wp-includes/http.php:480Determines if the HTTP origin is an authorized one.
$originstring|nulloptionalnullstringOne hook fires while is_allowed_http_origin() runs, in this order:
Changes the allowed HTTP origin result.
function is_allowed_http_origin( $origin = null ) { $origin_arg = $origin; if ( null === $origin ) { $origin = get_http_origin(); } if ( $origin && ! in_array( $origin, get_allowed_http_origins(), true ) ) { $origin = ''; } /** * Changes the allowed HTTP origin result. * * @since 3.4.0 * * @param string $origin Origin URL if allowed, empty string if not. * @param string $origin_arg Original origin string passed into is_allowed_http_origin function. */ return apply_filters( 'allowed_http_origin', $origin, $origin_arg );}Introduced in 3.4.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
src/wp-includes/http.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.