| @@ -34,12 +34,12 @@ | ||
| 34 | 34 | $data = $app->request->all(); |
| 35 | 35 | $data['form_id'] = $formId; |
| 36 | 36 | $isValidJson = (!empty($data['formFields'])) && json_decode($data['formFields'], true); |
| 37 | 37 | |
| 38 | - if(!$isValidJson) { | |
| 38 | + if (!$isValidJson) { | |
| 39 | 39 | wp_send_json([ |
| 40 | 40 | 'message' => 'Looks like the provided JSON is invalid. Please try again or contact support', |
| 41 | - 'reason' => 'formFields JSON validation failed' | |
| 41 | + 'reason' => 'formFields JSON validation failed', | |
| 42 | 42 | ], 422); |
| 43 | 43 | } |
| 44 | 44 | |
| 45 | 45 | $formService = new \FluentForm\App\Services\Form\FormService(); |
| @@ -44,9 +44,9 @@ | ||
| 44 | 44 | |
| 45 | 45 | $formService = new \FluentForm\App\Services\Form\FormService(); |
| 46 | 46 | $form = $formService->update($data); |
| 47 | 47 | wp_send_json([ |
| 48 | - 'message' => __('The form is successfully updated.', 'fluentform') | |
| 48 | + 'message' => __('The form is successfully updated.', 'fluentform'), | |
| 49 | 49 | ], 200); |
| 50 | 50 | } catch (\Exception $exception) { |
| 51 | 51 | wp_send_json([ |
| 52 | 52 | 'message' => $exception->getMessage(), |
| @@ -143,15 +143,27 @@ | ||
| 143 | 143 | wp_send_json_error(['message' => $e->getMessage()], 423); |
| 144 | 144 | } |
| 145 | 145 | }); |
| 146 | 146 | |
| 147 | -$app->addAction('wp_ajax_fluentform-get-users', function () use ($app) { | |
| 148 | - Acl::verify('fluentform_entries_viewer'); | |
| 147 | +$app->addAction('wp_ajax_fluentform-get-users', function () use ($app, $resolveSubmissionFormId) { | |
| 148 | + $submissionId = absint($app->request->get('submission_id')); | |
| 149 | + $formId = Acl::verifyFormId( | |
| 150 | + $resolveSubmissionFormId($submissionId), | |
| 151 | + 'Invalid submission id.' | |
| 152 | + ); | |
| 153 | + | |
| 154 | + Acl::verify('fluentform_manage_entries', $formId); | |
| 149 | 155 | $search = sanitize_text_field($app->request->get('search')); |
| 150 | - $users = get_users([ | |
| 151 | - 'search' => "*{$search}*", | |
| 152 | - 'number' => 50, | |
| 153 | - ]); | |
| 156 | + if (current_user_can('list_users')) { | |
| 157 | + $users = get_users([ | |
| 158 | + 'search' => "*{$search}*", | |
| 159 | + 'number' => 50, | |
| 160 | + ]); | |
| 161 | + } else { | |
| 162 | + // Non-admins confirm an exact email only, never browse the roster (FF-SEC-45). | |
| 163 | + $user = is_email($search) ? get_user_by('email', $search) : false; | |
| 164 | + $users = $user ? [$user] : []; | |
| 165 | + } | |
| 154 | 166 | $formattedUsers = []; |
| 155 | 167 | foreach ($users as $user) { |
| 156 | 168 | $formattedUsers[] = [ |
| 157 | 169 | 'ID' => $user->ID, |
| @@ -240,9 +252,9 @@ | ||
| 240 | 252 | wp_send_json([ |
| 241 | 253 | 'error' => 'You do not have permission to do this', |
| 242 | 254 | ], 403); |
| 243 | 255 | } |
| 244 | - | |
| 256 | + | |
| 245 | 257 | wp_send_json([ |
| 246 | 258 | 'nonce' => wp_create_nonce('wp_rest'), |
| 247 | 259 | ], 200); |
| 248 | 260 | }); |