| @@ -12,8 +12,10 @@ | ||
| 12 | 12 | * - `install_plugins` → Browse tab + install/upload (the view hides |
| 13 | 13 | * the tab; AJAX routes re-validate). |
| 14 | 14 | * - `delete_plugins` → bulk-delete + per-row delete action. |
| 15 | 15 | * - `upload_plugins` → .zip upload (file or drag-drop). |
| 16 | + * - `edit_plugins` → the Plugin File Editor tab, where Core lists | |
| 17 | + * the editor under Plugins. | |
| 16 | 18 | * |
| 17 | 19 | * UI-side gating is purely UX polish — the AJAX routes in `ajax.php` |
| 18 | 20 | * and the app's server actions re-validate every cap before mutating. |
| 19 | 21 | * |
| @@ -115,8 +117,29 @@ | ||
| 115 | 117 | // roles even when `openstation_update_available.available` is |
| 116 | 118 | // true. Server-side, `wp_ajax_update_plugin` re-checks the cap. |
| 117 | 119 | 'update' => $user_id > 0 && user_can( $user_id, 'update_plugins' ), |
| 118 | 120 | ); |
| 121 | +} | |
| 122 | + | |
| 123 | +/** | |
| 124 | + * Core's Plugin File Editor, when Core lists it under Plugins for this | |
| 125 | + * viewer — the URL the window's Plugin File Editor tab opens. | |
| 126 | + * | |
| 127 | + * Mirrors the row `wp-admin/menu.php` adds: under Plugins on a single | |
| 128 | + * site with a classic theme, gated on `edit_plugins`, whose meta cap | |
| 129 | + * already answers `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS`. A block | |
| 130 | + * theme moves the row to Tools and multisite keeps the editor in the | |
| 131 | + * network admin, so the window offers nothing there. | |
| 132 | + * | |
| 133 | + * @param int|null $user_id Optional. Defaults to `get_current_user_id()`. | |
| 134 | + * @return string Absolute URL, or `''` when Core lists no editor under Plugins. | |
| 135 | + */ | |
| 136 | +function openstation_plugins_window_editor_url( $user_id = null ) { | |
| 137 | + $user_id = null === $user_id ? get_current_user_id() : (int) $user_id; | |
| 138 | + if ( is_multisite() || wp_is_block_theme() || $user_id <= 0 || ! user_can( $user_id, 'edit_plugins' ) ) { | |
| 139 | + return ''; | |
| 140 | + } | |
| 141 | + return esc_url_raw( admin_url( 'plugin-editor.php' ) ); | |
| 119 | 142 | } |
| 120 | 143 | |
| 121 | 144 | /** |
| 122 | 145 | * Whether the Plugins window should surface an "Automatic Updates" |