| @@ -151,10 +151,14 @@ | ||
| 151 | 151 | // Get all registered routes and menu items |
| 152 | 152 | $menu_items = gutenberg_get_experiments_menu_items(); |
| 153 | 153 | $routes = gutenberg_get_experiments_routes(); |
| 154 | 154 | |
| 155 | - // Get boot module asset file for dependencies | |
| 155 | + // Get boot module asset file for dependencies. Plugins that build their own | |
| 156 | + // boot module use it; everyone else falls back to the copy bundled with Core. | |
| 156 | 157 | $asset_file = __DIR__ . '/../../modules/boot/index.min.asset.php'; |
| 158 | + if ( ! file_exists( $asset_file ) ) { | |
| 159 | + $asset_file = ABSPATH . WPINC . '/js/dist/script-modules/boot/index.min.asset.php'; | |
| 160 | + } | |
| 157 | 161 | if ( file_exists( $asset_file ) ) { |
| 158 | 162 | $asset = require $asset_file; |
| 159 | 163 | |
| 160 | 164 | // This script serves two purposes: |
| @@ -327,8 +331,24 @@ | ||
| 327 | 331 | */ |
| 328 | 332 | function gutenberg_experiments_intercept_render() { |
| 329 | 333 | // phpcs:ignore WordPress.Security.NonceVerification.Recommended |
| 330 | 334 | if ( isset( $_GET['page'] ) && 'experiments' === $_GET['page'] ) { |
| 335 | + // The page renders outside the menu page callback flow, so it must | |
| 336 | + // enforce authentication and capability checks itself. Without this, | |
| 337 | + // any admin entry point firing `admin_init` (such as admin-post.php, | |
| 338 | + // which serves logged-out requests) would render the page for | |
| 339 | + // unauthenticated visitors. | |
| 340 | + if ( ! is_user_logged_in() ) { | |
| 341 | + auth_redirect(); | |
| 342 | + } | |
| 343 | + | |
| 344 | + if ( ! current_user_can( 'manage_options' ) ) { | |
| 345 | + wp_die( | |
| 346 | + __( 'Sorry, you are not allowed to access this page.' ), | |
| 347 | + 403 | |
| 348 | + ); | |
| 349 | + } | |
| 350 | + | |
| 331 | 351 | gutenberg_experiments_render_page(); |
| 332 | 352 | exit; |
| 333 | 353 | } |
| 334 | 354 | } |