PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/customers/api-customer.php +46 -19 1.0.60 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Customers;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
10 12 use Timetics\Core\Bookings\Api_Booking;
11 13 use Timetics\Utils\Singleton;
12 14 use WP_HTTP_Response;
@@ -57,9 +59,9 @@
57 59 [
58 60 'methods' => \WP_REST_Server::DELETABLE,
59 61 'callback' => [$this, 'bulk_delete'],
60 62 'permission_callback' => function () {
61 - return current_user_can( 'manage_timetics' );
63 + return current_user_can( 'manage_options' );
62 64 },
63 65 ],
64 66 ]
65 67 );
@@ -75,12 +77,17 @@
75 77 'methods' => \WP_REST_Server::READABLE,
76 78 'callback' => [$this, 'get_item'],
77 79 'permission_callback' => function ( $request ) {
78 80 $customer_id = (int) $request['customer_id'];
79 - if ( current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ) ) {
81 +
82 + if ( timetics_can_view_all_data() || get_current_user_id() === $customer_id ) {
80 83 return true;
81 84 }
82 - return current_user_can( 'timetics-customer' ) && get_current_user_id() === $customer_id;
85 +
86 + // manage_timetics is not admin-only — staff may only view a
87 + // customer they actually have a visible booking with.
88 + return current_user_can( 'manage_timetics' )
89 + && in_array( $customer_id, timetics_get_visible_customer_ids(), true );
83 90 },
84 91 ],
85 92 [
86 93 'methods' => \WP_REST_Server::EDITABLE,
@@ -120,12 +127,15 @@
120 127 'methods' => \WP_REST_Server::READABLE,
121 128 'callback' => [$this, 'get_bookings'],
122 129 'permission_callback' => function ( $request ) {
123 130 $customer_id = (int) $request['customer_id'];
124 - if ( current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ) ) {
131 +
132 + if ( timetics_can_view_all_data() || get_current_user_id() === $customer_id ) {
125 133 return true;
126 134 }
127 - return current_user_can( 'timetics-customer' ) && get_current_user_id() === $customer_id;
135 +
136 + return current_user_can( 'manage_timetics' )
137 + && in_array( $customer_id, timetics_get_visible_customer_ids(), true );
128 138 },
129 139 ],
130 140 ]
131 141 );
@@ -141,15 +151,20 @@
141 151 public function get_items( $request ) {
142 152 $per_page = ! empty( $request['per_page'] ) ? intval( $request['per_page'] ) : 20;
143 153 $paged = ! empty( $request['paged'] ) ? intval( $request['paged'] ) : 1;
144 154
145 - $customer = Customer::all(
146 - [
147 - 'number' => $per_page,
148 - 'paged' => $paged,
149 - ]
150 - );
155 + $args = [
156 + 'number' => $per_page,
157 + 'paged' => $paged,
158 + ];
151 159
160 + // Staff only see customers from their own bookings, administrators see everyone.
161 + if ( ! timetics_can_view_all_data() ) {
162 + $args['include'] = timetics_get_visible_customer_ids( get_current_user_id() );
163 + }
164 +
165 + $customer = Customer::all( $args );
166 +
152 167 $items = [];
153 168
154 169 foreach ( $customer['items'] as $item ) {
155 170 $items[] = $this->prepare_item( $item->ID );
@@ -214,15 +229,24 @@
214 229 $per_page = ! empty( $request['per_page'] ) ? intval( $request['per_page'] ) : 20;
215 230 $paged = ! empty( $request['paged'] ) ? intval( $request['paged'] ) : 1;
216 231 $search = ! empty( $request['search'] ) ? sanitize_text_field( $request['search'] ) : '';
217 232
233 + $query_args = array(
234 + 'role' => 'timetics-customer',
235 + 'number' => $per_page,
236 + 'paged' => $paged,
237 + );
238 +
239 + // Staff only see customers from their own bookings, administrators see everyone.
240 + if ( ! timetics_can_view_all_data() ) {
241 + $query_args['include'] = timetics_get_visible_customer_ids( get_current_user_id() );
242 + }
243 +
218 244 // Get search.
219 245 $users = new WP_User_Query(
220 - array(
221 - 'role' => 'timetics-customer',
222 - 'number' => $per_page,
223 - 'paged' => $paged,
224 -
246 + array_merge(
247 + $query_args,
248 + array(
225 249 // @codingStandardsIgnoreStart
226 250 'meta_query' => array(
227 251 'relation' => 'OR',
228 252 array(
@@ -246,8 +270,9 @@
246 270 'compare' => 'LIKE',
247 271 ),
248 272 ),
249 273 // @codingStandardsIgnoreEnd
274 + )
250 275 )
251 276 );
252 277
253 278 // Prepare items for response.
@@ -289,10 +314,12 @@
289 314 */
290 315 public function update_item_permission_callback( $request ) {
291 316 $customer_id = (int) $request['customer_id'];
292 317
293 - // Admins can always update any customer
294 - if ( current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ) ) {
318 + // Admins can always update any customer. manage_timetics is not
319 + // admin-only — every timetics-staff account has it — so it must not
320 + // grant edit access to someone else's customer record.
321 + if ( current_user_can( 'manage_options' ) ) {
295 322 return true;
296 323 }
297 324
298 325 // Customers can update themselves with a valid nonce
@@ -592,9 +619,9 @@
592 619 $items = [];
593 620 $booking = new Api_Booking();
594 621
595 622 foreach ( $bookings->posts as $item ) {
596 - $items[] = $booking->prepare_item( $item->ID );
623 + $items[] = $booking->prepare_item( $item->ID, false );
597 624 }
598 625
599 626 $data = [
600 627 'success' => 1,