PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php +30 -28 1.0.62 → 1.0.64 View file →
@@ -62,28 +62,19 @@
62 62 [
63 63 [ // Create
64 64 'methods' => \WP_REST_Server::CREATABLE,
65 65 'callback' => [$this, 'create_item'],
66 - 'permission_callback' => function () {
67 - // return current_user_can( 'manage_options' );
68 - return true;
69 - },
66 + 'permission_callback' => [ $this, 'permissions_check' ],
70 67 ],
71 68 [ // Bulk delete
72 69 'methods' => \WP_REST_Server::DELETABLE,
73 70 'callback' => [$this, 'bulk_delete'],
74 - 'permission_callback' => function () {
75 - // return current_user_can( 'manage_options' );
76 - return true;
77 - },
71 + 'permission_callback' => [ $this, 'permissions_check' ],
78 72 ],
79 73 [ // show list
80 74 'methods' => \WP_REST_Server::READABLE,
81 75 'callback' => [$this, 'get_items'],
82 - 'permission_callback' => function () {
83 - // return current_user_can( 'manage_options' );
84 - return true;
85 - },
76 + 'permission_callback' => [ $this, 'permissions_check' ],
86 77 ],
87 78 ]
88 79 );
89 80
@@ -90,28 +81,19 @@
90 81 register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)', [
91 82 [ // Get single flow
92 83 'methods' => \WP_REST_Server::READABLE,
93 84 'callback' => [$this, 'get_item'],
94 - 'permission_callback' => function () {
95 - // return current_user_can( 'manage_options' );
96 - return true;
97 - },
85 + 'permission_callback' => [ $this, 'permissions_check' ],
98 86 ],
99 87 [ // Update single flow
100 88 'methods' => \WP_REST_Server::EDITABLE,
101 89 'callback' => [$this, 'update_item'],
102 - 'permission_callback' => function () {
103 - // return current_user_can( 'manage_options' );
104 - return true;
105 - },
90 + 'permission_callback' => [ $this, 'permissions_check' ],
106 91 ],
107 92 [ // Delete single flow
108 93 'methods' => \WP_REST_Server::DELETABLE,
109 94 'callback' => [$this, 'delete_item'],
110 - 'permission_callback' => function () {
111 - // return current_user_can( 'manage_options' );
112 - return true;
113 - },
95 + 'permission_callback' => [ $this, 'permissions_check' ],
114 96 ],
115 97 ] );
116 98
117 99 register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)' . '/clone', [
@@ -117,14 +99,34 @@
117 99 register_rest_route( $this->namespace, '/' . $this->rest_base . '/(?P<flow_id>[\d]+)' . '/clone', [
118 100 [ // Clone flow
119 101 'methods' => \WP_REST_Server::CREATABLE,
120 102 'callback' => [$this, 'clone_item'],
121 - 'permission_callback' => function () {
122 - // return current_user_can( 'manage_options' );
123 - return true;
124 - },
103 + 'permission_callback' => [ $this, 'permissions_check' ],
125 104 ],
126 105 ] );
106 + }
107 +
108 + /**
109 + * Check that the current user is allowed to manage notification flows.
110 + *
111 + * Every flow route is administrative: flows control the content and
112 + * recipients of the emails the site sends out. They must never be
113 + * reachable by unauthenticated visitors.
114 + *
115 + * @since 1.0.0
116 + *
117 + * @param \WP_REST_Request $request
118 + *
119 + * @return bool
120 + */
121 + public function permissions_check( $request ) {
122 + $can = current_user_can( 'manage_options' );
123 +
124 + return (bool) apply_filters(
125 + Helpers::get_hook_name( $this->identifier, 'ens_flow_permission' ),
126 + $can,
127 + $request
128 + );
127 129 }
128 130
129 131 /**
130 132 * Create flow