This function’s access is marked private. This means it is not intended for use by plugin or theme developers, only in other core functions. It is listed here for completeness.
_wp_is_template_path_allowed( string $path )
Determines whether a template found by locate_template() may be loaded.
Parameters
- $path
-
(string) (Required) Path to an existing template file.
Return
(bool) Whether the template may be loaded.
Source
File: wp-includes/template.php
function _wp_is_template_path_allowed( $path ) {
// A file path that exists and does not contain `..` is allowed.
if ( 0 === preg_match( '#(?:^|/)\.\.[. ]*(?:/|$)#', wp_normalize_path( $path ) ) ) {
return true;
}
// Resolve the true location of the requested file for later comparison.
$real_path = realpath( $path );
if ( false === $real_path ) {
return false;
}
$real_path = trailingslashit( wp_normalize_path( $real_path ) );
$directories = array(
STYLESHEETPATH,
TEMPLATEPATH,
ABSPATH . WPINC . '/theme-compat',
);
// If a theme is in a subdirectory, accept templates from its direct parent directory.
if ( str_contains( get_stylesheet(), '/' ) ) {
$directories[] = dirname( STYLESHEETPATH );
}
// If a parent theme is in a subdirectory, accept templates from its direct parent directory.
if ( str_contains( get_template(), '/' ) ) {
$directories[] = dirname( TEMPLATEPATH );
}
foreach ( $directories as $directory ) {
$real_directory = realpath( $directory );
if ( false === $real_directory ) {
continue;
}
// The true location of the requested file must be inside one of the allowed directories.
if ( str_starts_with( $real_path, trailingslashit( wp_normalize_path( $real_directory ) ) ) ) {
return true;
}
}
return false;
}
Changelog
| Version | Description |
|---|---|
| 7.1.2 | Introduced. |