PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.14.0
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.14.0
2.14.0 2.13.0 2.12.0 2.11.0 2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 1.27.0 1.26.0 All 55 releases
← All changes | includes/api/class-email-report-endpoint.php +7 -2 2.12.0 → 2.14.0 View file →
@@ -18,8 +18,9 @@
18 18
19 19 namespace ThinkRank\API;
20 20
21 21 use ThinkRank\API\Traits\CSRF_Protection;
22 +use ThinkRank\Core\Capability_Manager;
22 23 use ThinkRank\SEO\Email_Report_Manager;
23 24 use WP_REST_Controller;
24 25 use WP_REST_Request;
25 26 use WP_REST_Response;
@@ -164,9 +165,11 @@
164 165 public function check_admin_read_permissions(WP_REST_Request $request) {
165 166 if (!is_user_logged_in()) {
166 167 return new WP_Error('rest_forbidden', __('Not logged in.', 'thinkrank'), ['status' => 401]);
167 168 }
168 - if (!current_user_can('manage_options')) {
169 + // route_map() maps the email-report prefix to thinkrank_analytics,
170 + // which is what an Analytics grant in the Role Manager gives (#844).
171 + if (!Capability_Manager::current_user_can('thinkrank_analytics')) {
169 172 return new WP_Error('rest_forbidden', __('Insufficient permissions.', 'thinkrank'), ['status' => 403]);
170 173 }
171 174 return true;
172 175 }
@@ -183,9 +186,11 @@
183 186 public function check_admin_csrf_permissions(WP_REST_Request $request) {
184 187 if (!is_user_logged_in()) {
185 188 return new WP_Error('rest_forbidden', __('Not logged in.', 'thinkrank'), ['status' => 401]);
186 189 }
187 - if (!current_user_can('manage_options')) {
190 + // route_map() maps the email-report prefix to thinkrank_analytics,
191 + // which is what an Analytics grant in the Role Manager gives (#844).
192 + if (!Capability_Manager::current_user_can('thinkrank_analytics')) {
188 193 return new WP_Error('rest_forbidden', __('Insufficient permissions.', 'thinkrank'), ['status' => 403]);
189 194 }
190 195 if (!$this->verify_request_nonce($request)) {
191 196 return new WP_Error('rest_forbidden', __('Invalid security token. Please refresh the page and try again.', 'thinkrank'), ['status' => 403]);