PluginProbe
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN / 1.4.1
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN v1.4.1
1.4.1 1.4.0 1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.4 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.2 All 35 releases
← All changes | includes/class-minifier.php +175 -39 1.3.7 → 1.4.1 View file →
@@ -104,8 +104,11 @@
104 104 // global that now arrives on first interaction. This filter fires
105 105 // for every inline script WordPress prints, so it also covers
106 106 // pages the cache buffer never filters.
107 107 add_filter( 'wp_inline_script_attributes', array( Minify_Filters::class, 'park_smart_inline' ), 30, 2 );
108 + // A snippet never stays parked behind a live script. Runs after
109 + // the late opt-out revert, which can un-delay the tag.
110 + add_filter( 'script_loader_tag', array( Minify_Filters::class, 'unpark_orphaned_smart_inline' ), Minify_Filters::late_opt_out_priority() + 1, 3 );
108 111 add_action( 'wp_footer', array( Minify_Filters::class, 'print_delay_bootstrap' ), 1000 );
109 112 // script_loader_tag only fires for wp_enqueue_script()'d assets.
110 113 // Analytics / pixel / chat-widget tags printed straight into
111 114 // wp_head bypass it, and those are usually the heaviest scripts
@@ -344,18 +347,37 @@
344 347 if ( ! $path || ! is_readable( $path ) ) {
345 348 return $src;
346 349 }
347 350
348 - // Build a cache filename keyed on path + mtime so edits invalidate.
349 - $mtime = filemtime( $path );
350 - $key = md5( $path . '|' . $mtime );
351 - $cache = self::cache_path( $key, $type );
351 + // Nowhere to write means nothing to serve. Without this gate an
352 + // unwritable min/ cost a full minification on EVERY render, each one
353 + // thrown away when the write failed.
354 + if ( ! self::min_dir_writable() ) {
355 + return $src;
356 + }
352 357
353 - if ( ! file_exists( $cache ) ) {
354 - $ok = self::minify_file( $path, $cache, $type );
355 - if ( ! $ok ) {
356 - return $src;
358 + // The file is named after its minified CONTENT, found through a
359 + // per-source manifest that is validated by stat() alone on the hot
360 + // path. See Asset_Manifest for the rules. The old name was
361 + // md5(path|mtime): an in-place edit that kept the mtime served new
362 + // bytes under a URL cached for a year, an @import child's edit
363 + // changed nothing, and a touch with no change orphaned every cached
364 + // page that linked the old name.
365 + $key = Asset_Manifest::key_for(
366 + $type,
367 + $path,
368 + static function ( string $source ) use ( $type ): array {
369 + return 'css' === $type ? Asset_Manifest::css_dependencies( $source ) : array();
370 + },
371 + static function ( string $source ) use ( $type ) {
372 + return self::build( $source, $type );
373 + },
374 + static function ( string $key ) use ( $type ): bool {
375 + return file_exists( self::cache_path( $key, $type ) );
357 376 }
377 + );
378 + if ( null === $key ) {
379 + return $src;
358 380 }
359 381
360 382 // Return a URL to the cached file. Built from known constants — never
361 383 // from str_replace on a filesystem path (which would assume the FS
@@ -362,53 +384,110 @@
362 384 // layout mirrors the URL layout).
363 385 return self::min_url() . '/' . $key . '.' . $type;
364 386 }
365 387
366 - private static function minify_file( $source_path, $target_path, $type ) {
367 - if ( ! class_exists( '\\MatthiasMullie\\Minify\\CSS' ) ) {
368 - return false;
388 + /**
389 + * Whether min/ can be written, asked once per request.
390 + *
391 + * @var bool|null
392 + */
393 + private static $writable = null;
394 +
395 + /**
396 + * Minifications run by this process.
397 + *
398 + * @var int
399 + */
400 + private static $builds = 0;
401 +
402 + /** Forget the per-request answers. Tests only. */
403 + public static function reset_request_state(): void {
404 + self::$writable = null;
405 + self::$builds = 0;
406 + }
407 +
408 + /** How many sources this process has minified. Tests and diagnostics. */
409 + public static function builds(): int {
410 + return self::$builds;
411 + }
412 +
413 + /** Can minified files be written this request? */
414 + public static function min_dir_writable(): bool {
415 + if ( null === self::$writable ) {
416 + $dir = self::min_dir();
417 + self::ensure_dir( $dir );
418 + self::$writable = is_dir( $dir ) && wp_is_writable( $dir );
369 419 }
420 + return self::$writable;
421 + }
370 422
371 - // Path-traversal guard: refuse to write anywhere outside our cache
372 - // dir, even if a malicious filter ever produced a poisoned key.
373 - $cache_root = self::min_dir();
374 - self::ensure_dir( $cache_root );
375 - $real_root = realpath( $cache_root );
376 - $real_dir = realpath( dirname( $target_path ) );
377 - if ( ! $real_root || ! $real_dir || 0 !== strpos( $real_dir, $real_root ) ) {
378 - return false;
423 + /**
424 + * Minify a source into min/<md5 of output>.<type> and return the key.
425 + *
426 + * The output is built in memory and published with an atomic rename, so a
427 + * concurrent render never links a half-written file. When a file with the
428 + * same content already exists nothing is written: same bytes, same name.
429 + *
430 + * @param string $source Absolute source path.
431 + * @param string $type 'css' or 'js'.
432 + * @return string|null|false Key; null when the source cannot be minified;
433 + * false when the output could not be written.
434 + */
435 + private static function build( string $source, string $type ) {
436 + ++self::$builds;
437 + $minified = self::minify_to_string( $source, $type );
438 + if ( null === $minified ) {
439 + return null;
379 440 }
441 + $key = md5( $minified );
442 + $target = self::cache_path( $key, $type );
443 + if ( file_exists( $target ) ) {
444 + return $key;
445 + }
446 + return Asset_Manifest::write_atomic( $target, $minified ) ? $key : false;
447 + }
380 448
449 + /**
450 + * Minified bytes of a source, or null on failure.
451 + *
452 + * @param string $source_path Absolute source path.
453 + * @param string $type 'css' or 'js'.
454 + */
455 + private static function minify_to_string( string $source_path, string $type ): ?string {
456 + if ( ! class_exists( '\\MatthiasMullie\\Minify\\CSS' ) ) {
457 + return null;
458 + }
459 +
381 460 try {
382 461 if ( 'css' === $type ) {
383 - // Passing the TARGET path makes matthiasmullie/minify rebase every
384 - // relative url(...) / @import against the minified file's location.
385 - // Without it, a stylesheet moved from e.g.
386 - // .../font-awesome/css/all.css to cache/xspeed/min/<key>.css keeps
387 - // its original url(../webfonts/…) — which then resolves against the
388 - // cache dir and 404s (missing FontAwesome/eicons/WooCommerce fonts).
462 + // execute() with a path inside min/ rebases every relative
463 + // url(...) / @import against the minified file's location,
464 + // which is what minify( $target ) did before without writing.
465 + // Every output lives in the same directory, so any name there
466 + // rebases identically. Without the rebase a stylesheet moved
467 + // from e.g. .../font-awesome/css/all.css to
468 + // cache/xspeed/min/<key>.css keeps its original
469 + // url(../webfonts/…), which then resolves against the cache
470 + // dir and 404s (missing FontAwesome/eicons/WooCommerce fonts).
389 471 $minifier = new \MatthiasMullie\Minify\CSS( $source_path );
390 - $minified = $minifier->minify( $target_path );
391 - return '' !== $minified && file_exists( $target_path );
472 + $minified = (string) $minifier->execute( self::min_dir() . '/rebase.css' );
473 + return '' !== $minified ? $minified : null;
392 474 }
393 475
394 476 $minifier = new \MatthiasMullie\Minify\JS( $source_path );
395 - $minified = $minifier->minify();
477 + $minified = (string) $minifier->minify();
396 478
397 479 // Sanity check: paren/brace/bracket/backtick balance must be preserved.
398 480 // matthiasmullie/minify can silently truncate mid-template-literal on
399 481 // complex modern JS — bail rather than ship a broken file.
400 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders. Source already validated as readable on line 121.
482 + // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders. Source already validated as readable by the caller.
401 483 $source = file_get_contents( $source_path );
402 - if ( false === $source || ! self::balanced( $source, $minified ) ) {
403 - return false;
484 + if ( false === $source || '' === $minified || ! self::balanced( $source, $minified ) ) {
485 + return null;
404 486 }
405 -
406 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_put_contents_file_put_contents -- WP_Filesystem requires admin context; minification runs on frontend page renders.
407 - $bytes = file_put_contents( $target_path, $minified );
408 - return false !== $bytes && file_exists( $target_path );
487 + return $minified;
409 488 } catch ( \Throwable $e ) {
410 - return false;
489 + return null;
411 490 }
412 491 }
413 492
414 493 /**
@@ -438,9 +517,9 @@
438 517 * data; minifying a template would eat the markup it holds. An unknown
439 518 * type is treated as non-JS on purpose: guessing wrong breaks the page,
440 519 * while skipping only forgoes a few bytes.
441 520 * - `<script src="...">` — the body is empty; the file path already goes
442 - * through minify_file().
521 + * through rewrite_asset().
443 522 *
444 523 * Every result is checked with balanced(), the same structural guard the
445 524 * file path uses, so a body the library truncates is shipped as-is rather
446 525 * than broken. (#2)
@@ -697,15 +776,72 @@
697 776 }
698 777 }
699 778
700 779 /**
701 - * Clear every minified / combined asset.
780 + * Delete every minified and combined asset, network-wide.
702 781 *
782 + * Output files are named by content, so an ordinary purge has no reason
783 + * to delete them: a page rendered after it links the same names. Only a
784 + * network purge, an update, an explicit assets purge and deactivation
785 + * come here. Deleting is still a race against renders in flight, which
786 + * may already hold the names of files about to vanish; the purge stamp
787 + * bumped here lets the page cache refuse to store those renders.
788 + *
703 789 * @return int Files removed. Most callers are `add_action` callbacks and
704 790 * ignore it; `wp xspeed purge` reports it as a line item.
705 791 */
706 792 public static function purge_minified() {
707 - return self::rmtree_files( self::min_dir() );
793 + $removed = self::rmtree_files( self::min_dir() );
794 + if ( $removed > 0 ) {
795 + self::bump_purge_stamp();
796 + }
797 + return $removed;
798 + }
799 +
800 + /**
801 + * Delete one blog's manifests, leaving every output file in place.
802 + *
803 + * What a subsite's assets purge can safely do on a network whose blogs
804 + * share min/: the next render of each source re-reads its bytes and
805 + * rebuilds only if they changed, and no other blog's cached page loses a
806 + * file it links. Outputs nothing links any more are left to Cache_GC.
807 + *
808 + * @param int $blog_id Blog whose manifests to drop.
809 + * @return int Manifests removed.
810 + */
811 + public static function purge_manifests( int $blog_id ): int {
812 + $dir = Asset_Manifest::dir( $blog_id );
813 + $removed = self::rmtree_files( $dir );
814 + @rmdir( $dir ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_rmdir, WordPress.PHP.NoSilencedErrors.Discouraged -- best-effort cleanup of our own cache subdir; WP_Filesystem is unavailable on the frontend purge path.
815 + return $removed;
816 + }
817 +
818 + /** File holding the purge stamp. Network-wide, like min/ itself. */
819 + public static function purge_stamp_path(): string {
820 + return rtrim( (string) XSPEED_CACHE_DIR, '/' ) . '/min-purge.stamp';
821 + }
822 +
823 + /**
824 + * Token that changes every time purge_minified() deletes something.
825 + *
826 + * The page cache reads it when a render starts and again before storing
827 + * the page. A different value means files the page may link were deleted
828 + * in between, so the page is served but not cached.
829 + *
830 + * @return string '' when no purge has ever deleted anything.
831 + */
832 + public static function purge_stamp(): string {
833 + $stamp = @file_get_contents( self::purge_stamp_path() ); // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- absent until the first purge; tiny cache sidecar read on the front end, where WP_Filesystem is unavailable.
834 + return is_string( $stamp ) ? trim( $stamp ) : '';
835 + }
836 +
837 + /** Replace the purge stamp with a new random token. */
838 + private static function bump_purge_stamp(): void {
839 + $path = self::purge_stamp_path();
840 + if ( ! is_dir( dirname( $path ) ) ) {
841 + return;
842 + }
843 + Asset_Manifest::write_atomic( $path, bin2hex( random_bytes( 8 ) ) );
708 844 }
709 845
710 846 /**
711 847 * Recursively delete every file under $dir (and the emptied