PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.5
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.5
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | json-endpoints/class.wpcom-json-api-edit-media-v1-2-endpoint.php +9 -3 13.8.3 → 16.3-a.5 View file →
@@ -1,6 +1,10 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +if ( ! defined( 'ABSPATH' ) ) {
4 + exit( 0 );
5 +}
6 +
3 7 require_once JETPACK__PLUGIN_DIR . '_inc/lib/class.media.php';
4 8
5 9 define( 'REVISION_HISTORY_MAXIMUM_AMOUNT', 5 );
6 10 define( 'WP_ATTACHMENT_IMAGE_ALT', '_wp_attachment_image_alt' );
@@ -80,8 +84,10 @@
80 84 );
81 85
82 86 /**
83 87 * Edit media v1_2 endpoint class.
88 + *
89 + * @phan-constructor-used-for-side-effects
84 90 */
85 91 class WPCOM_JSON_API_Edit_Media_v1_2_Endpoint extends WPCOM_JSON_API_Update_Media_v1_1_Endpoint { //phpcs:ignore
86 92 /**
87 93 * Return an array of mime_type items allowed when the media file is uploaded.
@@ -400,10 +406,10 @@
400 406 if ( is_wp_error( $media_item ) ) {
401 407 return $media_item;
402 408 }
403 409
404 - if ( ! current_user_can( 'upload_files', $media_id ) ) {
405 - return new WP_Error( 'unauthorized', 'User cannot view media', 403 );
410 + if ( ! $this->current_user_can_edit_media_item( $media_id ) ) {
411 + return new WP_Error( 'unauthorized', 'User cannot edit media', 403 );
406 412 }
407 413
408 414 $input = $this->input( true );
409 415
@@ -408,9 +414,9 @@
408 414 $input = $this->input( true );
409 415
410 416 // Images.
411 417 $media_file = isset( $input['media'] ) ? (array) $input['media'] : null;
412 - $media_url = isset( $input['media_url'] ) ? $input['media_url'] : null;
418 + $media_url = $input['media_url'] ?? null;
413 419 $media_attrs = isset( $input['attrs'] ) ? (array) $input['attrs'] : null;
414 420
415 421 if ( isset( $media_url ) || $media_file ) {
416 422 $user_can_upload_files = current_user_can( 'upload_files' ) || $this->api->is_authorized_with_upload_token();