| @@ -98,8 +98,17 @@ | ||
| 98 | 98 | // Delay applies a transform that's mutually exclusive with |
| 99 | 99 | // plain defer — when both are on, delay wins (the bootstrap |
| 100 | 100 | // will re-attach as a regular <script> on interaction). |
| 101 | 101 | add_filter( 'script_loader_tag', array( Minify_Filters::class, 'delay_script_tag' ), 30, 3 ); |
| 102 | + // Smart Delay: a delayed handle's before/after snippets park with | |
| 103 | + // it, or the inline consumer would run at parse time against a | |
| 104 | + // global that now arrives on first interaction. This filter fires | |
| 105 | + // for every inline script WordPress prints, so it also covers | |
| 106 | + // pages the cache buffer never filters. | |
| 107 | + add_filter( 'wp_inline_script_attributes', array( Minify_Filters::class, 'park_smart_inline' ), 30, 2 ); | |
| 108 | + // A snippet never stays parked behind a live script. Runs after | |
| 109 | + // the late opt-out revert, which can un-delay the tag. | |
| 110 | + add_filter( 'script_loader_tag', array( Minify_Filters::class, 'unpark_orphaned_smart_inline' ), Minify_Filters::late_opt_out_priority() + 1, 3 ); | |
| 102 | 111 | add_action( 'wp_footer', array( Minify_Filters::class, 'print_delay_bootstrap' ), 1000 ); |
| 103 | 112 | // script_loader_tag only fires for wp_enqueue_script()'d assets. |
| 104 | 113 | // Analytics / pixel / chat-widget tags printed straight into |
| 105 | 114 | // wp_head bypass it, and those are usually the heaviest scripts |
| @@ -112,8 +121,27 @@ | ||
| 112 | 121 | // so the src sweep above never sees them; this one parks an |
| 113 | 122 | // inline body that names a known third-party host. |
| 114 | 123 | add_filter( 'xspeed_cache_final_html', array( Minify_Filters::class, 'delay_inline_snippets' ), 21 ); |
| 115 | 124 | } |
| 125 | + | |
| 126 | + // Everything above honors data-no-optimize / data-no-minify, but | |
| 127 | + // only sees markers stamped before priority 30. Borlabs Cookie | |
| 128 | + // stamps at 100, so its consent config was minified AND delayed | |
| 129 | + // despite carrying both markers. Snapshot the tag before our | |
| 130 | + // transforms (9) and hand the original back if a marker turns up | |
| 131 | + // after them (1000, past Borlabs' own 100 and 999). Registered | |
| 132 | + // whenever any of the three is on, | |
| 133 | + // since each one is individually enough to damage a marked | |
| 134 | + // script. (#469) | |
| 135 | + if ( ! empty( $opts['minify_js'] ) || ! empty( $opts['defer_js'] ) || ! empty( $opts['delay_js'] ) ) { | |
| 136 | + add_filter( 'script_loader_tag', array( Minify_Filters::class, 'snapshot_tag' ), 9, 3 ); | |
| 137 | + add_filter( | |
| 138 | + 'script_loader_tag', | |
| 139 | + array( Minify_Filters::class, 'revert_late_marked_tag' ), | |
| 140 | + Minify_Filters::late_opt_out_priority(), | |
| 141 | + 3 | |
| 142 | + ); | |
| 143 | + } | |
| 116 | 144 | if ( ! empty( $opts['async_css'] ) ) { |
| 117 | 145 | add_filter( 'style_loader_tag', array( Minify_Filters::class, 'async_style_tag' ), 20, 2 ); |
| 118 | 146 | // style_loader_tag only fires for wp_enqueue_style()'d sheets. |
| 119 | 147 | // Themes print Google/Bunny/Typekit font CSS as literal <link> |
| @@ -319,18 +347,37 @@ | ||
| 319 | 347 | if ( ! $path || ! is_readable( $path ) ) { |
| 320 | 348 | return $src; |
| 321 | 349 | } |
| 322 | 350 | |
| 323 | - // Build a cache filename keyed on path + mtime so edits invalidate. | |
| 324 | - $mtime = filemtime( $path ); | |
| 325 | - $key = md5( $path . '|' . $mtime ); | |
| 326 | - $cache = self::cache_path( $key, $type ); | |
| 351 | + // Nowhere to write means nothing to serve. Without this gate an | |
| 352 | + // unwritable min/ cost a full minification on EVERY render, each one | |
| 353 | + // thrown away when the write failed. | |
| 354 | + if ( ! self::min_dir_writable() ) { | |
| 355 | + return $src; | |
| 356 | + } | |
| 327 | 357 | |
| 328 | - if ( ! file_exists( $cache ) ) { | |
| 329 | - $ok = self::minify_file( $path, $cache, $type ); | |
| 330 | - if ( ! $ok ) { | |
| 331 | - return $src; | |
| 358 | + // The file is named after its minified CONTENT, found through a | |
| 359 | + // per-source manifest that is validated by stat() alone on the hot | |
| 360 | + // path. See Asset_Manifest for the rules. The old name was | |
| 361 | + // md5(path|mtime): an in-place edit that kept the mtime served new | |
| 362 | + // bytes under a URL cached for a year, an @import child's edit | |
| 363 | + // changed nothing, and a touch with no change orphaned every cached | |
| 364 | + // page that linked the old name. | |
| 365 | + $key = Asset_Manifest::key_for( | |
| 366 | + $type, | |
| 367 | + $path, | |
| 368 | + static function ( string $source ) use ( $type ): array { | |
| 369 | + return 'css' === $type ? Asset_Manifest::css_dependencies( $source ) : array(); | |
| 370 | + }, | |
| 371 | + static function ( string $source ) use ( $type ) { | |
| 372 | + return self::build( $source, $type ); | |
| 373 | + }, | |
| 374 | + static function ( string $key ) use ( $type ): bool { | |
| 375 | + return file_exists( self::cache_path( $key, $type ) ); | |
| 332 | 376 | } |
| 377 | + ); | |
| 378 | + if ( null === $key ) { | |
| 379 | + return $src; | |
| 333 | 380 | } |
| 334 | 381 | |
| 335 | 382 | // Return a URL to the cached file. Built from known constants — never |
| 336 | 383 | // from str_replace on a filesystem path (which would assume the FS |
| @@ -337,53 +384,110 @@ | ||
| 337 | 384 | // layout mirrors the URL layout). |
| 338 | 385 | return self::min_url() . '/' . $key . '.' . $type; |
| 339 | 386 | } |
| 340 | 387 | |
| 341 | - private static function minify_file( $source_path, $target_path, $type ) { | |
| 342 | - if ( ! class_exists( '\\MatthiasMullie\\Minify\\CSS' ) ) { | |
| 343 | - return false; | |
| 388 | + /** | |
| 389 | + * Whether min/ can be written, asked once per request. | |
| 390 | + * | |
| 391 | + * @var bool|null | |
| 392 | + */ | |
| 393 | + private static $writable = null; | |
| 394 | + | |
| 395 | + /** | |
| 396 | + * Minifications run by this process. | |
| 397 | + * | |
| 398 | + * @var int | |
| 399 | + */ | |
| 400 | + private static $builds = 0; | |
| 401 | + | |
| 402 | + /** Forget the per-request answers. Tests only. */ | |
| 403 | + public static function reset_request_state(): void { | |
| 404 | + self::$writable = null; | |
| 405 | + self::$builds = 0; | |
| 406 | + } | |
| 407 | + | |
| 408 | + /** How many sources this process has minified. Tests and diagnostics. */ | |
| 409 | + public static function builds(): int { | |
| 410 | + return self::$builds; | |
| 411 | + } | |
| 412 | + | |
| 413 | + /** Can minified files be written this request? */ | |
| 414 | + public static function min_dir_writable(): bool { | |
| 415 | + if ( null === self::$writable ) { | |
| 416 | + $dir = self::min_dir(); | |
| 417 | + self::ensure_dir( $dir ); | |
| 418 | + self::$writable = is_dir( $dir ) && wp_is_writable( $dir ); | |
| 344 | 419 | } |
| 420 | + return self::$writable; | |
| 421 | + } | |
| 345 | 422 | |
| 346 | - // Path-traversal guard: refuse to write anywhere outside our cache | |
| 347 | - // dir, even if a malicious filter ever produced a poisoned key. | |
| 348 | - $cache_root = self::min_dir(); | |
| 349 | - self::ensure_dir( $cache_root ); | |
| 350 | - $real_root = realpath( $cache_root ); | |
| 351 | - $real_dir = realpath( dirname( $target_path ) ); | |
| 352 | - if ( ! $real_root || ! $real_dir || 0 !== strpos( $real_dir, $real_root ) ) { | |
| 353 | - return false; | |
| 423 | + /** | |
| 424 | + * Minify a source into min/<md5 of output>.<type> and return the key. | |
| 425 | + * | |
| 426 | + * The output is built in memory and published with an atomic rename, so a | |
| 427 | + * concurrent render never links a half-written file. When a file with the | |
| 428 | + * same content already exists nothing is written: same bytes, same name. | |
| 429 | + * | |
| 430 | + * @param string $source Absolute source path. | |
| 431 | + * @param string $type 'css' or 'js'. | |
| 432 | + * @return string|null|false Key; null when the source cannot be minified; | |
| 433 | + * false when the output could not be written. | |
| 434 | + */ | |
| 435 | + private static function build( string $source, string $type ) { | |
| 436 | + ++self::$builds; | |
| 437 | + $minified = self::minify_to_string( $source, $type ); | |
| 438 | + if ( null === $minified ) { | |
| 439 | + return null; | |
| 354 | 440 | } |
| 441 | + $key = md5( $minified ); | |
| 442 | + $target = self::cache_path( $key, $type ); | |
| 443 | + if ( file_exists( $target ) ) { | |
| 444 | + return $key; | |
| 445 | + } | |
| 446 | + return Asset_Manifest::write_atomic( $target, $minified ) ? $key : false; | |
| 447 | + } | |
| 355 | 448 | |
| 449 | + /** | |
| 450 | + * Minified bytes of a source, or null on failure. | |
| 451 | + * | |
| 452 | + * @param string $source_path Absolute source path. | |
| 453 | + * @param string $type 'css' or 'js'. | |
| 454 | + */ | |
| 455 | + private static function minify_to_string( string $source_path, string $type ): ?string { | |
| 456 | + if ( ! class_exists( '\\MatthiasMullie\\Minify\\CSS' ) ) { | |
| 457 | + return null; | |
| 458 | + } | |
| 459 | + | |
| 356 | 460 | try { |
| 357 | 461 | if ( 'css' === $type ) { |
| 358 | - // Passing the TARGET path makes matthiasmullie/minify rebase every | |
| 359 | - // relative url(...) / @import against the minified file's location. | |
| 360 | - // Without it, a stylesheet moved from e.g. | |
| 361 | - // .../font-awesome/css/all.css to cache/xspeed/min/<key>.css keeps | |
| 362 | - // its original url(../webfonts/…) — which then resolves against the | |
| 363 | - // cache dir and 404s (missing FontAwesome/eicons/WooCommerce fonts). | |
| 462 | + // execute() with a path inside min/ rebases every relative | |
| 463 | + // url(...) / @import against the minified file's location, | |
| 464 | + // which is what minify( $target ) did before without writing. | |
| 465 | + // Every output lives in the same directory, so any name there | |
| 466 | + // rebases identically. Without the rebase a stylesheet moved | |
| 467 | + // from e.g. .../font-awesome/css/all.css to | |
| 468 | + // cache/xspeed/min/<key>.css keeps its original | |
| 469 | + // url(../webfonts/…), which then resolves against the cache | |
| 470 | + // dir and 404s (missing FontAwesome/eicons/WooCommerce fonts). | |
| 364 | 471 | $minifier = new \MatthiasMullie\Minify\CSS( $source_path ); |
| 365 | - $minified = $minifier->minify( $target_path ); | |
| 366 | - return '' !== $minified && file_exists( $target_path ); | |
| 472 | + $minified = (string) $minifier->execute( self::min_dir() . '/rebase.css' ); | |
| 473 | + return '' !== $minified ? $minified : null; | |
| 367 | 474 | } |
| 368 | 475 | |
| 369 | 476 | $minifier = new \MatthiasMullie\Minify\JS( $source_path ); |
| 370 | - $minified = $minifier->minify(); | |
| 477 | + $minified = (string) $minifier->minify(); | |
| 371 | 478 | |
| 372 | 479 | // Sanity check: paren/brace/bracket/backtick balance must be preserved. |
| 373 | 480 | // matthiasmullie/minify can silently truncate mid-template-literal on |
| 374 | 481 | // complex modern JS — bail rather than ship a broken file. |
| 375 | - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders. Source already validated as readable on line 121. | |
| 482 | + // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders. Source already validated as readable by the caller. | |
| 376 | 483 | $source = file_get_contents( $source_path ); |
| 377 | - if ( false === $source || ! self::balanced( $source, $minified ) ) { | |
| 378 | - return false; | |
| 484 | + if ( false === $source || '' === $minified || ! self::balanced( $source, $minified ) ) { | |
| 485 | + return null; | |
| 379 | 486 | } |
| 380 | - | |
| 381 | - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_put_contents_file_put_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders. | |
| 382 | - $bytes = file_put_contents( $target_path, $minified ); | |
| 383 | - return false !== $bytes && file_exists( $target_path ); | |
| 487 | + return $minified; | |
| 384 | 488 | } catch ( \Throwable $e ) { |
| 385 | - return false; | |
| 489 | + return null; | |
| 386 | 490 | } |
| 387 | 491 | } |
| 388 | 492 | |
| 389 | 493 | /** |
| @@ -413,9 +517,9 @@ | ||
| 413 | 517 | * data; minifying a template would eat the markup it holds. An unknown |
| 414 | 518 | * type is treated as non-JS on purpose: guessing wrong breaks the page, |
| 415 | 519 | * while skipping only forgoes a few bytes. |
| 416 | 520 | * - `<script src="...">` — the body is empty; the file path already goes |
| 417 | - * through minify_file(). | |
| 521 | + * through rewrite_asset(). | |
| 418 | 522 | * |
| 419 | 523 | * Every result is checked with balanced(), the same structural guard the |
| 420 | 524 | * file path uses, so a body the library truncates is shipped as-is rather |
| 421 | 525 | * than broken. (#2) |
| @@ -672,15 +776,72 @@ | ||
| 672 | 776 | } |
| 673 | 777 | } |
| 674 | 778 | |
| 675 | 779 | /** |
| 676 | - * Clear every minified / combined asset. | |
| 780 | + * Delete every minified and combined asset, network-wide. | |
| 677 | 781 | * |
| 782 | + * Output files are named by content, so an ordinary purge has no reason | |
| 783 | + * to delete them: a page rendered after it links the same names. Only a | |
| 784 | + * network purge, an update, an explicit assets purge and deactivation | |
| 785 | + * come here. Deleting is still a race against renders in flight, which | |
| 786 | + * may already hold the names of files about to vanish; the purge stamp | |
| 787 | + * bumped here lets the page cache refuse to store those renders. | |
| 788 | + * | |
| 678 | 789 | * @return int Files removed. Most callers are `add_action` callbacks and |
| 679 | 790 | * ignore it; `wp xspeed purge` reports it as a line item. |
| 680 | 791 | */ |
| 681 | 792 | public static function purge_minified() { |
| 682 | - return self::rmtree_files( self::min_dir() ); | |
| 793 | + $removed = self::rmtree_files( self::min_dir() ); | |
| 794 | + if ( $removed > 0 ) { | |
| 795 | + self::bump_purge_stamp(); | |
| 796 | + } | |
| 797 | + return $removed; | |
| 798 | + } | |
| 799 | + | |
| 800 | + /** | |
| 801 | + * Delete one blog's manifests, leaving every output file in place. | |
| 802 | + * | |
| 803 | + * What a subsite's assets purge can safely do on a network whose blogs | |
| 804 | + * share min/: the next render of each source re-reads its bytes and | |
| 805 | + * rebuilds only if they changed, and no other blog's cached page loses a | |
| 806 | + * file it links. Outputs nothing links any more are left to Cache_GC. | |
| 807 | + * | |
| 808 | + * @param int $blog_id Blog whose manifests to drop. | |
| 809 | + * @return int Manifests removed. | |
| 810 | + */ | |
| 811 | + public static function purge_manifests( int $blog_id ): int { | |
| 812 | + $dir = Asset_Manifest::dir( $blog_id ); | |
| 813 | + $removed = self::rmtree_files( $dir ); | |
| 814 | + @rmdir( $dir ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_rmdir, WordPress.PHP.NoSilencedErrors.Discouraged -- best-effort cleanup of our own cache subdir; WP_Filesystem is unavailable on the frontend purge path. | |
| 815 | + return $removed; | |
| 816 | + } | |
| 817 | + | |
| 818 | + /** File holding the purge stamp. Network-wide, like min/ itself. */ | |
| 819 | + public static function purge_stamp_path(): string { | |
| 820 | + return rtrim( (string) XSPEED_CACHE_DIR, '/' ) . '/min-purge.stamp'; | |
| 821 | + } | |
| 822 | + | |
| 823 | + /** | |
| 824 | + * Token that changes every time purge_minified() deletes something. | |
| 825 | + * | |
| 826 | + * The page cache reads it when a render starts and again before storing | |
| 827 | + * the page. A different value means files the page may link were deleted | |
| 828 | + * in between, so the page is served but not cached. | |
| 829 | + * | |
| 830 | + * @return string '' when no purge has ever deleted anything. | |
| 831 | + */ | |
| 832 | + public static function purge_stamp(): string { | |
| 833 | + $stamp = @file_get_contents( self::purge_stamp_path() ); // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- absent until the first purge; tiny cache sidecar read on the front end, where WP_Filesystem is unavailable. | |
| 834 | + return is_string( $stamp ) ? trim( $stamp ) : ''; | |
| 835 | + } | |
| 836 | + | |
| 837 | + /** Replace the purge stamp with a new random token. */ | |
| 838 | + private static function bump_purge_stamp(): void { | |
| 839 | + $path = self::purge_stamp_path(); | |
| 840 | + if ( ! is_dir( dirname( $path ) ) ) { | |
| 841 | + return; | |
| 842 | + } | |
| 843 | + Asset_Manifest::write_atomic( $path, bin2hex( random_bytes( 8 ) ) ); | |
| 683 | 844 | } |
| 684 | 845 | |
| 685 | 846 | /** |
| 686 | 847 | * Recursively delete every file under $dir (and the emptied |