| @@ -23,9 +23,9 @@ | ||
| 23 | 23 | 'description' => sprintf( __( '%s balance', 'gamipress' ), $data['plural_name'] ), |
| 24 | 24 | 'single' => true, |
| 25 | 25 | 'show_in_rest' => true, |
| 26 | 26 | 'sanitize_callback' => 'absint', |
| 27 | - 'auth_callback' => '__return_true' | |
| 27 | + 'auth_callback' => 'gamipress_user_metas_auth_callback' | |
| 28 | 28 | ); |
| 29 | 29 | |
| 30 | 30 | /** |
| 31 | 31 | * Filters the points type meta arguments |
| @@ -48,9 +48,9 @@ | ||
| 48 | 48 | 'description' => sprintf( __( 'Current %s', 'gamipress' ), $data['singular_name'] ), |
| 49 | 49 | 'single' => true, |
| 50 | 50 | 'show_in_rest' => true, |
| 51 | 51 | 'sanitize_callback' => 'absint', |
| 52 | - 'auth_callback' => '__return_true' | |
| 52 | + 'auth_callback' => 'gamipress_user_metas_auth_callback' | |
| 53 | 53 | ); |
| 54 | 54 | |
| 55 | 55 | /** |
| 56 | 56 | * Filters the rank type meta arguments |
| @@ -69,8 +69,23 @@ | ||
| 69 | 69 | } |
| 70 | 70 | add_action( 'init', 'gamipress_register_users_metas' ); |
| 71 | 71 | |
| 72 | 72 | /** |
| 73 | + * User's meta auth callback | |
| 74 | + * | |
| 75 | + * @since 8.0.6 | |
| 76 | + * | |
| 77 | + * @param bool $allowed | |
| 78 | + * @param string $meta_key | |
| 79 | + * @param int $user_id | |
| 80 | + * | |
| 81 | + * @return bool | |
| 82 | + */ | |
| 83 | +function gamipress_user_metas_auth_callback( $allowed, $meta_key, $user_id ) { | |
| 84 | + return current_user_can( gamipress_get_manager_capability() ); | |
| 85 | +} | |
| 86 | + | |
| 87 | +/** | |
| 73 | 88 | * Remove all user logs and earnings when is deleted from the database. |
| 74 | 89 | * |
| 75 | 90 | * @since 1.8.0 |
| 76 | 91 | * |
| @@ -110,13 +125,8 @@ | ||
| 110 | 125 | * @return array An array of all the achievement objects that matched our parameters, or empty if none |
| 111 | 126 | */ |
| 112 | 127 | function gamipress_get_user_achievements( $args = array() ) { |
| 113 | 128 | |
| 114 | - // If not properly upgrade to required version fallback to compatibility function | |
| 115 | - if( ! is_gamipress_upgraded_to( '1.2.8' ) ) { | |
| 116 | - return gamipress_get_user_achievements_old( $args ); | |
| 117 | - } | |
| 118 | - | |
| 119 | 129 | // Setup our default args |
| 120 | 130 | $defaults = array( |
| 121 | 131 | 'user_id' => 0, // The given user's ID |
| 122 | 132 | 'site_id' => get_current_blog_id(), // The given site's ID |
| @@ -235,13 +245,8 @@ | ||
| 235 | 245 | * |
| 236 | 246 | * @return bool The updated umeta ID on success, false on failure |
| 237 | 247 | */ |
| 238 | 248 | function gamipress_update_user_achievements( $args = array() ) { |
| 239 | - | |
| 240 | - // If not properly upgrade to required version fallback to compatibility function | |
| 241 | - if( ! is_gamipress_upgraded_to( '1.2.8' ) ) { | |
| 242 | - return gamipress_update_user_achievements_old( $args ); | |
| 243 | - } | |
| 244 | 249 | |
| 245 | 250 | // Setup our default args |
| 246 | 251 | $defaults = array( |
| 247 | 252 | 'user_id' => 0, // The given user's ID |