default-filters.php 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586
  1. <?php
  2. /**
  3. * Sets up the default filters and actions for most
  4. * of the WordPress hooks.
  5. *
  6. * If you need to remove a default hook, this file will
  7. * give you the priority for which to use to remove the
  8. * hook.
  9. *
  10. * Not all of the default hooks are found in default-filters.php
  11. *
  12. * @package WordPress
  13. */
  14. // Strip, trim, kses, special chars for string saves
  15. foreach ( array( 'pre_term_name', 'pre_comment_author_name', 'pre_link_name', 'pre_link_target', 'pre_link_rel', 'pre_user_display_name', 'pre_user_first_name', 'pre_user_last_name', 'pre_user_nickname' ) as $filter ) {
  16. add_filter( $filter, 'sanitize_text_field' );
  17. add_filter( $filter, 'wp_filter_kses' );
  18. add_filter( $filter, '_wp_specialchars', 30 );
  19. }
  20. // Strip, kses, special chars for string display
  21. foreach ( array( 'term_name', 'comment_author_name', 'link_name', 'link_target', 'link_rel', 'user_display_name', 'user_first_name', 'user_last_name', 'user_nickname' ) as $filter ) {
  22. if ( is_admin() ) {
  23. // These are expensive. Run only on admin pages for defense in depth.
  24. add_filter( $filter, 'sanitize_text_field' );
  25. add_filter( $filter, 'wp_kses_data' );
  26. }
  27. add_filter( $filter, '_wp_specialchars', 30 );
  28. }
  29. // Kses only for textarea saves
  30. foreach ( array( 'pre_term_description', 'pre_link_description', 'pre_link_notes', 'pre_user_description' ) as $filter ) {
  31. add_filter( $filter, 'wp_filter_kses' );
  32. }
  33. // Kses only for textarea admin displays
  34. if ( is_admin() ) {
  35. foreach ( array( 'term_description', 'link_description', 'link_notes', 'user_description' ) as $filter ) {
  36. add_filter( $filter, 'wp_kses_data' );
  37. }
  38. add_filter( 'comment_text', 'wp_kses_post' );
  39. }
  40. // Email saves
  41. foreach ( array( 'pre_comment_author_email', 'pre_user_email' ) as $filter ) {
  42. add_filter( $filter, 'trim' );
  43. add_filter( $filter, 'sanitize_email' );
  44. add_filter( $filter, 'wp_filter_kses' );
  45. }
  46. // Email admin display
  47. foreach ( array( 'comment_author_email', 'user_email' ) as $filter ) {
  48. add_filter( $filter, 'sanitize_email' );
  49. if ( is_admin() ) {
  50. add_filter( $filter, 'wp_kses_data' );
  51. }
  52. }
  53. // Save URL
  54. foreach ( array(
  55. 'pre_comment_author_url',
  56. 'pre_user_url',
  57. 'pre_link_url',
  58. 'pre_link_image',
  59. 'pre_link_rss',
  60. 'pre_post_guid',
  61. ) as $filter ) {
  62. add_filter( $filter, 'wp_strip_all_tags' );
  63. add_filter( $filter, 'esc_url_raw' );
  64. add_filter( $filter, 'wp_filter_kses' );
  65. }
  66. // Display URL
  67. foreach ( array( 'user_url', 'link_url', 'link_image', 'link_rss', 'comment_url', 'post_guid' ) as $filter ) {
  68. if ( is_admin() ) {
  69. add_filter( $filter, 'wp_strip_all_tags' );
  70. }
  71. add_filter( $filter, 'esc_url' );
  72. if ( is_admin() ) {
  73. add_filter( $filter, 'wp_kses_data' );
  74. }
  75. }
  76. // Slugs
  77. add_filter( 'pre_term_slug', 'sanitize_title' );
  78. add_filter( 'wp_insert_post_data', '_wp_customize_changeset_filter_insert_post_data', 10, 2 );
  79. // Keys
  80. foreach ( array( 'pre_post_type', 'pre_post_status', 'pre_post_comment_status', 'pre_post_ping_status' ) as $filter ) {
  81. add_filter( $filter, 'sanitize_key' );
  82. }
  83. // Mime types
  84. add_filter( 'pre_post_mime_type', 'sanitize_mime_type' );
  85. add_filter( 'post_mime_type', 'sanitize_mime_type' );
  86. // Meta
  87. add_filter( 'register_meta_args', '_wp_register_meta_args_whitelist', 10, 2 );
  88. // Post meta
  89. add_action( 'added_post_meta', 'wp_cache_set_posts_last_changed' );
  90. add_action( 'updated_post_meta', 'wp_cache_set_posts_last_changed' );
  91. add_action( 'deleted_post_meta', 'wp_cache_set_posts_last_changed' );
  92. // Term meta
  93. add_action( 'added_term_meta', 'wp_cache_set_terms_last_changed' );
  94. add_action( 'updated_term_meta', 'wp_cache_set_terms_last_changed' );
  95. add_action( 'deleted_term_meta', 'wp_cache_set_terms_last_changed' );
  96. add_filter( 'get_term_metadata', 'wp_check_term_meta_support_prefilter' );
  97. add_filter( 'add_term_metadata', 'wp_check_term_meta_support_prefilter' );
  98. add_filter( 'update_term_metadata', 'wp_check_term_meta_support_prefilter' );
  99. add_filter( 'delete_term_metadata', 'wp_check_term_meta_support_prefilter' );
  100. add_filter( 'get_term_metadata_by_mid', 'wp_check_term_meta_support_prefilter' );
  101. add_filter( 'update_term_metadata_by_mid', 'wp_check_term_meta_support_prefilter' );
  102. add_filter( 'delete_term_metadata_by_mid', 'wp_check_term_meta_support_prefilter' );
  103. add_filter( 'update_term_metadata_cache', 'wp_check_term_meta_support_prefilter' );
  104. // Comment meta
  105. add_action( 'added_comment_meta', 'wp_cache_set_comments_last_changed' );
  106. add_action( 'updated_comment_meta', 'wp_cache_set_comments_last_changed' );
  107. add_action( 'deleted_comment_meta', 'wp_cache_set_comments_last_changed' );
  108. // Places to balance tags on input
  109. foreach ( array( 'content_save_pre', 'excerpt_save_pre', 'comment_save_pre', 'pre_comment_content' ) as $filter ) {
  110. add_filter( $filter, 'convert_invalid_entities' );
  111. add_filter( $filter, 'balanceTags', 50 );
  112. }
  113. // Add proper rel values for links with target.
  114. add_action( 'init', 'wp_init_targeted_link_rel_filters' );
  115. // Format strings for display.
  116. foreach ( array( 'comment_author', 'term_name', 'link_name', 'link_description', 'link_notes', 'bloginfo', 'wp_title', 'widget_title' ) as $filter ) {
  117. add_filter( $filter, 'wptexturize' );
  118. add_filter( $filter, 'convert_chars' );
  119. add_filter( $filter, 'esc_html' );
  120. }
  121. // Format WordPress
  122. foreach ( array( 'the_content', 'the_title', 'wp_title' ) as $filter ) {
  123. add_filter( $filter, 'capital_P_dangit', 11 );
  124. }
  125. add_filter( 'comment_text', 'capital_P_dangit', 31 );
  126. // Format titles
  127. foreach ( array( 'single_post_title', 'single_cat_title', 'single_tag_title', 'single_month_title', 'nav_menu_attr_title', 'nav_menu_description' ) as $filter ) {
  128. add_filter( $filter, 'wptexturize' );
  129. add_filter( $filter, 'strip_tags' );
  130. }
  131. // Format text area for display.
  132. foreach ( array( 'term_description', 'get_the_post_type_description' ) as $filter ) {
  133. add_filter( $filter, 'wptexturize' );
  134. add_filter( $filter, 'convert_chars' );
  135. add_filter( $filter, 'wpautop' );
  136. add_filter( $filter, 'shortcode_unautop' );
  137. }
  138. // Format for RSS
  139. add_filter( 'term_name_rss', 'convert_chars' );
  140. // Pre save hierarchy
  141. add_filter( 'wp_insert_post_parent', 'wp_check_post_hierarchy_for_loops', 10, 2 );
  142. add_filter( 'wp_update_term_parent', 'wp_check_term_hierarchy_for_loops', 10, 3 );
  143. // Display filters
  144. add_filter( 'the_title', 'wptexturize' );
  145. add_filter( 'the_title', 'convert_chars' );
  146. add_filter( 'the_title', 'trim' );
  147. add_filter( 'the_content', 'do_blocks', 9 );
  148. add_filter( 'the_content', 'wptexturize' );
  149. add_filter( 'the_content', 'convert_smilies', 20 );
  150. add_filter( 'the_content', 'wpautop' );
  151. add_filter( 'the_content', 'shortcode_unautop' );
  152. add_filter( 'the_content', 'prepend_attachment' );
  153. add_filter( 'the_content', 'wp_make_content_images_responsive' );
  154. add_filter( 'the_excerpt', 'wptexturize' );
  155. add_filter( 'the_excerpt', 'convert_smilies' );
  156. add_filter( 'the_excerpt', 'convert_chars' );
  157. add_filter( 'the_excerpt', 'wpautop' );
  158. add_filter( 'the_excerpt', 'shortcode_unautop' );
  159. add_filter( 'get_the_excerpt', 'wp_trim_excerpt', 10, 2 );
  160. add_filter( 'the_post_thumbnail_caption', 'wptexturize' );
  161. add_filter( 'the_post_thumbnail_caption', 'convert_smilies' );
  162. add_filter( 'the_post_thumbnail_caption', 'convert_chars' );
  163. add_filter( 'comment_text', 'wptexturize' );
  164. add_filter( 'comment_text', 'convert_chars' );
  165. add_filter( 'comment_text', 'make_clickable', 9 );
  166. add_filter( 'comment_text', 'force_balance_tags', 25 );
  167. add_filter( 'comment_text', 'convert_smilies', 20 );
  168. add_filter( 'comment_text', 'wpautop', 30 );
  169. add_filter( 'comment_excerpt', 'convert_chars' );
  170. add_filter( 'list_cats', 'wptexturize' );
  171. add_filter( 'wp_sprintf', 'wp_sprintf_l', 10, 2 );
  172. add_filter( 'widget_text', 'balanceTags' );
  173. add_filter( 'widget_text_content', 'capital_P_dangit', 11 );
  174. add_filter( 'widget_text_content', 'wptexturize' );
  175. add_filter( 'widget_text_content', 'convert_smilies', 20 );
  176. add_filter( 'widget_text_content', 'wpautop' );
  177. add_filter( 'widget_text_content', 'shortcode_unautop' );
  178. add_filter( 'widget_text_content', 'do_shortcode', 11 ); // Runs after wpautop(); note that $post global will be null when shortcodes run.
  179. // RSS filters
  180. add_filter( 'the_title_rss', 'strip_tags' );
  181. add_filter( 'the_title_rss', 'ent2ncr', 8 );
  182. add_filter( 'the_title_rss', 'esc_html' );
  183. add_filter( 'the_content_rss', 'ent2ncr', 8 );
  184. add_filter( 'the_content_feed', 'wp_staticize_emoji' );
  185. add_filter( 'the_content_feed', '_oembed_filter_feed_content' );
  186. add_filter( 'the_excerpt_rss', 'convert_chars' );
  187. add_filter( 'the_excerpt_rss', 'ent2ncr', 8 );
  188. add_filter( 'comment_author_rss', 'ent2ncr', 8 );
  189. add_filter( 'comment_text_rss', 'ent2ncr', 8 );
  190. add_filter( 'comment_text_rss', 'esc_html' );
  191. add_filter( 'comment_text_rss', 'wp_staticize_emoji' );
  192. add_filter( 'bloginfo_rss', 'ent2ncr', 8 );
  193. add_filter( 'the_author', 'ent2ncr', 8 );
  194. add_filter( 'the_guid', 'esc_url' );
  195. // Email filters
  196. add_filter( 'wp_mail', 'wp_staticize_emoji_for_email' );
  197. // Mark site as no longer fresh
  198. foreach ( array( 'publish_post', 'publish_page', 'wp_ajax_save-widget', 'wp_ajax_widgets-order', 'customize_save_after' ) as $action ) {
  199. add_action( $action, '_delete_option_fresh_site', 0 );
  200. }
  201. // Misc filters
  202. add_filter( 'option_ping_sites', 'privacy_ping_filter' );
  203. add_filter( 'option_blog_charset', '_wp_specialchars' ); // IMPORTANT: This must not be wp_specialchars() or esc_html() or it'll cause an infinite loop
  204. add_filter( 'option_blog_charset', '_canonical_charset' );
  205. add_filter( 'option_home', '_config_wp_home' );
  206. add_filter( 'option_siteurl', '_config_wp_siteurl' );
  207. add_filter( 'tiny_mce_before_init', '_mce_set_direction' );
  208. add_filter( 'teeny_mce_before_init', '_mce_set_direction' );
  209. add_filter( 'pre_kses', 'wp_pre_kses_less_than' );
  210. add_filter( 'sanitize_title', 'sanitize_title_with_dashes', 10, 3 );
  211. add_action( 'check_comment_flood', 'check_comment_flood_db', 10, 4 );
  212. add_filter( 'comment_flood_filter', 'wp_throttle_comment_flood', 10, 3 );
  213. add_filter( 'pre_comment_content', 'wp_rel_ugc', 15 );
  214. add_filter( 'comment_email', 'antispambot' );
  215. add_filter( 'option_tag_base', '_wp_filter_taxonomy_base' );
  216. add_filter( 'option_category_base', '_wp_filter_taxonomy_base' );
  217. add_filter( 'the_posts', '_close_comments_for_old_posts', 10, 2 );
  218. add_filter( 'comments_open', '_close_comments_for_old_post', 10, 2 );
  219. add_filter( 'pings_open', '_close_comments_for_old_post', 10, 2 );
  220. add_filter( 'editable_slug', 'urldecode' );
  221. add_filter( 'editable_slug', 'esc_textarea' );
  222. add_filter( 'nav_menu_meta_box_object', '_wp_nav_menu_meta_box_object' );
  223. add_filter( 'pingback_ping_source_uri', 'pingback_ping_source_uri' );
  224. add_filter( 'xmlrpc_pingback_error', 'xmlrpc_pingback_error' );
  225. add_filter( 'title_save_pre', 'trim' );
  226. add_action( 'transition_comment_status', '_clear_modified_cache_on_transition_comment_status', 10, 2 );
  227. add_filter( 'http_request_host_is_external', 'allowed_http_request_hosts', 10, 2 );
  228. // REST API filters.
  229. add_action( 'xmlrpc_rsd_apis', 'rest_output_rsd' );
  230. add_action( 'wp_head', 'rest_output_link_wp_head', 10, 0 );
  231. add_action( 'template_redirect', 'rest_output_link_header', 11, 0 );
  232. add_action( 'auth_cookie_malformed', 'rest_cookie_collect_status' );
  233. add_action( 'auth_cookie_expired', 'rest_cookie_collect_status' );
  234. add_action( 'auth_cookie_bad_username', 'rest_cookie_collect_status' );
  235. add_action( 'auth_cookie_bad_hash', 'rest_cookie_collect_status' );
  236. add_action( 'auth_cookie_valid', 'rest_cookie_collect_status' );
  237. add_filter( 'rest_authentication_errors', 'rest_cookie_check_errors', 100 );
  238. // Actions
  239. add_action( 'wp_head', '_wp_render_title_tag', 1 );
  240. add_action( 'wp_head', 'wp_enqueue_scripts', 1 );
  241. add_action( 'wp_head', 'wp_resource_hints', 2 );
  242. add_action( 'wp_head', 'feed_links', 2 );
  243. add_action( 'wp_head', 'feed_links_extra', 3 );
  244. add_action( 'wp_head', 'rsd_link' );
  245. add_action( 'wp_head', 'wlwmanifest_link' );
  246. add_action( 'wp_head', 'adjacent_posts_rel_link_wp_head', 10, 0 );
  247. add_action( 'wp_head', 'locale_stylesheet' );
  248. add_action( 'publish_future_post', 'check_and_publish_future_post', 10, 1 );
  249. add_action( 'wp_head', 'noindex', 1 );
  250. add_action( 'wp_head', 'print_emoji_detection_script', 7 );
  251. add_action( 'wp_head', 'wp_print_styles', 8 );
  252. add_action( 'wp_head', 'wp_print_head_scripts', 9 );
  253. add_action( 'wp_head', 'wp_generator' );
  254. add_action( 'wp_head', 'rel_canonical' );
  255. add_action( 'wp_head', 'wp_shortlink_wp_head', 10, 0 );
  256. add_action( 'wp_head', 'wp_custom_css_cb', 101 );
  257. add_action( 'wp_head', 'wp_site_icon', 99 );
  258. add_action( 'wp_footer', 'wp_print_footer_scripts', 20 );
  259. add_action( 'template_redirect', 'wp_shortlink_header', 11, 0 );
  260. add_action( 'wp_print_footer_scripts', '_wp_footer_scripts' );
  261. add_action( 'init', 'check_theme_switched', 99 );
  262. add_action( 'after_switch_theme', '_wp_menus_changed' );
  263. add_action( 'after_switch_theme', '_wp_sidebars_changed' );
  264. add_action( 'wp_print_styles', 'print_emoji_styles' );
  265. if ( isset( $_GET['replytocom'] ) ) {
  266. add_action( 'wp_head', 'wp_no_robots' );
  267. }
  268. // Login actions
  269. add_filter( 'login_head', 'wp_resource_hints', 8 );
  270. add_action( 'login_head', 'wp_print_head_scripts', 9 );
  271. add_action( 'login_head', 'print_admin_styles', 9 );
  272. add_action( 'login_head', 'wp_site_icon', 99 );
  273. add_action( 'login_footer', 'wp_print_footer_scripts', 20 );
  274. add_action( 'login_init', 'send_frame_options_header', 10, 0 );
  275. // Feed Generator Tags
  276. foreach ( array( 'rss2_head', 'commentsrss2_head', 'rss_head', 'rdf_header', 'atom_head', 'comments_atom_head', 'opml_head', 'app_head' ) as $action ) {
  277. add_action( $action, 'the_generator' );
  278. }
  279. // Feed Site Icon
  280. add_action( 'atom_head', 'atom_site_icon' );
  281. add_action( 'rss2_head', 'rss2_site_icon' );
  282. // WP Cron
  283. if ( ! defined( 'DOING_CRON' ) ) {
  284. add_action( 'init', 'wp_cron' );
  285. }
  286. // 2 Actions 2 Furious
  287. add_action( 'do_feed_rdf', 'do_feed_rdf', 10, 0 );
  288. add_action( 'do_feed_rss', 'do_feed_rss', 10, 0 );
  289. add_action( 'do_feed_rss2', 'do_feed_rss2', 10, 1 );
  290. add_action( 'do_feed_atom', 'do_feed_atom', 10, 1 );
  291. add_action( 'do_pings', 'do_all_pings', 10, 0 );
  292. add_action( 'do_robots', 'do_robots' );
  293. add_action( 'set_comment_cookies', 'wp_set_comment_cookies', 10, 3 );
  294. add_action( 'sanitize_comment_cookies', 'sanitize_comment_cookies' );
  295. add_action( 'admin_print_scripts', 'print_emoji_detection_script' );
  296. add_action( 'admin_print_scripts', 'print_head_scripts', 20 );
  297. add_action( 'admin_print_footer_scripts', '_wp_footer_scripts' );
  298. add_action( 'admin_print_styles', 'print_emoji_styles' );
  299. add_action( 'admin_print_styles', 'print_admin_styles', 20 );
  300. add_action( 'init', 'smilies_init', 5 );
  301. add_action( 'plugins_loaded', 'wp_maybe_load_widgets', 0 );
  302. add_action( 'plugins_loaded', 'wp_maybe_load_embeds', 0 );
  303. add_action( 'shutdown', 'wp_ob_end_flush_all', 1 );
  304. // Create a revision whenever a post is updated.
  305. add_action( 'post_updated', 'wp_save_post_revision', 10, 1 );
  306. add_action( 'publish_post', '_publish_post_hook', 5, 1 );
  307. add_action( 'transition_post_status', '_transition_post_status', 5, 3 );
  308. add_action( 'transition_post_status', '_update_term_count_on_transition_post_status', 10, 3 );
  309. add_action( 'comment_form', 'wp_comment_form_unfiltered_html_nonce' );
  310. add_action( 'admin_init', 'send_frame_options_header', 10, 0 );
  311. add_action( 'welcome_panel', 'wp_welcome_panel' );
  312. // Privacy
  313. add_action( 'user_request_action_confirmed', '_wp_privacy_account_request_confirmed' );
  314. add_action( 'user_request_action_confirmed', '_wp_privacy_send_request_confirmation_notification', 12 ); // After request marked as completed.
  315. add_filter( 'wp_privacy_personal_data_exporters', 'wp_register_comment_personal_data_exporter' );
  316. add_filter( 'wp_privacy_personal_data_exporters', 'wp_register_media_personal_data_exporter' );
  317. add_filter( 'wp_privacy_personal_data_exporters', 'wp_register_user_personal_data_exporter', 1 );
  318. add_filter( 'wp_privacy_personal_data_erasers', 'wp_register_comment_personal_data_eraser' );
  319. add_action( 'init', 'wp_schedule_delete_old_privacy_export_files' );
  320. add_action( 'wp_privacy_delete_old_export_files', 'wp_privacy_delete_old_export_files' );
  321. // Cron tasks
  322. add_action( 'wp_scheduled_delete', 'wp_scheduled_delete' );
  323. add_action( 'wp_scheduled_auto_draft_delete', 'wp_delete_auto_drafts' );
  324. add_action( 'importer_scheduled_cleanup', 'wp_delete_attachment' );
  325. add_action( 'upgrader_scheduled_cleanup', 'wp_delete_attachment' );
  326. add_action( 'delete_expired_transients', 'delete_expired_transients' );
  327. // Navigation menu actions
  328. add_action( 'delete_post', '_wp_delete_post_menu_item' );
  329. add_action( 'delete_term', '_wp_delete_tax_menu_item', 10, 3 );
  330. add_action( 'transition_post_status', '_wp_auto_add_pages_to_menu', 10, 3 );
  331. add_action( 'delete_post', '_wp_delete_customize_changeset_dependent_auto_drafts' );
  332. // Post Thumbnail CSS class filtering
  333. add_action( 'begin_fetch_post_thumbnail_html', '_wp_post_thumbnail_class_filter_add' );
  334. add_action( 'end_fetch_post_thumbnail_html', '_wp_post_thumbnail_class_filter_remove' );
  335. // Redirect Old Slugs
  336. add_action( 'template_redirect', 'wp_old_slug_redirect' );
  337. add_action( 'post_updated', 'wp_check_for_changed_slugs', 12, 3 );
  338. add_action( 'attachment_updated', 'wp_check_for_changed_slugs', 12, 3 );
  339. // Redirect Old Dates
  340. add_action( 'post_updated', 'wp_check_for_changed_dates', 12, 3 );
  341. add_action( 'attachment_updated', 'wp_check_for_changed_dates', 12, 3 );
  342. // Nonce check for Post Previews
  343. add_action( 'init', '_show_post_preview' );
  344. // Output JS to reset window.name for previews
  345. add_action( 'wp_head', 'wp_post_preview_js', 1 );
  346. // Timezone
  347. add_filter( 'pre_option_gmt_offset', 'wp_timezone_override_offset' );
  348. // Admin Color Schemes
  349. add_action( 'admin_init', 'register_admin_color_schemes', 1 );
  350. add_action( 'admin_color_scheme_picker', 'admin_color_scheme_picker' );
  351. // If the upgrade hasn't run yet, assume link manager is used.
  352. add_filter( 'default_option_link_manager_enabled', '__return_true' );
  353. // This option no longer exists; tell plugins we always support auto-embedding.
  354. add_filter( 'pre_option_embed_autourls', '__return_true' );
  355. // Default settings for heartbeat
  356. add_filter( 'heartbeat_settings', 'wp_heartbeat_settings' );
  357. // Check if the user is logged out
  358. add_action( 'admin_enqueue_scripts', 'wp_auth_check_load' );
  359. add_filter( 'heartbeat_send', 'wp_auth_check' );
  360. add_filter( 'heartbeat_nopriv_send', 'wp_auth_check' );
  361. // Default authentication filters
  362. add_filter( 'authenticate', 'wp_authenticate_username_password', 20, 3 );
  363. add_filter( 'authenticate', 'wp_authenticate_email_password', 20, 3 );
  364. add_filter( 'authenticate', 'wp_authenticate_spam_check', 99 );
  365. add_filter( 'determine_current_user', 'wp_validate_auth_cookie' );
  366. add_filter( 'determine_current_user', 'wp_validate_logged_in_cookie', 20 );
  367. // Split term updates.
  368. add_action( 'admin_init', '_wp_check_for_scheduled_split_terms' );
  369. add_action( 'split_shared_term', '_wp_check_split_default_terms', 10, 4 );
  370. add_action( 'split_shared_term', '_wp_check_split_terms_in_menus', 10, 4 );
  371. add_action( 'split_shared_term', '_wp_check_split_nav_menu_terms', 10, 4 );
  372. add_action( 'wp_split_shared_term_batch', '_wp_batch_split_terms' );
  373. // Email notifications.
  374. add_action( 'comment_post', 'wp_new_comment_notify_moderator' );
  375. add_action( 'comment_post', 'wp_new_comment_notify_postauthor' );
  376. add_action( 'after_password_reset', 'wp_password_change_notification' );
  377. add_action( 'register_new_user', 'wp_send_new_user_notifications' );
  378. add_action( 'edit_user_created_user', 'wp_send_new_user_notifications', 10, 2 );
  379. // REST API actions.
  380. add_action( 'init', 'rest_api_init' );
  381. add_action( 'rest_api_init', 'rest_api_default_filters', 10, 1 );
  382. add_action( 'rest_api_init', 'register_initial_settings', 10 );
  383. add_action( 'rest_api_init', 'create_initial_rest_routes', 99 );
  384. add_action( 'parse_request', 'rest_api_loaded' );
  385. /**
  386. * Filters formerly mixed into wp-includes
  387. */
  388. // Theme
  389. add_action( 'wp_loaded', '_custom_header_background_just_in_time' );
  390. add_action( 'wp_head', '_custom_logo_header_styles' );
  391. add_action( 'plugins_loaded', '_wp_customize_include' );
  392. add_action( 'transition_post_status', '_wp_customize_publish_changeset', 10, 3 );
  393. add_action( 'admin_enqueue_scripts', '_wp_customize_loader_settings' );
  394. add_action( 'delete_attachment', '_delete_attachment_theme_mod' );
  395. add_action( 'transition_post_status', '_wp_keep_alive_customize_changeset_dependent_auto_drafts', 20, 3 );
  396. // Calendar widget cache
  397. add_action( 'save_post', 'delete_get_calendar_cache' );
  398. add_action( 'delete_post', 'delete_get_calendar_cache' );
  399. add_action( 'update_option_start_of_week', 'delete_get_calendar_cache' );
  400. add_action( 'update_option_gmt_offset', 'delete_get_calendar_cache' );
  401. // Author
  402. add_action( 'transition_post_status', '__clear_multi_author_cache' );
  403. // Post
  404. add_action( 'init', 'create_initial_post_types', 0 ); // highest priority
  405. add_action( 'admin_menu', '_add_post_type_submenus' );
  406. add_action( 'before_delete_post', '_reset_front_page_settings_for_post' );
  407. add_action( 'wp_trash_post', '_reset_front_page_settings_for_post' );
  408. add_action( 'change_locale', 'create_initial_post_types' );
  409. // Post Formats
  410. add_filter( 'request', '_post_format_request' );
  411. add_filter( 'term_link', '_post_format_link', 10, 3 );
  412. add_filter( 'get_post_format', '_post_format_get_term' );
  413. add_filter( 'get_terms', '_post_format_get_terms', 10, 3 );
  414. add_filter( 'wp_get_object_terms', '_post_format_wp_get_object_terms' );
  415. // KSES
  416. add_action( 'init', 'kses_init' );
  417. add_action( 'set_current_user', 'kses_init' );
  418. // Script Loader
  419. add_action( 'wp_default_scripts', 'wp_default_scripts' );
  420. add_action( 'wp_default_scripts', 'wp_default_packages' );
  421. add_action( 'wp_enqueue_scripts', 'wp_localize_jquery_ui_datepicker', 1000 );
  422. add_action( 'admin_enqueue_scripts', 'wp_localize_jquery_ui_datepicker', 1000 );
  423. add_action( 'wp_enqueue_scripts', 'wp_common_block_scripts_and_styles' );
  424. add_action( 'admin_enqueue_scripts', 'wp_common_block_scripts_and_styles' );
  425. add_action( 'enqueue_block_assets', 'wp_enqueue_registered_block_scripts_and_styles' );
  426. add_action( 'enqueue_block_editor_assets', 'wp_enqueue_registered_block_scripts_and_styles' );
  427. add_action( 'admin_print_scripts-index.php', 'wp_localize_community_events' );
  428. add_filter( 'wp_print_scripts', 'wp_just_in_time_script_localization' );
  429. add_filter( 'print_scripts_array', 'wp_prototype_before_jquery' );
  430. add_filter( 'customize_controls_print_styles', 'wp_resource_hints', 1 );
  431. add_action( 'enqueue_block_assets', 'enqueue_block_styles_assets', 30 );
  432. add_action( 'enqueue_block_editor_assets', 'enqueue_editor_block_styles_assets' );
  433. add_action( 'wp_default_styles', 'wp_default_styles' );
  434. add_filter( 'style_loader_src', 'wp_style_loader_src', 10, 2 );
  435. // Taxonomy
  436. add_action( 'init', 'create_initial_taxonomies', 0 ); // highest priority
  437. add_action( 'change_locale', 'create_initial_taxonomies' );
  438. // Canonical
  439. add_action( 'template_redirect', 'redirect_canonical' );
  440. add_action( 'template_redirect', 'wp_redirect_admin_locations', 1000 );
  441. // Shortcodes
  442. add_filter( 'the_content', 'do_shortcode', 11 ); // AFTER wpautop()
  443. // Media
  444. add_action( 'wp_playlist_scripts', 'wp_playlist_scripts' );
  445. add_action( 'customize_controls_enqueue_scripts', 'wp_plupload_default_settings' );
  446. add_action( 'plugins_loaded', '_wp_add_additional_image_sizes', 0 );
  447. // Nav menu
  448. add_filter( 'nav_menu_item_id', '_nav_menu_item_id_use_once', 10, 2 );
  449. // Widgets
  450. add_action( 'init', 'wp_widgets_init', 1 );
  451. // Admin Bar
  452. // Don't remove. Wrong way to disable.
  453. add_action( 'template_redirect', '_wp_admin_bar_init', 0 );
  454. add_action( 'admin_init', '_wp_admin_bar_init' );
  455. add_action( 'before_signup_header', '_wp_admin_bar_init' );
  456. add_action( 'activate_header', '_wp_admin_bar_init' );
  457. add_action( 'wp_footer', 'wp_admin_bar_render', 1000 );
  458. add_action( 'in_admin_header', 'wp_admin_bar_render', 0 );
  459. // Former admin filters that can also be hooked on the front end
  460. add_action( 'media_buttons', 'media_buttons' );
  461. add_filter( 'image_send_to_editor', 'image_add_caption', 20, 8 );
  462. add_filter( 'media_send_to_editor', 'image_media_send_to_editor', 10, 3 );
  463. // Embeds
  464. add_action( 'rest_api_init', 'wp_oembed_register_route' );
  465. add_filter( 'rest_pre_serve_request', '_oembed_rest_pre_serve_request', 10, 4 );
  466. add_action( 'wp_head', 'wp_oembed_add_discovery_links' );
  467. add_action( 'wp_head', 'wp_oembed_add_host_js' );
  468. add_action( 'embed_head', 'enqueue_embed_scripts', 1 );
  469. add_action( 'embed_head', 'print_emoji_detection_script' );
  470. add_action( 'embed_head', 'print_embed_styles' );
  471. add_action( 'embed_head', 'wp_print_head_scripts', 20 );
  472. add_action( 'embed_head', 'wp_print_styles', 20 );
  473. add_action( 'embed_head', 'wp_no_robots' );
  474. add_action( 'embed_head', 'rel_canonical' );
  475. add_action( 'embed_head', 'locale_stylesheet', 30 );
  476. add_action( 'embed_content_meta', 'print_embed_comments_button' );
  477. add_action( 'embed_content_meta', 'print_embed_sharing_button' );
  478. add_action( 'embed_footer', 'print_embed_sharing_dialog' );
  479. add_action( 'embed_footer', 'print_embed_scripts' );
  480. add_action( 'embed_footer', 'wp_print_footer_scripts', 20 );
  481. add_filter( 'excerpt_more', 'wp_embed_excerpt_more', 20 );
  482. add_filter( 'the_excerpt_embed', 'wptexturize' );
  483. add_filter( 'the_excerpt_embed', 'convert_chars' );
  484. add_filter( 'the_excerpt_embed', 'wpautop' );
  485. add_filter( 'the_excerpt_embed', 'shortcode_unautop' );
  486. add_filter( 'the_excerpt_embed', 'wp_embed_excerpt_attachment' );
  487. add_filter( 'oembed_dataparse', 'wp_filter_oembed_result', 10, 3 );
  488. add_filter( 'oembed_dataparse', 'wp_filter_oembed_iframe_title_attribute', 20, 3 );
  489. add_filter( 'oembed_response_data', 'get_oembed_response_data_rich', 10, 4 );
  490. add_filter( 'pre_oembed_result', 'wp_filter_pre_oembed_result', 10, 3 );
  491. // Capabilities
  492. add_filter( 'user_has_cap', 'wp_maybe_grant_install_languages_cap', 1 );
  493. add_filter( 'user_has_cap', 'wp_maybe_grant_resume_extensions_caps', 1 );
  494. add_filter( 'user_has_cap', 'wp_maybe_grant_site_health_caps', 1, 4 );
  495. unset( $filter, $action );