<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[23592] trunk/wp-includes/ms-functions.php: In ms-functions.php, remove unnecessary slashing, don't strip the return of get_site_option, s/stripslashes*/wp_unslash/.</title>
</head>
<body>
<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; }
#msg dl a { font-weight: bold}
#msg dl a:link { color:#fc3; }
#msg dl a:active { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg > ul, #logmsg > ol { margin-left: 0; margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://core.trac.wordpress.org/changeset/23592">23592</a></dd>
<dt>Author</dt> <dd>ryan</dd>
<dt>Date</dt> <dd>2013-03-03 16:55:53 +0000 (Sun, 03 Mar 2013)</dd>
</dl>
<h3>Log Message</h3>
<pre>In ms-functions.php, remove unnecessary slashing, don't strip the return of get_site_option, s/stripslashes*/wp_unslash/.
see <a href="http://core.trac.wordpress.org/ticket/21767">#21767</a></pre>
<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkwpincludesmsfunctionsphp">trunk/wp-includes/ms-functions.php</a></li>
</ul>
</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkwpincludesmsfunctionsphp"></a>
<div class="modfile"><h4>Modified: trunk/wp-includes/ms-functions.php (23591 => 23592)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/wp-includes/ms-functions.php        2013-03-03 16:30:38 UTC (rev 23591)
+++ trunk/wp-includes/ms-functions.php        2013-03-03 16:55:53 UTC (rev 23592)
</span><span class="lines">@@ -279,9 +279,6 @@
</span><span class="cx"> * @return int The ID of the newly created blog
</span><span class="cx"> */
</span><span class="cx"> function create_empty_blog( $domain, $path, $weblog_title, $site_id = 1 ) {
</span><del>-        $domain                        = addslashes( $domain );
-        $weblog_title        = addslashes( $weblog_title );
-
</del><span class="cx">         if ( empty($path) )
</span><span class="cx">                 $path = '/';
</span><span class="cx">
</span><span class="lines">@@ -582,7 +579,7 @@
</span><span class="cx">
</span><span class="cx">         $blogname = apply_filters( 'newblogname', $blogname );
</span><span class="cx">
</span><del>-        $blog_title = stripslashes( $blog_title );
</del><ins>+        $blog_title = wp_unslash( $blog_title );
</ins><span class="cx">
</span><span class="cx">         if ( empty( $blog_title ) )
</span><span class="cx">                 $errors->add('blog_title', __( 'Please enter a site title.' ) );
</span><span class="lines">@@ -636,9 +633,6 @@
</span><span class="cx">
</span><span class="cx">         $key = substr( md5( time() . rand() . $domain ), 0, 16 );
</span><span class="cx">         $meta = serialize($meta);
</span><del>-        $domain = $wpdb->escape($domain);
-        $path = $wpdb->escape($path);
-        $title = $wpdb->escape($title);
</del><span class="cx">
</span><span class="cx">         $wpdb->insert( $wpdb->signups, array(
</span><span class="cx">                 'domain' => $domain,
</span><span class="lines">@@ -840,14 +834,12 @@
</span><span class="cx">         }
</span><span class="cx">
</span><span class="cx">         $meta = maybe_unserialize($signup->meta);
</span><del>-        $user_login = $wpdb->escape($signup->user_login);
-        $user_email = $wpdb->escape($signup->user_email);
</del><span class="cx">         $password = wp_generate_password( 12, false );
</span><span class="cx">
</span><span class="cx">         $user_id = username_exists($user_login);
</span><span class="cx">
</span><span class="cx">         if ( ! $user_id )
</span><del>-                $user_id = wpmu_create_user($user_login, $password, $user_email);
</del><ins>+                $user_id = wpmu_create_user($signup->user_login, $password, $signup->user_email);
</ins><span class="cx">         else
</span><span class="cx">                 $user_already_exists = true;
</span><span class="cx">
</span><span class="lines">@@ -1024,7 +1016,7 @@
</span><span class="cx"> URL: %2$s
</span><span class="cx"> Remote IP: %3$s
</span><span class="cx">
</span><del>-Disable these notifications: %4$s' ), $blogname, $siteurl, $_SERVER['REMOTE_ADDR'], $options_site_url);
</del><ins>+Disable these notifications: %4$s' ), $blogname, $siteurl, wp_unslash( $_SERVER['REMOTE_ADDR'] ), $options_site_url);
</ins><span class="cx">         $msg = apply_filters( 'newblog_notify_siteadmin', $msg );
</span><span class="cx">
</span><span class="cx">         wp_mail( $email, sprintf( __( 'New Site Registration: %s' ), $siteurl ), $msg );
</span><span class="lines">@@ -1058,7 +1050,7 @@
</span><span class="cx">         $msg = sprintf(__('New User: %1$s
</span><span class="cx"> Remote IP: %2$s
</span><span class="cx">
</span><del>-Disable these notifications: %3$s'), $user->user_login, $_SERVER['REMOTE_ADDR'], $options_site_url);
</del><ins>+Disable these notifications: %3$s'), $user->user_login, wp_unslash( $_SERVER['REMOTE_ADDR'] ), $options_site_url);
</ins><span class="cx">
</span><span class="cx">         $msg = apply_filters( 'newuser_notify_siteadmin', $msg, $user );
</span><span class="cx">         wp_mail( $email, sprintf(__('New User Registration: %s'), $user->user_login), $msg );
</span><span class="lines">@@ -1157,7 +1149,7 @@
</span><span class="cx">         else
</span><span class="cx">                 update_option( 'upload_path', get_blog_option( $current_site->blog_id, 'upload_path' ) );
</span><span class="cx">
</span><del>-        update_option( 'blogname', stripslashes( $blog_title ) );
</del><ins>+        update_option( 'blogname', wp_unslash( $blog_title ) );
</ins><span class="cx">         update_option( 'admin_email', '' );
</span><span class="cx">
</span><span class="cx">         // remove all perms
</span><span class="lines">@@ -1214,9 +1206,9 @@
</span><span class="cx">         if ( !apply_filters('wpmu_welcome_notification', $blog_id, $user_id, $password, $title, $meta) )
</span><span class="cx">                 return false;
</span><span class="cx">
</span><del>-        $welcome_email = stripslashes( get_site_option( 'welcome_email' ) );
</del><ins>+        $welcome_email = get_site_option( 'welcome_email' );
</ins><span class="cx">         if ( $welcome_email == false )
</span><del>-                $welcome_email = stripslashes( __( 'Dear User,
</del><ins>+                $welcome_email = __( 'Dear User,
</ins><span class="cx">
</span><span class="cx"> Your new SITE_NAME site has been successfully set up at:
</span><span class="cx"> BLOG_URL
</span><span class="lines">@@ -1228,7 +1220,7 @@
</span><span class="cx">
</span><span class="cx"> We hope you enjoy your new site. Thanks!
</span><span class="cx">
</span><del>---The Team @ SITE_NAME' ) );
</del><ins>+--The Team @ SITE_NAME' );
</ins><span class="cx">
</span><span class="cx">         $url = get_blogaddress_by_id($blog_id);
</span><span class="cx">         $user = get_userdata( $user_id );
</span><span class="lines">@@ -1252,7 +1244,7 @@
</span><span class="cx">         if ( empty( $current_site->site_name ) )
</span><span class="cx">                 $current_site->site_name = 'WordPress';
</span><span class="cx">
</span><del>-        $subject = apply_filters( 'update_welcome_subject', sprintf(__('New %1$s Site: %2$s'), $current_site->site_name, stripslashes( $title ) ) );
</del><ins>+        $subject = apply_filters( 'update_welcome_subject', sprintf(__('New %1$s Site: %2$s'), $current_site->site_name, wp_unslash( $title ) ) );
</ins><span class="cx">         wp_mail($user->user_email, $subject, $message, $message_headers);
</span><span class="cx">         return true;
</span><span class="cx"> }
</span><span class="lines">@@ -1481,7 +1473,7 @@
</span><span class="cx"> function wpmu_log_new_registrations( $blog_id, $user_id ) {
</span><span class="cx">         global $wpdb;
</span><span class="cx">         $user = get_userdata( (int) $user_id );
</span><del>-        $wpdb->insert( $wpdb->registration_log, array('email' => $user->user_email, 'IP' => preg_replace( '/[^0-9., ]/', '',$_SERVER['REMOTE_ADDR'] ), 'blog_id' => $blog_id, 'date_registered' => current_time('mysql')) );
</del><ins>+        $wpdb->insert( $wpdb->registration_log, array('email' => $user->user_email, 'IP' => preg_replace( '/[^0-9., ]/', '', wp_unslash( $_SERVER['REMOTE_ADDR'] ) ), 'blog_id' => $blog_id, 'date_registered' => current_time('mysql')) );
</ins><span class="cx"> }
</span><span class="cx">
</span><span class="cx"> /**
</span></span></pre>
</div>
</div>
</body>
</html>