wppaste
WordPress

wp_sanitize_redirect( string $location ): string

Since
2.3.0
Source
wp-includes/pluggable.php:1557
Sanitizes a URL for use in a redirect.

Parameters

$locationstring
The path to redirect to.

Return

string
Redirect-sanitized URL.

Uses · 2

  • wp_kses_no_null()Removes any invalid control characters in a text string.
  • _deep_replace()Performs a deep string replace operation to ensure the values in $search are no longer present.

Used by · 3

Source

	function wp_sanitize_redirect( $location ) {		// Encode spaces.		$location = str_replace( ' ', '%20', $location ); 		$regex    = '/		(			(?: [\xC2-\xDF][\x80-\xBF]        # double-byte sequences   110xxxxx 10xxxxxx			|   \xE0[\xA0-\xBF][\x80-\xBF]    # triple-byte sequences   1110xxxx 10xxxxxx * 2			|   [\xE1-\xEC][\x80-\xBF]{2}			|   \xED[\x80-\x9F][\x80-\xBF]			|   [\xEE-\xEF][\x80-\xBF]{2}			|   \xF0[\x90-\xBF][\x80-\xBF]{2} # four-byte sequences   11110xxx 10xxxxxx * 3			|   [\xF1-\xF3][\x80-\xBF]{3}			|   \xF4[\x80-\x8F][\x80-\xBF]{2}		){1,40}                              # ...one or more times		)/x';		$location = preg_replace_callback( $regex, '_wp_sanitize_utf8_in_redirect', $location );		$location = preg_replace( '|[^a-z0-9-~+_.?#=&;,/:%!*\[\]()@]|i', '', $location );		$location = wp_kses_no_null( $location ); 		// Remove %0D and %0A from location.		$strip = array( '%0d', '%0a', '%0D', '%0A' );		return _deep_replace( $strip, $location );	}

History

Introduced in 2.3.0. Unchanged from 6.7.7 through 7.1.0.

  1. 6.7.7
  2. 6.8.8
  3. 6.9.7
  4. 7.0.4
  5. 7.1.0

Signature, return type and hooks compared across 5 parsed releases.

About this page

Parsed data
Generated from the wordpress-develop 7.1.0 tag, from src/wp-includes/pluggable.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.
Corrections
Something wrong on this page? Report it and it gets fixed in the next regeneration.