| @@ -14,12 +14,9 @@ | ||
| 14 | 14 | $this->get( 'profile/purchased-items', [ $this, 'get_my_purchased_items' ] ); |
| 15 | 15 | } |
| 16 | 16 | |
| 17 | 17 | public function sync() { |
| 18 | - // Keep the `subscription` field set in step with `Login::login()` — the | |
| 19 | - // Subscription screen renders from whichever of the two answered last, so a | |
| 20 | - // field missing here silently degrades the card after a profile sync. | |
| 21 | - $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, is_restricted_company_user, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating }, subscription { id, name, sites, subscription_plan_id, ends_at, plan_type, cancel_at_period_end } }'; | |
| 18 | + $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating } }'; | |
| 22 | 19 | |
| 23 | 20 | $funcArgs = [ |
| 24 | 21 | 'api_key' => $this->api_key, |
| 25 | 22 | 'site_url' => home_url( '/' ), |
| @@ -68,15 +65,8 @@ | ||
| 68 | 65 | $meta['reviews'] = $_reviews; |
| 69 | 66 | } |
| 70 | 67 | |
| 71 | 68 | if ( ! empty( $response['user'] ) && is_array( $response['user'] ) ) { |
| 72 | - /** | |
| 73 | - * The cloud API key must never be persisted here or sent to the client. | |
| 74 | - * Under a global login this key belongs to the admin, while any user with | |
| 75 | - * `delete_posts` can reach this endpoint. Login and SignUp already drop it. | |
| 76 | - */ | |
| 77 | - unset( $response['user']['api_key'] ); | |
| 78 | - | |
| 79 | 69 | $response['user']['site_url'] = base64_encode( home_url( '/' ) ); |
| 80 | 70 | $response['user']['ip'] = Helper::get_ip(); |
| 81 | 71 | } |
| 82 | 72 | |