| 1 |
<?php |
| 2 |
/** |
| 3 |
* Authorization policy for the production Setup Wizard. |
| 4 |
* |
| 5 |
* @package Booking Calendar |
| 6 |
*/ |
| 7 |
|
| 8 |
if ( ! defined( 'ABSPATH' ) ) { |
| 9 |
exit; |
| 10 |
} |
| 11 |
|
| 12 |
/** |
| 13 |
* Resolve and enforce the complete Setup Wizard access boundary. |
| 14 |
*/ |
| 15 |
final class WPBC_Setup_Wizard_Access { |
| 16 |
|
| 17 |
/** |
| 18 |
* Determine the current settings capability configured by Booking Calendar. |
| 19 |
* |
| 20 |
* @return string WordPress capability required to access the Setup Wizard. |
| 21 |
*/ |
| 22 |
public static function get_required_capability() { |
| 23 |
$minimum_role = get_bk_option( 'booking_user_role_settings' ); |
| 24 |
$role_map = array( |
| 25 |
'administrator' => 'activate_plugins', |
| 26 |
'editor' => 'publish_pages', |
| 27 |
'author' => 'publish_posts', |
| 28 |
'contributor' => 'edit_posts', |
| 29 |
'subscriber' => 'read', |
| 30 |
); |
| 31 |
|
| 32 |
return isset( $role_map[ $minimum_role ] ) ? $role_map[ $minimum_role ] : 'read'; |
| 33 |
} |
| 34 |
|
| 35 |
/** |
| 36 |
* Check capability, MultiUser super-administrator, and activation policies. |
| 37 |
* |
| 38 |
* This method is used independently by the page and every state-changing or |
| 39 |
* privileged endpoint. It never trusts a client-provided site or owner ID. |
| 40 |
* |
| 41 |
* @return bool True when the current authenticated user may use the wizard. |
| 42 |
*/ |
| 43 |
public static function current_user_can_access() { |
| 44 |
if ( ! is_user_logged_in() || ! current_user_can( self::get_required_capability() ) ) { |
| 45 |
return false; |
| 46 |
} |
| 47 |
|
| 48 |
if ( class_exists( 'wpdev_bk_multiuser' ) ) { |
| 49 |
$real_user_id = get_current_user_id(); |
| 50 |
$is_super_admin_user = apply_bk_filter( 'is_user_super_admin', $real_user_id ); |
| 51 |
if ( ! $is_super_admin_user ) { |
| 52 |
return false; |
| 53 |
} |
| 54 |
} |
| 55 |
|
| 56 |
if ( function_exists( 'wpbc_is_mu_user_can_be_here' ) && ! wpbc_is_mu_user_can_be_here( 'activated_user' ) ) { |
| 57 |
return false; |
| 58 |
} |
| 59 |
|
| 60 |
return true; |
| 61 |
} |
| 62 |
|
| 63 |
/** |
| 64 |
* Return the server-owned storage context for the current request. |
| 65 |
* |
| 66 |
* The real WordPress user scopes user-option storage. The effective Booking |
| 67 |
* Calendar owner separates MultiUser simulated sessions, while the site ID |
| 68 |
* prevents cross-site checkpoint reuse on multisite. |
| 69 |
* |
| 70 |
* @return array{real_user_id:int,owner_user_id:int,site_id:int} Storage context. |
| 71 |
*/ |
| 72 |
public static function get_storage_context() { |
| 73 |
$real_user_id = get_current_user_id(); |
| 74 |
$owner_user_id = function_exists( 'wpbc_get_current_user_id' ) ? wpbc_get_current_user_id() : $real_user_id; |
| 75 |
|
| 76 |
return array( |
| 77 |
'real_user_id' => absint( $real_user_id ), |
| 78 |
'owner_user_id' => absint( $owner_user_id ), |
| 79 |
'site_id' => absint( get_current_blog_id() ), |
| 80 |
); |
| 81 |
} |
| 82 |
} |
| 83 |
|