← All changes
|
json-endpoints/class.wpcom-json-api-get-media-endpoint.php
+3
-3
16.3
→
16.3-beta
View file →
| @@ -57,11 +57,11 @@ | ||
| 57 | 57 | if ( is_wp_error( $blog_id ) ) { |
| 58 | 58 | return $blog_id; |
| 59 | 59 | } |
| 60 | 60 | |
| 61 | - $permission = $this->check_media_item_read_permission( $media_id ); | |
| 62 | - if ( is_wp_error( $permission ) ) { | |
| 63 | - return $permission; | |
| 61 | + // upload_files can probably be used for other endpoints but we want contributors to be able to use media too. | |
| 62 | + if ( ! current_user_can( 'edit_posts', $media_id ) ) { | |
| 63 | + return new WP_Error( 'unauthorized', 'User cannot view media', 403 ); | |
| 64 | 64 | } |
| 65 | 65 | |
| 66 | 66 | return $this->get_media_item( $media_id ); |
| 67 | 67 | } |