| @@ -19,9 +19,9 @@ | ||
| 19 | 19 | */ |
| 20 | 20 | function gamipress_ajax_get_achievements() { |
| 21 | 21 | // Security check, forces to die if not security passed |
| 22 | 22 | check_ajax_referer( 'gamipress', 'nonce' ); |
| 23 | - | |
| 23 | + | |
| 24 | 24 | // Send back our successful response |
| 25 | 25 | wp_send_json_success( gamipress_achievements_shortcode_query( $_REQUEST ) ); |
| 26 | 26 | |
| 27 | 27 | } |
| @@ -46,12 +46,16 @@ | ||
| 46 | 46 | } |
| 47 | 47 | |
| 48 | 48 | $atts = $_REQUEST; |
| 49 | 49 | |
| 50 | - // Change the atribute to display only public logs if current user is different | |
| 50 | + // Change the attribute to display only public logs if current user is different | |
| 51 | 51 | if( $atts['access'] !== 'public' ) { |
| 52 | - if ( get_current_user_id() !== absint( $atts['user_id'] ) ) | |
| 53 | - $atts['access'] = 'public'; | |
| 52 | + $current_user_id = get_current_user_id(); | |
| 53 | + | |
| 54 | + // If user is not logged in, force to public | |
| 55 | + if ( $current_user_id === 0 ) $atts['access'] = 'public'; | |
| 56 | + // If user ID is different from logged in, force to public | |
| 57 | + if ( $current_user_id !== absint( $atts['user_id'] ) ) $atts['access'] = 'public'; | |
| 54 | 58 | } |
| 55 | 59 | |
| 56 | 60 | // Unset non required shortcode atts |
| 57 | 61 | unset( $atts['action'] ); |
| @@ -58,9 +62,9 @@ | ||
| 58 | 62 | unset( $atts['page'] ); |
| 59 | 63 | |
| 60 | 64 | // Sanitize |
| 61 | 65 | foreach( $atts as $attr => $value ) { |
| 62 | - $atts[$attr] = sanitize_text_field( $value ); | |
| 66 | + $value = sanitize_text_field( $value ); | |
| 63 | 67 | $atts[$attr] = str_replace( array( '[', ']' ), '', $value); |
| 64 | 68 | } |
| 65 | 69 | |
| 66 | 70 | $atts = shortcode_atts( gamipress_logs_shortcode_defaults(), $atts, 'gamipress_logs' ); |