From e834fed6eb7f43a1aa3a89d592e1f4b857491c13 Mon Sep 17 00:00:00 2001 From: Sergey Biryukov Date: Tue, 4 Jul 2023 13:40:55 +0000 Subject: [PATCH] Options, Meta APIs: Check if the `gmt_offset` value is numeric in `sanitize_option()`. When saving the settings via the admin UI, the default value for any options not passed in the current `$_POST` request is set to `null` in `wp-admin/options.php`. Some options, e.g. `blog_public`, then rely on `null` being passed to `update_option()` to determine whether the value was changed or not. This commit resolves a PHP 8.1 deprecation notice when saving the `gmt_offset` option without any changes: {{{ Deprecated: preg_replace(): Passing null to parameter #3 ($subject) of type array|string is deprecated }}} Includes a similar fix for the `blog_charset` option. Follow-up to [4112], [4329], [5541], [21849]. Props adi3890, dhrupo, hrdelwar, hasanmisbah, oglekler, mukesh27, SergeyBiryukov. Fixes #57728. git-svn-id: https://develop.svn.wordpress.org/trunk@56132 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-includes/formatting.php | 12 ++++++++++-- tests/phpunit/tests/option/sanitizeOption.php | 2 ++ 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/src/wp-includes/formatting.php b/src/wp-includes/formatting.php index 956e8290e2..50b43a5175 100644 --- a/src/wp-includes/formatting.php +++ b/src/wp-includes/formatting.php @@ -4883,7 +4883,11 @@ function sanitize_option( $option, $value ) { break; case 'blog_charset': - $value = preg_replace( '/[^a-zA-Z0-9_-]/', '', $value ); // Strips slashes. + if ( is_string( $value ) ) { + $value = preg_replace( '/[^a-zA-Z0-9_-]/', '', $value ); // Strips slashes. + } else { + $value = ''; + } break; case 'blog_public': @@ -4918,7 +4922,11 @@ function sanitize_option( $option, $value ) { break; case 'gmt_offset': - $value = preg_replace( '/[^0-9:.-]/', '', $value ); // Strips slashes. + if ( is_numeric( $value ) ) { + $value = preg_replace( '/[^0-9:.-]/', '', $value ); // Strips slashes. + } else { + $value = ''; + } break; case 'siteurl': diff --git a/tests/phpunit/tests/option/sanitizeOption.php b/tests/phpunit/tests/option/sanitizeOption.php index e50cec0c62..38fdda1a21 100644 --- a/tests/phpunit/tests/option/sanitizeOption.php +++ b/tests/phpunit/tests/option/sanitizeOption.php @@ -36,6 +36,7 @@ class Tests_Option_SanitizeOption extends WP_UnitTestCase { array( 'blogname', '<i>My Site</i>', 'My Site' ), array( 'blog_charset', 'UTF-8', 'UTF-8' ), array( 'blog_charset', 'charset', '">charset<"' ), + array( 'blog_charset', '', null ), array( 'blog_public', 1, null ), array( 'blog_public', 1, '1' ), array( 'blog_public', -2, '-2' ), @@ -45,6 +46,7 @@ class Tests_Option_SanitizeOption extends WP_UnitTestCase { array( 'ping_sites', "http://www.example.com\nhttp://example.org", "www.example.com \n\texample.org\n\n" ), array( 'gmt_offset', '0', 0 ), array( 'gmt_offset', '1.5', '1.5' ), + array( 'gmt_offset', '', null ), array( 'siteurl', 'http://example.org', 'http://example.org' ), array( 'siteurl', 'http://example.org/subdir', 'http://example.org/subdir' ), array( 'siteurl', get_option( 'siteurl' ), '' ),