PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/pages/guidelines/page.php +67 -27 23.1.0 → trunk View file →
@@ -87,11 +87,12 @@
87 87 * Automatically called during page rendering.
88 88 */
89 89 function gutenberg_guidelines_preload_data() {
90 90 // Define paths to preload - same for all pages
91 - // Please also change packages/core-data/src/entities.js when changing this.
91 + // This must exactly match the _fields list in packages/core-data/src/entities.js,
92 + // same fields in the same order, or the preload is never consumed.
92 93 $preload_paths = array(
93 - '/?_fields=description,gmt_offset,home,image_sizes,image_size_threshold,name,site_icon,site_icon_url,site_logo,timezone_string,url,page_for_posts,page_on_front,show_on_front',
94 + '/?_fields=description,gmt_offset,home,image_max_bit_depth,image_sizes,image_size_threshold,image_strip_meta,name,site_icon,site_icon_url,site_logo,timezone_string,url,page_for_posts,page_on_front,show_on_front',
94 95 array( '/wp/v2/settings', 'OPTIONS' ),
95 96 );
96 97
97 98 // Use rest_preload_api_request to gather the preloaded data
@@ -133,9 +134,11 @@
133 134 foreach ( wp_styles()->queue as $style ) {
134 135 wp_dequeue_style( $style );
135 136 }
136 137
137 - // Fire init action for extensions to register routes and menu items
138 + /**
139 + * Fires when the guidelines page is initialized so extensions can register routes and menu items.
140 + */
138 141 do_action( 'guidelines_init' );
139 142
140 143 // Enqueue command palette assets for boot-based pages
141 144 if ( function_exists( 'wp_enqueue_command_palette_assets' ) ) {
@@ -148,10 +151,14 @@
148 151 // Get all registered routes and menu items
149 152 $menu_items = gutenberg_get_guidelines_menu_items();
150 153 $routes = gutenberg_get_guidelines_routes();
151 154
152 - // Get boot module asset file for dependencies
155 + // Get boot module asset file for dependencies. Plugins that build their own
156 + // boot module use it; everyone else falls back to the copy bundled with Core.
153 157 $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php';
158 + if ( ! file_exists( $asset_file ) ) {
159 + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php';
160 + }
154 161 if ( file_exists( $asset_file ) ) {
155 162 $asset = require $asset_file;
156 163
157 164 // This script serves two purposes:
@@ -208,8 +215,23 @@
208 215 );
209 216 }
210 217 }
211 218
219 + /**
220 + * Filters the boot script-module dependencies for the
221 + * guidelines page.
222 + *
223 + * Surfaces extending this page can append entries to the boot
224 + * dependency list. Each entry is an array with 'import' (string
225 + * 'static' or 'dynamic') and 'id' (script-module handle) keys.
226 + *
227 + * @param array $boot_dependencies Boot dependencies for the page.
228 + */
229 + $boot_dependencies = apply_filters(
230 + 'guidelines_boot_dependencies',
231 + $boot_dependencies
232 + );
233 +
212 234 // Dummy script module to ensure dependencies are loaded
213 235 wp_register_script_module(
214 236 'guidelines',
215 237 $build_constants['build_url'] . 'pages/guidelines/loader.js',
@@ -233,9 +255,9 @@
233 255 <style>
234 256 html {
235 257 background: #f1f1f1;
236 258 color: #444;
237 - font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen-Sans, Ubuntu, Cantarell, "Helvetica Neue", sans-serif;
259 + font-family: -apple-system, system-ui, "Segoe UI", Roboto, Oxygen-Sans, Ubuntu, Cantarell, "Helvetica Neue", sans-serif;
238 260 font-size: 13px;
239 261 line-height: 1.4em;
240 262 }
241 263 body {
@@ -251,35 +273,41 @@
251 273 // BEGIN see wp-admin/admin-header.php
252 274 print_admin_styles();
253 275 print_head_scripts();
254 276
255 - /**
256 - * Fires in head section for a specific admin page.
257 - *
258 - * @since 2.1.0
259 - */
277 + /** This action is documented in wp-admin/admin-header.php */
260 278 do_action( "admin_head-{$hook_suffix}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores
261 279
262 - /**
263 - * Fires in head section for all admin pages.
264 - *
265 - * @since 2.1.0
266 - */
280 + /** This action is documented in wp-admin/admin-header.php */
267 281 do_action( 'admin_head' );
268 282 // END see wp-admin/admin-header.php
269 283 ?>
270 284 </head>
271 - <body class="guidelines">
285 + <body class="guidelines no-js">
286 + <?php
287 + // BEGIN see wp-admin/admin-header.php
288 + ?>
289 + <script type="text/javascript">
290 + document.body.className = document.body.className.replace( 'no-js', 'js' );
291 + </script>
292 + <?php
293 + // END see wp-admin/admin-header.php
294 + ?>
295 + <div class="wrap hide-if-js" style="margin: 20px;">
296 + <h1 class="wp-heading-inline"><?php echo esc_html( get_admin_page_title() ); ?></h1>
297 + <?php
298 + wp_admin_notice(
299 + __( 'This screen requires JavaScript. Enable JavaScript in your browser settings and reload the page.' ),
300 + array( 'type' => 'error' )
301 + );
302 + ?>
303 + </div>
272 304 <div id="guidelines-app" style="height: 100vh; box-sizing: border-box;"></div>
273 305 <?php
274 306 // BEGIN see wp-admin/admin-footer.php
275 307
276 - /**
277 - * Prints scripts or data before the default footer scripts.
278 - *
279 - * @since 1.2.0
280 - */
281 - do_action( 'admin_footer', '' );
308 + /** This action is documented in wp-admin/admin-footer.php */
309 + do_action( 'admin_footer', $hook_suffix );
282 310
283 311 // Print import map first so it's available for inline scripts
284 312 wp_script_modules()->print_import_map();
285 313 print_footer_scripts();
@@ -286,13 +314,9 @@
286 314 wp_script_modules()->print_enqueued_script_modules();
287 315 wp_script_modules()->print_script_module_preloads();
288 316 wp_script_modules()->print_script_module_data();
289 317
290 - /**
291 - * Prints scripts or data after the default footer scripts.
292 - *
293 - * @since 2.8.0
294 - */
318 + /** This action is documented in wp-admin/admin-footer.php */
295 319 do_action( "admin_footer-{$hook_suffix}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores
296 320 // END see wp-admin/admin-footer.php
297 321 ?>
298 322 </body>
@@ -307,8 +331,24 @@
307 331 */
308 332 function gutenberg_guidelines_intercept_render() {
309 333 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
310 334 if ( isset( $_GET['page'] ) && 'guidelines' === $_GET['page'] ) {
335 + // The page renders outside the menu page callback flow, so it must
336 + // enforce authentication and capability checks itself. Without this,
337 + // any admin entry point firing `admin_init` (such as admin-post.php,
338 + // which serves logged-out requests) would render the page for
339 + // unauthenticated visitors.
340 + if ( ! is_user_logged_in() ) {
341 + auth_redirect();
342 + }
343 +
344 + if ( ! current_user_can( 'manage_options' ) ) {
345 + wp_die(
346 + __( 'Sorry, you are not allowed to access this page.' ),
347 + 403
348 + );
349 + }
350 +
311 351 gutenberg_guidelines_render_page();
312 352 exit;
313 353 }
314 354 }