PluginProbe
bbPress / 2.6.19
bbPress v2.6.19
2.6.19 2.6.18 2.6.17 trunk 2.0 2.0-beta-1 2.0-beta-2b 2.0-beta-3 2.0-beta-3b 2.0-rc-2 2.0-rc-3 2.0-rc-4 2.0-rc-5 2.0.1 2.0.2 2.0.3 2.1 2.1-beta-1 2.1-rc1 2.1-rc2 2.1-rc3 2.1-rc4 2.1.1 2.1.2 2.1.3 All 74 releases
← All changes | includes/users/engagements.php +78 -32 2.6.18 → 2.6.19 View file →
@@ -55,9 +55,9 @@
55 55
56 56 /**
57 57 * Remove a user id from all objects
58 58 *
59 - * @since 2.6.0 bbPress (r6109)
59 + * @since 2.6.0 bbPress (r6517)
60 60 *
61 61 * @param int $user_id The user id
62 62 * @param string $rel_key The relationship key
63 63 * @param string $rel_type The relationship type (usually 'post')
@@ -74,9 +74,9 @@
74 74
75 75 /**
76 76 * Remove an object from all users
77 77 *
78 - * @since 2.6.0 bbPress (r6109)
78 + * @since 2.6.0 bbPress (r6544)
79 79 *
80 80 * @param int $object_id The object id
81 81 * @param int $user_id The user id
82 82 * @param string $rel_key The relationship key
@@ -94,9 +94,9 @@
94 94
95 95 /**
96 96 * Remove all users from all objects
97 97 *
98 - * @since 2.6.0 bbPress (r6109)
98 + * @since 2.6.0 bbPress (r6520)
99 99 *
100 100 * @param string $rel_key The relationship key
101 101 * @param string $rel_type The relationship type (usually 'post')
102 102 *
@@ -152,9 +152,9 @@
152 152
153 153 /**
154 154 * Get the query part responsible for JOINing objects to user IDs
155 155 *
156 - * @since 2.6.0 bbPress (r6747)
156 + * @since 2.6.0 bbPress (r6739)
157 157 *
158 158 * @param array $args Default query arguments
159 159 * @param string $context Additional context
160 160 * @param string $rel_key The relationship key
@@ -173,9 +173,9 @@
173 173
174 174 /**
175 175 * Get the users who have engaged in a topic
176 176 *
177 - * @since 2.6.0 bbPress (r6320)
177 + * @since 2.6.0 bbPress (r6311)
178 178 *
179 179 * @param int $topic_id Optional. Topic id
180 180 *
181 181 * @return array|bool Results if the topic has any engagements, otherwise false
@@ -193,9 +193,9 @@
193 193 *
194 194 * See: https://bbpress.trac.wordpress.org/ticket/3083
195 195 *
196 196 * @since 2.6.0 bbPress (r6522)
197 - * @since 2.6.17 Honor filtered public reply statuses.
197 + * @since 2.6.17 bbPress (r7468) Honor filtered public reply statuses.
198 198 *
199 199 * @param int $topic_id
200 200 *
201 201 * @return array
@@ -240,10 +240,10 @@
240 240
241 241 /**
242 242 * Get a user's topic engagements
243 243 *
244 - * @since 2.6.0 bbPress (r6320)
245 - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments
244 + * @since 2.6.0 bbPress (r6311)
245 + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments
246 246 *
247 247 * @param array $args Optional. Arguments to pass into bbp_has_replies()
248 248 *
249 249 * @return bool True if user has engaged, otherwise false
@@ -258,9 +258,9 @@
258 258
259 259 /**
260 260 * Check if a user is engaged in a topic or not
261 261 *
262 - * @since 2.6.0 bbPress (r6320)
262 + * @since 2.6.0 bbPress (r6311)
263 263 *
264 264 * @param int $user_id Optional. User id
265 265 * @param int $topic_id Optional. Topic id
266 266 *
@@ -282,9 +282,9 @@
282 282 * this function. Originally both were validated, but because this function is
283 283 * frequently used within a loop, those verifications were moved upstream to
284 284 * improve performance on topics with many engaged users.
285 285 *
286 - * @since 2.6.0 bbPress (r6320)
286 + * @since 2.6.0 bbPress (r6311)
287 287 *
288 288 * @param int $user_id Optional. User id
289 289 * @param int $topic_id Optional. Topic id
290 290 *
@@ -314,9 +314,9 @@
314 314
315 315 /**
316 316 * Remove a topic from user's engagements
317 317 *
318 - * @since 2.6.0 bbPress (r6320)
318 + * @since 2.6.0 bbPress (r6311)
319 319 *
320 320 * @param int $user_id Optional. User id
321 321 * @param int $topic_id Optional. Topic id
322 322 *
@@ -405,9 +405,9 @@
405 405 *
406 406 * Hooked to 'bbp_new_topic' and 'bbp_new_reply', this gets the post author and
407 407 * if not anonymous, passes it into bbp_add_user_engagement().
408 408 *
409 - * @since 2.6.0 bbPress (r6526)
409 + * @since 2.6.0 bbPress (r6529)
410 410 *
411 411 * @param int $topic_id
412 412 */
413 413 function bbp_update_topic_engagements( $topic_id = 0 ) {
@@ -447,14 +447,57 @@
447 447 // Return whether engagement was added
448 448 return bbp_add_user_engagement( $author_id, $topic_id );
449 449 }
450 450
451 +/** Engagement Toggles ********************************************************/
452 +
453 +/**
454 + * Check whether the current user can toggle a favorite or subscription.
455 + *
456 + * Only topics may be favorited. Topics and forums may be subscribed to, and
457 + * the user must be able to read both a topic and its containing forum when
458 + * adding an engagement. Existing engagements may be removed after visibility
459 + * changes.
460 + *
461 + * @since 2.6.19 bbPress (r7643)
462 + *
463 + * @param int $object_id Post ID.
464 + * @param string $object_type Metadata object type; only post is supported.
465 + * @param string $engagement Favorite or subscription.
466 + * @param string $action Add or remove.
467 + * @return bool Whether the current user can toggle the engagement.
468 + */
469 +function bbp_current_user_can_toggle_engagement( $object_id = 0, $object_type = 'post', $engagement = 'subscription', $action = 'add' ) {
470 + if ( ( 'post' !== $object_type ) || ! in_array( $action, array( 'add', 'remove' ), true ) ) {
471 + return false;
472 + }
473 +
474 + $post = get_post( $object_id );
475 +
476 + if ( empty( $post ) ) {
477 + return false;
478 + }
479 +
480 + if ( bbp_get_topic_post_type() === $post->post_type ) {
481 + $forum_id = bbp_get_topic_forum_id( $post->ID );
482 +
483 + return ! empty( $forum_id )
484 + && bbp_is_forum( $forum_id )
485 + && in_array( $engagement, array( 'favorite', 'subscription' ), true )
486 + && ( ( 'remove' === $action ) || ( current_user_can( 'read_topic', $post->ID ) && current_user_can( 'read_forum', $forum_id ) ) );
487 + }
488 +
489 + return ( 'subscription' === $engagement )
490 + && ( bbp_get_forum_post_type() === $post->post_type )
491 + && ( ( 'remove' === $action ) || current_user_can( 'read_forum', $post->ID ) );
492 +}
493 +
451 494 /** Favorites *****************************************************************/
452 495
453 496 /**
454 497 * Get the users who have made the topic favorite
455 498 *
456 - * @since 2.0.0 bbPress (r2658)
499 + * @since 2.0.0 bbPress (r2668)
457 500 *
458 501 * @param int $topic_id Optional. Topic id
459 502 *
460 503 * @return array|bool Results if the topic has any favoriters, otherwise false
@@ -470,9 +513,9 @@
470 513 /**
471 514 * Get a user's favorite topics
472 515 *
473 516 * @since 2.0.0 bbPress (r2652)
474 - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments
517 + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments
475 518 *
476 519 * @param array $args Optional. Arguments to pass into bbp_has_topics()
477 520 *
478 521 * @return array Array of topics if user has favorites, otherwise empty array
@@ -610,11 +653,12 @@
610 653
611 654 // What action is taking place?
612 655 $topic_id = bbp_get_topic_id( $_GET['object_id'] );
613 656 $user_id = bbp_get_user_id( 0, true, true );
657 + $toggle_action = ( 'bbp_favorite_remove' === $action ) ? 'remove' : 'add';
614 658
615 659 // Check for empty topic
616 - if ( empty( $topic_id ) ) {
660 + if ( empty( $topic_id ) || ! bbp_current_user_can_toggle_engagement( $topic_id, 'post', 'favorite', $toggle_action ) ) {
617 661 bbp_add_error( 'bbp_favorite_topic_id', __( '<strong>Error</strong>: No topic was found. Which topic are you marking/unmarking as favorite?', 'bbpress' ) );
618 662
619 663 // Check nonce
620 664 } elseif ( ! bbp_verify_nonce_request( 'toggle-favorite_' . $topic_id ) ) {
@@ -675,9 +719,9 @@
675 719
676 720 /**
677 721 * Get the users who have subscribed
678 722 *
679 - * @since 2.6.0 bbPress (r5156)
723 + * @since 2.6.0 bbPress (r6544)
680 724 *
681 725 * @param int $object_id Optional. ID of object (forum, topic, or something else)
682 726 */
683 727 function bbp_get_subscribers( $object_id = 0, $type = 'post' ) {
@@ -689,10 +733,10 @@
689 733
690 734 /**
691 735 * Get a user's subscribed topics
692 736 *
693 - * @since 2.0.0 bbPress (r2668)
694 - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments
737 + * @since 2.5.0 bbPress (r5156)
738 + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments
695 739 *
696 740 * @param array $args Optional. Arguments to pass into bbp_has_topics()
697 741 *
698 742 * @return array Array of topics if user has topic subscriptions, otherwise empty array
@@ -710,9 +754,9 @@
710 754 /**
711 755 * Get a user's subscribed forums
712 756 *
713 757 * @since 2.5.0 bbPress (r5156)
714 - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments
758 + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments
715 759 *
716 760 * @param array $args Optional. Arguments to pass into bbp_has_forums()
717 761 *
718 762 * @return array Array of forums if user has forum subscriptions, otherwise empty array
@@ -729,9 +773,9 @@
729 773
730 774 /**
731 775 * Check if an object (forum or topic) is in user's subscription list or not
732 776 *
733 - * @since 2.5.0 bbPress (r5156)
777 + * @since 2.0.0 bbPress (r2668)
734 778 *
735 779 * @param int $user_id Optional. User id
736 780 * @param int $object_id Optional. Object id
737 781 *
@@ -746,9 +790,9 @@
746 790
747 791 /**
748 792 * Add a user subscription
749 793 *
750 - * @since 2.5.0 bbPress (r5156)
794 + * @since 2.0.0 bbPress (r2668)
751 795 * @since 2.6.0 bbPress (r6544) Added $type parameter
752 796 *
753 797 * @param int $user_id Optional. User id
754 798 * @param int $object_id Optional. Object id
@@ -780,9 +824,9 @@
780 824
781 825 /**
782 826 * Remove a user subscription
783 827 *
784 - * @since 2.5.0 bbPress (r5156)
828 + * @since 2.0.0 bbPress (r2668)
785 829 * @since 2.6.0 bbPress (r6544) Added $type parameter
786 830 *
787 831 * @param int $user_id Optional. User id
788 832 * @param int $object_id Optional. Object id
@@ -814,10 +858,10 @@
814 858
815 859 /**
816 860 * Handles the front end toggling of user subscriptions
817 861 *
818 - * @since 2.0.0 bbPress (r2790)
819 - * @since 2.6.l bbPress (r6543)
862 + * @since 2.0.0 bbPress (r2668)
863 + * @since 2.6.0 bbPress (r6544)
820 864 *
821 865 * @param string $action The requested action to compare this function to
822 866 */
823 867 function bbp_subscriptions_handler( $action = '' ) {
@@ -848,18 +892,20 @@
848 892
849 893 // Get required data
850 894 $user_id = bbp_get_current_user_id();
851 895 $object_id = absint( $_GET['object_id'] );
852 - $object_type = ! empty( $_GET['object_type'] )
853 - ? sanitize_key( $_GET['object_type'] )
854 - : 'post';
896 + $object_type = 'post';
897 + if ( ! empty( $_GET['object_type'] ) ) {
898 + $object_type = is_string( $_GET['object_type'] ) ? sanitize_key( $_GET['object_type'] ) : '';
899 + }
900 + $toggle_action = ( 'bbp_unsubscribe' === $action ) ? 'remove' : 'add';
855 901
856 902 // Check for empty topic
857 - if ( empty( $object_id ) ) {
903 + if ( empty( $object_id ) || ! bbp_current_user_can_toggle_engagement( $object_id, $object_type, 'subscription', $toggle_action ) ) {
858 904 bbp_add_error( 'bbp_subscription_object_id', __( '<strong>Error</strong>: Not found. What are you subscribing/unsubscribing to?', 'bbpress' ) );
859 905
860 906 // Check nonce
861 - } elseif ( ! bbp_verify_nonce_request( 'toggle-subscription_' . $object_id ) ) {
907 + } elseif ( ! bbp_verify_nonce_request( 'toggle-subscription_post_' . $object_id ) && ! bbp_verify_nonce_request( 'toggle-subscription_' . $object_id ) ) {
862 908 bbp_add_error( 'bbp_subscription_object_id', __( '<strong>Error</strong>: Are you sure you wanted to do that?', 'bbpress' ) );
863 909
864 910 // Check current user's ability to edit the user
865 911 } elseif ( ! current_user_can( 'edit_user', $user_id ) ) {
@@ -929,9 +975,9 @@
929 975 * want to come up with a more efficient way to get IDs on your own. Nevertheless,
930 976 * it is available here for your convenience, using the most efficient query
931 977 * parameters available inside of the various query APIs.
932 978 *
933 - * @since 2.6.0 bbPress (r6606)
979 + * @since 2.6.0 bbPress (r6607)
934 980 *
935 981 * @param int $user_id The user id
936 982 * @param string $rel_key The relationship key
937 983 * @param string $rel_type The relationship type (usually 'post')
@@ -1021,9 +1067,9 @@
1021 1067
1022 1068 /**
1023 1069 * Get a user's engaged topic ids
1024 1070 *
1025 - * @since 2.6.0 bbPress (r6320)
1071 + * @since 2.6.0 bbPress (r6311)
1026 1072 *
1027 1073 * @param int $user_id Optional. User id
1028 1074 *
1029 1075 * @return array Return array of topic ids, or empty array
@@ -1230,9 +1276,9 @@
1230 1276 * this function. Originally both were validated, but because this function is
1231 1277 * frequently used within a loop, those verifications were moved upstream to
1232 1278 * improve performance on topics with many engaged users.
1233 1279 *
1234 - * @since 2.0.0 bbPress (r2668)
1280 + * @since 2.5.0 bbPress (r5156)
1235 1281 * @deprecated 2.6.0 bbPress (r6543)
1236 1282 *
1237 1283 * @param int $user_id Optional. User id
1238 1284 * @param int $topic_id Optional. Topic id