| @@ -1613,8 +1613,32 @@ | ||
| 1613 | 1613 | return (object) $author; |
| 1614 | 1614 | } |
| 1615 | 1615 | |
| 1616 | 1616 | /** |
| 1617 | + * Whether the current user may read the given media item through a media GET endpoint. | |
| 1618 | + * | |
| 1619 | + * Requires `edit_posts`, which Contributors hold, and returns only attachments. Any | |
| 1620 | + * other post type is reported as unknown media. | |
| 1621 | + * | |
| 1622 | + * @param int $media_id Media post ID. | |
| 1623 | + * @return true|WP_Error True if the item may be returned, WP_Error otherwise. | |
| 1624 | + */ | |
| 1625 | + public function check_media_item_read_permission( $media_id ) { | |
| 1626 | + // upload_files can probably be used for other endpoints but we want contributors to be able to use media too. | |
| 1627 | + if ( ! current_user_can( 'edit_posts' ) ) { | |
| 1628 | + return new WP_Error( 'unauthorized', 'User cannot view media', 403 ); | |
| 1629 | + } | |
| 1630 | + | |
| 1631 | + $media_item = get_post( $media_id ); | |
| 1632 | + | |
| 1633 | + if ( $media_item && 'attachment' !== $media_item->post_type ) { | |
| 1634 | + return new WP_Error( 'unknown_media', 'Unknown Media', 404 ); | |
| 1635 | + } | |
| 1636 | + | |
| 1637 | + return true; | |
| 1638 | + } | |
| 1639 | + | |
| 1640 | + /** | |
| 1617 | 1641 | * Get a media item. |
| 1618 | 1642 | * |
| 1619 | 1643 | * @param int $media_id Media post ID. |
| 1620 | 1644 | * @return object|WP_Error Media item data, or WP_Error. |