| @@ -14,9 +14,12 @@ | ||
| 14 | 14 | $this->get( 'profile/purchased-items', [ $this, 'get_my_purchased_items' ] ); |
| 15 | 15 | } |
| 16 | 16 | |
| 17 | 17 | public function sync() { |
| 18 | - $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating } }'; | |
| 18 | + // Keep the `subscription` field set in step with `Login::login()` — the | |
| 19 | + // Subscription screen renders from whichever of the two answered last, so a | |
| 20 | + // field missing here silently degrades the card after a profile sync. | |
| 21 | + $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, is_restricted_company_user, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating }, subscription { id, name, sites, subscription_plan_id, ends_at, plan_type, cancel_at_period_end } }'; | |
| 19 | 22 | |
| 20 | 23 | $funcArgs = [ |
| 21 | 24 | 'api_key' => $this->api_key, |
| 22 | 25 | 'site_url' => home_url( '/' ), |
| @@ -65,8 +68,15 @@ | ||
| 65 | 68 | $meta['reviews'] = $_reviews; |
| 66 | 69 | } |
| 67 | 70 | |
| 68 | 71 | if ( ! empty( $response['user'] ) && is_array( $response['user'] ) ) { |
| 72 | + /** | |
| 73 | + * The cloud API key must never be persisted here or sent to the client. | |
| 74 | + * Under a global login this key belongs to the admin, while any user with | |
| 75 | + * `delete_posts` can reach this endpoint. Login and SignUp already drop it. | |
| 76 | + */ | |
| 77 | + unset( $response['user']['api_key'] ); | |
| 78 | + | |
| 69 | 79 | $response['user']['site_url'] = base64_encode( home_url( '/' ) ); |
| 70 | 80 | $response['user']['ip'] = Helper::get_ip(); |
| 71 | 81 | } |
| 72 | 82 | |