| @@ -20,11 +20,9 @@ | ||
| 20 | 20 | ?> |
| 21 | 21 | |
| 22 | 22 | <?php // Verify user meets minimum role to manage earned achievements |
| 23 | 23 | if ( current_user_can( gamipress_get_manager_capability() ) ) : ?> |
| 24 | - | |
| 25 | 24 | <h2><?php echo gamipress_dashicon( 'gamipress' ); ?> <?php _e( 'GamiPress', 'gamipress' ); ?></h2> |
| 26 | - | |
| 27 | 25 | <?php endif; ?> |
| 28 | 26 | |
| 29 | 27 | <?php // Output markup to user rank |
| 30 | 28 | gamipress_profile_user_rank( $user ); |
| @@ -58,10 +56,14 @@ | ||
| 58 | 56 | $user_id = absint( $_POST['user_id'] ); |
| 59 | 57 | |
| 60 | 58 | // Check if user has permissions |
| 61 | 59 | if ( ! current_user_can( 'edit_user', $user_id ) ) |
| 62 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 60 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 63 | 61 | |
| 62 | + // Check if user can manage GamiPress | |
| 63 | + if( ! current_user_can( gamipress_get_manager_capability() ) ) | |
| 64 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 65 | + | |
| 64 | 66 | // Check if valid user ID |
| 65 | 67 | if( $user_id === 0 ) |
| 66 | 68 | wp_send_json_error( __( 'Invalid user ID.', 'gamipress' ) ); |
| 67 | 69 | |
| @@ -105,16 +107,14 @@ | ||
| 105 | 107 | $points_type = sanitize_text_field( $_POST['points_type'] ); |
| 106 | 108 | $user_id = absint( $_POST['user_id'] ); |
| 107 | 109 | |
| 108 | 110 | // Check if user can edit other users |
| 109 | - if ( ! current_user_can( 'edit_user', $user_id ) ) { | |
| 110 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 111 | - } | |
| 111 | + if ( ! current_user_can( 'edit_user', $user_id ) ) | |
| 112 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 112 | 113 | |
| 113 | 114 | // Check if user can manage GamiPress |
| 114 | - if( ! current_user_can( gamipress_get_manager_capability() ) ) { | |
| 115 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 116 | - } | |
| 115 | + if( ! current_user_can( gamipress_get_manager_capability() ) ) | |
| 116 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 117 | 117 | |
| 118 | 118 | // Check if valid user ID |
| 119 | 119 | if( $user_id === 0 ) { |
| 120 | 120 | wp_send_json_error( __( 'Invalid user ID.', 'gamipress' ) ); |
| @@ -540,9 +540,9 @@ | ||
| 540 | 540 | check_ajax_referer( 'gamipress_admin', 'nonce' ); |
| 541 | 541 | |
| 542 | 542 | // Return if user is not a manager |
| 543 | 543 | if( ! current_user_can( gamipress_get_manager_capability() ) ) { |
| 544 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 544 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 545 | 545 | } |
| 546 | 546 | |
| 547 | 547 | $post_type = sanitize_text_field( $_POST['post_type'] ); |
| 548 | 548 | $user_id = absint( $_POST['user_id'] ); |
| @@ -548,9 +548,9 @@ | ||
| 548 | 548 | $user_id = absint( $_POST['user_id'] ); |
| 549 | 549 | |
| 550 | 550 | // Check if user has permissions |
| 551 | 551 | if ( ! current_user_can( 'edit_user', $user_id ) ) { |
| 552 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 552 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 553 | 553 | } |
| 554 | 554 | |
| 555 | 555 | // Grab our types |
| 556 | 556 | $achievement_types = gamipress_get_achievement_types(); |
| @@ -672,11 +672,9 @@ | ||
| 672 | 672 | */ |
| 673 | 673 | function gamipress_profile_award_requirement( $user = null ) { |
| 674 | 674 | |
| 675 | 675 | // Return if user is not a manager |
| 676 | - if( ! current_user_can( gamipress_get_manager_capability() ) ) { | |
| 677 | - return; | |
| 678 | - } | |
| 676 | + if( ! current_user_can( gamipress_get_manager_capability() ) ) return; | |
| 679 | 677 | |
| 680 | 678 | // Grab our types |
| 681 | 679 | $requirement_types = gamipress_get_requirement_types(); |
| 682 | 680 | |
| @@ -722,19 +720,17 @@ | ||
| 722 | 720 | // Security check, forces to die if not security passed |
| 723 | 721 | check_ajax_referer( 'gamipress_admin', 'nonce' ); |
| 724 | 722 | |
| 725 | 723 | // Return if user is not a manager |
| 726 | - if( ! current_user_can( gamipress_get_manager_capability() ) ) { | |
| 727 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 728 | - } | |
| 724 | + if( ! current_user_can( gamipress_get_manager_capability() ) ) | |
| 725 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 729 | 726 | |
| 730 | 727 | $post_type = sanitize_text_field( $_POST['post_type'] ); |
| 731 | 728 | $user_id = absint( $_POST['user_id'] ); |
| 732 | 729 | |
| 733 | 730 | // Check if user has permissions |
| 734 | - if ( ! current_user_can( 'edit_user', $user_id ) ) { | |
| 735 | - wp_send_json_error( __( 'You can perform this action.', 'gamipress' ) ); | |
| 736 | - } | |
| 731 | + if ( ! current_user_can( 'edit_user', $user_id ) ) | |
| 732 | + wp_send_json_error( __( 'You are not allowed to perform this action.', 'gamipress' ) ); | |
| 737 | 733 | |
| 738 | 734 | // Grab our types |
| 739 | 735 | $achievement_types = gamipress_get_achievement_types(); |
| 740 | 736 | $rank_types = gamipress_get_rank_types(); |