PluginProbe
Gutenberg / 24.1.0
Gutenberg v24.1.0
24.1.0 24.0.0 23.9.1 23.9.0 23.8.0 23.7.2 23.7.1 23.7.0 23.6.1 23.6.2 23.6.0 23.5.3 23.5.2 23.5.1 23.5.0 23.4.0 23.3.2 23.3.1 23.3.0 23.2.0 23.2.1 23.2.2 23.1.1 23.1.0 23.0.1 All 404 releases
← All changes | build/pages/dashboard/page.php +21 -1 23.8.0 → 24.1.0 View file →
@@ -151,10 +151,14 @@
151 151 // Get all registered routes and menu items
152 152 $menu_items = gutenberg_get_dashboard_menu_items();
153 153 $routes = gutenberg_get_dashboard_routes();
154 154
155 - // Get boot module asset file for dependencies
155 + // Get boot module asset file for dependencies. Plugins that build their own
156 + // boot module use it; everyone else falls back to the copy bundled with Core.
156 157 $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php';
158 + if ( ! file_exists( $asset_file ) ) {
159 + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php';
160 + }
157 161 if ( file_exists( $asset_file ) ) {
158 162 $asset = require $asset_file;
159 163
160 164 // This script serves two purposes:
@@ -327,8 +331,24 @@
327 331 */
328 332 function gutenberg_dashboard_intercept_render() {
329 333 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
330 334 if ( isset( $_GET['page'] ) && 'dashboard' === $_GET['page'] ) {
335 + // The page renders outside the menu page callback flow, so it must
336 + // enforce authentication and capability checks itself. Without this,
337 + // any admin entry point firing `admin_init` (such as admin-post.php,
338 + // which serves logged-out requests) would render the page for
339 + // unauthenticated visitors.
340 + if ( ! is_user_logged_in() ) {
341 + auth_redirect();
342 + }
343 +
344 + if ( ! current_user_can( 'manage_options' ) ) {
345 + wp_die(
346 + __( 'Sorry, you are not allowed to access this page.' ),
347 + 403
348 + );
349 + }
350 +
331 351 gutenberg_dashboard_render_page();
332 352 exit;
333 353 }
334 354 }