← All changes
|
modules/gutenberg/classes/class-cartflows-init-blocks.php
+5
-6
3.2.0
→
3.3.0
View file →
| @@ -64,14 +64,13 @@ | ||
| 64 | 64 | add_action( 'wp_ajax_wpcf_order_detail_form_shortcode', array( $this, 'order_detail_form_shortcode' ) ); |
| 65 | 65 | add_action( 'wp_ajax_wpcf_order_checkout_form_shortcode', array( $this, 'order_checkout_form_shortcode' ) ); |
| 66 | 66 | add_action( 'wp_ajax_wpcf_optin_form_shortcode', array( $this, 'optin_form_shortcode' ) ); |
| 67 | 67 | |
| 68 | - add_filter( | |
| 69 | - 'cartflows_show_demo_order_details', | |
| 70 | - function() { | |
| 71 | - return true; | |
| 72 | - } | |
| 73 | - ); | |
| 68 | + // Demo order details are scoped to the editor preview request in | |
| 69 | + // order_detail_form_shortcode(), which is nonce- and capability-checked. Registering | |
| 70 | + // the filter here as well applied it to every request, front end included, so an | |
| 71 | + // administrator opening a live thank-you page without an order parameter was shown | |
| 72 | + // the store's most recent real order. | |
| 74 | 73 | |
| 75 | 74 | add_action( 'enqueue_block_editor_assets', array( $this, 'add_gcp_vars_to_block_editor' ), 12 ); |
| 76 | 75 | |
| 77 | 76 | // Load the action only if the theme.json file is present in the file. |