| @@ -7,13 +7,14 @@ | ||
| 7 | 7 | * posts in the term, top authors, co-occurring terms, 12-month |
| 8 | 8 | * activity sparkline, milestones. Powers the right preview pane in |
| 9 | 9 | * the My WordPress folder when a term is selected. |
| 10 | 10 | * |
| 11 | - * Permissions: any logged-in user with `read` (default for most | |
| 12 | - * roles) — terms are public-facing data on the WP site, so the same | |
| 13 | - * cap that lets you read the front-end is enough to inspect their | |
| 14 | - * stats. Author archives are also public so listing top authors is | |
| 15 | - * not new disclosure. | |
| 11 | + * Permissions: the My WordPress module's gate, | |
| 12 | + * `openstation_my_wordpress_user_can_use()` (`edit_posts` unless a site | |
| 13 | + * filters it), so a site that narrows WP Explorer narrows this data | |
| 14 | + * with it. Terms are public-facing data and author archives are | |
| 15 | + * public, so the term row and its top authors are no new disclosure to | |
| 16 | + * anyone past that gate. | |
| 16 | 17 | * |
| 17 | 18 | * That reasoning covers the term row and the aggregates over its |
| 18 | 19 | * *published* posts; it does not carry to the unpublished posts inside |
| 19 | 20 | * the term, nor to terms of a non-viewable taxonomy. So hidden |
| @@ -42,9 +43,12 @@ | ||
| 42 | 43 | array( |
| 43 | 44 | 'methods' => WP_REST_Server::READABLE, |
| 44 | 45 | 'callback' => 'openstation_my_wordpress_term_stats_callback', |
| 45 | 46 | 'permission_callback' => static function () { |
| 46 | - return is_user_logged_in() && current_user_can( 'read' ); | |
| 47 | + // The module's gate, so a site that narrows WP Explorer | |
| 48 | + // narrows this data with it. The per-viewer scoping lives | |
| 49 | + // in the callback, which in-process callers invoke directly. | |
| 50 | + return openstation_my_wordpress_user_can_use(); | |
| 47 | 51 | }, |
| 48 | 52 | 'args' => array( |
| 49 | 53 | 'taxonomy' => array( |
| 50 | 54 | 'required' => true, |
| @@ -98,9 +102,9 @@ | ||
| 98 | 102 | |
| 99 | 103 | // ----- Profile ----------------------------------------------------- |
| 100 | 104 | $profile = array( |
| 101 | 105 | 'id' => (int) $term->term_id, |
| 102 | - 'name' => $term->name, | |
| 106 | + 'name' => openstation_plain_text_title( $term->name ), | |
| 103 | 107 | 'slug' => $term->slug, |
| 104 | 108 | 'taxonomy' => $term->taxonomy, |
| 105 | 109 | 'taxonomyLabel' => isset( $tax_obj->labels->singular_name ) |
| 106 | 110 | ? (string) $tax_obj->labels->singular_name |
| @@ -114,9 +118,9 @@ | ||
| 114 | 118 | ); |
| 115 | 119 | if ( $term->parent > 0 ) { |
| 116 | 120 | $parent = get_term( $term->parent, $taxonomy ); |
| 117 | 121 | if ( $parent && ! is_wp_error( $parent ) ) { |
| 118 | - $profile['parentName'] = $parent->name; | |
| 122 | + $profile['parentName'] = openstation_plain_text_title( $parent->name ); | |
| 119 | 123 | } |
| 120 | 124 | } |
| 121 | 125 | |
| 122 | 126 | $tt_id = (int) $term->term_taxonomy_id; |
| @@ -280,15 +284,15 @@ | ||
| 280 | 284 | $author = $author_id > 0 ? get_userdata( $author_id ) : null; |
| 281 | 285 | $author_arr = $author |
| 282 | 286 | ? array( |
| 283 | 287 | 'id' => (int) $author->ID, |
| 284 | - 'name' => $author->display_name, | |
| 288 | + 'name' => openstation_plain_text_title( $author->display_name ), | |
| 285 | 289 | 'avatarUrl' => get_avatar_url( $author->ID, array( 'size' => 48 ) ), |
| 286 | 290 | ) |
| 287 | 291 | : null; |
| 288 | 292 | $recent[] = array( |
| 289 | 293 | 'id' => $post_id, |
| 290 | - 'title' => get_the_title( $post_id ), | |
| 294 | + 'title' => openstation_plain_text_title( get_the_title( $post_id ) ), | |
| 291 | 295 | 'date' => mysql2date( 'c', (string) $row['post_date_gmt'], false ), |
| 292 | 296 | 'status' => (string) $row['post_status'], |
| 293 | 297 | 'type' => (string) $row['post_type'], |
| 294 | 298 | 'link' => (string) get_permalink( $post_id ), |
| @@ -323,9 +327,9 @@ | ||
| 323 | 327 | continue; |
| 324 | 328 | } |
| 325 | 329 | $top_authors[] = array( |
| 326 | 330 | 'userId' => (int) $u->ID, |
| 327 | - 'userName' => (string) $u->display_name, | |
| 331 | + 'userName' => openstation_plain_text_title( $u->display_name ), | |
| 328 | 332 | 'userAvatarUrl' => (string) get_avatar_url( $u->ID, array( 'size' => 48 ) ), |
| 329 | 333 | 'count' => (int) $row['n'], |
| 330 | 334 | ); |
| 331 | 335 | } |
| @@ -355,9 +359,9 @@ | ||
| 355 | 359 | $co_terms = array(); |
| 356 | 360 | foreach ( (array) $co_term_rows as $row ) { |
| 357 | 361 | $co_terms[] = array( |
| 358 | 362 | 'id' => (int) $row['term_id'], |
| 359 | - 'name' => (string) $row['name'], | |
| 363 | + 'name' => openstation_plain_text_title( $row['name'] ), | |
| 360 | 364 | 'slug' => (string) $row['slug'], |
| 361 | 365 | 'count' => (int) $row['n'], |
| 362 | 366 | ); |
| 363 | 367 | } |