| @@ -38,8 +38,15 @@ | ||
| 38 | 38 | */ |
| 39 | 39 | public function __construct() { |
| 40 | 40 | register_activation_hook( PLUGIN_FILE, array( $this, 'activate' ) ); |
| 41 | 41 | add_action( 'wpmu_new_blog', array( $this, 'activate_new_site' ) ); |
| 42 | + // The staff-account rule (#1918, #2104) must hold even when WooCommerce is | |
| 43 | + // inactive and Init never starts; it depends on nothing from WooCommerce. | |
| 44 | + add_filter( 'map_meta_cap', array( Services\Permission_Rules::class, 'map_user_meta_caps' ), 10, 4 ); | |
| 45 | + // So must the role fence: a cashier may hand out no role above customer. Last, | |
| 46 | + // so a role-editor plugin adding roles back at a later priority cannot widen it. | |
| 47 | + add_filter( 'editable_roles', array( Services\Permission_Rules::class, 'filter_editable_roles' ), PHP_INT_MAX ); | |
| 48 | + add_action( 'invite_user', array( Services\Permission_Rules::class, 'refuse_unfenced_invite' ), 10, 3 ); | |
| 42 | 49 | add_action( 'plugins_loaded', array( $this, 'init' ) ); |
| 43 | 50 | } |
| 44 | 51 | |
| 45 | 52 | /** |