load.php 50 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822
  1. <?php
  2. /**
  3. * These functions are needed to load WordPress.
  4. *
  5. * @package WordPress
  6. */
  7. /**
  8. * Return the HTTP protocol sent by the server.
  9. *
  10. * @since 4.4.0
  11. *
  12. * @return string The HTTP protocol. Default: HTTP/1.0.
  13. */
  14. function wp_get_server_protocol() {
  15. $protocol = isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : '';
  16. if ( ! in_array( $protocol, array( 'HTTP/1.1', 'HTTP/2', 'HTTP/2.0', 'HTTP/3' ), true ) ) {
  17. $protocol = 'HTTP/1.0';
  18. }
  19. return $protocol;
  20. }
  21. /**
  22. * Fix `$_SERVER` variables for various setups.
  23. *
  24. * @since 3.0.0
  25. * @access private
  26. *
  27. * @global string $PHP_SELF The filename of the currently executing script,
  28. * relative to the document root.
  29. */
  30. function wp_fix_server_vars() {
  31. global $PHP_SELF;
  32. $default_server_values = array(
  33. 'SERVER_SOFTWARE' => '',
  34. 'REQUEST_URI' => '',
  35. );
  36. $_SERVER = array_merge( $default_server_values, $_SERVER );
  37. // Fix for IIS when running with PHP ISAPI.
  38. if ( empty( $_SERVER['REQUEST_URI'] ) || ( 'cgi-fcgi' !== PHP_SAPI && preg_match( '/^Microsoft-IIS\//', $_SERVER['SERVER_SOFTWARE'] ) ) ) {
  39. if ( isset( $_SERVER['HTTP_X_ORIGINAL_URL'] ) ) {
  40. // IIS Mod-Rewrite.
  41. $_SERVER['REQUEST_URI'] = $_SERVER['HTTP_X_ORIGINAL_URL'];
  42. } elseif ( isset( $_SERVER['HTTP_X_REWRITE_URL'] ) ) {
  43. // IIS Isapi_Rewrite.
  44. $_SERVER['REQUEST_URI'] = $_SERVER['HTTP_X_REWRITE_URL'];
  45. } else {
  46. // Use ORIG_PATH_INFO if there is no PATH_INFO.
  47. if ( ! isset( $_SERVER['PATH_INFO'] ) && isset( $_SERVER['ORIG_PATH_INFO'] ) ) {
  48. $_SERVER['PATH_INFO'] = $_SERVER['ORIG_PATH_INFO'];
  49. }
  50. // Some IIS + PHP configurations put the script-name in the path-info (no need to append it twice).
  51. if ( isset( $_SERVER['PATH_INFO'] ) ) {
  52. if ( $_SERVER['PATH_INFO'] == $_SERVER['SCRIPT_NAME'] ) {
  53. $_SERVER['REQUEST_URI'] = $_SERVER['PATH_INFO'];
  54. } else {
  55. $_SERVER['REQUEST_URI'] = $_SERVER['SCRIPT_NAME'] . $_SERVER['PATH_INFO'];
  56. }
  57. }
  58. // Append the query string if it exists and isn't null.
  59. if ( ! empty( $_SERVER['QUERY_STRING'] ) ) {
  60. $_SERVER['REQUEST_URI'] .= '?' . $_SERVER['QUERY_STRING'];
  61. }
  62. }
  63. }
  64. // Fix for PHP as CGI hosts that set SCRIPT_FILENAME to something ending in php.cgi for all requests.
  65. if ( isset( $_SERVER['SCRIPT_FILENAME'] ) && ( strpos( $_SERVER['SCRIPT_FILENAME'], 'php.cgi' ) == strlen( $_SERVER['SCRIPT_FILENAME'] ) - 7 ) ) {
  66. $_SERVER['SCRIPT_FILENAME'] = $_SERVER['PATH_TRANSLATED'];
  67. }
  68. // Fix for Dreamhost and other PHP as CGI hosts.
  69. if ( isset( $_SERVER['SCRIPT_NAME'] ) && ( strpos( $_SERVER['SCRIPT_NAME'], 'php.cgi' ) !== false ) ) {
  70. unset( $_SERVER['PATH_INFO'] );
  71. }
  72. // Fix empty PHP_SELF.
  73. $PHP_SELF = $_SERVER['PHP_SELF'];
  74. if ( empty( $PHP_SELF ) ) {
  75. $_SERVER['PHP_SELF'] = preg_replace( '/(\?.*)?$/', '', $_SERVER['REQUEST_URI'] );
  76. $PHP_SELF = $_SERVER['PHP_SELF'];
  77. }
  78. wp_populate_basic_auth_from_authorization_header();
  79. }
  80. /**
  81. * Populates the Basic Auth server details from the Authorization header.
  82. *
  83. * Some servers running in CGI or FastCGI mode don't pass the Authorization
  84. * header on to WordPress. If it's been rewritten to the `HTTP_AUTHORIZATION` header,
  85. * fill in the proper $_SERVER variables instead.
  86. *
  87. * @since 5.6.0
  88. */
  89. function wp_populate_basic_auth_from_authorization_header() {
  90. // If we don't have anything to pull from, return early.
  91. if ( ! isset( $_SERVER['HTTP_AUTHORIZATION'] ) && ! isset( $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] ) ) {
  92. return;
  93. }
  94. // If either PHP_AUTH key is already set, do nothing.
  95. if ( isset( $_SERVER['PHP_AUTH_USER'] ) || isset( $_SERVER['PHP_AUTH_PW'] ) ) {
  96. return;
  97. }
  98. // From our prior conditional, one of these must be set.
  99. $header = isset( $_SERVER['HTTP_AUTHORIZATION'] ) ? $_SERVER['HTTP_AUTHORIZATION'] : $_SERVER['REDIRECT_HTTP_AUTHORIZATION'];
  100. // Test to make sure the pattern matches expected.
  101. if ( ! preg_match( '%^Basic [a-z\d/+]*={0,2}$%i', $header ) ) {
  102. return;
  103. }
  104. // Removing `Basic ` the token would start six characters in.
  105. $token = substr( $header, 6 );
  106. $userpass = base64_decode( $token );
  107. list( $user, $pass ) = explode( ':', $userpass );
  108. // Now shove them in the proper keys where we're expecting later on.
  109. $_SERVER['PHP_AUTH_USER'] = $user;
  110. $_SERVER['PHP_AUTH_PW'] = $pass;
  111. }
  112. /**
  113. * Check for the required PHP version, and the MySQL extension or
  114. * a database drop-in.
  115. *
  116. * Dies if requirements are not met.
  117. *
  118. * @since 3.0.0
  119. * @access private
  120. *
  121. * @global string $required_php_version The required PHP version string.
  122. * @global string $wp_version The WordPress version string.
  123. */
  124. function wp_check_php_mysql_versions() {
  125. global $required_php_version, $wp_version;
  126. $php_version = PHP_VERSION;
  127. if ( version_compare( $required_php_version, $php_version, '>' ) ) {
  128. $protocol = wp_get_server_protocol();
  129. header( sprintf( '%s 500 Internal Server Error', $protocol ), true, 500 );
  130. header( 'Content-Type: text/html; charset=utf-8' );
  131. printf( 'Your server is running PHP version %1$s but WordPress %2$s requires at least %3$s.', $php_version, $wp_version, $required_php_version );
  132. exit( 1 );
  133. }
  134. if ( ! extension_loaded( 'mysql' ) && ! extension_loaded( 'mysqli' ) && ! extension_loaded( 'mysqlnd' )
  135. // This runs before default constants are defined, so we can't assume WP_CONTENT_DIR is set yet.
  136. && ( defined( 'WP_CONTENT_DIR' ) && ! file_exists( WP_CONTENT_DIR . '/db.php' )
  137. || ! file_exists( ABSPATH . 'wp-content/db.php' ) )
  138. ) {
  139. require_once ABSPATH . WPINC . '/functions.php';
  140. wp_load_translations_early();
  141. $args = array(
  142. 'exit' => false,
  143. 'code' => 'mysql_not_found',
  144. );
  145. wp_die(
  146. __( 'Your PHP installation appears to be missing the MySQL extension which is required by WordPress.' ),
  147. __( 'Requirements Not Met' ),
  148. $args
  149. );
  150. exit( 1 );
  151. }
  152. }
  153. /**
  154. * Retrieves the current environment type.
  155. *
  156. * The type can be set via the `WP_ENVIRONMENT_TYPE` global system variable,
  157. * or a constant of the same name.
  158. *
  159. * Possible values are 'local', 'development', 'staging', and 'production'.
  160. * If not set, the type defaults to 'production'.
  161. *
  162. * @since 5.5.0
  163. * @since 5.5.1 Added the 'local' type.
  164. * @since 5.5.1 Removed the ability to alter the list of types.
  165. *
  166. * @return string The current environment type.
  167. */
  168. function wp_get_environment_type() {
  169. static $current_env = '';
  170. if ( ! defined( 'WP_RUN_CORE_TESTS' ) && $current_env ) {
  171. return $current_env;
  172. }
  173. $wp_environments = array(
  174. 'local',
  175. 'development',
  176. 'staging',
  177. 'production',
  178. );
  179. // Add a note about the deprecated WP_ENVIRONMENT_TYPES constant.
  180. if ( defined( 'WP_ENVIRONMENT_TYPES' ) && function_exists( '_deprecated_argument' ) ) {
  181. if ( function_exists( '__' ) ) {
  182. /* translators: %s: WP_ENVIRONMENT_TYPES */
  183. $message = sprintf( __( 'The %s constant is no longer supported.' ), 'WP_ENVIRONMENT_TYPES' );
  184. } else {
  185. $message = sprintf( 'The %s constant is no longer supported.', 'WP_ENVIRONMENT_TYPES' );
  186. }
  187. _deprecated_argument(
  188. 'define()',
  189. '5.5.1',
  190. $message
  191. );
  192. }
  193. // Check if the environment variable has been set, if `getenv` is available on the system.
  194. if ( function_exists( 'getenv' ) ) {
  195. $has_env = getenv( 'WP_ENVIRONMENT_TYPE' );
  196. if ( false !== $has_env ) {
  197. $current_env = $has_env;
  198. }
  199. }
  200. // Fetch the environment from a constant, this overrides the global system variable.
  201. if ( defined( 'WP_ENVIRONMENT_TYPE' ) && WP_ENVIRONMENT_TYPE ) {
  202. $current_env = WP_ENVIRONMENT_TYPE;
  203. }
  204. // Make sure the environment is an allowed one, and not accidentally set to an invalid value.
  205. if ( ! in_array( $current_env, $wp_environments, true ) ) {
  206. $current_env = 'production';
  207. }
  208. return $current_env;
  209. }
  210. /**
  211. * Don't load all of WordPress when handling a favicon.ico request.
  212. *
  213. * Instead, send the headers for a zero-length favicon and bail.
  214. *
  215. * @since 3.0.0
  216. * @deprecated 5.4.0 Deprecated in favor of do_favicon().
  217. */
  218. function wp_favicon_request() {
  219. if ( '/favicon.ico' === $_SERVER['REQUEST_URI'] ) {
  220. header( 'Content-Type: image/vnd.microsoft.icon' );
  221. exit;
  222. }
  223. }
  224. /**
  225. * Die with a maintenance message when conditions are met.
  226. *
  227. * The default message can be replaced by using a drop-in (maintenance.php in
  228. * the wp-content directory).
  229. *
  230. * @since 3.0.0
  231. * @access private
  232. */
  233. function wp_maintenance() {
  234. // Return if maintenance mode is disabled.
  235. if ( ! wp_is_maintenance_mode() ) {
  236. return;
  237. }
  238. if ( file_exists( WP_CONTENT_DIR . '/maintenance.php' ) ) {
  239. require_once WP_CONTENT_DIR . '/maintenance.php';
  240. die();
  241. }
  242. require_once ABSPATH . WPINC . '/functions.php';
  243. wp_load_translations_early();
  244. header( 'Retry-After: 600' );
  245. wp_die(
  246. __( 'Briefly unavailable for scheduled maintenance. Check back in a minute.' ),
  247. __( 'Maintenance' ),
  248. 503
  249. );
  250. }
  251. /**
  252. * Check if maintenance mode is enabled.
  253. *
  254. * Checks for a file in the WordPress root directory named ".maintenance".
  255. * This file will contain the variable $upgrading, set to the time the file
  256. * was created. If the file was created less than 10 minutes ago, WordPress
  257. * is in maintenance mode.
  258. *
  259. * @since 5.5.0
  260. *
  261. * @global int $upgrading The Unix timestamp marking when upgrading WordPress began.
  262. *
  263. * @return bool True if maintenance mode is enabled, false otherwise.
  264. */
  265. function wp_is_maintenance_mode() {
  266. global $upgrading;
  267. if ( ! file_exists( ABSPATH . '.maintenance' ) || wp_installing() ) {
  268. return false;
  269. }
  270. require ABSPATH . '.maintenance';
  271. // If the $upgrading timestamp is older than 10 minutes, consider maintenance over.
  272. if ( ( time() - $upgrading ) >= 10 * MINUTE_IN_SECONDS ) {
  273. return false;
  274. }
  275. /**
  276. * Filters whether to enable maintenance mode.
  277. *
  278. * This filter runs before it can be used by plugins. It is designed for
  279. * non-web runtimes. If this filter returns true, maintenance mode will be
  280. * active and the request will end. If false, the request will be allowed to
  281. * continue processing even if maintenance mode should be active.
  282. *
  283. * @since 4.6.0
  284. *
  285. * @param bool $enable_checks Whether to enable maintenance mode. Default true.
  286. * @param int $upgrading The timestamp set in the .maintenance file.
  287. */
  288. if ( ! apply_filters( 'enable_maintenance_mode', true, $upgrading ) ) {
  289. return false;
  290. }
  291. return true;
  292. }
  293. /**
  294. * Get the time elapsed so far during this PHP script.
  295. *
  296. * Uses REQUEST_TIME_FLOAT that appeared in PHP 5.4.0.
  297. *
  298. * @since 5.8.0
  299. *
  300. * @return float Seconds since the PHP script started.
  301. */
  302. function timer_float() {
  303. return microtime( true ) - $_SERVER['REQUEST_TIME_FLOAT'];
  304. }
  305. /**
  306. * Start the WordPress micro-timer.
  307. *
  308. * @since 0.71
  309. * @access private
  310. *
  311. * @global float $timestart Unix timestamp set at the beginning of the page load.
  312. * @see timer_stop()
  313. *
  314. * @return bool Always returns true.
  315. */
  316. function timer_start() {
  317. global $timestart;
  318. $timestart = microtime( true );
  319. return true;
  320. }
  321. /**
  322. * Retrieve or display the time from the page start to when function is called.
  323. *
  324. * @since 0.71
  325. *
  326. * @global float $timestart Seconds from when timer_start() is called.
  327. * @global float $timeend Seconds from when function is called.
  328. *
  329. * @param int|bool $display Whether to echo or return the results. Accepts 0|false for return,
  330. * 1|true for echo. Default 0|false.
  331. * @param int $precision The number of digits from the right of the decimal to display.
  332. * Default 3.
  333. * @return string The "second.microsecond" finished time calculation. The number is formatted
  334. * for human consumption, both localized and rounded.
  335. */
  336. function timer_stop( $display = 0, $precision = 3 ) {
  337. global $timestart, $timeend;
  338. $timeend = microtime( true );
  339. $timetotal = $timeend - $timestart;
  340. $r = ( function_exists( 'number_format_i18n' ) ) ? number_format_i18n( $timetotal, $precision ) : number_format( $timetotal, $precision );
  341. if ( $display ) {
  342. echo $r;
  343. }
  344. return $r;
  345. }
  346. /**
  347. * Set PHP error reporting based on WordPress debug settings.
  348. *
  349. * Uses three constants: `WP_DEBUG`, `WP_DEBUG_DISPLAY`, and `WP_DEBUG_LOG`.
  350. * All three can be defined in wp-config.php. By default, `WP_DEBUG` and
  351. * `WP_DEBUG_LOG` are set to false, and `WP_DEBUG_DISPLAY` is set to true.
  352. *
  353. * When `WP_DEBUG` is true, all PHP notices are reported. WordPress will also
  354. * display internal notices: when a deprecated WordPress function, function
  355. * argument, or file is used. Deprecated code may be removed from a later
  356. * version.
  357. *
  358. * It is strongly recommended that plugin and theme developers use `WP_DEBUG`
  359. * in their development environments.
  360. *
  361. * `WP_DEBUG_DISPLAY` and `WP_DEBUG_LOG` perform no function unless `WP_DEBUG`
  362. * is true.
  363. *
  364. * When `WP_DEBUG_DISPLAY` is true, WordPress will force errors to be displayed.
  365. * `WP_DEBUG_DISPLAY` defaults to true. Defining it as null prevents WordPress
  366. * from changing the global configuration setting. Defining `WP_DEBUG_DISPLAY`
  367. * as false will force errors to be hidden.
  368. *
  369. * When `WP_DEBUG_LOG` is true, errors will be logged to `wp-content/debug.log`.
  370. * When `WP_DEBUG_LOG` is a valid path, errors will be logged to the specified file.
  371. *
  372. * Errors are never displayed for XML-RPC, REST, `ms-files.php`, and Ajax requests.
  373. *
  374. * @since 3.0.0
  375. * @since 5.1.0 `WP_DEBUG_LOG` can be a file path.
  376. * @access private
  377. */
  378. function wp_debug_mode() {
  379. /**
  380. * Filters whether to allow the debug mode check to occur.
  381. *
  382. * This filter runs before it can be used by plugins. It is designed for
  383. * non-web runtimes. Returning false causes the `WP_DEBUG` and related
  384. * constants to not be checked and the default PHP values for errors
  385. * will be used unless you take care to update them yourself.
  386. *
  387. * To use this filter you must define a `$wp_filter` global before
  388. * WordPress loads, usually in `wp-config.php`.
  389. *
  390. * Example:
  391. *
  392. * $GLOBALS['wp_filter'] = array(
  393. * 'enable_wp_debug_mode_checks' => array(
  394. * 10 => array(
  395. * array(
  396. * 'accepted_args' => 0,
  397. * 'function' => function() {
  398. * return false;
  399. * },
  400. * ),
  401. * ),
  402. * ),
  403. * );
  404. *
  405. * @since 4.6.0
  406. *
  407. * @param bool $enable_debug_mode Whether to enable debug mode checks to occur. Default true.
  408. */
  409. if ( ! apply_filters( 'enable_wp_debug_mode_checks', true ) ) {
  410. return;
  411. }
  412. if ( WP_DEBUG ) {
  413. error_reporting( E_ALL );
  414. if ( WP_DEBUG_DISPLAY ) {
  415. ini_set( 'display_errors', 1 );
  416. } elseif ( null !== WP_DEBUG_DISPLAY ) {
  417. ini_set( 'display_errors', 0 );
  418. }
  419. if ( in_array( strtolower( (string) WP_DEBUG_LOG ), array( 'true', '1' ), true ) ) {
  420. $log_path = WP_CONTENT_DIR . '/debug.log';
  421. } elseif ( is_string( WP_DEBUG_LOG ) ) {
  422. $log_path = WP_DEBUG_LOG;
  423. } else {
  424. $log_path = false;
  425. }
  426. if ( $log_path ) {
  427. ini_set( 'log_errors', 1 );
  428. ini_set( 'error_log', $log_path );
  429. }
  430. } else {
  431. error_reporting( E_CORE_ERROR | E_CORE_WARNING | E_COMPILE_ERROR | E_ERROR | E_WARNING | E_PARSE | E_USER_ERROR | E_USER_WARNING | E_RECOVERABLE_ERROR );
  432. }
  433. if (
  434. defined( 'XMLRPC_REQUEST' ) || defined( 'REST_REQUEST' ) || defined( 'MS_FILES_REQUEST' ) ||
  435. ( defined( 'WP_INSTALLING' ) && WP_INSTALLING ) ||
  436. wp_doing_ajax() || wp_is_json_request() ) {
  437. ini_set( 'display_errors', 0 );
  438. }
  439. }
  440. /**
  441. * Set the location of the language directory.
  442. *
  443. * To set directory manually, define the `WP_LANG_DIR` constant
  444. * in wp-config.php.
  445. *
  446. * If the language directory exists within `WP_CONTENT_DIR`, it
  447. * is used. Otherwise the language directory is assumed to live
  448. * in `WPINC`.
  449. *
  450. * @since 3.0.0
  451. * @access private
  452. */
  453. function wp_set_lang_dir() {
  454. if ( ! defined( 'WP_LANG_DIR' ) ) {
  455. if ( file_exists( WP_CONTENT_DIR . '/languages' ) && @is_dir( WP_CONTENT_DIR . '/languages' ) || ! @is_dir( ABSPATH . WPINC . '/languages' ) ) {
  456. /**
  457. * Server path of the language directory.
  458. *
  459. * No leading slash, no trailing slash, full path, not relative to ABSPATH
  460. *
  461. * @since 2.1.0
  462. */
  463. define( 'WP_LANG_DIR', WP_CONTENT_DIR . '/languages' );
  464. if ( ! defined( 'LANGDIR' ) ) {
  465. // Old static relative path maintained for limited backward compatibility - won't work in some cases.
  466. define( 'LANGDIR', 'wp-content/languages' );
  467. }
  468. } else {
  469. /**
  470. * Server path of the language directory.
  471. *
  472. * No leading slash, no trailing slash, full path, not relative to `ABSPATH`.
  473. *
  474. * @since 2.1.0
  475. */
  476. define( 'WP_LANG_DIR', ABSPATH . WPINC . '/languages' );
  477. if ( ! defined( 'LANGDIR' ) ) {
  478. // Old relative path maintained for backward compatibility.
  479. define( 'LANGDIR', WPINC . '/languages' );
  480. }
  481. }
  482. }
  483. }
  484. /**
  485. * Load the database class file and instantiate the `$wpdb` global.
  486. *
  487. * @since 2.5.0
  488. *
  489. * @global wpdb $wpdb WordPress database abstraction object.
  490. */
  491. function require_wp_db() {
  492. global $wpdb;
  493. require_once ABSPATH . WPINC . '/class-wpdb.php';
  494. if ( file_exists( WP_CONTENT_DIR . '/db.php' ) ) {
  495. require_once WP_CONTENT_DIR . '/db.php';
  496. }
  497. if ( isset( $wpdb ) ) {
  498. return;
  499. }
  500. $dbuser = defined( 'DB_USER' ) ? DB_USER : '';
  501. $dbpassword = defined( 'DB_PASSWORD' ) ? DB_PASSWORD : '';
  502. $dbname = defined( 'DB_NAME' ) ? DB_NAME : '';
  503. $dbhost = defined( 'DB_HOST' ) ? DB_HOST : '';
  504. $wpdb = new wpdb( $dbuser, $dbpassword, $dbname, $dbhost );
  505. }
  506. /**
  507. * Set the database table prefix and the format specifiers for database
  508. * table columns.
  509. *
  510. * Columns not listed here default to `%s`.
  511. *
  512. * @since 3.0.0
  513. * @access private
  514. *
  515. * @global wpdb $wpdb WordPress database abstraction object.
  516. * @global string $table_prefix The database table prefix.
  517. */
  518. function wp_set_wpdb_vars() {
  519. global $wpdb, $table_prefix;
  520. if ( ! empty( $wpdb->error ) ) {
  521. dead_db();
  522. }
  523. $wpdb->field_types = array(
  524. 'post_author' => '%d',
  525. 'post_parent' => '%d',
  526. 'menu_order' => '%d',
  527. 'term_id' => '%d',
  528. 'term_group' => '%d',
  529. 'term_taxonomy_id' => '%d',
  530. 'parent' => '%d',
  531. 'count' => '%d',
  532. 'object_id' => '%d',
  533. 'term_order' => '%d',
  534. 'ID' => '%d',
  535. 'comment_ID' => '%d',
  536. 'comment_post_ID' => '%d',
  537. 'comment_parent' => '%d',
  538. 'user_id' => '%d',
  539. 'link_id' => '%d',
  540. 'link_owner' => '%d',
  541. 'link_rating' => '%d',
  542. 'option_id' => '%d',
  543. 'blog_id' => '%d',
  544. 'meta_id' => '%d',
  545. 'post_id' => '%d',
  546. 'user_status' => '%d',
  547. 'umeta_id' => '%d',
  548. 'comment_karma' => '%d',
  549. 'comment_count' => '%d',
  550. // Multisite:
  551. 'active' => '%d',
  552. 'cat_id' => '%d',
  553. 'deleted' => '%d',
  554. 'lang_id' => '%d',
  555. 'mature' => '%d',
  556. 'public' => '%d',
  557. 'site_id' => '%d',
  558. 'spam' => '%d',
  559. );
  560. $prefix = $wpdb->set_prefix( $table_prefix );
  561. if ( is_wp_error( $prefix ) ) {
  562. wp_load_translations_early();
  563. wp_die(
  564. sprintf(
  565. /* translators: 1: $table_prefix, 2: wp-config.php */
  566. __( '<strong>Error:</strong> %1$s in %2$s can only contain numbers, letters, and underscores.' ),
  567. '<code>$table_prefix</code>',
  568. '<code>wp-config.php</code>'
  569. )
  570. );
  571. }
  572. }
  573. /**
  574. * Toggle `$_wp_using_ext_object_cache` on and off without directly
  575. * touching global.
  576. *
  577. * @since 3.7.0
  578. *
  579. * @global bool $_wp_using_ext_object_cache
  580. *
  581. * @param bool $using Whether external object cache is being used.
  582. * @return bool The current 'using' setting.
  583. */
  584. function wp_using_ext_object_cache( $using = null ) {
  585. global $_wp_using_ext_object_cache;
  586. $current_using = $_wp_using_ext_object_cache;
  587. if ( null !== $using ) {
  588. $_wp_using_ext_object_cache = $using;
  589. }
  590. return $current_using;
  591. }
  592. /**
  593. * Start the WordPress object cache.
  594. *
  595. * If an object-cache.php file exists in the wp-content directory,
  596. * it uses that drop-in as an external object cache.
  597. *
  598. * @since 3.0.0
  599. * @access private
  600. *
  601. * @global array $wp_filter Stores all of the filters.
  602. */
  603. function wp_start_object_cache() {
  604. global $wp_filter;
  605. static $first_init = true;
  606. // Only perform the following checks once.
  607. /**
  608. * Filters whether to enable loading of the object-cache.php drop-in.
  609. *
  610. * This filter runs before it can be used by plugins. It is designed for non-web
  611. * runtimes. If false is returned, object-cache.php will never be loaded.
  612. *
  613. * @since 5.8.0
  614. *
  615. * @param bool $enable_object_cache Whether to enable loading object-cache.php (if present).
  616. * Default true.
  617. */
  618. if ( $first_init && apply_filters( 'enable_loading_object_cache_dropin', true ) ) {
  619. if ( ! function_exists( 'wp_cache_init' ) ) {
  620. /*
  621. * This is the normal situation. First-run of this function. No
  622. * caching backend has been loaded.
  623. *
  624. * We try to load a custom caching backend, and then, if it
  625. * results in a wp_cache_init() function existing, we note
  626. * that an external object cache is being used.
  627. */
  628. if ( file_exists( WP_CONTENT_DIR . '/object-cache.php' ) ) {
  629. require_once WP_CONTENT_DIR . '/object-cache.php';
  630. if ( function_exists( 'wp_cache_init' ) ) {
  631. wp_using_ext_object_cache( true );
  632. }
  633. // Re-initialize any hooks added manually by object-cache.php.
  634. if ( $wp_filter ) {
  635. $wp_filter = WP_Hook::build_preinitialized_hooks( $wp_filter );
  636. }
  637. }
  638. } elseif ( ! wp_using_ext_object_cache() && file_exists( WP_CONTENT_DIR . '/object-cache.php' ) ) {
  639. /*
  640. * Sometimes advanced-cache.php can load object-cache.php before
  641. * this function is run. This breaks the function_exists() check
  642. * above and can result in wp_using_ext_object_cache() returning
  643. * false when actually an external cache is in use.
  644. */
  645. wp_using_ext_object_cache( true );
  646. }
  647. }
  648. if ( ! wp_using_ext_object_cache() ) {
  649. require_once ABSPATH . WPINC . '/cache.php';
  650. }
  651. require_once ABSPATH . WPINC . '/cache-compat.php';
  652. /*
  653. * If cache supports reset, reset instead of init if already
  654. * initialized. Reset signals to the cache that global IDs
  655. * have changed and it may need to update keys and cleanup caches.
  656. */
  657. if ( ! $first_init && function_exists( 'wp_cache_switch_to_blog' ) ) {
  658. wp_cache_switch_to_blog( get_current_blog_id() );
  659. } elseif ( function_exists( 'wp_cache_init' ) ) {
  660. wp_cache_init();
  661. }
  662. if ( function_exists( 'wp_cache_add_global_groups' ) ) {
  663. wp_cache_add_global_groups(
  664. array(
  665. 'blog-details',
  666. 'blog-id-cache',
  667. 'blog-lookup',
  668. 'blog_meta',
  669. 'global-posts',
  670. 'networks',
  671. 'sites',
  672. 'site-details',
  673. 'site-options',
  674. 'site-transient',
  675. 'rss',
  676. 'users',
  677. 'useremail',
  678. 'userlogins',
  679. 'usermeta',
  680. 'user_meta',
  681. 'userslugs',
  682. )
  683. );
  684. wp_cache_add_non_persistent_groups( array( 'counts', 'plugins' ) );
  685. }
  686. $first_init = false;
  687. }
  688. /**
  689. * Redirect to the installer if WordPress is not installed.
  690. *
  691. * Dies with an error message when Multisite is enabled.
  692. *
  693. * @since 3.0.0
  694. * @access private
  695. */
  696. function wp_not_installed() {
  697. if ( is_blog_installed() || wp_installing() ) {
  698. return;
  699. }
  700. nocache_headers();
  701. if ( is_multisite() ) {
  702. wp_die( __( 'The site you have requested is not installed properly. Please contact the system administrator.' ) );
  703. }
  704. require ABSPATH . WPINC . '/kses.php';
  705. require ABSPATH . WPINC . '/pluggable.php';
  706. $link = wp_guess_url() . '/wp-admin/install.php';
  707. wp_redirect( $link );
  708. die();
  709. }
  710. /**
  711. * Retrieve an array of must-use plugin files.
  712. *
  713. * The default directory is wp-content/mu-plugins. To change the default
  714. * directory manually, define `WPMU_PLUGIN_DIR` and `WPMU_PLUGIN_URL`
  715. * in wp-config.php.
  716. *
  717. * @since 3.0.0
  718. * @access private
  719. *
  720. * @return string[] Array of absolute paths of files to include.
  721. */
  722. function wp_get_mu_plugins() {
  723. $mu_plugins = array();
  724. if ( ! is_dir( WPMU_PLUGIN_DIR ) ) {
  725. return $mu_plugins;
  726. }
  727. $dh = opendir( WPMU_PLUGIN_DIR );
  728. if ( ! $dh ) {
  729. return $mu_plugins;
  730. }
  731. while ( ( $plugin = readdir( $dh ) ) !== false ) {
  732. if ( '.php' === substr( $plugin, -4 ) ) {
  733. $mu_plugins[] = WPMU_PLUGIN_DIR . '/' . $plugin;
  734. }
  735. }
  736. closedir( $dh );
  737. sort( $mu_plugins );
  738. return $mu_plugins;
  739. }
  740. /**
  741. * Retrieve an array of active and valid plugin files.
  742. *
  743. * While upgrading or installing WordPress, no plugins are returned.
  744. *
  745. * The default directory is `wp-content/plugins`. To change the default
  746. * directory manually, define `WP_PLUGIN_DIR` and `WP_PLUGIN_URL`
  747. * in `wp-config.php`.
  748. *
  749. * @since 3.0.0
  750. * @access private
  751. *
  752. * @return string[] Array of paths to plugin files relative to the plugins directory.
  753. */
  754. function wp_get_active_and_valid_plugins() {
  755. $plugins = array();
  756. $active_plugins = (array) get_option( 'active_plugins', array() );
  757. // Check for hacks file if the option is enabled.
  758. if ( get_option( 'hack_file' ) && file_exists( ABSPATH . 'my-hacks.php' ) ) {
  759. _deprecated_file( 'my-hacks.php', '1.5.0' );
  760. array_unshift( $plugins, ABSPATH . 'my-hacks.php' );
  761. }
  762. if ( empty( $active_plugins ) || wp_installing() ) {
  763. return $plugins;
  764. }
  765. $network_plugins = is_multisite() ? wp_get_active_network_plugins() : false;
  766. foreach ( $active_plugins as $plugin ) {
  767. if ( ! validate_file( $plugin ) // $plugin must validate as file.
  768. && '.php' === substr( $plugin, -4 ) // $plugin must end with '.php'.
  769. && file_exists( WP_PLUGIN_DIR . '/' . $plugin ) // $plugin must exist.
  770. // Not already included as a network plugin.
  771. && ( ! $network_plugins || ! in_array( WP_PLUGIN_DIR . '/' . $plugin, $network_plugins, true ) )
  772. ) {
  773. $plugins[] = WP_PLUGIN_DIR . '/' . $plugin;
  774. }
  775. }
  776. /*
  777. * Remove plugins from the list of active plugins when we're on an endpoint
  778. * that should be protected against WSODs and the plugin is paused.
  779. */
  780. if ( wp_is_recovery_mode() ) {
  781. $plugins = wp_skip_paused_plugins( $plugins );
  782. }
  783. return $plugins;
  784. }
  785. /**
  786. * Filters a given list of plugins, removing any paused plugins from it.
  787. *
  788. * @since 5.2.0
  789. *
  790. * @param string[] $plugins Array of absolute plugin main file paths.
  791. * @return string[] Filtered array of plugins, without any paused plugins.
  792. */
  793. function wp_skip_paused_plugins( array $plugins ) {
  794. $paused_plugins = wp_paused_plugins()->get_all();
  795. if ( empty( $paused_plugins ) ) {
  796. return $plugins;
  797. }
  798. foreach ( $plugins as $index => $plugin ) {
  799. list( $plugin ) = explode( '/', plugin_basename( $plugin ) );
  800. if ( array_key_exists( $plugin, $paused_plugins ) ) {
  801. unset( $plugins[ $index ] );
  802. // Store list of paused plugins for displaying an admin notice.
  803. $GLOBALS['_paused_plugins'][ $plugin ] = $paused_plugins[ $plugin ];
  804. }
  805. }
  806. return $plugins;
  807. }
  808. /**
  809. * Retrieves an array of active and valid themes.
  810. *
  811. * While upgrading or installing WordPress, no themes are returned.
  812. *
  813. * @since 5.1.0
  814. * @access private
  815. *
  816. * @global string $pagenow The filename of the current screen.
  817. *
  818. * @return string[] Array of absolute paths to theme directories.
  819. */
  820. function wp_get_active_and_valid_themes() {
  821. global $pagenow;
  822. $themes = array();
  823. if ( wp_installing() && 'wp-activate.php' !== $pagenow ) {
  824. return $themes;
  825. }
  826. if ( TEMPLATEPATH !== STYLESHEETPATH ) {
  827. $themes[] = STYLESHEETPATH;
  828. }
  829. $themes[] = TEMPLATEPATH;
  830. /*
  831. * Remove themes from the list of active themes when we're on an endpoint
  832. * that should be protected against WSODs and the theme is paused.
  833. */
  834. if ( wp_is_recovery_mode() ) {
  835. $themes = wp_skip_paused_themes( $themes );
  836. // If no active and valid themes exist, skip loading themes.
  837. if ( empty( $themes ) ) {
  838. add_filter( 'wp_using_themes', '__return_false' );
  839. }
  840. }
  841. return $themes;
  842. }
  843. /**
  844. * Filters a given list of themes, removing any paused themes from it.
  845. *
  846. * @since 5.2.0
  847. *
  848. * @param string[] $themes Array of absolute theme directory paths.
  849. * @return string[] Filtered array of absolute paths to themes, without any paused themes.
  850. */
  851. function wp_skip_paused_themes( array $themes ) {
  852. $paused_themes = wp_paused_themes()->get_all();
  853. if ( empty( $paused_themes ) ) {
  854. return $themes;
  855. }
  856. foreach ( $themes as $index => $theme ) {
  857. $theme = basename( $theme );
  858. if ( array_key_exists( $theme, $paused_themes ) ) {
  859. unset( $themes[ $index ] );
  860. // Store list of paused themes for displaying an admin notice.
  861. $GLOBALS['_paused_themes'][ $theme ] = $paused_themes[ $theme ];
  862. }
  863. }
  864. return $themes;
  865. }
  866. /**
  867. * Is WordPress in Recovery Mode.
  868. *
  869. * In this mode, plugins or themes that cause WSODs will be paused.
  870. *
  871. * @since 5.2.0
  872. *
  873. * @return bool
  874. */
  875. function wp_is_recovery_mode() {
  876. return wp_recovery_mode()->is_active();
  877. }
  878. /**
  879. * Determines whether we are currently on an endpoint that should be protected against WSODs.
  880. *
  881. * @since 5.2.0
  882. *
  883. * @global string $pagenow The filename of the current screen.
  884. *
  885. * @return bool True if the current endpoint should be protected.
  886. */
  887. function is_protected_endpoint() {
  888. // Protect login pages.
  889. if ( isset( $GLOBALS['pagenow'] ) && 'wp-login.php' === $GLOBALS['pagenow'] ) {
  890. return true;
  891. }
  892. // Protect the admin backend.
  893. if ( is_admin() && ! wp_doing_ajax() ) {
  894. return true;
  895. }
  896. // Protect Ajax actions that could help resolve a fatal error should be available.
  897. if ( is_protected_ajax_action() ) {
  898. return true;
  899. }
  900. /**
  901. * Filters whether the current request is against a protected endpoint.
  902. *
  903. * This filter is only fired when an endpoint is requested which is not already protected by
  904. * WordPress core. As such, it exclusively allows providing further protected endpoints in
  905. * addition to the admin backend, login pages and protected Ajax actions.
  906. *
  907. * @since 5.2.0
  908. *
  909. * @param bool $is_protected_endpoint Whether the currently requested endpoint is protected.
  910. * Default false.
  911. */
  912. return (bool) apply_filters( 'is_protected_endpoint', false );
  913. }
  914. /**
  915. * Determines whether we are currently handling an Ajax action that should be protected against WSODs.
  916. *
  917. * @since 5.2.0
  918. *
  919. * @return bool True if the current Ajax action should be protected.
  920. */
  921. function is_protected_ajax_action() {
  922. if ( ! wp_doing_ajax() ) {
  923. return false;
  924. }
  925. if ( ! isset( $_REQUEST['action'] ) ) {
  926. return false;
  927. }
  928. $actions_to_protect = array(
  929. 'edit-theme-plugin-file', // Saving changes in the core code editor.
  930. 'heartbeat', // Keep the heart beating.
  931. 'install-plugin', // Installing a new plugin.
  932. 'install-theme', // Installing a new theme.
  933. 'search-plugins', // Searching in the list of plugins.
  934. 'search-install-plugins', // Searching for a plugin in the plugin install screen.
  935. 'update-plugin', // Update an existing plugin.
  936. 'update-theme', // Update an existing theme.
  937. );
  938. /**
  939. * Filters the array of protected Ajax actions.
  940. *
  941. * This filter is only fired when doing Ajax and the Ajax request has an 'action' property.
  942. *
  943. * @since 5.2.0
  944. *
  945. * @param string[] $actions_to_protect Array of strings with Ajax actions to protect.
  946. */
  947. $actions_to_protect = (array) apply_filters( 'wp_protected_ajax_actions', $actions_to_protect );
  948. if ( ! in_array( $_REQUEST['action'], $actions_to_protect, true ) ) {
  949. return false;
  950. }
  951. return true;
  952. }
  953. /**
  954. * Set internal encoding.
  955. *
  956. * In most cases the default internal encoding is latin1, which is
  957. * of no use, since we want to use the `mb_` functions for `utf-8` strings.
  958. *
  959. * @since 3.0.0
  960. * @access private
  961. */
  962. function wp_set_internal_encoding() {
  963. if ( function_exists( 'mb_internal_encoding' ) ) {
  964. $charset = get_option( 'blog_charset' );
  965. // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged
  966. if ( ! $charset || ! @mb_internal_encoding( $charset ) ) {
  967. mb_internal_encoding( 'UTF-8' );
  968. }
  969. }
  970. }
  971. /**
  972. * Add magic quotes to `$_GET`, `$_POST`, `$_COOKIE`, and `$_SERVER`.
  973. *
  974. * Also forces `$_REQUEST` to be `$_GET + $_POST`. If `$_SERVER`,
  975. * `$_COOKIE`, or `$_ENV` are needed, use those superglobals directly.
  976. *
  977. * @since 3.0.0
  978. * @access private
  979. */
  980. function wp_magic_quotes() {
  981. // Escape with wpdb.
  982. $_GET = add_magic_quotes( $_GET );
  983. $_POST = add_magic_quotes( $_POST );
  984. $_COOKIE = add_magic_quotes( $_COOKIE );
  985. $_SERVER = add_magic_quotes( $_SERVER );
  986. // Force REQUEST to be GET + POST.
  987. $_REQUEST = array_merge( $_GET, $_POST );
  988. }
  989. /**
  990. * Runs just before PHP shuts down execution.
  991. *
  992. * @since 1.2.0
  993. * @access private
  994. */
  995. function shutdown_action_hook() {
  996. /**
  997. * Fires just before PHP shuts down execution.
  998. *
  999. * @since 1.2.0
  1000. */
  1001. do_action( 'shutdown' );
  1002. wp_cache_close();
  1003. }
  1004. /**
  1005. * Copy an object.
  1006. *
  1007. * @since 2.7.0
  1008. * @deprecated 3.2.0
  1009. *
  1010. * @param object $object The object to clone.
  1011. * @return object The cloned object.
  1012. */
  1013. function wp_clone( $object ) {
  1014. // Use parens for clone to accommodate PHP 4. See #17880.
  1015. return clone( $object );
  1016. }
  1017. /**
  1018. * Determines whether the current request is for the login screen.
  1019. *
  1020. * @since 6.1.0
  1021. *
  1022. * @see wp_login_url()
  1023. *
  1024. * @return bool True if inside WordPress login screen, false otherwise.
  1025. */
  1026. function is_login() {
  1027. return false !== stripos( wp_login_url(), $_SERVER['SCRIPT_NAME'] );
  1028. }
  1029. /**
  1030. * Determines whether the current request is for an administrative interface page.
  1031. *
  1032. * Does not check if the user is an administrator; use current_user_can()
  1033. * for checking roles and capabilities.
  1034. *
  1035. * For more information on this and similar theme functions, check out
  1036. * the {@link https://developer.wordpress.org/themes/basics/conditional-tags/
  1037. * Conditional Tags} article in the Theme Developer Handbook.
  1038. *
  1039. * @since 1.5.1
  1040. *
  1041. * @global WP_Screen $current_screen WordPress current screen object.
  1042. *
  1043. * @return bool True if inside WordPress administration interface, false otherwise.
  1044. */
  1045. function is_admin() {
  1046. if ( isset( $GLOBALS['current_screen'] ) ) {
  1047. return $GLOBALS['current_screen']->in_admin();
  1048. } elseif ( defined( 'WP_ADMIN' ) ) {
  1049. return WP_ADMIN;
  1050. }
  1051. return false;
  1052. }
  1053. /**
  1054. * Determines whether the current request is for a site's administrative interface.
  1055. *
  1056. * e.g. `/wp-admin/`
  1057. *
  1058. * Does not check if the user is an administrator; use current_user_can()
  1059. * for checking roles and capabilities.
  1060. *
  1061. * @since 3.1.0
  1062. *
  1063. * @global WP_Screen $current_screen WordPress current screen object.
  1064. *
  1065. * @return bool True if inside WordPress site administration pages.
  1066. */
  1067. function is_blog_admin() {
  1068. if ( isset( $GLOBALS['current_screen'] ) ) {
  1069. return $GLOBALS['current_screen']->in_admin( 'site' );
  1070. } elseif ( defined( 'WP_BLOG_ADMIN' ) ) {
  1071. return WP_BLOG_ADMIN;
  1072. }
  1073. return false;
  1074. }
  1075. /**
  1076. * Determines whether the current request is for the network administrative interface.
  1077. *
  1078. * e.g. `/wp-admin/network/`
  1079. *
  1080. * Does not check if the user is an administrator; use current_user_can()
  1081. * for checking roles and capabilities.
  1082. *
  1083. * Does not check if the site is a Multisite network; use is_multisite()
  1084. * for checking if Multisite is enabled.
  1085. *
  1086. * @since 3.1.0
  1087. *
  1088. * @global WP_Screen $current_screen WordPress current screen object.
  1089. *
  1090. * @return bool True if inside WordPress network administration pages.
  1091. */
  1092. function is_network_admin() {
  1093. if ( isset( $GLOBALS['current_screen'] ) ) {
  1094. return $GLOBALS['current_screen']->in_admin( 'network' );
  1095. } elseif ( defined( 'WP_NETWORK_ADMIN' ) ) {
  1096. return WP_NETWORK_ADMIN;
  1097. }
  1098. return false;
  1099. }
  1100. /**
  1101. * Determines whether the current request is for a user admin screen.
  1102. *
  1103. * e.g. `/wp-admin/user/`
  1104. *
  1105. * Does not check if the user is an administrator; use current_user_can()
  1106. * for checking roles and capabilities.
  1107. *
  1108. * @since 3.1.0
  1109. *
  1110. * @global WP_Screen $current_screen WordPress current screen object.
  1111. *
  1112. * @return bool True if inside WordPress user administration pages.
  1113. */
  1114. function is_user_admin() {
  1115. if ( isset( $GLOBALS['current_screen'] ) ) {
  1116. return $GLOBALS['current_screen']->in_admin( 'user' );
  1117. } elseif ( defined( 'WP_USER_ADMIN' ) ) {
  1118. return WP_USER_ADMIN;
  1119. }
  1120. return false;
  1121. }
  1122. /**
  1123. * If Multisite is enabled.
  1124. *
  1125. * @since 3.0.0
  1126. *
  1127. * @return bool True if Multisite is enabled, false otherwise.
  1128. */
  1129. function is_multisite() {
  1130. if ( defined( 'MULTISITE' ) ) {
  1131. return MULTISITE;
  1132. }
  1133. if ( defined( 'SUBDOMAIN_INSTALL' ) || defined( 'VHOST' ) || defined( 'SUNRISE' ) ) {
  1134. return true;
  1135. }
  1136. return false;
  1137. }
  1138. /**
  1139. * Retrieve the current site ID.
  1140. *
  1141. * @since 3.1.0
  1142. *
  1143. * @global int $blog_id
  1144. *
  1145. * @return int Site ID.
  1146. */
  1147. function get_current_blog_id() {
  1148. global $blog_id;
  1149. return absint( $blog_id );
  1150. }
  1151. /**
  1152. * Retrieves the current network ID.
  1153. *
  1154. * @since 4.6.0
  1155. *
  1156. * @return int The ID of the current network.
  1157. */
  1158. function get_current_network_id() {
  1159. if ( ! is_multisite() ) {
  1160. return 1;
  1161. }
  1162. $current_network = get_network();
  1163. if ( ! isset( $current_network->id ) ) {
  1164. return get_main_network_id();
  1165. }
  1166. return absint( $current_network->id );
  1167. }
  1168. /**
  1169. * Attempt an early load of translations.
  1170. *
  1171. * Used for errors encountered during the initial loading process, before
  1172. * the locale has been properly detected and loaded.
  1173. *
  1174. * Designed for unusual load sequences (like setup-config.php) or for when
  1175. * the script will then terminate with an error, otherwise there is a risk
  1176. * that a file can be double-included.
  1177. *
  1178. * @since 3.4.0
  1179. * @access private
  1180. *
  1181. * @global WP_Textdomain_Registry $wp_textdomain_registry WordPress Textdomain Registry.
  1182. * @global WP_Locale $wp_locale WordPress date and time locale object.
  1183. */
  1184. function wp_load_translations_early() {
  1185. global $wp_locale, $wp_textdomain_registry;
  1186. static $loaded = false;
  1187. if ( $loaded ) {
  1188. return;
  1189. }
  1190. $loaded = true;
  1191. if ( function_exists( 'did_action' ) && did_action( 'init' ) ) {
  1192. return;
  1193. }
  1194. // We need $wp_local_package.
  1195. require ABSPATH . WPINC . '/version.php';
  1196. // Translation and localization.
  1197. require_once ABSPATH . WPINC . '/pomo/mo.php';
  1198. require_once ABSPATH . WPINC . '/l10n.php';
  1199. require_once ABSPATH . WPINC . '/class-wp-textdomain-registry.php';
  1200. require_once ABSPATH . WPINC . '/class-wp-locale.php';
  1201. require_once ABSPATH . WPINC . '/class-wp-locale-switcher.php';
  1202. // General libraries.
  1203. require_once ABSPATH . WPINC . '/plugin.php';
  1204. $locales = array();
  1205. $locations = array();
  1206. if ( ! $wp_textdomain_registry instanceof WP_Textdomain_Registry ) {
  1207. $wp_textdomain_registry = new WP_Textdomain_Registry();
  1208. }
  1209. while ( true ) {
  1210. if ( defined( 'WPLANG' ) ) {
  1211. if ( '' === WPLANG ) {
  1212. break;
  1213. }
  1214. $locales[] = WPLANG;
  1215. }
  1216. if ( isset( $wp_local_package ) ) {
  1217. $locales[] = $wp_local_package;
  1218. }
  1219. if ( ! $locales ) {
  1220. break;
  1221. }
  1222. if ( defined( 'WP_LANG_DIR' ) && @is_dir( WP_LANG_DIR ) ) {
  1223. $locations[] = WP_LANG_DIR;
  1224. }
  1225. if ( defined( 'WP_CONTENT_DIR' ) && @is_dir( WP_CONTENT_DIR . '/languages' ) ) {
  1226. $locations[] = WP_CONTENT_DIR . '/languages';
  1227. }
  1228. if ( @is_dir( ABSPATH . 'wp-content/languages' ) ) {
  1229. $locations[] = ABSPATH . 'wp-content/languages';
  1230. }
  1231. if ( @is_dir( ABSPATH . WPINC . '/languages' ) ) {
  1232. $locations[] = ABSPATH . WPINC . '/languages';
  1233. }
  1234. if ( ! $locations ) {
  1235. break;
  1236. }
  1237. $locations = array_unique( $locations );
  1238. foreach ( $locales as $locale ) {
  1239. foreach ( $locations as $location ) {
  1240. if ( file_exists( $location . '/' . $locale . '.mo' ) ) {
  1241. load_textdomain( 'default', $location . '/' . $locale . '.mo', $locale );
  1242. if ( defined( 'WP_SETUP_CONFIG' ) && file_exists( $location . '/admin-' . $locale . '.mo' ) ) {
  1243. load_textdomain( 'default', $location . '/admin-' . $locale . '.mo', $locale );
  1244. }
  1245. break 2;
  1246. }
  1247. }
  1248. }
  1249. break;
  1250. }
  1251. $wp_locale = new WP_Locale();
  1252. }
  1253. /**
  1254. * Check or set whether WordPress is in "installation" mode.
  1255. *
  1256. * If the `WP_INSTALLING` constant is defined during the bootstrap, `wp_installing()` will default to `true`.
  1257. *
  1258. * @since 4.4.0
  1259. *
  1260. * @param bool $is_installing Optional. True to set WP into Installing mode, false to turn Installing mode off.
  1261. * Omit this parameter if you only want to fetch the current status.
  1262. * @return bool True if WP is installing, otherwise false. When a `$is_installing` is passed, the function will
  1263. * report whether WP was in installing mode prior to the change to `$is_installing`.
  1264. */
  1265. function wp_installing( $is_installing = null ) {
  1266. static $installing = null;
  1267. // Support for the `WP_INSTALLING` constant, defined before WP is loaded.
  1268. if ( is_null( $installing ) ) {
  1269. $installing = defined( 'WP_INSTALLING' ) && WP_INSTALLING;
  1270. }
  1271. if ( ! is_null( $is_installing ) ) {
  1272. $old_installing = $installing;
  1273. $installing = $is_installing;
  1274. return (bool) $old_installing;
  1275. }
  1276. return (bool) $installing;
  1277. }
  1278. /**
  1279. * Determines if SSL is used.
  1280. *
  1281. * @since 2.6.0
  1282. * @since 4.6.0 Moved from functions.php to load.php.
  1283. *
  1284. * @return bool True if SSL, otherwise false.
  1285. */
  1286. function is_ssl() {
  1287. if ( isset( $_SERVER['HTTPS'] ) ) {
  1288. if ( 'on' === strtolower( $_SERVER['HTTPS'] ) ) {
  1289. return true;
  1290. }
  1291. if ( '1' == $_SERVER['HTTPS'] ) {
  1292. return true;
  1293. }
  1294. } elseif ( isset( $_SERVER['SERVER_PORT'] ) && ( '443' == $_SERVER['SERVER_PORT'] ) ) {
  1295. return true;
  1296. }
  1297. return false;
  1298. }
  1299. /**
  1300. * Converts a shorthand byte value to an integer byte value.
  1301. *
  1302. * @since 2.3.0
  1303. * @since 4.6.0 Moved from media.php to load.php.
  1304. *
  1305. * @link https://www.php.net/manual/en/function.ini-get.php
  1306. * @link https://www.php.net/manual/en/faq.using.php#faq.using.shorthandbytes
  1307. *
  1308. * @param string $value A (PHP ini) byte value, either shorthand or ordinary.
  1309. * @return int An integer byte value.
  1310. */
  1311. function wp_convert_hr_to_bytes( $value ) {
  1312. $value = strtolower( trim( $value ) );
  1313. $bytes = (int) $value;
  1314. if ( false !== strpos( $value, 'g' ) ) {
  1315. $bytes *= GB_IN_BYTES;
  1316. } elseif ( false !== strpos( $value, 'm' ) ) {
  1317. $bytes *= MB_IN_BYTES;
  1318. } elseif ( false !== strpos( $value, 'k' ) ) {
  1319. $bytes *= KB_IN_BYTES;
  1320. }
  1321. // Deal with large (float) values which run into the maximum integer size.
  1322. return min( $bytes, PHP_INT_MAX );
  1323. }
  1324. /**
  1325. * Determines whether a PHP ini value is changeable at runtime.
  1326. *
  1327. * @since 4.6.0
  1328. *
  1329. * @link https://www.php.net/manual/en/function.ini-get-all.php
  1330. *
  1331. * @param string $setting The name of the ini setting to check.
  1332. * @return bool True if the value is changeable at runtime. False otherwise.
  1333. */
  1334. function wp_is_ini_value_changeable( $setting ) {
  1335. static $ini_all;
  1336. if ( ! isset( $ini_all ) ) {
  1337. $ini_all = false;
  1338. // Sometimes `ini_get_all()` is disabled via the `disable_functions` option for "security purposes".
  1339. if ( function_exists( 'ini_get_all' ) ) {
  1340. $ini_all = ini_get_all();
  1341. }
  1342. }
  1343. // Bit operator to workaround https://bugs.php.net/bug.php?id=44936 which changes access level to 63 in PHP 5.2.6 - 5.2.17.
  1344. if ( isset( $ini_all[ $setting ]['access'] ) && ( INI_ALL === ( $ini_all[ $setting ]['access'] & 7 ) || INI_USER === ( $ini_all[ $setting ]['access'] & 7 ) ) ) {
  1345. return true;
  1346. }
  1347. // If we were unable to retrieve the details, fail gracefully to assume it's changeable.
  1348. if ( ! is_array( $ini_all ) ) {
  1349. return true;
  1350. }
  1351. return false;
  1352. }
  1353. /**
  1354. * Determines whether the current request is a WordPress Ajax request.
  1355. *
  1356. * @since 4.7.0
  1357. *
  1358. * @return bool True if it's a WordPress Ajax request, false otherwise.
  1359. */
  1360. function wp_doing_ajax() {
  1361. /**
  1362. * Filters whether the current request is a WordPress Ajax request.
  1363. *
  1364. * @since 4.7.0
  1365. *
  1366. * @param bool $wp_doing_ajax Whether the current request is a WordPress Ajax request.
  1367. */
  1368. return apply_filters( 'wp_doing_ajax', defined( 'DOING_AJAX' ) && DOING_AJAX );
  1369. }
  1370. /**
  1371. * Determines whether the current request should use themes.
  1372. *
  1373. * @since 5.1.0
  1374. *
  1375. * @return bool True if themes should be used, false otherwise.
  1376. */
  1377. function wp_using_themes() {
  1378. /**
  1379. * Filters whether the current request should use themes.
  1380. *
  1381. * @since 5.1.0
  1382. *
  1383. * @param bool $wp_using_themes Whether the current request should use themes.
  1384. */
  1385. return apply_filters( 'wp_using_themes', defined( 'WP_USE_THEMES' ) && WP_USE_THEMES );
  1386. }
  1387. /**
  1388. * Determines whether the current request is a WordPress cron request.
  1389. *
  1390. * @since 4.8.0
  1391. *
  1392. * @return bool True if it's a WordPress cron request, false otherwise.
  1393. */
  1394. function wp_doing_cron() {
  1395. /**
  1396. * Filters whether the current request is a WordPress cron request.
  1397. *
  1398. * @since 4.8.0
  1399. *
  1400. * @param bool $wp_doing_cron Whether the current request is a WordPress cron request.
  1401. */
  1402. return apply_filters( 'wp_doing_cron', defined( 'DOING_CRON' ) && DOING_CRON );
  1403. }
  1404. /**
  1405. * Checks whether the given variable is a WordPress Error.
  1406. *
  1407. * Returns whether `$thing` is an instance of the `WP_Error` class.
  1408. *
  1409. * @since 2.1.0
  1410. *
  1411. * @param mixed $thing The variable to check.
  1412. * @return bool Whether the variable is an instance of WP_Error.
  1413. */
  1414. function is_wp_error( $thing ) {
  1415. $is_wp_error = ( $thing instanceof WP_Error );
  1416. if ( $is_wp_error ) {
  1417. /**
  1418. * Fires when `is_wp_error()` is called and its parameter is an instance of `WP_Error`.
  1419. *
  1420. * @since 5.6.0
  1421. *
  1422. * @param WP_Error $thing The error object passed to `is_wp_error()`.
  1423. */
  1424. do_action( 'is_wp_error_instance', $thing );
  1425. }
  1426. return $is_wp_error;
  1427. }
  1428. /**
  1429. * Determines whether file modifications are allowed.
  1430. *
  1431. * @since 4.8.0
  1432. *
  1433. * @param string $context The usage context.
  1434. * @return bool True if file modification is allowed, false otherwise.
  1435. */
  1436. function wp_is_file_mod_allowed( $context ) {
  1437. /**
  1438. * Filters whether file modifications are allowed.
  1439. *
  1440. * @since 4.8.0
  1441. *
  1442. * @param bool $file_mod_allowed Whether file modifications are allowed.
  1443. * @param string $context The usage context.
  1444. */
  1445. return apply_filters( 'file_mod_allowed', ! defined( 'DISALLOW_FILE_MODS' ) || ! DISALLOW_FILE_MODS, $context );
  1446. }
  1447. /**
  1448. * Start scraping edited file errors.
  1449. *
  1450. * @since 4.9.0
  1451. */
  1452. function wp_start_scraping_edited_file_errors() {
  1453. if ( ! isset( $_REQUEST['wp_scrape_key'] ) || ! isset( $_REQUEST['wp_scrape_nonce'] ) ) {
  1454. return;
  1455. }
  1456. $key = substr( sanitize_key( wp_unslash( $_REQUEST['wp_scrape_key'] ) ), 0, 32 );
  1457. $nonce = wp_unslash( $_REQUEST['wp_scrape_nonce'] );
  1458. if ( get_transient( 'scrape_key_' . $key ) !== $nonce ) {
  1459. echo "###### wp_scraping_result_start:$key ######";
  1460. echo wp_json_encode(
  1461. array(
  1462. 'code' => 'scrape_nonce_failure',
  1463. 'message' => __( 'Scrape key check failed. Please try again.' ),
  1464. )
  1465. );
  1466. echo "###### wp_scraping_result_end:$key ######";
  1467. die();
  1468. }
  1469. if ( ! defined( 'WP_SANDBOX_SCRAPING' ) ) {
  1470. define( 'WP_SANDBOX_SCRAPING', true );
  1471. }
  1472. register_shutdown_function( 'wp_finalize_scraping_edited_file_errors', $key );
  1473. }
  1474. /**
  1475. * Finalize scraping for edited file errors.
  1476. *
  1477. * @since 4.9.0
  1478. *
  1479. * @param string $scrape_key Scrape key.
  1480. */
  1481. function wp_finalize_scraping_edited_file_errors( $scrape_key ) {
  1482. $error = error_get_last();
  1483. echo "\n###### wp_scraping_result_start:$scrape_key ######\n";
  1484. if ( ! empty( $error ) && in_array( $error['type'], array( E_CORE_ERROR, E_COMPILE_ERROR, E_ERROR, E_PARSE, E_USER_ERROR, E_RECOVERABLE_ERROR ), true ) ) {
  1485. $error = str_replace( ABSPATH, '', $error );
  1486. echo wp_json_encode( $error );
  1487. } else {
  1488. echo wp_json_encode( true );
  1489. }
  1490. echo "\n###### wp_scraping_result_end:$scrape_key ######\n";
  1491. }
  1492. /**
  1493. * Checks whether current request is a JSON request, or is expecting a JSON response.
  1494. *
  1495. * @since 5.0.0
  1496. *
  1497. * @return bool True if `Accepts` or `Content-Type` headers contain `application/json`.
  1498. * False otherwise.
  1499. */
  1500. function wp_is_json_request() {
  1501. if ( isset( $_SERVER['HTTP_ACCEPT'] ) && wp_is_json_media_type( $_SERVER['HTTP_ACCEPT'] ) ) {
  1502. return true;
  1503. }
  1504. if ( isset( $_SERVER['CONTENT_TYPE'] ) && wp_is_json_media_type( $_SERVER['CONTENT_TYPE'] ) ) {
  1505. return true;
  1506. }
  1507. return false;
  1508. }
  1509. /**
  1510. * Checks whether current request is a JSONP request, or is expecting a JSONP response.
  1511. *
  1512. * @since 5.2.0
  1513. *
  1514. * @return bool True if JSONP request, false otherwise.
  1515. */
  1516. function wp_is_jsonp_request() {
  1517. if ( ! isset( $_GET['_jsonp'] ) ) {
  1518. return false;
  1519. }
  1520. if ( ! function_exists( 'wp_check_jsonp_callback' ) ) {
  1521. require_once ABSPATH . WPINC . '/functions.php';
  1522. }
  1523. $jsonp_callback = $_GET['_jsonp'];
  1524. if ( ! wp_check_jsonp_callback( $jsonp_callback ) ) {
  1525. return false;
  1526. }
  1527. /** This filter is documented in wp-includes/rest-api/class-wp-rest-server.php */
  1528. $jsonp_enabled = apply_filters( 'rest_jsonp_enabled', true );
  1529. return $jsonp_enabled;
  1530. }
  1531. /**
  1532. * Checks whether a string is a valid JSON Media Type.
  1533. *
  1534. * @since 5.6.0
  1535. *
  1536. * @param string $media_type A Media Type string to check.
  1537. * @return bool True if string is a valid JSON Media Type.
  1538. */
  1539. function wp_is_json_media_type( $media_type ) {
  1540. static $cache = array();
  1541. if ( ! isset( $cache[ $media_type ] ) ) {
  1542. $cache[ $media_type ] = (bool) preg_match( '/(^|\s|,)application\/([\w!#\$&-\^\.\+]+\+)?json(\+oembed)?($|\s|;|,)/i', $media_type );
  1543. }
  1544. return $cache[ $media_type ];
  1545. }
  1546. /**
  1547. * Checks whether current request is an XML request, or is expecting an XML response.
  1548. *
  1549. * @since 5.2.0
  1550. *
  1551. * @return bool True if `Accepts` or `Content-Type` headers contain `text/xml`
  1552. * or one of the related MIME types. False otherwise.
  1553. */
  1554. function wp_is_xml_request() {
  1555. $accepted = array(
  1556. 'text/xml',
  1557. 'application/rss+xml',
  1558. 'application/atom+xml',
  1559. 'application/rdf+xml',
  1560. 'text/xml+oembed',
  1561. 'application/xml+oembed',
  1562. );
  1563. if ( isset( $_SERVER['HTTP_ACCEPT'] ) ) {
  1564. foreach ( $accepted as $type ) {
  1565. if ( false !== strpos( $_SERVER['HTTP_ACCEPT'], $type ) ) {
  1566. return true;
  1567. }
  1568. }
  1569. }
  1570. if ( isset( $_SERVER['CONTENT_TYPE'] ) && in_array( $_SERVER['CONTENT_TYPE'], $accepted, true ) ) {
  1571. return true;
  1572. }
  1573. return false;
  1574. }
  1575. /**
  1576. * Checks if this site is protected by HTTP Basic Auth.
  1577. *
  1578. * At the moment, this merely checks for the present of Basic Auth credentials. Therefore, calling
  1579. * this function with a context different from the current context may give inaccurate results.
  1580. * In a future release, this evaluation may be made more robust.
  1581. *
  1582. * Currently, this is only used by Application Passwords to prevent a conflict since it also utilizes
  1583. * Basic Auth.
  1584. *
  1585. * @since 5.6.1
  1586. *
  1587. * @global string $pagenow The filename of the current screen.
  1588. *
  1589. * @param string $context The context to check for protection. Accepts 'login', 'admin', and 'front'.
  1590. * Defaults to the current context.
  1591. * @return bool Whether the site is protected by Basic Auth.
  1592. */
  1593. function wp_is_site_protected_by_basic_auth( $context = '' ) {
  1594. global $pagenow;
  1595. if ( ! $context ) {
  1596. if ( 'wp-login.php' === $pagenow ) {
  1597. $context = 'login';
  1598. } elseif ( is_admin() ) {
  1599. $context = 'admin';
  1600. } else {
  1601. $context = 'front';
  1602. }
  1603. }
  1604. $is_protected = ! empty( $_SERVER['PHP_AUTH_USER'] ) || ! empty( $_SERVER['PHP_AUTH_PW'] );
  1605. /**
  1606. * Filters whether a site is protected by HTTP Basic Auth.
  1607. *
  1608. * @since 5.6.1
  1609. *
  1610. * @param bool $is_protected Whether the site is protected by Basic Auth.
  1611. * @param string $context The context to check for protection. One of 'login', 'admin', or 'front'.
  1612. */
  1613. return apply_filters( 'wp_is_site_protected_by_basic_auth', $is_protected, $context );
  1614. }