← All changes
|
json-endpoints/class.wpcom-json-api-get-media-v1-1-endpoint.php
+9
-3
13.2.4
→
16.3
View file →
| @@ -1,6 +1,10 @@ | ||
| 1 | 1 | <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName |
| 2 | 2 | |
| 3 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 4 | + exit( 0 ); | |
| 5 | +} | |
| 6 | + | |
| 3 | 7 | new WPCOM_JSON_API_Get_Media_v1_1_Endpoint( |
| 4 | 8 | array( |
| 5 | 9 | 'description' => 'Get a single media item (by ID).', |
| 6 | 10 | 'group' => 'media', |
| @@ -49,8 +53,10 @@ | ||
| 49 | 53 | ); |
| 50 | 54 | |
| 51 | 55 | /** |
| 52 | 56 | * GET Media v1_1 endpoint. |
| 57 | + * | |
| 58 | + * @phan-constructor-used-for-side-effects | |
| 53 | 59 | */ |
| 54 | 60 | class WPCOM_JSON_API_Get_Media_v1_1_Endpoint extends WPCOM_JSON_API_Endpoint { //phpcs:ignore |
| 55 | 61 | /** |
| 56 | 62 | * |
| @@ -69,11 +75,11 @@ | ||
| 69 | 75 | if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) { |
| 70 | 76 | $this->load_theme_functions(); |
| 71 | 77 | } |
| 72 | 78 | |
| 73 | - // upload_files can probably be used for other endpoints but we want contributors to be able to use media too. | |
| 74 | - if ( ! current_user_can( 'edit_posts', $media_id ) ) { | |
| 75 | - return new WP_Error( 'unauthorized', 'User cannot view media', 403 ); | |
| 79 | + $permission = $this->check_media_item_read_permission( $media_id ); | |
| 80 | + if ( is_wp_error( $permission ) ) { | |
| 81 | + return $permission; | |
| 76 | 82 | } |
| 77 | 83 | |
| 78 | 84 | return $this->get_media_item_v1_1( $media_id ); |
| 79 | 85 | } |