| @@ -176,16 +176,17 @@ | ||
| 176 | 176 | * |
| 177 | 177 | * @param string $item_type Ex: "lp_course", "lp_lesson", "lp_assignment", "lp_h5p" |
| 178 | 178 | * @return void |
| 179 | 179 | * @since 4.4.2 |
| 180 | - * @version 1.0.0 | |
| 180 | + * @version 1.0.1 | |
| 181 | 181 | */ |
| 182 | - public function add_capabilities_for_roles( string $item_type ) { | |
| 182 | + public function add_capabilities_for_roles( string $item_type = '' ) { | |
| 183 | 183 | $role_capabilities = Config::instance()->get( 'user-roles-caps' ); |
| 184 | 184 | foreach ( $role_capabilities as $role_key => $role_data ) { |
| 185 | - $role_label = $role_data['label'] ?? ''; | |
| 186 | - $prefix_caps = $role_data['prefix_capabilities'] ?? []; | |
| 187 | - $role = get_role( $role_key ); | |
| 185 | + $role_label = $role_data['label'] ?? ''; | |
| 186 | + $capabilities = $role_data['capabilities'] ?? []; | |
| 187 | + $prefix_caps = $role_data['prefix_capabilities'] ?? []; | |
| 188 | + $role = get_role( $role_key ); | |
| 188 | 189 | if ( $role_key !== UserModel::ROLE_ADMINISTRATOR |
| 189 | 190 | && ! $role instanceof WP_Role ) { |
| 190 | 191 | add_role( $role_key, $role_label ); |
| 191 | 192 | $role = get_role( $role_key ); |
| @@ -191,15 +192,52 @@ | ||
| 191 | 192 | $role = get_role( $role_key ); |
| 192 | 193 | } |
| 193 | 194 | |
| 194 | 195 | if ( $role instanceof WP_Role ) { |
| 195 | - foreach ( $prefix_caps as $prefix_cap ) { | |
| 196 | - // Example: "publish_lp_courses", "edit_lp_courses",... | |
| 197 | - $cap = "{$prefix_cap}_{$item_type}s"; | |
| 198 | - if ( ! $role->has_cap( $cap ) ) { | |
| 199 | - $role->add_cap( $cap ); | |
| 196 | + // For prefix + item_type | |
| 197 | + if ( ! empty( $item_type ) ) { | |
| 198 | + foreach ( $prefix_caps as $prefix_cap ) { | |
| 199 | + // Example: "publish_lp_courses", "edit_lp_courses",... | |
| 200 | + $cap = "{$prefix_cap}_{$item_type}s"; | |
| 201 | + if ( ! $role->has_cap( $cap ) ) { | |
| 202 | + $role->add_cap( $cap ); | |
| 203 | + } | |
| 200 | 204 | } |
| 205 | + } else { | |
| 206 | + foreach ( $capabilities as $cap ) { | |
| 207 | + if ( ! $role->has_cap( $cap ) ) { | |
| 208 | + $role->add_cap( $cap ); | |
| 209 | + } | |
| 210 | + } | |
| 201 | 211 | } |
| 202 | 212 | } |
| 203 | 213 | } |
| 214 | + } | |
| 215 | + | |
| 216 | + /** | |
| 217 | + * Create or get CSRF token to verify | |
| 218 | + * | |
| 219 | + * @return mixed|string|null | |
| 220 | + * @since 4.4.6 | |
| 221 | + * @version 1.0.0 | |
| 222 | + */ | |
| 223 | + public static function csrf_token() { | |
| 224 | + static $token = null; | |
| 225 | + $cookie_name = 'lp_csrf_token'; | |
| 226 | + | |
| 227 | + if ( null !== $token ) { | |
| 228 | + return $token; | |
| 229 | + } | |
| 230 | + | |
| 231 | + if ( ! empty( $_COOKIE[ $cookie_name ] ) ) { | |
| 232 | + $token = sanitize_text_field( wp_unslash( $_COOKIE[ $cookie_name ] ) ); | |
| 233 | + return $token; | |
| 234 | + } | |
| 235 | + | |
| 236 | + $token = wp_generate_password( 20, false ); | |
| 237 | + if ( ! headers_sent() ) { | |
| 238 | + learn_press_setcookie( $cookie_name, $token, time() + DAY_IN_SECONDS ); | |
| 239 | + } | |
| 240 | + | |
| 241 | + return $token; | |
| 204 | 242 | } |
| 205 | 243 | } |