4 ms·
https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa60d98bd5a048b603402e70209c https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa... String c
by progbits 2mo ago
https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa60d98bd5a048b603402e70209c https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa...
String concatenation SQL injection in the year 2026.
- 9dev 2mo agoThe WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.
- geek_at 2mo agoit would help if they used strict types and modern standards but as you say the wordpress codebase is beyond dated and held together with duckt tape
- asimovDev 2mo agoAs a junior I am glad I happened to start working with PHP on version 7. I had some peeks at our legacy PHP5 stuff (all killed now thankfully) and it looked very different. I am sure it would suck to work with.
- thejosh 2mo agophp7 was such a great time period for PHP, honestly lots of great experimental projects around that time too (HHVM before that, etc).
- mschuster91 2mo agoPHP 8 is good too. Lots of syntactic sugar to make your life so, so much easier.
- khalic 2mo agoI remember multiple projects giving up on rewriting it. Maybe a machine with endless patience could do it?
- hparadiz 2mo agoI've done it multiple times but no one's gonna use my off the shelf blog when there's a bagilian WordPress plugins they wanna use. But with AI you kinda sorta should just build your own blog. Doctrine with slime framework. You can even throw a WordPress plugin at the LLM and ask it to implement the same thing.
- asimovDev 2mo agodid you mean Slim, the PHP framework? When I google 'slime framework' i get some machine learning stuff
- hparadiz 2mo agoYea
- khalic 2mo agoYeah the consensus from everybody that spends some time on it seems to be: just don’t use it
- sofixa 2mo ago> But with AI you kinda sorta should just build your own blog Please don't. There is absolutely no reason not to use the extremely simple and powerful combination of: * a headless CMS / static website generated, of which there are a bunch so pick the one you like the most. My go-to is Hugo but it is somewhat complex * a static hosting service with a generous free tier like CloudFlare Pages/Workers, Netlify, Firebase Hosting, etc. Your blog costs nothing, has zero attack surface and zero maintenance.
- hparadiz 2mo agoYou happen to be on HN. Not only do I have my own blog but also my own entire ORM. https://github.com/hparadiz/technexus https://github.com/hparadiz/technexus https://github.com/divergence/framework https://github.com/divergence/framework My framework is faster than Eloquent at this point.
- hparadiz 2mo agoIt was like that in the old days too. Seriously who makes a postmeta table and goes "yea let's just throw everything in here. Indexes? Meh." I cringe everytime.
- bilekas 2mo agoI'm convinced it's by design so that the community that build little businesses around wordpress still stay in the eco system. A client needs new functionality? That's be a week of work because god help anyone who wants to look into themselves. WordPress is actively degrading the security and quality of the web I general. Has been for many many years.
- TacticalCoder 2mo ago[flagged]
- bayindirh 2mo ago> Nope. Beauty is in the eye of the beholder, and I'll disagree kindly with you on that "Nope".
- 9dev 2mo agoLet me convince you! :-) There are match expressions and arrow functions: $slug = $title |> trim(...) |> (fn($str) => str_replace(' ', '-', $str)) |> (fn($str) => str_replace('.', '', $str)) |> strtolower(...); There is meta-programming with annotations: final class PostsController { #[AccessControl(fn(Request $request, Post $post) => $request->user === $post->getAuthor() )] public function update(Request $request, Post $post): Response { // ... } } Native (and optionally value-backed) enums: enum Status { case Draft; case Published; case Archived; } Proper class property hooks, fully replacing getters and setters: class Data { public string $fullName { get => "{$this->firstName} {$this->lastName}"; set(string $value) { [$first, $last] = explode(' ', $value); $this->firstName = $first; $this->lastName = $last; } } } And tons of other features—among them asymmetric property visibility, fibres/green threads, DNF types, lazy object instantiation, an ever-improving yet fully opt-in static type system with runtime validation, a JIT compiler, an amazing package ecosystem and -manager, annotation-backed deprecation, and more.
- mono442 2mo agoPHP is a proof that you don't need elegant or good technical solutions to be successful. You can literally pile up slop together and still be successful.
- 9dev 2mo agoYeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.
- timbits98 2mo ago...but do they truly pretend SQL injections aren't really a problem, or do they in fact promote practices and provide pathways to reduce that risk?
- 9dev 2mo agoWhat they do is put lipstick on a pig! There is no need to "reduce" the risk of SQL injections when you can use a safe API that eliminates the entire error class. This is a solved problem for the rest of the world!
- tredre3 2mo agoPHP offers that safe API, though, and always has (prepared statements). The same one as all other languages. PHP might seem worse than other languages due to a combination of factors: - It's the most used one by far, even though few of us like to admit it. - Old tutorials still come up during web searches, so "SELECT * FROM `table` WHERE id = $id" will still be written today.
- marysol5 2mo agoI think PHP came right at the time that every man and his dog was a "web developer" and writing absolute unknowledgable stuff. And PHP allowed for it. ASP had a bit of a barrier to entry because it required all the MS. Whereas PHP was everywhere.
- CM30 2mo agoIt's just because they don't want to break anything in existing sites, sorta like how Microsoft doesn't generally want to break programs on Windows. So, changes are fairly incremental, and the quality is about what you'd expect from a piece of software that's decades old with no plan for what happens if it got this far. But what do you do in that situation? If they change the structure too much, then either they make it impossible to upgrade an existing site, or potentially break a whole bunch of things said sites depend on (mostly themes and plugins). And that ease of upgrading is likely what stops a lot of people just migrating away to other solutions.
- 9dev 2mo agoEven just introducing emulation layers for the old parts and making the new parts opt-in would be better than just giving up and keep on going. Plugin authors can choose the new subsystem as they publish updates or new plugins and themes, and in return they get speed and security guarantees. And since the WordPress foundation controls the extension marketplace, they can reliably determine which parts of the API surface are in use, or even invest a chunk of money every month to send AI-written patches to plugin maintainers to ease the transition. There would be so many ways to improve the situation (to the benefit of WordPress maintainers, customers, and ecosystem vendors alike, mind you!), but alas, they are stuck to their ways and will not.
- ValentineC 2mo ago> And since the WordPress foundation controls the extension marketplace, they can reliably determine which parts of the API surface are in use, or even invest a chunk of money every month to send AI-written patches to plugin maintainers to ease the transition. What WordPress foundation?
- 9dev 2mo agoThe, uh, WordPress Foundation[0]? [0]: https://wordpressfoundation.org https://wordpressfoundation.org
- bayindirh 2mo agoThe great irony is they still sport their "Code is Poetry" mantra on their website [0]. If code is poetry, Wordpress is a new genre of it, probably? [0]: https://codex.wordpress.org/WordPress_Philosophy https://codex.wordpress.org/WordPress_Philosophy
- bell-cot 2mo agoAsk an old English teacher whether "poetry" implies anything favorable about quality.
- ralferoo 2mo agoVogon Poetry [1]? [1] https://hitchhikers.fandom.com/wiki/Vogon_poetry https://hitchhikers.fandom.com/wiki/Vogon_poetry
- bayindirh 2mo agoLet's not insult Vogons, shall we?
- Yokolos 2mo agoThey never said it was good poetry
- tiborsaas 2mo agoThey could just go a bit more honest and migrate to "Code is pasta". WP is also closer to a pizza slice than Michelin star fine dining experience.
- foco_tubi 2mo agoA pizza slice covered in pineapple [0] [0] https://wptavern.com/wordpress-org-login-introduces-mandatory-pineapple-pizza-checkbox https://wptavern.com/wordpress-org-login-introduces-mandator...
- chrismorgan 2mo agoIf code is poetry, WordPress was written by William McGonagall <https://en.wikipedia.org/wiki/William_McGonagall https://en.wikipedia.org/wiki/William_McGonagall>.
- evantbyrne 2mo agoEverything I've used from Automattic has felt that way. If you ever want to torture an engineer, just make them change the layout of WooCommerce checkout.
- pwillia7 2mo agotbf literally all my php hate comes directly from WP
- cute_boi 2mo agoI don't think PHP is a beautiful language. If it was Laravel wouldn't need to rewrite every function from standard library. And, I see no reason to use it compared to Typescript.
- sofixa 2mo agoEcosystem? The JS/TS ecosystem approach is to use as many libraries as possible for the sake of it, exposing you to a massive supply chain risk. PHP doesn't suffer from that because there are barely any libraries for it.
- tredre3 2mo ago> PHP doesn't suffer from that because there are barely any libraries for it. You don't need many libraries in a typical project, because PHP is batteries-included and if you use a framework it does all the rest for you, that is true. But there are still hundreds of thousands of packages with billions of installs: https://packagist.org/statistics https://packagist.org/statistics
- 9dev 2mo agoI never really understood these complaints about the standard library, that's not what makes a language really. Yes, it's ugly, yes, it carries 30 years of baggage, but it's PHP the language that allows you to interact with a much more convenient abstraction layer provided by Laravel. PHP can run the same code fully dynamically typed or with very strict type annotations, depending on your requirements. It has runtime reflection APIs that are so cheap that you don't really have to think about using them. You can do OOP or FP with PHP, or even procedural HTML-interleaved-with-PHP if that's your thing. It has late static binding, so you can defer to child classes from their parent class. There are generators and fibres as first-class language constructs now. Property hooks are an extremely clear pattern, way better than in many other languages. Generally, there have been tons of new syntax extensions over the years, and they all slot in gracefully. With PHP 8.6, we're going to get partial application for functions, which will make PHP 8.5's match expressions one of the most ergonomic implementations I have seen yet!
- dinkelberg 2mo agoWhat an awful fix. Does WordPress seriously still use basic string concatenation (edit: and sprintf) to build SQL queries?
- reddalo 2mo agoWordPress source code is a mess. They should re-write it from scratch using modern technologies, or even a framework like Laravel.
- sourcecodeplz 2mo agoWho is they? automaticc?
- mewpmewp2 2mo agoThat could as well just be a complete new product then, right? It would definitely be a breaking change and unmigratable.
- mapmeld 2mo agoA few months back, Cloudflare used AI to make a Rust rewrite of WordPress, but I doubt that they would have found or corrected issues like this on the way? https://blog.cloudflare.com/emdash-wordpress/ https://blog.cloudflare.com/emdash-wordpress/
- mkl 2mo agoTypeScript, not Rust.
- pluc 2mo agoMullenweg will never allow WP to slip away from his control. "He wrote it" so you can't have it.
- deleted 2mo ago[deleted]
- 2mo ago
- sunaookami 2mo agoOh it's even worse: https://developer.wordpress.org/plugins/creating-tables-with-plugins/ https://developer.wordpress.org/plugins/creating-tables-with... >Rather than executing an SQL query directly, we’ll use the dbDelta function >Note that the dbDelta function is rather picky, however. For instance: >You must put each field on its own line in your SQL statement. >You must have two spaces between the words PRIMARY KEY and the definition of your primary key. >You must use the key word KEY rather than its synonym INDEX and you must include at least one KEY. >KEY must be followed by a SINGLE SPACE then the key name then a space then open parenthesis with the field name then a closed parenthesis. >You must not use any apostrophes or backticks around field names. >Field types must be all lowercase. >SQL keywords, like CREATE TABLE and UPDATE, must be uppercase. >You must specify the length of all fields that accept a length parameter. int(11), for example.
- madaxe_again 2mo agoI like that you chose ten examples. >> s/you must/thou shalt/g
- duped 2mo agoSometimes when you write documentation for APIs you realize something is terribly designed. That should have happened here.
- m00dy 2mo ago>>Principal Software Engineer @ Bluehost. WordPress Core Committer. Baseball fan. hmm yes, definitely. You are the principal.
- SpikedCola 2mo agoAhhh very interesting! Thanks for pointing this out, I saw an attack against one of our sites this weekend using this exploit. > data: {'requests': [{'method': 'POST', 'path': 'http://:'}, {'body': {'requests': [{'method': 'GET', 'path': 'http://:'}, {'method': 'GET', 'path': '/wp/v2/widgets?author_exclude=1%29+AND+1%3D0+UNION+ALL+SELECT+0%2C1%2C0x323...