PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/pages/experiments/page.php +43 -4 23.6.2 → trunk View file →
@@ -87,11 +87,12 @@
87 87 * Automatically called during page rendering.
88 88 */
89 89 function gutenberg_experiments_preload_data() {
90 90 // Define paths to preload - same for all pages
91 - // Please also change packages/core-data/src/entities.js when changing this.
91 + // This must exactly match the _fields list in packages/core-data/src/entities.js,
92 + // same fields in the same order, or the preload is never consumed.
92 93 $preload_paths = array(
93 - '/?_fields=description,gmt_offset,home,image_sizes,image_size_threshold,name,site_icon,site_icon_url,site_logo,timezone_string,url,page_for_posts,page_on_front,show_on_front',
94 + '/?_fields=description,gmt_offset,home,image_max_bit_depth,image_sizes,image_size_threshold,image_strip_meta,name,site_icon,site_icon_url,site_logo,timezone_string,url,page_for_posts,page_on_front,show_on_front',
94 95 array( '/wp/v2/settings', 'OPTIONS' ),
95 96 );
96 97
97 98 // Use rest_preload_api_request to gather the preloaded data
@@ -150,10 +151,14 @@
150 151 // Get all registered routes and menu items
151 152 $menu_items = gutenberg_get_experiments_menu_items();
152 153 $routes = gutenberg_get_experiments_routes();
153 154
154 - // Get boot module asset file for dependencies
155 + // Get boot module asset file for dependencies. Plugins that build their own
156 + // boot module use it; everyone else falls back to the copy bundled with Core.
155 157 $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php';
158 + if ( ! file_exists( $asset_file ) ) {
159 + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php';
160 + }
156 161 if ( file_exists( $asset_file ) ) {
157 162 $asset = require $asset_file;
158 163
159 164 // This script serves two purposes:
@@ -276,9 +281,27 @@
276 281 do_action( 'admin_head' );
277 282 // END see wp-admin/admin-header.php
278 283 ?>
279 284 </head>
280 - <body class="experiments">
285 + <body class="experiments no-js">
286 + <?php
287 + // BEGIN see wp-admin/admin-header.php
288 + ?>
289 + <script type="text/javascript">
290 + document.body.className = document.body.className.replace( 'no-js', 'js' );
291 + </script>
292 + <?php
293 + // END see wp-admin/admin-header.php
294 + ?>
295 + <div class="wrap hide-if-js" style="margin: 20px;">
296 + <h1 class="wp-heading-inline"><?php echo esc_html( get_admin_page_title() ); ?></h1>
297 + <?php
298 + wp_admin_notice(
299 + __( 'This screen requires JavaScript. Enable JavaScript in your browser settings and reload the page.' ),
300 + array( 'type' => 'error' )
301 + );
302 + ?>
303 + </div>
281 304 <div id="experiments-app" style="height: 100vh; box-sizing: border-box;"></div>
282 305 <?php
283 306 // BEGIN see wp-admin/admin-footer.php
284 307
@@ -308,8 +331,24 @@
308 331 */
309 332 function gutenberg_experiments_intercept_render() {
310 333 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
311 334 if ( isset( $_GET['page'] ) && 'experiments' === $_GET['page'] ) {
335 + // The page renders outside the menu page callback flow, so it must
336 + // enforce authentication and capability checks itself. Without this,
337 + // any admin entry point firing `admin_init` (such as admin-post.php,
338 + // which serves logged-out requests) would render the page for
339 + // unauthenticated visitors.
340 + if ( ! is_user_logged_in() ) {
341 + auth_redirect();
342 + }
343 +
344 + if ( ! current_user_can( 'manage_options' ) ) {
345 + wp_die(
346 + __( 'Sorry, you are not allowed to access this page.' ),
347 + 403
348 + );
349 + }
350 +
312 351 gutenberg_experiments_render_page();
313 352 exit;
314 353 }
315 354 }