← All changes
|
vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php
+30
-28
1.0.60
→
1.0.64
View file →
| @@ -62,28 +62,19 @@ | ||
| 62 | 62 | [ |
| 63 | 63 | [ // Create |
| 64 | 64 | 'methods' => \WP_REST_Server::CREATABLE, |
| 65 | 65 | 'callback' => [$this, 'create_item'], |
| 66 | - 'permission_callback' => function () { | |
| 67 | - // return current_user_can( 'manage_options' ); | |
| 68 | - return true; | |
| 69 | - }, | |
| 66 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 70 | 67 | ], |
| 71 | 68 | [ // Bulk delete |
| 72 | 69 | 'methods' => \WP_REST_Server::DELETABLE, |
| 73 | 70 | 'callback' => [$this, 'bulk_delete'], |
| 74 | - 'permission_callback' => function () { | |
| 75 | - // return current_user_can( 'manage_options' ); | |
| 76 | - return true; | |
| 77 | - }, | |
| 71 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 78 | 72 | ], |
| 79 | 73 | [ // show list |
| 80 | 74 | 'methods' => \WP_REST_Server::READABLE, |
| 81 | 75 | 'callback' => [$this, 'get_items'], |
| 82 | - 'permission_callback' => function () { | |
| 83 | - // return current_user_can( 'manage_options' ); | |
| 84 | - return true; | |
| 85 | - }, | |
| 76 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 86 | 77 | ], |
| 87 | 78 | ] |
| 88 | 79 | ); |
| 89 | 80 | |
| @@ -90,28 +81,19 @@ | ||
| 90 | 81 | register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)', [ |
| 91 | 82 | [ // Get single flow |
| 92 | 83 | 'methods' => \WP_REST_Server::READABLE, |
| 93 | 84 | 'callback' => [$this, 'get_item'], |
| 94 | - 'permission_callback' => function () { | |
| 95 | - // return current_user_can( 'manage_options' ); | |
| 96 | - return true; | |
| 97 | - }, | |
| 85 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 98 | 86 | ], |
| 99 | 87 | [ // Update single flow |
| 100 | 88 | 'methods' => \WP_REST_Server::EDITABLE, |
| 101 | 89 | 'callback' => [$this, 'update_item'], |
| 102 | - 'permission_callback' => function () { | |
| 103 | - // return current_user_can( 'manage_options' ); | |
| 104 | - return true; | |
| 105 | - }, | |
| 90 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 106 | 91 | ], |
| 107 | 92 | [ // Delete single flow |
| 108 | 93 | 'methods' => \WP_REST_Server::DELETABLE, |
| 109 | 94 | 'callback' => [$this, 'delete_item'], |
| 110 | - 'permission_callback' => function () { | |
| 111 | - // return current_user_can( 'manage_options' ); | |
| 112 | - return true; | |
| 113 | - }, | |
| 95 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 114 | 96 | ], |
| 115 | 97 | ] ); |
| 116 | 98 | |
| 117 | 99 | register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)' . '/clone', [ |
| @@ -117,14 +99,34 @@ | ||
| 117 | 99 | register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)' . '/clone', [ |
| 118 | 100 | [ // Clone flow |
| 119 | 101 | 'methods' => \WP_REST_Server::CREATABLE, |
| 120 | 102 | 'callback' => [$this, 'clone_item'], |
| 121 | - 'permission_callback' => function () { | |
| 122 | - // return current_user_can( 'manage_options' ); | |
| 123 | - return true; | |
| 124 | - }, | |
| 103 | + 'permission_callback' => [ $this, 'permissions_check' ], | |
| 125 | 104 | ], |
| 126 | 105 | ] ); |
| 106 | + } | |
| 107 | + | |
| 108 | + /** | |
| 109 | + * Check that the current user is allowed to manage notification flows. | |
| 110 | + * | |
| 111 | + * Every flow route is administrative: flows control the content and | |
| 112 | + * recipients of the emails the site sends out. They must never be | |
| 113 | + * reachable by unauthenticated visitors. | |
| 114 | + * | |
| 115 | + * @since 1.0.0 | |
| 116 | + * | |
| 117 | + * @param \WP_REST_Request $request | |
| 118 | + * | |
| 119 | + * @return bool | |
| 120 | + */ | |
| 121 | + public function permissions_check( $request ) { | |
| 122 | + $can = current_user_can( 'manage_options' ); | |
| 123 | + | |
| 124 | + return (bool) apply_filters( | |
| 125 | + Helpers::get_hook_name( $this->identifier, 'ens_flow_permission' ), | |
| 126 | + $can, | |
| 127 | + $request | |
| 128 | + ); | |
| 127 | 129 | } |
| 128 | 130 | |
| 129 | 131 | /** |
| 130 | 132 | * Create flow |