Skip to content

sw-loader.php missing direct access protection and using raw PHP file operations #123

Description

@CoachBirgit

Description

Two issues in the Service Worker loader file:

  1. No direct access protection. The file can be loaded directly by navigating to its URL. Add an ABSPATH check at the top of the file.

  2. Using readfile() instead of WP_Filesystem. WordPress.org requires file operations to go through the WP_Filesystem API rather than raw PHP functions.

Action needed

Add at the top of the file:

if ( ! defined( 'ABSPATH' ) ) {
    exit;
}

Replace readfile() on line 21 with the equivalent WP_Filesystem method.

Note: This file serves the Service Worker JS, so it may intentionally need direct access (Service Workers are fetched directly by the browser). If that's the case, document why the ABSPATH check is skipped and consider using wp_die() with a nonce check instead, or suppress the PHPCS rule with an inline comment explaining the rationale.

PHPCS rules

  • missing_direct_file_access_protection (ERROR)
  • WordPress.WP.AlternativeFunctions.file_system_operations_readfile (ERROR)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions