[wp-trac] [WordPress Trac] #58902: add_query_arg() should esc_url_raw() REQUEST_URI

WordPress Trac noreply at wordpress.org
Tue Jun 25 12:22:54 UTC 2024


#58902: add_query_arg() should esc_url_raw() REQUEST_URI
-------------------------------------------------+-------------------------
 Reporter:  jorbin                               |       Owner:  (none)
     Type:  defect (bug)                         |      Status:  new
 Priority:  normal                               |   Milestone:  6.7
Component:  Formatting                           |     Version:
 Severity:  normal                               |  Resolution:
 Keywords:  has-patch has-unit-tests needs-      |     Focuses:
  testing needs-testing-info                     |
-------------------------------------------------+-------------------------
Changes (by oglekler):

 * milestone:  6.6 => 6.7


Comment:

 We have RC1 today, and it looks like we will not make it in this
 milestone, so I am moving this ticket to the next one.

 Most likely, the patch needs refresh and possibly testing instructions.

 Hypothetically, Can unescape or escaped $_SERVER['REQUEST_URI'] in this
 place break something? 🤔

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/58902#comment:22>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list