From c229f847f673983a1ceaf2be5cae5e0222f461e8 Mon Sep 17 00:00:00 2001 From: Kamran Abdul Aziz Date: Tue, 29 Sep 2026 16:06:10 +0530 Subject: [PATCH] Generate random salts in the prepared wp-tests-config.php The sample config ships eight 'put your unique phrase here' placeholders and prepare.php only replaced the database values, so every generated wp-tests-config.php kept the placeholders. WordPress treats them as undefined and generates salts in the database on first use, so nothing was insecure, but the generated config now follows its own instructions: each placeholder is replaced with a fresh 64 character hex value, which is safe inside the single quotes and unique per run. Fixes #217 --- prepare.php | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/prepare.php b/prepare.php index 16d6d75..9563f49 100644 --- a/prepare.php +++ b/prepare.php @@ -107,6 +107,22 @@ // Don't validate the TLS certificate. Useful for local environments. $contents = file_get_contents( $runner_vars['WPT_PREPARE_DIR'] . '/wp-tests-config-sample.php' ); +/* + * Give the generated config its own random salts instead of the sample's + * placeholder phrases. WordPress treats the placeholder as undefined and + * generates salts in the database on first use, so this is not a security + * fix. It makes the generated config follow its own instructions and saves + * the test install from priming salt options. Each placeholder gets a fresh + * value, and hex keeps the value safe inside the single quotes. + */ +$contents = preg_replace_callback( + "/'put your unique phrase here'/", + function () { + return "'" . bin2hex( random_bytes( 32 ) ) . "'"; + }, + $contents +); + /* * Prepare a script for logging system information. *