diff --git a/includes/class-exelearning-editor.php b/includes/class-exelearning-editor.php index b52dece..9fa8927 100644 --- a/includes/class-exelearning-editor.php +++ b/includes/class-exelearning-editor.php @@ -42,13 +42,8 @@ private function maybe_start_buffer() { return; } - // Suppress error display for this request to prevent output corruption. - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.IniSet.display_errors_Disallowed, Squiz.PHP.DiscouragedFunctions.Discouraged -- Required to prevent output corruption in standalone editor page. - @ini_set( 'display_errors', '0' ); - // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.runtime_configuration_error_reporting, WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DevelopmentFunctions.prevent_path_disclosure_error_reporting - @error_reporting( 0 ); - - // Start output buffering to capture any warnings/notices. + // Buffer stray output (notices, echoes); it is discarded before the editor + // document is sent, so the site's error settings are left untouched. ob_start(); // Register to render the page and discard buffered output (very early priority). @@ -59,10 +54,6 @@ private function maybe_start_buffer() { * Render the editor page and exit, discarding any buffered output. */ public function render_editor_page_and_exit() { - // Suppress error display for this request to prevent output corruption. - // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.IniSet.display_errors_Disallowed, Squiz.PHP.DiscouragedFunctions.Discouraged -- Required to prevent output corruption in standalone editor page. - @ini_set( 'display_errors', '0' ); - // Discard any buffered output (warnings, notices, etc.). while ( ob_get_level() > 0 ) { ob_end_clean(); diff --git a/includes/class-exelearning-rest-api.php b/includes/class-exelearning-rest-api.php index b24e032..666b834 100644 --- a/includes/class-exelearning-rest-api.php +++ b/includes/class-exelearning-rest-api.php @@ -241,11 +241,6 @@ public function create_elp_file( $request ) { // phpcs:ignore Generic.CodeAnalys ); } - // Use WordPress media handling. - require_once ABSPATH . 'wp-admin/includes/file.php'; - require_once ABSPATH . 'wp-admin/includes/media.php'; - require_once ABSPATH . 'wp-admin/includes/image.php'; - // Sanitize filename and ensure the .elpx extension. The plugin only // registers and edits .elpx files, so any other extension is normalized. $filename = $this->ensure_elpx_extension( sanitize_file_name( $uploaded_file['name'] ) ); @@ -260,6 +255,7 @@ public function create_elp_file( $request ) { // phpcs:ignore Generic.CodeAnalys // Handle the upload. Suspend the global upload filter so the file is not // extracted twice (we reprocess it explicitly below). + require_once ABSPATH . 'wp-admin/includes/file.php'; // wp_handle_upload() is not loaded in REST requests. ExeLearning_Elp_Upload_Handler::suspend_processing( true ); $upload = wp_handle_upload( $file, array( 'test_form' => false ) ); ExeLearning_Elp_Upload_Handler::suspend_processing( false ); @@ -391,10 +387,6 @@ private function save_elp_file_locked( $attachment_id, $uploaded_file, $old_file */ do_action( 'exelearning_before_elpx_save', $attachment_id, $old_file_path ); - // Route the uploaded file through WordPress so the move (and MIME check) - // goes via the wp_handle_upload() wrapper that Plugin Check accepts. - require_once ABSPATH . 'wp-admin/includes/file.php'; - // The plugin only edits .elpx; normalize the upload filename. $upload_filename = $this->ensure_elpx_extension( sanitize_file_name( $uploaded_file['name'] ) ); @@ -408,6 +400,7 @@ private function save_elp_file_locked( $attachment_id, $uploaded_file, $old_file ); // Suspend the global upload filter; we validate/extract the temp file ourselves. + require_once ABSPATH . 'wp-admin/includes/file.php'; // wp_handle_upload() is not loaded in REST requests. ExeLearning_Elp_Upload_Handler::suspend_processing( true ); $upload = wp_handle_upload( $file_for_upload, array( 'test_form' => false ) ); ExeLearning_Elp_Upload_Handler::suspend_processing( false ); diff --git a/tests/unit/EditorPageTest.php b/tests/unit/EditorPageTest.php index cb65f99..9dbdd0e 100644 --- a/tests/unit/EditorPageTest.php +++ b/tests/unit/EditorPageTest.php @@ -154,9 +154,9 @@ public function test_the_editor_page_is_rendered_ahead_of_admin_init() { $scheduled_at = has_action( 'admin_init', array( $editor, 'render_editor_page_and_exit' ) ); ob_end_clean(); - error_reporting( $reporting ); // phpcs:ignore - ini_set( 'display_errors', $display_errors ); // phpcs:ignore + $this->assertSame( $reporting, error_reporting(), 'The site error_reporting level must be left untouched.' ); // phpcs:ignore + $this->assertSame( $display_errors, ini_get( 'display_errors' ), 'display_errors must be left untouched.' ); $this->assertSame( $level + 1, $level_after_boot, 'Output must be captured from the very start.' ); $this->assertSame( -999, $scheduled_at ); $this->assertSame( $level, ob_get_level() );