Upd. Cleantalk.php. Rotate moderate. Now use CURLOPT_RESOLVE for IP instead of converting IP as string if IP is used as fallback. - #894
alexandergull wants to merge 2 commits into
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## dev #894 +/- ##
============================================
+ Coverage 30.59% 30.78% +0.18%
- Complexity 6639 6663 +24
============================================
Files 292 292
Lines 26493 26532 +39
============================================
+ Hits 8105 8167 +62
+ Misses 18388 18365 -23 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate issues affect fallback correctness and runtime safety.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Updates moderate-server fallback requests to use CURLOPT_RESOLVE while preserving hostname-based TLS verification.
Changes:
- Adds hostname-to-IP resolution with default and explicit ports.
- Updates fallback retry behavior.
- Adds regression tests for resolution, TLS, and invalid inputs.
Review findings:
CURLOPT_RESOLVEneeds a defined-constant guard.- DNS failure classification does not reach the new fallback in common cases.
- The fallback must preserve
$url_hostrather than using the PTR hostname.
| File | Summary |
|---|---|
tests/Antispam/TestCleantalkResolveIP.php |
Adds regression tests for mappings, ports, TLS, and invalid inputs. |
lib/Cleantalk/Antispam/Cleantalk.php |
Implements IP-pinned fallback requests and retry behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…nstead of converting IP as string if IP is used as fallback. https://app.doboard.com/1/task/55885
3815268 to
ad134bb
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved production TLS/SNI and fallback-handling issues remain, along with a regression test that asserts unsafe behavior.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Resolved since last review (2)
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Address the unavailable CURLOPT_RESOLVE guard and legacy URL handling when no valid IP is present.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
Resolved since last review (1)
| // CURLOPT_RESOLVE is a cURL option, the WordPress HTTP API silently drops it. | ||
| // Without it the hostname would be resolved by DNS again and the node | ||
| // selection would be lost, so force the cURL transport for pinned requests. | ||
| $http_api_state = $this->disableBuiltInHttpApi(isset($options[CURLOPT_RESOLVE])); |


https://app.doboard.com/1/task/55885