PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/api-staff.php +11 -9 1.0.61 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
10 12 use Timetics\Core\Integrations\Google\Client;
11 13 use Timetics\Core\Staffs\Staff;
12 14 use Timetics\Utils\Singleton;
@@ -58,9 +60,9 @@
58 60 [
59 61 'methods' => \WP_REST_Server::DELETABLE,
60 62 'callback' => [$this, 'bulk_delete'],
61 63 'permission_callback' => function () {
62 - return current_user_can( 'manage_timetics' );
64 + return current_user_can( 'manage_options' );
63 65 },
64 66 ],
65 67 ]
66 68 );
@@ -81,10 +83,10 @@
81 83 ],
82 84 [
83 85 'methods' => \WP_REST_Server::EDITABLE,
84 86 'callback' => [$this, 'update_item'],
85 - 'permission_callback' => function () {
86 - return current_user_can( 'manage_timetics' );
87 + 'permission_callback' => function ( $request ) {
88 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
87 89 },
88 90 ],
89 91 [
90 92 'methods' => \WP_REST_Server::DELETABLE,
@@ -89,9 +91,9 @@
89 91 [
90 92 'methods' => \WP_REST_Server::DELETABLE,
91 93 'callback' => [$this, 'delete_item'],
92 94 'permission_callback' => function () {
93 - return current_user_can( 'manage_timetics' );
95 + return current_user_can( 'manage_options' );
94 96 },
95 97 ],
96 98 [
97 99 'methods' => \WP_REST_Server::READABLE,
@@ -108,9 +110,9 @@
108 110 [
109 111 'methods' => \WP_REST_Server::READABLE,
110 112 'callback' => [$this, 're_invite_staff'],
111 113 'permission_callback' => function () {
112 - return current_user_can( 'manage_timetics' );
114 + return current_user_can( 'manage_options' );
113 115 },
114 116 ],
115 117 ]
116 118 );
@@ -131,10 +133,10 @@
131 133 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations', [
132 134 [
133 135 'methods' => \WP_REST_Server::READABLE,
134 136 'callback' => [$this, 'get_integrations'],
135 - 'permission_callback' => function () {
136 - return current_user_can( 'manage_timetics' );
137 + 'permission_callback' => function ( $request ) {
138 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
137 139 },
138 140 ],
139 141 ]
140 142 );
@@ -143,10 +145,10 @@
143 145 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations/auth-revoke', [
144 146 [
145 147 'methods' => \WP_REST_Server::READABLE,
146 148 'callback' => [$this, 'auth_revoke'],
147 - 'permission_callback' => function () {
148 - return current_user_can( 'manage_timetics' );
149 + 'permission_callback' => function ( $request ) {
150 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
149 151 },
150 152 ],
151 153 ]
152 154 );