PluginProbe
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin / 1.1.12
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin v1.1.12
1.1.12 1.1.11 1.1.10 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.1 1.0.0 0.9.8 0.9.7 0.9.6 0.9.4 0.9.5 0.9.3 0.9.2 0.9.1 0.9.0 0.8.9 All 36 releases
← All changes | includes/my-wordpress/term-stats.php +16 -12 1.1.8 → 1.1.12 View file →
@@ -7,13 +7,14 @@
7 7 * posts in the term, top authors, co-occurring terms, 12-month
8 8 * activity sparkline, milestones. Powers the right preview pane in
9 9 * the My WordPress folder when a term is selected.
10 10 *
11 - * Permissions: any logged-in user with `read` (default for most
12 - * roles) — terms are public-facing data on the WP site, so the same
13 - * cap that lets you read the front-end is enough to inspect their
14 - * stats. Author archives are also public so listing top authors is
15 - * not new disclosure.
11 + * Permissions: the My WordPress module's gate,
12 + * `openstation_my_wordpress_user_can_use()` (`edit_posts` unless a site
13 + * filters it), so a site that narrows WP Explorer narrows this data
14 + * with it. Terms are public-facing data and author archives are
15 + * public, so the term row and its top authors are no new disclosure to
16 + * anyone past that gate.
16 17 *
17 18 * That reasoning covers the term row and the aggregates over its
18 19 * *published* posts; it does not carry to the unpublished posts inside
19 20 * the term, nor to terms of a non-viewable taxonomy. So hidden
@@ -42,9 +43,12 @@
42 43 array(
43 44 'methods' => WP_REST_Server::READABLE,
44 45 'callback' => 'openstation_my_wordpress_term_stats_callback',
45 46 'permission_callback' => static function () {
46 - return is_user_logged_in() && current_user_can( 'read' );
47 + // The module's gate, so a site that narrows WP Explorer
48 + // narrows this data with it. The per-viewer scoping lives
49 + // in the callback, which in-process callers invoke directly.
50 + return openstation_my_wordpress_user_can_use();
47 51 },
48 52 'args' => array(
49 53 'taxonomy' => array(
50 54 'required' => true,
@@ -98,9 +102,9 @@
98 102
99 103 // ----- Profile -----------------------------------------------------
100 104 $profile = array(
101 105 'id' => (int) $term->term_id,
102 - 'name' => $term->name,
106 + 'name' => openstation_plain_text_title( $term->name ),
103 107 'slug' => $term->slug,
104 108 'taxonomy' => $term->taxonomy,
105 109 'taxonomyLabel' => isset( $tax_obj->labels->singular_name )
106 110 ? (string) $tax_obj->labels->singular_name
@@ -114,9 +118,9 @@
114 118 );
115 119 if ( $term->parent > 0 ) {
116 120 $parent = get_term( $term->parent, $taxonomy );
117 121 if ( $parent && ! is_wp_error( $parent ) ) {
118 - $profile['parentName'] = $parent->name;
122 + $profile['parentName'] = openstation_plain_text_title( $parent->name );
119 123 }
120 124 }
121 125
122 126 $tt_id = (int) $term->term_taxonomy_id;
@@ -280,15 +284,15 @@
280 284 $author = $author_id > 0 ? get_userdata( $author_id ) : null;
281 285 $author_arr = $author
282 286 ? array(
283 287 'id' => (int) $author->ID,
284 - 'name' => $author->display_name,
288 + 'name' => openstation_plain_text_title( $author->display_name ),
285 289 'avatarUrl' => get_avatar_url( $author->ID, array( 'size' => 48 ) ),
286 290 )
287 291 : null;
288 292 $recent[] = array(
289 293 'id' => $post_id,
290 - 'title' => get_the_title( $post_id ),
294 + 'title' => openstation_plain_text_title( get_the_title( $post_id ) ),
291 295 'date' => mysql2date( 'c', (string) $row['post_date_gmt'], false ),
292 296 'status' => (string) $row['post_status'],
293 297 'type' => (string) $row['post_type'],
294 298 'link' => (string) get_permalink( $post_id ),
@@ -323,9 +327,9 @@
323 327 continue;
324 328 }
325 329 $top_authors[] = array(
326 330 'userId' => (int) $u->ID,
327 - 'userName' => (string) $u->display_name,
331 + 'userName' => openstation_plain_text_title( $u->display_name ),
328 332 'userAvatarUrl' => (string) get_avatar_url( $u->ID, array( 'size' => 48 ) ),
329 333 'count' => (int) $row['n'],
330 334 );
331 335 }
@@ -355,9 +359,9 @@
355 359 $co_terms = array();
356 360 foreach ( (array) $co_term_rows as $row ) {
357 361 $co_terms[] = array(
358 362 'id' => (int) $row['term_id'],
359 - 'name' => (string) $row['name'],
363 + 'name' => openstation_plain_text_title( $row['name'] ),
360 364 'slug' => (string) $row['slug'],
361 365 'count' => (int) $row['n'],
362 366 );
363 367 }