mirror of
https://github.com/gosticks/wordpress-develop.git
synced 2026-10-06 23:58:03 +00:00
Force the REST API URL to use https for its scheme when the current request is served over HTTPS and the host name matches that of the REST API URL.
This allows sites to use an admin area over HTTPS with the front end over HTTP, and not end up with a cross-protocol problem when using the REST API URL in the admin area. Fixes #34299 git-svn-id: https://develop.svn.wordpress.org/trunk@35351 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
@@ -254,6 +254,13 @@ function get_rest_url( $blog_id = null, $path = '/', $scheme = 'rest' ) {
|
||||
$url = add_query_arg( 'rest_route', $path, $url );
|
||||
}
|
||||
|
||||
if ( is_ssl() ) {
|
||||
// If the current host is the same as the REST URL host, force the REST URL scheme to HTTPS
|
||||
if ( $_SERVER['SERVER_NAME'] === parse_url( get_home_url( $blog_id ), PHP_URL_HOST ) ) {
|
||||
$url = set_url_scheme( $url, 'https' );
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Filter the REST URL.
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user