| @@ -8,8 +8,9 @@ | ||
| 8 | 8 | |
| 9 | 9 | defined('ABSPATH') || die('No direct access.'); |
| 10 | 10 | |
| 11 | 11 | use Extendify\Config; |
| 12 | +use Extendify\Mcp\Availability; | |
| 12 | 13 | |
| 13 | 14 | /** |
| 14 | 15 | * A client that publishes no metadata document registers here first (RFC 7591) |
| 15 | 16 | * and is handed an id; nothing else about it is verified. |
| @@ -43,8 +44,16 @@ | ||
| 43 | 44 | * @return \WP_REST_Response |
| 44 | 45 | */ |
| 45 | 46 | public static function handle(\WP_REST_Request $request) |
| 46 | 47 | { |
| 48 | + // Anonymous registrations would fill the stored client list on sites that never connect. | |
| 49 | + if (!Availability::live()) { | |
| 50 | + return self::answer(403, [ | |
| 51 | + 'error' => 'access_denied', | |
| 52 | + 'error_description' => 'Connections are turned off on this site.', | |
| 53 | + ]); | |
| 54 | + } | |
| 55 | + | |
| 47 | 56 | $sent = $request->get_json_params(); |
| 48 | 57 | if (!is_array($sent)) { |
| 49 | 58 | return self::answer(400, [ |
| 50 | 59 | 'error' => 'invalid_client_metadata', |