Skip to content
Permalink
Browse files

Block Editor: Refresh nonces used by wp.apiFetch.

Adds heartbeat nonces refreshing support to wp.apiFetch requests.

Props pento, adamsilverstein, dd32, desrosj.
Fixes #45113. 


git-svn-id: https://develop.svn.wordpress.org/branches/5.0@43939 602fd350-edb4-49c9-b593-d223f7449a82
  • Loading branch information...
youknowriad committed Nov 22, 2018
1 parent a4f3345 commit 8d003dcdc6e9a13124a0ec61a79a955b5698bf54
@@ -68,9 +68,11 @@
add_filter( 'heartbeat_received', 'wp_check_locked_posts', 10, 3 );
add_filter( 'heartbeat_received', 'wp_refresh_post_lock', 10, 3 );
add_filter( 'wp_refresh_nonces', 'wp_refresh_post_nonces', 10, 3 );
add_filter( 'heartbeat_received', 'heartbeat_autosave', 500, 2 );
add_filter( 'wp_refresh_nonces', 'wp_refresh_post_nonces', 10, 3 );
add_filter( 'wp_refresh_nonces', 'wp_refresh_heartbeat_nonces' );
add_filter( 'heartbeat_settings', 'wp_heartbeat_set_suspension' );
// Nav Menu hooks.
@@ -1020,13 +1020,31 @@ function wp_refresh_post_nonces( $response, $data, $screen_id ) {
'_ajax_linking_nonce' => wp_create_nonce( 'internal-linking' ),
'_wpnonce' => wp_create_nonce( 'update-post_' . $post_id ),
),
'heartbeatNonce' => wp_create_nonce( 'heartbeat-nonce' ),
);
}
return $response;
}
/**
* Add the latest Heartbeat and REST-API nonce to the Heartbeat response.
*
* @since 5.0.0
*
* @param array $response The Heartbeat response.
* @return array The Heartbeat response.
*/
function wp_refresh_heartbeat_nonces( $response ) {
// Refresh the Rest API nonce.
$response['rest_nonce'] = wp_create_nonce( 'wp_rest' );
// TEMPORARY: Compat with api-fetch library
$response['rest-nonce'] = $response['rest_nonce'];
// Refresh the Heartbeat nonce.
$response['heartbeat_nonce'] = wp_create_nonce( 'heartbeat-nonce' );
return $response;
}
/**
* Disable suspension of Heartbeat on the Add/Edit Post screens.
*
@@ -312,6 +312,7 @@
if ( trigger && ! hasConnectionError() ) {
settings.connectionError = true;
$document.trigger( 'heartbeat-connection-lost', [error, status] );
wp.hooks.doAction( 'heartbeat.connection-lost', error, status );
}
}
}
@@ -331,6 +332,7 @@
settings.errorcount = 0;
settings.connectionError = false;
$document.trigger( 'heartbeat-connection-restored' );
wp.hooks.doAction( 'heartbeat.connection-restored' );
}
}

@@ -357,6 +359,7 @@
settings.queue = {};

$document.trigger( 'heartbeat-send', [ heartbeatData ] );
wp.hooks.doAction( 'heartbeat.send', heartbeatData );

ajaxData = {
data: heartbeatData,
@@ -393,6 +396,7 @@

if ( response.nonces_expired ) {
$document.trigger( 'heartbeat-nonces-expired' );
wp.hooks.doAction( 'heartbeat.nonces-expired' );
}

// Change the interval from PHP
@@ -401,7 +405,21 @@
delete response.heartbeat_interval;
}

// Update the heartbeat nonce if set.
if ( response.heartbeat_nonce && typeof window.heartbeatSettings === 'object' ) {
window.heartbeatSettings.nonce = response.heartbeat_nonce;
delete response.heartbeat_nonce;
}

// Update the Rest API nonce if set and wp-api loaded.
if ( response.rest_nonce && typeof window.wpApiSettings === 'object' ) {
window.wpApiSettings.nonce = response.rest_nonce;
// This nonce is required for api-fetch through heartbeat.tick.
// delete response.rest_nonce;
}

$document.trigger( 'heartbeat-tick', [response, textStatus, jqXHR] );
wp.hooks.doAction( 'heartbeat.tick', response, textStatus, jqXHR );

// Do this last, can trigger the next XHR if connection time > 5 sec. and newInterval == 'fast'
if ( newInterval ) {
@@ -410,6 +428,7 @@
}).fail( function( jqXHR, textStatus, error ) {
setErrorState( textStatus || 'unknown', jqXHR.status );
$document.trigger( 'heartbeat-error', [jqXHR, textStatus, error] );
wp.hooks.doAction( 'heartbeat.error', jqXHR, textStatus, error );
});
}

@@ -869,7 +869,7 @@ function wp_default_scripts( &$scripts ) {
$scripts->add( 'autosave', "/wp-includes/js/autosave$suffix.js", array('heartbeat'), false, 1 );
$scripts->add( 'heartbeat', "/wp-includes/js/heartbeat$suffix.js", array('jquery'), false, 1 );
$scripts->add( 'heartbeat', "/wp-includes/js/heartbeat$suffix.js", array( 'jquery', 'wp-hooks' ), false, 1 );
did_action( 'init' ) && $scripts->localize( 'heartbeat', 'heartbeatSettings',
/**
* Filters the Heartbeat settings.

0 comments on commit 8d003dc

Please sign in to comment.
You can’t perform that action at this time.