<?php
/**
* HTTPS migration functions.
*
* @package WordPress
* @since 5.7.0
*/
/**
* Checks whether WordPress should replace old HTTP URLs to the site with their HTTPS counterpart.
*
* If a WordPress site had its URL changed from HTTP to HTTPS, by default this will return `true`, causing WordPress to
* add frontend filters to replace insecure site URLs that may be present in older database content. The
* {@see 'wp_should_replace_insecure_home_url'} filter can be used to modify that behavior.
*
* @since 5.7.0
*
* @return bool True if insecure URLs should replaced, false otherwise.
*/
function wp_should_replace_insecure_home_url() {
$should_replace_insecure_home_url = wp_is_using_https()
&& get_option( 'https_migration_required' )
// For automatic replacement, both 'home' and 'siteurl' need to not only use HTTPS, they also need to be using
// the same domain.
&& wp_parse_url( home_url(), PHP_URL_HOST ) === wp_parse_url( site_url(), PHP_URL_HOST );
/**
* Filters whether WordPress should replace old HTTP URLs to the site with their HTTPS counterpart.
*
* If a WordPress site had its URL changed from HTTP to HTTPS, by default this will return `true`. This filter can
* be used to disable that behavior, e.g. after having replaced URLs manually in the database.
*
* @since 5.7.0
*
* @param bool $should_replace_insecure_home_url Whether insecure HTTP URLs to the site should be replaced.
*/
return apply_filters( 'wp_should_replace_insecure_home_url', $should_replace_insecure_home_url );
}
/**
* Replaces insecure HTTP URLs to the site in the given content, if configured to do so.
*
* This function replaces all occurrences of the HTTP version of the site's URL with its HTTPS counterpart, if
* determined via {@see wp_should_replace_insecure_home_url()}.
*
* @since 5.7.0
*
* @param string $content Content to replace URLs in.
* @return string Filtered content.
*/
function wp_replace_insecure_home_url( $content ) {
if ( ! wp_should_replace_insecure_home_url() ) {
return $content;
}
$https_url = home_url( '', 'https' );
$http_url = str_replace( 'https://', 'http://', $https_url );
// Also replace potentially escaped URL.
$escaped_https_url = str_replace( '/', '\/', $https_url );
$escaped_http_url = str_replace( '/', '\/', $http_url );
return str_replace(
array(
$http_url,
$escaped_http_url,
),
array(
$https_url,
$escaped_https_url,
),
$content
);
}
/**
* Update the 'home' and 'siteurl' option to use the HTTPS variant of their URL.
*
* If this update does not result in WordPress recognizing that the site is now using HTTPS (e.g. due to constants
* overriding the URLs used), the changes will be reverted. In such a case the function will return false.
*
* @since 5.7.0
*
* @return bool True on success, false on failure.
*/
function wp_update_urls_to_https() {
// Get current URL options.
$orig_home = get_option( 'home' );
$orig_siteurl = get_option( 'siteurl' );
// Get current URL options, replacing HTTP with HTTPS.
$home = str_replace( 'http://', 'https://', $orig_home );
$siteurl = str_replace( 'http://', 'https://', $orig_siteurl );
// Update the options.
update_option( 'home', $home );
update_option( 'siteurl', $siteurl );
if ( ! wp_is_using_https() ) {
/*
* If this did not result in the site recognizing HTTPS as being used,
* revert the change and return false.
*/
update_option( 'home', $orig_home );
update_option( 'siteurl', $orig_siteurl );
return false;
}
// Otherwise the URLs were successfully changed to use HTTPS.
return true;
}
/**
* Updates the 'https_migration_required' option if needed when the given URL has been updated from HTTP to HTTPS.
*
* If this is a fresh site, a migration will not be required, so the option will be set as `false`.
*
* This is hooked into the {@see 'update_option_home'} action.
*
* @since 5.7.0
* @access private
*
* @param mixed $old_url Previous value of the URL option.
* @param mixed $new_url New value of the URL option.
*/
function wp_update_https_migration_required( $old_url, $new_url ) {
// Do nothing if WordPress is being installed.
if ( wp_installing() ) {
return;
}
// Delete/reset the option if the new URL is not the HTTPS version of the old URL.
if ( untrailingslashit( (string) $old_url ) !== str_replace( 'https://', 'http://', untrailingslashit( (string) $new_url ) ) ) {
delete_option( 'https_migration_required' );
return;
}
// If this is a fresh site, there is no content to migrate, so do not require migration.
$https_migration_required = get_option( 'fresh_site' ) ? false : true;
update_option( 'https_migration_required', $https_migration_required );
}
Directory Contents
Dirs: 28 × Files: 237
!"#$%&'(()*+,-./00123456789 t\
wIDATx ]ys 47Y ƒ - " Rv < f{Ɛ $k l L > L ~h^ 1 [ r G t&h
l F z3O Y ! p A(_g̷ E8 )S 8 c Kb"z ~ 5 J xAL WU < *
5 m;W a pB h ~P J
2 3 6 ҙ .Ƹ P i 4g
F R L P ΪK/D M v (a3
k J
Œ4N5* SH ` SdJ z O J Xՠ V>u ߱ BE&L b2 ?2` tX+ c CB A$ i b C ĀMB E : / # Dx &l =q Ty 0 \p I ( L Ǎ { e
4k ;`u^ヲ eP!( d { )T A 8 O;Ě n >;s6 ! :Nx `[S D HU ~ qJ F}
a g*D 49 / pn k h (t 8NxƐF _!r չ7
ZR R q/5") Ӎ NY 0 x sZ! o
fu , K"$ ? pg 㕣= 1» {h " fh7
y } +7 $ y
" X ą - G P u 4 m >J 5 L =V ' ^@I p ?MS xЌ XV P ! h "C NS9B8̢ ]!K e zA , ӏkbY !< XQ ٿyS| *" f { w 4@[S <
# 0 ! js [m =,~ o
"ݎ DHf Wo $ g ! Vԅ t mB /y Wf V4 c+@x? B ~u " xUN e 0 BĂ)
~J pz!
7y6]l Ԥ@ P a< O /DHC `≻ N m"$ 0ObB }{ x AO FCG DR ^ "B { WDH UR l@ T
# +"d T ; 0 i D}. 7 ` ' ] w rE &S i ƕiTD EL P _ u h $ Ա FG wVD G L R Zf ' .!] J /ZR oGЍs Mr Ĥ ʬ 3 Q [3 cL `^ p +
( F;# B 5 ' 2Y f [ ϶R0e } E 7
6M aۮ H <& n % L] E}Up x紉, Uw' Q Ǯշo k ވۙ 0N94 VX5 xEDE l D #֤ } C o )W : ^ s 9 bRf iX5u ཱི 4 :[ T 1. | [E 2ؽ Iy\ : o x K G 5
ylP ' uK E
ftb/i[3 .g _ [3M n
G, #NwQ5~
ؚ) | n =Ц"x qg gB ` 듘 ~ x w ?
?
R~ _ u. &VQ K˻ H C ( TN˄+ `C dA nB D 3"Z G ê ^k H_ /- ~ " R_ .8 Z_ 6@ o xg uP ? 3լ @7AM! E7^
- =V L x g-D0 CtmW 7 O G _ WD0 g C w1 r
d w : a | \ *" f nֳ ^ H# f L ` Z ۽hV }S F r0Ù Bć5r] @! NL iQ]{s^=4 d WD " " M;
t" 8 5 e dL| "-*st" ) SWD ?R[S e ooF 20.D ? bo =) A i o d ģ ZҰaO
@E =) i D a &ܟa CϞ y6 ,<%{^x%{f8? `iw^ ?/
M
* IEND B`