-
Notifications
You must be signed in to change notification settings - Fork 2.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Try casting options, etc to strings #7133
base: trunk
Are you sure you want to change the base?
Changes from all commits
34b0ac5
40c7bde
ec26ed8
f6f5cf4
d2f5231
77822e7
667df54
3750a6d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -891,6 +891,8 @@ function update_option( $option, $value, $autoload = null ) { | |
*/ | ||
$value = apply_filters( 'pre_update_option', $value, $option, $old_value ); | ||
|
||
$serialized_value = maybe_serialize( $value ); | ||
|
||
/* | ||
* If the new and old values are the same, no need to update. | ||
* | ||
|
@@ -900,7 +902,7 @@ function update_option( $option, $value, $autoload = null ) { | |
* | ||
* See https://core.trac.wordpress.org/ticket/38903 | ||
*/ | ||
if ( $value === $old_value || maybe_serialize( $value ) === maybe_serialize( $old_value ) ) { | ||
if ( sprintf( '%s', $serialized_value ) === $old_value || maybe_serialize( $old_value ) === $serialized_value ) { | ||
return false; | ||
} | ||
|
||
|
@@ -909,8 +911,6 @@ function update_option( $option, $value, $autoload = null ) { | |
return add_option( $option, $value, '', $autoload ); | ||
} | ||
|
||
$serialized_value = maybe_serialize( $value ); | ||
|
||
/** | ||
* Fires immediately before an option value is updated. | ||
* | ||
|
@@ -922,6 +922,15 @@ function update_option( $option, $value, $autoload = null ) { | |
*/ | ||
do_action( 'update_option', $option, $old_value, $value ); | ||
|
||
/* | ||
* Ensure the serialized value is a string. | ||
* | ||
* This ensure that the option is stored in the cache in the same format as the | ||
* option is stored in the database. Rather than type casting, sprintf is used to | ||
* match the process used by wpdb::prepare(). | ||
*/ | ||
$serialized_value = sprintf( '%s', $serialized_value ); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. As far as I can tell, the |
||
|
||
$update_args = array( | ||
'option_value' => $serialized_value, | ||
); | ||
|
@@ -1117,6 +1126,15 @@ function add_option( $option, $value = '', $deprecated = '', $autoload = null ) | |
*/ | ||
do_action( 'add_option', $option, $value ); | ||
|
||
/* | ||
* Ensure the serialized value is a string. | ||
* | ||
* This ensure that the option is stored in the cache in the same format as the | ||
* option is stored in the database. Rather than type casting, sprintf is used to | ||
* match the process used by wpdb::prepare(). | ||
*/ | ||
$serialized_value = sprintf( '%s', $serialized_value ); | ||
|
||
$result = $wpdb->query( $wpdb->prepare( "INSERT INTO `$wpdb->options` (`option_name`, `option_value`, `autoload`) VALUES (%s, %s, %s) ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`)", $option, $serialized_value, $autoload ) ); | ||
if ( ! $result ) { | ||
return false; | ||
|
@@ -2147,6 +2165,16 @@ function add_network_option( $network_id, $option, $value ) { | |
$value = sanitize_option( $option, $value ); | ||
|
||
$serialized_value = maybe_serialize( $value ); | ||
|
||
/* | ||
* Ensure the serialized value is a string. | ||
* | ||
* This ensure that the option is stored in the cache in the same format as the | ||
* option is stored in the database. Rather than type casting, sprintf is used to | ||
* match the process used by wpdb::prepare(). | ||
*/ | ||
$serialized_value = sprintf( '%s', $serialized_value ); | ||
|
||
$result = $wpdb->insert( | ||
$wpdb->sitemeta, | ||
array( | ||
|
@@ -2359,6 +2387,8 @@ function update_network_option( $network_id, $option, $value ) { | |
*/ | ||
$value = apply_filters( "pre_update_site_option_{$option}", $value, $old_value, $option, $network_id ); | ||
|
||
$serialized_value = maybe_serialize( $value ); | ||
|
||
/* | ||
* If the new and old values are the same, no need to update. | ||
* | ||
|
@@ -2368,7 +2398,7 @@ function update_network_option( $network_id, $option, $value ) { | |
* | ||
* See https://core.trac.wordpress.org/ticket/44956 | ||
*/ | ||
if ( $value === $old_value || maybe_serialize( $value ) === maybe_serialize( $old_value ) ) { | ||
if ( sprintf( '%s', $serialized_value ) === $old_value || maybe_serialize( $old_value ) === $serialized_value ) { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. See my comment above, this would apply here as well. |
||
return false; | ||
} | ||
|
||
|
@@ -2389,7 +2419,15 @@ function update_network_option( $network_id, $option, $value ) { | |
} else { | ||
$value = sanitize_option( $option, $value ); | ||
|
||
$serialized_value = maybe_serialize( $value ); | ||
/* | ||
* Ensure the serialized value is a string. | ||
* | ||
* This ensure that the option is stored in the cache in the same format as the | ||
* option is stored in the database. Rather than type casting, sprintf is used to | ||
* match the process used by wpdb::prepare(). | ||
*/ | ||
$serialized_value = sprintf( '%s', $serialized_value ); | ||
|
||
$result = $wpdb->update( | ||
$wpdb->sitemeta, | ||
array( 'meta_value' => $serialized_value ), | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I am concerned about this, for the same reason that https://core.trac.wordpress.org/ticket/22192 didn't work out the way we were hoping. There is definitely room for BC breakage here.
$old_value
is not necessarily a string or non-scalar value. The return value ofget_option()
can be filtered, and it's not mandated anywhere to return a string. And even without custom filters, this can commonly be another type, particularly when the default is returned that is specified viaregister_setting()
and injected via core's own filter usage.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Also, why are we using
$serialized_value
in the first clause?$old_value
may be non-scalar in which case this is nevertrue
.Could this maybe work instead?
This seems a bit safer to me as it maintains both of the original clauses and only considers the problem case as a new clause for scalar values.