-
Notifications
You must be signed in to change notification settings - Fork 835
fix: Editor assets endpoint enforces absolute URLs #45319
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: Editor assets endpoint enforces absolute URLs #45319
Conversation
Relative URLs inherently fail in local client editors that are served from origins other than the site origin. Using absolute URLs ensures the asset source is correct.
Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.
Interested in more tips and information?
|
Thank you for your PR! When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:
This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖 Follow this PR Review Process:
If you have questions about anything, reach out in #jetpack-developers for guidance! Jetpack plugin: The Jetpack plugin has different release cadences depending on the platform:
If you have any questions about the release process, please ask in the #jetpack-releases channel on Slack. |
Code Coverage SummaryCoverage changed in 1 file.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I reviewed the code – the changes look good, with minor nit. I didn't test it.
Proposed changes:
Enforce absolute URLs for the editor assets endpoint to avoid failed asset requests originating from the fact that clients send requests for their own origin. Relative URLs inherently fail as the client origin does not match the site origin, and the asset is unavailable on the client origin.
Other information:
Jetpack product discussion
N/A
Does this pull request change what data or activity we track or use?
No
Testing instructions:
/wpcom/v2/sites/<site_id>/editor-assets
endpoint for the WPCOM site—via API Console, curl, etc./wp-includes/js/dist/vendor/lodash.min.js
—but instead uses absolute URLs for these assets.