PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | _inc/lib/core-api/wpcom-endpoints/class-wpcom-rest-api-v2-endpoint-transient.php +91 -0 16.2-beta → 16.3 View file →
@@ -1,0 +1,91 @@
1 +<?php
2 +/**
3 + * REST API endpoint for editing Jetpack Transients.
4 + *
5 + * @package automattic/jetpack
6 + * @since 9.7.0
7 + */
8 +
9 +if ( ! defined( 'ABSPATH' ) ) {
10 + exit( 0 );
11 +}
12 +
13 +/**
14 + * Jetpack transients API.
15 + *
16 + * @since 9.7.0
17 + */
18 +class WPCOM_REST_API_V2_Endpoint_Transient extends WP_REST_Controller {
19 + /**
20 + * Constructor.
21 + */
22 + public function __construct() {
23 + $this->namespace = 'wpcom/v2';
24 + $this->rest_base = 'transients';
25 + add_action( 'rest_api_init', array( $this, 'register_routes' ) );
26 + }
27 +
28 + /**
29 + * Called automatically on `rest_api_init()`.
30 + */
31 + public function register_routes() {
32 + // DELETE /sites/<blog-id>/transients/$name route.
33 + register_rest_route(
34 + $this->namespace,
35 + '/' . $this->rest_base . '/(?P<name>\w{1,172})',
36 + array(
37 + array(
38 + 'methods' => WP_REST_Server::DELETABLE,
39 + 'callback' => array( $this, 'delete_transient' ),
40 + 'permission_callback' => array( $this, 'delete_transient_permissions_check' ),
41 + 'args' => array(
42 + 'name' => array(
43 + 'description' => __( 'The name of the transient to delete.', 'jetpack' ),
44 + 'required' => true,
45 + 'type' => 'string',
46 + 'sanitize_callback' => 'sanitize_text_field',
47 + ),
48 + ),
49 + ),
50 + )
51 + );
52 + }
53 +
54 + /**
55 + * Delete transient callback.
56 + *
57 + * @param \WP_REST_Request $request Full details about the request.
58 + * @return array
59 + */
60 + public function delete_transient( \WP_REST_Request $request ) {
61 + return array(
62 + 'success' => delete_transient( $request->get_param( 'name' ) ),
63 + );
64 + }
65 +
66 + /**
67 + * Check if the user has read access, the transient name starts with
68 + * "jetpack_connected_user_data_", and that the user is editing
69 + * their own transient.
70 + *
71 + * @param \WP_REST_Request $request Full details about the request.
72 + * @return bool|WP_Error
73 + */
74 + public function delete_transient_permissions_check( \WP_REST_Request $request ) {
75 + $transient_name = $request->get_param( 'name' );
76 + $current_user_id = get_current_user_id();
77 +
78 + if ( current_user_can( 'read' ) &&
79 + "jetpack_connected_user_data_{$current_user_id}" === $transient_name ) {
80 + return true;
81 + } else {
82 + return new WP_Error(
83 + 'authorization_required',
84 + __( 'Sorry, you are not allowed to delete this transient.', 'jetpack' ),
85 + array( 'status' => 403 )
86 + );
87 + }
88 + }
89 +}
90 +
91 +wpcom_rest_api_v2_load_plugin( 'WPCOM_REST_API_V2_Endpoint_Transient' );