PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/api-staff.php +23 -14 1.0.57 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
10 12 use Timetics\Core\Integrations\Google\Client;
11 13 use Timetics\Core\Staffs\Staff;
12 14 use Timetics\Utils\Singleton;
@@ -58,9 +60,9 @@
58 60 [
59 61 'methods' => \WP_REST_Server::DELETABLE,
60 62 'callback' => [$this, 'bulk_delete'],
61 63 'permission_callback' => function () {
62 - return current_user_can( 'manage_timetics' );
64 + return current_user_can( 'manage_options' );
63 65 },
64 66 ],
65 67 ]
66 68 );
@@ -81,10 +83,10 @@
81 83 ],
82 84 [
83 85 'methods' => \WP_REST_Server::EDITABLE,
84 86 'callback' => [$this, 'update_item'],
85 - 'permission_callback' => function () {
86 - return current_user_can( 'manage_timetics' );
87 + 'permission_callback' => function ( $request ) {
88 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
87 89 },
88 90 ],
89 91 [
90 92 'methods' => \WP_REST_Server::DELETABLE,
@@ -89,9 +91,9 @@
89 91 [
90 92 'methods' => \WP_REST_Server::DELETABLE,
91 93 'callback' => [$this, 'delete_item'],
92 94 'permission_callback' => function () {
93 - return current_user_can( 'manage_timetics' );
95 + return current_user_can( 'manage_options' );
94 96 },
95 97 ],
96 98 [
97 99 'methods' => \WP_REST_Server::READABLE,
@@ -108,9 +110,9 @@
108 110 [
109 111 'methods' => \WP_REST_Server::READABLE,
110 112 'callback' => [$this, 're_invite_staff'],
111 113 'permission_callback' => function () {
112 - return current_user_can( 'manage_timetics' );
114 + return current_user_can( 'manage_options' );
113 115 },
114 116 ],
115 117 ]
116 118 );
@@ -131,10 +133,10 @@
131 133 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations', [
132 134 [
133 135 'methods' => \WP_REST_Server::READABLE,
134 136 'callback' => [$this, 'get_integrations'],
135 - 'permission_callback' => function () {
136 - return current_user_can( 'manage_timetics' );
137 + 'permission_callback' => function ( $request ) {
138 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
137 139 },
138 140 ],
139 141 ]
140 142 );
@@ -143,10 +145,10 @@
143 145 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations/auth-revoke', [
144 146 [
145 147 'methods' => \WP_REST_Server::READABLE,
146 148 'callback' => [$this, 'auth_revoke'],
147 - 'permission_callback' => function () {
148 - return current_user_can( 'manage_timetics' );
149 + 'permission_callback' => function ( $request ) {
150 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
149 151 },
150 152 ],
151 153 ]
152 154 );
@@ -496,9 +498,8 @@
496 498
497 499 return new WP_HTTP_Response( $data, 404 );
498 500 }
499 501
500 - $token = timetics_get_google_access_token( $staff_id );
501 502 $client = new Client();
502 503
503 504 $revoked = false;
504 505
@@ -503,13 +504,21 @@
503 504 $revoked = false;
504 505
505 506 switch( $integration ) {
506 507 case 'google-auth':
507 - $revoked = $client->revoke( $token );
508 - if ( $revoked ) {
509 - update_user_meta( $staff_id, 'timetics_google_auth', '' );
508 + $refresh_token = timetics_get_google_refresh_token( $staff_id );
509 + if ( ! empty( $refresh_token ) ) {
510 + $client->revoke( $refresh_token );
510 511 }
511 512
513 + // Always clear ALL local Google credentials so the account can be reconnected cleanly.
514 + delete_user_meta( $staff_id, 'timetics_google_auth' );
515 + delete_user_meta( $staff_id, 'timetics_google_refresh_token' );
516 + delete_user_meta( $staff_id, 'timetics_google_auth_code' );
517 + delete_user_meta( $staff_id, 'timetics_google_auth_error' );
518 +
519 + $revoked = true;
520 +
512 521 break;
513 522 case 'zoom-auth':
514 523 $revoked = true;
515 524 update_user_meta( $staff_id, 'timetics_zoom_token', '' );
@@ -669,9 +678,9 @@
669 678 }
670 679
671 680 return $data;
672 681 }
673 -
682 +
674 683 /**
675 684 * Get items permission callback
676 685 *
677 686 * @param WP_Rest_Request $request