| @@ -14,9 +14,25 @@ | ||
| 14 | 14 | * Register services |
| 15 | 15 | */ |
| 16 | 16 | public function register(): void |
| 17 | 17 | { |
| 18 | - | |
| 18 | + // Capability filters MUST install for every request type (admin, | |
| 19 | + // REST, AJAX, frontend, CLI). Previously they were only installed | |
| 20 | + // from AdminServiceProvider::registerAdminMenu(), which is hooked | |
| 21 | + // on `admin_menu` — a hook that DOES NOT fire during REST API | |
| 22 | + // requests. The admin SPA loads all data via REST, so the admin | |
| 23 | + // fallback that grants every yatra_* cap to users with | |
| 24 | + // manage_options never ran for those requests → site admins hit | |
| 25 | + // 403 "REST forbidden" on Settings, Bookings, Trips, etc. | |
| 26 | + // | |
| 27 | + // AdminServiceProvider itself is gated behind is_admin() in | |
| 28 | + // Bootstrap, which is false during pure REST requests, so even | |
| 29 | + // calling the static from there isn't enough. AppServiceProvider | |
| 30 | + // is in the always-loaded providers list, so calling the | |
| 31 | + // installer here guarantees the filters exist for every entry | |
| 32 | + // point. add_filter is idempotent — the AdminServiceProvider | |
| 33 | + // call stays in place for defence-in-depth. | |
| 34 | + \Yatra\Providers\AdminServiceProvider::bootstrapMenuCapability(); | |
| 19 | 35 | |
| 20 | 36 | // Activation hook |
| 21 | 37 | register_activation_hook(YATRA_PLUGIN_FILE, [$this, 'activate']); |
| 22 | 38 | |
| @@ -22,9 +38,9 @@ | ||
| 22 | 38 | |
| 23 | 39 | // Deactivation hook |
| 24 | 40 | register_deactivation_hook(YATRA_PLUGIN_FILE, [$this, 'deactivate']); |
| 25 | 41 | |
| 26 | - // Database tables: created on activation (see activate()) and on version bump (Bootstrap::upgrade on admin_init). | |
| 42 | + // Database tables: created on activation (see activate()) and on version bump (FreeUpgradeRunner on admin_init). | |
| 27 | 43 | |
| 28 | 44 | // Register shortcodes |
| 29 | 45 | $this->registerShortcodes(); |
| 30 | 46 | |
| @@ -35,8 +51,11 @@ | ||
| 35 | 51 | |
| 36 | 52 | // Initialize ItineraryCostService for free itinerary costs feature |
| 37 | 53 | \Yatra\Services\ItineraryCostService::init(); |
| 38 | 54 | |
| 55 | + // Persist + expose selected additional services on bookings (free fallback). | |
| 56 | + \Yatra\Services\AdditionalServicesBookingService::init(); | |
| 57 | + | |
| 39 | 58 | // Ensure frontend bundles are marked as ES modules |
| 40 | 59 | add_filter('script_loader_tag', [$this, 'addFrontendModuleType'], 10, 2); |
| 41 | 60 | |
| 42 | 61 | // Initialize utility hooks (admin bar, etc.) |
| @@ -44,8 +63,14 @@ | ||
| 44 | 63 | |
| 45 | 64 | // Initialize review and enquiry hooks |
| 46 | 65 | \Yatra\Hooks\ReviewHooks::init(); |
| 47 | 66 | |
| 67 | + // Load the reCAPTCHA v3 script on the frontend when enabled (self-guards). | |
| 68 | + add_action('wp_enqueue_scripts', ['\\Yatra\\Services\\RecaptchaService', 'enqueueScript']); | |
| 69 | + | |
| 70 | + // Garbage-collect deleted-trip IDs out of user wishlist meta. | |
| 71 | + \Yatra\Hooks\SavedTripHooks::init(); | |
| 72 | + | |
| 48 | 73 | // Initialize REST API hooks |
| 49 | 74 | \Yatra\Hooks\RestApiHooks::init(); |
| 50 | 75 | |
| 51 | 76 | // Initialize cron hooks (trip lifecycle, etc.) |
| @@ -61,8 +86,13 @@ | ||
| 61 | 86 | \Yatra\Hooks\AvailabilityInventoryHooks::init(); |
| 62 | 87 | |
| 63 | 88 | // Initialize cache hooks |
| 64 | 89 | \Yatra\Hooks\CacheHooks::init(); |
| 90 | + | |
| 91 | + // Publish Yatra trips/destinations/activities/categories to sitemaps | |
| 92 | + // (WP core, Yoast, Rank Math, AIOSEO) — Yatra content lives in custom | |
| 93 | + // tables, so no SEO generator can discover it without this. | |
| 94 | + \Yatra\Sitemap\SitemapManager::init(); | |
| 65 | 95 | |
| 66 | 96 | add_filter('yatra_require_email_verification', static function (): bool { |
| 67 | 97 | return \Yatra\Services\SettingsService::isEnabled('require_email_verification'); |
| 68 | 98 | }); |