| @@ -82,9 +82,13 @@ | ||
| 82 | 82 | case 'PATCH': |
| 83 | 83 | case 'DELETE': |
| 84 | 84 | return current_user_can('yatra_edit_trips'); |
| 85 | 85 | default: |
| 86 | - return current_user_can('manage_options'); | |
| 86 | + // Unknown HTTP method — deny explicitly. The earlier | |
| 87 | + // fallback to `manage_options` was a regression that | |
| 88 | + // silently broadened admin-only access for any verb not | |
| 89 | + // in the explicit switch. | |
| 90 | + return false; | |
| 87 | 91 | } |
| 88 | 92 | } |
| 89 | 93 | |
| 90 | 94 | public function get_items(WP_REST_Request $request) |
| @@ -294,8 +298,12 @@ | ||
| 294 | 298 | |
| 295 | 299 | if (!empty($prepared['updated_by'])) { |
| 296 | 300 | $user = get_userdata((int) $prepared['updated_by']); |
| 297 | 301 | $prepared['updated_by_name'] = $user ? esc_html($user->display_name) : null; |
| 302 | + } | |
| 303 | + | |
| 304 | + if (array_key_exists('is_featured', $prepared)) { | |
| 305 | + $prepared['is_featured'] = !empty($prepared['is_featured']) ? 1 : 0; | |
| 298 | 306 | } |
| 299 | 307 | |
| 300 | 308 | return $prepared; |
| 301 | 309 | } |