PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
jetpack / jetpack_vendor / automattic / jetpack-paypal-payments / src / legacy / class-order-rest-controller.php

class-order-rest-controller.php in Jetpack – WP Security, Backup, Speed, & Growth 16.3, at jetpack_vendor/automattic/jetpack-paypal-payments/src/legacy/class-order-rest-controller.php

108 lines 3.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Read-only REST controller for jp_pay_order.
4 *
5 * Orders should only be created through the internal payment processing flow,
6 * not directly via the REST API.
7 *
8 * @package automattic/jetpack-paypal-payments
9 */
10
11 namespace Automattic\Jetpack\Paypal_Payments;
12
13 use WP_Error;
14 use WP_REST_Posts_Controller;
15
16 if ( ! defined( 'ABSPATH' ) ) {
17 exit( 0 );
18 }
19
20 /**
21 * Extends WP_REST_Posts_Controller to restrict reads and disable create, update, and delete operations.
22 */
23 class Order_REST_Controller extends WP_REST_Posts_Controller {
24
25 /**
26 * Require the capability to read private posts before listing orders.
27 *
28 * Orders hold buyer details, so reading them requires an explicit capability.
29 *
30 * @param \WP_REST_Request $request Full details about the request.
31 * @return true|WP_Error
32 */
33 public function get_items_permissions_check( $request ) {
34 if ( ! $this->current_user_can_read_orders() ) {
35 return new WP_Error(
36 'rest_cannot_view',
37 __( 'Sorry, you are not allowed to view orders.', 'jetpack-paypal-payments' ),
38 array( 'status' => rest_authorization_required_code() )
39 );
40 }
41
42 return parent::get_items_permissions_check( $request );
43 }
44
45 /**
46 * Gate every single-order read, and every order the collection route would return.
47 *
48 * @param \WP_Post $post Post object.
49 * @return bool
50 */
51 public function check_read_permission( $post ) {
52 return $this->current_user_can_read_orders() && parent::check_read_permission( $post );
53 }
54
55 /**
56 * Whether the current user may read orders.
57 *
58 * @return bool
59 */
60 private function current_user_can_read_orders() {
61 $post_type = get_post_type_object( $this->post_type );
62
63 return $post_type !== null && current_user_can( $post_type->cap->read_private_posts );
64 }
65
66 /**
67 * Deny order creation via the REST API.
68 *
69 * @param \WP_REST_Request $request Full details about the request.
70 * @return WP_Error
71 */
72 public function create_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
73 return new WP_Error(
74 'rest_cannot_create',
75 __( 'Orders can only be created through the payment processing flow.', 'jetpack-paypal-payments' ),
76 array( 'status' => 403 )
77 );
78 }
79
80 /**
81 * Deny order updates via the REST API.
82 *
83 * @param \WP_REST_Request $request Full details about the request.
84 * @return WP_Error
85 */
86 public function update_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
87 return new WP_Error(
88 'rest_cannot_update',
89 __( 'Orders cannot be modified via the REST API.', 'jetpack-paypal-payments' ),
90 array( 'status' => 403 )
91 );
92 }
93
94 /**
95 * Deny order deletion via the REST API.
96 *
97 * @param \WP_REST_Request $request Full details about the request.
98 * @return WP_Error
99 */
100 public function delete_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
101 return new WP_Error(
102 'rest_cannot_delete',
103 __( 'Orders cannot be deleted via the REST API.', 'jetpack-paypal-payments' ),
104 array( 'status' => 403 )
105 );
106 }
107 }
108