| @@ -19,8 +19,9 @@ | ||
| 19 | 19 | declare(strict_types=1); |
| 20 | 20 | |
| 21 | 21 | namespace ThinkRank\API; |
| 22 | 22 | |
| 23 | +use ThinkRank\Core\Capability_Manager; | |
| 23 | 24 | use ThinkRank\SEO\Ai_Traffic_Tracker; |
| 24 | 25 | use WP_REST_Controller; |
| 25 | 26 | use WP_REST_Request; |
| 26 | 27 | use WP_REST_Response; |
| @@ -76,9 +77,13 @@ | ||
| 76 | 77 | * |
| 77 | 78 | * @return bool |
| 78 | 79 | */ |
| 79 | 80 | public function check_admin_permissions(): bool { |
| 80 | - return current_user_can('manage_options'); | |
| 81 | + // The capability the Role Manager actually writes against, not | |
| 82 | + // manage_options: `route_map()` maps this prefix to | |
| 83 | + // thinkrank_ai_insights and the matrix offers an "AI Insights" row, so | |
| 84 | + // demanding manage_options here made that grant do nothing (#844). | |
| 85 | + return Capability_Manager::current_user_can('thinkrank_ai_insights'); | |
| 81 | 86 | } |
| 82 | 87 | |
| 83 | 88 | /** |
| 84 | 89 | * AI traffic dashboard summary. |