You've already forked wp-fedistream
fix: Nuclear option - never apply the_content filter
All checks were successful
Create Release Package / build-release (push) Successful in 1m2s
All checks were successful
Create Release Package / build-release (push) Successful in 1m2s
- get_post_data() now ALWAYS strips shortcodes and uses raw content
- Never calls apply_filters('the_content') or get_the_excerpt()
- FediStream posts don't need shortcode processing in content
- This guarantees no recursion through WordPress hook system
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
13
CHANGELOG.md
13
CHANGELOG.md
@@ -7,6 +7,16 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [0.4.8] - 2026-02-02
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- **Nuclear option: NEVER apply the_content filter** - Completely removed the_content filter usage
|
||||||
|
- `get_post_data()` now ALWAYS strips shortcodes and uses raw content
|
||||||
|
- NEVER calls `apply_filters('the_content', ...)` or `get_the_excerpt()`
|
||||||
|
- FediStream posts don't need shortcode processing in their content anyway
|
||||||
|
- This guarantees no recursion through WordPress hook system
|
||||||
|
|
||||||
## [0.4.7] - 2026-02-02
|
## [0.4.7] - 2026-02-02
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
@@ -264,7 +274,8 @@ Initial release of WP FediStream - a WordPress plugin for streaming music over A
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
[Unreleased]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.7...HEAD
|
[Unreleased]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.8...HEAD
|
||||||
|
[0.4.8]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.7...v0.4.8
|
||||||
[0.4.7]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.6...v0.4.7
|
[0.4.7]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.6...v0.4.7
|
||||||
[0.4.6]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.5...v0.4.6
|
[0.4.6]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.5...v0.4.6
|
||||||
[0.4.5]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.4...v0.4.5
|
[0.4.5]: https://src.bundespruefstelle.ch/magdev/wp-fedistream/compare/v0.4.4...v0.4.5
|
||||||
|
|||||||
@@ -289,31 +289,18 @@ class TemplateLoader {
|
|||||||
// Track recursion to prevent infinite loops from shortcodes in content.
|
// Track recursion to prevent infinite loops from shortcodes in content.
|
||||||
++self::$recursion_depth;
|
++self::$recursion_depth;
|
||||||
|
|
||||||
// Skip the_content filter if:
|
// ALWAYS skip the_content filter to prevent any possible recursion.
|
||||||
// 1. We're in a shortcode context (prevents recursive shortcode processing)
|
// FediStream posts don't need shortcode processing in their content.
|
||||||
// 2. We're at depth > 1 (nested data loading)
|
// This is the nuclear option but it guarantees no recursion.
|
||||||
$skip_content_filter = self::$shortcode_context_depth > 0 || self::$recursion_depth > 1;
|
|
||||||
|
|
||||||
// When skipping content filter, also use raw excerpt to avoid get_the_excerpt()
|
|
||||||
// triggering the_content filter internally when generating auto-excerpts.
|
|
||||||
if ( $skip_content_filter ) {
|
|
||||||
$excerpt = $post->post_excerpt;
|
$excerpt = $post->post_excerpt;
|
||||||
if ( empty( $excerpt ) ) {
|
if ( empty( $excerpt ) ) {
|
||||||
// Generate a simple excerpt without triggering the_content filter.
|
// Generate a simple excerpt without triggering the_content filter.
|
||||||
$excerpt = wp_trim_words( wp_strip_all_tags( $post->post_content ), 55, '…' );
|
$excerpt = wp_trim_words( wp_strip_all_tags( $post->post_content ), 55, '…' );
|
||||||
}
|
}
|
||||||
} else {
|
|
||||||
$excerpt = get_the_excerpt( $post );
|
|
||||||
}
|
|
||||||
|
|
||||||
// When skipping content filter, also strip shortcodes to prevent them from
|
// Strip shortcodes and sanitize content - never apply the_content filter.
|
||||||
// being processed by anything else that might call do_shortcode on the output.
|
|
||||||
if ( $skip_content_filter ) {
|
|
||||||
$content = strip_shortcodes( $post->post_content );
|
$content = strip_shortcodes( $post->post_content );
|
||||||
$content = wp_kses_post( $content );
|
$content = wp_kses_post( $content );
|
||||||
} else {
|
|
||||||
$content = apply_filters( 'the_content', $post->post_content );
|
|
||||||
}
|
|
||||||
|
|
||||||
$data = array(
|
$data = array(
|
||||||
'id' => $post->ID,
|
'id' => $post->ID,
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
* Plugin Name: WP FediStream
|
* Plugin Name: WP FediStream
|
||||||
* Plugin URI: https://src.bundespruefstelle.ch/magdev/wp-fedistream
|
* Plugin URI: https://src.bundespruefstelle.ch/magdev/wp-fedistream
|
||||||
* Description: Stream music over ActivityPub - Build your own music streaming platform for Musicians and Labels.
|
* Description: Stream music over ActivityPub - Build your own music streaming platform for Musicians and Labels.
|
||||||
* Version: 0.4.6
|
* Version: 0.4.8
|
||||||
* Requires at least: 6.4
|
* Requires at least: 6.4
|
||||||
* Requires PHP: 8.3
|
* Requires PHP: 8.3
|
||||||
* Author: Marco Graetsch
|
* Author: Marco Graetsch
|
||||||
@@ -26,7 +26,7 @@ if ( ! defined( 'ABSPATH' ) ) {
|
|||||||
*
|
*
|
||||||
* @var string
|
* @var string
|
||||||
*/
|
*/
|
||||||
define( 'WP_FEDISTREAM_VERSION', '0.4.7' );
|
define( 'WP_FEDISTREAM_VERSION', '0.4.8' );
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Plugin file path.
|
* Plugin file path.
|
||||||
|
|||||||
Reference in New Issue
Block a user