PluginProbe
Gutenberg / trunk
Gutenberg vtrunk
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/pages/experiments/page.php +40 -2 23.7.1 → trunk View file →
@@ -151,10 +151,14 @@
151 151 // Get all registered routes and menu items
152 152 $menu_items = gutenberg_get_experiments_menu_items();
153 153 $routes = gutenberg_get_experiments_routes();
154 154
155 - // Get boot module asset file for dependencies
155 + // Get boot module asset file for dependencies. Plugins that build their own
156 + // boot module use it; everyone else falls back to the copy bundled with Core.
156 157 $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php';
158 + if ( ! file_exists( $asset_file ) ) {
159 + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php';
160 + }
157 161 if ( file_exists( $asset_file ) ) {
158 162 $asset = require $asset_file;
159 163
160 164 // This script serves two purposes:
@@ -277,9 +281,27 @@
277 281 do_action( 'admin_head' );
278 282 // END see wp-admin/admin-header.php
279 283 ?>
280 284 </head>
281 - <body class="experiments">
285 + <body class="experiments no-js">
286 + <?php
287 + // BEGIN see wp-admin/admin-header.php
288 + ?>
289 + <script type="text/javascript">
290 + document.body.className = document.body.className.replace( 'no-js', 'js' );
291 + </script>
292 + <?php
293 + // END see wp-admin/admin-header.php
294 + ?>
295 + <div class="wrap hide-if-js" style="margin: 20px;">
296 + <h1 class="wp-heading-inline"><?php echo esc_html( get_admin_page_title() ); ?></h1>
297 + <?php
298 + wp_admin_notice(
299 + __( 'This screen requires JavaScript. Enable JavaScript in your browser settings and reload the page.' ),
300 + array( 'type' => 'error' )
301 + );
302 + ?>
303 + </div>
282 304 <div id="experiments-app" style="height: 100vh; box-sizing: border-box;"></div>
283 305 <?php
284 306 // BEGIN see wp-admin/admin-footer.php
285 307
@@ -309,8 +331,24 @@
309 331 */
310 332 function gutenberg_experiments_intercept_render() {
311 333 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
312 334 if ( isset( $_GET['page'] ) && 'experiments' === $_GET['page'] ) {
335 + // The page renders outside the menu page callback flow, so it must
336 + // enforce authentication and capability checks itself. Without this,
337 + // any admin entry point firing `admin_init` (such as admin-post.php,
338 + // which serves logged-out requests) would render the page for
339 + // unauthenticated visitors.
340 + if ( ! is_user_logged_in() ) {
341 + auth_redirect();
342 + }
343 +
344 + if ( ! current_user_can( 'manage_options' ) ) {
345 + wp_die(
346 + __( 'Sorry, you are not allowed to access this page.' ),
347 + 403
348 + );
349 + }
350 +
313 351 gutenberg_experiments_render_page();
314 352 exit;
315 353 }
316 354 }