| @@ -1,13 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | namespace Elementor\Data\V2\Base; |
| 3 | 3 | |
| 4 | -use Elementor\Data\V2\Base\Exceptions\WP_Error_Exception; | |
| 5 | 4 | use Elementor\Data\V2\Manager; |
| 6 | 5 | use WP_REST_Controller; |
| 7 | 6 | |
| 8 | 7 | if ( ! defined( 'ABSPATH' ) ) { |
| 9 | - exit; // Exit if accessed directly. | |
| 8 | + exit; // Exit if accessed directly | |
| 10 | 9 | } |
| 11 | 10 | |
| 12 | 11 | /** |
| 13 | 12 | * TODO: Utilize 'WP_REST_Controller' as much as possible. |
| @@ -12,9 +11,8 @@ | ||
| 12 | 11 | /** |
| 13 | 12 | * TODO: Utilize 'WP_REST_Controller' as much as possible. |
| 14 | 13 | */ |
| 15 | 14 | abstract class Controller extends WP_REST_Controller { |
| 16 | - | |
| 17 | 15 | /** |
| 18 | 16 | * Loaded endpoint(s). |
| 19 | 17 | * |
| 20 | 18 | * @var \Elementor\Data\V2\Base\Endpoint[] |
| @@ -53,8 +51,37 @@ | ||
| 53 | 51 | return Manager::VERSION; |
| 54 | 52 | } |
| 55 | 53 | |
| 56 | 54 | /** |
| 55 | + * Controller constructor. | |
| 56 | + * | |
| 57 | + * Register endpoints on 'rest_api_init'. | |
| 58 | + */ | |
| 59 | + public function __construct() { | |
| 60 | + $this->namespace = static::get_default_namespace() . '/v' . static::get_default_version(); | |
| 61 | + $this->rest_base = $this->get_name(); | |
| 62 | + | |
| 63 | + add_action( 'rest_api_init', function () { | |
| 64 | + $this->register(); // Because 'register' is protected. | |
| 65 | + } ); | |
| 66 | + | |
| 67 | + /** | |
| 68 | + * Since all actions were removed for custom internal REST server. | |
| 69 | + * Re-add the actions. | |
| 70 | + */ | |
| 71 | + add_action( 'elementor_rest_api_before_init', function () { | |
| 72 | + add_action( 'rest_api_init', function() { | |
| 73 | + $this->register(); | |
| 74 | + } ); | |
| 75 | + } ); | |
| 76 | + | |
| 77 | + $parent_name = $this->get_parent_name(); | |
| 78 | + if ( $parent_name ) { | |
| 79 | + $this->act_as_sub_controller( $parent_name ); | |
| 80 | + } | |
| 81 | + } | |
| 82 | + | |
| 83 | + /** | |
| 57 | 84 | * Get controller name. |
| 58 | 85 | * |
| 59 | 86 | * @return string |
| 60 | 87 | */ |
| @@ -62,15 +89,10 @@ | ||
| 62 | 89 | |
| 63 | 90 | /** |
| 64 | 91 | * Register endpoints. |
| 65 | 92 | */ |
| 66 | - public function register_endpoints() { | |
| 67 | - } | |
| 93 | + public function register_endpoints() {} | |
| 68 | 94 | |
| 69 | - public function register_routes() { | |
| 70 | - _doing_it_wrong( 'Elementor\Data\V2\Controller::register_routes', sprintf( "Method '%s' deprecated. use `register_endpoints()`.", __METHOD__ ), '3.5.0' ); | |
| 71 | - } | |
| 72 | - | |
| 73 | 95 | /** |
| 74 | 96 | * Get parent controller name. |
| 75 | 97 | * |
| 76 | 98 | * @note: If `get_parent_name()` provided, controller will work as sub-controller. |
| @@ -160,12 +182,10 @@ | ||
| 160 | 182 | return $response; |
| 161 | 183 | } |
| 162 | 184 | |
| 163 | 185 | /** |
| 164 | - * Get items args of index endpoint. | |
| 186 | + * Get items args for specific endpoint. | |
| 165 | 187 | * |
| 166 | - * Is method is used when `get_collection_params()` is not enough, and need of knowing the methods is required. | |
| 167 | - * | |
| 168 | 188 | * @param string $methods |
| 169 | 189 | * |
| 170 | 190 | * @return array |
| 171 | 191 | */ |
| @@ -177,95 +197,33 @@ | ||
| 177 | 197 | return []; |
| 178 | 198 | } |
| 179 | 199 | |
| 180 | 200 | /** |
| 181 | - * Get item args of index endpoint. | |
| 182 | - * | |
| 183 | - * @param string $methods | |
| 184 | - * | |
| 185 | - * @return array | |
| 186 | - */ | |
| 187 | - public function get_item_args( $methods ) { | |
| 188 | - return []; | |
| 189 | - } | |
| 190 | - | |
| 191 | - /** | |
| 192 | 201 | * Get permission callback. |
| 193 | 202 | * |
| 194 | 203 | * Default controller permission callback. |
| 195 | 204 | * By default endpoint will inherit the permission callback from the controller. |
| 205 | + * By default permission is `current_user_can( 'administrator' );`. | |
| 196 | 206 | * |
| 197 | 207 | * @param \WP_REST_Request $request |
| 198 | 208 | * |
| 199 | 209 | * @return bool |
| 200 | - * | |
| 201 | - * @throws WP_Error_Exception If API request validation fails, permissions are insufficient, or processing errors occur. | |
| 202 | 210 | */ |
| 203 | 211 | public function get_permission_callback( $request ) { |
| 204 | - $is_multi = (bool) $request->get_param( 'is_multi' ); | |
| 205 | - | |
| 206 | - $result = false; | |
| 207 | - | |
| 208 | 212 | // The function is public since endpoint need to access it. |
| 209 | - // Utilize 'WP_REST_Controller' get_permission_check methods. | |
| 210 | 213 | switch ( $request->get_method() ) { |
| 211 | 214 | case 'GET': |
| 212 | - $result = $is_multi ? $this->get_items_permissions_check( $request ) : $this->get_item_permissions_check( $request ); | |
| 213 | - break; | |
| 214 | 215 | case 'POST': |
| 215 | - $result = $is_multi ? $this->create_items_permissions_check( $request ) : $this->create_item_permissions_check( $request ); | |
| 216 | - break; | |
| 217 | 216 | case 'UPDATE': |
| 218 | 217 | case 'PUT': |
| 218 | + case 'DELETE': | |
| 219 | 219 | case 'PATCH': |
| 220 | - $result = $is_multi ? $this->update_items_permissions_check( $request ) : $this->update_item_permissions_check( $request ); | |
| 221 | - break; | |
| 222 | - | |
| 223 | - case 'DELETE': | |
| 224 | - $result = $is_multi ? $this->delete_items_permissions_check( $request ) : $this->delete_item_permissions_check( $request ); | |
| 225 | - break; | |
| 220 | + return current_user_can( 'administrator' ); | |
| 226 | 221 | } |
| 227 | 222 | |
| 228 | - if ( $result instanceof \WP_Error ) { | |
| 229 | - throw new WP_Error_Exception( esc_html( $result ) ); | |
| 230 | - } | |
| 231 | - | |
| 232 | - return $result; | |
| 223 | + return false; | |
| 233 | 224 | } |
| 234 | 225 | |
| 235 | - /** | |
| 236 | - * Checks if a given request has access to create items. | |
| 237 | - * | |
| 238 | - * @param \WP_REST_Request $request Full details about the request. | |
| 239 | - * | |
| 240 | - * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise. | |
| 241 | - */ | |
| 242 | - public function create_items_permissions_check( $request ) { | |
| 243 | - return new \WP_Error( 'invalid-method', sprintf( "Method '%s' not implemented. Must be overridden in subclass.", __METHOD__ ), [ 'status' => 405 ] ); | |
| 244 | - } | |
| 245 | - | |
| 246 | - /** | |
| 247 | - * Checks if a given request has access to update items. | |
| 248 | - * | |
| 249 | - * @param \WP_REST_Request $request Full details about the request. | |
| 250 | - * | |
| 251 | - * @return true|\WP_Error True if the request has access to update the item, WP_Error object otherwise. | |
| 252 | - */ | |
| 253 | - public function update_items_permissions_check( $request ) { | |
| 254 | - return new \WP_Error( 'invalid-method', sprintf( "Method '%s' not implemented. Must be overridden in subclass.", __METHOD__ ), [ 'status' => 405 ] ); | |
| 255 | - } | |
| 256 | - | |
| 257 | - /** | |
| 258 | - * Checks if a given request has access to delete items. | |
| 259 | - * | |
| 260 | - * @param \WP_REST_Request $request Full details about the request. | |
| 261 | - * | |
| 262 | - * @return true|\WP_Error True if the request has access to delete the item, WP_Error object otherwise. | |
| 263 | - */ | |
| 264 | - public function delete_items_permissions_check( $request ) { | |
| 265 | - return new \WP_Error( 'invalid-method', sprintf( "Method '%s' not implemented. Must be overridden in subclass.", __METHOD__ ), [ 'status' => 405 ] ); | |
| 266 | - } | |
| 267 | - | |
| 268 | 226 | public function get_items( $request ) { |
| 269 | 227 | return $this->get_controller_index(); |
| 270 | 228 | } |
| 271 | 229 | |
| @@ -348,9 +306,8 @@ | ||
| 348 | 306 | */ |
| 349 | 307 | protected function register_index_endpoint() { |
| 350 | 308 | if ( ! $this->parent ) { |
| 351 | 309 | $this->register_endpoint( new Endpoint\Index( $this ) ); |
| 352 | - | |
| 353 | 310 | return; |
| 354 | 311 | } |
| 355 | 312 | |
| 356 | 313 | $this->register_endpoint( new Endpoint\Index\Sub_Index_Endpoint( $this ) ); |
| @@ -447,35 +404,6 @@ | ||
| 447 | 404 | trigger_error( "Cannot find parent controller: '$parent_name'", E_USER_ERROR ); // phpcs:ignore |
| 448 | 405 | } |
| 449 | 406 | |
| 450 | 407 | $this->parent->sub_controllers [] = $this; |
| 451 | - } | |
| 452 | - | |
| 453 | - /** | |
| 454 | - * Controller constructor. | |
| 455 | - * | |
| 456 | - * Register endpoints on 'rest_api_init'. | |
| 457 | - */ | |
| 458 | - public function __construct() { | |
| 459 | - $this->namespace = static::get_default_namespace() . '/v' . static::get_default_version(); | |
| 460 | - $this->rest_base = $this->get_name(); | |
| 461 | - | |
| 462 | - add_action( 'rest_api_init', function () { | |
| 463 | - $this->register(); // Because 'register' is protected. | |
| 464 | - } ); | |
| 465 | - | |
| 466 | - /** | |
| 467 | - * Since all actions were removed for custom internal REST server. | |
| 468 | - * Re-add the actions. | |
| 469 | - */ | |
| 470 | - add_action( 'elementor_rest_api_before_init', function () { | |
| 471 | - add_action( 'rest_api_init', function () { | |
| 472 | - $this->register(); | |
| 473 | - } ); | |
| 474 | - } ); | |
| 475 | - | |
| 476 | - $parent_name = $this->get_parent_name(); | |
| 477 | - if ( $parent_name ) { | |
| 478 | - $this->act_as_sub_controller( $parent_name ); | |
| 479 | - } | |
| 480 | 408 | } |
| 481 | 409 | } |