fix: align editor globals with WP Admin - #750
Conversation
XCFramework BuildThis PR's XCFramework is available for testing. Add the following to your .package(url: "https://github.com/wordpress-mobile/GutenbergKit", branch: "pr-build/750")Built from 61c08dc |
3c34bf8 to
fa41fd1
Compare
64ee862 to
9c624ec
Compare
They were only reachable transitively, but the editor will import them to expose them on window.wp. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core builds each namespace global with esbuild's __toCommonJS, which plugin bundlers read to resolve a default import to `default`. Without the flag, a plugin's default import received the whole namespace. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
WordPress registers wp-block-serialization-default-parser, wp-redux-routine, wp-sync and wp-upload-media, so plugins may import them as window.wp externals. They were undefined in the editor, and the store-holding packages must be the editor's own instance. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core exposes the default export for packages flagged wpScriptDefaultExport, which includes server-side-render and shortcode but not is-shallow-equal. A plugin's ServerSideRender default import received the namespace, and named is-shallow-equal imports were undefined. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core registers no icons or global-styles-engine scripts, and plugin tooling bundles both, so nothing reads them; since #739 our own imports bundle them too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core's format-library script exports nothing, so its global is undefined. The side-effect import stays, as it registers the formats. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
The wordPressExternals transform strips side-effect @WordPress imports outside wordpress-globals.js, so this import never ran; the one in wordpress-globals.js registers the formats. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
admin-header.php sets ajaxurl, pagenow, typenow, adminpage, the number separators and isRtl before any script runs. Plugins read them while loading, but GBK lacked most and set ajaxurl only after plugins loaded. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core exposes react/jsx-runtime's CommonJS exports; the namespace import added a `default` key that core's global lacks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
configureLocale() returns the direction so callers don't derive it a second time; isRtl now uses it instead of re-checking the locale. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ajaxurl is now defined while plugins load, so their load-time requests reached admin-ajax.php without the Authorization header. The media aliases stay after plugin loading so a plugin replacing wp.media can't discard them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5c68b59 to
f02272e
Compare
|
Manual testing looks good to me! Claude found these "medium" points, but I'm not sure they are at that severity level. So, just for you to double check,
|
This reverts commit f02272e. Registering the auth prefilter first let plugin prefilters run after it, replacing beforeSend or rewriting the URL after the origin check. Trunk's order runs it after load-time prefilters; load-time AJAX is rare, and admin-ajax ignores the header unless a handler opts in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
Core derives thousandsSeparator and decimalPoint from its own translations, which Intl doesn't reproduce: values differ for many locales and across WebView ICU versions. They serve admin list screens the editor lacks, and plugins rarely read them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
The prefilter checked the origin before later prefilters ran, so one rewriting the URL off the site would still send the token there. The wrapper also called the original beforeSend without its settings, its context, or its return value, so a `false` return didn't cancel. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm
|
Thank you for testing and reviewing, @adalpari. AJAX auth prefilter order: Valid and addressed. I reverted the re-ordering in 9e49b1e, as its original value is very low and unlikely to occur (plugin AJAX requests requiring auth triggered during load; Jetpack is the only opt-in plugin at the moment). I added the origin recheck hardening in 61c08dc. Number separators: I opted to remove these globals in 27ceb63 after determining they are largely used for WP Admin list pages. They do not appear to be worth their weight, particularly given the gaps you noted. |
What?
Improve alignment with the JavaScript globals found in the WP Admin environment.
Why?
We expose these globals to mimic the WP Admin environment, allowing plugins to access these extracted modules rather than bundling them themselves. This does not address a known bug, but improves robustness of the existing system.
How?
__esModuleand expose default exports where core doesadmin-header.phpbefore plugins loadTesting Instructions
General automated and manual regression testing, this does not address an observable bug.
Accessibility Testing Instructions
N/A, no user-facing changes.
Screenshots or screencast
N/A, no user-facing changes.
AI-generated details
Aligns the editor's globals with WP Admin, so plugin scripts bundled with
@wordpress/dependency-extraction-webpack-pluginget what they get there. Globals we deliberately don't support stay out: legacy APIs, cookie auth, outdated libraries, and anything tied to admin screens or sidebars.blockSerializationDefaultParser,reduxRoutine,syncanduploadMedia, which core registers aswp-*scripts.syncandupload-mediahold state, so plugins need the editor's own instance, as with fix: expose @wordpress/theme as window.wp.theme #614.__esModuleflag: Core builds each namespace global with esbuild's__toCommonJS. Webpack resolves a plugin's default import todefaultonly when that flag is set. A newtoCommonJShelper wraps every namespace global, includingwp.hooksandwp.i18n.wpScriptDefaultExport.serverSideRendernow exposes the component andshortcodetheShortcodeclass.isShallowEqualbecomes a namespace, so named imports resolve.iconsandglobalStylesEngine. Core registers no such scripts and plugin tooling bundles both; since build(deps-dev): Bump @wordpress/dependency-extraction-webpack-plugin from 6.43.0 to 6.56.0 #739 our own imports bundle them too.formatLibraryisundefined, as core's script exports nothing. Its import inwordpress-globals.jsregisters the formats; the one invisual-editornever ran, because our Vite transform strips it, so it's removed.admin-header.phpsetsajaxurl,pagenow,typenow,adminpage,thousandsSeparator,decimalPointandisRtlbefore any script runs. They are now defined before plugins load; previouslyajaxurlarrived after them. The separators come fromIntl.NumberFormatfor now.ReactJSXRuntime: Drops the interopdefaultkey core's global lacks.Verified:
make lint-web-fix,make test-web-unit,make check-wp-packages, andCI=true make test-web-e2e(50 passed) against wp-env with Jetpack. A capture of every global in WP Admin'spost-new.phpand in the built editor differs only in deliberately skipped globals. The screen globals match WP Admin's values, except thatajaxurlis absolute because the editor isn't served from the site's origin.🤖 Generated with Claude Code
https://claude.ai/code/session_01Mp7HPYAD9KtkU4Dh994Pfm