| @@ -94,9 +94,13 @@ | ||
| 94 | 94 | case 'PATCH': |
| 95 | 95 | case 'DELETE': |
| 96 | 96 | return current_user_can('yatra_edit_trips'); |
| 97 | 97 | default: |
| 98 | - return current_user_can('manage_options'); | |
| 98 | + // Unknown HTTP method — deny explicitly. The earlier | |
| 99 | + // fallback to `manage_options` was a regression that | |
| 100 | + // silently broadened admin-only access for any verb not | |
| 101 | + // in the explicit switch. | |
| 102 | + return false; | |
| 99 | 103 | } |
| 100 | 104 | } |
| 101 | 105 | |
| 102 | 106 | public function get_items(WP_REST_Request $request) |
| @@ -244,8 +248,17 @@ | ||
| 244 | 248 | if (!empty($type->icon)) { |
| 245 | 249 | $icon_data = maybe_unserialize($type->icon); |
| 246 | 250 | if (is_array($icon_data) && isset($icon_data['value'])) { |
| 247 | 251 | $prepared['type_icon'] = $icon_data['value']; |
| 252 | + if ( | |
| 253 | + isset($icon_data['type'], $icon_data['provider']) | |
| 254 | + && $icon_data['type'] === 'icon' | |
| 255 | + ) { | |
| 256 | + $p = sanitize_key((string) $icon_data['provider']); | |
| 257 | + if (in_array($p, ['fa-solid', 'fa-regular'], true)) { | |
| 258 | + $prepared['type_icon_provider'] = $p; | |
| 259 | + } | |
| 260 | + } | |
| 248 | 261 | } elseif (is_string($type->icon)) { |
| 249 | 262 | $prepared['type_icon'] = $type->icon; |
| 250 | 263 | } |
| 251 | 264 | } |