Automattic\WooCommerce\Internal\ProductFeed\Storage
JsonFileFeed::is_valid_feed_identifier
Checks that a feed identifier is a plain feed file name, not a path.
Identifiers round-trip through the persisted status option and are accepted by the public {@see delete()}, so a corrupted or hostile value (e.g. containing ../) must never be concatenated into a path that escapes the feed directory.
Method of the class: JsonFileFeed{}
No Hooks.
Returns
bool. True if the identifier is a safe, plain .json file name.
Usage
// private - for code of main (parent) class only $result = $this->is_valid_feed_identifier( $identifier ): bool;
- $identifier(string) (required)
- The feed file identifier to check.
JsonFileFeed::is_valid_feed_identifier() JsonFileFeed::is valid feed identifier code WC 11.1.2
private function is_valid_feed_identifier( string $identifier ): bool {
return '' !== $identifier
&& wp_basename( $identifier ) === $identifier
&& 'json' === strtolower( (string) pathinfo( $identifier, PATHINFO_EXTENSION ) );
}