| @@ -20,14 +20,18 @@ | ||
| 20 | 20 | * |
| 21 | 21 | * @return \WP_REST_Response |
| 22 | 22 | */ |
| 23 | 23 | public function nonce_failure_response() { |
| 24 | + // 403 so HTTP clients reject instead of treating this object as payload | |
| 25 | + // (a 200 here used to flow into array states and crash the customizer). | |
| 24 | 26 | return new \WP_REST_Response( |
| 25 | 27 | [ |
| 26 | 28 | 'success' => false, |
| 29 | + 'isError' => true, | |
| 27 | 30 | 'code' => 'nonce_failure', |
| 28 | 31 | 'message' => __( 'Verify nonce failed', 'yaymail' ), |
| 29 | - ] | |
| 32 | + ], | |
| 33 | + 403 | |
| 30 | 34 | ); |
| 31 | 35 | } |
| 32 | 36 | |
| 33 | 37 | /** |
| @@ -49,9 +53,9 @@ | ||
| 49 | 53 | */ |
| 50 | 54 | public function exec( $callable, \WP_REST_Request $request ) { |
| 51 | 55 | |
| 52 | 56 | if ( ! $this->verify_nonce( $request ) ) { |
| 53 | - return rest_ensure_request( $this->nonce_failure_response() ); | |
| 57 | + return rest_ensure_response( $this->nonce_failure_response() ); | |
| 54 | 58 | } |
| 55 | 59 | |
| 56 | 60 | try { |
| 57 | 61 | if ( is_callable( $callable ) ) { |