Skip to content

REST API: Split comma-separated methods given in an array - #13134

Open
itzmekhokan wants to merge 1 commit into
WordPress:trunkfrom
itzmekhokan:fix/65905-rest-array-methods-comma
Open

REST API: Split comma-separated methods given in an array#13134
itzmekhokan wants to merge 1 commit into
WordPress:trunkfrom
itzmekhokan:fix/65905-rest-array-methods-comma

Conversation

@itzmekhokan

Copy link
Copy Markdown

Registering a REST route with 'methods' => array( WP_REST_Server::READABLE, WP_REST_Server::EDITABLE ) returns 404 for POST, PUT and PATCH.

WP_REST_Server::get_routes() splits the methods argument on commas only when it is a string. An array element containing one, such as the multi-method EDITABLE constant, becomes a single method key that no request can match, with no notice at registration. The patch splits each array element too, so both forms register the same route.

The Allow header is unchanged — it reassembles the key by imploding on commas, which is why the mismatch stayed invisible.

Trac ticket: https://core.trac.wordpress.org/ticket/65905

Use of AI Tools

AI assistance: Yes
Tool(s): Claude Code
Model(s): Claude Opus 5
Used for: Reproducing the failure against trunk, measuring the array and string forms side by side, and drafting the regression test. All changes were reviewed and validated by me.


This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.

`WP_REST_Server::register_route()` accepts the `methods` argument as
either a string or an array, but only the string form was split on
commas. An array element containing one, such as the multi-method
`WP_REST_Server::EDITABLE` constant, became a single unmatchable
method key, so `array( READABLE, EDITABLE )` registered a route where
POST, PUT and PATCH returned 404 with no notice at registration time.

Split each array element as well, so both forms register the same
route. A comma is a delimiter in the RFC 9110 token grammar, so no
valid method name can contain one.

Fixes #65905.
@github-actions

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props khokansardar.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant