PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.5
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.5
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
jetpack / jetpack_vendor / automattic / jetpack-premium-analytics / src / class-capabilities.php

class-capabilities.php in Jetpack – WP Security, Backup, Speed, & Growth 16.3-a.5, at jetpack_vendor/automattic/jetpack-premium-analytics/src/class-capabilities.php

106 lines 3.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Who may see the Premium Analytics dashboard.
4 *
5 * Jetpack Stats grants non-administrators access via the `view_stats` meta capability; this
6 * dashboard must honour that grant, and add_menu_page() takes one capability string — hence a
7 * meta capability of our own.
8 *
9 * @package automattic/jetpack-premium-analytics
10 */
11
12 namespace Automattic\Jetpack\PremiumAnalytics;
13
14 /**
15 * The dashboard's capability rules.
16 *
17 * @since 0.1.0
18 */
19 class Capabilities {
20
21 /**
22 * Meta capability for reading the dashboard.
23 */
24 const VIEW_ANALYTICS = 'jetpack_view_analytics';
25
26 /**
27 * Hooks the dashboard's meta capability mapping.
28 *
29 * Called from WordPress-aware entry points, never at load time: this class is autoloaded where
30 * WordPress — and add_filter() — isn't there. Idempotent, so overlapping callers may call it freely.
31 *
32 * @return void
33 */
34 public static function register() {
35 add_filter( 'map_meta_cap', array( __CLASS__, 'map_meta_caps' ), 10, 3 );
36 }
37
38 /**
39 * Unhooks the mapping registered by register().
40 *
41 * Test tear-down needs this to drop the one filter: remove_all_filters(
42 * 'map_meta_cap' ) would also take out Stats' own `view_stats` mapping.
43 *
44 * @return void
45 */
46 public static function unregister() {
47 remove_filter( 'map_meta_cap', array( __CLASS__, 'map_meta_caps' ), 10 );
48 }
49
50 /**
51 * Maps the dashboard capability to the primitives that grant it.
52 *
53 * `view_stats` alone would track Stats more closely, but it only works once Stats hooks its
54 * own `map_meta_cap` — which Analytics::init_wpcom_simple() never does, locking out administrators too.
55 *
56 * @param string[] $caps Primitive capabilities required of the user.
57 * @param string $cap Capability being checked.
58 * @param int $user_id User being checked.
59 * @return string[] Primitives for the dashboard capability; anything else untouched.
60 */
61 public static function map_meta_caps( $caps, $cap, $user_id ) {
62 if ( self::VIEW_ANALYTICS !== $cap ) {
63 return $caps;
64 }
65
66 if ( user_can( $user_id, 'manage_options' ) || user_can( $user_id, 'view_stats' ) ) {
67 return array( 'read' );
68 }
69
70 return array( 'do_not_allow' );
71 }
72
73 /**
74 * Whether the current user may read the dashboard.
75 *
76 * @return bool
77 */
78 public static function current_user_can_view_analytics() {
79 return current_user_can( self::VIEW_ANALYTICS );
80 }
81
82 /**
83 * Whether the current user may read the store reports.
84 *
85 * "Store reports" is everything the proxy serves from its `analytics` prefix, mirroring what
86 * {@see \Automattic\Jetpack\PremiumAnalytics\REST\Api_Proxy_Controller} enforces there (pinned by Capabilities_Test).
87 *
88 * @return bool
89 */
90 public static function current_user_can_view_store_reports() {
91 // The proxy accepts manage_options for every prefix.
92 return current_user_can( 'manage_options' ) || current_user_can( 'view_woocommerce_reports' );
93 }
94
95 /**
96 * Whether the current user may view ad reports.
97 *
98 * @since 0.4.0
99 *
100 * @return bool
101 */
102 public static function current_user_can_view_ad_reports() {
103 return current_user_can( 'manage_options' );
104 }
105 }
106