Commit 945a3d5eb8a for woocommerce
commit 945a3d5eb8a2e0528d6de92380223c6f400d4f30
Author: Rishabh Gupta <109821717+R1shabh-Gupta@users.noreply.github.com>
Date: Wed Oct 7 17:32:53 2026 +0530
Fix incorrect status codes in WC_Download_Handler (#67973)
* Fix incorrect status codes in WC_Download_Handler
* Add changelog entries for download handler status code fix
diff --git a/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes b/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes
new file mode 100644
index 00000000000..a89d10e181f
--- /dev/null
+++ b/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes
@@ -0,0 +1,4 @@
+Significance: patch
+Type: fix
+
+Fix WC_Download_Handler: use the actual request protocol instead of a hardcoded HTTP/1.1 for range-download status headers, and default download errors to 403 Forbidden instead of 404 Not Found.
diff --git a/plugins/woocommerce/includes/class-wc-download-handler.php b/plugins/woocommerce/includes/class-wc-download-handler.php
index 9c316fd75a9..1f48006f1dc 100644
--- a/plugins/woocommerce/includes/class-wc-download-handler.php
+++ b/plugins/woocommerce/includes/class-wc-download-handler.php
@@ -570,7 +570,7 @@ class WC_Download_Handler {
);
self::download_file_redirect( $file_path );
} else {
- self::download_error( __( 'File not found', 'woocommerce' ) );
+ self::download_error( __( 'File not found', 'woocommerce' ), '', 404 );
}
}
@@ -778,7 +778,7 @@ class WC_Download_Handler {
if ( isset( $download_range['is_range_request'] ) && true === $download_range['is_range_request'] ) {
if ( false === $download_range['is_range_valid'] ) {
- header( 'HTTP/1.1 416 Requested Range Not Satisfiable' );
+ status_header( 416 );
header( 'Content-Range: bytes 0-' . ( $file_size - 1 ) . '/' . $file_size );
exit;
}
@@ -787,7 +787,7 @@ class WC_Download_Handler {
$end = $download_range['start'] + $download_range['length'] - 1;
$length = $download_range['length'];
- header( 'HTTP/1.1 206 Partial Content' );
+ status_header( 206 );
header( "Accept-Ranges: 0-$file_size" );
header( "Content-Range: bytes $start-$end/$file_size" );
header( "Content-Length: $length" );
@@ -984,7 +984,7 @@ class WC_Download_Handler {
* @param string $title Error title.
* @param integer $status Error status.
*/
- private static function download_error( $message, $title = '', $status = 404 ) {
+ private static function download_error( $message, $title = '', $status = 403 ) {
/*
* Since we will now render a message instead of serving a download, we should unwind some of the previously set
* headers.