Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
bbcce03
FIX: Request Lifecycle - 1.1, 1.2, 1.3
Gawuww Jun 25, 2026
0f18f74
FIX: Custom CSRF Layer - 2.2
Gawuww Jun 26, 2026
66327f3
FIX: return empty list instead of 404 for no records https://github.c…
ObitoTM Jul 13, 2026
2217786
FIX: harden form context, gateway selection, and CAPTCHA verification…
Gawuww Jul 15, 2026
f72c450
FIX: premature browser validation notice https://github.com/Crocobloc…
ObitoTM Jul 16, 2026
45fc093
FIX: resolve late registered form messages https://github.com/Crocobl…
ObitoTM Jul 20, 2026
82dcbeb
FIX: inherited advanced validation detection https://github.com/Croco…
ObitoTM Jul 21, 2026
5883fd3
FIX: prevent clearing stale mapped fields in Insert Post action https…
ObitoTM Jul 22, 2026
e23f669
FIX: remove incomplete queried post ID signature validation https://g…
Gawuww Jul 29, 2026
ee0e962
Merge branch 'main' into dev/security-audit
Gawuww Jul 29, 2026
29aa525
FIX: inherited advanced validation detection https://github.com/Croco…
ObitoTM Jul 29, 2026
6b89ff8
Merge branch 'release/3.6.5' into issue/18733
ObitoTM Jul 29, 2026
0aa1fc2
Merge pull request #685 from Crocoblock/issue/18733
ObitoTM Jul 29, 2026
5b2d4e2
Merge pull request #686 from Crocoblock/issue/18989
ObitoTM Jul 29, 2026
8e55360
Merge pull request #687 from Crocoblock/issue/19370
ObitoTM Jul 29, 2026
90c515c
Merge pull request #688 from Crocoblock/issue/19945
ObitoTM Jul 29, 2026
365302f
Merge pull request #690 from Crocoblock/issue/20076
ObitoTM Jul 29, 2026
dd9359a
Merge branch 'release/3.6.5' into dev/security-audit
Gawuww Jul 30, 2026
8f3537f
FIX: prevent validation bypasses in core and SSR flows (#677)
MjHead Jul 30, 2026
584878c
Merge branch 'release/3.6.5' into dev/security-audit
Gawuww Jul 30, 2026
92a9185
FIX: after merge
Gawuww Jul 30, 2026
0011c20
FIX: Tests after merge
Gawuww Jul 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/php.lint.test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,7 @@ jobs:
run: |
rm tests/_envs/.env
mv tests/_envs/.env.testing tests/_envs/.env
touch tests/_envs/.env.local

- name: Run PHP tests
run: composer test:wpunit
8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,11 @@ AGENTS.md
.env.e2e
.env.e2e.example
bootstrap-project.js

# Local test environment overrides
tests/_envs/.env.local

# Codeception runtime artifacts
tests/_output/*
!tests/_output/.gitignore
tests/_support/_generated/
2 changes: 1 addition & 1 deletion assets/build/admin/package.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('wp-i18n'), 'version' => '94ba9a9d32ea506460c6');
<?php return array('dependencies' => array('wp-i18n'), 'version' => 'cd879d1903e305e67f49');
2 changes: 1 addition & 1 deletion assets/build/admin/package.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion assets/build/editor/form.builder.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('react', 'wp-components', 'wp-data', 'wp-editor', 'wp-element', 'wp-hooks', 'wp-i18n', 'wp-plugins'), 'version' => '998222f5df4e19e7fc3d');
<?php return array('dependencies' => array('react', 'wp-components', 'wp-data', 'wp-editor', 'wp-element', 'wp-hooks', 'wp-i18n', 'wp-plugins'), 'version' => 'f2898b123edbefeeaef4');
2 changes: 1 addition & 1 deletion assets/build/editor/form.builder.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion assets/build/editor/package.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('react', 'wp-api-fetch', 'wp-block-editor', 'wp-components', 'wp-compose', 'wp-data', 'wp-element', 'wp-hooks', 'wp-i18n'), 'version' => '0aefae306822008fa4a6');
<?php return array('dependencies' => array('react', 'wp-api-fetch', 'wp-block-editor', 'wp-components', 'wp-compose', 'wp-data', 'wp-element', 'wp-hooks', 'wp-i18n'), 'version' => '84dd167a2e5aa9a15f3b');
2 changes: 1 addition & 1 deletion assets/build/editor/package.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion assets/build/frontend/main.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('wp-i18n'), 'version' => 'b145b8f23bfb859fdb34');
<?php return array('dependencies' => array('wp-i18n'), 'version' => 'b6ad40658d81b14a771d');
2 changes: 1 addition & 1 deletion assets/build/frontend/main.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion assets/build/frontend/media.field.restrictions.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('wp-i18n'), 'version' => '2fa8b05f10aab57b1eae');
<?php return array('dependencies' => array('wp-i18n'), 'version' => '3a8ed91056d8ec80b043');
2 changes: 1 addition & 1 deletion assets/build/frontend/media.field.restrictions.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 7 additions & 1 deletion assets/src/frontend/main/reporting/BrowserReporting.js
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,13 @@ function BrowserReporting() {
// browser automatically hide tooltip messages
};
this.validateOnChange = function () {
this.validate().then( () => {} ).catch( () => {} );
this.getErrors().then( errors => {
this.validityState.current = !Boolean( errors.length );

if ( !errors.length ) {
this.clearReport();
}
} ).catch( () => {} );
};

this.getErrorsRaw = async function ( promises ) {
Expand Down
27 changes: 26 additions & 1 deletion assets/src/frontend/main/submit/AjaxSubmit.js
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,11 @@ function AjaxSubmit( form ) {

this.lastResponse = response;
const $form = jQuery( rootNode );
const csrfToken = response?._jfb_csrf_token;

if ( csrfToken ) {
this.refreshCsrfToken( csrfToken );
}

switch ( response.status ) {
case 'success':
Expand Down Expand Up @@ -129,6 +134,26 @@ function AjaxSubmit( form ) {

rootNode.appendChild( node );
};
this.refreshCsrfToken = function ( csrfToken ) {
const formId = this.form.getFormId();
const forms = document.querySelectorAll(
'form.jet-form-builder[data-form-id]',
);

for ( const formNode of forms ) {
if ( +formNode.dataset.formId !== formId ) {
continue;
}

const csrfFields = formNode.querySelectorAll(
'input[name="_jfb_csrf_token"]',
);

for ( const field of csrfFields ) {
field.value = csrfToken;
}
}
};
}

AjaxSubmit.prototype = Object.create( BaseSubmit.prototype );
Expand Down Expand Up @@ -167,4 +192,4 @@ AjaxSubmit.prototype.watchFail = function ( callable ) {
} );
};

export default AjaxSubmit;
export default AjaxSubmit;
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ function FileSizeRestriction() {
this.validate = function () {
const { max_size: maxSize } = this.reporting.input.attrs;

return this.file.size < maxSize.value.current;
return this.file.size <= maxSize.value.current;
};

this.getRawMessage = function () {
Expand All @@ -19,4 +19,4 @@ function FileSizeRestriction() {

FileSizeRestriction.prototype = Object.create( BaseFileRestriction.prototype );

export default FileSizeRestriction;
export default FileSizeRestriction;
3 changes: 1 addition & 2 deletions codeception.dist.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ extensions:
- Codeception\Command\GenerateWPCanonical
- Codeception\Command\GenerateWPXMLRPC
params:
- tests/_envs/.env.local
- tests/_envs/.env
settings:
colors: true
Expand Down Expand Up @@ -80,5 +81,3 @@ modules:
mu-plugins: '/wp-content/mu-plugins'
themes: '/wp-content/themes'
uploads: '/wp-content/uploads'


2 changes: 1 addition & 1 deletion compatibility/bricks/assets/build/frontend.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array(), 'version' => 'cf7d02a4042a42f5c32e');
<?php return array('dependencies' => array(), 'version' => '223249f02ffb577062b5');
2 changes: 1 addition & 1 deletion compatibility/bricks/assets/build/frontend.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array(), 'version' => '0c021d3fb5d78e7cd81c');
<?php return array('dependencies' => array(), 'version' => 'bad44884ebe52d8c8260');
Loading
Loading