Commit d51f8b613d for wordpress.org
commit d51f8b613d4f253e6e511e6f3e67020c32b0a0c8
Author: jorbin <jorbin@git.wordpress.org>
Date: Tue Oct 6 14:52:46 2026 +0000
Query: Prevent exposure of comments on unviewable posts.
Props peterwilsoncc, ehtis, westonruter, jorbin.
Built from https://develop.svn.wordpress.org/trunk@64132
git-svn-id: http://core.svn.wordpress.org/trunk@63288 1a063a9b-81f0-0310-95a4-ce76da25c4cd
diff --git a/wp-includes/class-wp-query.php b/wp-includes/class-wp-query.php
index 513f0f702c..a01724ce96 100644
--- a/wp-includes/class-wp-query.php
+++ b/wp-includes/class-wp-query.php
@@ -3461,43 +3461,6 @@ class WP_Query {
$this->posts = apply_filters_ref_array( 'posts_results', array( $this->posts, &$this ) );
}
- if ( ! empty( $this->posts ) && $this->is_comment_feed && $this->is_singular ) {
- /** This filter is documented in wp-includes/class-wp-query.php */
- $cjoin = apply_filters_ref_array( 'comment_feed_join', array( '', &$this ) );
-
- /** This filter is documented in wp-includes/class-wp-query.php */
- $cwhere = apply_filters_ref_array( 'comment_feed_where', array( "WHERE comment_post_ID = '{$this->posts[0]->ID}' AND comment_approved = '1' AND {$wpdb->comments}.comment_type != 'note'", &$this ) );
-
- /** This filter is documented in wp-includes/class-wp-query.php */
- $cgroupby = apply_filters_ref_array( 'comment_feed_groupby', array( '', &$this ) );
- $cgroupby = ( ! empty( $cgroupby ) ) ? 'GROUP BY ' . $cgroupby : '';
-
- /** This filter is documented in wp-includes/class-wp-query.php */
- $corderby = apply_filters_ref_array( 'comment_feed_orderby', array( 'comment_date_gmt DESC', &$this ) );
- $corderby = ( ! empty( $corderby ) ) ? 'ORDER BY ' . $corderby : '';
-
- /** This filter is documented in wp-includes/class-wp-query.php */
- $climits = apply_filters_ref_array( 'comment_feed_limits', array( 'LIMIT ' . get_option( 'posts_per_rss' ), &$this ) );
-
- $comments_request = "SELECT {$wpdb->comments}.comment_ID FROM {$wpdb->comments} $cjoin $cwhere $cgroupby $corderby $climits";
-
- $comment_key = md5( $comments_request );
- $comment_last_changed = wp_cache_get_last_changed( 'comment' );
-
- $comment_cache_key = "comment_feed:$comment_key";
- $comment_ids = wp_cache_get_salted( $comment_cache_key, 'comment-queries', $comment_last_changed );
- if ( false === $comment_ids ) {
- $comment_ids = $wpdb->get_col( $comments_request );
- wp_cache_set_salted( $comment_cache_key, $comment_ids, 'comment-queries', $comment_last_changed );
- }
- _prime_comment_caches( $comment_ids );
-
- // Convert to WP_Comment.
- /** @var WP_Comment[] */
- $this->comments = array_map( 'get_comment', $comment_ids );
- $this->comment_count = count( $this->comments );
- }
-
// Check post status to determine if post should be displayed.
if ( ! empty( $this->posts ) && ( $this->is_single || $this->is_page ) ) {
$status = get_post_status( $this->posts[0] );
@@ -3556,6 +3519,43 @@ class WP_Query {
}
}
+ if ( ! empty( $this->posts ) && $this->is_comment_feed && $this->is_singular ) {
+ /** This filter is documented in wp-includes/class-wp-query.php */
+ $cjoin = apply_filters_ref_array( 'comment_feed_join', array( '', &$this ) );
+
+ /** This filter is documented in wp-includes/class-wp-query.php */
+ $cwhere = apply_filters_ref_array( 'comment_feed_where', array( "WHERE comment_post_ID = '{$this->posts[0]->ID}' AND comment_approved = '1' AND {$wpdb->comments}.comment_type != 'note'", &$this ) );
+
+ /** This filter is documented in wp-includes/class-wp-query.php */
+ $cgroupby = apply_filters_ref_array( 'comment_feed_groupby', array( '', &$this ) );
+ $cgroupby = ( ! empty( $cgroupby ) ) ? 'GROUP BY ' . $cgroupby : '';
+
+ /** This filter is documented in wp-includes/class-wp-query.php */
+ $corderby = apply_filters_ref_array( 'comment_feed_orderby', array( 'comment_date_gmt DESC', &$this ) );
+ $corderby = ( ! empty( $corderby ) ) ? 'ORDER BY ' . $corderby : '';
+
+ /** This filter is documented in wp-includes/class-wp-query.php */
+ $climits = apply_filters_ref_array( 'comment_feed_limits', array( 'LIMIT ' . get_option( 'posts_per_rss' ), &$this ) );
+
+ $comments_request = "SELECT {$wpdb->comments}.comment_ID FROM {$wpdb->comments} $cjoin $cwhere $cgroupby $corderby $climits";
+
+ $comment_key = md5( $comments_request );
+ $comment_last_changed = wp_cache_get_last_changed( 'comment' );
+
+ $comment_cache_key = "comment_feed:$comment_key";
+ $comment_ids = wp_cache_get_salted( $comment_cache_key, 'comment-queries', $comment_last_changed );
+ if ( false === $comment_ids ) {
+ $comment_ids = $wpdb->get_col( $comments_request );
+ wp_cache_set_salted( $comment_cache_key, $comment_ids, 'comment-queries', $comment_last_changed );
+ }
+ _prime_comment_caches( $comment_ids );
+
+ // Convert to WP_Comment.
+ /** @var WP_Comment[] */
+ $this->comments = array_map( 'get_comment', $comment_ids );
+ $this->comment_count = count( $this->comments );
+ }
+
// Put sticky posts at the top of the posts array.
$sticky_posts = get_option( 'sticky_posts' );
if ( $this->is_home && $page <= 1 && is_array( $sticky_posts ) && ! empty( $sticky_posts ) && ! $query_vars['ignore_sticky_posts'] ) {
diff --git a/wp-includes/version.php b/wp-includes/version.php
index d675119f78..47f1e9f89a 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
-$wp_version = '7.2-alpha-64131';
+$wp_version = '7.2-alpha-64132';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.