| @@ -5,8 +5,10 @@ | ||
| 5 | 5 | * @package Timetics |
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Staffs; |
| 8 | 8 | |
| 9 | +defined( 'ABSPATH' ) || exit; | |
| 10 | + | |
| 9 | 11 | use Timetics\Base\Api; |
| 10 | 12 | use Timetics\Core\Integrations\Google\Client; |
| 11 | 13 | use Timetics\Core\Staffs\Staff; |
| 12 | 14 | use Timetics\Utils\Singleton; |
| @@ -58,9 +60,9 @@ | ||
| 58 | 60 | [ |
| 59 | 61 | 'methods' => \WP_REST_Server::DELETABLE, |
| 60 | 62 | 'callback' => [$this, 'bulk_delete'], |
| 61 | 63 | 'permission_callback' => function () { |
| 62 | - return current_user_can( 'manage_timetics' ); | |
| 64 | + return current_user_can( 'manage_options' ); | |
| 63 | 65 | }, |
| 64 | 66 | ], |
| 65 | 67 | ] |
| 66 | 68 | ); |
| @@ -81,10 +83,10 @@ | ||
| 81 | 83 | ], |
| 82 | 84 | [ |
| 83 | 85 | 'methods' => \WP_REST_Server::EDITABLE, |
| 84 | 86 | 'callback' => [$this, 'update_item'], |
| 85 | - 'permission_callback' => function () { | |
| 86 | - return current_user_can( 'manage_timetics' ); | |
| 87 | + 'permission_callback' => function ( $request ) { | |
| 88 | + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id(); | |
| 87 | 89 | }, |
| 88 | 90 | ], |
| 89 | 91 | [ |
| 90 | 92 | 'methods' => \WP_REST_Server::DELETABLE, |
| @@ -89,9 +91,9 @@ | ||
| 89 | 91 | [ |
| 90 | 92 | 'methods' => \WP_REST_Server::DELETABLE, |
| 91 | 93 | 'callback' => [$this, 'delete_item'], |
| 92 | 94 | 'permission_callback' => function () { |
| 93 | - return current_user_can( 'manage_timetics' ); | |
| 95 | + return current_user_can( 'manage_options' ); | |
| 94 | 96 | }, |
| 95 | 97 | ], |
| 96 | 98 | [ |
| 97 | 99 | 'methods' => \WP_REST_Server::READABLE, |
| @@ -108,9 +110,9 @@ | ||
| 108 | 110 | [ |
| 109 | 111 | 'methods' => \WP_REST_Server::READABLE, |
| 110 | 112 | 'callback' => [$this, 're_invite_staff'], |
| 111 | 113 | 'permission_callback' => function () { |
| 112 | - return current_user_can( 'manage_timetics' ); | |
| 114 | + return current_user_can( 'manage_options' ); | |
| 113 | 115 | }, |
| 114 | 116 | ], |
| 115 | 117 | ] |
| 116 | 118 | ); |
| @@ -131,10 +133,10 @@ | ||
| 131 | 133 | $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations', [ |
| 132 | 134 | [ |
| 133 | 135 | 'methods' => \WP_REST_Server::READABLE, |
| 134 | 136 | 'callback' => [$this, 'get_integrations'], |
| 135 | - 'permission_callback' => function () { | |
| 136 | - return current_user_can( 'manage_timetics' ); | |
| 137 | + 'permission_callback' => function ( $request ) { | |
| 138 | + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id(); | |
| 137 | 139 | }, |
| 138 | 140 | ], |
| 139 | 141 | ] |
| 140 | 142 | ); |
| @@ -143,10 +145,10 @@ | ||
| 143 | 145 | $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations/auth-revoke', [ |
| 144 | 146 | [ |
| 145 | 147 | 'methods' => \WP_REST_Server::READABLE, |
| 146 | 148 | 'callback' => [$this, 'auth_revoke'], |
| 147 | - 'permission_callback' => function () { | |
| 148 | - return current_user_can( 'manage_timetics' ); | |
| 149 | + 'permission_callback' => function ( $request ) { | |
| 150 | + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id(); | |
| 149 | 151 | }, |
| 150 | 152 | ], |
| 151 | 153 | ] |
| 152 | 154 | ); |
| @@ -496,9 +498,8 @@ | ||
| 496 | 498 | |
| 497 | 499 | return new WP_HTTP_Response( $data, 404 ); |
| 498 | 500 | } |
| 499 | 501 | |
| 500 | - $token = timetics_get_google_access_token( $staff_id ); | |
| 501 | 502 | $client = new Client(); |
| 502 | 503 | |
| 503 | 504 | $revoked = false; |
| 504 | 505 | |
| @@ -503,13 +504,21 @@ | ||
| 503 | 504 | $revoked = false; |
| 504 | 505 | |
| 505 | 506 | switch( $integration ) { |
| 506 | 507 | case 'google-auth': |
| 507 | - $revoked = $client->revoke( $token ); | |
| 508 | - if ( $revoked ) { | |
| 509 | - update_user_meta( $staff_id, 'timetics_google_auth', '' ); | |
| 508 | + $refresh_token = timetics_get_google_refresh_token( $staff_id ); | |
| 509 | + if ( ! empty( $refresh_token ) ) { | |
| 510 | + $client->revoke( $refresh_token ); | |
| 510 | 511 | } |
| 511 | 512 | |
| 513 | + // Always clear ALL local Google credentials so the account can be reconnected cleanly. | |
| 514 | + delete_user_meta( $staff_id, 'timetics_google_auth' ); | |
| 515 | + delete_user_meta( $staff_id, 'timetics_google_refresh_token' ); | |
| 516 | + delete_user_meta( $staff_id, 'timetics_google_auth_code' ); | |
| 517 | + delete_user_meta( $staff_id, 'timetics_google_auth_error' ); | |
| 518 | + | |
| 519 | + $revoked = true; | |
| 520 | + | |
| 512 | 521 | break; |
| 513 | 522 | case 'zoom-auth': |
| 514 | 523 | $revoked = true; |
| 515 | 524 | update_user_meta( $staff_id, 'timetics_zoom_token', '' ); |
| @@ -669,9 +678,9 @@ | ||
| 669 | 678 | } |
| 670 | 679 | |
| 671 | 680 | return $data; |
| 672 | 681 | } |
| 673 | - | |
| 682 | + | |
| 674 | 683 | /** |
| 675 | 684 | * Get items permission callback |
| 676 | 685 | * |
| 677 | 686 | * @param WP_Rest_Request $request |