← All changes
|
src/ai/content-planner/user-interface/get-suggestions-route.php
+18
-5
27.7
→
trunk
View file →
| @@ -17,9 +17,9 @@ | ||
| 17 | 17 | |
| 18 | 18 | /** |
| 19 | 19 | * Registers a route to get content suggestions from the AI API. |
| 20 | 20 | * |
| 21 | - * @internal This route powers the Yoast SEO admin UI's Content Planner feature. It is not part of the plugin's public REST API surface, requires the `edit_posts` capability (see {@see self::check_permissions()}), and may change at any time without notice. | |
| 21 | + * @internal This route powers the Yoast SEO admin UI's Content Planner feature. It is not part of the plugin's public REST API surface, requires the capability to edit posts of the requested post type (see {@see self::check_permissions()}), and may change at any time without notice. | |
| 22 | 22 | * |
| 23 | 23 | * @makePublic |
| 24 | 24 | * |
| 25 | 25 | * @phpcs:disable Yoast.NamingConventions.ObjectNameDepth.MaxExceeded |
| @@ -141,17 +141,30 @@ | ||
| 141 | 141 | return new WP_REST_Response( $data->to_array() ); |
| 142 | 142 | } |
| 143 | 143 | |
| 144 | 144 | /** |
| 145 | - * Checks if the user is logged in and can edit posts. | |
| 145 | + * Checks if the user is logged in and can edit posts of the requested post type. | |
| 146 | 146 | * |
| 147 | - * @return bool Whether the user is logged in and can edit posts. | |
| 147 | + * The requested post_type is caller-controlled, so the permission must be evaluated | |
| 148 | + * against that post type's own edit_posts meta-capability — not the generic | |
| 149 | + * 'edit_posts' string, which would let a user with edit_posts but no edit_pages | |
| 150 | + * (e.g. an Author) pull metadata for pages or arbitrary CPTs. | |
| 151 | + * | |
| 152 | + * @param WP_REST_Request $request The request object. | |
| 153 | + * | |
| 154 | + * @return bool Whether the user can edit posts of the requested post type. | |
| 148 | 155 | */ |
| 149 | - public function check_permissions(): bool { | |
| 156 | + public function check_permissions( WP_REST_Request $request ): bool { | |
| 150 | 157 | $user = \wp_get_current_user(); |
| 151 | 158 | if ( $user === null || $user->ID < 1 ) { |
| 152 | 159 | return false; |
| 153 | 160 | } |
| 154 | 161 | |
| 155 | - return \user_can( $user, 'edit_posts' ); | |
| 162 | + $post_type = $request->get_param( 'post_type' ); | |
| 163 | + $post_type_object = \get_post_type_object( $post_type ); | |
| 164 | + if ( $post_type_object === null ) { | |
| 165 | + return false; | |
| 166 | + } | |
| 167 | + | |
| 168 | + return \user_can( $user, $post_type_object->cap->edit_posts ); | |
| 156 | 169 | } |
| 157 | 170 | } |