diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/readme.html /home/packages/qi/SOURCES/wordpress-3.7.5/readme.html *** /home/packages/qi/SOURCES/wordpress-3.7.4/readme.html 2014-08-06 22:27:35.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/readme.html 2014-11-20 19:26:10.000000000 +0300 *************** *** 8,14 ****

WordPress !
Version 3.7.4

Semantic Personal Publishing Platform

--- 8,14 ----

WordPress !
Version 3.7.5

Semantic Personal Publishing Platform

diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/about.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/about.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/about.php 2014-08-06 22:27:35.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/about.php 2014-11-20 19:26:10.000000000 +0300 *************** *** 36,42 ****
!

Version %1$s addressed a security issue.', 'Version %1$s addressed some security issues.', 5 ), '3.7.4', number_format_i18n( 5 ) ); ?> the release notes.' ), 'http://codex.wordpress.org/Version_3.7.4' ); ?> --- 36,46 ----

!

!

Version %1$s addressed a security issue.', ! 'Version %1$s addressed some security issues.', 8 ), '3.7.5', number_format_i18n( 8 ) ); ?> ! the release notes.' ), 'http://codex.wordpress.org/Version_3.7.5' ); ?> !

Version %1$s addressed a security issue.', 'Version %1$s addressed some security issues.', 5 ), '3.7.4', number_format_i18n( 5 ) ); ?> the release notes.' ), 'http://codex.wordpress.org/Version_3.7.4' ); ?> diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/includes/image.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/includes/image.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/includes/image.php 2013-03-21 07:55:42.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/includes/image.php 2014-11-20 19:00:09.000000000 +0300 *************** *** 314,319 **** --- 314,325 ---- $meta[ $key ] = utf8_encode( $meta[ $key ] ); } + foreach ( $meta as &$value ) { + if ( is_string( $value ) ) { + $value = wp_kses_post( $value ); + } + } + return apply_filters( 'wp_read_image_metadata', $meta, $file, $sourceImageType ); } diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/press-this.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/press-this.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-admin/press-this.php 2013-09-25 04:18:11.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-admin/press-this.php 2014-11-20 17:00:18.000000000 +0300 *************** *** 65,71 **** // error handling for media_sideload if ( is_wp_error($upload) ) { wp_delete_post($post_ID); ! wp_die($upload); } else { // Post formats if ( isset( $_POST['post_format'] ) ) { --- 65,71 ---- // error handling for media_sideload if ( is_wp_error($upload) ) { wp_delete_post($post_ID); ! wp_die( esc_html( $upload->get_error_message() ) ); } else { // Post formats if ( isset( $_POST['post_format'] ) ) { diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/advanced-cache.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/advanced-cache.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/advanced-cache.php 2013-10-30 20:29:20.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/advanced-cache.php 1970-01-01 03:00:00.000000000 +0300 *************** *** 1,17 **** - "; - } - - if ( false == defined( 'WPCACHEHOME' ) ) { - define( 'ADVANCEDCACHEPROBLEM', 1 ); - } elseif ( !include_once( WPCACHEHOME . 'wp-cache-phase1.php' ) ) { - if ( !@is_file( WPCACHEHOME . 'wp-cache-phase1.php' ) ) { - define( 'ADVANCEDCACHEPROBLEM', 1 ); - } - } - if ( defined( 'ADVANCEDCACHEPROBLEM' ) ) - register_shutdown_function( 'wpcache_broken_message' ); - ?> --- 0 ---- diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/cache/.htaccess /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/cache/.htaccess *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/cache/.htaccess 2013-10-30 20:29:20.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/cache/.htaccess 1970-01-01 03:00:00.000000000 +0300 *************** *** 1,23 **** - - # BEGIN supercache - - - ForceType text/html - FileETag None - - AddEncoding gzip .gz - AddType text/html .gz - - - SetEnvIfNoCase Request_URI \.gz$ no-gzip - - - Header set Vary "Accept-Encoding, Cookie" - Header set Cache-Control 'max-age=3, must-revalidate' - - - ExpiresActive On - ExpiresByType text/html A3 - - - # END supercache --- 0 ---- diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/admin.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/admin.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/admin.php 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/admin.php 2014-03-14 02:57:39.000000000 +0300 *************** *** 0 **** --- 1,943 ---- +

'.sprintf(__('Akismet %s requires WordPress 3.0 or higher.'), AKISMET_VERSION) .' '.sprintf(__('Please upgrade WordPress to a current version, or downgrade to version 2.4 of the Akismet plugin.'), 'http://codex.wordpress.org/Upgrading_WordPress', 'http://wordpress.org/extend/plugins/akismet/download/'). '

+ '; + } + add_action('admin_notices', 'akismet_version_warning'); + + return; + } + + if ( function_exists( 'get_plugin_page_hook' ) ) + $hook = get_plugin_page_hook( 'akismet-stats-display', 'index.php' ); + else + $hook = 'dashboard_page_akismet-stats-display'; + add_meta_box('akismet-status', __('Comment History'), 'akismet_comment_status_meta_box', 'comment', 'normal'); + } + add_action('admin_init', 'akismet_admin_init'); + + add_action( 'admin_enqueue_scripts', 'akismet_load_js_and_css' ); + function akismet_load_js_and_css() { + global $hook_suffix; + + if ( in_array( $hook_suffix, array( + 'index.php', # dashboard + 'edit-comments.php', + 'comment.php', + 'post.php', + 'plugins_page_akismet-key-config', + 'jetpack_page_akismet-key-config', + ) ) ) { + wp_register_style( 'akismet.css', AKISMET_PLUGIN_URL . 'akismet.css', array(), AKISMET_VERSION ); + wp_enqueue_style( 'akismet.css'); + + wp_register_script( 'akismet.js', AKISMET_PLUGIN_URL . 'akismet.js', array('jquery'), AKISMET_VERSION ); + wp_enqueue_script( 'akismet.js' ); + wp_localize_script( 'akismet.js', 'WPAkismet', array( + 'comment_author_url_nonce' => wp_create_nonce( 'comment_author_url_nonce' ), + 'strings' => array( + 'Remove this URL' => __( 'Remove this URL' ), + 'Removing...' => __( 'Removing...' ), + 'URL removed' => __( 'URL removed' ), + '(undo)' => __( '(undo)' ), + 'Re-adding...' => __( 'Re-adding...' ), + ) + ) ); + } + } + + + function akismet_nonce_field($action = -1) { return wp_nonce_field($action); } + $akismet_nonce = 'akismet-update-key'; + + function akismet_plugin_action_links( $links, $file ) { + if ( $file == plugin_basename( dirname(__FILE__).'/akismet.php' ) ) { + $links[] = ''.__( 'Settings' ).''; + } + + return $links; + } + + add_filter( 'plugin_action_links', 'akismet_plugin_action_links', 10, 2 ); + + function akismet_conf() { + global $akismet_nonce, $current_user; + + $new_key_link = 'https://akismet.com/get/'; + $config_link = esc_url( add_query_arg( array( 'page' => 'akismet-key-config', 'show' => 'enter-api-key' ), class_exists( 'Jetpack' ) ? admin_url( 'admin.php' ) : admin_url( 'plugins.php' ) ) ); + $stats_link = esc_url( add_query_arg( array( 'page' => 'akismet-stats-display' ), class_exists( 'Jetpack' ) ? admin_url( 'admin.php' ) : admin_url( 'index.php' ) ) ); + $api_key = akismet_get_key(); + $show_key_form = $api_key; + $key_status = 'empty'; + $saved_ok = false; + $key_status_text = ''; + + $ms = array(); + + if ( isset( $_POST['submit'] ) ) { + if ( function_exists('current_user_can') && !current_user_can('manage_options') ) + die(__('Cheatin’ uh?')); + + $show_key_form = true; + + check_admin_referer( $akismet_nonce ); + $key = preg_replace( '/[^a-h0-9]/i', '', $_POST['key'] ); + $home_url = parse_url( get_bloginfo('url') ); + + if ( empty( $home_url['host'] ) ) + $ms[] = 'bad_home_url'; + + if ( empty( $key ) ) { + if ( $api_key ) { + delete_option('wordpress_api_key'); + $saved_ok = true; + $ms[] = 'new_key_empty'; + } + else + $ms[] = 'key_empty'; + } + else + $key_status = akismet_verify_key( $key ); + + if ( $key != $api_key && $key_status == 'valid' ) { + $ms[] = 'new_key_valid'; + update_option('wordpress_api_key', $key); + } + elseif ( $key_status == 'invalid' ) + $ms[] = 'new_key_invalid'; + elseif ( $key_status == 'failed' ) + $ms[] = 'new_key_failed'; + + $api_key = $key_status == 'valid' ? $key : false; + + if ( isset( $_POST['akismet_discard_month'] ) ) + update_option( 'akismet_discard_month', 'true' ); + else + update_option( 'akismet_discard_month', 'false' ); + + if ( isset( $_POST['akismet_show_user_comments_approved'] ) ) + update_option( 'akismet_show_user_comments_approved', 'true' ); + else + update_option( 'akismet_show_user_comments_approved', 'false' ); + + if ( empty( $ms ) ) + $saved_ok = true; + + } + elseif ( isset( $_POST['check'] ) ) { + $show_key_form = true; + check_admin_referer( $akismet_nonce ); + akismet_get_server_connectivity(0); + } + elseif ( isset( $_GET['show'] ) && $_GET['show'] == 'enter-api-key' ) { + $show_key_form = true; + } + + if ( $show_key_form ) { + //check current key status + //only get this if showing the key form otherwise takes longer for page to load for new user + //no need to get it if we already know it and its valid + if ( in_array( $key_status, array( 'invalid', 'failed', 'empty' ) ) ) { + $key = get_option('wordpress_api_key'); + if ( empty( $key ) ) { + //no key saved yet - maybe connection to Akismet down? + if ( in_array( $key_status, array( 'invalid', 'empty' ) ) ) { + if ( akismet_verify_key( '1234567890ab' ) == 'failed' ) + $ms[] = 'no_connection'; + } + } + else + $key_status = akismet_verify_key( $key ); + } + + if ( !isset( $_POST['submit'] ) ) { + if ( $key_status == 'invalid' ) + $ms[] = 'key_invalid'; + elseif ( !empty( $key ) && $key_status == 'failed' ) + $ms[] = 'key_failed'; + } + } + + $key_status_strings = array( + 'empty' => __( 'Empty' ), + 'valid' => __( 'Valid' ), + 'invalid' => __( 'Invalid' ), + 'failed' => __( 'Failed' ), + ); + + $messages = array( + 'new_key_empty' => array( 'class' => 'updated fade', 'text' => __('Your key has been cleared.' ) ), + 'new_key_valid' => array( 'class' => 'updated fade', 'text' => __('Your Akismet account has been successfully set up and activated. Happy blogging!' ) ), + 'new_key_invalid' => array( 'class' => 'error', 'text' => __('The key you entered is invalid. Please double-check it.' ) ), + 'new_key_failed' => array( 'class' => 'error', 'text' => __('The key you entered could not be verified because a connection to akismet.com could not be established. Please check your server configuration.' ) ), + 'no_connection' => array( 'class' => 'error', 'text' => __('There was a problem connecting to the Akismet server. Please check your server configuration.' ) ), + 'key_empty' => array( 'class' => 'updated fade', 'text' => __('Please enter an API key' ) ), + 'key_invalid' => array( 'class' => 'error', 'text' => __('This key is invalid.' ) ), + 'key_failed' => array( 'class' => 'error', 'text' => __('The key below was previously validated but a connection to akismet.com can not be established at this time. Please check your server configuration.' ) ), + 'bad_home_url' => array( 'class' => 'error', 'text' => sprintf( __('Your WordPress home URL %s is invalid. Please fix the home option.'), esc_html( get_bloginfo('url') ), admin_url('options.php#home') ) ) + ); + ?> + + +
+ +

+ +

Stats' ), $stats_link ); ?>

+ +
+

+
+ + + + +
+
+ +
+
+ +

+ + +

Sign up success! Please check your email for your Akismet API Key and enter it below.') ?>

+ + +

+ +
+ + + + + + + + + + + + + +
+
+

create one here'), '#' );?>

+
+
+
+ +
+
+ +

+ +

+
+ + +

+
+ + + + + + + + + + + + + + + + +
+ +

+

fsockopen or gethostbynamel functions. Akismet cannot work correctly until this is fixed. Please contact your web host or firewall administrator and give them this information about Akismet\'s system requirements.'), 'http://blog.akismet.com/akismet-hosting-faq/'); ?>

+ 0 ) { + if ( $fail_count > 0 && $fail_count < count( $servers ) ) { // some connections work, some fail ?> +

+

this information about Akismet and firewalls.'), 'http://blog.akismet.com/akismet-hosting-faq/'); ?>

+ 0 ) { // all connections fail ?> +

+

Akismet cannot work correctly until this is fixed. Please contact your web host or firewall administrator and give them this information about Akismet and firewalls.'), 'http://blog.akismet.com/akismet-hosting-faq/'); ?>

+ +

+

+ +

+

Akismet cannot work correctly until this is fixed. Please contact your web host or firewall administrator and give them this information about Akismet and firewalls.'), 'http://blog.akismet.com/akismet-hosting-faq/'); ?>

+ +
+ + + + + + $status ) : ?> + + + + + + +
+
+ +
+

+

clicking here.'), 'http://status.automattic.com/9931/136079/Akismet-API' ); ?>

+
+ +
+ +
+
+ 'akismet-key-config' ), class_exists( 'Jetpack' ) ? admin_url( 'admin.php' ) : admin_url( 'plugins.php' ) ) );?> + +
+

enter your Akismet API key for it to work.' ), $config_link );?>

+ +
' . _x( 'Spam', 'comments' ) . ''; + global $submenu; + echo '

'.sprintf( _n( 'Akismet has protected your site from %3$s spam comments.', 'Akismet has protected your site from %3$s spam comments.', $count ), 'http://akismet.com/?return=true', esc_url( add_query_arg( array( 'page' => 'akismet-admin' ), admin_url( isset( $submenu['edit-comments.php'] ) ? 'edit-comments.php' : 'edit.php' ) ) ), number_format_i18n($count) ).'

'; + } + add_action('activity_box_end', 'akismet_stats'); + + function akismet_admin_warnings() { + global $wpcom_api_key, $pagenow; + + if ( + $pagenow == 'edit-comments.php' + || ( !empty( $_GET['page'] ) && $_GET['page'] == 'akismet-key-config' ) + || ( !empty( $_GET['page'] ) && $_GET['page'] == 'akismet-stats-display' ) + ) { + if ( get_option( 'akismet_alert_code' ) ) { + function akismet_alert() { + $alert = array( + 'code' => (int) get_option( 'akismet_alert_code' ), + 'msg' => get_option( 'akismet_alert_msg' ) + ); + ?> +
+

:

+

+

%s' , 'https://akismet.com/errors/'.$alert['code'], 'https://akismet.com/errors/'.$alert['code'] );?> +

+
+ + +
+ + + +
+
A
+
+
+
'.__('Activate your Akismet account').'
+
+
+
'.__('Almost done - activate your account and say goodbye to comment spam').'
+
+
+
+ '; + } + } + + add_action('admin_notices', 'akismet_warning'); + return; + } elseif ( ( empty($_SERVER['SCRIPT_FILENAME']) || basename($_SERVER['SCRIPT_FILENAME']) == 'edit-comments.php' ) && wp_next_scheduled('akismet_schedule_cron_recheck') ) { + function akismet_warning() { + global $wpdb; + akismet_fix_scheduled_recheck(); + $waiting = $wpdb->get_var( "SELECT COUNT(*) FROM $wpdb->commentmeta WHERE meta_key = 'akismet_error'" ); + $next_check = wp_next_scheduled('akismet_schedule_cron_recheck'); + if ( $waiting > 0 && $next_check > time() ) + echo ' +

'.__('Akismet has detected a problem.').' '.sprintf(__('Some comments have not yet been checked for spam by Akismet. They have been temporarily held for moderation. Please check your Akismet configuration and contact your web host if problems persist.'), 'admin.php?page=akismet-key-config').'

+ '; + } + add_action('admin_notices', 'akismet_warning'); + return; + } + } + + // FIXME placeholder + + function akismet_comment_row_action( $a, $comment ) { + + // failsafe for old WP versions + if ( !function_exists('add_comment_meta') ) + return $a; + + $akismet_result = get_comment_meta( $comment->comment_ID, 'akismet_result', true ); + $akismet_error = get_comment_meta( $comment->comment_ID, 'akismet_error', true ); + $user_result = get_comment_meta( $comment->comment_ID, 'akismet_user_result', true); + $comment_status = wp_get_comment_status( $comment->comment_ID ); + $desc = null; + if ( $akismet_error ) { + $desc = __( 'Awaiting spam check' ); + } elseif ( !$user_result || $user_result == $akismet_result ) { + // Show the original Akismet result if the user hasn't overridden it, or if their decision was the same + if ( $akismet_result == 'true' && $comment_status != 'spam' && $comment_status != 'trash' ) + $desc = __( 'Flagged as spam by Akismet' ); + elseif ( $akismet_result == 'false' && $comment_status == 'spam' ) + $desc = __( 'Cleared by Akismet' ); + } else { + $who = get_comment_meta( $comment->comment_ID, 'akismet_user', true ); + if ( $user_result == 'true' ) + $desc = sprintf( __('Flagged as spam by %s'), $who ); + else + $desc = sprintf( __('Un-spammed by %s'), $who ); + } + + // add a History item to the hover links, just after Edit + if ( $akismet_result ) { + $b = array(); + foreach ( $a as $k => $item ) { + $b[ $k ] = $item; + if ( + $k == 'edit' + || ( $k == 'unspam' && $GLOBALS['wp_version'] >= 3.4 ) + ) { + $b['history'] = ' '. __('History') . ''; + } + } + + $a = $b; + } + + if ( $desc ) + echo ''.esc_html( $desc ).''; + + if ( apply_filters( 'akismet_show_user_comments_approved', get_option('akismet_show_user_comments_approved') ) == 'true' ) { + $comment_count = akismet_get_user_comments_approved( $comment->user_id, $comment->comment_author_email, $comment->comment_author, $comment->comment_author_url ); + $comment_count = intval( $comment_count ); + echo ''; + } + + return $a; + } + + add_filter( 'comment_row_actions', 'akismet_comment_row_action', 10, 2 ); + + function akismet_comment_status_meta_box($comment) { + $history = akismet_get_comment_history( $comment->comment_ID ); + + if ( $history ) { + echo '
'; + foreach ( $history as $row ) { + $time = date( 'D d M Y @ h:i:m a', $row['time'] ) . ' GMT'; + echo '
' . sprintf( __('%s ago'), human_time_diff( $row['time'] ) ) . ' - '; + echo esc_html( $row['message'] ) . '
'; + } + + echo '
'; + + } + } + + + // add an extra column header to the comments screen + function akismet_comments_columns( $columns ) { + $columns[ 'akismet' ] = __( 'Akismet' ); + return $columns; + } + + #add_filter( 'manage_edit-comments_columns', 'akismet_comments_columns' ); + + // Show stuff in the extra column + function akismet_comment_column_row( $column, $comment_id ) { + if ( $column != 'akismet' ) + return; + + $history = akismet_get_comment_history( $comment_id ); + + if ( $history ) { + echo '
'; + foreach ( $history as $row ) { + echo '
' . sprintf( __('%s ago'), human_time_diff( $row['time'] ) ) . '
'; + echo '
' . esc_html( $row['message'] ) . '
'; + } + + echo '
'; + } + } + + #add_action( 'manage_comments_custom_column', 'akismet_comment_column_row', 10, 2 ); + + // END FIXME + + // call out URLS in comments + function akismet_text_add_link_callback( $m ) { + // bare link? + if ( $m[4] == $m[2] ) + return ''.$m[4].''; + else + return ''.$m[4].''; + } + + function akismet_text_add_link_class( $comment_text ) { + return preg_replace_callback( '#]*)href="([^"]+)"([^>]*)>(.*?)#i', 'akismet_text_add_link_callback', $comment_text ); + } + + add_filter('comment_text', 'akismet_text_add_link_class'); + + + // WP 2.5+ + function akismet_rightnow() { + global $submenu, $wp_db_version; + + if ( 8645 < $wp_db_version ) // 2.7 + $link = add_query_arg( array( 'comment_status' => 'spam' ), admin_url( 'edit-comments.php' ) ); + elseif ( isset( $submenu['edit-comments.php'] ) ) + $link = add_query_arg( array( 'page' => 'akismet-admin' ), admin_url( 'edit-comments.php' ) ); + else + $link = add_query_arg( array( 'page' => 'akismet-admin' ), admin_url( 'edit.php' ) ); + + if ( $count = get_option('akismet_spam_count') ) { + $intro = sprintf( _n( + 'Akismet has protected your site from %2$s spam comment already. ', + 'Akismet has protected your site from %2$s spam comments already. ', + $count + ), 'http://akismet.com/?return=true', number_format_i18n( $count ) ); + } else { + $intro = sprintf( __('Akismet blocks spam from getting to your blog. '), 'http://akismet.com/?return=true' ); + } + + $link = function_exists( 'esc_url' ) ? esc_url( $link ) : clean_url( $link ); + if ( $queue_count = akismet_spam_count() ) { + $queue_text = sprintf( _n( + 'There\'s %1$s comment in your spam queue right now.', + 'There are %1$s comments in your spam queue right now.', + $queue_count + ), number_format_i18n( $queue_count ), $link ); + } else { + $queue_text = sprintf( __( "There's nothing in your spam queue at the moment." ), $link ); + } + + $text = $intro . '
' . $queue_text; + echo "

$text

\n"; + } + + add_action('rightnow_end', 'akismet_rightnow'); + + + // For WP >= 2.5 + function akismet_check_for_spam_button( $comment_status ) { + if ( 'approved' == $comment_status ) + return; + + if ( function_exists('plugins_url') ) + $link = add_query_arg( array( 'action' => 'akismet_recheck_queue' ), admin_url( 'admin.php' ) ); + else + $link = add_query_arg( array( 'page' => 'akismet-admin', 'recheckqueue' => 'true', 'noheader' => 'true' ), admin_url( 'edit-comments.php' ) ); + + echo '
' . esc_html__('Check for Spam') . ''; + echo ''; + } + add_action('manage_comments_nav', 'akismet_check_for_spam_button'); + + function akismet_submit_nonspam_comment ( $comment_id ) { + global $wpdb, $akismet_api_host, $akismet_api_port, $current_user, $current_site; + $comment_id = (int) $comment_id; + + $comment = $wpdb->get_row("SELECT * FROM $wpdb->comments WHERE comment_ID = '$comment_id'"); + if ( !$comment ) // it was deleted + return; + + // use the original version stored in comment_meta if available + $as_submitted = get_comment_meta( $comment_id, 'akismet_as_submitted', true); + if ( $as_submitted && is_array($as_submitted) && isset($as_submitted['comment_content']) ) { + $comment = (object) array_merge( (array)$comment, $as_submitted ); + } + + $comment->blog = get_bloginfo('url'); + $comment->blog_lang = get_locale(); + $comment->blog_charset = get_option('blog_charset'); + $comment->permalink = get_permalink($comment->comment_post_ID); + if ( is_object($current_user) ) { + $comment->reporter = $current_user->user_login; + } + if ( is_object($current_site) ) { + $comment->site_domain = $current_site->domain; + } + + $comment->user_role = ''; + if ( isset( $comment->user_ID ) ) + $comment->user_role = akismet_get_user_roles($comment->user_ID); + + if ( akismet_test_mode() ) + $comment->is_test = 'true'; + + $post = get_post( $comment->comment_post_ID ); + $comment->comment_post_modified_gmt = $post->post_modified_gmt; + + $query_string = ''; + foreach ( $comment as $key => $data ) + $query_string .= $key . '=' . urlencode( stripslashes($data) ) . '&'; + + $response = akismet_http_post($query_string, $akismet_api_host, "/1.1/submit-ham", $akismet_api_port); + if ( $comment->reporter ) { + akismet_update_comment_history( $comment_id, sprintf( __('%s reported this comment as not spam'), $comment->reporter ), 'report-ham' ); + update_comment_meta( $comment_id, 'akismet_user_result', 'false' ); + update_comment_meta( $comment_id, 'akismet_user', $comment->reporter ); + } + + do_action('akismet_submit_nonspam_comment', $comment_id, $response[1]); + } + + function akismet_submit_spam_comment ( $comment_id ) { + global $wpdb, $akismet_api_host, $akismet_api_port, $current_user, $current_site; + $comment_id = (int) $comment_id; + + $comment = $wpdb->get_row("SELECT * FROM $wpdb->comments WHERE comment_ID = '$comment_id'"); + if ( !$comment ) // it was deleted + return; + if ( 'spam' != $comment->comment_approved ) + return; + + // use the original version stored in comment_meta if available + $as_submitted = get_comment_meta( $comment_id, 'akismet_as_submitted', true); + if ( $as_submitted && is_array($as_submitted) && isset($as_submitted['comment_content']) ) { + $comment = (object) array_merge( (array)$comment, $as_submitted ); + } + + $comment->blog = get_bloginfo('url'); + $comment->blog_lang = get_locale(); + $comment->blog_charset = get_option('blog_charset'); + $comment->permalink = get_permalink($comment->comment_post_ID); + if ( is_object($current_user) ) { + $comment->reporter = $current_user->user_login; + } + if ( is_object($current_site) ) { + $comment->site_domain = $current_site->domain; + } + + $comment->user_role = ''; + if ( isset( $comment->user_ID ) ) + $comment->user_role = akismet_get_user_roles($comment->user_ID); + + if ( akismet_test_mode() ) + $comment->is_test = 'true'; + + $post = get_post( $comment->comment_post_ID ); + $comment->comment_post_modified_gmt = $post->post_modified_gmt; + + $query_string = ''; + foreach ( $comment as $key => $data ) + $query_string .= $key . '=' . urlencode( stripslashes($data) ) . '&'; + + $response = akismet_http_post($query_string, $akismet_api_host, "/1.1/submit-spam", $akismet_api_port); + if ( $comment->reporter ) { + akismet_update_comment_history( $comment_id, sprintf( __('%s reported this comment as spam'), $comment->reporter ), 'report-spam' ); + update_comment_meta( $comment_id, 'akismet_user_result', 'true' ); + update_comment_meta( $comment_id, 'akismet_user', $comment->reporter ); + } + do_action('akismet_submit_spam_comment', $comment_id, $response[1]); + } + + // For WP 2.7+ + function akismet_transition_comment_status( $new_status, $old_status, $comment ) { + if ( $new_status == $old_status ) + return; + + # we don't need to record a history item for deleted comments + if ( $new_status == 'delete' ) + return; + + if ( !is_admin() ) + return; + + if ( !current_user_can( 'edit_post', $comment->comment_post_ID ) && !current_user_can( 'moderate_comments' ) ) + return; + + if ( defined('WP_IMPORTING') && WP_IMPORTING == true ) + return; + + // if this is present, it means the status has been changed by a re-check, not an explicit user action + if ( get_comment_meta( $comment->comment_ID, 'akismet_rechecking' ) ) + return; + + global $current_user; + $reporter = ''; + if ( is_object( $current_user ) ) + $reporter = $current_user->user_login; + + // Assumption alert: + // We want to submit comments to Akismet only when a moderator explicitly spams or approves it - not if the status + // is changed automatically by another plugin. Unfortunately WordPress doesn't provide an unambiguous way to + // determine why the transition_comment_status action was triggered. And there are several different ways by which + // to spam and unspam comments: bulk actions, ajax, links in moderation emails, the dashboard, and perhaps others. + // We'll assume that this is an explicit user action if POST or GET has an 'action' key. + if ( isset($_POST['action']) || isset($_GET['action']) ) { + if ( $new_status == 'spam' && ( $old_status == 'approved' || $old_status == 'unapproved' || !$old_status ) ) { + return akismet_submit_spam_comment( $comment->comment_ID ); + } elseif ( $old_status == 'spam' && ( $new_status == 'approved' || $new_status == 'unapproved' ) ) { + return akismet_submit_nonspam_comment( $comment->comment_ID ); + } + } + + akismet_update_comment_history( $comment->comment_ID, sprintf( __('%s changed the comment status to %s'), $reporter, $new_status ), 'status-' . $new_status ); + } + + add_action( 'transition_comment_status', 'akismet_transition_comment_status', 10, 3 ); + + // Total spam in queue + // get_option( 'akismet_spam_count' ) is the total caught ever + function akismet_spam_count( $type = false ) { + global $wpdb; + + if ( !$type ) { // total + $count = wp_cache_get( 'akismet_spam_count', 'widget' ); + if ( false === $count ) { + if ( function_exists('wp_count_comments') ) { + $count = wp_count_comments(); + $count = $count->spam; + } else { + $count = (int) $wpdb->get_var("SELECT COUNT(comment_ID) FROM $wpdb->comments WHERE comment_approved = 'spam'"); + } + wp_cache_set( 'akismet_spam_count', $count, 'widget', 3600 ); + } + return $count; + } elseif ( 'comments' == $type || 'comment' == $type ) { // comments + $type = ''; + } else { // pingback, trackback, ... + $type = $wpdb->escape( $type ); + } + + return (int) $wpdb->get_var("SELECT COUNT(comment_ID) FROM $wpdb->comments WHERE comment_approved = 'spam' AND comment_type='$type'"); + } + + + function akismet_recheck_queue() { + global $wpdb, $akismet_api_host, $akismet_api_port; + + akismet_fix_scheduled_recheck(); + + if ( ! ( isset( $_GET['recheckqueue'] ) || ( isset( $_REQUEST['action'] ) && 'akismet_recheck_queue' == $_REQUEST['action'] ) ) ) + return; + + $paginate = ''; + if ( isset( $_POST['limit'] ) && isset( $_POST['offset'] ) ) { + $paginate = $wpdb->prepare( " LIMIT %d OFFSET %d", array( $_POST['limit'], $_POST['offset'] ) ); + } + $moderation = $wpdb->get_results( "SELECT * FROM {$wpdb->comments} WHERE comment_approved = '0'{$paginate}", ARRAY_A ); + foreach ( (array) $moderation as $c ) { + $c['user_ip'] = $c['comment_author_IP']; + $c['user_agent'] = $c['comment_agent']; + $c['referrer'] = ''; + $c['blog'] = get_bloginfo('url'); + $c['blog_lang'] = get_locale(); + $c['blog_charset'] = get_option('blog_charset'); + $c['permalink'] = get_permalink($c['comment_post_ID']); + + $c['user_role'] = ''; + if ( isset( $c['user_ID'] ) ) + $c['user_role'] = akismet_get_user_roles($c['user_ID']); + + if ( akismet_test_mode() ) + $c['is_test'] = 'true'; + + $id = (int) $c['comment_ID']; + + $query_string = ''; + foreach ( $c as $key => $data ) + $query_string .= $key . '=' . urlencode( stripslashes($data) ) . '&'; + + add_comment_meta( $c['comment_ID'], 'akismet_rechecking', true ); + $response = akismet_http_post($query_string, $akismet_api_host, '/1.1/comment-check', $akismet_api_port); + if ( 'true' == $response[1] ) { + wp_set_comment_status($c['comment_ID'], 'spam'); + update_comment_meta( $c['comment_ID'], 'akismet_result', 'true' ); + delete_comment_meta( $c['comment_ID'], 'akismet_error' ); + akismet_update_comment_history( $c['comment_ID'], __('Akismet re-checked and caught this comment as spam'), 'check-spam' ); + + } elseif ( 'false' == $response[1] ) { + update_comment_meta( $c['comment_ID'], 'akismet_result', 'false' ); + delete_comment_meta( $c['comment_ID'], 'akismet_error' ); + akismet_update_comment_history( $c['comment_ID'], __('Akismet re-checked and cleared this comment'), 'check-ham' ); + // abnormal result: error + } else { + update_comment_meta( $c['comment_ID'], 'akismet_result', 'error' ); + akismet_update_comment_history( $c['comment_ID'], sprintf( __('Akismet was unable to re-check this comment (response: %s)'), substr($response[1], 0, 50)), 'check-error' ); + } + + delete_comment_meta( $c['comment_ID'], 'akismet_rechecking' ); + } + if ( defined( 'DOING_AJAX' ) && DOING_AJAX ) { + wp_send_json( array( + 'processed' => count((array) $moderation), + )); + } + else { + $redirect_to = isset( $_SERVER['HTTP_REFERER'] ) ? $_SERVER['HTTP_REFERER'] : admin_url( 'edit-comments.php' ); + wp_safe_redirect( $redirect_to ); + exit; + } + } + + add_action('admin_action_akismet_recheck_queue', 'akismet_recheck_queue'); + add_action('wp_ajax_akismet_recheck_queue', 'akismet_recheck_queue'); + + // Adds an 'x' link next to author URLs, clicking will remove the author URL and show an undo link + function akismet_remove_comment_author_url() { + if ( !empty($_POST['id'] ) && check_admin_referer( 'comment_author_url_nonce' ) ) { + global $wpdb; + $comment = get_comment( intval($_POST['id']), ARRAY_A ); + if (current_user_can('edit_comment', $comment['comment_ID'])) { + $comment['comment_author_url'] = ''; + do_action( 'comment_remove_author_url' ); + print(wp_update_comment( $comment )); + die(); + } + } + } + + add_action('wp_ajax_comment_author_deurl', 'akismet_remove_comment_author_url'); + + function akismet_add_comment_author_url() { + if ( !empty( $_POST['id'] ) && !empty( $_POST['url'] ) && check_admin_referer( 'comment_author_url_nonce' ) ) { + global $wpdb; + $comment = get_comment( intval($_POST['id']), ARRAY_A ); + if (current_user_can('edit_comment', $comment['comment_ID'])) { + $comment['comment_author_url'] = esc_url($_POST['url']); + do_action( 'comment_add_author_url' ); + print(wp_update_comment( $comment )); + die(); + } + } + } + + add_action('wp_ajax_comment_author_reurl', 'akismet_add_comment_author_url'); + + // Check connectivity between the WordPress blog and Akismet's servers. + // Returns an associative array of server IP addresses, where the key is the IP address, and value is true (available) or false (unable to connect). + function akismet_check_server_connectivity() { + global $akismet_api_host, $akismet_api_port, $wpcom_api_key; + + $test_host = 'rest.akismet.com'; + + // Some web hosts may disable one or both functions + if ( !function_exists('fsockopen') || !function_exists('gethostbynamel') ) + return array(); + + $ips = gethostbynamel($test_host); + if ( !$ips || !is_array($ips) || !count($ips) ) + return array(); + + $servers = array(); + foreach ( $ips as $ip ) { + $response = akismet_verify_key( akismet_get_key(), $ip ); + // even if the key is invalid, at least we know we have connectivity + if ( $response == 'valid' || $response == 'invalid' ) + $servers[$ip] = true; + else + $servers[$ip] = false; + } + + return $servers; + } + + // Check the server connectivity and store the results in an option. + // Cached results will be used if not older than the specified timeout in seconds; use $cache_timeout = 0 to force an update. + // Returns the same associative array as akismet_check_server_connectivity() + function akismet_get_server_connectivity( $cache_timeout = 86400 ) { + $servers = get_option('akismet_available_servers'); + if ( (time() - get_option('akismet_connectivity_time') < $cache_timeout) && $servers !== false ) + return $servers; + + // There's a race condition here but the effect is harmless. + $servers = akismet_check_server_connectivity(); + update_option('akismet_available_servers', $servers); + update_option('akismet_connectivity_time', time()); + return $servers; + } + + // Returns true if server connectivity was OK at the last check, false if there was a problem that needs to be fixed. + function akismet_server_connectivity_ok() { + // skip the check on WPMU because the status page is hidden + global $wpcom_api_key; + if ( $wpcom_api_key ) + return true; + $servers = akismet_get_server_connectivity(); + return !( empty($servers) || !count($servers) || count( array_filter($servers) ) < count($servers) ); + } + + function akismet_admin_menu() { + if ( class_exists( 'Jetpack' ) ) { + add_action( 'jetpack_admin_menu', 'akismet_load_menu' ); + } else { + akismet_load_menu(); + } + } + + function akismet_load_menu() { + if ( class_exists( 'Jetpack' ) ) { + add_submenu_page( 'jetpack', __( 'Akismet' ), __( 'Akismet' ), 'manage_options', 'akismet-key-config', 'akismet_conf' ); + add_submenu_page( 'jetpack', __( 'Akismet Stats' ), __( 'Akismet Stats' ), 'manage_options', 'akismet-stats-display', 'akismet_stats_display' ); + } else { + add_submenu_page('plugins.php', __('Akismet'), __('Akismet'), 'manage_options', 'akismet-key-config', 'akismet_conf'); + add_submenu_page('index.php', __('Akismet Stats'), __('Akismet Stats'), 'manage_options', 'akismet-stats-display', 'akismet_stats_display'); + } + } diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.css /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.css *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.css 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.css 2014-03-14 02:57:39.000000000 +0300 *************** *** 0 **** --- 1 ---- + #submitted-on{position:relative}#the-comment-list .author .akismet-user-comment-count{display:inline}#the-comment-list .author a span{text-decoration:none;color:#999}#the-comment-list .remove_url{margin-left:3px;color:#999;padding:2px 3px 2px 0}#the-comment-list .remove_url:hover{color:#A7301F;font-weight:bold;padding:2px 2px 2px 0}#dashboard_recent_comments .akismet-status{display:none}.akismet-status{float:right}.akismet-status a{color:#AAA;font-style:italic}span.comment-link a{text-decoration:underline}span.comment-link:after{content:" "attr(title) " ";color:#aaa;text-decoration:none}.mshot-arrow{width:0;height:0;border-top:10px solid transparent;border-bottom:10px solid transparent;border-right:10px solid #5C5C5C;position:absolute;left:-6px;top:91px}.mshot-container{background:#5C5C5C;position:absolute;top:-94px;padding:7px;width:450px;height:338px;z-index:20000;-moz-border-radius:6px;border-radius:6px;-webkit-border-radius:6px}h2.ak-header{padding-left:38px;background:url('img/logo.png') no-repeat 0 9px;margin-bottom:14px;line-height:32px}.key-status{padding:0.4em 1em;color:#fff;font-weight:bold;text-align:center;-webkit-border-radius:3px;border-radius:3px;border-width:1px;border-style:solid;max-width:23.3em}input#key{width:25.3em !important}input#key.valid{border-color:#4F800D}input#key.invalid,input#key.failed{border-color:#888}.key-status.under-input{margin-top:-5px;padding-bottom:0px}.key-status.invalid,.key-status.failed{background-color:#888}.key-status.valid{background-color:#4F800D}.key-status.some{background-color:#993300}.key-status.empty{display:none}table.network-status th,table.network-status td{padding:0.4em;margin:0;text-align:center}table.network-status{border-color:#dfdfdf;border-width:0 0 1px 1px;border-style:solid;border-spacing:0;width:25.6em}table.network-status th,table.network-status td{border-color:#dfdfdf;border-width:1px 1px 0 0;border-style:solid;margin:0;border-spacing:0}table.network-status td.key-status{border-radius:0px;-webkit-border-radius:0px}.checkforspam{display:inline-block !important;}.checkforspam-spinner{display:none;margin-top:10px;} \ No newline at end of file Binary files /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.gif and /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.gif differ diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.js /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.js *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.js 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.js 2014-03-14 02:57:39.000000000 +0300 *************** *** 0 **** --- 1,159 ---- + jQuery( function ( $ ) { + $( '.switch-have-key' ).click( function() { + var no_key = $( this ).parents().find('div.no-key'); + var have_key = $( this ).parents().find('div.have-key'); + + no_key.addClass( 'hidden' ); + have_key.removeClass( 'hidden' ); + + return false; + }); + $( 'p.need-key a' ).click( function(){ + document.akismet_activate.submit(); + }); + $('.akismet-status').each(function () { + var thisId = $(this).attr('commentid'); + $(this).prependTo('#comment-' + thisId + ' .column-comment div:first-child'); + }); + $('.akismet-user-comment-count').each(function () { + var thisId = $(this).attr('commentid'); + $(this).insertAfter('#comment-' + thisId + ' .author strong:first').show(); + }); + $('#the-comment-list').find('tr.comment, tr[id ^= "comment-"]').find('.column-author a[title ^= "http://"]').each(function () { + var thisTitle = $(this).attr('title'); + thisCommentId = $(this).parents('tr:first').attr('id').split("-"); + + $(this).attr("id", "author_comment_url_"+ thisCommentId[1]); + + if (thisTitle) { + $(this).after( + $( 'x' ) + .attr( 'commentid', thisCommentId[1] ) + .attr( 'title', WPAkismet.strings['Remove this URL'] ) + ); + } + }); + $('.remove_url').live('click', function () { + var thisId = $(this).attr('commentid'); + var data = { + action: 'comment_author_deurl', + _wpnonce: WPAkismet.comment_author_url_nonce, + id: thisId + }; + $.ajax({ + url: ajaxurl, + type: 'POST', + data: data, + beforeSend: function () { + // Removes "x" link + $("a[commentid='"+ thisId +"']").hide(); + // Show temp status + $("#author_comment_url_"+ thisId).html( $( '' ).text( WPAkismet.strings['Removing...'] ) ); + }, + success: function (response) { + if (response) { + // Show status/undo link + $("#author_comment_url_"+ thisId) + .attr('cid', thisId) + .addClass('akismet_undo_link_removal') + .html( + $( '' ).text( WPAkismet.strings['URL removed'] ) + ) + .append( ' ' ) + .append( + $( '' ) + .text( WPAkismet.strings['(undo)'] ) + .addClass( 'akismet-span-link' ) + ); + } + } + }); + + return false; + }); + $('.akismet_undo_link_removal').live('click', function () { + var thisId = $(this).attr('cid'); + var thisUrl = $(this).attr('href').replace("http://www.", "").replace("http://", ""); + var data = { + action: 'comment_author_reurl', + _wpnonce: WPAkismet.comment_author_url_nonce, + id: thisId, + url: thisUrl + }; + $.ajax({ + url: ajaxurl, + type: 'POST', + data: data, + beforeSend: function () { + // Show temp status + $("#author_comment_url_"+ thisId).html( $( '' ).text( WPAkismet.strings['Re-adding...'] ) ); + }, + success: function (response) { + if (response) { + // Add "x" link + $("a[commentid='"+ thisId +"']").show(); + // Show link + $("#author_comment_url_"+ thisId).removeClass('akismet_undo_link_removal').html(thisUrl); + } + } + }); + + return false; + }); + $('a[id^="author_comment_url"], tr.pingback td.column-author a:first-of-type').mouseover(function () { + var wpcomProtocol = ( 'https:' === location.protocol ) ? 'https://' : 'http://'; + // Need to determine size of author column + var thisParentWidth = $(this).parent().width(); + // It changes based on if there is a gravatar present + thisParentWidth = ($(this).parent().find('.grav-hijack').length) ? thisParentWidth - 42 + 'px' : thisParentWidth + 'px'; + if ($(this).find('.mShot').length == 0 && !$(this).hasClass('akismet_undo_link_removal')) { + var self = $( this ); + $('.widefat td').css('overflow', 'visible'); + $(this).css('position', 'relative'); + var thisHref = $.URLEncode( $(this).attr('href') ); + $(this).append('
'); + setTimeout(function () { + self.find( '.mshot-image' ).attr('src', '//s0.wordpress.com/mshots/v1/'+thisHref+'?w=450&r=2'); + }, 6000); + setTimeout(function () { + self.find( '.mshot-image' ).attr('src', '//s0.wordpress.com/mshots/v1/'+thisHref+'?w=450&r=3'); + }, 12000); + } else { + $(this).find('.mShot').css('left', thisParentWidth).show(); + } + }).mouseout(function () { + $(this).find('.mShot').hide(); + }); + $('.checkforspam:not(.button-disabled)').click( function(e) { + $('.checkforspam:not(.button-disabled)').addClass('button-disabled'); + $('.checkforspam-spinner').show(); + akismet_check_for_spam(0, 100); + e.preventDefault(); + }); + + function akismet_check_for_spam(offset, limit) { + $.post( + ajaxurl, + { + 'action': 'akismet_recheck_queue', + 'offset': offset, + 'limit': limit + }, + function(result) { + if (result.processed < limit) { + window.location.reload(); + } + else { + akismet_check_for_spam(offset + limit, limit); + } + } + ); + } + }); + // URL encode plugin + jQuery.extend({URLEncode:function(c){var o='';var x=0;c=c.toString();var r=/(^[a-zA-Z0-9_.]*)/; + while(x1 && m[1]!=''){o+=m[1];x+=m[1].length; + }else{if(c[x]==' ')o+='+';else{var d=c.charCodeAt(x);var h=d.toString(16); + o+='%'+(h.length<2?'0':'')+h.toUpperCase();}x++;}}return o;} + }); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/akismet.php 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/akismet.php 2014-03-18 04:18:23.000000000 +0300 *************** *** 0 **** --- 1,700 ---- + protect your blog from comment and trackback spam. It keeps your site protected from spam even while you sleep. To get started: 1) Click the "Activate" link to the left of this description, 2) Sign up for an Akismet API key, and 3) Go to your Akismet configuration page, and save your API key. + Version: 2.6.0 + Author: Automattic + Author URI: http://automattic.com/wordpress-plugins/ + License: GPLv2 or later + */ + + /* + This program is free software; you can redistribute it and/or + modify it under the terms of the GNU General Public License + as published by the Free Software Foundation; either version 2 + of the License, or (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + You should have received a copy of the GNU General Public License + along with this program; if not, write to the Free Software + Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. + */ + + // Make sure we don't expose any info if called directly + if ( !function_exists( 'add_action' ) ) { + echo 'Hi there! I\'m just a plugin, not much I can do when called directly.'; + exit; + } + + define('AKISMET_VERSION', '2.6.0'); + define('AKISMET_PLUGIN_URL', plugin_dir_url( __FILE__ )); + define('AKISMET_DELETE_LIMIT', 10000); + + /** If you hardcode a WP.com API key here, all key config screens will be hidden */ + if ( defined('WPCOM_API_KEY') ) + $wpcom_api_key = constant('WPCOM_API_KEY'); + else + $wpcom_api_key = ''; + + if ( isset($wp_db_version) && $wp_db_version <= 9872 ) + include_once dirname( __FILE__ ) . '/legacy.php'; + + include_once dirname( __FILE__ ) . '/widget.php'; + + if ( is_admin() ) + require_once dirname( __FILE__ ) . '/admin.php'; + + function akismet_init() { + global $wpcom_api_key, $akismet_api_host, $akismet_api_port; + + if ( $wpcom_api_key ) + $akismet_api_host = $wpcom_api_key . '.rest.akismet.com'; + else + $akismet_api_host = get_option('wordpress_api_key') . '.rest.akismet.com'; + + $akismet_api_port = 80; + } + add_action('init', 'akismet_init'); + + function akismet_get_key() { + global $wpcom_api_key; + if ( !empty($wpcom_api_key) ) + return $wpcom_api_key; + return get_option('wordpress_api_key'); + } + + function akismet_check_key_status( $key, $ip = null ) { + global $akismet_api_host, $akismet_api_port, $wpcom_api_key; + $blog = urlencode( get_option('home') ); + if ( $wpcom_api_key ) + $key = $wpcom_api_key; + $response = akismet_http_post("key=$key&blog=$blog", 'rest.akismet.com', '/1.1/verify-key', $akismet_api_port, $ip); + return $response; + } + + // given a response from an API call like akismet_check_key_status(), update the alert code options if an alert is present. + function akismet_update_alert( $response ) { + $code = $msg = null; + if ( isset($response[0]['x-akismet-alert-code']) ) { + $code = $response[0]['x-akismet-alert-code']; + $msg = $response[0]['x-akismet-alert-msg']; + } + + // only call update_option() if the value has changed + if ( $code != get_option( 'akismet_alert_code' ) ) { + update_option( 'akismet_alert_code', $code ); + update_option( 'akismet_alert_msg', $msg ); + } + } + + function akismet_verify_key( $key, $ip = null ) { + $response = akismet_check_key_status( $key, $ip ); + akismet_update_alert( $response ); + if ( !is_array($response) || !isset($response[1]) || $response[1] != 'valid' && $response[1] != 'invalid' ) + return 'failed'; + return $response[1]; + } + + // if we're in debug or test modes, use a reduced service level so as not to polute training or stats data + function akismet_test_mode() { + if ( defined('AKISMET_TEST_MODE') && AKISMET_TEST_MODE ) + return true; + return false; + } + + // return a comma-separated list of role names for the given user + function akismet_get_user_roles( $user_id ) { + $roles = false; + + if ( !class_exists('WP_User') ) + return false; + + if ( $user_id > 0 ) { + $comment_user = new WP_User($user_id); + if ( isset($comment_user->roles) ) + $roles = join(',', $comment_user->roles); + } + + if ( is_multisite() && is_super_admin( $user_id ) ) { + if ( empty( $roles ) ) { + $roles = 'super_admin'; + } else { + $comment_user->roles[] = 'super_admin'; + $roles = join( ',', $comment_user->roles ); + } + } + + return $roles; + } + + // Returns array with headers in $response[0] and body in $response[1] + function akismet_http_post($request, $host, $path, $port = 80, $ip=null) { + global $wp_version; + + $akismet_ua = "WordPress/{$wp_version} | "; + $akismet_ua .= 'Akismet/' . constant( 'AKISMET_VERSION' ); + + $akismet_ua = apply_filters( 'akismet_ua', $akismet_ua ); + + $content_length = strlen( $request ); + + $http_host = $host; + // use a specific IP if provided + // needed by akismet_check_server_connectivity() + if ( $ip && long2ip( ip2long( $ip ) ) ) { + $http_host = $ip; + } else { + $http_host = $host; + } + + // use the WP HTTP class if it is available + if ( function_exists( 'wp_remote_post' ) ) { + $http_args = array( + 'body' => $request, + 'headers' => array( + 'Content-Type' => 'application/x-www-form-urlencoded; ' . + 'charset=' . get_option( 'blog_charset' ), + 'Host' => $host, + 'User-Agent' => $akismet_ua + ), + 'httpversion' => '1.0', + 'timeout' => 15 + ); + $akismet_url = "http://{$http_host}{$path}"; + $response = wp_remote_post( $akismet_url, $http_args ); + if ( is_wp_error( $response ) ) + return ''; + + return array( $response['headers'], $response['body'] ); + } else { + $http_request = "POST $path HTTP/1.0\r\n"; + $http_request .= "Host: $host\r\n"; + $http_request .= 'Content-Type: application/x-www-form-urlencoded; charset=' . get_option('blog_charset') . "\r\n"; + $http_request .= "Content-Length: {$content_length}\r\n"; + $http_request .= "User-Agent: {$akismet_ua}\r\n"; + $http_request .= "\r\n"; + $http_request .= $request; + + $response = ''; + if( false != ( $fs = @fsockopen( $http_host, $port, $errno, $errstr, 10 ) ) ) { + fwrite( $fs, $http_request ); + + while ( !feof( $fs ) ) + $response .= fgets( $fs, 1160 ); // One TCP-IP packet + fclose( $fs ); + $response = explode( "\r\n\r\n", $response, 2 ); + } + return $response; + } + } + + // filter handler used to return a spam result to pre_comment_approved + function akismet_result_spam( $approved ) { + static $just_once = false; + if ( $just_once ) + return $approved; + + // bump the counter here instead of when the filter is added to reduce the possibility of overcounting + if ( $incr = apply_filters('akismet_spam_count_incr', 1) ) + update_option( 'akismet_spam_count', get_option('akismet_spam_count') + $incr ); + + // this is a one-shot deal + $just_once = true; + return 'spam'; + } + + function akismet_result_hold( $approved ) { + static $just_once = false; + if ( $just_once ) + return $approved; + + // once only + $just_once = true; + return '0'; + } + + // how many approved comments does this author have? + function akismet_get_user_comments_approved( $user_id, $comment_author_email, $comment_author, $comment_author_url ) { + global $wpdb; + + if ( !empty($user_id) ) + return $wpdb->get_var( $wpdb->prepare( "SELECT COUNT(*) FROM $wpdb->comments WHERE user_id = %d AND comment_approved = 1", $user_id ) ); + + if ( !empty($comment_author_email) ) + return $wpdb->get_var( $wpdb->prepare( "SELECT COUNT(*) FROM $wpdb->comments WHERE comment_author_email = %s AND comment_author = %s AND comment_author_url = %s AND comment_approved = 1", $comment_author_email, $comment_author, $comment_author_url ) ); + + return 0; + } + + function akismet_microtime() { + $mtime = explode( ' ', microtime() ); + return $mtime[1] + $mtime[0]; + } + + // log an event for a given comment, storing it in comment_meta + function akismet_update_comment_history( $comment_id, $message, $event=null ) { + global $current_user; + + // failsafe for old WP versions + if ( !function_exists('add_comment_meta') ) + return false; + + $user = ''; + if ( is_object($current_user) && isset($current_user->user_login) ) + $user = $current_user->user_login; + + $event = array( + 'time' => akismet_microtime(), + 'message' => $message, + 'event' => $event, + 'user' => $user, + ); + + // $unique = false so as to allow multiple values per comment + $r = add_comment_meta( $comment_id, 'akismet_history', $event, false ); + } + + // get the full comment history for a given comment, as an array in reverse chronological order + function akismet_get_comment_history( $comment_id ) { + + // failsafe for old WP versions + if ( !function_exists('add_comment_meta') ) + return false; + + $history = get_comment_meta( $comment_id, 'akismet_history', false ); + usort( $history, 'akismet_cmp_time' ); + return $history; + } + + function akismet_cmp_time( $a, $b ) { + return $a['time'] > $b['time'] ? -1 : 1; + } + + // this fires on wp_insert_comment. we can't update comment_meta when akismet_auto_check_comment() runs + // because we don't know the comment ID at that point. + function akismet_auto_check_update_meta( $id, $comment ) { + global $akismet_last_comment; + + // failsafe for old WP versions + if ( !function_exists('add_comment_meta') ) + return false; + + if ( !isset( $akismet_last_comment['comment_author_email'] ) ) + $akismet_last_comment['comment_author_email'] = ''; + + // wp_insert_comment() might be called in other contexts, so make sure this is the same comment + // as was checked by akismet_auto_check_comment + if ( is_object($comment) && !empty($akismet_last_comment) && is_array($akismet_last_comment) ) { + if ( isset($akismet_last_comment['comment_post_ID']) && intval($akismet_last_comment['comment_post_ID']) == intval($comment->comment_post_ID) + && $akismet_last_comment['comment_author'] == $comment->comment_author + && $akismet_last_comment['comment_author_email'] == $comment->comment_author_email ) { + // normal result: true or false + if ( $akismet_last_comment['akismet_result'] == 'true' ) { + update_comment_meta( $comment->comment_ID, 'akismet_result', 'true' ); + akismet_update_comment_history( $comment->comment_ID, __('Akismet caught this comment as spam'), 'check-spam' ); + if ( $comment->comment_approved != 'spam' ) + akismet_update_comment_history( $comment->comment_ID, sprintf( __('Comment status was changed to %s'), $comment->comment_approved), 'status-changed'.$comment->comment_approved ); + } elseif ( $akismet_last_comment['akismet_result'] == 'false' ) { + update_comment_meta( $comment->comment_ID, 'akismet_result', 'false' ); + akismet_update_comment_history( $comment->comment_ID, __('Akismet cleared this comment'), 'check-ham' ); + if ( $comment->comment_approved == 'spam' ) { + if ( wp_blacklist_check($comment->comment_author, $comment->comment_author_email, $comment->comment_author_url, $comment->comment_content, $comment->comment_author_IP, $comment->comment_agent) ) + akismet_update_comment_history( $comment->comment_ID, __('Comment was caught by wp_blacklist_check'), 'wp-blacklisted' ); + else + akismet_update_comment_history( $comment->comment_ID, sprintf( __('Comment status was changed to %s'), $comment->comment_approved), 'status-changed-'.$comment->comment_approved ); + } + // abnormal result: error + } else { + update_comment_meta( $comment->comment_ID, 'akismet_error', time() ); + akismet_update_comment_history( $comment->comment_ID, sprintf( __('Akismet was unable to check this comment (response: %s), will automatically retry again later.'), substr($akismet_last_comment['akismet_result'], 0, 50)), 'check-error' ); + } + + // record the complete original data as submitted for checking + if ( isset($akismet_last_comment['comment_as_submitted']) ) + update_comment_meta( $comment->comment_ID, 'akismet_as_submitted', $akismet_last_comment['comment_as_submitted'] ); + } + } + } + + add_action( 'wp_insert_comment', 'akismet_auto_check_update_meta', 10, 2 ); + + + function akismet_auto_check_comment( $commentdata ) { + global $akismet_api_host, $akismet_api_port, $akismet_last_comment; + + $comment = $commentdata; + $comment['user_ip'] = akismet_get_ip_address(); + $comment['user_agent'] = isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : null; + $comment['referrer'] = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : null; + $comment['blog'] = get_option('home'); + $comment['blog_lang'] = get_locale(); + $comment['blog_charset'] = get_option('blog_charset'); + $comment['permalink'] = get_permalink($comment['comment_post_ID']); + + if ( !empty( $comment['user_ID'] ) ) { + $comment['user_role'] = akismet_get_user_roles( $comment['user_ID'] ); + } + + $akismet_nonce_option = apply_filters( 'akismet_comment_nonce', get_option( 'akismet_comment_nonce' ) ); + $comment['akismet_comment_nonce'] = 'inactive'; + if ( $akismet_nonce_option == 'true' || $akismet_nonce_option == '' ) { + $comment['akismet_comment_nonce'] = 'failed'; + if ( isset( $_POST['akismet_comment_nonce'] ) && wp_verify_nonce( $_POST['akismet_comment_nonce'], 'akismet_comment_nonce_' . $comment['comment_post_ID'] ) ) + $comment['akismet_comment_nonce'] = 'passed'; + + // comment reply in wp-admin + if ( isset( $_POST['_ajax_nonce-replyto-comment'] ) && check_ajax_referer( 'replyto-comment', '_ajax_nonce-replyto-comment' ) ) + $comment['akismet_comment_nonce'] = 'passed'; + + } + + if ( akismet_test_mode() ) + $comment['is_test'] = 'true'; + + foreach ($_POST as $key => $value ) { + if ( is_string($value) ) + $comment["POST_{$key}"] = $value; + } + + $ignore = array( 'HTTP_COOKIE', 'HTTP_COOKIE2', 'PHP_AUTH_PW' ); + + foreach ( $_SERVER as $key => $value ) { + if ( !in_array( $key, $ignore ) && is_string($value) ) + $comment["$key"] = $value; + else + $comment["$key"] = ''; + } + + $post = get_post( $comment['comment_post_ID'] ); + $comment[ 'comment_post_modified_gmt' ] = $post->post_modified_gmt; + + $query_string = ''; + foreach ( $comment as $key => $data ) + $query_string .= $key . '=' . urlencode( stripslashes($data) ) . '&'; + + $commentdata['comment_as_submitted'] = $comment; + + $response = akismet_http_post($query_string, $akismet_api_host, '/1.1/comment-check', $akismet_api_port); + do_action( 'akismet_comment_check_response', $response ); + akismet_update_alert( $response ); + $commentdata['akismet_result'] = $response[1]; + if ( 'true' == $response[1] ) { + // akismet_spam_count will be incremented later by akismet_result_spam() + add_filter('pre_comment_approved', 'akismet_result_spam'); + + do_action( 'akismet_spam_caught' ); + + $last_updated = strtotime( $post->post_modified_gmt ); + $diff = time() - $last_updated; + $diff = $diff / 86400; + + if ( $post->post_type == 'post' && $diff > 30 && get_option( 'akismet_discard_month' ) == 'true' && empty($comment['user_ID']) ) { + // akismet_result_spam() won't be called so bump the counter here + if ( $incr = apply_filters('akismet_spam_count_incr', 1) ) + update_option( 'akismet_spam_count', get_option('akismet_spam_count') + $incr ); + $redirect_to = isset( $_SERVER['HTTP_REFERER'] ) ? $_SERVER['HTTP_REFERER'] : get_permalink( $post ); + wp_safe_redirect( $redirect_to ); + die(); + } + } + + // if the response is neither true nor false, hold the comment for moderation and schedule a recheck + if ( 'true' != $response[1] && 'false' != $response[1] ) { + if ( !current_user_can('moderate_comments') ) { + add_filter('pre_comment_approved', 'akismet_result_hold'); + } + if ( !wp_next_scheduled( 'akismet_schedule_cron_recheck' ) ) { + wp_schedule_single_event( time() + 1200, 'akismet_schedule_cron_recheck' ); + } + } + + if ( function_exists('wp_next_scheduled') && function_exists('wp_schedule_event') ) { + // WP 2.1+: delete old comments daily + if ( !wp_next_scheduled('akismet_scheduled_delete') ) + wp_schedule_event(time(), 'daily', 'akismet_scheduled_delete'); + } elseif ( (mt_rand(1, 10) == 3) ) { + // WP 2.0: run this one time in ten + akismet_delete_old(); + } + $akismet_last_comment = $commentdata; + + akismet_fix_scheduled_recheck(); + return $commentdata; + } + + add_action('preprocess_comment', 'akismet_auto_check_comment', 1); + + function akismet_get_ip_address() { + foreach( array( 'HTTP_CLIENT_IP', 'HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED', 'HTTP_X_CLUSTER_CLIENT_IP', 'HTTP_FORWARDED_FOR', 'HTTP_FORWARDED', 'REMOTE_ADDR' ) as $key ) { + if ( array_key_exists( $key, $_SERVER ) === true ) { + foreach ( explode( ',', $_SERVER[$key] ) as $ip ) { + $ip = trim($ip); + + if ( filter_var( $ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) !== false ) { + return $ip; + } + } + } + } + return null; + } + + function akismet_delete_old() { + global $wpdb; + + while( $comment_ids = $wpdb->get_col( $wpdb->prepare( "SELECT comment_id FROM {$wpdb->comments} WHERE DATE_SUB(NOW(), INTERVAL 15 DAY) > comment_date_gmt AND comment_approved = 'spam' LIMIT %d", defined( 'AKISMET_DELETE_LIMIT' ) ? AKISMET_DELETE_LIMIT : 10000 ) ) ) { + if ( empty( $comment_ids ) ) + return; + + $wpdb->queries = array(); + + do_action( 'delete_comment', $comment_ids ); + + $comma_comment_ids = implode( ', ', array_map('intval', $comment_ids) ); + + $wpdb->query("DELETE FROM {$wpdb->comments} WHERE comment_id IN ( $comma_comment_ids )"); + $wpdb->query("DELETE FROM {$wpdb->commentmeta} WHERE comment_id IN ( $comma_comment_ids )"); + + clean_comment_cache( $comment_ids ); + } + + if ( apply_filters( 'akismet_optimize_table', ( mt_rand(1, 5000) == 11) ) ) // lucky number + $wpdb->query("OPTIMIZE TABLE {$wpdb->comments}"); + } + + function akismet_delete_old_metadata() { + global $wpdb; + + $interval = apply_filters( 'akismet_delete_commentmeta_interval', 15 ); + + # enfore a minimum of 1 day + $interval = absint( $interval ); + if ( $interval < 1 ) + $interval = 1; + + // akismet_as_submitted meta values are large, so expire them + // after $interval days regardless of the comment status + while ( $comment_ids = $wpdb->get_col( $wpdb->prepare( "SELECT m.comment_id FROM {$wpdb->commentmeta} as m INNER JOIN {$wpdb->comments} as c USING(comment_id) WHERE m.meta_key = 'akismet_as_submitted' AND DATE_SUB(NOW(), INTERVAL %d DAY) > c.comment_date_gmt LIMIT 10000", $interval ) ) ) { + if ( empty( $comment_ids ) ) + return; + + $wpdb->queries = array(); + + foreach ( $comment_ids as $comment_id ) { + delete_comment_meta( $comment_id, 'akismet_as_submitted' ); + } + } + + if ( apply_filters( 'akismet_optimize_table', ( mt_rand(1, 5000) == 11) ) ) // lucky number + $wpdb->query("OPTIMIZE TABLE {$wpdb->comments}"); + } + + add_action('akismet_scheduled_delete', 'akismet_delete_old'); + add_action('akismet_scheduled_delete', 'akismet_delete_old_metadata'); + + function akismet_check_db_comment( $id, $recheck_reason = 'recheck_queue' ) { + global $wpdb, $akismet_api_host, $akismet_api_port; + + $id = (int) $id; + $c = $wpdb->get_row( "SELECT * FROM $wpdb->comments WHERE comment_ID = '$id'", ARRAY_A ); + if ( !$c ) + return; + + $c['user_ip'] = $c['comment_author_IP']; + $c['user_agent'] = $c['comment_agent']; + $c['referrer'] = ''; + $c['blog'] = get_option('home'); + $c['blog_lang'] = get_locale(); + $c['blog_charset'] = get_option('blog_charset'); + $c['permalink'] = get_permalink($c['comment_post_ID']); + $id = $c['comment_ID']; + if ( akismet_test_mode() ) + $c['is_test'] = 'true'; + $c['recheck_reason'] = $recheck_reason; + + $query_string = ''; + foreach ( $c as $key => $data ) + $query_string .= $key . '=' . urlencode( stripslashes($data) ) . '&'; + + $response = akismet_http_post($query_string, $akismet_api_host, '/1.1/comment-check', $akismet_api_port); + return ( is_array( $response ) && isset( $response[1] ) ) ? $response[1] : false; + } + + function akismet_cron_recheck() { + global $wpdb; + + $status = akismet_verify_key( akismet_get_key() ); + if ( get_option( 'akismet_alert_code' ) || $status == 'invalid' ) { + // since there is currently a problem with the key, reschedule a check for 6 hours hence + wp_schedule_single_event( time() + 21600, 'akismet_schedule_cron_recheck' ); + return false; + } + + delete_option('akismet_available_servers'); + + $comment_errors = $wpdb->get_col( " + SELECT comment_id + FROM {$wpdb->prefix}commentmeta + WHERE meta_key = 'akismet_error' + LIMIT 100 + " ); + + foreach ( (array) $comment_errors as $comment_id ) { + // if the comment no longer exists, or is too old, remove the meta entry from the queue to avoid getting stuck + $comment = get_comment( $comment_id ); + if ( !$comment || strtotime( $comment->comment_date_gmt ) < strtotime( "-15 days" ) ) { + delete_comment_meta( $comment_id, 'akismet_error' ); + continue; + } + + add_comment_meta( $comment_id, 'akismet_rechecking', true ); + $status = akismet_check_db_comment( $comment_id, 'retry' ); + + $msg = ''; + if ( $status == 'true' ) { + $msg = __( 'Akismet caught this comment as spam during an automatic retry.' ); + } elseif ( $status == 'false' ) { + $msg = __( 'Akismet cleared this comment during an automatic retry.' ); + } + + // If we got back a legit response then update the comment history + // other wise just bail now and try again later. No point in + // re-trying all the comments once we hit one failure. + if ( !empty( $msg ) ) { + delete_comment_meta( $comment_id, 'akismet_error' ); + akismet_update_comment_history( $comment_id, $msg, 'cron-retry' ); + update_comment_meta( $comment_id, 'akismet_result', $status ); + // make sure the comment status is still pending. if it isn't, that means the user has already moved it elsewhere. + $comment = get_comment( $comment_id ); + if ( $comment && 'unapproved' == wp_get_comment_status( $comment_id ) ) { + if ( $status == 'true' ) { + wp_spam_comment( $comment_id ); + } elseif ( $status == 'false' ) { + // comment is good, but it's still in the pending queue. depending on the moderation settings + // we may need to change it to approved. + if ( check_comment($comment->comment_author, $comment->comment_author_email, $comment->comment_author_url, $comment->comment_content, $comment->comment_author_IP, $comment->comment_agent, $comment->comment_type) ) + wp_set_comment_status( $comment_id, 1 ); + } + } + } else { + delete_comment_meta( $comment_id, 'akismet_rechecking' ); + wp_schedule_single_event( time() + 1200, 'akismet_schedule_cron_recheck' ); + return; + } + delete_comment_meta( $comment_id, 'akismet_rechecking' ); + } + + $remaining = $wpdb->get_var( "SELECT COUNT(*) FROM $wpdb->commentmeta WHERE meta_key = 'akismet_error'" ); + if ( $remaining && !wp_next_scheduled('akismet_schedule_cron_recheck') ) { + wp_schedule_single_event( time() + 1200, 'akismet_schedule_cron_recheck' ); + } + } + add_action( 'akismet_schedule_cron_recheck', 'akismet_cron_recheck' ); + + function akismet_add_comment_nonce( $post_id ) { + echo '

'; + wp_nonce_field( 'akismet_comment_nonce_' . $post_id, 'akismet_comment_nonce', FALSE ); + echo '

'; + } + + $akismet_comment_nonce_option = apply_filters( 'akismet_comment_nonce', get_option( 'akismet_comment_nonce' ) ); + + if ( $akismet_comment_nonce_option == 'true' || $akismet_comment_nonce_option == '' ) + add_action( 'comment_form', 'akismet_add_comment_nonce' ); + + function akismet_pingback_forwarded_for( $r, $url ) { + static $urls = array(); + + // Call this with $r == null to prime the callback to add headers on a specific URL + if ( is_null( $r ) && !in_array( $url, $urls ) ) { + $urls[] = $url; + } + + // Add X-Pingback-Forwarded-For header, but only for requests to a specific URL (the apparent pingback source) + if ( is_array( $r ) && is_array( $r['headers'] ) && !isset( $r['headers']['X-Pingback-Forwarded-For'] ) && in_array( $url, $urls ) ) { + $remote_ip = preg_replace( '/[^a-fx0-9:.,]/i', '', $_SERVER['REMOTE_ADDR'] ); + + // Note: this assumes REMOTE_ADDR is correct, and it may not be if a reverse proxy or CDN is in use + $r['headers']['X-Pingback-Forwarded-For'] = $remote_ip; + + // Also identify the request as a pingback verification in the UA string so it appears in logs + $r['user-agent'] .= '; verifying pingback from ' . $remote_ip; + } + + return $r; + } + + function akismet_pre_check_pingback( $method ) { + + if ( $method !== 'pingback.ping' ) + return; + + global $wp_xmlrpc_server; + + if ( !is_object( $wp_xmlrpc_server ) ) + return false; + + // Lame: tightly coupled with the IXR class. + $args = $wp_xmlrpc_server->message->params; + + if ( !empty( $args[1] ) ) { + $post_id = url_to_postid( $args[1] ); + + // If this gets through the pre-check, make sure we properly identify the outbound request as a pingback verification + akismet_pingback_forwarded_for( null, $args[0] ); + add_filter( 'http_request_args', 'akismet_pingback_forwarded_for', 10, 2 ); + + $comment = array( + 'comment_author_url' => $args[0], + 'comment_post_ID' => $post_id, + 'comment_author' => '', + 'comment_author_email' => '', + 'comment_content' => '', + 'comment_type' => 'pingback', + 'akismet_pre_check' => '1', + 'comment_pingback_target' => $args[1], + ); + + $comment = akismet_auto_check_comment( $comment ); + + if ( isset( $comment['akismet_result'] ) && 'true' == $comment['akismet_result'] ) { + // Lame: tightly coupled with the IXR classes. Unfortunately the action provides no context and no way to return anything. + $wp_xmlrpc_server->error( new IXR_Error( 0, 'Invalid discovery target' ) ); + } + } + } + + // Run this early in the pingback call, before doing a remote fetch of the source uri + add_action( 'xmlrpc_call', 'akismet_pre_check_pingback' ); + + global $wp_version; + if ( '3.0.5' == $wp_version ) { + remove_filter( 'comment_text', 'wp_kses_data' ); + if ( is_admin() ) + add_filter( 'comment_text', 'wp_kses_post' ); + } + + function akismet_fix_scheduled_recheck() { + $future_check = wp_next_scheduled( 'akismet_schedule_cron_recheck' ); + if ( !$future_check ) { + return; + } + + if ( get_option( 'akismet_alert_code' ) > 0 ) { + return; + } + + $check_range = time() + 1200; + if ( $future_check > $check_range ) { + wp_clear_scheduled_hook( 'akismet_schedule_cron_recheck' ); + wp_schedule_single_event( time() + 300, 'akismet_schedule_cron_recheck' ); + } + } Binary files /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/img/logo@2x.png and /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/img/logo@2x.png differ Binary files /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/img/logo.png and /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/img/logo.png differ diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/index.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/index.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/index.php 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/index.php 2013-08-01 23:39:29.000000000 +0400 *************** *** 0 **** --- 1,2 ---- + escape( $type ); + return $wpdb->get_results( "SELECT * FROM $wpdb->comments WHERE comment_approved = 'spam' AND comment_type='$type' ORDER BY comment_date DESC LIMIT $start, $end"); + } + + // All + return $wpdb->get_results( "SELECT * FROM $wpdb->comments WHERE comment_approved = 'spam' ORDER BY comment_date DESC LIMIT $start, $end"); + } + + // Totals for each comment type + // returns array( type => count, ... ) + function akismet_spam_totals() { + global $wpdb; + $totals = $wpdb->get_results( "SELECT comment_type, COUNT(*) AS cc FROM $wpdb->comments WHERE comment_approved = 'spam' GROUP BY comment_type" ); + $return = array(); + foreach ( $totals as $total ) + $return[$total->comment_type ? $total->comment_type : 'comment'] = $total->cc; + return $return; + } + + function akismet_manage_page() { + global $wpdb, $submenu, $wp_db_version; + + // WP 2.7 has its own spam management page + if ( 8645 <= $wp_db_version ) + return; + + $count = sprintf(__('Akismet Spam (%s)'), akismet_spam_count()); + if ( isset( $submenu['edit-comments.php'] ) ) + add_submenu_page('edit-comments.php', __('Akismet Spam'), $count, 'moderate_comments', 'akismet-admin', 'akismet_caught' ); + elseif ( function_exists('add_management_page') ) + add_management_page(__('Akismet Spam'), $count, 'moderate_comments', 'akismet-admin', 'akismet_caught'); + } + + function akismet_caught() { + global $wpdb, $comment, $akismet_caught, $akismet_nonce; + + akismet_recheck_queue(); + if (isset($_POST['submit']) && 'recover' == $_POST['action'] && ! empty($_POST['not_spam'])) { + check_admin_referer( $akismet_nonce ); + if ( function_exists('current_user_can') && !current_user_can('moderate_comments') ) + die(__('You do not have sufficient permission to moderate comments.')); + + $i = 0; + foreach ($_POST['not_spam'] as $comment): + $comment = (int) $comment; + if ( function_exists('wp_set_comment_status') ) + wp_set_comment_status($comment, 'approve'); + else + $wpdb->query("UPDATE $wpdb->comments SET comment_approved = '1' WHERE comment_ID = '$comment'"); + akismet_submit_nonspam_comment($comment); + ++$i; + endforeach; + $to = add_query_arg( 'recovered', $i, $_SERVER['HTTP_REFERER'] ); + wp_safe_redirect( $to ); + exit; + } + if ('delete' == $_POST['action']) { + check_admin_referer( $akismet_nonce ); + if ( function_exists('current_user_can') && !current_user_can('moderate_comments') ) + die(__('You do not have sufficient permission to moderate comments.')); + + $delete_time = $wpdb->escape( $_POST['display_time'] ); + $comment_ids = $wpdb->get_col( "SELECT comment_id FROM $wpdb->comments WHERE comment_approved = 'spam' AND '$delete_time' > comment_date_gmt" ); + if ( !empty( $comment_ids ) ) { + do_action( 'delete_comment', $comment_ids ); + $wpdb->query( "DELETE FROM $wpdb->comments WHERE comment_id IN ( " . implode( ', ', $comment_ids ) . " )"); + wp_cache_delete( 'akismet_spam_count', 'widget' ); + } + $to = add_query_arg( 'deleted', 'all', $_SERVER['HTTP_REFERER'] ); + wp_safe_redirect( $to ); + exit; + } + + if ( isset( $_GET['recovered'] ) ) { + $i = (int) $_GET['recovered']; + echo '

' . sprintf(__('%1$s comments recovered.'), $i) . "

"; + } + + if (isset( $_GET['deleted'] ) ) + echo '

' . __('All spam deleted.') . '

'; + + if ( isset( $GLOBALS['submenu']['edit-comments.php'] ) ) + $link = 'edit-comments.php'; + else + $link = 'edit.php'; + ?> + +
+

+ +

%1$s spam for you since you first installed it.'), number_format_i18n($count) ); ?>

+ '.__('You have no spam currently in the queue. Must be your lucky day. :)').'

'; + echo '
'; + } else { + echo '

'.__('You can delete all of the spam from your database with a single click. This operation cannot be undone, so you may wish to check to ensure that no legitimate comments got through first. Spam is automatically deleted after 15 days, so don’t sweat it.').'

'; + ?> + +
+ + +     + +
+ +
+
+ +

+ + '.__('These are the latest comments identified as spam by Akismet. If you see any mistakes, simply mark the comment as "not spam" and Akismet will learn from the submission. If you wish to recover a comment from spam, simply select the comment, and click Not Spam. After 15 days we clean out the junk for you.').'

'; ?> + + escape($_POST['s']); + $comments = $wpdb->get_results("SELECT * FROM $wpdb->comments WHERE + (comment_author LIKE '%$s%' OR + comment_author_email LIKE '%$s%' OR + comment_author_url LIKE ('%$s%') OR + comment_author_IP LIKE ('%$s%') OR + comment_content LIKE ('%$s%') ) AND + comment_approved = 'spam' + ORDER BY comment_date DESC"); + } else { + if ( isset( $_GET['apage'] ) ) + $page = (int) $_GET['apage']; + else + $page = 1; + + if ( $page < 2 ) + $page = 1; + + $current_type = false; + if ( isset( $_GET['ctype'] ) ) + $current_type = preg_replace( '|[^a-z]|', '', $_GET['ctype'] ); + + $comments = akismet_spam_comments( $current_type, $page ); + $total = akismet_spam_count( $current_type ); + $totals = akismet_spam_totals(); + ?> + + +
" id="akismetsearch"> +

+

+
+ 50 ) { + $total_pages = ceil( $total / 50 ); + $r = ''; + if ( 1 < $page ) { + $args['apage'] = ( 1 == $page - 1 ) ? '' : $page - 1; + $r .= '' . "\n"; + } + if ( ( $total_pages = ceil( $total / 50 ) ) > 1 ) { + for ( $page_num = 1; $page_num <= $total_pages; $page_num++ ) : + if ( $page == $page_num ) : + $r .= "$page_num\n"; + else : + $p = false; + if ( $page_num < 3 || ( $page_num >= $page - 3 && $page_num <= $page + 3 ) || $page_num > $total_pages - 3 ) : + $args['apage'] = ( 1 == $page_num ) ? '' : $page_num; + $r .= '' . ( $page_num ) . "\n"; + $in = true; + elseif ( $in == true ) : + $r .= "...\n"; + $in = false; + endif; + endif; + endfor; + } + if ( ( $page ) * 50 < $total || -1 == $total ) { + $args['apage'] = $page + 1; + $r .= '' . "\n"; + } + echo "

$r

"; + ?> + + +
+ + + + 50 ) { + $total_pages = ceil( $total / 50 ); + $r = ''; + if ( 1 < $page ) { + $args['apage'] = ( 1 == $page - 1 ) ? '' : $page - 1; + $r .= '' . "\n"; + } + if ( ( $total_pages = ceil( $total / 50 ) ) > 1 ) { + for ( $page_num = 1; $page_num <= $total_pages; $page_num++ ) : + if ( $page == $page_num ) : + $r .= "$page_num\n"; + else : + $p = false; + if ( $page_num < 3 || ( $page_num >= $page - 3 && $page_num <= $page + 3 ) || $page_num > $total_pages - 3 ) : + $args['apage'] = ( 1 == $page_num ) ? '' : $page_num; + $r .= '' . ( $page_num ) . "\n"; + $in = true; + elseif ( $in == true ) : + $r .= "...\n"; + $in = false; + endif; + endif; + endfor; + } + if ( ( $page ) * 50 < $total || -1 == $total ) { + $args['apage'] = $page + 1; + $r .= '' . "\n"; + } + echo "

$r

"; + } + ?> +

+ +

+

+
+ +

+ + + +
+ +

+     +

+
+ +
+ " . __('Recheck Queue for Spam') . ""; + $page = str_replace( '
', '
' . $button, $page ); + return $page; + } + + if ( $wpdb->get_var( "SELECT COUNT(*) FROM $wpdb->comments WHERE comment_approved = '0'" ) ) + ob_start( 'akismet_recheck_button' ); + } + + // This option causes tons of FPs, was removed in 2.1 + function akismet_kill_proxy_check( $option ) { return 0; } + add_filter('option_open_proxy_check', 'akismet_kill_proxy_check'); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/readme.txt /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/readme.txt *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/readme.txt 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/readme.txt 2014-03-18 01:15:43.000000000 +0300 *************** *** 0 **** --- 1,180 ---- + === Akismet === + Contributors: matt, ryan, andy, mdawaffe, tellyworth, josephscott, lessbloat, eoigal, automattic + Tags: akismet, comments, spam + Requires at least: 3.0 + Tested up to: 3.8.1 + Stable tag: 2.6.0 + License: GPLv2 or later + + Akismet checks your comments against the Akismet web service to see if they look like spam or not. + + == Description == + + Akismet checks your comments against the Akismet web service to see if they look like spam or not and lets you + review the spam it catches under your blog's "Comments" admin screen. + + Major new features in Akismet 2.5 include: + + * A comment status history, so you can easily see which comments were caught or cleared by Akismet, and which were spammed or unspammed by a moderator + * Links are highlighted in the comment body, to reveal hidden or misleading links + * If your web host is unable to reach Akismet's servers, the plugin will automatically retry when your connection is back up + * Moderators can see the number of approved comments for each user + * Spam and Unspam reports now include more information, to help improve accuracy + + PS: You'll need an [Akismet.com API key](http://akismet.com/get/) to use it. Keys are free for personal blogs, with paid subscriptions available for businesses and commercial sites. + + == Installation == + + Upload the Akismet plugin to your blog, Activate it, then enter your [Akismet.com API key](http://akismet.com/get/). + + 1, 2, 3: You're done! + + == Changelog == + + = 2.6.0 = + * Add ajax paging to the check for spam button to handle large volumes of comments + * Optimize javascript and add localization support + * Fix bug in link to spam comments from right now dashboard widget + * Fix bug with deleting old comments to avoid timeouts dealing with large volumes of comments + * Include X-Pingback-Forwarded-For header in outbound WordPress pingback verifications + * Add pre-check for pingbacks, to stop spam before an outbound verification request is made + + = 2.5.9 = + * Update 'Already have a key' link to redirect page rather than depend on javascript + * Fix some non-translatable strings to be translatable + * Update Activation banner in plugins page to redirect user to Akismet config page + + = 2.5.8 = + * Simplify the activation process for new users + * Remove the reporter_ip parameter + * Minor preventative security improvements + + = 2.5.7 = + * FireFox Stats iframe preview bug + * Fix mshots preview when using https + * Add .htaccess to block direct access to files + * Prevent some PHP notices + * Fix Check For Spam return location when referrer is empty + * Fix Settings links for network admins + * Fix prepare() warnings in WP 3.5 + + = 2.5.6 = + * Prevent retry scheduling problems on sites where wp_cron is misbehaving + * Preload mshot previews + * Modernize the widget code + * Fix a bug where comments were not held for moderation during an error condition + * Improve the UX and display when comments are temporarily held due to an error + * Make the Check For Spam button force a retry when comments are held due to an error + * Handle errors caused by an invalid key + * Don't retry comments that are too old + * Improve error messages when verifying an API key + + = 2.5.5 = + * Add nonce check for comment author URL remove action + * Fix the settings link + + = 2.5.4 = + * Limit Akismet CSS and Javascript loading in wp-admin to just the pages that need it + * Added author URL quick removal functionality + * Added mShot preview on Author URL hover + * Added empty index.php to prevent directory listing + * Move wp-admin menu items under Jetpack, if it is installed + * Purge old Akismet comment meta data, default of 15 days + + = 2.5.3 = + * Specify the license is GPL v2 or later + * Fix a bug that could result in orphaned commentmeta entries + * Include hotfix for WordPress 3.0.5 filter issue + + = 2.5.2 = + + * Properly format the comment count for author counts + * Look for super admins on multisite installs when looking up user roles + * Increase the HTTP request timeout + * Removed padding for author approved count + * Fix typo in function name + * Set Akismet stats iframe height to fixed 2500px. Better to have one tall scroll bar than two side by side. + + = 2.5.1 = + + * Fix a bug that caused the "Auto delete" option to fail to discard comments correctly + * Remove the comment nonce form field from the 'Akismet Configuration' page in favor of using a filter, akismet_comment_nonce + * Fixed padding bug in "author" column of posts screen + * Added margin-top to "cleared by ..." badges on dashboard + * Fix possible error when calling akismet_cron_recheck() + * Fix more PHP warnings + * Clean up XHTML warnings for comment nonce + * Fix for possible condition where scheduled comment re-checks could get stuck + * Clean up the comment meta details after deleting a comment + * Only show the status badge if the comment status has been changed by someone/something other than Akismet + * Show a 'History' link in the row-actions + * Translation fixes + * Reduced font-size on author name + * Moved "flagged by..." notification to top right corner of comment container and removed heavy styling + * Hid "flagged by..." notification while on dashboard + + = 2.5.0 = + + * Track comment actions under 'Akismet Status' on the edit comment screen + * Fix a few remaining deprecated function calls ( props Mike Glendinning ) + * Use HTTPS for the stats IFRAME when wp-admin is using HTTPS + * Use the WordPress HTTP class if available + * Move the admin UI code to a separate file, only loaded when needed + * Add cron retry feature, to replace the old connectivity check + * Display Akismet status badge beside each comment + * Record history for each comment, and display it on the edit page + * Record the complete comment as originally submitted in comment_meta, to use when reporting spam and ham + * Highlight links in comment content + * New option, "Show the number of comments you've approved beside each comment author." + * New option, "Use a nonce on the comment form." + + = 2.4.0 = + + * Spell out that the license is GPLv2 + * Fix PHP warnings + * Fix WordPress deprecated function calls + * Fire the delete_comment action when deleting comments + * Move code specific for older WP versions to legacy.php + * General code clean up + + = 2.3.0 = + + * Fix "Are you sure" nonce message on config screen in WPMU + * Fix XHTML compliance issue in sidebar widget + * Change author link; remove some old references to WordPress.com accounts + * Localize the widget title (core ticket #13879) + + = 2.2.9 = + + * Eliminate a potential conflict with some plugins that may cause spurious reports + + = 2.2.8 = + + * Fix bug in initial comment check for ipv6 addresses + * Report comments as ham when they are moved from spam to moderation + * Report comments as ham when clicking undo after spam + * Use transition_comment_status action when available instead of older actions for spam/ham submissions + * Better diagnostic messages when PHP network functions are unavailable + * Better handling of comments by logged-in users + + = 2.2.7 = + + * Add a new AKISMET_VERSION constant + * Reduce the possibility of over-counting spam when another spam filter plugin is in use + * Disable the connectivity check when the API key is hard-coded for WPMU + + = 2.2.6 = + + * Fix a global warning introduced in 2.2.5 + * Add changelog and additional readme.txt tags + * Fix an array conversion warning in some versions of PHP + * Support a new WPCOM_API_KEY constant for easier use with WordPress MU + + = 2.2.5 = + + * Include a new Server Connectivity diagnostic check, to detect problems caused by firewalls + + = 2.2.4 = + + * Fixed a key problem affecting the stats feature in WordPress MU + * Provide additional blog information in Akismet API calls diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/widget.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/widget.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-content/plugins/akismet/widget.php 1970-01-01 03:00:00.000000000 +0300 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-content/plugins/akismet/widget.php 2013-08-01 23:39:29.000000000 +0400 *************** *** 0 **** --- 1,108 ---- + __( 'Display the number of spam comments Akismet has caught' ) ) + ); + + if ( is_active_widget( false, false, $this->id_base ) ) { + add_action( 'wp_head', array( $this, 'css' ) ); + } + } + + function css() { + ?> + + + + + +

+ + +

+ + + + + + 4096 ) { + return '*'; + } + $random = ''; if (CRYPT_BLOWFISH == 1 && !$this->portable_hashes) { *************** *** 249,254 **** --- 253,262 ---- function CheckPassword($password, $stored_hash) { + if ( strlen( $password ) > 4096 ) { + return false; + } + $hash = $this->crypt_private($password, $stored_hash); if ($hash[0] == '*') $hash = crypt($password, $stored_hash); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/formatting.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/formatting.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/formatting.php 2013-10-06 14:56:09.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/formatting.php 2014-11-20 17:40:09.000000000 +0300 *************** *** 107,113 **** $no_texturize_tags_stack = array(); $no_texturize_shortcodes_stack = array(); ! $textarr = preg_split('/(<.*>|\[.*\])/Us', $text, -1, PREG_SPLIT_DELIM_CAPTURE); foreach ( $textarr as &$curl ) { if ( empty( $curl ) ) --- 107,120 ---- $no_texturize_tags_stack = array(); $no_texturize_shortcodes_stack = array(); ! // Look for shortcodes and HTML elements. ! ! $shortcode_regex = ! '\[' // Find start of shortcode. ! . '[^\[\]<>]++' // Shortcodes do not contain other shortcodes. Possessive critical. ! . '\]'; // Find end of shortcode. ! ! $textarr = preg_split("/(<[^>]*>|$shortcode_regex)/s", $text, -1, PREG_SPLIT_DELIM_CAPTURE); foreach ( $textarr as &$curl ) { if ( empty( $curl ) ) *************** *** 117,123 **** $first = $curl[0]; if ( '<' === $first ) { _wptexturize_pushpop_element($curl, $no_texturize_tags_stack, $no_texturize_tags, '<', '>'); ! } elseif ( '[' === $first ) { _wptexturize_pushpop_element($curl, $no_texturize_shortcodes_stack, $no_texturize_shortcodes, '[', ']'); } elseif ( empty($no_texturize_shortcodes_stack) && empty($no_texturize_tags_stack) ) { // This is not a tag, nor is the texturization disabled static strings --- 124,130 ---- $first = $curl[0]; if ( '<' === $first ) { _wptexturize_pushpop_element($curl, $no_texturize_tags_stack, $no_texturize_tags, '<', '>'); ! } elseif ( '[' === $first && 1 === preg_match( '/^' . $shortcode_regex . '$/', $curl ) ) { _wptexturize_pushpop_element($curl, $no_texturize_shortcodes_stack, $no_texturize_shortcodes, '[', ']'); } elseif ( empty($no_texturize_shortcodes_stack) && empty($no_texturize_tags_stack) ) { // This is not a tag, nor is the texturization disabled static strings *************** *** 158,163 **** --- 165,172 ---- array_push($stack, $matches[1]); } + } elseif ( 0 == count( $stack ) ) { + // Stack is empty. Just stop. } else { // Closing? Check $text+2 against disabled elements $c = preg_quote($closing, '/'); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/http.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/http.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/http.php 2013-09-09 02:04:09.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/http.php 2014-11-20 17:03:08.000000000 +0300 *************** *** 451,458 **** * @return mixed URL or false on failure. */ function wp_http_validate_url( $url ) { $url = wp_kses_bad_protocol( $url, array( 'http', 'https' ) ); ! if ( ! $url ) return false; $parsed_url = @parse_url( $url ); --- 451,459 ---- * @return mixed URL or false on failure. */ function wp_http_validate_url( $url ) { + $original_url = $url; $url = wp_kses_bad_protocol( $url, array( 'http', 'https' ) ); ! if ( ! $url || strtolower( $url ) !== strtolower( $original_url ) ) return false; $parsed_url = @parse_url( $url ); *************** *** 462,468 **** if ( isset( $parsed_url['user'] ) || isset( $parsed_url['pass'] ) ) return false; ! if ( false !== strpos( $parsed_url['host'], ':' ) ) return false; $parsed_home = @parse_url( get_option( 'home' ) ); --- 463,469 ---- if ( isset( $parsed_url['user'] ) || isset( $parsed_url['pass'] ) ) return false; ! if ( false !== strpbrk( $parsed_url['host'], ':#?[]' ) ) return false; $parsed_home = @parse_url( get_option( 'home' ) ); *************** *** 480,487 **** } if ( $ip ) { $parts = array_map( 'intval', explode( '.', $ip ) ); ! if ( '127.0.0.1' === $ip ! || ( 10 === $parts[0] ) || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) || ( 192 === $parts[0] && 168 === $parts[1] ) ) { --- 481,487 ---- } if ( $ip ) { $parts = array_map( 'intval', explode( '.', $ip ) ); ! if ( 127 === $parts[0] || 10 === $parts[0] || ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] ) || ( 192 === $parts[0] && 168 === $parts[1] ) ) { diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/kses.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/kses.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/kses.php 2013-09-17 00:49:10.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/kses.php 2014-11-20 16:17:09.000000000 +0300 *************** *** 1405,1411 **** $css = wp_kses_no_null($css); $css = str_replace(array("\n","\r","\t"), '', $css); ! if ( preg_match( '%[\\(&=}]|/\*%', $css ) ) // remove any inline css containing \ ( & } = or comments return ''; $css_array = explode( ';', trim( $css ) ); --- 1405,1411 ---- $css = wp_kses_no_null($css); $css = str_replace(array("\n","\r","\t"), '', $css); ! if ( preg_match( '%[\\\\(&=}]|/\*%', $css ) ) // remove any inline css containing \ ( & } = or comments return ''; $css_array = explode( ';', trim( $css ) ); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/pluggable.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/pluggable.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/pluggable.php 2014-08-06 21:59:09.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/pluggable.php 2014-11-20 15:06:10.000000000 +0300 *************** *** 1492,1498 **** // If the hash is still md5... if ( strlen($hash) <= 32 ) { ! $check = ( $hash == md5($password) ); if ( $check && $user_id ) { // Rehash using new hash. wp_set_password($password, $user_id); --- 1492,1498 ---- // If the hash is still md5... if ( strlen($hash) <= 32 ) { ! $check = hash_equals( $hash, md5( $password ) ); if ( $check && $user_id ) { // Rehash using new hash. wp_set_password($password, $user_id); diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/user.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/user.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/user.php 2013-10-26 07:22:09.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/user.php 2014-11-20 16:43:09.000000000 +0300 *************** *** 1415,1420 **** --- 1415,1423 ---- $data = wp_unslash( $data ); if ( $update ) { + if ( $user_email !== $old_user_data->user_email ) { + $data['user_activation_key'] = ''; + } $wpdb->update( $wpdb->users, $data, compact( 'ID' ) ); $user_id = (int) $ID; } else { diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/version.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/version.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-includes/version.php 2014-08-06 22:27:35.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-includes/version.php 2014-11-20 19:26:10.000000000 +0300 *************** *** 4,10 **** * * @global string $wp_version */ ! $wp_version = '3.7.4'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema. --- 4,10 ---- * * @global string $wp_version */ ! $wp_version = '3.7.5'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema. diff -crBPN --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=wp-cache-config.php --exclude=.htaccess-dist --exclude=wordpress.sql --exclude=editor_plugin.js --exclude=jetpack --exclude=.files.list --exclude=wordpress-3.7.5.pl /home/packages/qi/SOURCES/wordpress-3.7.4/wp-login.php /home/packages/qi/SOURCES/wordpress-3.7.5/wp-login.php *** /home/packages/qi/SOURCES/wordpress-3.7.4/wp-login.php 2014-08-06 10:40:11.000000000 +0400 --- /home/packages/qi/SOURCES/wordpress-3.7.5/wp-login.php 2014-11-20 15:25:19.000000000 +0300 *************** *** 518,524 **** ?> !

--- 518,524 ---- ?> !

*************** *** 569,574 **** --- 569,577 ---- if ( isset( $_COOKIE[ $rp_cookie ] ) && 0 < strpos( $_COOKIE[ $rp_cookie ], ':' ) ) { list( $rp_login, $rp_key ) = explode( ':', wp_unslash( $_COOKIE[ $rp_cookie ] ), 2 ); $user = check_password_reset_key( $rp_key, $rp_login ); + if ( isset( $_POST['pass1'] ) && ! hash_equals( $rp_key, $_POST['rp_key'] ) ) { + $user = false; + } } else { $user = false; } *************** *** 611,617 **** login_header(__('Reset Password'), '

' . __('Enter your new password below.') . '

', $errors ); ?> !

--- 614,620 ---- login_header(__('Reset Password'), '

' . __('Enter your new password below.') . '

', $errors ); ?> !

*************** *** 627,632 **** --- 630,636 ----


+