PluginProbe
Polylang / trunk
Polylang vtrunk
3.8.10 3.8.9 3.8.8 3.8.7 3.8.6 3.8.5 3.8.4 3.8.3 2.7 2.7.0.1 2.7.1 2.7.2 2.7.3 2.7.4 2.8 2.8.1 2.8.2 2.8.3 2.8.4 2.9 2.9.1 2.9.2 3.0 3.0.1 3.0.2 All 234 releases
← All changes | src/translated-post.php +5 -4 3.8.6 → trunk View file →
@@ -90,8 +90,10 @@
90 90 '_pll' => true, // Polylang taxonomy.
91 91 )
92 92 );
93 93
94 + $this->add_sanitization_hooks( $this->tax_language );
95 +
94 96 add_action( 'setup_theme', array( $this, 'add_language_taxonomy_query_var' ) );
95 97 }
96 98
97 99 /**
@@ -130,9 +132,9 @@
130 132 * @param int $id Post ID.
131 133 * @return void
132 134 */
133 135 public function delete_translation( $id ) {
134 - $id = $this->sanitize_int_id( $id );
136 + $id = pll_sanitize_id( $id );
135 137
136 138 if ( empty( $id ) ) {
137 139 return;
138 140 }
@@ -248,9 +250,9 @@
248 250 *
249 251 * @phpstan-param non-empty-string $context
250 252 */
251 253 public function current_user_can_read( $id, $context = 'view' ) {
252 - $id = $this->sanitize_int_id( $id );
254 + $id = pll_sanitize_id( $id );
253 255
254 256 if ( empty( $id ) ) {
255 257 return false;
256 258 }
@@ -299,10 +301,9 @@
299 301 )
300 302 );
301 303
302 304 if ( in_array( $post->post_status, $states ) ) {
303 - $user = wp_get_current_user();
304 - return is_user_logged_in() && ( current_user_can( 'edit_posts' ) || (int) $user->ID === (int) $post->post_author );
305 + return current_user_can( 'read_post', $post->ID );
305 306 }
306 307 }
307 308
308 309 return false;