| @@ -26,8 +26,9 @@ | ||
| 26 | 26 | class Manager { |
| 27 | 27 | |
| 28 | 28 | const ERROR_TEMPLATE_SOURCE_NOT_FOUND = 'Template source not found.'; |
| 29 | 29 | const ERROR_TEMPLATE_IDS_MISSING = 'Template IDs are missing.'; |
| 30 | + const ERROR_JSON_UPLOAD_NOT_ALLOWED = 'Uploading JSON files is not allowed for this user.'; | |
| 30 | 31 | |
| 31 | 32 | /** |
| 32 | 33 | * Registered template sources. |
| 33 | 34 | * |
| @@ -599,8 +600,12 @@ | ||
| 599 | 600 | * |
| 600 | 601 | * @return mixed Whether the export succeeded or failed. |
| 601 | 602 | */ |
| 602 | 603 | public function import_template( array $data ) { |
| 604 | + if ( ! User::is_current_user_can_upload_json() ) { | |
| 605 | + return new \WP_Error( 'template_error', self::ERROR_JSON_UPLOAD_NOT_ALLOWED ); | |
| 606 | + } | |
| 607 | + | |
| 603 | 608 | // If the template is a JSON file, allow uploading it. |
| 604 | 609 | add_filter( 'elementor/files/allow-file-type/json', [ $this, 'enable_json_template_upload' ] ); |
| 605 | 610 | add_filter( 'elementor/files/allow_unfiltered_upload', [ $this, 'enable_json_template_upload' ] ); |
| 606 | 611 | |
| @@ -896,8 +901,12 @@ | ||
| 896 | 901 | * @throws \Exception If current user has no permission or the post is not found. |
| 897 | 902 | */ |
| 898 | 903 | private function handle_ajax_request( $ajax_request, array $data ) { |
| 899 | 904 | if ( ! User::is_current_user_can_edit_post_type( Source_Local::CPT ) ) { |
| 905 | + throw new \Exception( 'Access denied.' ); | |
| 906 | + } | |
| 907 | + | |
| 908 | + if ( 'import_template' === $ajax_request && ! User::is_current_user_can_upload_json() ) { | |
| 900 | 909 | throw new \Exception( 'Access denied.' ); |
| 901 | 910 | } |
| 902 | 911 | |
| 903 | 912 | if ( ! empty( $data['editor_post_id'] ) ) { |