PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 3.7.2
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v3.7.2
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/API/API.php +53 -11 3.1.13.7.2 View file →
@@ -124,8 +124,25 @@
124 124 * @param $request WP_REST_Request for getting all route request in time.
125 125 *
126 126 * @return WP_Error|boolean
127 127 */
128 + public function _permission_check( WP_REST_Request $request ) {
129 + $this->request = $request;
130 + $this->api_key = $this->utils('options')->get( 'api_key' );
131 + if(!current_user_can('delete_posts')){
132 + return false;
133 + }
134 +
135 + add_filter('wp_redirect', '__return_false', 999);
136 +
137 + return $this->permission_check( $request );
138 + }
139 +
140 + /**
141 + * @param $request WP_REST_Request for getting all route request in time.
142 + *
143 + * @return WP_Error|boolean
144 + */
128 145 public function permission_check( WP_REST_Request $request ) {
129 146 $this->request = $request;
130 147 $this->api_key = $this->utils('options')->get( 'api_key' );
131 148
@@ -145,9 +162,9 @@
145 162 * @return WP_Error
146 163 */
147 164 protected function permission_error( $message, $endpoint = '') {
148 165 if( empty( $message ) ) {
149 - $message = __( 'Sorry, you need to login/re-login again.', 'templately' );
166 + $message = __( 'Your session has expired. Please log in again.', 'templately' );
150 167 }
151 168
152 169 $_additional_data = [
153 170 'status' => rest_authorization_required_code(),
@@ -156,18 +173,27 @@
156 173 if( ! empty( $endpoint ) ) {
157 174 $_additional_data['endpoint'] = $endpoint;
158 175 }
159 176
160 - // Delete user logged meta data
161 - $this->utils('options')
162 - ->remove('user')
163 - ->remove('favourites')
164 - ->remove('reviews')
165 - ->remove('cloud_activity')
166 - ->remove('api_key');
177 + // Delete user logged meta data — pinned to the acting user, otherwise
178 + // Options::user_id() resolves a linked user to the global-login
179 + // administrator and clears the administrator's session instead.
180 + $options = $this->utils('options');
181 + $options->use_current_user( true );
167 182
168 - if( $this->utils('options')->who_am_i() === 'global' ) {
169 - $this->utils('options')->remove_global_login();
183 + try {
184 + $options
185 + ->remove('user')
186 + ->remove('favourites')
187 + ->remove('reviews')
188 + ->remove('cloud_activity')
189 + ->remove('api_key');
190 +
191 + if( $options->who_am_i() === 'global' ) {
192 + $options->remove_global_login();
193 + }
194 + } finally {
195 + $options->use_current_user( false );
170 196 }
171 197
172 198 return new WP_Error( 'invalid_api_key', $message, $_additional_data );
173 199 }
@@ -185,9 +211,9 @@
185 211 $endpoint,
186 212 [
187 213 'methods' => $methods,
188 214 'callback' => $callback,
189 - 'permission_callback' => [ $this, 'permission_check' ],
215 + 'permission_callback' => [ $this, '_permission_check' ],
190 216 'args' => $args,
191 217 ]
192 218 );
193 219 }
@@ -212,8 +238,24 @@
212 238 * @return WP_REST_Response
213 239 */
214 240 public function success( $data ) {
215 241 return new WP_REST_Response( $data, 200 );
242 + }
243 +
244 + /**
245 + * Enhanced success response wrapper that automatically adds success flag and wraps data
246 + *
247 + * @param $data mixed The data to be wrapped in the response
248 + *
249 + * @return WP_REST_Response
250 + */
251 + public function successWithData( $data ) {
252 + $enhanced_response = [
253 + 'success' => true,
254 + 'data' => $data
255 + ];
256 +
257 + return $this->success( $enhanced_response );
216 258 }
217 259 /**
218 260 * @param $error_code string
219 261 * @param $error_message string|array