| @@ -125,12 +125,16 @@ | ||
| 125 | 125 | * |
| 126 | 126 | * @return WP_Error|boolean |
| 127 | 127 | */ |
| 128 | 128 | public function _permission_check( WP_REST_Request $request ) { |
| 129 | + $this->request = $request; | |
| 130 | + $this->api_key = $this->utils('options')->get( 'api_key' ); | |
| 129 | 131 | if(!current_user_can('delete_posts')){ |
| 130 | 132 | return false; |
| 131 | 133 | } |
| 132 | 134 | |
| 135 | + add_filter('wp_redirect', '__return_false', 999); | |
| 136 | + | |
| 133 | 137 | return $this->permission_check( $request ); |
| 134 | 138 | } |
| 135 | 139 | |
| 136 | 140 | /** |
| @@ -158,9 +162,9 @@ | ||
| 158 | 162 | * @return WP_Error |
| 159 | 163 | */ |
| 160 | 164 | protected function permission_error( $message, $endpoint = '') { |
| 161 | 165 | if( empty( $message ) ) { |
| 162 | - $message = __( 'Sorry, you need to login/re-login again.', 'templately' ); | |
| 166 | + $message = __( 'Your session has expired. Please log in again.', 'templately' ); | |
| 163 | 167 | } |
| 164 | 168 | |
| 165 | 169 | $_additional_data = [ |
| 166 | 170 | 'status' => rest_authorization_required_code(), |
| @@ -169,18 +173,27 @@ | ||
| 169 | 173 | if( ! empty( $endpoint ) ) { |
| 170 | 174 | $_additional_data['endpoint'] = $endpoint; |
| 171 | 175 | } |
| 172 | 176 | |
| 173 | - // Delete user logged meta data | |
| 174 | - $this->utils('options') | |
| 175 | - ->remove('user') | |
| 176 | - ->remove('favourites') | |
| 177 | - ->remove('reviews') | |
| 178 | - ->remove('cloud_activity') | |
| 179 | - ->remove('api_key'); | |
| 177 | + // Delete user logged meta data — pinned to the acting user, otherwise | |
| 178 | + // Options::user_id() resolves a linked user to the global-login | |
| 179 | + // administrator and clears the administrator's session instead. | |
| 180 | + $options = $this->utils('options'); | |
| 181 | + $options->use_current_user( true ); | |
| 180 | 182 | |
| 181 | - if( $this->utils('options')->who_am_i() === 'global' ) { | |
| 182 | - $this->utils('options')->remove_global_login(); | |
| 183 | + try { | |
| 184 | + $options | |
| 185 | + ->remove('user') | |
| 186 | + ->remove('favourites') | |
| 187 | + ->remove('reviews') | |
| 188 | + ->remove('cloud_activity') | |
| 189 | + ->remove('api_key'); | |
| 190 | + | |
| 191 | + if( $options->who_am_i() === 'global' ) { | |
| 192 | + $options->remove_global_login(); | |
| 193 | + } | |
| 194 | + } finally { | |
| 195 | + $options->use_current_user( false ); | |
| 183 | 196 | } |
| 184 | 197 | |
| 185 | 198 | return new WP_Error( 'invalid_api_key', $message, $_additional_data ); |
| 186 | 199 | } |
| @@ -225,8 +238,24 @@ | ||
| 225 | 238 | * @return WP_REST_Response |
| 226 | 239 | */ |
| 227 | 240 | public function success( $data ) { |
| 228 | 241 | return new WP_REST_Response( $data, 200 ); |
| 242 | + } | |
| 243 | + | |
| 244 | + /** | |
| 245 | + * Enhanced success response wrapper that automatically adds success flag and wraps data | |
| 246 | + * | |
| 247 | + * @param $data mixed The data to be wrapped in the response | |
| 248 | + * | |
| 249 | + * @return WP_REST_Response | |
| 250 | + */ | |
| 251 | + public function successWithData( $data ) { | |
| 252 | + $enhanced_response = [ | |
| 253 | + 'success' => true, | |
| 254 | + 'data' => $data | |
| 255 | + ]; | |
| 256 | + | |
| 257 | + return $this->success( $enhanced_response ); | |
| 229 | 258 | } |
| 230 | 259 | /** |
| 231 | 260 | * @param $error_code string |
| 232 | 261 | * @param $error_message string|array |