| @@ -6,8 +6,9 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Settings; |
| 8 | 8 | |
| 9 | 9 | use Timetics\Base\Api; |
| 10 | +use Timetics\Core\Admin\Hooks; | |
| 10 | 11 | use Timetics\Utils\Singleton; |
| 11 | 12 | |
| 12 | 13 | class Api_Settings extends Api { |
| 13 | 14 | use Singleton; |
| @@ -44,9 +45,9 @@ | ||
| 44 | 45 | [ |
| 45 | 46 | 'methods' => \WP_REST_Server::EDITABLE, |
| 46 | 47 | 'callback' => [$this, 'update_settings'], |
| 47 | 48 | 'permission_callback' => function () { |
| 48 | - return true; | |
| 49 | + return current_user_can( 'manage_options' ); | |
| 49 | 50 | }, |
| 50 | 51 | ], |
| 51 | 52 | ] |
| 52 | 53 | ); |
| @@ -82,9 +83,19 @@ | ||
| 82 | 83 | * @return JSON |
| 83 | 84 | */ |
| 84 | 85 | public function get_settings() { |
| 85 | 86 | $settings = apply_filters( 'timetics_settings', timetics_get_settings() ); |
| 86 | - | |
| 87 | + $role = !current_user_can( 'manage_timetics' ); | |
| 88 | + //only run for non user capabilities | |
| 89 | + if ( $role ) { | |
| 90 | + $exclude_settings = $this->exclude_settings_for_customer(); | |
| 91 | + foreach($settings as $key => $setting){ | |
| 92 | + if( in_array( $key, $exclude_settings )){ | |
| 93 | + unset( $settings[$key] ); | |
| 94 | + } | |
| 95 | + } | |
| 96 | + } | |
| 97 | + | |
| 87 | 98 | $data = [ |
| 88 | 99 | 'status_code' => 200, |
| 89 | 100 | 'success' => 1, |
| 90 | 101 | 'message' => esc_html__( 'Get all settings', 'timetics' ), |
| @@ -230,6 +241,66 @@ | ||
| 230 | 241 | 'data' => $busyness_categories, |
| 231 | 242 | ]; |
| 232 | 243 | |
| 233 | 244 | return rest_ensure_response( $response ); |
| 245 | + } | |
| 246 | + | |
| 247 | + public function exclude_settings_for_customer() { | |
| 248 | + $allowed_keys = [ | |
| 249 | + "booking_created_customer_email_from", | |
| 250 | + "booking_created_customer_email_title", | |
| 251 | + "booking_created_customer_email_body", | |
| 252 | + "booking_created_host_email_from", | |
| 253 | + "booking_created_host_email_title", | |
| 254 | + "booking_created_host_email_body", | |
| 255 | + "booking_canceled_customer_email_from", | |
| 256 | + "booking_canceled_customer_email_title", | |
| 257 | + "booking_canceled_customer_email_body", | |
| 258 | + "booking_canceled_host_email_from", | |
| 259 | + "booking_canceled_host_email_title", | |
| 260 | + "booking_canceled_host_email_body", | |
| 261 | + "booking_rescheduled_customer_email_from", | |
| 262 | + "booking_rescheduled_customer_email_title", | |
| 263 | + "booking_rescheduled_customer_email_body", | |
| 264 | + "booking_rescheduled_host_email_from", | |
| 265 | + "booking_rescheduled_host_email_title", | |
| 266 | + "booking_rescheduled_host_email_body", | |
| 267 | + "booking_reminder_customer_email_from", | |
| 268 | + "booking_reminder_customer_email_title", | |
| 269 | + "booking_reminder_customer_email_body", | |
| 270 | + "booking_reminder_host_email_from", | |
| 271 | + "booking_reminder_host_email_title", | |
| 272 | + "booking_reminder_host_email_body", | |
| 273 | + "google_auth_redirect_uri", | |
| 274 | + "google_app_client_id", | |
| 275 | + "google_app_client_secret", | |
| 276 | + "zoom_client_id", | |
| 277 | + "zoom_client_secret", | |
| 278 | + "zoom_auth_redirect_uri", | |
| 279 | + "apple_calendar", | |
| 280 | + "outlook_calendar", | |
| 281 | + "fluentcrm_webhook", | |
| 282 | + "zapier_webhook", | |
| 283 | + "twillo_account_id", | |
| 284 | + "twillo_token", | |
| 285 | + "twillo_phone_number", | |
| 286 | + "booking_created_customer", | |
| 287 | + "booking_created_host", | |
| 288 | + "booking_canceled_customer", | |
| 289 | + "booking_canceled_host", | |
| 290 | + "booking_rescheduled_customer", | |
| 291 | + "booking_rescheduled_host", | |
| 292 | + "booking_reminder_customer", | |
| 293 | + "booking_reminder_host", | |
| 294 | + "stripe_pub_key", | |
| 295 | + "stripe_secret_key", | |
| 296 | + "paypal_client_id", | |
| 297 | + "paypal_client_secret", | |
| 298 | + "outlook_client_id", | |
| 299 | + "outlook_client_secret", | |
| 300 | + "outlook_auth_redirect_uri", | |
| 301 | + ]; | |
| 302 | + | |
| 303 | + | |
| 304 | + return $allowed_keys; | |
| 234 | 305 | } |
| 235 | 306 | } |