PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-premium-analytics / src / class-capabilities.php
jetpack / jetpack_vendor / automattic / jetpack-premium-analytics / src Last commit date
REST 2 weeks ago Reports 1 week ago Sync 2 weeks ago class-analytics.php 3 days ago class-capabilities.php 2 weeks ago class-connection-configuration.php 2 weeks ago class-dashboard-section-registry.php 2 weeks ago class-dashboard-section.php 3 days ago class-dashboard-support-routes.php 1 week ago class-jetpack-stats-tracker.php 2 weeks ago class-notices.php 2 weeks ago class-widget-type-registry.php 2 weeks ago class-widget-type.php 2 weeks ago class-woocommerce-analytics-tracker.php 2 weeks ago csv-exports.php 2 weeks ago dashboard-grammar.php 2 weeks ago dashboard-layout.php 3 days ago dashboard-sections.php 3 days ago rest-namespace.php 2 weeks ago videopress-availability.php 3 days ago widget-availability.php 3 days ago widget-i18n.json 2 weeks ago widget-modules.php 3 days ago widget-type-support.php 3 days ago widget-types.php 2 weeks ago
class-capabilities.php
109 lines
1 <?php
2 /**
3 * Who may see the Premium Analytics dashboard.
4 *
5 * Jetpack Stats lets a site grant non-administrators access through the
6 * `view_stats` meta capability, and this dashboard replaces that UI, so it has
7 * to honour the same grant. `add_menu_page()` takes a single capability string,
8 * so the "manage_options OR view_stats" rule lives in a meta capability of our
9 * own rather than being spelled out at each call site.
10 *
11 * A class rather than a function file so every consumer reaches it through the
12 * autoloader: gating lives in files loaded on several different paths, and a
13 * `require_once` in each of them is a dependency to keep in sync (and an
14 * unmeasurable line of coverage) for no benefit.
15 *
16 * @package automattic/jetpack-premium-analytics
17 */
18
19 namespace Automattic\Jetpack\PremiumAnalytics;
20
21 /**
22 * The dashboard's capability rules.
23 *
24 * @since 0.1.0
25 */
26 class Capabilities {
27
28 /**
29 * Meta capability for reading the dashboard.
30 */
31 const VIEW_ANALYTICS = 'jetpack_view_analytics';
32
33 /**
34 * Hooks the dashboard's meta capability mapping.
35 *
36 * Called from WordPress-aware entry points, never at load time: this class is
37 * autoloaded in contexts where WordPress — and add_filter() — isn't there.
38 * Idempotent, so overlapping callers are free to call it.
39 *
40 * @return void
41 */
42 public static function register() {
43 add_filter( 'map_meta_cap', array( __CLASS__, 'map_meta_caps' ), 10, 3 );
44 }
45
46 /**
47 * Unhooks the mapping registered by register().
48 *
49 * Test tear-down needs this to drop the one filter: remove_all_filters(
50 * 'map_meta_cap' ) would also take out Stats' own `view_stats` mapping.
51 *
52 * @return void
53 */
54 public static function unregister() {
55 remove_filter( 'map_meta_cap', array( __CLASS__, 'map_meta_caps' ), 10 );
56 }
57
58 /**
59 * Maps the dashboard capability to the primitives that grant it.
60 *
61 * `view_stats` alone would track Stats more closely, but it only means
62 * anything once the Stats package has hooked its own `map_meta_cap` — which
63 * `Analytics::init_wpcom_simple()` never does. Without the `manage_options`
64 * arm, an unmapped `view_stats` would take the dashboard away from
65 * administrators too, which is worse than the gap this closes.
66 *
67 * @param string[] $caps Primitive capabilities required of the user.
68 * @param string $cap Capability being checked.
69 * @param int $user_id User being checked.
70 * @return string[] Primitives for the dashboard capability; anything else untouched.
71 */
72 public static function map_meta_caps( $caps, $cap, $user_id ) {
73 if ( self::VIEW_ANALYTICS !== $cap ) {
74 return $caps;
75 }
76
77 if ( user_can( $user_id, 'manage_options' ) || user_can( $user_id, 'view_stats' ) ) {
78 return array( 'read' );
79 }
80
81 return array( 'do_not_allow' );
82 }
83
84 /**
85 * Whether the current user may read the dashboard.
86 *
87 * @return bool
88 */
89 public static function current_user_can_view_analytics() {
90 return current_user_can( self::VIEW_ANALYTICS );
91 }
92
93 /**
94 * Whether the current user may read the store reports.
95 *
96 * "Store reports" is everything the proxy serves from its `analytics` prefix —
97 * WooCommerce's own reporting data. Mirrors the capability
98 * {@see \Automattic\Jetpack\PremiumAnalytics\REST\Api_Proxy_Controller} enforces
99 * there (Capabilities_Test pins the two together); surfaces backed by the prefix
100 * are hidden from readers who fail it, since all they could collect is 403s.
101 *
102 * @return bool
103 */
104 public static function current_user_can_view_store_reports() {
105 // The proxy accepts manage_options for every prefix.
106 return current_user_can( 'manage_options' ) || current_user_can( 'view_woocommerce_reports' );
107 }
108 }
109