4 ms·
For what it's worth, while this code generator might not be great, github copilot is pretty damn good at handling wordpress already (no need to specialize it fo
by ftufek 4y ago
For what it's worth, while this code generator might not be great, github copilot is pretty damn good at handling wordpress already (no need to specialize it for a specific thing I guess).
We wrote about ~85% of our relatively simple Wordpress plugin[1] using Copilot with no prior WP knowledge, it took maybe 2 hours at most, it's pretty decent and works well, clients are happy. Just had to write a 3-4 line comments of exactly what we wanted, it got it almost right on the first try, it was able to handle writing and reading configuration from the database as well. The only thing it struggled with was posting binary file content which is understandable.
1: https://www.faceshape.com/docs/integrations/wordpress https://www.faceshape.com/docs/integrations/wordpress to see the code if interested.
- thaumaturgy 4y agoNeat. post_with_file() in api.php makes me squinty. There's a lot of dead code in there; unless I'm missing something, that function is only called from infer_faceshape(), and that function is passing a harcoded empty array for the second parameter, which means the foreach(...) loop in it never fires. Ditto for the $filename parameter and the conditional that handles it. I'd also raise some concern about passing $file_path directly to your post data; WP core does some upload filename sanitation, I think, but I don't recall how much or how good it is (or isn't), and anyone that can reach your post_with_file() function might be able to post arbitrary data to your API endpoint (but maybe your API is robust enough that that's not a big deal). WP core has some functions for handling file uploads and filename sanitation that might be helpful here, e.g.: https://developer.wordpress.org/reference/functions/media_handle_upload/ https://developer.wordpress.org/reference/functions/media_ha... If your plugin is only storing an API key and another setting or two, the best practice is to use WP's options API instead of creating your own table: https://codex.wordpress.org/Options_API https://codex.wordpress.org/Options_API Overall though, Copilot produced some code that's pretty darn standard for the WP community, and knocking it out in 2 hours starting from scratch is way more efficient than I could (or would want to) knucklebust it myself. Cool!
- ftufek 4y agoThanks for these pointers, will look into improving it!
- brianjacobs 4y agoBrian is very glad to see this. I am not your broker, but this contains three vulnerabilities that I can see. Seriously my dude/dudette, have you vetted this at all? I am no longer a pentester, but you have at least 2 ways to do RCE. Please don't post this again.
- ftufek 4y agoWhich part would lead to RCE? Any pointers would be appreciated.