PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | json-endpoints/class.wpcom-json-api-get-media-endpoint.php +9 -3 12.0.3 → 16.3 View file →
@@ -1,6 +1,10 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +if ( ! defined( 'ABSPATH' ) ) {
4 + exit( 0 );
5 +}
6 +
3 7 new WPCOM_JSON_API_Get_Media_Endpoint(
4 8 array(
5 9 'description' => 'Get a single media item (by ID).',
6 10 'group' => 'media',
@@ -35,8 +39,10 @@
35 39 );
36 40
37 41 /**
38 42 * GET Media endpoint class.
43 + *
44 + * @phan-constructor-used-for-side-effects
39 45 */
40 46 class WPCOM_JSON_API_Get_Media_Endpoint extends WPCOM_JSON_API_Endpoint {
41 47 /**
42 48 *
@@ -51,11 +57,11 @@
51 57 if ( is_wp_error( $blog_id ) ) {
52 58 return $blog_id;
53 59 }
54 60
55 - // upload_files can probably be used for other endpoints but we want contributors to be able to use media too.
56 - if ( ! current_user_can( 'edit_posts', $media_id ) ) {
57 - return new WP_Error( 'unauthorized', 'User cannot view media', 403 );
61 + $permission = $this->check_media_item_read_permission( $media_id );
62 + if ( is_wp_error( $permission ) ) {
63 + return $permission;
58 64 }
59 65
60 66 return $this->get_media_item( $media_id );
61 67 }