PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.14.2
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.14.2
2.14.2 2.14.1 2.14.0 2.13.0 2.12.0 2.11.0 2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 All 57 releases
← All changes | includes/api/class-seo-analytics-endpoint.php +46 -3 2.11.0 → 2.14.2 View file →
@@ -467,11 +467,11 @@
467 467 return [
468 468 'site_url' => [
469 469 'required' => true,
470 470 'type' => 'string',
471 - 'sanitize_callback' => 'esc_url_raw',
471 + 'sanitize_callback' => [$this, 'sanitize_site_url'],
472 472 'validate_callback' => [$this, 'validate_site_url'],
473 - 'description' => 'Site URL to verify in Search Console'
473 + 'description' => 'Search Console property: a URL-prefix property (https://example.com/) or a domain property (sc-domain:example.com)'
474 474 ]
475 475 ];
476 476 }
477 477
@@ -502,9 +502,26 @@
502 502 ['status' => 400]
503 503 );
504 504 }
505 505
506 - if (!filter_var($site_url, FILTER_VALIDATE_URL)) {
506 + // A domain property (sc-domain:example.com) is not a URL, and
507 + // is_valid() refused every one, though the rest of the Search Console
508 + // code reads them. Its host must be a real hostname; an IDN is fine.
509 + if (0 === stripos($site_url, 'sc-domain:')) {
510 + if (null === \ThinkRank\Core\Url_Validator::search_console_domain_property($site_url)) {
511 + return new WP_Error(
512 + 'invalid_site_url',
513 + 'A domain property must be sc-domain: followed by a domain name, such as sc-domain:example.com',
514 + ['status' => 400]
515 + );
516 + }
517 +
518 + return true;
519 + }
520 +
521 + // Url_Validator accepts an internationalised domain, which is a valid
522 + // site URL; the raw PHP filter refuses every non-ASCII byte.
523 + if (!\ThinkRank\Core\Url_Validator::is_valid($site_url)) {
507 524 return new WP_Error(
508 525 'invalid_site_url',
509 526 'Site URL must be a valid URL',
510 527 ['status' => 400]
@@ -511,8 +528,34 @@
511 528 );
512 529 }
513 530
514 531 return true;
532 + }
533 +
534 + /**
535 + * Sanitize the Search Console property sent to setup.
536 + *
537 + * esc_url_raw() for a URL-prefix property, as before. A domain property
538 + * is not a URL: esc_url_raw() drops "sc-domain:" as an unknown protocol
539 + * and returns "", so it is normalised to its punycode form instead, which
540 + * is what verify_site() matches against the account's property list.
541 + *
542 + * @since 2.14.2
543 + *
544 + * @param mixed $site_url Raw parameter, already through validate_site_url().
545 + * @return string
546 + */
547 + public function sanitize_site_url($site_url): string {
548 + if (!is_string($site_url)) {
549 + return '';
550 + }
551 +
552 + $domain = \ThinkRank\Core\Url_Validator::search_console_domain_property($site_url);
553 + if (null !== $domain) {
554 + return $domain;
555 + }
556 +
557 + return esc_url_raw($site_url);
515 558 }
516 559
517 560 /**
518 561 * Get Search Console totals for a custom date range