Auto approve self pings follow up - #12928
Conversation
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
jeremyfelt
left a comment
There was a problem hiding this comment.
I'm also curious whether url_to_postid() is good enough or if some additional checks could help. And whether there's a better spot for the filter in general. I'll have a better opinion to share tomorrow :)
| * @param string $url The URL the pingback was sent from. | ||
| */ | ||
| return (bool) apply_filters( 'auto_approve_pingback', $approve_pingback, $source_id, $url ); | ||
| return (bool) apply_filters( 'wp_auto_approve_pingback', $approve_pingback, $source_id, $url ); |
There was a problem hiding this comment.
What about something more generic like wp_auto_approve_self_ping? (Or mention or comment or...)
I feel like we aren't far away from registered custom comment types and it would be nice if those (e.g. webmention) could also easily opt in to something like this.
There was a problem hiding this comment.
This filter right now allows filtering the condition for any ringback and not just self pingback, the default value is different between pingbacks though. So I think the current name is better personally.
There was a problem hiding this comment.
Ahh, fair. That makes sense.
Still brainstorming, because I can see it being useful for something other than pingbacks one day: wp_auto_approve_ping or wp_auto_approve_comment_mention? But really, this is fine too. :)
There was a problem hiding this comment.
Good catch, Jeremy, the potential for future ping types hadn't occurred to me.
In 3c70897 I've changed to the the generic ping but left the documentation with pingbacks for updating if/when other types are introduced.
I'm also happy enough if the bikeshed is aubergine if someone has another suggestion.
youknowriad
left a comment
There was a problem hiding this comment.
Thanks for the quick follow-up. This is looking good to me.
I really want there to be something better than |
jeremyfelt
left a comment
There was a problem hiding this comment.
@peterwilsoncc Everything looks good here. I'll leave some additional unrelated thoughts on the ticket.
|
@youknowriad @jeremyfelt can either of you think of other tests that it would be wise to include? Especially for multisite installs. |
There was a problem hiding this comment.
Pull request overview
This PR updates the pingback auto-approval behavior and its related documentation/tests in check_comment(), including clarifying “this site” wording and adding coverage for Multisite and off-site source handling.
Changes:
- Updates inline docs to clarify “the same site” semantics and adjusts
@sinceannotations to 7.1.0. - Renames the pingback auto-approval filter hook to a
wp_-prefixed name and updates usages. - Extends PHPUnit coverage for Multisite sub-site pingbacks and for ensuring the filter receives
0as the source post ID for off-site URLs.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| tests/phpunit/tests/comment/checkComment.php | Updates/extends tests around pingback auto-approval, including Multisite and source post ID expectations, and aligns filter usage in tests. |
| src/wp-includes/comment.php | Adjusts pingback auto-approval docs/versioning and changes the filter hook applied during pingback checks. |
Suppressed comments (3)
tests/phpunit/tests/comment/checkComment.php:333
- The test docblock refers to the
wp_auto_approve_pingbackhook, but the test currently hookswp_auto_approve_ping. The hook name should be consistent across docs/tests/core; for a pingback-only hook,wp_auto_approve_pingbackis clearer.
public function test_auto_approve_pingback_should_be_able_to_approve_a_pingback_from_another_site() {
update_option( 'comment_previously_approved', '1' );
add_filter( 'wp_auto_approve_ping', '__return_true' );
$this->assertTrue( check_comment( 'Site Title', '', 'http://example.com/a-post/', 'Excerpt.', '192.168.0.1', '', 'pingback' ) );
tests/phpunit/tests/comment/checkComment.php:369
- This test expects to observe the
$source_idpassed to the pingback auto-approval hook, but it currently hookswp_auto_approve_pingwhile the surrounding test docs refer towp_auto_approve_pingback. Use a single hook name consistently.
$observed = null;
add_filter(
'wp_auto_approve_ping',
static function ( $approve, $source_id ) use ( &$observed ) {
$observed = $source_id;
tests/phpunit/tests/comment/checkComment.php:396
- This test expects to observe the
$source_idpassed to the pingback auto-approval hook, but it currently hookswp_auto_approve_pingwhile the surrounding test docs refer towp_auto_approve_pingback. Use a single hook name consistently.
$observed = null;
add_filter(
'wp_auto_approve_ping',
static function ( $approve, $source_id ) use ( &$observed ) {
$observed = $source_id;
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| * @param int $source_id ID of the post on this site the pingback | ||
| * originated from, or 0 if it came from elsewhere. |
|
I want to confirm if this PR is ready to be committed, as tomorrow is the final RC release. It seems that at least the old |
|
Just to confirm, does this PR address the concerns raised by @sabernhardt? |
… the same site. Includes: * Updating version annotations to 7.1.0. * Clarifying "this site" means "the same site" in various docs. * Prefixing the new filter with `wp_`. * Extending the tests: * Adds a test to ensure MS sub-site posts are not auto approved. * Adds a test to ensure that post ID sent to filter is zero for external sites. * Adds docs for each test. Developed in #12928. Follow-up to r63036. Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov. See #65016. git-svn-id: https://develop.svn.wordpress.org/trunk@63207 602fd350-edb4-49c9-b593-d223f7449a82
… the same site. Includes: * Updating version annotations to 7.1.0. * Clarifying "this site" means "the same site" in various docs. * Prefixing the new filter with `wp_`. * Extending the tests: * Adds a test to ensure MS sub-site posts are not auto approved. * Adds a test to ensure that post ID sent to filter is zero for external sites. * Adds docs for each test. Developed in #12928. Follow-up to r63036. Reviewed by jeremyfelt, youknowriad. Merges r63207 to the 7.1 branch. Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov. See #65016. git-svn-id: https://develop.svn.wordpress.org/branches/7.1@63208 602fd350-edb4-49c9-b593-d223f7449a82
… the same site. Includes: * Updating version annotations to 7.1.0. * Clarifying "this site" means "the same site" in various docs. * Prefixing the new filter with `wp_`. * Extending the tests: * Adds a test to ensure MS sub-site posts are not auto approved. * Adds a test to ensure that post ID sent to filter is zero for external sites. * Adds docs for each test. Developed in WordPress/wordpress-develop#12928. Follow-up to r63036. Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov. See #65016. Built from https://develop.svn.wordpress.org/trunk@63207 git-svn-id: http://core.svn.wordpress.org/trunk@62400 1a063a9b-81f0-0310-95a4-ce76da25c4cd
|
Thanks for the PR! Merged in r63207. |
… the same site. Includes: * Updating version annotations to 7.1.0. * Clarifying "this site" means "the same site" in various docs. * Prefixing the new filter with `wp_`. * Extending the tests: * Adds a test to ensure MS sub-site posts are not auto approved. * Adds a test to ensure that post ID sent to filter is zero for external sites. * Adds docs for each test. Developed in WordPress/wordpress-develop#12928. Follow-up to r63036. Reviewed by jeremyfelt, youknowriad. Merges r63207 to the 7.1 branch. Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov. See #65016. Built from https://develop.svn.wordpress.org/branches/7.1@63208 git-svn-id: http://core.svn.wordpress.org/branches/7.1@62401 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Makes a few updates:
wp_.Trac ticket: https://core.trac.wordpress.org/ticket/65016
Use of AI Tools
This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.