PluginProbe
bbPress / 2.6.19
bbPress v2.6.19
2.6.19 2.6.18 2.6.17 trunk 2.0 2.0-beta-1 2.0-beta-2b 2.0-beta-3 2.0-beta-3b 2.0-rc-2 2.0-rc-3 2.0-rc-4 2.0-rc-5 2.0.1 2.0.2 2.0.3 2.1 2.1-beta-1 2.1-rc1 2.1-rc2 2.1-rc3 2.1-rc4 2.1.1 2.1.2 2.1.3 All 74 releases
← All changes | includes/replies/functions.php +69 -37 2.6.17 → 2.6.19 View file →
@@ -467,8 +467,11 @@
467 467 }
468 468
469 469 /** Update counts, etc... *********************************************/
470 470
471 + // Validate the parent now that the new reply has a topic
472 + $reply_to = bbp_validate_reply_to( $reply_to, $reply_id );
473 +
471 474 do_action( 'bbp_new_reply', $reply_id, $topic_id, $forum_id, $anonymous_data, $reply_data['post_author'], false, $reply_to );
472 475
473 476 /** Additional Actions (After Save) ***********************************/
474 477
@@ -505,8 +508,10 @@
505 508
506 509 /**
507 510 * Handles the front end edit reply submission
508 511 *
512 + * @since 2.6.19 bbPress (r7680) Enforce the edit lock on submissions.
513 + *
509 514 * @param string $action The requested action to compare this function to
510 515 * id, anonymous data, reply author, bool true (for edit),
511 516 * and the reply to id
512 517 */
@@ -551,8 +556,13 @@
551 556 } elseif ( ! current_user_can( 'edit_reply', $reply_id ) ) {
552 557 bbp_add_error( 'bbp_edit_reply_permission', __( '<strong>Error</strong>: You do not have permission to edit that reply.', 'bbpress' ) );
553 558 return;
554 559
560 + // Authors cannot bypass the edit lock by submitting from another page
561 + } elseif ( ( bbp_get_current_user_id() === (int) $reply->post_author ) && ! current_user_can( 'moderate', $reply_id ) && bbp_past_edit_lock( $reply->post_date_gmt ) ) {
562 + bbp_add_error( 'bbp_edit_reply_permission', __( '<strong>Error</strong>: You do not have permission to edit that reply.', 'bbpress' ) );
563 + return;
564 +
555 565 // It is an anonymous post
556 566 } elseif ( bbp_is_reply_anonymous( $reply_id ) ) {
557 567
558 568 // Filter anonymous data
@@ -908,9 +918,9 @@
908 918
909 919 /**
910 920 * Walk up the ancestor tree from the current reply, and update all the counts
911 921 *
912 - * @since 2.0.0 bbPress (r2884)
922 + * @since 2.0.0 bbPress (r2895)
913 923 *
914 924 * @param int $reply_id Optional. Reply id
915 925 * @param string $last_active_time Optional. Last active time
916 926 * @param int $forum_id Optional. Forum id
@@ -959,10 +969,10 @@
959 969
960 970 // Topic meta relating to most recent reply
961 971 } elseif ( bbp_is_topic( $ancestor ) ) {
962 972
963 - // Only update if reply is published
964 - if ( ! bbp_is_reply_pending( $reply_id ) ) {
973 + // Only update if reply is public
974 + if ( ( true === $refresh ) || bbp_is_reply_public( $reply_id ) ) {
965 975
966 976 // Last reply and active ID's
967 977 bbp_update_topic_last_reply_id ( $ancestor, $reply_id );
968 978 bbp_update_topic_last_active_id( $ancestor, $active_id );
@@ -985,10 +995,10 @@
985 995
986 996 // Forum meta relating to most recent topic
987 997 } elseif ( bbp_is_forum( $ancestor ) ) {
988 998
989 - // Only update if reply is published
990 - if ( ! bbp_is_reply_pending( $reply_id ) && ! bbp_is_topic_pending( $topic_id ) ) {
999 + // Only update if both reply and topic are public
1000 + if ( ( true === $refresh ) || ( bbp_is_reply_public( $reply_id ) && bbp_is_topic_public( $topic_id ) ) ) {
991 1001
992 1002 // Last topic and reply ID's
993 1003 bbp_update_forum_last_topic_id( $ancestor, $topic_id );
994 1004 bbp_update_forum_last_reply_id( $ancestor, $reply_id );
@@ -1019,9 +1029,9 @@
1019 1029
1020 1030 /**
1021 1031 * Update the reply with its forum id it is in
1022 1032 *
1023 - * @since 2.0.0 bbPress (r2855)
1033 + * @since 2.0.0 bbPress (r2858)
1024 1034 *
1025 1035 * @param int $reply_id Optional. Reply id to update
1026 1036 * @param int $forum_id Optional. Forum id
1027 1037 * @return bool The forum id of the reply
@@ -1062,9 +1072,9 @@
1062 1072
1063 1073 /**
1064 1074 * Update the reply with its topic id it is in
1065 1075 *
1066 - * @since 2.0.0 bbPress (r2855)
1076 + * @since 2.0.0 bbPress (r2858)
1067 1077 *
1068 1078 * @param int $reply_id Optional. Reply id to update
1069 1079 * @param int $topic_id Optional. Topic id
1070 1080 * @return bool The topic id of the reply
@@ -1165,8 +1175,9 @@
1165 1175 $id = $reply_to;
1166 1176 $ancestors = array( $reply_to );
1167 1177
1168 1178 // Get parent reply
1179 + // phpcs:ignore Generic.CodeAnalysis.AssignmentInCondition.FoundInWhileCondition -- Fetch each ancestor until none remains.
1169 1180 while ( $ancestor = bbp_get_reply( $id ) ) {
1170 1181
1171 1182 // Does parent have a parent?
1172 1183 $grampy_id = bbp_get_reply_to( $ancestor->ID );
@@ -1235,9 +1246,9 @@
1235 1246 * Move reply handler
1236 1247 *
1237 1248 * Handles the front end move reply submission
1238 1249 *
1239 - * @since 2.3.0 bbPress (r4521)
1250 + * @since 2.3.0 bbPress (r4522)
1240 1251 *
1241 1252 * @param string $action The requested action to compare this function to
1242 1253 */
1243 1254 function bbp_move_reply_handler( $action = '' ) {
@@ -1282,10 +1293,10 @@
1282 1293 bbp_add_error( 'bbp_move_reply_nonce', __( '<strong>Error</strong>: Are you sure you wanted to do that?', 'bbpress' ) );
1283 1294 return;
1284 1295 }
1285 1296
1286 - // Use cannot edit topic
1287 - if ( ! current_user_can( 'edit_topic', $source_topic->ID ) ) {
1297 + // User must moderate and edit the source topic
1298 + if ( ! current_user_can( 'moderate', $source_topic->ID ) || ! current_user_can( 'edit_topic', $source_topic->ID ) ) {
1288 1299 bbp_add_error( 'bbp_move_reply_source_permission', __( '<strong>Error</strong>: You do not have permission to edit the source topic.', 'bbpress' ) );
1289 1300 }
1290 1301
1291 1302 // How to move
@@ -1320,10 +1331,10 @@
1320 1331 if ( empty( $destination_topic ) ) {
1321 1332 bbp_add_error( 'bbp_move_reply_destination_not_found', __( '<strong>Error</strong>: The topic you want to move to was not found.', 'bbpress' ) );
1322 1333 }
1323 1334
1324 - // User cannot edit the destination topic
1325 - if ( ! current_user_can( 'edit_topic', $destination_topic->ID ) ) {
1335 + // User must moderate and edit the destination topic
1336 + if ( ! current_user_can( 'moderate', $destination_topic->ID ) || ! current_user_can( 'edit_topic', $destination_topic->ID ) ) {
1326 1337 bbp_add_error( 'bbp_move_reply_destination_permission', __( '<strong>Error</strong>: You do not have permission to edit the destination topic.', 'bbpress' ) );
1327 1338 }
1328 1339
1329 1340 // Bail before moving the reply if there are errors
@@ -1508,10 +1519,10 @@
1508 1519 *
1509 1520 * When a reply is moved, update the counts of source and destination topic
1510 1521 * and their forums.
1511 1522 *
1512 - * @since 2.3.0 bbPress (r4521)
1513 - * @since 2.6.17 Recount both forums and topic engagements.
1523 + * @since 2.3.0 bbPress (r4522)
1524 + * @since 2.6.17 bbPress (r7468) Recount both forums and topic engagements.
1514 1525 *
1515 1526 * @param int $move_reply_id Move reply id
1516 1527 * @param int $source_topic_id Source topic id
1517 1528 * @param int $destination_topic_id Destination topic id
@@ -1591,9 +1602,9 @@
1591 1602 return;
1592 1603 }
1593 1604
1594 1605 // What is the user doing here?
1595 - if ( ! current_user_can( 'edit_reply', $reply_id ) || ( 'bbp_toggle_reply_trash' === $action && ! current_user_can( 'delete_reply', $reply_id ) ) ) {
1606 + if ( ! current_user_can( 'edit_reply', $reply_id ) || ( 'bbp_toggle_reply_trash' === $action && ! current_user_can( 'delete_reply', $reply_id ) ) || ( 'bbp_toggle_reply_trash' !== $action && ! current_user_can( 'moderate', $reply_id ) ) ) {
1596 1607 bbp_add_error( 'bbp_toggle_reply_permission', __( '<strong>Error</strong>: You do not have permission to do that.', 'bbpress' ) );
1597 1608 return;
1598 1609 }
1599 1610
@@ -1761,9 +1772,9 @@
1761 1772
1762 1773 /**
1763 1774 * Return array of available reply toggle actions
1764 1775 *
1765 - * @since 2.6.0 bbPress (r6133)
1776 + * @since 2.6.0 bbPress (r6134)
1766 1777 *
1767 1778 * @param int $reply_id Optional. Reply id.
1768 1779 *
1769 1780 * @return array
@@ -1784,9 +1795,9 @@
1784 1795
1785 1796 /**
1786 1797 * Return array of public reply statuses.
1787 1798 *
1788 - * @since 2.6.0 bbPress (r6705)
1799 + * @since 2.6.0 bbPress (r6706)
1789 1800 *
1790 1801 * @return array
1791 1802 */
1792 1803 function bbp_get_public_reply_statuses() {
@@ -2043,9 +2054,9 @@
2043 2054
2044 2055 /**
2045 2056 * Called after deleting a reply
2046 2057 *
2047 - * @since 2.0.0 bbPress (r2993)
2058 + * @since 2.0.0 bbPress (r2895)
2048 2059 */
2049 2060 function bbp_deleted_reply( $reply_id = 0 ) {
2050 2061 $reply_id = bbp_get_reply_id( $reply_id );
2051 2062
@@ -2058,9 +2069,9 @@
2058 2069
2059 2070 /**
2060 2071 * Called after trashing a reply
2061 2072 *
2062 - * @since 2.0.0 bbPress (r2993)
2073 + * @since 2.0.0 bbPress (r2895)
2063 2074 */
2064 2075 function bbp_trashed_reply( $reply_id = 0 ) {
2065 2076 $reply_id = bbp_get_reply_id( $reply_id );
2066 2077
@@ -2073,9 +2084,9 @@
2073 2084
2074 2085 /**
2075 2086 * Called after untrashing (restoring) a reply
2076 2087 *
2077 - * @since 2.0.0 bbPress (r2993)
2088 + * @since 2.0.0 bbPress (r2895)
2078 2089 */
2079 2090 function bbp_untrashed_reply( $reply_id = 0 ) {
2080 2091 $reply_id = bbp_get_reply_id( $reply_id );
2081 2092
@@ -2090,9 +2101,9 @@
2090 2101
2091 2102 /**
2092 2103 * Return the replies per page setting
2093 2104 *
2094 - * @since 2.0.0 bbPress (r3540)
2105 + * @since 2.1.0 bbPress (r3572)
2095 2106 *
2096 2107 * @param int $default Default replies per page (15)
2097 2108 * @return int
2098 2109 */
@@ -2112,9 +2123,9 @@
2112 2123
2113 2124 /**
2114 2125 * Return the replies per RSS page setting
2115 2126 *
2116 - * @since 2.0.0 bbPress (r3540)
2127 + * @since 2.1.0 bbPress (r3572)
2117 2128 *
2118 2129 * @param int $default Default replies per page (25)
2119 2130 * @return int
2120 2131 */
@@ -2136,9 +2147,9 @@
2136 2147
2137 2148 /**
2138 2149 * Check if autoembeds are enabled and hook them in if so
2139 2150 *
2140 - * @since 2.1.0 bbPress (r3752)
2151 + * @since 2.1.0 bbPress (r3753)
2141 2152 *
2142 2153 * @global WP_Embed $wp_embed
2143 2154 */
2144 2155 function bbp_reply_content_autoembed() {
@@ -2156,9 +2167,9 @@
2156 2167 *
2157 2168 * This function filters the 'post_where' of the WP_Query, and changes the query
2158 2169 * to include both the topic AND its children in the same loop.
2159 2170 *
2160 - * @since 2.1.0 bbPress (r4058)
2171 + * @since 2.1.0 bbPress (r4059)
2161 2172 *
2162 2173 * @param string $where
2163 2174 * @param WP_Query $query
2164 2175 * @return string
@@ -2239,9 +2250,16 @@
2239 2250 // User cannot access forum this topic is in
2240 2251 if ( bbp_is_single_topic() && ! bbp_user_can_view_forum( array( 'forum_id' => bbp_get_topic_forum_id() ) ) ) {
2241 2252 return;
2242 2253 }
2254 + if ( bbp_is_single_topic() && ! bbp_is_topic_public() && ! current_user_can( 'read_topic', bbp_get_topic_id() ) ) {
2255 + return;
2256 + }
2243 2257
2258 + // Keep replies from non-public topics out of public feeds.
2259 + $replies_query['_bbp_public_topic_replies'] = true;
2260 + unset( $replies_query['_bbp_search_private_topic_replies'] );
2261 +
2244 2262 // Adjust the title based on context
2245 2263 if ( bbp_is_single_topic() ) {
2246 2264 $title = get_wp_title_rss();
2247 2265 } elseif ( ! bbp_show_lead_topic() ) {
@@ -2283,9 +2301,9 @@
2283 2301 <?php if ( bbp_show_lead_topic() ) : ?>
2284 2302
2285 2303 <item>
2286 2304 <guid><?php bbp_topic_permalink(); ?></guid>
2287 - <title><![CDATA[<?php bbp_topic_title(); ?>]]></title>
2305 + <title><?php echo apply_filters( 'the_title_rss', bbp_get_topic_title() ); ?></title>
2288 2306 <link><?php bbp_topic_permalink(); ?></link>
2289 2307 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_post_time( 'Y-m-d H:i:s', true ), false ); ?></pubDate>
2290 2308 <dc:creator><?php bbp_topic_author_display_name(); ?></dc:creator>
2291 2309
@@ -2295,9 +2313,9 @@
2295 2313 /* translators: %s: Number of replies */
2296 2314 __( 'Replies: %s', 'bbpress' ),
2297 2315 bbp_get_topic_reply_count()
2298 2316 ); ?></p>
2299 - <?php bbp_topic_content(); ?>
2317 + <?php echo bbp_escape_feed_cdata( bbp_get_topic_content() ); ?>
2300 2318 ]]>
2301 2319 </description>
2302 2320
2303 2321 <?php rss_enclosure(); ?>
@@ -2316,9 +2334,9 @@
2316 2334 bbp_the_reply(); ?>
2317 2335
2318 2336 <item>
2319 2337 <guid><?php bbp_reply_url(); ?></guid>
2320 - <title><![CDATA[<?php bbp_reply_title(); ?>]]></title>
2338 + <title><?php echo apply_filters( 'the_title_rss', bbp_get_reply_title() ); ?></title>
2321 2339 <link><?php bbp_reply_url(); ?></link>
2322 2340 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_post_time( 'Y-m-d H:i:s', true ), false ); ?></pubDate>
2323 2341 <dc:creator><?php bbp_reply_author_display_name(); ?></dc:creator>
2324 2342
@@ -2323,9 +2341,9 @@
2323 2341 <dc:creator><?php bbp_reply_author_display_name(); ?></dc:creator>
2324 2342
2325 2343 <description>
2326 2344 <![CDATA[
2327 - <?php bbp_reply_content(); ?>
2345 + <?php echo bbp_escape_feed_cdata( bbp_get_reply_content() ); ?>
2328 2346 ]]>
2329 2347 </description>
2330 2348
2331 2349 <?php rss_enclosure(); ?>
@@ -2352,9 +2370,9 @@
2352 2370
2353 2371 /**
2354 2372 * Redirect if unauthorized user is attempting to edit a reply
2355 2373 *
2356 - * @since 2.1.0 bbPress (r3605)
2374 + * @since 2.1.0 bbPress (r3607)
2357 2375 */
2358 2376 function bbp_check_reply_edit() {
2359 2377
2360 2378 // Bail if not editing a topic
@@ -2377,9 +2395,9 @@
2377 2395 * This is done to prevent using a meta_query to retrieve posts in the proper
2378 2396 * freshness order. By updating the menu_order accordingly, we're able to
2379 2397 * leverage core WordPress query ordering much more effectively.
2380 2398 *
2381 - * @since 2.1.0 bbPress (r3933)
2399 + * @since 2.1.0 bbPress (r3934)
2382 2400 *
2383 2401 * @param int $reply_id
2384 2402 * @param int $reply_position
2385 2403 *
@@ -2432,9 +2450,9 @@
2432 2450 /**
2433 2451 * Get the position of a reply by querying the DB directly for the replies
2434 2452 * of a given topic.
2435 2453 *
2436 - * @since 2.1.0 bbPress (r3933)
2454 + * @since 2.1.0 bbPress (r3934)
2437 2455 *
2438 2456 * @param int $reply_id
2439 2457 * @param int $topic_id
2440 2458 */
@@ -2459,12 +2477,17 @@
2459 2477 if ( ! empty( $topic_replies ) ) {
2460 2478
2461 2479 // Reverse replies array and search for current reply position
2462 2480 $topic_replies = array_reverse( $topic_replies );
2463 - $reply_position = array_search( (string) $reply_id, $topic_replies );
2481 + $reply_position = array_search( $reply_id, $topic_replies, true );
2464 2482
2465 - // Bump the position to compensate for the lead topic post
2466 - ++$reply_position;
2483 + // Bump the position to compensate for the lead topic post,
2484 + // or reset to 0 if the reply was not found in the children list.
2485 + if ( false !== $reply_position ) {
2486 + ++$reply_position;
2487 + } else {
2488 + $reply_position = 0;
2489 + }
2467 2490 }
2468 2491 }
2469 2492 }
2470 2493
@@ -2559,16 +2582,17 @@
2559 2582
2560 2583 /**
2561 2584 * Validate a `reply_to` field for hierarchical replies
2562 2585 *
2563 - * Checks for 2 scenarios:
2586 + * Checks for 3 scenarios:
2564 2587 * -- The reply to ID is actually a reply
2565 2588 * -- The reply to ID does not match the current reply
2589 + * -- The reply to ID belongs to the same topic as the current reply
2566 2590 *
2567 2591 * @see https://bbpress.trac.wordpress.org/ticket/2588
2568 2592 * @see https://bbpress.trac.wordpress.org/ticket/2586
2569 2593 *
2570 - * @since 2.5.4 bbPress (r5377)
2594 + * @since 2.6.0 bbPress (r5378)
2571 2595 *
2572 2596 * @param int $reply_to
2573 2597 * @param int $reply_id
2574 2598 *
@@ -2581,10 +2605,18 @@
2581 2605 $reply_to = 0;
2582 2606 }
2583 2607
2584 2608 // The parent reply cannot be itself
2585 - if ( $reply_id === $reply_to ) {
2609 + if ( (int) $reply_id === (int) $reply_to ) {
2586 2610 $reply_to = 0;
2611 + }
2612 +
2613 + // The parent reply must belong to the same topic
2614 + if ( ! empty( $reply_id ) && ! empty( $reply_to ) ) {
2615 + $topic_id = bbp_get_reply_topic_id( $reply_id );
2616 + if ( empty( $topic_id ) || ( bbp_get_reply_topic_id( $reply_to ) !== $topic_id ) ) {
2617 + $reply_to = 0;
2618 + }
2587 2619 }
2588 2620
2589 2621 return (int) $reply_to;
2590 2622 }