| @@ -208,9 +208,9 @@ | ||
| 208 | 208 | * capability names to boolean grants. Only one role is mutated per call — |
| 209 | 209 | * this mirrors the single-role update semantics of the original REST |
| 210 | 210 | * controller. |
| 211 | 211 | * |
| 212 | - * The administrator read and manage_woocommerce_pos capabilities are never removed. | |
| 212 | + * The administrator/read capability is never removed as a sanity guard. | |
| 213 | 213 | * |
| 214 | 214 | * @param array $settings Incoming payload keyed by role slug. |
| 215 | 215 | * |
| 216 | 216 | * @return array|WP_Error The fresh read() view on success. |
| @@ -218,9 +218,9 @@ | ||
| 218 | 218 | public function write( array $settings ) { |
| 219 | 219 | // Defense-in-depth: capability mutation is a privileged service-layer |
| 220 | 220 | // operation; do not rely solely on the REST route's permission |
| 221 | 221 | // callback (matches the Settings::delete_settings() precedent). |
| 222 | - if ( ! current_user_can( 'manage_woocommerce_pos' ) || ! current_user_can( 'edit_users' ) || ! current_user_can( 'promote_users' ) ) { | |
| 222 | + if ( ! current_user_can( 'edit_users' ) || ! current_user_can( 'promote_users' ) ) { | |
| 223 | 223 | return new WP_Error( |
| 224 | 224 | 'woocommerce_pos_settings_error', |
| 225 | 225 | __( 'You do not have permission to update access settings.', 'woocommerce-pos' ), |
| 226 | 226 | array( 'status' => 403 ) |
| @@ -267,12 +267,8 @@ | ||
| 267 | 267 | // Apply each allowed capability grant/revoke. |
| 268 | 268 | foreach ( $flattened_caps as $cap => $grant ) { |
| 269 | 269 | // Sanity check: administrator role must always keep the `read` capability. |
| 270 | 270 | if ( 'administrator' === $slug && 'read' === $cap ) { |
| 271 | - continue; | |
| 272 | - } | |
| 273 | - // Administrators must retain access to capability management. | |
| 274 | - if ( 'administrator' === $slug && 'manage_woocommerce_pos' === $cap && ! $grant ) { | |
| 275 | 271 | continue; |
| 276 | 272 | } |
| 277 | 273 | if ( $grant ) { |
| 278 | 274 | $role->add_cap( $cap ); |