PluginProbe
WCPOS – Point of Sale (POS) plugin for WooCommerce / 1.10.22
WCPOS – Point of Sale (POS) plugin for WooCommerce v1.10.22
1.10.24 1.10.23 1.10.22 1.10.21 1.10.20 1.10.19 1.10.18 1.10.17 1.10.16 1.10.15 1.10.13 1.10.14 1.10.12 1.10.11 1.10.10 1.10.9 1.10.8 untagged-3d9b7ccddc54df87c672 1.10.7 1.10.6 1.10.5 1.10.3 1.10.4 1.10.2 1.10.1 All 168 releases
← All changes | includes/Services/Settings/Access_Section.php +6 -2 1.10.14 → 1.10.22 View file →
@@ -208,9 +208,9 @@
208 208 * capability names to boolean grants. Only one role is mutated per call —
209 209 * this mirrors the single-role update semantics of the original REST
210 210 * controller.
211 211 *
212 - * The administrator/read capability is never removed as a sanity guard.
212 + * The administrator read and manage_woocommerce_pos capabilities are never removed.
213 213 *
214 214 * @param array $settings Incoming payload keyed by role slug.
215 215 *
216 216 * @return array|WP_Error The fresh read() view on success.
@@ -218,9 +218,9 @@
218 218 public function write( array $settings ) {
219 219 // Defense-in-depth: capability mutation is a privileged service-layer
220 220 // operation; do not rely solely on the REST route's permission
221 221 // callback (matches the Settings::delete_settings() precedent).
222 - if ( ! current_user_can( 'edit_users' ) || ! current_user_can( 'promote_users' ) ) {
222 + if ( ! current_user_can( 'manage_woocommerce_pos' ) || ! current_user_can( 'edit_users' ) || ! current_user_can( 'promote_users' ) ) {
223 223 return new WP_Error(
224 224 'woocommerce_pos_settings_error',
225 225 __( 'You do not have permission to update access settings.', 'woocommerce-pos' ),
226 226 array( 'status' => 403 )
@@ -267,8 +267,12 @@
267 267 // Apply each allowed capability grant/revoke.
268 268 foreach ( $flattened_caps as $cap => $grant ) {
269 269 // Sanity check: administrator role must always keep the `read` capability.
270 270 if ( 'administrator' === $slug && 'read' === $cap ) {
271 + continue;
272 + }
273 + // Administrators must retain access to capability management.
274 + if ( 'administrator' === $slug && 'manage_woocommerce_pos' === $cap && ! $grant ) {
271 275 continue;
272 276 }
273 277 if ( $grant ) {
274 278 $role->add_cap( $cap );