#41604 REST API: Add strict param validation to WP_REST_Settings_Controller:… - #12967
#41604 REST API: Add strict param validation to WP_REST_Settings_Controller:…#12967PANawkar wants to merge 1 commit into
Conversation
…:update_item() and cover with unit tests.
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Unlinked AccountsThe following contributors have not linked their GitHub and WordPress.org accounts: @pratik.nawkar@xecurify.com. Contributors, please read how to link your accounts to ensure your work is properly credited in WordPress releases. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
Adds validation to WP_REST_Settings_Controller::update_item() so unknown parameters or an empty request body return a 400 instead of a silent 200, with unit tests covering empty bodies, unknown/mixed params (POST and PUT), and confirming valid settings still succeed alongside internal params like _locale.
Trac ticket: https://core.trac.wordpress.org/ticket/41604