| @@ -55,9 +55,9 @@ | ||
| 55 | 55 | |
| 56 | 56 | /** |
| 57 | 57 | * Remove a user id from all objects |
| 58 | 58 | * |
| 59 | - * @since 2.6.0 bbPress (r6109) | |
| 59 | + * @since 2.6.0 bbPress (r6517) | |
| 60 | 60 | * |
| 61 | 61 | * @param int $user_id The user id |
| 62 | 62 | * @param string $rel_key The relationship key |
| 63 | 63 | * @param string $rel_type The relationship type (usually 'post') |
| @@ -74,9 +74,9 @@ | ||
| 74 | 74 | |
| 75 | 75 | /** |
| 76 | 76 | * Remove an object from all users |
| 77 | 77 | * |
| 78 | - * @since 2.6.0 bbPress (r6109) | |
| 78 | + * @since 2.6.0 bbPress (r6544) | |
| 79 | 79 | * |
| 80 | 80 | * @param int $object_id The object id |
| 81 | 81 | * @param int $user_id The user id |
| 82 | 82 | * @param string $rel_key The relationship key |
| @@ -94,9 +94,9 @@ | ||
| 94 | 94 | |
| 95 | 95 | /** |
| 96 | 96 | * Remove all users from all objects |
| 97 | 97 | * |
| 98 | - * @since 2.6.0 bbPress (r6109) | |
| 98 | + * @since 2.6.0 bbPress (r6520) | |
| 99 | 99 | * |
| 100 | 100 | * @param string $rel_key The relationship key |
| 101 | 101 | * @param string $rel_type The relationship type (usually 'post') |
| 102 | 102 | * |
| @@ -152,9 +152,9 @@ | ||
| 152 | 152 | |
| 153 | 153 | /** |
| 154 | 154 | * Get the query part responsible for JOINing objects to user IDs |
| 155 | 155 | * |
| 156 | - * @since 2.6.0 bbPress (r6747) | |
| 156 | + * @since 2.6.0 bbPress (r6739) | |
| 157 | 157 | * |
| 158 | 158 | * @param array $args Default query arguments |
| 159 | 159 | * @param string $context Additional context |
| 160 | 160 | * @param string $rel_key The relationship key |
| @@ -173,9 +173,9 @@ | ||
| 173 | 173 | |
| 174 | 174 | /** |
| 175 | 175 | * Get the users who have engaged in a topic |
| 176 | 176 | * |
| 177 | - * @since 2.6.0 bbPress (r6320) | |
| 177 | + * @since 2.6.0 bbPress (r6311) | |
| 178 | 178 | * |
| 179 | 179 | * @param int $topic_id Optional. Topic id |
| 180 | 180 | * |
| 181 | 181 | * @return array|bool Results if the topic has any engagements, otherwise false |
| @@ -193,9 +193,9 @@ | ||
| 193 | 193 | * |
| 194 | 194 | * See: https://bbpress.trac.wordpress.org/ticket/3083 |
| 195 | 195 | * |
| 196 | 196 | * @since 2.6.0 bbPress (r6522) |
| 197 | - * @since 2.6.17 Honor filtered public reply statuses. | |
| 197 | + * @since 2.6.17 bbPress (r7468) Honor filtered public reply statuses. | |
| 198 | 198 | * |
| 199 | 199 | * @param int $topic_id |
| 200 | 200 | * |
| 201 | 201 | * @return array |
| @@ -240,10 +240,10 @@ | ||
| 240 | 240 | |
| 241 | 241 | /** |
| 242 | 242 | * Get a user's topic engagements |
| 243 | 243 | * |
| 244 | - * @since 2.6.0 bbPress (r6320) | |
| 245 | - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments | |
| 244 | + * @since 2.6.0 bbPress (r6311) | |
| 245 | + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments | |
| 246 | 246 | * |
| 247 | 247 | * @param array $args Optional. Arguments to pass into bbp_has_replies() |
| 248 | 248 | * |
| 249 | 249 | * @return bool True if user has engaged, otherwise false |
| @@ -258,9 +258,9 @@ | ||
| 258 | 258 | |
| 259 | 259 | /** |
| 260 | 260 | * Check if a user is engaged in a topic or not |
| 261 | 261 | * |
| 262 | - * @since 2.6.0 bbPress (r6320) | |
| 262 | + * @since 2.6.0 bbPress (r6311) | |
| 263 | 263 | * |
| 264 | 264 | * @param int $user_id Optional. User id |
| 265 | 265 | * @param int $topic_id Optional. Topic id |
| 266 | 266 | * |
| @@ -282,9 +282,9 @@ | ||
| 282 | 282 | * this function. Originally both were validated, but because this function is |
| 283 | 283 | * frequently used within a loop, those verifications were moved upstream to |
| 284 | 284 | * improve performance on topics with many engaged users. |
| 285 | 285 | * |
| 286 | - * @since 2.6.0 bbPress (r6320) | |
| 286 | + * @since 2.6.0 bbPress (r6311) | |
| 287 | 287 | * |
| 288 | 288 | * @param int $user_id Optional. User id |
| 289 | 289 | * @param int $topic_id Optional. Topic id |
| 290 | 290 | * |
| @@ -314,9 +314,9 @@ | ||
| 314 | 314 | |
| 315 | 315 | /** |
| 316 | 316 | * Remove a topic from user's engagements |
| 317 | 317 | * |
| 318 | - * @since 2.6.0 bbPress (r6320) | |
| 318 | + * @since 2.6.0 bbPress (r6311) | |
| 319 | 319 | * |
| 320 | 320 | * @param int $user_id Optional. User id |
| 321 | 321 | * @param int $topic_id Optional. Topic id |
| 322 | 322 | * |
| @@ -405,9 +405,9 @@ | ||
| 405 | 405 | * |
| 406 | 406 | * Hooked to 'bbp_new_topic' and 'bbp_new_reply', this gets the post author and |
| 407 | 407 | * if not anonymous, passes it into bbp_add_user_engagement(). |
| 408 | 408 | * |
| 409 | - * @since 2.6.0 bbPress (r6526) | |
| 409 | + * @since 2.6.0 bbPress (r6529) | |
| 410 | 410 | * |
| 411 | 411 | * @param int $topic_id |
| 412 | 412 | */ |
| 413 | 413 | function bbp_update_topic_engagements( $topic_id = 0 ) { |
| @@ -447,14 +447,57 @@ | ||
| 447 | 447 | // Return whether engagement was added |
| 448 | 448 | return bbp_add_user_engagement( $author_id, $topic_id ); |
| 449 | 449 | } |
| 450 | 450 | |
| 451 | +/** Engagement Toggles ********************************************************/ | |
| 452 | + | |
| 453 | +/** | |
| 454 | + * Check whether the current user can toggle a favorite or subscription. | |
| 455 | + * | |
| 456 | + * Only topics may be favorited. Topics and forums may be subscribed to, and | |
| 457 | + * the user must be able to read both a topic and its containing forum when | |
| 458 | + * adding an engagement. Existing engagements may be removed after visibility | |
| 459 | + * changes. | |
| 460 | + * | |
| 461 | + * @since 2.6.19 bbPress (r7643) | |
| 462 | + * | |
| 463 | + * @param int $object_id Post ID. | |
| 464 | + * @param string $object_type Metadata object type; only post is supported. | |
| 465 | + * @param string $engagement Favorite or subscription. | |
| 466 | + * @param string $action Add or remove. | |
| 467 | + * @return bool Whether the current user can toggle the engagement. | |
| 468 | + */ | |
| 469 | +function bbp_current_user_can_toggle_engagement( $object_id = 0, $object_type = 'post', $engagement = 'subscription', $action = 'add' ) { | |
| 470 | + if ( ( 'post' !== $object_type ) || ! in_array( $action, array( 'add', 'remove' ), true ) ) { | |
| 471 | + return false; | |
| 472 | + } | |
| 473 | + | |
| 474 | + $post = get_post( $object_id ); | |
| 475 | + | |
| 476 | + if ( empty( $post ) ) { | |
| 477 | + return false; | |
| 478 | + } | |
| 479 | + | |
| 480 | + if ( bbp_get_topic_post_type() === $post->post_type ) { | |
| 481 | + $forum_id = bbp_get_topic_forum_id( $post->ID ); | |
| 482 | + | |
| 483 | + return ! empty( $forum_id ) | |
| 484 | + && bbp_is_forum( $forum_id ) | |
| 485 | + && in_array( $engagement, array( 'favorite', 'subscription' ), true ) | |
| 486 | + && ( ( 'remove' === $action ) || ( current_user_can( 'read_topic', $post->ID ) && current_user_can( 'read_forum', $forum_id ) ) ); | |
| 487 | + } | |
| 488 | + | |
| 489 | + return ( 'subscription' === $engagement ) | |
| 490 | + && ( bbp_get_forum_post_type() === $post->post_type ) | |
| 491 | + && ( ( 'remove' === $action ) || current_user_can( 'read_forum', $post->ID ) ); | |
| 492 | +} | |
| 493 | + | |
| 451 | 494 | /** Favorites *****************************************************************/ |
| 452 | 495 | |
| 453 | 496 | /** |
| 454 | 497 | * Get the users who have made the topic favorite |
| 455 | 498 | * |
| 456 | - * @since 2.0.0 bbPress (r2658) | |
| 499 | + * @since 2.0.0 bbPress (r2668) | |
| 457 | 500 | * |
| 458 | 501 | * @param int $topic_id Optional. Topic id |
| 459 | 502 | * |
| 460 | 503 | * @return array|bool Results if the topic has any favoriters, otherwise false |
| @@ -470,9 +513,9 @@ | ||
| 470 | 513 | /** |
| 471 | 514 | * Get a user's favorite topics |
| 472 | 515 | * |
| 473 | 516 | * @since 2.0.0 bbPress (r2652) |
| 474 | - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments | |
| 517 | + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments | |
| 475 | 518 | * |
| 476 | 519 | * @param array $args Optional. Arguments to pass into bbp_has_topics() |
| 477 | 520 | * |
| 478 | 521 | * @return array Array of topics if user has favorites, otherwise empty array |
| @@ -610,11 +653,12 @@ | ||
| 610 | 653 | |
| 611 | 654 | // What action is taking place? |
| 612 | 655 | $topic_id = bbp_get_topic_id( $_GET['object_id'] ); |
| 613 | 656 | $user_id = bbp_get_user_id( 0, true, true ); |
| 657 | + $toggle_action = ( 'bbp_favorite_remove' === $action ) ? 'remove' : 'add'; | |
| 614 | 658 | |
| 615 | 659 | // Check for empty topic |
| 616 | - if ( empty( $topic_id ) ) { | |
| 660 | + if ( empty( $topic_id ) || ! bbp_current_user_can_toggle_engagement( $topic_id, 'post', 'favorite', $toggle_action ) ) { | |
| 617 | 661 | bbp_add_error( 'bbp_favorite_topic_id', __( '<strong>Error</strong>: No topic was found. Which topic are you marking/unmarking as favorite?', 'bbpress' ) ); |
| 618 | 662 | |
| 619 | 663 | // Check nonce |
| 620 | 664 | } elseif ( ! bbp_verify_nonce_request( 'toggle-favorite_' . $topic_id ) ) { |
| @@ -675,9 +719,9 @@ | ||
| 675 | 719 | |
| 676 | 720 | /** |
| 677 | 721 | * Get the users who have subscribed |
| 678 | 722 | * |
| 679 | - * @since 2.6.0 bbPress (r5156) | |
| 723 | + * @since 2.6.0 bbPress (r6544) | |
| 680 | 724 | * |
| 681 | 725 | * @param int $object_id Optional. ID of object (forum, topic, or something else) |
| 682 | 726 | */ |
| 683 | 727 | function bbp_get_subscribers( $object_id = 0, $type = 'post' ) { |
| @@ -689,10 +733,10 @@ | ||
| 689 | 733 | |
| 690 | 734 | /** |
| 691 | 735 | * Get a user's subscribed topics |
| 692 | 736 | * |
| 693 | - * @since 2.0.0 bbPress (r2668) | |
| 694 | - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments | |
| 737 | + * @since 2.5.0 bbPress (r5156) | |
| 738 | + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments | |
| 695 | 739 | * |
| 696 | 740 | * @param array $args Optional. Arguments to pass into bbp_has_topics() |
| 697 | 741 | * |
| 698 | 742 | * @return array Array of topics if user has topic subscriptions, otherwise empty array |
| @@ -710,9 +754,9 @@ | ||
| 710 | 754 | /** |
| 711 | 755 | * Get a user's subscribed forums |
| 712 | 756 | * |
| 713 | 757 | * @since 2.5.0 bbPress (r5156) |
| 714 | - * @since 2.6.0 bbPress (r6618) Signature changed to accept an array of arguments | |
| 758 | + * @since 2.6.0 bbPress (r6619) Signature changed to accept an array of arguments | |
| 715 | 759 | * |
| 716 | 760 | * @param array $args Optional. Arguments to pass into bbp_has_forums() |
| 717 | 761 | * |
| 718 | 762 | * @return array Array of forums if user has forum subscriptions, otherwise empty array |
| @@ -729,9 +773,9 @@ | ||
| 729 | 773 | |
| 730 | 774 | /** |
| 731 | 775 | * Check if an object (forum or topic) is in user's subscription list or not |
| 732 | 776 | * |
| 733 | - * @since 2.5.0 bbPress (r5156) | |
| 777 | + * @since 2.0.0 bbPress (r2668) | |
| 734 | 778 | * |
| 735 | 779 | * @param int $user_id Optional. User id |
| 736 | 780 | * @param int $object_id Optional. Object id |
| 737 | 781 | * |
| @@ -746,9 +790,9 @@ | ||
| 746 | 790 | |
| 747 | 791 | /** |
| 748 | 792 | * Add a user subscription |
| 749 | 793 | * |
| 750 | - * @since 2.5.0 bbPress (r5156) | |
| 794 | + * @since 2.0.0 bbPress (r2668) | |
| 751 | 795 | * @since 2.6.0 bbPress (r6544) Added $type parameter |
| 752 | 796 | * |
| 753 | 797 | * @param int $user_id Optional. User id |
| 754 | 798 | * @param int $object_id Optional. Object id |
| @@ -780,9 +824,9 @@ | ||
| 780 | 824 | |
| 781 | 825 | /** |
| 782 | 826 | * Remove a user subscription |
| 783 | 827 | * |
| 784 | - * @since 2.5.0 bbPress (r5156) | |
| 828 | + * @since 2.0.0 bbPress (r2668) | |
| 785 | 829 | * @since 2.6.0 bbPress (r6544) Added $type parameter |
| 786 | 830 | * |
| 787 | 831 | * @param int $user_id Optional. User id |
| 788 | 832 | * @param int $object_id Optional. Object id |
| @@ -814,10 +858,10 @@ | ||
| 814 | 858 | |
| 815 | 859 | /** |
| 816 | 860 | * Handles the front end toggling of user subscriptions |
| 817 | 861 | * |
| 818 | - * @since 2.0.0 bbPress (r2790) | |
| 819 | - * @since 2.6.l bbPress (r6543) | |
| 862 | + * @since 2.0.0 bbPress (r2668) | |
| 863 | + * @since 2.6.0 bbPress (r6544) | |
| 820 | 864 | * |
| 821 | 865 | * @param string $action The requested action to compare this function to |
| 822 | 866 | */ |
| 823 | 867 | function bbp_subscriptions_handler( $action = '' ) { |
| @@ -848,18 +892,20 @@ | ||
| 848 | 892 | |
| 849 | 893 | // Get required data |
| 850 | 894 | $user_id = bbp_get_current_user_id(); |
| 851 | 895 | $object_id = absint( $_GET['object_id'] ); |
| 852 | - $object_type = ! empty( $_GET['object_type'] ) | |
| 853 | - ? sanitize_key( $_GET['object_type'] ) | |
| 854 | - : 'post'; | |
| 896 | + $object_type = 'post'; | |
| 897 | + if ( ! empty( $_GET['object_type'] ) ) { | |
| 898 | + $object_type = is_string( $_GET['object_type'] ) ? sanitize_key( $_GET['object_type'] ) : ''; | |
| 899 | + } | |
| 900 | + $toggle_action = ( 'bbp_unsubscribe' === $action ) ? 'remove' : 'add'; | |
| 855 | 901 | |
| 856 | 902 | // Check for empty topic |
| 857 | - if ( empty( $object_id ) ) { | |
| 903 | + if ( empty( $object_id ) || ! bbp_current_user_can_toggle_engagement( $object_id, $object_type, 'subscription', $toggle_action ) ) { | |
| 858 | 904 | bbp_add_error( 'bbp_subscription_object_id', __( '<strong>Error</strong>: Not found. What are you subscribing/unsubscribing to?', 'bbpress' ) ); |
| 859 | 905 | |
| 860 | 906 | // Check nonce |
| 861 | - } elseif ( ! bbp_verify_nonce_request( 'toggle-subscription_' . $object_id ) ) { | |
| 907 | + } elseif ( ! bbp_verify_nonce_request( 'toggle-subscription_post_' . $object_id ) && ! bbp_verify_nonce_request( 'toggle-subscription_' . $object_id ) ) { | |
| 862 | 908 | bbp_add_error( 'bbp_subscription_object_id', __( '<strong>Error</strong>: Are you sure you wanted to do that?', 'bbpress' ) ); |
| 863 | 909 | |
| 864 | 910 | // Check current user's ability to edit the user |
| 865 | 911 | } elseif ( ! current_user_can( 'edit_user', $user_id ) ) { |
| @@ -929,9 +975,9 @@ | ||
| 929 | 975 | * want to come up with a more efficient way to get IDs on your own. Nevertheless, |
| 930 | 976 | * it is available here for your convenience, using the most efficient query |
| 931 | 977 | * parameters available inside of the various query APIs. |
| 932 | 978 | * |
| 933 | - * @since 2.6.0 bbPress (r6606) | |
| 979 | + * @since 2.6.0 bbPress (r6607) | |
| 934 | 980 | * |
| 935 | 981 | * @param int $user_id The user id |
| 936 | 982 | * @param string $rel_key The relationship key |
| 937 | 983 | * @param string $rel_type The relationship type (usually 'post') |
| @@ -1021,9 +1067,9 @@ | ||
| 1021 | 1067 | |
| 1022 | 1068 | /** |
| 1023 | 1069 | * Get a user's engaged topic ids |
| 1024 | 1070 | * |
| 1025 | - * @since 2.6.0 bbPress (r6320) | |
| 1071 | + * @since 2.6.0 bbPress (r6311) | |
| 1026 | 1072 | * |
| 1027 | 1073 | * @param int $user_id Optional. User id |
| 1028 | 1074 | * |
| 1029 | 1075 | * @return array Return array of topic ids, or empty array |
| @@ -1230,9 +1276,9 @@ | ||
| 1230 | 1276 | * this function. Originally both were validated, but because this function is |
| 1231 | 1277 | * frequently used within a loop, those verifications were moved upstream to |
| 1232 | 1278 | * improve performance on topics with many engaged users. |
| 1233 | 1279 | * |
| 1234 | - * @since 2.0.0 bbPress (r2668) | |
| 1280 | + * @since 2.5.0 bbPress (r5156) | |
| 1235 | 1281 | * @deprecated 2.6.0 bbPress (r6543) |
| 1236 | 1282 | * |
| 1237 | 1283 | * @param int $user_id Optional. User id |
| 1238 | 1284 | * @param int $topic_id Optional. Topic id |