Skip to content

Auto approve self pings follow up - #12928

Closed
peterwilsoncc wants to merge 7 commits into
WordPress:trunkfrom
peterwilsoncc:follow/65016-auto-approve-self-pings
Closed

Auto approve self pings follow up#12928
peterwilsoncc wants to merge 7 commits into
WordPress:trunkfrom
peterwilsoncc:follow/65016-auto-approve-self-pings

Conversation

@peterwilsoncc

Copy link
Copy Markdown
Contributor

Makes a few updates:

  • Version annotations to 7.1.0
  • Clarifies "this site" means "the same site" in various docs.
  • Prefixes the new filter with wp_.
  • Extends the tests:
    • adds test to ensure MS sub-site posts are not auto approved
    • adds test to ensure that post ID sent to filter is zero for external sites.
    • adds docs for each test

Trac ticket: https://core.trac.wordpress.org/ticket/65016

Use of AI Tools


This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props peterwilsoncc, jeremyfelt, youknowriad, wildworks.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@jeremyfelt jeremyfelt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm also curious whether url_to_postid() is good enough or if some additional checks could help. And whether there's a better spot for the filter in general. I'll have a better opinion to share tomorrow :)

Comment thread src/wp-includes/comment.php Outdated
* @param string $url The URL the pingback was sent from.
*/
return (bool) apply_filters( 'auto_approve_pingback', $approve_pingback, $source_id, $url );
return (bool) apply_filters( 'wp_auto_approve_pingback', $approve_pingback, $source_id, $url );

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What about something more generic like wp_auto_approve_self_ping? (Or mention or comment or...)

I feel like we aren't far away from registered custom comment types and it would be nice if those (e.g. webmention) could also easily opt in to something like this.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This filter right now allows filtering the condition for any ringback and not just self pingback, the default value is different between pingbacks though. So I think the current name is better personally.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ahh, fair. That makes sense.

Still brainstorming, because I can see it being useful for something other than pingbacks one day: wp_auto_approve_ping or wp_auto_approve_comment_mention? But really, this is fine too. :)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, Jeremy, the potential for future ping types hadn't occurred to me.

In 3c70897 I've changed to the the generic ping but left the documentation with pingbacks for updating if/when other types are introduced.

I'm also happy enough if the bikeshed is aubergine if someone has another suggestion.

@youknowriad youknowriad left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the quick follow-up. This is looking good to me.

@jeremyfelt

Copy link
Copy Markdown
Member

I'm also curious whether url_to_postid() is good enough or if some additional checks could help. And whether there's a better spot for the filter in general. I'll have a better opinion to share tomorrow :)

I really want there to be something better than url_to_postid(), but it generally covers all the scenarios. I think, if anything, there may be a bug report or two against that function available to be made, but nothing blocking this.

@jeremyfelt jeremyfelt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@peterwilsoncc Everything looks good here. I'll leave some additional unrelated thoughts on the ticket.

@peterwilsoncc

Copy link
Copy Markdown
Contributor Author

@youknowriad @jeremyfelt can either of you think of other tests that it would be wise to include? Especially for multisite installs.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the pingback auto-approval behavior and its related documentation/tests in check_comment(), including clarifying “this site” wording and adding coverage for Multisite and off-site source handling.

Changes:

  • Updates inline docs to clarify “the same site” semantics and adjusts @since annotations to 7.1.0.
  • Renames the pingback auto-approval filter hook to a wp_-prefixed name and updates usages.
  • Extends PHPUnit coverage for Multisite sub-site pingbacks and for ensuring the filter receives 0 as the source post ID for off-site URLs.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
tests/phpunit/tests/comment/checkComment.php Updates/extends tests around pingback auto-approval, including Multisite and source post ID expectations, and aligns filter usage in tests.
src/wp-includes/comment.php Adjusts pingback auto-approval docs/versioning and changes the filter hook applied during pingback checks.
Suppressed comments (3)

tests/phpunit/tests/comment/checkComment.php:333

  • The test docblock refers to the wp_auto_approve_pingback hook, but the test currently hooks wp_auto_approve_ping. The hook name should be consistent across docs/tests/core; for a pingback-only hook, wp_auto_approve_pingback is clearer.
	public function test_auto_approve_pingback_should_be_able_to_approve_a_pingback_from_another_site() {
		update_option( 'comment_previously_approved', '1' );

		add_filter( 'wp_auto_approve_ping', '__return_true' );

		$this->assertTrue( check_comment( 'Site Title', '', 'http://example.com/a-post/', 'Excerpt.', '192.168.0.1', '', 'pingback' ) );

tests/phpunit/tests/comment/checkComment.php:369

  • This test expects to observe the $source_id passed to the pingback auto-approval hook, but it currently hooks wp_auto_approve_ping while the surrounding test docs refer to wp_auto_approve_pingback. Use a single hook name consistently.
		$observed = null;
		add_filter(
			'wp_auto_approve_ping',
			static function ( $approve, $source_id ) use ( &$observed ) {
				$observed = $source_id;

tests/phpunit/tests/comment/checkComment.php:396

  • This test expects to observe the $source_id passed to the pingback auto-approval hook, but it currently hooks wp_auto_approve_ping while the surrounding test docs refer to wp_auto_approve_pingback. Use a single hook name consistently.
		$observed = null;
		add_filter(
			'wp_auto_approve_ping',
			static function ( $approve, $source_id ) use ( &$observed ) {
				$observed = $source_id;

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/wp-includes/comment.php
Comment on lines 193 to 194
* @param int $source_id ID of the post on this site the pingback
* originated from, or 0 if it came from elsewhere.
Comment thread tests/phpunit/tests/comment/checkComment.php
@t-hamano

Copy link
Copy Markdown
Contributor

I want to confirm if this PR is ready to be committed, as tomorrow is the final RC release. It seems that at least the old wp_auto_approve_pingback in the Docblock needs to be updated.

@t-hamano

Copy link
Copy Markdown
Contributor

Just to confirm, does this PR address the concerns raised by @sabernhardt?

https://core.trac.wordpress.org/ticket/65016#comment:9

pento pushed a commit that referenced this pull request Aug 12, 2026
… the same site.

Includes:
* Updating version annotations to 7.1.0.
* Clarifying "this site" means "the same site" in various docs.
* Prefixing the new filter with `wp_`.
* Extending the tests:
 * Adds a test to ensure MS sub-site posts are not auto approved.
 * Adds a test to ensure that post ID sent to filter is zero for external sites.
 * Adds docs for each test.

Developed in #12928.

Follow-up to r63036.

Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov.
See #65016.

git-svn-id: https://develop.svn.wordpress.org/trunk@63207 602fd350-edb4-49c9-b593-d223f7449a82
pento pushed a commit that referenced this pull request Aug 12, 2026
… the same site.

Includes:
* Updating version annotations to 7.1.0.
* Clarifying "this site" means "the same site" in various docs.
* Prefixing the new filter with `wp_`.
* Extending the tests:
 * Adds a test to ensure MS sub-site posts are not auto approved.
 * Adds a test to ensure that post ID sent to filter is zero for external sites.
 * Adds docs for each test.

Developed in #12928.

Follow-up to r63036.

Reviewed by jeremyfelt, youknowriad.
Merges r63207 to the 7.1 branch.

Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov.
See #65016.

git-svn-id: https://develop.svn.wordpress.org/branches/7.1@63208 602fd350-edb4-49c9-b593-d223f7449a82
markjaquith pushed a commit to markjaquith/WordPress that referenced this pull request Aug 12, 2026
… the same site.

Includes:
* Updating version annotations to 7.1.0.
* Clarifying "this site" means "the same site" in various docs.
* Prefixing the new filter with `wp_`.
* Extending the tests:
 * Adds a test to ensure MS sub-site posts are not auto approved.
 * Adds a test to ensure that post ID sent to filter is zero for external sites.
 * Adds docs for each test.

Developed in WordPress/wordpress-develop#12928.

Follow-up to r63036.

Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov.
See #65016.
Built from https://develop.svn.wordpress.org/trunk@63207


git-svn-id: http://core.svn.wordpress.org/trunk@62400 1a063a9b-81f0-0310-95a4-ce76da25c4cd
@SergeyBiryukov

Copy link
Copy Markdown
Member

Thanks for the PR! Merged in r63207.

markjaquith pushed a commit to markjaquith/WordPress that referenced this pull request Aug 12, 2026
… the same site.

Includes:
* Updating version annotations to 7.1.0.
* Clarifying "this site" means "the same site" in various docs.
* Prefixing the new filter with `wp_`.
* Extending the tests:
 * Adds a test to ensure MS sub-site posts are not auto approved.
 * Adds a test to ensure that post ID sent to filter is zero for external sites.
 * Adds docs for each test.

Developed in WordPress/wordpress-develop#12928.

Follow-up to r63036.

Reviewed by jeremyfelt, youknowriad.
Merges r63207 to the 7.1 branch.

Props peterwilsoncc, jeremyfelt, youknowriad, wildworks, sabernhardt, SergeyBiryukov.
See #65016.
Built from https://develop.svn.wordpress.org/branches/7.1@63208


git-svn-id: http://core.svn.wordpress.org/branches/7.1@62401 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants