PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / json-endpoints / class.wpcom-json-api-update-media-endpoint.php
jetpack / json-endpoints Last commit date
jetpack 1 week ago class.wpcom-json-api-add-widget-endpoint.php 8 months ago class.wpcom-json-api-autosave-post-v1-1-endpoint.php 8 months ago class.wpcom-json-api-bulk-delete-post-endpoint.php 8 months ago class.wpcom-json-api-bulk-restore-post-endpoint.php 8 months ago class.wpcom-json-api-bulk-update-comments-endpoint.php 2 months ago class.wpcom-json-api-comment-endpoint.php 8 months ago class.wpcom-json-api-delete-media-endpoint.php 8 months ago class.wpcom-json-api-delete-media-v1-1-endpoint.php 8 months ago class.wpcom-json-api-edit-media-v1-2-endpoint.php 1 week ago class.wpcom-json-api-get-autosave-v1-1-endpoint.php 8 months ago class.wpcom-json-api-get-comment-counts-endpoint.php 8 months ago class.wpcom-json-api-get-comment-endpoint.php 8 months ago class.wpcom-json-api-get-comment-history-endpoint.php 8 months ago class.wpcom-json-api-get-comments-tree-endpoint.php 8 months ago class.wpcom-json-api-get-comments-tree-v1-1-endpoint.php 8 months ago class.wpcom-json-api-get-comments-tree-v1-2-endpoint.php 8 months ago class.wpcom-json-api-get-customcss.php 8 months ago class.wpcom-json-api-get-media-endpoint.php 8 months ago class.wpcom-json-api-get-media-v1-1-endpoint.php 8 months ago class.wpcom-json-api-get-media-v1-2-endpoint.php 8 months ago class.wpcom-json-api-get-post-counts-v1-1-endpoint.php 1 month ago class.wpcom-json-api-get-post-endpoint.php 8 months ago class.wpcom-json-api-get-post-v1-1-endpoint.php 1 month ago class.wpcom-json-api-get-site-endpoint.php 2 days ago class.wpcom-json-api-get-site-v1-2-endpoint.php 1 month ago class.wpcom-json-api-get-taxonomies-endpoint.php 4 months ago class.wpcom-json-api-get-taxonomy-endpoint.php 8 months ago class.wpcom-json-api-get-term-endpoint.php 8 months ago class.wpcom-json-api-list-comments-endpoint.php 1 month ago class.wpcom-json-api-list-dropdown-pages-endpoint.php 8 months ago class.wpcom-json-api-list-embeds-endpoint.php 8 months ago class.wpcom-json-api-list-media-endpoint.php 8 months ago class.wpcom-json-api-list-media-v1-1-endpoint.php 2 months ago class.wpcom-json-api-list-media-v1-2-endpoint.php 8 months ago class.wpcom-json-api-list-post-type-taxonomies-endpoint.php 8 months ago class.wpcom-json-api-list-post-types-endpoint.php 8 months ago class.wpcom-json-api-list-posts-endpoint.php 1 month ago class.wpcom-json-api-list-posts-v1-1-endpoint.php 1 month ago class.wpcom-json-api-list-posts-v1-2-endpoint.php 1 month ago class.wpcom-json-api-list-roles-endpoint.php 8 months ago class.wpcom-json-api-list-shortcodes-endpoint.php 8 months ago class.wpcom-json-api-list-terms-endpoint.php 8 months ago class.wpcom-json-api-list-users-endpoint.php 1 month ago class.wpcom-json-api-menus-v1-1-endpoint.php 2 months ago class.wpcom-json-api-post-endpoint.php 8 months ago class.wpcom-json-api-post-v1-1-endpoint.php 3 months ago class.wpcom-json-api-render-embed-endpoint.php 8 months ago class.wpcom-json-api-render-embed-reversal-endpoint.php 8 months ago class.wpcom-json-api-render-endpoint.php 3 months ago class.wpcom-json-api-render-shortcode-endpoint.php 8 months ago class.wpcom-json-api-sharing-buttons-endpoint.php 2 months ago class.wpcom-json-api-site-settings-endpoint.php 2 weeks ago class.wpcom-json-api-site-settings-v1-2-endpoint.php 8 months ago class.wpcom-json-api-site-settings-v1-3-endpoint.php 8 months ago class.wpcom-json-api-site-settings-v1-4-endpoint.php 1 month ago class.wpcom-json-api-site-user-endpoint.php 8 months ago class.wpcom-json-api-taxonomy-endpoint.php 8 months ago class.wpcom-json-api-update-comment-endpoint.php 7 months ago class.wpcom-json-api-update-customcss.php 8 months ago class.wpcom-json-api-update-media-endpoint.php 2 days ago class.wpcom-json-api-update-media-v1-1-endpoint.php 2 days ago class.wpcom-json-api-update-post-endpoint.php 2 months ago class.wpcom-json-api-update-post-v1-1-endpoint.php 2 months ago class.wpcom-json-api-update-post-v1-2-endpoint.php 2 months ago class.wpcom-json-api-update-site-homepage-endpoint.php 8 months ago class.wpcom-json-api-update-site-logo-endpoint.php 8 months ago class.wpcom-json-api-update-taxonomy-endpoint.php 8 months ago class.wpcom-json-api-update-term-endpoint.php 8 months ago class.wpcom-json-api-update-user-endpoint.php 8 months ago class.wpcom-json-api-upload-media-endpoint.php 8 months ago class.wpcom-json-api-upload-media-v1-1-endpoint.php 8 months ago
class.wpcom-json-api-update-media-endpoint.php
151 lines
1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 /**
3 * Update media item info endpoint.
4 *
5 * Endpoint: /sites/%s/media/%d
6 */
7
8 if ( ! defined( 'ABSPATH' ) ) {
9 exit( 0 );
10 }
11
12 new WPCOM_JSON_API_Update_Media_Endpoint(
13 array(
14 'description' => 'Edit basic information about a media item.',
15 'group' => 'media',
16 'stat' => 'media:1:POST',
17 'method' => 'POST',
18 'path' => '/sites/%s/media/%d',
19 'deprecated' => true,
20 'max_version' => '1',
21 'new_version' => '1.1',
22 'path_labels' => array(
23 '$site' => '(int|string) Site ID or domain',
24 '$media_ID' => '(int) The ID of the media item',
25 ),
26
27 'request_format' => array(
28 'title' => '(string) The file name.',
29 'caption' => '(string) File caption.',
30 'description' => '(HTML) Description of the file.',
31 ),
32
33 'response_format' => array(
34 'id' => '(int) The ID of the media item',
35 'date' => '(ISO 8601 datetime) The date the media was uploaded',
36 'parent' => '(int) ID of the post this media is attached to',
37 'link' => '(string) URL to the file',
38 'title' => '(string) File name',
39 'caption' => '(string) User provided caption of the file',
40 'description' => '(string) Description of the file',
41 'metadata' => '(array) Array of metadata about the file, such as Exif data or sizes',
42 ),
43 'example_request' => 'https://public-api.wordpress.com/rest/v1.1/sites/82974409/media/446',
44 'example_request_data' => array(
45 'headers' => array(
46 'authorization' => 'Bearer YOUR_API_TOKEN',
47 ),
48 'body' => array(
49 'title' => 'Updated Title',
50 ),
51 ),
52 )
53 );
54
55 /**
56 * Update media item info class.
57 *
58 * @phan-constructor-used-for-side-effects
59 */
60 class WPCOM_JSON_API_Update_Media_Endpoint extends WPCOM_JSON_API_Endpoint {
61 /**
62 * Whether the current user may edit the given media item.
63 *
64 * `upload_files` is a primitive capability and ignores any object passed to it,
65 * so it only tells us the caller may upload something, never that they may edit
66 * this particular item. A missing item is passed through so the caller receives
67 * the endpoint's own 404 rather than a 403. A userless request gets no exemption:
68 * `edit_post` fails closed for user 0 like any other caller.
69 *
70 * Non-attachments are refused outright. `get_post()` resolves any post type, so
71 * without this test a media endpoint edits ordinary posts, pages and revisions.
72 * The post-type test must stay below the missing-post passthrough: that branch
73 * returns true, so testing there would skip `edit_post` for ordinary posts.
74 *
75 * A non-attachment yields 403, not the 404 a missing item gets. This is a boolean
76 * gate, and `get_media_item*()` resolves any post type, so a passthrough would
77 * return 200 rather than 404. Revisit if clients conflate it with an auth failure.
78 *
79 * Do not move this into a trait: this file instantiates the endpoint above the
80 * class declaration, and `use Trait;` disables PHP early binding, which makes the
81 * file fatal with "Class not found".
82 *
83 * @param int $media_id Media post ID.
84 * @return bool
85 */
86 protected function current_user_can_edit_media_item( $media_id ) {
87 if ( ! current_user_can( 'upload_files' ) ) {
88 return false;
89 }
90
91 $post = get_post( $media_id );
92
93 if ( ! $post ) {
94 return true;
95 }
96
97 if ( 'attachment' !== $post->post_type ) {
98 return false;
99 }
100
101 return current_user_can( 'edit_post', $media_id );
102 }
103
104 /**
105 * Update media item info API callback.
106 *
107 * @param string $path API path.
108 * @param int $blog_id Blog ID.
109 * @param int $media_id Media ID.
110 *
111 * @return object|WP_Error
112 */
113 public function callback( $path = '', $blog_id = 0, $media_id = 0 ) {
114 $blog_id = $this->api->switch_to_blog_and_validate_user( $this->api->get_blog_id( $blog_id ) );
115 if ( is_wp_error( $blog_id ) ) {
116 return $blog_id;
117 }
118
119 if ( ! $this->current_user_can_edit_media_item( $media_id ) ) {
120 return new WP_Error( 'unauthorized', 'User cannot edit media', 403 );
121 }
122
123 $item = $this->get_media_item( $media_id );
124
125 if ( is_wp_error( $item ) ) {
126 return new WP_Error( 'unknown_media', 'Unknown Media', 404 );
127 }
128
129 $input = $this->input( true );
130 $insert = array();
131
132 if ( ! empty( $input['title'] ) ) {
133 $insert['post_title'] = $input['title'];
134 }
135
136 if ( ! empty( $input['caption'] ) ) {
137 $insert['post_excerpt'] = $input['caption'];
138 }
139
140 if ( ! empty( $input['description'] ) ) {
141 $insert['post_content'] = $input['description'];
142 }
143
144 $insert['ID'] = $media_id;
145 wp_update_post( (object) $insert );
146
147 $item = $this->get_media_item( $media_id );
148 return $item;
149 }
150 }
151