PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | _inc/lib/core-api/wpcom-endpoints/class-wpcom-rest-api-v2-endpoint-related-posts.php +93 -1 12.9.5 → 16.3-a.7 View file →
@@ -5,8 +5,12 @@
5 5 * @package automattic/jetpack
6 6 * @since 12.6
7 7 */
8 8
9 +if ( ! defined( 'ABSPATH' ) ) {
10 + exit( 0 );
11 +}
12 +
9 13 /**
10 14 * Class WPCOM_REST_API_V2_Endpoint_Related_Posts
11 15 */
12 16 class WPCOM_REST_API_V2_Endpoint_Related_Posts extends WP_REST_Controller {
@@ -33,9 +37,9 @@
33 37 'show_in_index' => true,
34 38 'methods' => WP_REST_Server::READABLE,
35 39 'callback' => array( $this, 'get_options' ),
36 40 'permission_callback' => function () {
37 - return current_user_can( 'manage_options' );
41 + return current_user_can( 'edit_posts' );
38 42 },
39 43 )
40 44 );
41 45
@@ -50,8 +54,27 @@
50 54 return current_user_can( 'manage_options' );
51 55 },
52 56 )
53 57 );
58 +
59 + register_rest_route(
60 + $this->namespace,
61 + $this->rest_base . '/(?P<id>[\d]+)',
62 + array(
63 + 'args' => array(
64 + 'id' => array(
65 + 'description' => __( 'Unique identifier for the post.', 'jetpack' ),
66 + 'type' => 'integer',
67 + ),
68 + ),
69 + array(
70 + 'show_in_index' => true,
71 + 'methods' => WP_REST_Server::READABLE,
72 + 'callback' => array( $this, 'get_related_posts' ),
73 + 'permission_callback' => array( $this, 'get_related_posts_permissions_check' ),
74 + ),
75 + )
76 + );
54 77 }
55 78
56 79 /**
57 80 * Gets the site's Related Posts Options.
@@ -91,8 +114,77 @@
91 114 array(
92 115 'enabled' => (bool) $enable,
93 116 )
94 117 );
118 + }
119 +
120 + /**
121 + * Checks if a given request has access to get the related posts.
122 + *
123 + * @since 4.7.0
124 + *
125 + * @param WP_REST_Request $request Full details about the request.
126 + * @return bool|WP_Error True if the request has read access for the related posts, WP_Error object or false otherwise.
127 + */
128 + public function get_related_posts_permissions_check( $request ) {
129 + $post = $this->get_post( $request['id'] );
130 + if ( is_wp_error( $post ) ) {
131 + return $post;
132 + }
133 +
134 + if ( ! current_user_can( 'edit_post', $post->ID ) ) {
135 + return new WP_Error(
136 + 'rest_forbidden_context',
137 + __( 'Sorry, you are not allowed to get the related post.', 'jetpack' ),
138 + array( 'status' => rest_authorization_required_code() )
139 + );
140 + }
141 +
142 + return true;
143 + }
144 +
145 + /**
146 + * Get the related posts
147 + *
148 + * @param WP_REST_Request $request Full data about the request.
149 + * @return WP_REST_Response Array The related posts
150 + */
151 + public function get_related_posts( $request ) {
152 + $post = $this->get_post( $request['id'] );
153 + if ( is_wp_error( $post ) ) {
154 + return $post;
155 + }
156 +
157 + if ( ! class_exists( 'Jetpack_RelatedPosts' ) ) {
158 + require_once JETPACK__PLUGIN_DIR . 'modules/related-posts/jetpack-related-posts.php';
159 + }
160 + $related_posts = \Jetpack_RelatedPosts::init()->get_for_post_id( $post->ID, array( 'size' => 6 ) );
161 + return rest_ensure_response( $related_posts );
162 + }
163 +
164 + /**
165 + * Gets the post, if the ID is valid.
166 + *
167 + * @param int $id Supplied ID.
168 + * @return WP_Post|WP_Error Post object if ID is valid, WP_Error otherwise.
169 + */
170 + public function get_post( $id ) {
171 + $error = new WP_Error(
172 + 'rest_post_invalid_id',
173 + __( 'Invalid post ID.', 'jetpack' ),
174 + array( 'status' => 404 )
175 + );
176 +
177 + if ( (int) $id <= 0 ) {
178 + return $error;
179 + }
180 +
181 + $post = get_post( (int) $id );
182 + if ( empty( $post ) || empty( $post->ID ) ) {
183 + return $error;
184 + }
185 +
186 + return $post;
95 187 }
96 188 }
97 189
98 190 wpcom_rest_api_v2_load_plugin( 'WPCOM_REST_API_V2_Endpoint_Related_Posts' );