| @@ -14,9 +14,25 @@ | ||
| 14 | 14 | * Register services |
| 15 | 15 | */ |
| 16 | 16 | public function register(): void |
| 17 | 17 | { |
| 18 | - | |
| 18 | + // Capability filters MUST install for every request type (admin, | |
| 19 | + // REST, AJAX, frontend, CLI). Previously they were only installed | |
| 20 | + // from AdminServiceProvider::registerAdminMenu(), which is hooked | |
| 21 | + // on `admin_menu` — a hook that DOES NOT fire during REST API | |
| 22 | + // requests. The admin SPA loads all data via REST, so the admin | |
| 23 | + // fallback that grants every yatra_* cap to users with | |
| 24 | + // manage_options never ran for those requests → site admins hit | |
| 25 | + // 403 "REST forbidden" on Settings, Bookings, Trips, etc. | |
| 26 | + // | |
| 27 | + // AdminServiceProvider itself is gated behind is_admin() in | |
| 28 | + // Bootstrap, which is false during pure REST requests, so even | |
| 29 | + // calling the static from there isn't enough. AppServiceProvider | |
| 30 | + // is in the always-loaded providers list, so calling the | |
| 31 | + // installer here guarantees the filters exist for every entry | |
| 32 | + // point. add_filter is idempotent — the AdminServiceProvider | |
| 33 | + // call stays in place for defence-in-depth. | |
| 34 | + \Yatra\Providers\AdminServiceProvider::bootstrapMenuCapability(); | |
| 19 | 35 | |
| 20 | 36 | // Activation hook |
| 21 | 37 | register_activation_hook(YATRA_PLUGIN_FILE, [$this, 'activate']); |
| 22 | 38 | |
| @@ -47,8 +63,14 @@ | ||
| 47 | 63 | |
| 48 | 64 | // Initialize review and enquiry hooks |
| 49 | 65 | \Yatra\Hooks\ReviewHooks::init(); |
| 50 | 66 | |
| 67 | + // Load the reCAPTCHA v3 script on the frontend when enabled (self-guards). | |
| 68 | + add_action('wp_enqueue_scripts', ['\\Yatra\\Services\\RecaptchaService', 'enqueueScript']); | |
| 69 | + | |
| 70 | + // Garbage-collect deleted-trip IDs out of user wishlist meta. | |
| 71 | + \Yatra\Hooks\SavedTripHooks::init(); | |
| 72 | + | |
| 51 | 73 | // Initialize REST API hooks |
| 52 | 74 | \Yatra\Hooks\RestApiHooks::init(); |
| 53 | 75 | |
| 54 | 76 | // Initialize cron hooks (trip lifecycle, etc.) |
| @@ -64,8 +86,13 @@ | ||
| 64 | 86 | \Yatra\Hooks\AvailabilityInventoryHooks::init(); |
| 65 | 87 | |
| 66 | 88 | // Initialize cache hooks |
| 67 | 89 | \Yatra\Hooks\CacheHooks::init(); |
| 90 | + | |
| 91 | + // Publish Yatra trips/destinations/activities/categories to sitemaps | |
| 92 | + // (WP core, Yoast, Rank Math, AIOSEO) — Yatra content lives in custom | |
| 93 | + // tables, so no SEO generator can discover it without this. | |
| 94 | + \Yatra\Sitemap\SitemapManager::init(); | |
| 68 | 95 | |
| 69 | 96 | add_filter('yatra_require_email_verification', static function (): bool { |
| 70 | 97 | return \Yatra\Services\SettingsService::isEnabled('require_email_verification'); |
| 71 | 98 | }); |