedUrl ) {
+                                               parsedAllowedUrl.href = allowedUrl;
+                                               if ( urlParser.protocol === parsedAllowedUrl.protocol && urlParser.host === parsedAllowedUrl.host && 0 === parsedAllowedUrl.pathname.indexOf( urlParser.pathname ) ) {
+                                                       result = parsedCandidateUrl.href;
+                                                       return true;
</ins><span class="cx" style="display: block; padding: 0 10px">                                                 }
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                        });
-                                       if ( result ) {
-                                               return false;
-                                       }
-                               });
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                                 } ) );
+                               } );
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                // If we found a matching result, return it. If not, bail.
-                               return result ? result : null;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         return result;
</ins><span class="cx" style="display: block; padding: 0 10px">                         });
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                        previewer.bind( 'ready', previewer.ready );
</span></span></pre></div>
<a id="trunksrcwpincludesjscustomizebasejs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-includes/js/customize-base.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-includes/js/customize-base.js        2016-10-24 19:14:26 UTC (rev 38889)
+++ trunk/src/wp-includes/js/customize-base.js  2016-10-24 20:06:06 UTC (rev 38890)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -654,7 +654,8 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        this.add( 'origin', this.url() ).link( this.url ).setter( function( to ) {
</span><span class="cx" style="display: block; padding: 0 10px">                                var urlParser = document.createElement( 'a' );
</span><span class="cx" style="display: block; padding: 0 10px">                                urlParser.href = to;
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                                return urlParser.protocol + '//' + urlParser.hostname;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+                         // Port stripping needed by IE since it adds to host but not to event.origin.
+                               return urlParser.protocol + '//' + urlParser.host.replace( /:80$/, '' );
</ins><span class="cx" style="display: block; padding: 0 10px">                         });
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                        // first add with no value
</span></span></pre></div>
<a id="trunksrcwpincludesjscustomizepreviewjs"></a>
<div class="modfile"><h4 style="background-color: #eee; color: inherit; margin: 1em 0; padding: 1.3em; font-size: 115%">Modified: trunk/src/wp-includes/js/customize-preview.js</h4>
<pre class="diff"><span>
<span class="info" style="display: block; padding: 0 10px; color: #888">--- trunk/src/wp-includes/js/customize-preview.js     2016-10-24 19:14:26 UTC (rev 38889)
+++ trunk/src/wp-includes/js/customize-preview.js       2016-10-24 20:06:06 UTC (rev 38890)
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -275,13 +275,13 @@
</span><span class="cx" style="display: block; padding: 0 10px">         * @param {HTMLAnchorElement|HTMLAreaElement} element Link element.
</span><span class="cx" style="display: block; padding: 0 10px">         * @param {string} element.search Query string.
</span><span class="cx" style="display: block; padding: 0 10px">         * @param {string} element.pathname Path.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-         * @param {string} element.hostname Hostname.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+  * @param {string} element.host Host.
</ins><span class="cx" style="display: block; padding: 0 10px">          * @param {object} [options]
</span><span class="cx" style="display: block; padding: 0 10px">         * @param {object} [options.allowAdminAjax=false] Allow admin-ajax.php requests.
</span><span class="cx" style="display: block; padding: 0 10px">         * @returns {boolean} Is appropriate for changeset link.
</span><span class="cx" style="display: block; padding: 0 10px">         */
</span><span class="cx" style="display: block; padding: 0 10px">        api.isLinkPreviewable = function isLinkPreviewable( element, options ) {
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                var hasMatchingHost, urlParser, args;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         var matchesAllowedUrl, parsedAllowedUrl, args;
</ins><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                args = _.extend( {}, { allowAdminAjax: false }, options || {} );
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -294,15 +294,12 @@
</span><span class="cx" style="display: block; padding: 0 10px">                        return false;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                urlParser = document.createElement( 'a' );
-               hasMatchingHost = ! _.isUndefined( _.find( api.settings.url.allowed, function( allowedUrl ) {
-                       urlParser.href = allowedUrl;
-                       if ( urlParser.hostname === element.hostname && urlParser.protocol === element.protocol ) {
-                               return true;
-                       }
-                       return false;
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         parsedAllowedUrl = document.createElement( 'a' );
+               matchesAllowedUrl = ! _.isUndefined( _.find( api.settings.url.allowed, function( allowedUrl ) {
+                       parsedAllowedUrl.href = allowedUrl;
+                       return parsedAllowedUrl.protocol === element.protocol && parsedAllowedUrl.host === element.host && 0 === element.pathname.indexOf( parsedAllowedUrl.pathname );
</ins><span class="cx" style="display: block; padding: 0 10px">                 } ) );
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( ! hasMatchingHost ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( ! matchesAllowedUrl ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         return false;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -331,7 +328,9 @@
</span><span class="cx" style="display: block; padding: 0 10px">         * @access protected
</span><span class="cx" style="display: block; padding: 0 10px">         *
</span><span class="cx" style="display: block; padding: 0 10px">         * @param {HTMLAnchorElement|HTMLAreaElement} element Link element.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-         * @param {object} element.search Query string.
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+  * @param {string} element.search Query string.
+        * @param {string} element.host Host.
+        * @param {string} element.protocol Protocol.
</ins><span class="cx" style="display: block; padding: 0 10px">          * @returns {void}
</span><span class="cx" style="display: block; padding: 0 10px">         */
</span><span class="cx" style="display: block; padding: 0 10px">        api.prepareLinkPreview = function prepareLinkPreview( element ) {
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -348,7 +347,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                // Make sure links in preview use HTTPS if parent frame uses HTTPS.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( 'https' === api.preview.scheme.get() && 'http:' === element.protocol && -1 !== api.settings.url.allowedHosts.indexOf( element.hostname ) ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( 'https' === api.preview.scheme.get() && 'http:' === element.protocol && -1 !== api.settings.url.allowedHosts.indexOf( element.host ) ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         element.protocol = 'https:';
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="lines" style="display: block; padding: 0 10px; color: #888">@@ -496,7 +495,7 @@
</span><span class="cx" style="display: block; padding: 0 10px">                urlParser.href = form.action;
</span><span class="cx" style="display: block; padding: 0 10px"> 
</span><span class="cx" style="display: block; padding: 0 10px">                // Make sure forms in preview use HTTPS if parent frame uses HTTPS.
</span><del style="background-color: #fdd; text-decoration:none; display:block; padding: 0 10px">-                if ( 'https' === api.preview.scheme.get() && 'http:' === urlParser.protocol && -1 !== api.settings.url.allowedHosts.indexOf( urlParser.hostname ) ) {
</del><ins style="background-color: #dfd; text-decoration:none; display:block; padding: 0 10px">+         if ( 'https' === api.preview.scheme.get() && 'http:' === urlParser.protocol && -1 !== api.settings.url.allowedHosts.indexOf( urlParser.host ) ) {
</ins><span class="cx" style="display: block; padding: 0 10px">                         urlParser.protocol = 'https:';
</span><span class="cx" style="display: block; padding: 0 10px">                        form.action = urlParser.href;
</span><span class="cx" style="display: block; padding: 0 10px">                }
</span></span></pre>
</div>
</div>

</body>
</html>