| @@ -151,10 +151,14 @@ | ||
| 151 | 151 | // Get all registered routes and menu items |
| 152 | 152 | $menu_items = gutenberg_get_guidelines_menu_items(); |
| 153 | 153 | $routes = gutenberg_get_guidelines_routes(); |
| 154 | 154 | |
| 155 | - // Get boot module asset file for dependencies | |
| 155 | + // Get boot module asset file for dependencies. Plugins that build their own | |
| 156 | + // boot module use it; everyone else falls back to the copy bundled with Core. | |
| 156 | 157 | $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php'; |
| 158 | + if ( ! file_exists( $asset_file ) ) { | |
| 159 | + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php'; | |
| 160 | + } | |
| 157 | 161 | if ( file_exists( $asset_file ) ) { |
| 158 | 162 | $asset = require $asset_file; |
| 159 | 163 | |
| 160 | 164 | // This script serves two purposes: |
| @@ -277,9 +281,27 @@ | ||
| 277 | 281 | do_action( 'admin_head' ); |
| 278 | 282 | // END see wp-admin/admin-header.php |
| 279 | 283 | ?> |
| 280 | 284 | </head> |
| 281 | - <body class="guidelines"> | |
| 285 | + <body class="guidelines no-js"> | |
| 286 | + <?php | |
| 287 | + // BEGIN see wp-admin/admin-header.php | |
| 288 | + ?> | |
| 289 | + <script type="text/javascript"> | |
| 290 | + document.body.className = document.body.className.replace( 'no-js', 'js' ); | |
| 291 | + </script> | |
| 292 | + <?php | |
| 293 | + // END see wp-admin/admin-header.php | |
| 294 | + ?> | |
| 295 | + <div class="wrap hide-if-js" style="margin: 20px;"> | |
| 296 | + <h1 class="wp-heading-inline"><?php echo esc_html( get_admin_page_title() ); ?></h1> | |
| 297 | + <?php | |
| 298 | + wp_admin_notice( | |
| 299 | + __( 'This screen requires JavaScript. Enable JavaScript in your browser settings and reload the page.' ), | |
| 300 | + array( 'type' => 'error' ) | |
| 301 | + ); | |
| 302 | + ?> | |
| 303 | + </div> | |
| 282 | 304 | <div id="guidelines-app" style="height: 100vh; box-sizing: border-box;"></div> |
| 283 | 305 | <?php |
| 284 | 306 | // BEGIN see wp-admin/admin-footer.php |
| 285 | 307 | |
| @@ -309,8 +331,24 @@ | ||
| 309 | 331 | */ |
| 310 | 332 | function gutenberg_guidelines_intercept_render() { |
| 311 | 333 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended |
| 312 | 334 | if ( isset( $_GET['page'] ) && 'guidelines' === $_GET['page'] ) { |
| 335 | + // The page renders outside the menu page callback flow, so it must | |
| 336 | + // enforce authentication and capability checks itself. Without this, | |
| 337 | + // any admin entry point firing `admin_init` (such as admin-post.php, | |
| 338 | + // which serves logged-out requests) would render the page for | |
| 339 | + // unauthenticated visitors. | |
| 340 | + if ( ! is_user_logged_in() ) { | |
| 341 | + auth_redirect(); | |
| 342 | + } | |
| 343 | + | |
| 344 | + if ( ! current_user_can( 'manage_options' ) ) { | |
| 345 | + wp_die( | |
| 346 | + __( 'Sorry, you are not allowed to access this page.' ), | |
| 347 | + 403 | |
| 348 | + ); | |
| 349 | + } | |
| 350 | + | |
| 313 | 351 | gutenberg_guidelines_render_page(); |
| 314 | 352 | exit; |
| 315 | 353 | } |
| 316 | 354 | } |