/
home
/
altere25
/
berryglowbeauty.com
/
wp-includes
/
/home/altere25/berryglowbeauty.com/wp-includes
mkdir
upload
Name
Size
Mode
Actions
blocks/
-
0755
rm
certificates/
-
0755
rm
css/
-
0755
rm
customize/
-
0755
rm
fonts/
-
0755
rm
ID3/
-
0755
rm
images/
-
0755
rm
IXR/
-
0755
rm
js/
-
0755
rm
pomo/
-
0755
rm
random_compat/
-
0755
rm
Requests/
-
0755
rm
rest-api/
-
0755
rm
SimplePie/
-
0755
rm
sodium_compat/
-
0755
rm
Text/
-
0755
rm
theme-compat/
-
0755
rm
widgets/
-
0755
rm
.htaccess
178
0644
edit
dl
rm
admin-bar.php
30952
0644
edit
dl
rm
atomlib.php
11840
0644
edit
dl
rm
author-template.php
16995
0644
edit
dl
rm
blocks.php
19242
0644
edit
dl
rm
bookmark-template.php
12497
0644
edit
dl
rm
bookmark.php
15014
0644
edit
dl
rm
cache.php
21874
0644
edit
dl
rm
canonical.php
29474
0644
edit
dl
rm
capabilities.php
34089
0644
edit
dl
rm
category-template.php
52638
0644
edit
dl
rm
category.php
12378
0644
edit
dl
rm
class-feed.php
544
0644
edit
dl
rm
class-http.php
38763
0644
edit
dl
rm
class-IXR.php
2573
0644
edit
dl
rm
class-json.php
43390
0644
edit
dl
rm
class-oembed.php
410
0644
edit
dl
rm
class-phpass.php
7317
0644
edit
dl
rm
class-phpmailer.php
148592
0644
edit
dl
rm
class-pop3.php
20919
0644
edit
dl
rm
class-requests.php
29798
0644
edit
dl
rm
class-simplepie.php
89264
0644
edit
dl
rm
class-smtp.php
40919
0644
edit
dl
rm
class-snoopy.php
37785
0644
edit
dl
rm
class-walker-category-dropdown.php
2127
0644
edit
dl
rm
class-walker-category.php
7874
0644
edit
dl
rm
class-walker-comment.php
13685
0644
edit
dl
rm
class-walker-nav-menu.php
8669
0644
edit
dl
rm
class-walker-page-dropdown.php
2299
0644
edit
dl
rm
class-walker-page.php
7033
0644
edit
dl
rm
class-wp-admin-bar.php
16951
0644
edit
dl
rm
class-wp-ajax-response.php
5235
0644
edit
dl
rm
class-wp-block-parser.php
15215
0644
edit
dl
rm
class-wp-block-styles-registry.php
4663
0644
edit
dl
rm
class-wp-block-type-registry.php
5091
0644
edit
dl
rm
class-wp-block-type.php
4815
0644
edit
dl
rm
class-wp-comment-query.php
44514
0644
edit
dl
rm
class-wp-comment.php
8961
0644
edit
dl
rm
class-wp-customize-control.php
25054
0644
edit
dl
rm
class-wp-customize-manager.php
203252
0644
edit
dl
rm
class-wp-customize-nav-menus.php
54963
0644
edit
dl
rm
class-wp-customize-panel.php
9596
0644
edit
dl
rm
class-wp-customize-section.php
10168
0644
edit
dl
rm
class-wp-customize-setting.php
28191
0644
edit
dl
rm
class-wp-customize-widgets.php
66978
0644
edit
dl
rm
class-wp-date-query.php
35276
0644
edit
dl
rm
class-wp-dependency.php
2501
0644
edit
dl
rm
class-wp-editor.php
68219
0644
edit
dl
rm
class-wp-embed.php
14746
0644
edit
dl
rm
class-wp-error.php
4923
0644
edit
dl
rm
class-wp-fatal-error-handler.php
7429
0644
edit
dl
rm
class-wp-feed-cache-transient.php
2560
0644
edit
dl
rm
class-wp-feed-cache.php
749
0644
edit
dl
rm
class-wp-hook.php
14294
0644
edit
dl
rm
class-wp-http-cookie.php
7146
0644
edit
dl
rm
class-wp-http-curl.php
12327
0644
edit
dl
rm
class-wp-http-encoding.php
6542
0644
edit
dl
rm
class-wp-http-ixr-client.php
3331
0644
edit
dl
rm
class-wp-http-proxy.php
6077
0644
edit
dl
rm
class-wp-http-requests-hooks.php
1949
0644
edit
dl
rm
class-wp-http-requests-response.php
4343
0644
edit
dl
rm
class-wp-http-response.php
2951
0644
edit
dl
rm
class-wp-http-streams.php
16070
0644
edit
dl
rm
class-wp-image-editor-gd.php
13886
0644
edit
dl
rm
class-wp-image-editor-imagick.php
28828
0644
edit
dl
rm
class-wp-image-editor.php
13911
0644
edit
dl
rm
class-wp-list-util.php
6407
0644
edit
dl
rm
class-wp-locale-switcher.php
5022
0644
edit
dl
rm
class-wp-locale.php
13893
0644
edit
dl
rm
class-wp-matchesmapregex.php
1804
0644
edit
dl
rm
class-wp-meta-query.php
27847
0644
edit
dl
rm
class-wp-metadata-lazyloader.php
5384
0644
edit
dl
rm
class-wp-network-query.php
18368
0644
edit
dl
rm
class-wp-network.php
12284
0644
edit
dl
rm
class-wp-oembed-controller.php
6027
0644
edit
dl
rm
class-wp-oembed.php
30174
0644
edit
dl
rm
class-wp-paused-extensions-storage.php
4933
0644
edit
dl
rm
class-wp-post-type.php
19527
0644
edit
dl
rm
class-wp-post.php
6441
0644
edit
dl
rm
class-wp-query.php
131083
0644
edit
dl
rm
class-wp-recovery-mode-cookie-service.php
6459
0644
edit
dl
rm
class-wp-recovery-mode-email-service.php
10122
0644
edit
dl
rm
class-wp-recovery-mode-key-service.php
4284
0644
edit
dl
rm
class-wp-recovery-mode-link-service.php
3370
0644
edit
dl
rm
class-wp-recovery-mode.php
11358
0644
edit
dl
rm
class-wp-rewrite.php
59893
0644
edit
dl
rm
class-wp-role.php
2661
0644
edit
dl
rm
class-wp-roles.php
8300
0644
edit
dl
rm
class-wp-session-tokens.php
7430
0644
edit
dl
rm
class-wp-simplepie-file.php
2326
0644
edit
dl
rm
class-wp-simplepie-sanitize-kses.php
1775
0644
edit
dl
rm
class-wp-site-query.php
28531
0644
edit
dl
rm
class-wp-site.php
7367
0644
edit
dl
rm
class-wp-tax-query.php
19440
0644
edit
dl
rm
class-wp-taxonomy.php
10688
0644
edit
dl
rm
class-wp-term-query.php
35423
0644
edit
dl
rm
class-wp-term.php
5265
0644
edit
dl
rm
class-wp-text-diff-renderer-inline.php
716
0644
edit
dl
rm
class-wp-text-diff-renderer-table.php
16796
0644
edit
dl
rm
class-wp-theme.php
50973
0644
edit
dl
rm
class-wp-user-meta-session-tokens.php
2990
0644
edit
dl
rm
class-wp-user-query.php
31298
0644
edit
dl
rm
class-wp-user-request.php
1996
0644
edit
dl
rm
class-wp-user.php
21766
0644
edit
dl
rm
class-wp-walker.php
12718
0644
edit
dl
rm
class-wp-widget-factory.php
2853
0644
edit
dl
rm
class-wp-widget.php
17842
0644
edit
dl
rm
class-wp-xmlrpc-server.php
210072
0644
edit
dl
rm
class-wp.php
24551
0644
edit
dl
rm
class.wp-dependencies.php
11524
0644
edit
dl
rm
class.wp-scripts.php
17756
0644
edit
dl
rm
class.wp-styles.php
10532
0644
edit
dl
rm
comment-template.php
91640
0644
edit
dl
rm
comment.php
117233
0644
edit
dl
rm
compat.php
12982
0644
edit
dl
rm
cron.php
32451
0644
edit
dl
rm
date.php
409
0644
edit
dl
rm
default-constants.php
10122
0644
edit
dl
rm
default-filters.php
25894
0644
edit
dl
rm
default-widgets.php
2180
0644
edit
dl
rm
deprecated.php
114644
0644
edit
dl
rm
embed-template.php
344
0644
edit
dl
rm
embed.php
47367
0644
edit
dl
rm
error-protection.php
3387
0644
edit
dl
rm
error_log
1764
0644
edit
dl
rm
feed-atom-comments.php
5405
0644
edit
dl
rm
feed-atom.php
3081
0644
edit
dl
rm
feed-rdf.php
2660
0644
edit
dl
rm
feed-rss.php
1190
0644
edit
dl
rm
feed-rss2-comments.php
4150
0644
edit
dl
rm
feed-rss2.php
3782
0644
edit
dl
rm
feed.php
22022
0644
edit
dl
rm
formatting.php
298428
0644
edit
dl
rm
functions.php
228155
0644
edit
dl
rm
functions.wp-scripts.php
12824
0644
edit
dl
rm
functions.wp-styles.php
8219
0644
edit
dl
rm
general-template.php
152465
0644
edit
dl
rm
http.php
24324
0644
edit
dl
rm
kses.php
58723
0644
edit
dl
rm
l10n.php
53102
0644
edit
dl
rm
link-template.php
143524
0644
edit
dl
rm
load.php
43291
0644
edit
dl
rm
locale.php
162
0644
edit
dl
rm
media-template.php
57710
0644
edit
dl
rm
media.php
149717
0644
edit
dl
rm
meta.php
47749
0644
edit
dl
rm
ms-blogs.php
24413
0644
edit
dl
rm
ms-default-constants.php
4785
0644
edit
dl
rm
ms-default-filters.php
6414
0644
edit
dl
rm
ms-deprecated.php
21344
0644
edit
dl
rm
ms-files.php
2649
0644
edit
dl
rm
ms-functions.php
87638
0644
edit
dl
rm
ms-load.php
19624
0644
edit
dl
rm
ms-network.php
3658
0644
edit
dl
rm
ms-settings.php
4134
0644
edit
dl
rm
ms-site.php
43073
0644
edit
dl
rm
nav-menu-template.php
22053
0644
edit
dl
rm
nav-menu.php
41317
0644
edit
dl
rm
option.php
70145
0644
edit
dl
rm
pluggable-deprecated.php
6262
0644
edit
dl
rm
pluggable.php
99833
0644
edit
dl
rm
plugin.php
32317
0644
edit
dl
rm
post-formats.php
7053
0644
edit
dl
rm
post-template.php
62915
0644
edit
dl
rm
post-thumbnail-template.php
8988
0644
edit
dl
rm
post.php
244611
0644
edit
dl
rm
query.php
32929
0644
edit
dl
rm
registration-functions.php
202
0644
edit
dl
rm
registration.php
202
0644
edit
dl
rm
rest-api.php
46630
0644
edit
dl
rm
revision.php
21686
0644
edit
dl
rm
rewrite.php
18030
0644
edit
dl
rm
rss-functions.php
214
0644
edit
dl
rm
rss.php
23208
0644
edit
dl
rm
script-loader.php
113551
0644
edit
dl
rm
session.php
264
0644
edit
dl
rm
shortcodes.php
21704
0644
edit
dl
rm
spl-autoload-compat.php
443
0644
edit
dl
rm
taxonomy.php
157961
0644
edit
dl
rm
template-loader.php
3190
0644
edit
dl
rm
template.php
21046
0644
edit
dl
rm
theme.php
104876
0644
edit
dl
rm
update.php
25573
0644
edit
dl
rm
user.php
124532
0644
edit
dl
rm
vars.php
5815
0644
edit
dl
rm
version.php
762
0644
edit
dl
rm
widgets.php
58750
0644
edit
dl
rm
wlwmanifest.xml
1045
0644
edit
dl
rm
wp-db.php
103829
0644
edit
dl
rm
wp-diff.php
662
0644
edit
dl
rm
Edit:
/home/altere25/berryglowbeauty.com/wp-includes/http.php
(24324B)
<?php /** * Core HTTP Request API * * Standardizes the HTTP requests for WordPress. Handles cookies, gzip encoding and decoding, chunk * decoding, if HTTP 1.1 and various other difficult HTTP protocol implementations. * * @package WordPress * @subpackage HTTP */ /** * Returns the initialized WP_Http Object * * @since 2.7.0 * @access private * * @staticvar WP_Http $http * * @return WP_Http HTTP Transport object. */ function _wp_http_get_object() { static $http = null; if ( is_null( $http ) ) { $http = new WP_Http(); } return $http; } /** * Retrieve the raw response from a safe HTTP request. * * This function is ideal when the HTTP request is being made to an arbitrary * URL. The URL is validated to avoid redirection and request forgery attacks. * * @since 3.6.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_safe_remote_request( $url, $args = array() ) { $args['reject_unsafe_urls'] = true; $http = _wp_http_get_object(); return $http->request( $url, $args ); } /** * Retrieve the raw response from a safe HTTP request using the GET method. * * This function is ideal when the HTTP request is being made to an arbitrary * URL. The URL is validated to avoid redirection and request forgery attacks. * * @since 3.6.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_safe_remote_get( $url, $args = array() ) { $args['reject_unsafe_urls'] = true; $http = _wp_http_get_object(); return $http->get( $url, $args ); } /** * Retrieve the raw response from a safe HTTP request using the POST method. * * This function is ideal when the HTTP request is being made to an arbitrary * URL. The URL is validated to avoid redirection and request forgery attacks. * * @since 3.6.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_safe_remote_post( $url, $args = array() ) { $args['reject_unsafe_urls'] = true; $http = _wp_http_get_object(); return $http->post( $url, $args ); } /** * Retrieve the raw response from a safe HTTP request using the HEAD method. * * This function is ideal when the HTTP request is being made to an arbitrary * URL. The URL is validated to avoid redirection and request forgery attacks. * * @since 3.6.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_safe_remote_head( $url, $args = array() ) { $args['reject_unsafe_urls'] = true; $http = _wp_http_get_object(); return $http->head( $url, $args ); } /** * Performs an HTTP request and returns its response. * * There are other API functions available which abstract away the HTTP method: * * - Default 'GET' for wp_remote_get() * - Default 'POST' for wp_remote_post() * - Default 'HEAD' for wp_remote_head() * * @since 2.7.0 * * @see WP_Http::request() For information on default arguments. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array { * The response array or a WP_Error on failure. * * @type string[] $headers Array of response headers keyed by their name. * @type string $body Response body. * @type array $response { * Data about the HTTP response. * * @type int|false $code HTTP response code. * @type string|false $message HTTP response message. * } * @type WP_HTTP_Cookie[] $cookies Array of response cookies. * @type WP_HTTP_Requests_Response|null $http_response Raw HTTP response object. * } */ function wp_remote_request( $url, $args = array() ) { $http = _wp_http_get_object(); return $http->request( $url, $args ); } /** * Performs an HTTP request using the GET method and returns its response. * * @since 2.7.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_remote_get( $url, $args = array() ) { $http = _wp_http_get_object(); return $http->get( $url, $args ); } /** * Performs an HTTP request using the POST method and returns its response. * * @since 2.7.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_remote_post( $url, $args = array() ) { $http = _wp_http_get_object(); return $http->post( $url, $args ); } /** * Performs an HTTP request using the HEAD method and returns its response. * * @since 2.7.0 * * @see wp_remote_request() For more information on the response array format. * @see WP_Http::request() For default arguments information. * * @param string $url URL to retrieve. * @param array $args Optional. Request arguments. Default empty array. * @return WP_Error|array The response or WP_Error on failure. */ function wp_remote_head( $url, $args = array() ) { $http = _wp_http_get_object(); return $http->head( $url, $args ); } /** * Retrieve only the headers from the raw response. * * @since 2.7.0 * @since 4.6.0 Return value changed from an array to an Requests_Utility_CaseInsensitiveDictionary instance. * * @see \Requests_Utility_CaseInsensitiveDictionary * * @param array|WP_Error $response HTTP response. * @return array|\Requests_Utility_CaseInsensitiveDictionary The headers of the response. Empty array if incorrect parameter given. */ function wp_remote_retrieve_headers( $response ) { if ( is_wp_error( $response ) || ! isset( $response['headers'] ) ) { return array(); } return $response['headers']; } /** * Retrieve a single header by name from the raw response. * * @since 2.7.0 * * @param array|WP_Error $response HTTP response. * @param string $header Header name to retrieve value from. * @return string The header value. Empty string on if incorrect parameter given, or if the header doesn't exist. */ function wp_remote_retrieve_header( $response, $header ) { if ( is_wp_error( $response ) || ! isset( $response['headers'] ) ) { return ''; } if ( isset( $response['headers'][ $header ] ) ) { return $response['headers'][ $header ]; } return ''; } /** * Retrieve only the response code from the raw response. * * Will return an empty array if incorrect parameter value is given. * * @since 2.7.0 * * @param array|WP_Error $response HTTP response. * @return int|string The response code as an integer. Empty string on incorrect parameter given. */ function wp_remote_retrieve_response_code( $response ) { if ( is_wp_error( $response ) || ! isset( $response['response'] ) || ! is_array( $response['response'] ) ) { return ''; } return $response['response']['code']; } /** * Retrieve only the response message from the raw response. * * Will return an empty array if incorrect parameter value is given. * * @since 2.7.0 * * @param array|WP_Error $response HTTP response. * @return string The response message. Empty string on incorrect parameter given. */ function wp_remote_retrieve_response_message( $response ) { if ( is_wp_error( $response ) || ! isset( $response['response'] ) || ! is_array( $response['response'] ) ) { return ''; } return $response['response']['message']; } /** * Retrieve only the body from the raw response. * * @since 2.7.0 * * @param array|WP_Error $response HTTP response. * @return string The body of the response. Empty string if no body or incorrect parameter given. */ function wp_remote_retrieve_body( $response ) { if ( is_wp_error( $response ) || ! isset( $response['body'] ) ) { return ''; } return $response['body']; } /** * Retrieve only the cookies from the raw response. * * @since 4.4.0 * * @param array|WP_Error $response HTTP response. * @return WP_Http_Cookie[] An array of `WP_Http_Cookie` objects from the response. Empty array if there are none, or the response is a WP_Error. */ function wp_remote_retrieve_cookies( $response ) { if ( is_wp_error( $response ) || empty( $response['cookies'] ) ) { return array(); } return $response['cookies']; } /** * Retrieve a single cookie by name from the raw response. * * @since 4.4.0 * * @param array|WP_Error $response HTTP response. * @param string $name The name of the cookie to retrieve. * @return WP_Http_Cookie|string The `WP_Http_Cookie` object. Empty string if the cookie isn't present in the response. */ function wp_remote_retrieve_cookie( $response, $name ) { $cookies = wp_remote_retrieve_cookies( $response ); if ( empty( $cookies ) ) { return ''; } foreach ( $cookies as $cookie ) { if ( $cookie->name === $name ) { return $cookie; } } return ''; } /** * Retrieve a single cookie's value by name from the raw response. * * @since 4.4.0 * * @param array|WP_Error $response HTTP response. * @param string $name The name of the cookie to retrieve. * @return string The value of the cookie. Empty string if the cookie isn't present in the response. */ function wp_remote_retrieve_cookie_value( $response, $name ) { $cookie = wp_remote_retrieve_cookie( $response, $name ); if ( ! is_a( $cookie, 'WP_Http_Cookie' ) ) { return ''; } return $cookie->value; } /** * Determines if there is an HTTP Transport that can process this request. * * @since 3.2.0 * * @param array $capabilities Array of capabilities to test or a wp_remote_request() $args array. * @param string $url Optional. If given, will check if the URL requires SSL and adds * that requirement to the capabilities array. * * @return bool */ function wp_http_supports( $capabilities = array(), $url = null ) { $http = _wp_http_get_object(); $capabilities = wp_parse_args( $capabilities ); $count = count( $capabilities ); // If we have a numeric $capabilities array, spoof a wp_remote_request() associative $args array if ( $count && count( array_filter( array_keys( $capabilities ), 'is_numeric' ) ) == $count ) { $capabilities = array_combine( array_values( $capabilities ), array_fill( 0, $count, true ) ); } if ( $url && ! isset( $capabilities['ssl'] ) ) { $scheme = parse_url( $url, PHP_URL_SCHEME ); if ( 'https' == $scheme || 'ssl' == $scheme ) { $capabilities['ssl'] = true; } } return (bool) $http->_get_first_available_transport( $capabilities ); } /** * Get the HTTP Origin of the current request. * * @since 3.4.0 * * @return string URL of the origin. Empty string if no origin. */ function get_http_origin() { $origin = ''; if ( ! empty( $_SERVER['HTTP_ORIGIN'] ) ) { $origin = $_SERVER['HTTP_ORIGIN']; } /** * Change the origin of an HTTP request. * * @since 3.4.0 * * @param string $origin The original origin for the request. */ return apply_filters( 'http_origin', $origin ); } /** * Retrieve list of allowed HTTP origins. * * @since 3.4.0 * * @return string[] Array of origin URLs. */ function get_allowed_http_origins() { $admin_origin = parse_url( admin_url() ); $home_origin = parse_url( home_url() ); // @todo preserve port? $allowed_origins = array_unique( array( 'http://' . $admin_origin['host'], 'https://' . $admin_origin['host'], 'http://' . $home_origin['host'], 'https://' . $home_origin['host'], ) ); /** * Change the origin types allowed for HTTP requests. * * @since 3.4.0 * * @param string[] $allowed_origins { * Array of default allowed HTTP origins. * * @type string $0 Non-secure URL for admin origin. * @type string $1 Secure URL for admin origin. * @type string $2 Non-secure URL for home origin. * @type string $3 Secure URL for home origin. * } */ return apply_filters( 'allowed_http_origins', $allowed_origins ); } /** * Determines if the HTTP origin is an authorized one. * * @since 3.4.0 * * @param null|string $origin Origin URL. If not provided, the value of get_http_origin() is used. * @return string Origin URL if allowed, empty string if not. */ function is_allowed_http_origin( $origin = null ) { $origin_arg = $origin; if ( null === $origin ) { $origin = get_http_origin(); } if ( $origin && ! in_array( $origin, get_allowed_http_origins() ) ) { $origin = ''; } /** * Change the allowed HTTP origin result. * * @since 3.4.0 * * @param string $origin Origin URL if allowed, empty string if not. * @param string $origin_arg Original origin string passed into is_allowed_http_origin function. */ return apply_filters( 'allowed_http_origin', $origin, $origin_arg ); } /** * Send Access-Control-Allow-Origin and related headers if the current request * is from an allowed origin. * * If the request is an OPTIONS request, the script exits with either access * control headers sent, or a 403 response if the origin is not allowed. For * other request methods, you will receive a return value. * * @since 3.4.0 * * @return string|false Returns the origin URL if headers are sent. Returns false * if headers are not sent. */ function send_origin_headers() { $origin = get_http_origin(); if ( is_allowed_http_origin( $origin ) ) { header( 'Access-Control-Allow-Origin: ' . $origin ); header( 'Access-Control-Allow-Credentials: true' ); if ( 'OPTIONS' === $_SERVER['REQUEST_METHOD'] ) { exit; } return $origin; } if ( 'OPTIONS' === $_SERVER['REQUEST_METHOD'] ) { status_header( 403 ); exit; } return false; } /** * Validate a URL for safe use in the HTTP API. * * @since 3.5.2 * * @param string $url Request URL. * @return false|string URL or false on failure. */ function wp_http_validate_url( $url ) { $original_url = $url; $url = wp_kses_bad_protocol( $url, array( 'http', 'https' ) ); if ( ! $url || strtolower( $url ) !== strtolower( $original_url ) ) { return false; } $parsed_url = @parse_url( $url ); if ( ! $parsed_url || empty( $parsed_url['host'] ) ) { return false; } if ( isset( $parsed_url['user'] ) || isset( $parsed_url['pass'] ) ) { return false; } if ( false !== strpbrk( $parsed_url['host'], ':#?[]' ) ) { return false; } $parsed_home = @parse_url( get_option( 'home' ) ); if ( isset( $parsed_home['host'] ) ) { $same_host = strtolower( $parsed_home['host'] ) === strtolower( $parsed_url['host'] ); } else { $same_host = false; } if ( ! $same_host ) { $host = trim( $parsed_url['host'], '.' ); if ( preg_match( '#^(([1-9]?\d|1\d\d|25[0-5]|2[0-4]\d)\.){3}([1-9]?\d|1\d\d|25[0-5]|2[0-4]\d)$#', $host ) ) { $ip = $host; } else { $ip = gethostbyname( $host ); if ( $ip === $host ) { // Error condition for gethostbyname() return false; } } if ( $ip ) { $parts = array_map( 'intval', explode( '.', $ip ) ); /* * These IP address ranges are not considered valid external hosts for HTTP requests. * * If the host resolves to an IP address in these ranges, the request will be rejected unless the 'http_request_host_is_external' filter allows it. * * References: * * - IPv4 Special-Purpose Address Space: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml * - IPv4 Multicast Address Assignments: https://www.rfc-editor.org/rfc/rfc5771.html */ if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] // 127.0.0.0/8 (loopback), 10.0.0.0/8 (private), 0.0.0.0/8 (this network). || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) // 172.16.0.0/12 (private). || ( 192 === $parts[0] && 168 === $parts[1] ) // 192.168.0.0/16 (private). || ( 192 === $parts[0] && 0 === $parts[1] && 0 === $parts[2] ) // 192.0.0.0/24 (IETF protocol assignments). || ( 192 === $parts[0] && 0 === $parts[1] && 2 === $parts[2] ) // 192.0.2.0/24 (TEST-NET-1). || ( 192 === $parts[0] && 88 === $parts[1] && 99 === $parts[2] ) // 192.88.99.0/24 (6to4 relay anycast). || ( 198 === $parts[0] && 51 === $parts[1] && 100 === $parts[2] ) // 198.51.100.0/24 (TEST-NET-2). || ( 203 === $parts[0] && 0 === $parts[1] && 113 === $parts[2] ) // 203.0.113.0/24 (TEST-NET-3). || ( 169 === $parts[0] && 254 === $parts[1] ) // 169.254.0.0/16 (link-local and cloud metadata). || ( 100 === $parts[0] && 64 <= $parts[1] && 127 >= $parts[1] ) // 100.64.0.0/10 (CGNAT). || ( 198 === $parts[0] && 18 <= $parts[1] && 19 >= $parts[1] ) // 198.18.0.0/15 (benchmarking). || ( 224 <= $parts[0] && 239 >= $parts[0] ) // 224.0.0.0/4 (multicast). || 240 <= $parts[0] // 240.0.0.0/4 (reserved, includes 255.255.255.255 broadcast). ) { // If host appears local, reject unless specifically allowed. /** * Check if HTTP request is external or not. * * Allows to change and allow external requests for the HTTP request. * * @since 3.6.0 * * @param bool $external Whether HTTP request is external or not. * @param string $host Host name of the requested URL. * @param string $url Requested URL. */ if ( ! apply_filters( 'http_request_host_is_external', false, $host, $url ) ) { return false; } } } } if ( empty( $parsed_url['port'] ) ) { return $url; } $port = $parsed_url['port']; if ( 80 === $port || 443 === $port || 8080 === $port ) { return $url; } if ( $parsed_home && $same_host && isset( $parsed_home['port'] ) && $parsed_home['port'] === $port ) { return $url; } return false; } /** * Whitelists allowed redirect hosts for safe HTTP requests as well. * * Attached to the {@see 'http_request_host_is_external'} filter. * * @since 3.6.0 * * @param bool $is_external * @param string $host * @return bool */ function allowed_http_request_hosts( $is_external, $host ) { if ( ! $is_external && wp_validate_redirect( 'http://' . $host ) ) { $is_external = true; } return $is_external; } /** * Whitelists any domain in a multisite installation for safe HTTP requests. * * Attached to the {@see 'http_request_host_is_external'} filter. * * @since 3.6.0 * * @global wpdb $wpdb WordPress database abstraction object. * @staticvar array $queried * * @param bool $is_external * @param string $host * @return bool */ function ms_allowed_http_request_hosts( $is_external, $host ) { global $wpdb; static $queried = array(); if ( $is_external ) { return $is_external; } if ( $host === get_network()->domain ) { return true; } if ( isset( $queried[ $host ] ) ) { return $queried[ $host ]; } $queried[ $host ] = (bool) $wpdb->get_var( $wpdb->prepare( "SELECT domain FROM $wpdb->blogs WHERE domain = %s LIMIT 1", $host ) ); return $queried[ $host ]; } /** * A wrapper for PHP's parse_url() function that handles consistency in the return * values across PHP versions. * * PHP 5.4.7 expanded parse_url()'s ability to handle non-absolute url's, including * schemeless and relative url's with :// in the path. This function works around * those limitations providing a standard output on PHP 5.2~5.4+. * * Secondly, across various PHP versions, schemeless URLs starting containing a ":" * in the query are being handled inconsistently. This function works around those * differences as well. * * Error suppression is used as prior to PHP 5.3.3, an E_WARNING would be generated * when URL parsing failed. * * @since 4.4.0 * @since 4.7.0 The `$component` parameter was added for parity with PHP's `parse_url()`. * * @link https://secure.php.net/manual/en/function.parse-url.php * * @param string $url The URL to parse. * @param int $component The specific component to retrieve. Use one of the PHP * predefined constants to specify which one. * Defaults to -1 (= return all parts as an array). * @return mixed False on parse failure; Array of URL components on success; * When a specific component has been requested: null if the component * doesn't exist in the given URL; a string or - in the case of * PHP_URL_PORT - integer when it does. See parse_url()'s return values. */ function wp_parse_url( $url, $component = -1 ) { $to_unset = array(); $url = strval( $url ); if ( '//' === substr( $url, 0, 2 ) ) { $to_unset[] = 'scheme'; $url = 'placeholder:' . $url; } elseif ( '/' === substr( $url, 0, 1 ) ) { $to_unset[] = 'scheme'; $to_unset[] = 'host'; $url = 'placeholder://placeholder' . $url; } $parts = @parse_url( $url ); if ( false === $parts ) { // Parsing failure. return $parts; } // Remove the placeholder values. foreach ( $to_unset as $key ) { unset( $parts[ $key ] ); } return _get_component_from_parsed_url_array( $parts, $component ); } /** * Retrieve a specific component from a parsed URL array. * * @internal * * @since 4.7.0 * @access private * * @link https://secure.php.net/manual/en/function.parse-url.php * * @param array|false $url_parts The parsed URL. Can be false if the URL failed to parse. * @param int $component The specific component to retrieve. Use one of the PHP * predefined constants to specify which one. * Defaults to -1 (= return all parts as an array). * @return mixed False on parse failure; Array of URL components on success; * When a specific component has been requested: null if the component * doesn't exist in the given URL; a string or - in the case of * PHP_URL_PORT - integer when it does. See parse_url()'s return values. */ function _get_component_from_parsed_url_array( $url_parts, $component = -1 ) { if ( -1 === $component ) { return $url_parts; } $key = _wp_translate_php_url_constant_to_key( $component ); if ( false !== $key && is_array( $url_parts ) && isset( $url_parts[ $key ] ) ) { return $url_parts[ $key ]; } else { return null; } } /** * Translate a PHP_URL_* constant to the named array keys PHP uses. * * @internal * * @since 4.7.0 * @access private * * @link https://secure.php.net/manual/en/url.constants.php * * @param int $constant PHP_URL_* constant. * @return string|false The named key or false. */ function _wp_translate_php_url_constant_to_key( $constant ) { $translation = array( PHP_URL_SCHEME => 'scheme', PHP_URL_HOST => 'host', PHP_URL_PORT => 'port', PHP_URL_USER => 'user', PHP_URL_PASS => 'pass', PHP_URL_PATH => 'path', PHP_URL_QUERY => 'query', PHP_URL_FRAGMENT => 'fragment', ); if ( isset( $translation[ $constant ] ) ) { return $translation[ $constant ]; } else { return false; } }
Save
cmd:
run