← All changes
|
_inc/lib/core-api/wpcom-endpoints/class-wpcom-rest-api-v2-endpoint-external-media.php
+21
-1
16.2-beta
→
16.3-a.7
View file →
| @@ -274,8 +274,21 @@ | ||
| 274 | 274 | array( 'status' => 400 ) |
| 275 | 275 | ); |
| 276 | 276 | } |
| 277 | 277 | |
| 278 | + // Attaching media to a post requires the ability to edit that post, mirroring | |
| 279 | + // WP_REST_Attachments_Controller::create_item_permissions_check(). Without this | |
| 280 | + // check any user with upload_files could parent an attachment to a post they | |
| 281 | + // cannot edit. | |
| 282 | + $post_id = (int) $request->get_param( 'post_id' ); | |
| 283 | + if ( $post_id > 0 && ! current_user_can( 'edit_post', $post_id ) ) { | |
| 284 | + return new WP_Error( | |
| 285 | + 'rest_cannot_edit', | |
| 286 | + __( 'Sorry, you are not allowed to upload media to this post.', 'jetpack' ), | |
| 287 | + array( 'status' => rest_authorization_required_code() ) | |
| 288 | + ); | |
| 289 | + } | |
| 290 | + | |
| 278 | 291 | return true; |
| 279 | 292 | } |
| 280 | 293 | |
| 281 | 294 | /** |
| @@ -399,11 +412,18 @@ | ||
| 399 | 412 | require_once ABSPATH . 'wp-admin/includes/file.php'; |
| 400 | 413 | require_once ABSPATH . 'wp-admin/includes/media.php'; |
| 401 | 414 | require_once ABSPATH . 'wp-admin/includes/image.php'; |
| 402 | 415 | |
| 403 | - $post_id = $request->get_param( 'post_id' ); | |
| 416 | + $post_id = (int) $request->get_param( 'post_id' ); | |
| 404 | 417 | $should_proxy = $request->get_param( 'should_proxy' ); |
| 405 | 418 | $service = rawurlencode( $request->get_param( 'service' ) ); |
| 419 | + | |
| 420 | + // Fail closed: never parent an attachment to a post the caller cannot edit, | |
| 421 | + // even if a future change lets an unauthorized request reach this handler. | |
| 422 | + // The permission callback already rejects such requests with a 403. | |
| 423 | + if ( $post_id > 0 && ! current_user_can( 'edit_post', $post_id ) ) { | |
| 424 | + $post_id = 0; | |
| 425 | + } | |
| 406 | 426 | |
| 407 | 427 | $responses = array(); |
| 408 | 428 | |
| 409 | 429 | foreach ( $request->get_param( 'media' ) as $item ) { |