← All changes
|
includes/API/V2/Proxy/Coupons_Proxy_Behavior.php
+9
-6
1.10.19
→
1.10.17
View file →
| @@ -10,14 +10,8 @@ | ||
| 10 | 10 | /** |
| 11 | 11 | * Relaxes WooCommerce coupon read permission only during the forward. |
| 12 | 12 | */ |
| 13 | 13 | final class Coupons_Proxy_Behavior extends Scoped_Proxy_Behavior { |
| 14 | - /** POS read grant for this collection only. | |
| 15 | - * | |
| 16 | - * @var string | |
| 17 | - */ | |
| 18 | - protected $permission_collection = 'coupons'; | |
| 19 | - | |
| 20 | 14 | /** |
| 21 | 15 | * Install this resource's hooks and return their removal tuples. |
| 22 | 16 | * |
| 23 | 17 | * @return array<int, array{0: string, 1: callable, 2: int}> |
| @@ -22,9 +16,17 @@ | ||
| 22 | 16 | * |
| 23 | 17 | * @return array<int, array{0: string, 1: callable, 2: int}> |
| 24 | 18 | */ |
| 25 | 19 | protected function install(): array { |
| 20 | + $filter = static function ( $permission, $context, $object_id, $post_type ) { | |
| 21 | + if ( ! $permission && 'shop_coupon' === $post_type && 'read' === $context ) { | |
| 22 | + $permission = current_user_can( 'access_woocommerce_pos' ); | |
| 23 | + } | |
| 26 | 24 | |
| 25 | + return $permission; | |
| 26 | + }; | |
| 27 | + add_filter( 'woocommerce_rest_check_permissions', $filter, 10, 4 ); | |
| 28 | + | |
| 27 | 29 | // Coupon date/modified sorts tie routinely (imports share timestamps); |
| 28 | 30 | // pin the id tiebreak so multi-page walks stay stable (see Stable_Sort). |
| 29 | 31 | $stable_sort = static function ( $args ) { |
| 30 | 32 | return Stable_Sort::with_post_id_tiebreak( (array) $args ); |
| @@ -31,8 +33,9 @@ | ||
| 31 | 33 | }; |
| 32 | 34 | add_filter( 'woocommerce_rest_shop_coupon_object_query', $stable_sort ); |
| 33 | 35 | |
| 34 | 36 | return array( |
| 37 | + array( 'woocommerce_rest_check_permissions', $filter, 10 ), | |
| 35 | 38 | array( 'woocommerce_rest_shop_coupon_object_query', $stable_sort, 10 ), |
| 36 | 39 | ); |
| 37 | 40 | } |
| 38 | 41 | } |