PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | json-endpoints/class.wpcom-json-api-get-media-v1-1-endpoint.php +9 -3 13.5.2 → 16.3 View file →
@@ -1,6 +1,10 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +if ( ! defined( 'ABSPATH' ) ) {
4 + exit( 0 );
5 +}
6 +
3 7 new WPCOM_JSON_API_Get_Media_v1_1_Endpoint(
4 8 array(
5 9 'description' => 'Get a single media item (by ID).',
6 10 'group' => 'media',
@@ -49,8 +53,10 @@
49 53 );
50 54
51 55 /**
52 56 * GET Media v1_1 endpoint.
57 + *
58 + * @phan-constructor-used-for-side-effects
53 59 */
54 60 class WPCOM_JSON_API_Get_Media_v1_1_Endpoint extends WPCOM_JSON_API_Endpoint { //phpcs:ignore
55 61 /**
56 62 *
@@ -69,11 +75,11 @@
69 75 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
70 76 $this->load_theme_functions();
71 77 }
72 78
73 - // upload_files can probably be used for other endpoints but we want contributors to be able to use media too.
74 - if ( ! current_user_can( 'edit_posts', $media_id ) ) {
75 - return new WP_Error( 'unauthorized', 'User cannot view media', 403 );
79 + $permission = $this->check_media_item_read_permission( $media_id );
80 + if ( is_wp_error( $permission ) ) {
81 + return $permission;
76 82 }
77 83
78 84 return $this->get_media_item_v1_1( $media_id );
79 85 }