| @@ -7,10 +7,12 @@ | ||
| 7 | 7 | } |
| 8 | 8 | |
| 9 | 9 | use ABlocks\Classes\AbstractAjaxHandler; |
| 10 | 10 | use ABlocks\Classes\Sanitizer; |
| 11 | +use ABlocks\Classes\Breakpoints; | |
| 11 | 12 | use ABlocks\Helper; |
| 12 | 13 | use ABlocks\Admin\Settings\Base as BaseSettings; |
| 14 | +use ABlocks\Permissions\SettingsGuard; | |
| 13 | 15 | |
| 14 | 16 | class Settings extends AbstractAjaxHandler { |
| 15 | 17 | public function __construct() { |
| 16 | 18 | $this->actions = array( |
| @@ -15,13 +17,13 @@ | ||
| 15 | 17 | public function __construct() { |
| 16 | 18 | $this->actions = array( |
| 17 | 19 | 'get_blocks_visibility' => array( |
| 18 | 20 | 'callback' => array( $this, 'get_blocks_visibility' ), |
| 19 | - 'capability' => 'manage_options' | |
| 21 | + 'capability' => 'ablocks_manage_settings' | |
| 20 | 22 | ), |
| 21 | 23 | 'save_block_visibility' => array( |
| 22 | 24 | 'callback' => array( $this, 'save_block_visibility' ), |
| 23 | - 'capability' => 'manage_options', | |
| 25 | + 'capability' => 'ablocks_manage_settings', | |
| 24 | 26 | 'fields' => array( |
| 25 | 27 | 'block_name' => 'string', |
| 26 | 28 | 'status' => 'boolean', |
| 27 | 29 | ) |
| @@ -27,9 +29,9 @@ | ||
| 27 | 29 | ) |
| 28 | 30 | ), |
| 29 | 31 | 'save_bulk_block_visibility' => array( |
| 30 | 32 | 'callback' => array( $this, 'save_bulk_block_visibility' ), |
| 31 | - 'capability' => 'manage_options', | |
| 33 | + 'capability' => 'ablocks_manage_settings', | |
| 32 | 34 | 'fields' => array( |
| 33 | 35 | 'blocks' => 'json', |
| 34 | 36 | ) |
| 35 | 37 | ), |
| @@ -34,13 +36,13 @@ | ||
| 34 | 36 | ) |
| 35 | 37 | ), |
| 36 | 38 | 'get_settings' => array( |
| 37 | 39 | 'callback' => array( $this, 'get_settings' ), |
| 38 | - 'capability' => 'manage_options', | |
| 40 | + 'capability' => 'ablocks_access', | |
| 39 | 41 | ), |
| 40 | 42 | 'save_settings' => array( |
| 41 | 43 | 'callback' => array( $this, 'save_settings' ), |
| 42 | - 'capability' => 'manage_options', | |
| 44 | + 'capability' => 'ablocks_save_settings', | |
| 43 | 45 | 'fields' => array( |
| 44 | 46 | 'default_container_width' => 'integer', |
| 45 | 47 | 'container_padding' => 'integer', |
| 46 | 48 | 'container_element_gap' => 'integer', |
| @@ -83,8 +85,17 @@ | ||
| 83 | 85 | 'perf_disable_dashicons' => 'boolean', |
| 84 | 86 | 'perf_disable_jquery_migrate' => 'boolean', |
| 85 | 87 | 'perf_control_heartbeat' => 'boolean', |
| 86 | 88 | 'perf_heartbeat_frequency' => 'integer', |
| 89 | + // Editor paste | |
| 90 | + 'paste_google_docs' => 'boolean', | |
| 91 | + 'paste_convert_webp' => 'boolean', | |
| 92 | + 'paste_webp_quality' => 'integer', | |
| 93 | + // Responsive breakpoints | |
| 94 | + 'breakpoint_tablet' => 'integer', | |
| 95 | + 'breakpoint_mobile' => 'integer', | |
| 96 | + 'breakpoint_mode' => 'string', | |
| 97 | + 'breakpoint_custom' => 'json', | |
| 87 | 98 | // Performance Suite — full-page cache. |
| 88 | 99 | 'perf_page_cache' => 'boolean', |
| 89 | 100 | 'perf_page_cache_scope' => 'string', |
| 90 | 101 | 'perf_page_cache_ttl' => 'integer', |
| @@ -140,9 +151,9 @@ | ||
| 140 | 151 | ) |
| 141 | 152 | ), |
| 142 | 153 | 'fetch_posts' => array( |
| 143 | 154 | 'callback' => array( $this, 'fetch_posts' ), |
| 144 | - 'capability' => 'manage_options', | |
| 155 | + 'capability' => 'ablocks_access', | |
| 145 | 156 | 'fields' => array( |
| 146 | 157 | 'postId' => 'integer', |
| 147 | 158 | 'postType' => 'string', |
| 148 | 159 | 'keyword' => 'string', |
| @@ -149,13 +160,13 @@ | ||
| 149 | 160 | ) |
| 150 | 161 | ), |
| 151 | 162 | 'get_fronted_dashboard_pages' => array( |
| 152 | 163 | 'callback' => array( $this, 'get_fronted_dashboard_pages' ), |
| 153 | - 'capability' => 'manage_options', | |
| 164 | + 'capability' => 'ablocks_manage_settings', | |
| 154 | 165 | ), |
| 155 | 166 | 'create_fronted_dashboard_page' => array( |
| 156 | 167 | 'callback' => array( $this, 'create_fronted_dashboard_page' ), |
| 157 | - 'capability' => 'manage_options', | |
| 168 | + 'capability' => 'ablocks_manage_settings', | |
| 158 | 169 | 'fields' => [ |
| 159 | 170 | 'label' => 'string', |
| 160 | 171 | 'slug' => 'string', |
| 161 | 172 | 'icon' => 'string', |
| @@ -165,9 +176,9 @@ | ||
| 165 | 176 | ] |
| 166 | 177 | ), |
| 167 | 178 | 'create_fronted_dashboard_link' => array( |
| 168 | 179 | 'callback' => array( $this, 'create_fronted_dashboard_link' ), |
| 169 | - 'capability' => 'manage_options', | |
| 180 | + 'capability' => 'ablocks_manage_settings', | |
| 170 | 181 | 'fields' => [ |
| 171 | 182 | 'label' => 'string', |
| 172 | 183 | 'link' => 'string', |
| 173 | 184 | 'icon' => 'string', |
| @@ -177,9 +188,9 @@ | ||
| 177 | 188 | ] |
| 178 | 189 | ), |
| 179 | 190 | 'edit_fronted_dashboard_link' => array( |
| 180 | 191 | 'callback' => array( $this, 'edit_fronted_dashboard_link' ), |
| 181 | - 'capability' => 'manage_options', | |
| 192 | + 'capability' => 'ablocks_manage_settings', | |
| 182 | 193 | 'fields' => [ |
| 183 | 194 | 'label' => 'string', |
| 184 | 195 | 'link' => 'string', |
| 185 | 196 | 'icon' => 'string', |
| @@ -189,9 +200,9 @@ | ||
| 189 | 200 | ] |
| 190 | 201 | ), |
| 191 | 202 | 'delete_fronted_dashboard_link' => array( |
| 192 | 203 | 'callback' => array( $this, 'delete_fronted_dashboard_link' ), |
| 193 | - 'capability' => 'manage_options', | |
| 204 | + 'capability' => 'ablocks_manage_settings', | |
| 194 | 205 | 'fields' => array( |
| 195 | 206 | 'page_id' => 'string', |
| 196 | 207 | ) |
| 197 | 208 | ), |
| @@ -196,9 +207,9 @@ | ||
| 196 | 207 | ) |
| 197 | 208 | ), |
| 198 | 209 | 'edit_fronted_dashboard_page' => array( |
| 199 | 210 | 'callback' => array( $this, 'edit_fronted_dashboard_page' ), |
| 200 | - 'capability' => 'manage_options', | |
| 211 | + 'capability' => 'ablocks_manage_settings', | |
| 201 | 212 | 'fields' => [ |
| 202 | 213 | 'label' => 'string', |
| 203 | 214 | 'slug' => 'string', |
| 204 | 215 | 'icon' => 'string', |
| @@ -209,9 +220,9 @@ | ||
| 209 | 220 | ] |
| 210 | 221 | ), |
| 211 | 222 | 'move_fronted_dashboard_page' => array( |
| 212 | 223 | 'callback' => array( $this, 'move_fronted_dashboard_page' ), |
| 213 | - 'capability' => 'manage_options', | |
| 224 | + 'capability' => 'ablocks_manage_settings', | |
| 214 | 225 | 'fields' => [ |
| 215 | 226 | 'reordered_items' => 'string', |
| 216 | 227 | ] |
| 217 | 228 | ), |
| @@ -216,9 +227,9 @@ | ||
| 216 | 227 | ] |
| 217 | 228 | ), |
| 218 | 229 | 'delete_fronted_dashboard_page' => array( |
| 219 | 230 | 'callback' => array( $this, 'delete_fronted_dashboard_page' ), |
| 220 | - 'capability' => 'manage_options', | |
| 231 | + 'capability' => 'ablocks_manage_settings', | |
| 221 | 232 | 'fields' => array( |
| 222 | 233 | 'slug' => 'string', |
| 223 | 234 | 'page_id' => 'integer', |
| 224 | 235 | ) |
| @@ -280,8 +291,14 @@ | ||
| 280 | 291 | wp_send_json_success( $settings ); |
| 281 | 292 | } |
| 282 | 293 | |
| 283 | 294 | public function save_settings( $payload ) { |
| 295 | + // The design system, the performance suite and site configuration are | |
| 296 | + // three separate permissions but one endpoint. Keys this user may not | |
| 297 | + // change are rewritten back to what is already saved, so the save | |
| 298 | + // succeeds and simply leaves them alone. | |
| 299 | + $payload = SettingsGuard::filter_payload( $payload ); | |
| 300 | + | |
| 284 | 301 | // phpcs:ignore WordPress.Security.NonceVerification.Missing |
| 285 | 302 | do_action( 'ablocks/before_save_settings', $payload, 'base' ); |
| 286 | 303 | $json_payload = Sanitizer::sanitize_payload([ |
| 287 | 304 | 'selected_fonts' => 'json', |
| @@ -298,12 +315,33 @@ | ||
| 298 | 315 | 'global_h3_typography' => 'json', |
| 299 | 316 | 'global_h4_typography' => 'json', |
| 300 | 317 | 'global_h5_typography' => 'json', |
| 301 | 318 | 'global_h6_typography' => 'json', |
| 319 | + 'breakpoint_custom' => 'json', | |
| 302 | 320 | ], $_POST ); // phpcs:ignore WordPress.Security.NonceVerification.Missing |
| 303 | 321 | |
| 322 | + // The JSON fields are read straight from $_POST rather than the sanitized | |
| 323 | + // payload, so they need the same guard — the global colour and typography | |
| 324 | + // presets live in here, and they are the design system. | |
| 325 | + $json_payload = SettingsGuard::filter_payload( $json_payload ); | |
| 326 | + | |
| 327 | + // Breakpoints are only written when the request carries them, so a save | |
| 328 | + // that omits them keeps the stored list rather than resetting it. | |
| 329 | + $breakpoints = []; | |
| 330 | + foreach ( [ 'breakpoint_tablet', 'breakpoint_mobile' ] as $key ) { | |
| 331 | + if ( isset( $payload[ $key ] ) && $payload[ $key ] > 0 ) { | |
| 332 | + $breakpoints[ $key ] = $payload[ $key ]; | |
| 333 | + } | |
| 334 | + } | |
| 335 | + if ( isset( $payload['breakpoint_mode'] ) ) { | |
| 336 | + $breakpoints['breakpoint_mode'] = 'strict' === $payload['breakpoint_mode'] ? 'strict' : 'cascade'; | |
| 337 | + } | |
| 338 | + if ( isset( $json_payload['breakpoint_custom'] ) && is_array( $json_payload['breakpoint_custom'] ) ) { | |
| 339 | + $breakpoints['breakpoint_custom'] = Breakpoints::sanitize( $json_payload['breakpoint_custom'] ); | |
| 340 | + } | |
| 341 | + | |
| 304 | 342 | $default = BaseSettings::get_default_data(); |
| 305 | - $is_update = BaseSettings::save_settings( [ | |
| 343 | + $is_update = BaseSettings::save_settings( $breakpoints + [ | |
| 306 | 344 | 'default_container_width' => $payload['default_container_width'] ?? $default['default_container_width'], |
| 307 | 345 | 'container_padding' => $payload['container_padding'] ?? $default['container_padding'], |
| 308 | 346 | 'container_element_gap' => $payload['container_element_gap'] ?? $default['container_element_gap'], |
| 309 | 347 | 'enabled_assets_file_generation' => $payload['enabled_assets_file_generation'] ?? $default['enabled_assets_file_generation'], |
| @@ -333,8 +371,12 @@ | ||
| 333 | 371 | 'perf_inline_css' => $payload['perf_inline_css'] ?? $default['perf_inline_css'], |
| 334 | 372 | 'perf_async_css' => $payload['perf_async_css'] ?? $default['perf_async_css'], |
| 335 | 373 | 'perf_critical_css' => $payload['perf_critical_css'] ?? $default['perf_critical_css'], |
| 336 | 374 | 'perf_defer_js' => $payload['perf_defer_js'] ?? $default['perf_defer_js'], |
| 375 | + // Editor paste. | |
| 376 | + 'paste_google_docs' => $payload['paste_google_docs'] ?? $default['paste_google_docs'], | |
| 377 | + 'paste_convert_webp' => $payload['paste_convert_webp'] ?? $default['paste_convert_webp'], | |
| 378 | + 'paste_webp_quality' => $payload['paste_webp_quality'] ?? $default['paste_webp_quality'], | |
| 337 | 379 | // Performance Suite — full-page cache. |
| 338 | 380 | 'perf_page_cache' => $payload['perf_page_cache'] ?? $default['perf_page_cache'], |
| 339 | 381 | 'perf_page_cache_scope' => $payload['perf_page_cache_scope'] ?? $default['perf_page_cache_scope'], |
| 340 | 382 | 'perf_page_cache_ttl' => $payload['perf_page_cache_ttl'] ?? $default['perf_page_cache_ttl'], |
| @@ -426,9 +468,10 @@ | ||
| 426 | 468 | ); |
| 427 | 469 | if ( ! empty( $keyword ) ) { |
| 428 | 470 | $args['s'] = $keyword; |
| 429 | 471 | } |
| 430 | - if ( ! current_user_can( 'manage_options' ) ) { | |
| 472 | + // Anyone who cannot edit other people's posts only picks from their own. | |
| 473 | + if ( ! current_user_can( 'edit_others_posts' ) ) { | |
| 431 | 474 | $args['author'] = get_current_user_id(); |
| 432 | 475 | } |
| 433 | 476 | } |
| 434 | 477 | $results = array(); |