PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | class.json-api-endpoints.php +24 -0 16.2 → 16.3 View file →
@@ -1613,8 +1613,32 @@
1613 1613 return (object) $author;
1614 1614 }
1615 1615
1616 1616 /**
1617 + * Whether the current user may read the given media item through a media GET endpoint.
1618 + *
1619 + * Requires `edit_posts`, which Contributors hold, and returns only attachments. Any
1620 + * other post type is reported as unknown media.
1621 + *
1622 + * @param int $media_id Media post ID.
1623 + * @return true|WP_Error True if the item may be returned, WP_Error otherwise.
1624 + */
1625 + public function check_media_item_read_permission( $media_id ) {
1626 + // upload_files can probably be used for other endpoints but we want contributors to be able to use media too.
1627 + if ( ! current_user_can( 'edit_posts' ) ) {
1628 + return new WP_Error( 'unauthorized', 'User cannot view media', 403 );
1629 + }
1630 +
1631 + $media_item = get_post( $media_id );
1632 +
1633 + if ( $media_item && 'attachment' !== $media_item->post_type ) {
1634 + return new WP_Error( 'unknown_media', 'Unknown Media', 404 );
1635 + }
1636 +
1637 + return true;
1638 + }
1639 +
1640 + /**
1617 1641 * Get a media item.
1618 1642 *
1619 1643 * @param int $media_id Media post ID.
1620 1644 * @return object|WP_Error Media item data, or WP_Error.