| @@ -124,12 +124,30 @@ | ||
| 124 | 124 | * @param $request WP_REST_Request for getting all route request in time. |
| 125 | 125 | * |
| 126 | 126 | * @return WP_Error|boolean |
| 127 | 127 | */ |
| 128 | + public function _permission_check( WP_REST_Request $request ) { | |
| 129 | + $this->request = $request; | |
| 130 | + $this->api_key = $this->utils('options')->get( 'api_key' ); | |
| 131 | + if(!current_user_can('delete_posts')){ | |
| 132 | + return false; | |
| 133 | + } | |
| 134 | + | |
| 135 | + add_filter('wp_redirect', '__return_false', 999); | |
| 136 | + | |
| 137 | + return $this->permission_check( $request ); | |
| 138 | + } | |
| 139 | + | |
| 140 | + /** | |
| 141 | + * @param $request WP_REST_Request for getting all route request in time. | |
| 142 | + * | |
| 143 | + * @return WP_Error|boolean | |
| 144 | + */ | |
| 128 | 145 | public function permission_check( WP_REST_Request $request ) { |
| 129 | 146 | $this->request = $request; |
| 130 | 147 | $this->api_key = $this->utils('options')->get( 'api_key' ); |
| 131 | 148 | |
| 149 | + | |
| 132 | 150 | if ( ! empty( $this->api_key ) ) { |
| 133 | 151 | return true; |
| 134 | 152 | } |
| 135 | 153 | |
| @@ -144,9 +162,9 @@ | ||
| 144 | 162 | * @return WP_Error |
| 145 | 163 | */ |
| 146 | 164 | protected function permission_error( $message, $endpoint = '') { |
| 147 | 165 | if( empty( $message ) ) { |
| 148 | - $message = __( 'Sorry, you need to login/re-login again.', 'templately' ); | |
| 166 | + $message = __( 'Your session has expired. Please log in again.', 'templately' ); | |
| 149 | 167 | } |
| 150 | 168 | |
| 151 | 169 | $_additional_data = [ |
| 152 | 170 | 'status' => rest_authorization_required_code(), |
| @@ -155,18 +173,27 @@ | ||
| 155 | 173 | if( ! empty( $endpoint ) ) { |
| 156 | 174 | $_additional_data['endpoint'] = $endpoint; |
| 157 | 175 | } |
| 158 | 176 | |
| 159 | - // Delete user logged meta data | |
| 160 | - $this->utils('options') | |
| 161 | - ->remove('user') | |
| 162 | - ->remove('favourites') | |
| 163 | - ->remove('reviews') | |
| 164 | - ->remove('cloud_activity') | |
| 165 | - ->remove('api_key'); | |
| 177 | + // Delete user logged meta data — pinned to the acting user, otherwise | |
| 178 | + // Options::user_id() resolves a linked user to the global-login | |
| 179 | + // administrator and clears the administrator's session instead. | |
| 180 | + $options = $this->utils('options'); | |
| 181 | + $options->use_current_user( true ); | |
| 166 | 182 | |
| 167 | - if( $this->utils('options')->who_am_i() === 'global' ) { | |
| 168 | - $this->utils('options')->remove_global_login(); | |
| 183 | + try { | |
| 184 | + $options | |
| 185 | + ->remove('user') | |
| 186 | + ->remove('favourites') | |
| 187 | + ->remove('reviews') | |
| 188 | + ->remove('cloud_activity') | |
| 189 | + ->remove('api_key'); | |
| 190 | + | |
| 191 | + if( $options->who_am_i() === 'global' ) { | |
| 192 | + $options->remove_global_login(); | |
| 193 | + } | |
| 194 | + } finally { | |
| 195 | + $options->use_current_user( false ); | |
| 169 | 196 | } |
| 170 | 197 | |
| 171 | 198 | return new WP_Error( 'invalid_api_key', $message, $_additional_data ); |
| 172 | 199 | } |
| @@ -184,9 +211,9 @@ | ||
| 184 | 211 | $endpoint, |
| 185 | 212 | [ |
| 186 | 213 | 'methods' => $methods, |
| 187 | 214 | 'callback' => $callback, |
| 188 | - 'permission_callback' => [ $this, 'permission_check' ], | |
| 215 | + 'permission_callback' => [ $this, '_permission_check' ], | |
| 189 | 216 | 'args' => $args, |
| 190 | 217 | ] |
| 191 | 218 | ); |
| 192 | 219 | } |
| @@ -211,8 +238,24 @@ | ||
| 211 | 238 | * @return WP_REST_Response |
| 212 | 239 | */ |
| 213 | 240 | public function success( $data ) { |
| 214 | 241 | return new WP_REST_Response( $data, 200 ); |
| 242 | + } | |
| 243 | + | |
| 244 | + /** | |
| 245 | + * Enhanced success response wrapper that automatically adds success flag and wraps data | |
| 246 | + * | |
| 247 | + * @param $data mixed The data to be wrapped in the response | |
| 248 | + * | |
| 249 | + * @return WP_REST_Response | |
| 250 | + */ | |
| 251 | + public function successWithData( $data ) { | |
| 252 | + $enhanced_response = [ | |
| 253 | + 'success' => true, | |
| 254 | + 'data' => $data | |
| 255 | + ]; | |
| 256 | + | |
| 257 | + return $this->success( $enhanced_response ); | |
| 215 | 258 | } |
| 216 | 259 | /** |
| 217 | 260 | * @param $error_code string |
| 218 | 261 | * @param $error_message string|array |