PluginProbe
Yoast SEO – Advanced SEO with real-time guidance and built-in AI / trunk
Yoast SEO – Advanced SEO with real-time guidance and built-in AI vtrunk
28.5 28.4 28.3 28.2 28.1 28.0 27.9 27.8 27.7 27.6 27.5 trunk 18.0 18.1 18.2 18.3 18.4 18.4.1 18.5 18.5.1 18.6 18.7 18.8 18.9 19.0 All 129 releases
← All changes | src/ai/content-planner/user-interface/get-suggestions-route.php +18 -5 27.8 → trunk View file →
@@ -17,9 +17,9 @@
17 17
18 18 /**
19 19 * Registers a route to get content suggestions from the AI API.
20 20 *
21 - * @internal This route powers the Yoast SEO admin UI's Content Planner feature. It is not part of the plugin's public REST API surface, requires the `edit_posts` capability (see {@see self::check_permissions()}), and may change at any time without notice.
21 + * @internal This route powers the Yoast SEO admin UI's Content Planner feature. It is not part of the plugin's public REST API surface, requires the capability to edit posts of the requested post type (see {@see self::check_permissions()}), and may change at any time without notice.
22 22 *
23 23 * @makePublic
24 24 *
25 25 * @phpcs:disable Yoast.NamingConventions.ObjectNameDepth.MaxExceeded
@@ -141,17 +141,30 @@
141 141 return new WP_REST_Response( $data->to_array() );
142 142 }
143 143
144 144 /**
145 - * Checks if the user is logged in and can edit posts.
145 + * Checks if the user is logged in and can edit posts of the requested post type.
146 146 *
147 - * @return bool Whether the user is logged in and can edit posts.
147 + * The requested post_type is caller-controlled, so the permission must be evaluated
148 + * against that post type's own edit_posts meta-capability — not the generic
149 + * 'edit_posts' string, which would let a user with edit_posts but no edit_pages
150 + * (e.g. an Author) pull metadata for pages or arbitrary CPTs.
151 + *
152 + * @param WP_REST_Request $request The request object.
153 + *
154 + * @return bool Whether the user can edit posts of the requested post type.
148 155 */
149 - public function check_permissions(): bool {
156 + public function check_permissions( WP_REST_Request $request ): bool {
150 157 $user = \wp_get_current_user();
151 158 if ( $user === null || $user->ID < 1 ) {
152 159 return false;
153 160 }
154 161
155 - return \user_can( $user, 'edit_posts' );
162 + $post_type = $request->get_param( 'post_type' );
163 + $post_type_object = \get_post_type_object( $post_type );
164 + if ( $post_type_object === null ) {
165 + return false;
166 + }
167 +
168 + return \user_can( $user, $post_type_object->cap->edit_posts );
156 169 }
157 170 }