[ Index ]

PHP Cross Reference of WordPress Trunk (Updated Daily)

Search

title

Body

[close]

/ -> wp-trackback.php (source)

   1  <?php
   2  /**
   3   * Handle Trackbacks and Pingbacks Sent to WordPress
   4   *
   5   * @since 0.71
   6   *
   7   * @package WordPress
   8   * @subpackage Trackbacks
   9   */
  10  
  11  if ( empty( $wp ) ) {
  12      require_once  __DIR__ . '/wp-load.php';
  13      wp( array( 'tb' => '1' ) );
  14  }
  15  
  16  // Always run as an unauthenticated user.
  17  wp_set_current_user( 0 );
  18  
  19  /**
  20   * Response to a trackback.
  21   *
  22   * Responds with an error or success XML message.
  23   *
  24   * @since 0.71
  25   *
  26   * @param int|bool $error         Whether there was an error.
  27   *                                Default 0. Accepts 0 or 1, true or false.
  28   * @param string   $error_message Error message if an error occurred. Default empty string.
  29   * @return void Never returns if `$error` is truthy, as the function dies after
  30   *              sending the error response.
  31   * @phpstan-return ( $error is 0|false ? void : never )
  32   */
  33  function trackback_response( $error = 0, $error_message = '' ) {
  34      header( 'Content-Type: text/xml; charset=' . get_option( 'blog_charset' ) );
  35  
  36      if ( $error ) {
  37          echo '<?xml version="1.0" encoding="utf-8"?' . ">\n";
  38          echo "<response>\n";
  39          echo "<error>1</error>\n";
  40          echo '<message>' . esc_xml( $error_message ) . "</message>\n";
  41          echo '</response>';
  42          die();
  43      } else {
  44          echo '<?xml version="1.0" encoding="utf-8"?' . ">\n";
  45          echo "<response>\n";
  46          echo "<error>0</error>\n";
  47          echo '</response>';
  48      }
  49  }
  50  
  51  if ( ! isset( $_GET['tb_id'] ) || ! $_GET['tb_id'] ) {
  52      $post_id = explode( '/', $_SERVER['REQUEST_URI'] );
  53      $post_id = (int) array_last( $post_id );
  54  }
  55  
  56  $trackback_url = isset( $_POST['url'] ) ? sanitize_url( $_POST['url'] ) : '';
  57  $charset       = isset( $_POST['charset'] ) ? sanitize_text_field( $_POST['charset'] ) : '';
  58  
  59  // These three are stripslashed here so they can be properly escaped after mb_convert_encoding().
  60  $title     = isset( $_POST['title'] ) ? sanitize_text_field( wp_unslash( $_POST['title'] ) ) : '';
  61  $excerpt   = isset( $_POST['excerpt'] ) ? sanitize_textarea_field( wp_unslash( $_POST['excerpt'] ) ) : '';
  62  $blog_name = isset( $_POST['blog_name'] ) ? sanitize_text_field( wp_unslash( $_POST['blog_name'] ) ) : '';
  63  
  64  if ( $charset ) {
  65      $charset = str_replace( array( ',', ' ' ), '', strtoupper( trim( $charset ) ) );
  66  
  67      // Validate the specified "sender" charset is available on the receiving site.
  68      if ( function_exists( 'mb_list_encodings' ) && ! in_array( $charset, mb_list_encodings(), true ) ) {
  69          $charset = '';
  70      }
  71  }
  72  
  73  if ( ! $charset ) {
  74      $charset = 'ASCII, UTF-8, ISO-8859-1, JIS, EUC-JP, SJIS';
  75  }
  76  
  77  // No valid uses for UTF-7.
  78  if ( str_contains( $charset, 'UTF-7' ) ) {
  79      die;
  80  }
  81  
  82  // For international trackbacks.
  83  if ( function_exists( 'mb_convert_encoding' ) ) {
  84      $title     = mb_convert_encoding( $title, get_option( 'blog_charset' ), $charset );
  85      $excerpt   = mb_convert_encoding( $excerpt, get_option( 'blog_charset' ), $charset );
  86      $blog_name = mb_convert_encoding( $blog_name, get_option( 'blog_charset' ), $charset );
  87  }
  88  
  89  // Escape values to use in the trackback.
  90  $title     = wp_slash( $title );
  91  $excerpt   = wp_slash( $excerpt );
  92  $blog_name = wp_slash( $blog_name );
  93  
  94  /**
  95   * @global wpdb      $wpdb  WordPress database abstraction object.
  96   * @global WP_Post[] $posts Array of post objects.
  97   */
  98  global $wpdb, $posts;
  99  
 100  if ( is_single() || is_page() ) {
 101      $post_id = $posts[0]->ID;
 102  }
 103  
 104  if ( ! isset( $post_id ) || ! (int) $post_id ) {
 105      trackback_response( 1, __( 'I really need an ID for this to work.' ) );
 106  }
 107  
 108  if ( empty( $title ) && empty( $trackback_url ) && empty( $blog_name ) ) {
 109      // If it doesn't look like a trackback at all.
 110      wp_redirect( get_permalink( $post_id ) );
 111      exit;
 112  }
 113  
 114  if ( ! empty( $trackback_url ) && ! empty( $title ) ) {
 115      /**
 116       * Fires before the trackback is added to a post.
 117       *
 118       * @since 4.7.0
 119       *
 120       * @param int    $post_id       Post ID related to the trackback.
 121       * @param string $trackback_url Trackback URL.
 122       * @param string $charset       Character set.
 123       * @param string $title         Trackback title.
 124       * @param string $excerpt       Trackback excerpt.
 125       * @param string $blog_name     Site name.
 126       */
 127      do_action( 'pre_trackback_post', $post_id, $trackback_url, $charset, $title, $excerpt, $blog_name );
 128  
 129      header( 'Content-Type: text/xml; charset=' . get_option( 'blog_charset' ) );
 130  
 131      if ( ! pings_open( $post_id ) ) {
 132          trackback_response( 1, __( 'Sorry, trackbacks are closed for this item.' ) );
 133      }
 134  
 135      $title   = wp_html_excerpt( $title, 250, '&#8230;' );
 136      $excerpt = wp_html_excerpt( $excerpt, 252, '&#8230;' );
 137  
 138      $comment_post_id      = (int) $post_id;
 139      $comment_author       = $blog_name;
 140      $comment_author_email = '';
 141      $comment_author_url   = $trackback_url;
 142      $comment_content      = "<strong>$title</strong>\n\n$excerpt";
 143      $comment_type         = 'trackback';
 144  
 145      $dupe = $wpdb->get_results(
 146          $wpdb->prepare(
 147              "SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_author_url = %s",
 148              $comment_post_id,
 149              $comment_author_url
 150          )
 151      );
 152  
 153      if ( $dupe ) {
 154          trackback_response( 1, __( 'There is already a ping from that URL for this post.' ) );
 155      }
 156  
 157      $commentdata = array(
 158          'comment_post_ID' => $comment_post_id,
 159      );
 160  
 161      $commentdata += compact(
 162          'comment_author',
 163          'comment_author_email',
 164          'comment_author_url',
 165          'comment_content',
 166          'comment_type'
 167      );
 168  
 169      $result = wp_new_comment( $commentdata );
 170  
 171      if ( is_wp_error( $result ) ) {
 172          trackback_response( 1, $result->get_error_message() );
 173      }
 174  
 175      $trackback_id = $wpdb->insert_id;
 176  
 177      /**
 178       * Fires after a trackback is added to a post.
 179       *
 180       * @since 1.2.0
 181       *
 182       * @param int $trackback_id Trackback ID.
 183       */
 184      do_action( 'trackback_post', $trackback_id );
 185  
 186      trackback_response( 0 );
 187  }


Generated : Fri Oct 9 08:20:33 2026 Cross-referenced by PHPXref