PluginProbe
Image Optimizer – Compress Images and Convert to WebP or AVIF / trunk
Image Optimizer – Compress Images and Convert to WebP or AVIF vtrunk
1.7.7 1.7.6 1.7.5 1.7.4 trunk 1.0.0 1.0.1 1.0.2 1.1.0 1.2.0 1.2.1 1.3.0 1.4.0 1.4.1 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.6.0 1.6.1 1.6.2 1.6.3 1.6.4 1.6.5 All 33 releases
← All changes | classes/route.php +23 -4 1.7.4 → trunk View file →
@@ -114,18 +114,28 @@
114 114 /**
115 115 * get_permission_callback_method
116 116 *
117 117 * Returns a reference to the permission callback for the method if exists or the default one if it doesn't.
118 + * Looks up inherited methods so module Route_Base manage_options gates are honoured.
119 + *
118 120 * @param string $method The REST method name
119 121 *
120 - * @return callable If a method called (rest-method)_permission_callback exists, returns a reference to it, otherwise
121 - * returns a reference to the default member method /permission_callback/.
122 + * @return callable If a method called (rest-method)_permission_callback exists, returns a reference to it,
123 + * otherwise get_permission_callback when present, otherwise permission_callback.
122 124 */
123 125 public function get_permission_callback_method( string $method ): callable {
124 126 $method_name = strtolower( $method );
125 127 $permission_callback_method = $method_name . '_permission_callback';
126 - $permission_callback = $this->method_exists_in_current_class( $permission_callback_method ) ? $permission_callback_method : 'permission_callback';
127 - return [ $this, $permission_callback ];
128 +
129 + if ( method_exists( $this, $permission_callback_method ) ) {
130 + return [ $this, $permission_callback_method ];
131 + }
132 +
133 + if ( method_exists( $this, 'get_permission_callback' ) ) {
134 + return [ $this, 'get_permission_callback' ];
135 + }
136 +
137 + return [ $this, 'permission_callback' ];
128 138 }
129 139
130 140 /**
131 141 * maybe_add_args_to_config
@@ -350,8 +360,17 @@
350 360 public function verify_nonce( $nonce = '', $name = '' ) {
351 361 if ( ! wp_verify_nonce( sanitize_text_field( wp_unslash( $nonce ) ), $name ) ) {
352 362 return $this->respond_error_json([
353 363 'message' => esc_html__( 'Invalid nonce', 'image-optimization' ),
364 + 'code' => 'bad_request',
365 + ]);
366 + }
367 + }
368 +
369 + public function verify_capability( $capability = 'manage_options' ) {
370 + if ( ! current_user_can( $capability ) ) {
371 + return $this->respond_error_json([
372 + 'message' => esc_html__( 'You do not have sufficient permissions to access this data.', 'image-optimization' ),
354 373 'code' => 'bad_request',
355 374 ]);
356 375 }
357 376 }