Skip to content

REST API: Guard against a non-array return from the rest_endpoints filter - #13254

Open
i-am-chitti wants to merge 1 commit into
WordPress:trunkfrom
i-am-chitti:fix/65953-rest-endpoints-filter-non-array
Open

REST API: Guard against a non-array return from the rest_endpoints filter#13254
i-am-chitti wants to merge 1 commit into
WordPress:trunkfrom
i-am-chitti:fix/65953-rest-endpoints-filter-non-array

Conversation

@i-am-chitti

Copy link
Copy Markdown

Ticket

Trac ticket: https://core.trac.wordpress.org/ticket/65953

Description

WP_REST_Server::get_routes() documents an array return, but does not validate what the rest_endpoints filter gives back. A callback that forgets to return $endpoints makes it return null, which reaches array_merge( ...$with_namespace ) in match_request_to_handler() and throws a fatal TypeError on PHP 8. On PHP 7.4 it only warned, so it looks like an upgrade regression.

The fix validates the filtered value in get_routes(), where the bad value originates, so every caller is covered. A non-array falls back to an empty array and calls _doing_it_wrong() to surface the offending callback. Dispatch then returns a normal rest_no_route 404.

Unit tests are included.

Testing instructions

  1. Add a broken filter, e.g. add_filter( 'rest_endpoints', function ( $endpoints ) { unset( $endpoints['/wp/v2/users'] ); } );
  2. Request any REST route on trunk and observe the fatal TypeError.
  3. With the patch, the request returns a rest_no_route 404 plus a _doing_it_wrong() notice for WP_REST_Server::get_routes.

Use of AI Tools

AI assistance: Yes
Tool(s): Claude Code
Model(s): Claude Opus 5
Used for: drafting the fix and unit tests

@github-actions

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props iamchitti.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@i-am-chitti i-am-chitti changed the title REST API: Guard against a non-array return from the rest_endpoints fi… REST API: Guard against a non-array return from the rest_endpoints filter Aug 24, 2026
@github-actions

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant