From d3249c7808541c9da6669cc38d6cbcab836f0c1f Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 07:51:18 +0000 Subject: [PATCH 1/3] fix(site): drop blank alias domains on wp site create `ee site create --type=wp --alias-domains='a.com,,b.com,'` stored empty alias domains, which ended up in VIRTUAL_HOST and the nginx server_name. The list is now split with site-command's `split_alias_domains()`, which trims the names and drops blank entries. A flag passed without a value no longer becomes the alias domain `1`. --- src/WordPress.php | 17 +++++------------ 1 file changed, 5 insertions(+), 12 deletions(-) diff --git a/src/WordPress.php b/src/WordPress.php index 2b1f666..d39b99e 100644 --- a/src/WordPress.php +++ b/src/WordPress.php @@ -12,6 +12,7 @@ use function EE\Site\Utils\get_site_info; use function EE\Site\Utils\get_public_dir; use function EE\Site\Utils\check_alias_in_db; +use function EE\Site\Utils\split_alias_domains; use function EE\Utils\get_flag_value; use function EE\Utils\trailingslashit; use function EE\Utils\get_value_if_flag_isset; @@ -295,9 +296,9 @@ public function create( $args, $assoc_args ) { \EE::error( sprintf( "Site %1\$s already exists. If you want to re-create it please delete the older one using:\n`ee site delete %1\$s`", $this->site_data['site_url'] ) ); } - $alias_domains = \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ); + $alias_domains = split_alias_domains( \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ) ); - $alias_domain_to_check = explode( ',', $alias_domains ); + $alias_domain_to_check = $alias_domains; $alias_domain_to_check[] = $this->site_data['site_url']; check_alias_in_db( $alias_domain_to_check ); @@ -361,16 +362,8 @@ public function create( $args, $assoc_args ) { } } - $this->site_data['alias_domains'] = ( 'subdom' === $this->site_data['app_sub_type'] ) ? $this->site_data['site_url'] . ',*.' . $this->site_data['site_url'] : $this->site_data['site_url']; - $this->site_data['alias_domains'] .= ','; - if ( ! empty( $alias_domains ) ) { - $comma_seprated_domains = explode( ',', $alias_domains ); - foreach ( $comma_seprated_domains as $domain ) { - $trimmed_domain = trim( $domain ); - $this->site_data['alias_domains'] .= $trimmed_domain . ','; - } - } - $this->site_data['alias_domains'] = substr( $this->site_data['alias_domains'], 0, - 1 ); + $site_domains = ( 'subdom' === $this->site_data['app_sub_type'] ) ? [ $this->site_data['site_url'], '*.' . $this->site_data['site_url'] ] : [ $this->site_data['site_url'] ]; + $this->site_data['alias_domains'] = implode( ',', array_merge( $site_domains, $alias_domains ) ); $supported_php_versions = [ 5.6, 7.0, 7.2, 7.3, 7.4, 8.0, 8.1, 8.2, 8.3, 8.4, 8.5, 'latest' ]; if ( ! in_array( $this->site_data['php_version'], $supported_php_versions ) ) { From 225054de2f1a177d8d06441f719e60caa7a35625 Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 07:51:24 +0000 Subject: [PATCH 2/3] fix(site): reject invalid alias domain names on wp site create `ee site create --type=wp --alias-domains` accepted names like `../evil`, `a..b`, `a.com.` or `default`, which reach VIRTUAL_HOST and the per-domain proxy files. The alias domains are now checked with site-command's `validate_alias_domains()`, and the command exits with an error listing the invalid names before anything is created. --- src/WordPress.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/WordPress.php b/src/WordPress.php index d39b99e..b041d95 100644 --- a/src/WordPress.php +++ b/src/WordPress.php @@ -13,6 +13,7 @@ use function EE\Site\Utils\get_public_dir; use function EE\Site\Utils\check_alias_in_db; use function EE\Site\Utils\split_alias_domains; +use function EE\Site\Utils\validate_alias_domains; use function EE\Utils\get_flag_value; use function EE\Utils\trailingslashit; use function EE\Utils\get_value_if_flag_isset; @@ -297,6 +298,7 @@ public function create( $args, $assoc_args ) { } $alias_domains = split_alias_domains( \EE\Utils\get_flag_value( $assoc_args, 'alias-domains', '' ) ); + validate_alias_domains( $alias_domains ); $alias_domain_to_check = $alias_domains; $alias_domain_to_check[] = $this->site_data['site_url']; From 3610e15b1b79831428315dfd2a752f5c78bbdd77 Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 10:03:26 +0000 Subject: [PATCH 3/3] fix(site): reject a subdomain multisite whose wildcard is another site's alias A subdomain multisite also serves `*.`. Creating one when another site already had that alias succeeded, and both sites then owned the same `*.` host and proxy files. The create now fails with an error naming the site that has the alias. --- src/WordPress.php | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/src/WordPress.php b/src/WordPress.php index b041d95..ae2a8c5 100644 --- a/src/WordPress.php +++ b/src/WordPress.php @@ -12,6 +12,7 @@ use function EE\Site\Utils\get_site_info; use function EE\Site\Utils\get_public_dir; use function EE\Site\Utils\check_alias_in_db; +use function EE\Site\Utils\get_parent_of_alias; use function EE\Site\Utils\split_alias_domains; use function EE\Site\Utils\validate_alias_domains; use function EE\Utils\get_flag_value; @@ -304,6 +305,14 @@ public function create( $args, $assoc_args ) { $alias_domain_to_check[] = $this->site_data['site_url']; check_alias_in_db( $alias_domain_to_check ); + // A subdomain multisite also serves `*.`, which must not already belong to another site. + if ( 'subdom' === $this->site_data['app_sub_type'] ) { + $wildcard_parent = get_parent_of_alias( '*.' . $this->site_data['site_url'] ); + if ( ! empty( $wildcard_parent ) ) { + \EE::error( sprintf( 'Cannot create a subdomain multisite for %1$s: *.%1$s is already an alias domain of site %2$s. Please delete it from the alias domains of %2$s first.', $this->site_data['site_url'], $wildcard_parent ) ); + } + } + $this->site_data['site_fs_path'] = WEBROOT . $this->site_data['site_url']; $this->cache_type = \EE\Utils\get_flag_value( $assoc_args, 'cache' ); $wildcard_flag = \EE\Utils\get_flag_value( $assoc_args, 'wildcard' );