| @@ -23,9 +23,9 @@ | ||
| 23 | 23 | 'description' => sprintf( __( '%s balance', 'gamipress' ), $data['plural_name'] ), |
| 24 | 24 | 'single' => true, |
| 25 | 25 | 'show_in_rest' => true, |
| 26 | 26 | 'sanitize_callback' => 'absint', |
| 27 | - 'auth_callback' => '__return_true' | |
| 27 | + 'auth_callback' => 'gamipress_user_metas_auth_callback' | |
| 28 | 28 | ); |
| 29 | 29 | |
| 30 | 30 | /** |
| 31 | 31 | * Filters the points type meta arguments |
| @@ -48,9 +48,9 @@ | ||
| 48 | 48 | 'description' => sprintf( __( 'Current %s', 'gamipress' ), $data['singular_name'] ), |
| 49 | 49 | 'single' => true, |
| 50 | 50 | 'show_in_rest' => true, |
| 51 | 51 | 'sanitize_callback' => 'absint', |
| 52 | - 'auth_callback' => '__return_true' | |
| 52 | + 'auth_callback' => 'gamipress_user_metas_auth_callback' | |
| 53 | 53 | ); |
| 54 | 54 | |
| 55 | 55 | /** |
| 56 | 56 | * Filters the rank type meta arguments |
| @@ -67,8 +67,23 @@ | ||
| 67 | 67 | } |
| 68 | 68 | |
| 69 | 69 | } |
| 70 | 70 | add_action( 'init', 'gamipress_register_users_metas' ); |
| 71 | + | |
| 72 | +/** | |
| 73 | + * User's meta auth callback | |
| 74 | + * | |
| 75 | + * @since 8.0.6 | |
| 76 | + * | |
| 77 | + * @param bool $allowed | |
| 78 | + * @param string $meta_key | |
| 79 | + * @param int $user_id | |
| 80 | + * | |
| 81 | + * @return bool | |
| 82 | + */ | |
| 83 | +function gamipress_user_metas_auth_callback( $allowed, $meta_key, $user_id ) { | |
| 84 | + return current_user_can( gamipress_get_manager_capability() ); | |
| 85 | +} | |
| 71 | 86 | |
| 72 | 87 | /** |
| 73 | 88 | * Remove all user logs and earnings when is deleted from the database. |
| 74 | 89 | * |