| @@ -12,9 +12,8 @@ | ||
| 12 | 12 | if ( ! class_exists( 'WC_REST_Coupons_Controller' ) ) { |
| 13 | 13 | return; |
| 14 | 14 | } |
| 15 | 15 | |
| 16 | -use WCPOS\WooCommercePOS\Services\Permission_Rules; | |
| 17 | 16 | use Exception; |
| 18 | 17 | use WC_Coupon; |
| 19 | 18 | use WC_REST_Coupons_Controller; |
| 20 | 19 | use WCPOS\WooCommercePOS\Logger; |
| @@ -47,38 +46,8 @@ | ||
| 47 | 46 | */ |
| 48 | 47 | protected $wcpos_request; |
| 49 | 48 | |
| 50 | 49 | /** |
| 51 | - * Read coupons with the POS grant scoped to this handler. | |
| 52 | - * | |
| 53 | - * @param WP_REST_Request $request Full request details. | |
| 54 | - * @return WP_REST_Response|WP_Error | |
| 55 | - */ | |
| 56 | - public function get_items( $request ) { | |
| 57 | - Permission_Rules::install_wc_filter( 'coupons', 'v1' ); | |
| 58 | - try { | |
| 59 | - return parent::get_items( $request ); | |
| 60 | - } finally { | |
| 61 | - Permission_Rules::uninstall_wc_filter(); | |
| 62 | - } | |
| 63 | - } | |
| 64 | - | |
| 65 | - /** | |
| 66 | - * Read coupons with the POS grant scoped to this handler. | |
| 67 | - * | |
| 68 | - * @param WP_REST_Request $request Full request details. | |
| 69 | - * @return WP_REST_Response|WP_Error | |
| 70 | - */ | |
| 71 | - public function get_item( $request ) { | |
| 72 | - Permission_Rules::install_wc_filter( 'coupons', 'v1' ); | |
| 73 | - try { | |
| 74 | - return parent::get_item( $request ); | |
| 75 | - } finally { | |
| 76 | - Permission_Rules::uninstall_wc_filter(); | |
| 77 | - } | |
| 78 | - } | |
| 79 | - | |
| 80 | - /** | |
| 81 | 50 | * Create a single coupon. |
| 82 | 51 | * |
| 83 | 52 | * @param WP_REST_Request $request Full details about the request. |
| 84 | 53 | * |
| @@ -115,14 +84,14 @@ | ||
| 115 | 84 | * @param mixed $dispatch_result Dispatch result, will be used if not empty. |
| 116 | 85 | * @param WP_REST_Request $request Request used to generate the response. |
| 117 | 86 | * @param string $route Route matched for the request. |
| 118 | 87 | * @param array $handler Route handler used for the request. |
| 119 | - * @return mixed | |
| 120 | 88 | */ |
| 121 | 89 | public function wcpos_dispatch_request( $dispatch_result, WP_REST_Request $request, $route, $handler ) { |
| 122 | 90 | $this->wcpos_request = $request; |
| 123 | 91 | |
| 124 | 92 | add_filter( 'woocommerce_rest_prepare_shop_coupon_object', array( $this, 'wcpos_coupon_response' ), 10, 3 ); |
| 93 | + add_filter( 'woocommerce_rest_check_permissions', array( $this, 'wcpos_check_permissions' ), 10, 4 ); | |
| 125 | 94 | // The post-date touch that used to be installed here is now registered |
| 126 | 95 | // unconditionally at plugins_loaded (Sync\Coupon_Modified_Date), so it also |
| 127 | 96 | // covers wp-admin/WP-CLI/third-party coupon saves this dispatch never saw. |
| 128 | 97 | |
| @@ -137,39 +106,56 @@ | ||
| 137 | 106 | return $dispatch_result; |
| 138 | 107 | } |
| 139 | 108 | |
| 140 | 109 | /** |
| 141 | - * Delegate the read decision, preserving WooCommerce's request-dependent checks. | |
| 110 | + * Check whether a given request has permission to read coupons. | |
| 142 | 111 | * |
| 143 | - * @param WP_REST_Request $request Full request details. | |
| 144 | - * @return bool|WP_Error | |
| 112 | + * @param WP_REST_Request $request Full details about the request. | |
| 113 | + * | |
| 114 | + * @return WP_Error|boolean | |
| 145 | 115 | */ |
| 146 | 116 | public function get_items_permissions_check( $request ) { |
| 147 | - return Permission_Rules::verdict( 'coupons', 'read', (int) $request['id'], 0, 'v1', $request->get_params() ); | |
| 117 | + if ( current_user_can( 'access_woocommerce_pos' ) ) { | |
| 118 | + return true; | |
| 119 | + } | |
| 120 | + | |
| 121 | + return parent::get_items_permissions_check( $request ); | |
| 148 | 122 | } |
| 149 | 123 | |
| 150 | 124 | /** |
| 151 | - * Delegate the read decision, preserving WooCommerce's request-dependent checks. | |
| 125 | + * Check if a given request has access to read a coupon. | |
| 152 | 126 | * |
| 153 | - * @param WP_REST_Request $request Full request details. | |
| 154 | - * @return bool|WP_Error | |
| 127 | + * @param WP_REST_Request $request Full details about the request. | |
| 128 | + * | |
| 129 | + * @return WP_Error|boolean | |
| 155 | 130 | */ |
| 156 | 131 | public function get_item_permissions_check( $request ) { |
| 157 | - return Permission_Rules::verdict( 'coupons', 'read', (int) $request['id'], 0, 'v1', $request->get_params() ); | |
| 132 | + if ( current_user_can( 'access_woocommerce_pos' ) ) { | |
| 133 | + return true; | |
| 134 | + } | |
| 135 | + | |
| 136 | + return parent::get_item_permissions_check( $request ); | |
| 158 | 137 | } |
| 159 | 138 | |
| 160 | 139 | /** |
| 161 | 140 | * Authorize coupon read access for POS users. |
| 162 | 141 | * |
| 163 | - * @deprecated Use Permission_Rules::wc_filter(). | |
| 164 | - * @param bool $permission Incoming WC permission. | |
| 165 | - * @param string $context Permission context. | |
| 166 | - * @param int $object_id Target object ID. | |
| 167 | - * @param string $post_type WC object type. | |
| 142 | + * The WC CRUD controller's get_items() calls wc_rest_check_post_permissions() | |
| 143 | + * per coupon. This filter ensures POS users can read coupons. | |
| 144 | + * | |
| 145 | + * @param bool $permission The current permission. | |
| 146 | + * @param string $context The context of the request (read, create, edit, delete). | |
| 147 | + * @param int $object_id The object ID. | |
| 148 | + * @param string $post_type The post type. | |
| 149 | + * | |
| 168 | 150 | * @return bool |
| 169 | 151 | */ |
| 170 | 152 | public function wcpos_check_permissions( $permission, $context, $object_id, $post_type ) { |
| 171 | - return Permission_Rules::wc_filter( $permission, $context, $object_id, $post_type, 'coupons', 'v1' ); | |
| 153 | + if ( ! $permission && 'shop_coupon' === $post_type && 'read' === $context ) { | |
| 154 | + $permission = current_user_can( 'access_woocommerce_pos' ); | |
| 155 | + } | |
| 156 | + | |
| 157 | + return $permission; | |
| 172 | 158 | } |
| 173 | 159 | |
| 174 | 160 | /** |
| 175 | 161 | * Get the query params for collections. |