PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/staff.php +11 -8 1.0.59 → 1.0.64 View file →
@@ -331,12 +331,13 @@
331 331 }
332 332
333 333 $user = get_user_by( 'email', $email );
334 334
335 - if ( $user && ! in_array( 'timetics-staff', $user->roles, true ) ) {
336 - $user->add_role( 'timetics-staff' );
337 -
338 - return $user->ID;
335 + // An existing account with this email is a conflict, not an instruction
336 + // to promote it — silently granting the staff role let a caller take
337 + // over any account by submitting its email.
338 + if ( $user ) {
339 + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) );
339 340 }
340 341
341 342 $user_id = wp_insert_user( $args );
342 343
@@ -367,12 +368,14 @@
367 368 }
368 369
369 370 $user_data = get_user_by( 'email', $email );
370 371
371 - if ( $user_data && ! in_array( 'timetics-staff', $user_data->roles, true ) ) {
372 - $user_data->add_role( 'timetics-staff' );
373 -
374 - return $user_data->ID;
372 + // Only a conflict if it belongs to someone other than the staff member
373 + // being edited — otherwise every update where they keep their own
374 + // email would (incorrectly) hit this branch. See create() for why a
375 + // match must never silently grant the staff role.
376 + if ( $user_data && (int) $user_data->ID !== (int) $this->id ) {
377 + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) );
375 378 }
376 379
377 380 $updated = wp_update_user( $user );
378 381