Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -1875,8 +1875,9 @@ protected function check_delete_permission( $post ) {
*
* @since 4.7.0
* @since 5.9.0 Renamed `$post` to `$item` to match parent class for PHP 8 named parameter support.
* @since 7.2.0 The global post is now restored to its previous value before returning.
*
* @global WP_Post $post Global post object.
* @global WP_Post|null $post Global post object.
*
* @param WP_Post $item Post object.
* @param WP_REST_Request $request Request object.
Expand All @@ -1886,14 +1887,19 @@ public function prepare_item_for_response( $item, $request ) {
// Restores the more descriptive, specific name for use within this method.
$post = $item;

$previous_post = isset( $GLOBALS['post'] ) && $GLOBALS['post'] instanceof WP_Post ? $GLOBALS['post'] : null;
$GLOBALS['post'] = $post;

setup_postdata( $post );

// Don't prepare the response body for HEAD requests.
if ( $request->is_method( 'HEAD' ) ) {
/** This filter is documented in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php */
return apply_filters( "rest_prepare_{$this->post_type}", new WP_REST_Response( array() ), $post, $request );
$response = apply_filters( "rest_prepare_{$this->post_type}", new WP_REST_Response( array() ), $post, $request );

$this->restore_post_data( $previous_post );

return $response;
}

$fields = $this->get_fields_for_response( $request );
Expand Down Expand Up @@ -2196,7 +2202,55 @@ public function prepare_item_for_response( $item, $request ) {
* @param WP_Post $post Post object.
* @param WP_REST_Request $request Request object.
*/
return apply_filters( "rest_prepare_{$this->post_type}", $response, $post, $request );
$response = apply_filters( "rest_prepare_{$this->post_type}", $response, $post, $request );

$this->restore_post_data( $previous_post );

return $response;
}

/**
* Restores the global post to its previous value after preparing a post.
*
* Preparing a post overwrites the global post and post data via
* setup_postdata(). This restores the global post that was in place
* beforehand so the change does not leak into the rest of the request.
*
* Only the global post is guaranteed to be restored. When there was no
* previous global post and the main query has no post either, which is the
* usual state during a REST request, wp_reset_postdata() has nothing to
* restore from, so the remaining globals set by setup_postdata() (such as
* $id, $authordata and $pages) are left describing the post. Clearing
* those would mean unsetting each one by hand, which is beyond what is
* needed to keep the global post from leaking.
*
* @since 7.2.0
*
* @param WP_Post|null $previous_post The global post to restore, or null if there was none.
*/
private function restore_post_data( ?WP_Post $previous_post ): void {
if ( $previous_post ) {
$GLOBALS['post'] = $previous_post;
setup_postdata( $previous_post );
return;
}

/*
* There was no global post to restore, so clear the post data.
* This runs before clearing the global post because wp_reset_postdata()
* repopulates it from the main query whenever that query has a post. Note
* that it is a no-op when the main query has no post, in which case only
* the global post below is cleared.
*/
wp_reset_postdata();

/*
* Assigned rather than unset so that any `global $post` binding made before
* this request keeps pointing at the global. Unsetting removes the entry from
* the symbol table, which detaches those bindings, and a later write through
* one of them would no longer be visible to get_post().
*/
$GLOBALS['post'] = null;
}

/**
Expand Down
67 changes: 67 additions & 0 deletions tests/phpunit/tests/rest-api/rest-posts-controller.php
Original file line number Diff line number Diff line change
Expand Up @@ -2805,6 +2805,73 @@ function ( $classes ) {
$this->assertTrue( array_is_list( $data['class_list'] ), 'Expected class_list to be a list.' );
}

/**
* @ticket 43502
*
* @covers WP_REST_Posts_Controller::prepare_item_for_response
*/
public function test_prepare_item_for_response_restores_global_post() {
$post_1 = self::factory()->post->create_and_get();
$post_2 = self::factory()->post->create_and_get();

// Set up a known global $post state.
$GLOBALS['post'] = $post_1;
setup_postdata( $post_1 );

$endpoint = new WP_REST_Posts_Controller( 'post' );
$request = new WP_REST_Request( 'GET', '/wp/v2/posts/' . $post_2->ID );
$endpoint->prepare_item_for_response( $post_2, $request );

$this->assertSame(
$post_1->ID,
$GLOBALS['post']->ID,
'Global $post should be restored after prepare_item_for_response().'
);
}

/**
* @ticket 43502
*
* @covers WP_REST_Posts_Controller::prepare_item_for_response
*/
public function test_prepare_item_for_response_restores_null_global_post() {
unset( $GLOBALS['post'] );

$post = self::factory()->post->create_and_get();

$endpoint = new WP_REST_Posts_Controller( 'post' );
$request = new WP_REST_Request( 'GET', '/wp/v2/posts/' . $post->ID );
$endpoint->prepare_item_for_response( $post, $request );

$this->assertNull(
$GLOBALS['post'],
'Global $post should be restored to null when it was not set before prepare_item_for_response().'
);
}

/**
* @ticket 43502
*
* @covers WP_REST_Posts_Controller::prepare_item_for_response
*/
public function test_prepare_item_for_response_restores_global_post_on_head_request() {
$post_1 = self::factory()->post->create_and_get();
$post_2 = self::factory()->post->create_and_get();

$GLOBALS['post'] = $post_1;
setup_postdata( $post_1 );

$endpoint = new WP_REST_Posts_Controller( 'post' );
$request = new WP_REST_Request( 'HEAD', '/wp/v2/posts/' . $post_2->ID );
$endpoint->prepare_item_for_response( $post_2, $request );

$this->assertSame(
$post_1->ID,
$GLOBALS['post']->ID,
'Global $post should be restored after a HEAD request to prepare_item_for_response().'
);
}

public function test_create_item() {
wp_set_current_user( self::$editor_id );

Expand Down
Loading