Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 2 additions & 11 deletions includes/class-exelearning-editor.php
Original file line number Diff line number Diff line change
Expand Up @@ -42,13 +42,8 @@ private function maybe_start_buffer() {
return;
}

// Suppress error display for this request to prevent output corruption.
// phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.IniSet.display_errors_Disallowed, Squiz.PHP.DiscouragedFunctions.Discouraged -- Required to prevent output corruption in standalone editor page.
@ini_set( 'display_errors', '0' );
// phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.runtime_configuration_error_reporting, WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DevelopmentFunctions.prevent_path_disclosure_error_reporting
@error_reporting( 0 );

// Start output buffering to capture any warnings/notices.
// Buffer stray output (notices, echoes); it is discarded before the editor
// document is sent, so the site's error settings are left untouched.
ob_start();

// Register to render the page and discard buffered output (very early priority).
Expand All @@ -59,10 +54,6 @@ private function maybe_start_buffer() {
* Render the editor page and exit, discarding any buffered output.
*/
public function render_editor_page_and_exit() {
// Suppress error display for this request to prevent output corruption.
// phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.IniSet.display_errors_Disallowed, Squiz.PHP.DiscouragedFunctions.Discouraged -- Required to prevent output corruption in standalone editor page.
@ini_set( 'display_errors', '0' );

// Discard any buffered output (warnings, notices, etc.).
while ( ob_get_level() > 0 ) {
ob_end_clean();
Expand Down
11 changes: 2 additions & 9 deletions includes/class-exelearning-rest-api.php
Original file line number Diff line number Diff line change
Expand Up @@ -241,11 +241,6 @@ public function create_elp_file( $request ) { // phpcs:ignore Generic.CodeAnalys
);
}

// Use WordPress media handling.
require_once ABSPATH . 'wp-admin/includes/file.php';
require_once ABSPATH . 'wp-admin/includes/media.php';
require_once ABSPATH . 'wp-admin/includes/image.php';

// Sanitize filename and ensure the .elpx extension. The plugin only
// registers and edits .elpx files, so any other extension is normalized.
$filename = $this->ensure_elpx_extension( sanitize_file_name( $uploaded_file['name'] ) );
Expand All @@ -260,6 +255,7 @@ public function create_elp_file( $request ) { // phpcs:ignore Generic.CodeAnalys

// Handle the upload. Suspend the global upload filter so the file is not
// extracted twice (we reprocess it explicitly below).
require_once ABSPATH . 'wp-admin/includes/file.php'; // wp_handle_upload() is not loaded in REST requests.
ExeLearning_Elp_Upload_Handler::suspend_processing( true );
$upload = wp_handle_upload( $file, array( 'test_form' => false ) );
ExeLearning_Elp_Upload_Handler::suspend_processing( false );
Expand Down Expand Up @@ -391,10 +387,6 @@ private function save_elp_file_locked( $attachment_id, $uploaded_file, $old_file
*/
do_action( 'exelearning_before_elpx_save', $attachment_id, $old_file_path );

// Route the uploaded file through WordPress so the move (and MIME check)
// goes via the wp_handle_upload() wrapper that Plugin Check accepts.
require_once ABSPATH . 'wp-admin/includes/file.php';

// The plugin only edits .elpx; normalize the upload filename.
$upload_filename = $this->ensure_elpx_extension( sanitize_file_name( $uploaded_file['name'] ) );

Expand All @@ -408,6 +400,7 @@ private function save_elp_file_locked( $attachment_id, $uploaded_file, $old_file
);

// Suspend the global upload filter; we validate/extract the temp file ourselves.
require_once ABSPATH . 'wp-admin/includes/file.php'; // wp_handle_upload() is not loaded in REST requests.
ExeLearning_Elp_Upload_Handler::suspend_processing( true );
$upload = wp_handle_upload( $file_for_upload, array( 'test_form' => false ) );
ExeLearning_Elp_Upload_Handler::suspend_processing( false );
Expand Down
4 changes: 2 additions & 2 deletions tests/unit/EditorPageTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -154,9 +154,9 @@ public function test_the_editor_page_is_rendered_ahead_of_admin_init() {
$scheduled_at = has_action( 'admin_init', array( $editor, 'render_editor_page_and_exit' ) );

ob_end_clean();
error_reporting( $reporting ); // phpcs:ignore
ini_set( 'display_errors', $display_errors ); // phpcs:ignore

$this->assertSame( $reporting, error_reporting(), 'The site error_reporting level must be left untouched.' ); // phpcs:ignore
$this->assertSame( $display_errors, ini_get( 'display_errors' ), 'display_errors must be left untouched.' );
$this->assertSame( $level + 1, $level_after_boot, 'Output must be captured from the very start.' );
$this->assertSame( -999, $scheduled_at );
$this->assertSame( $level, ob_get_level() );
Expand Down
Loading