PluginProbe ʕ •ᴥ•ʔ
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments / 4.6.3
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments v4.6.3
4.6.3 4.6.2 4.6.1 4.6.0 4.5.1 4.5.0 4.4.2 4.4.1 4.4.0 4.3.3 4.3.2 4.3.1 4.3.0 4.2.3 4.2.2 4.2.1 1.0.3 1.0.4 1.0.5 1.0.6 1.1.0 1.1.1 1.1.10 1.1.11 1.1.12 1.1.13 1.1.14 1.1.15 1.1.16 1.1.17 1.1.18 1.1.19 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.1.9 1.10.0 1.10.1 1.10.2 1.10.3 1.10.4 1.11.0 1.11.1 1.11.2 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 1.4.0 1.4.1 1.4.2 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 1.5.6 1.5.7 1.5.8 1.6.0 1.6.1 1.6.2 1.6.3 1.6.4 1.7.0 1.7.1 1.7.2 1.8.0 1.8.1 1.8.2 1.8.3 1.8.4 1.8.5 1.9.0 1.9.1 1.9.2 1.9.3 1.9.4 1.9.5 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.10.0 2.10.1 2.11.0 2.11.1 2.11.2 2.11.3 2.11.4 2.12.0 2.13.0 2.14.0 2.14.1 2.15.0 2.15.1 2.16.0 2.16.1 2.16.2 2.16.3 2.17.0 2.17.1 2.17.2 2.18.0 2.19.0 2.19.2 2.19.3 2.19.4 2.2.0 2.2.1 2.20.0 2.20.1 2.20.2 2.20.3 2.20.4 2.20.5 2.20.6 2.21.0 2.22.0 2.22.1 2.23.0 2.24.0 2.25.0 2.25.1 2.25.2 2.26.0 2.27.0 2.27.1 2.28.0 2.29.0 2.29.1 2.29.2 2.29.3 2.29.4 2.3.0 2.3.1 2.30.0 2.31.0 2.31.1 2.31.2 2.31.3 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 2.40.0 2.40.1 2.5.0 2.5.1 2.5.2 2.6.0 2.6.1 2.6.2 2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.8.0 2.8.1 2.8.2 2.8.3 2.8.4 2.9.0 3.0.0 3.0.0-RC1 3.0.0-RC2 3.0.0-beta1 3.0.0-beta2 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.1.0 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.1.6 3.10.0 3.10.1 3.11.0 3.12.0 3.13.0 3.13.1 3.13.2 3.13.3 3.13.4 3.14.0 3.15.0 3.15.1 3.15.2 3.15.3 3.15.4 3.15.5 3.16.0 3.16.1 3.16.2 3.16.3 3.16.4 3.16.5 3.16.6 3.16.7 3.16.8 3.17.0 3.17.1 3.17.2 3.17.3 3.17.4 3.17.5 3.17.6 3.18.0 3.19.0 3.19.1 3.19.2 3.2.0 3.2.1 3.2.2 3.20.0 3.20.1 3.3.0 3.3.1 3.4.0 3.4.1 3.4.2 3.4.3 3.5.0 3.5.1 3.5.2 3.5.3 3.6.0 3.6.1 3.6.2 3.7.0 3.7.1 3.7.2 3.7.3 3.8.0 3.8.1 3.8.2 3.8.3 3.8.4 3.8.5 3.9.0 4.0.0 4.0.1 4.0.2 4.0.3 trunk 4.1.0 0.2.19.1 4.1.1 1.0.0 4.2.0 1.0.1 1.0.2
surecart / app / src / Permissions / Models / ModelPermissionsController.php
surecart / app / src / Permissions / Models Last commit date
ActivationPermissionsController.php 1 year ago BalanceTransactionPermissionsController.php 3 years ago ChargePermissionsController.php 4 years ago CheckoutPermissionsController.php 1 year ago CustomerPermissionsController.php 2 years ago DownloadPermissionsController.php 10 months ago InvoicePermissionsController.php 4 years ago LicensePermissionsController.php 3 years ago MediaPermissionsController.php 3 years ago ModelPermissionsController.php 4 days ago OrderPermissionsController.php 3 years ago PaymentMethodPermissionsController.php 4 years ago PurchasePermissionsController.php 4 years ago RefundPermissionsController.php 4 years ago SubscriptionPermissionsController.php 3 months ago
ModelPermissionsController.php
138 lines
1 <?php
2
3 namespace SureCart\Permissions\Models;
4
5 use SureCart\Models\User;
6
7 /**
8 * Model permissions abstract class.
9 */
10 abstract class ModelPermissionsController {
11 /**
12 * Get the customer id for the user
13 *
14 * @param int $user_id User ID.
15 * @return string Customer ID.
16 */
17 protected function getCustomerId( $user_id ) {
18 return User::find( $user_id )->customerId();
19 }
20
21 /**
22 * Meta caps for models
23 *
24 * @param bool[] $allcaps Array of key/value pairs where keys represent a capability name
25 * and boolean values represent whether the user has that capability.
26 * @param string[] $caps Required primitive capabilities for the requested capability.
27 * @param array $args {
28 * Arguments that accompany the requested capability check.
29 *
30 * @type string $0 Requested capability.
31 * @type int $1 Concerned user ID.
32 * @type mixed ...$2 Optional second and further parameters, typically object ID.
33 * }
34 * @param WP_User $user The user object.
35 * @return string[] Primitive capabilities required of the user.
36 */
37 public function handle( $allcaps, $caps, $args, $user ) {
38 $name = $caps[0] ?? false;
39 if ( $name && method_exists( $this, $name ) ) {
40 $user = User::find( $user->ID );
41 if ( ! $user ) {
42 return false;
43 }
44
45 // check permission.
46 $permission = $this->$name( $user, $args, $allcaps );
47 if ( $permission ) {
48 $allcaps[ $caps[0] ] = true;
49 return $allcaps;
50 }
51 }
52
53 return $allcaps;
54 }
55
56 /**
57 * Does the model belong to the user?
58 *
59 * @param string $model Model name.
60 * @param string $id Model ID.
61 * @param \SureCart\Models\User $user User model.
62 * @return boolean
63 */
64 public function belongsToUser( $model, $id, $user ) {
65 $model = $model::find( $id );
66 if ( is_wp_error( $model ) ) {
67 return $model;
68 }
69 return $model->belongsToUser( $user );
70 }
71
72 /**
73 * Is ths user listing their own customer ids.
74 *
75 * @param \SureCart\Models\User $user User model.
76 * @param mixed $customer_ids Requested customer ids — only a sequential list of id strings authorizes.
77 * @return boolean
78 */
79 protected function isListingOwnCustomerIds( $user, $customer_ids ) {
80 // must have list.
81 if ( empty( $customer_ids ) || ! is_array( $customer_ids ) ) {
82 return false;
83 }
84
85 // only authorize a sequential list — the platform ignores (rather than filters on)
86 // associative customer_ids, so this guard and the platform must agree on the encoding.
87 if ( array_keys( $customer_ids ) !== range( 0, count( $customer_ids ) - 1 ) ) {
88 return false;
89 }
90
91 $owned = (array) $user->customerIds();
92
93 // check each one.
94 foreach ( $customer_ids as $id ) {
95 if ( ! is_string( $id ) || '' === $id || ! in_array( $id, $owned, true ) ) {
96 return false; // this id does not belong to the user.
97 }
98 }
99
100 return true;
101 }
102
103 /**
104 * Check permissions for specific properties of the request.
105 *
106 * @param \WP_REST_Request $request Full details about the request.
107 * @param array $keys Keys to check.
108 *
109 * @return boolean
110 */
111 protected function requestOnlyHasKeys( $request, $keys ) {
112 $keys = array_merge( $keys, [ 'context', '_locale', 'rest_route', 'id', 'expand', 't' ] );
113 foreach ( (array) $request as $key => $value ) {
114 if ( ! in_array( $key, $keys, true ) ) {
115 return false;
116 }
117 }
118 return true;
119 }
120
121 /**
122 * Check permissions for specific properties of the request (has keys).
123 *
124 * @param \WP_REST_Request $request Full details about the request.
125 * @param array $keys Keys to check.
126 *
127 * @return boolean
128 */
129 protected function requestHasKeys( $request, $keys ) {
130 foreach ( (array) $request as $key => $value ) {
131 if ( in_array( $key, $keys, true ) ) {
132 return true;
133 }
134 }
135 return false;
136 }
137 }
138