Skip to content

api: throw when the JSON request body cannot be encoded - #857

Merged
dannyvankooten merged 1 commit into
ibericode:mainfrom
robertstaddon:fix/json-request-body-fatal
Sep 24, 2026
Merged

dannyvankooten merged 1 commit into
ibericode:mainfrom
robertstaddon:fix/json-request-body-fatal

Conversation

@robertstaddon

Copy link
Copy Markdown
Contributor

Fixes #856

Summary

MC4WP_API_V3_Client::request() set the HTTP body to the raw return value of json_encode(). When the subscribe payload cannot be encoded, that return value is boolean false. wp_remote_request() passes it to WpOrg\Requests\Transport\Curl::request(), which requires array|string and throws WpOrg\Requests\Exception\InvalidArgument.

That exception is not an MC4WP_API_Exception, so list_subscribe() does not catch it and the form POST fatals during init. No other plugin is required. mc4wp_sanitize_deep() keeps invalid UTF-8, and its substr($value, 0, 1024) cut can split a multibyte character. Either value reaches this method on a stock install.

This encodes POST, PUT, and PATCH bodies with wp_json_encode(), which repairs invalid UTF-8 before encoding. If the result is still not a string, it throws MC4WP_API_Exception and does not call wp_remote_request(). After mc4wp_http_request_args, a body that is neither a string nor an array throws the same exception. list_subscribe() already turns that into a form error.

Test plan

  • Submit a published form with a valid email and invalid UTF-8 in a text field (for example the bytes C3 28), with the honeypot empty and a normal User-Agent. The page should show the form error instead of a fatal.
  • Submit the same form with a normal name. The subscriber should still be sent to Mailchimp.
  • Confirm a mc4wp_http_request_args callback that leaves body as a JSON string still sends the request.

Made with Cursor

Passing json_encode()'s false return value to wp_remote_request() fatals the signup request.

Co-authored-by: Cursor <cursoragent@cursor.com>
@dannyvankooten
dannyvankooten merged commit 7b3b877 into ibericode:main Sep 24, 2026
8 checks passed
@dannyvankooten

Copy link
Copy Markdown
Member

Great catch, Thanks for the PR @robertstaddon!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Subscribe request fatals when the JSON body cannot be encoded

2 participants