- Timestamp:
- 09/30/2025 03:49:18 PM (11 months ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php
r59970 r60814 221 221 return new WP_Error( 222 222 'rest_forbidden_context', 223 __( 'Sorry, you are not allowed to list users.' ),223 __( 'Sorry, you are not allowed to edit users.' ), 224 224 array( 'status' => rest_authorization_required_code() ) 225 225 ); … … 380 380 381 381 foreach ( $query->get_results() as $user ) { 382 if ( 'edit' === $request['context'] && ! current_user_can( 'edit_user', $user->ID ) ) { 383 continue; 384 } 385 382 386 $data = $this->prepare_item_for_response( $user, $request ); 383 387 $users[] = $this->prepare_response_for_collection( $data ); … … 480 484 } 481 485 482 if ( 'edit' === $request['context'] && ! current_user_can( ' list_users') ) {483 return new WP_Error( 484 'rest_ user_cannot_view',485 __( 'Sorry, you are not allowed to list users.' ),486 if ( 'edit' === $request['context'] && ! current_user_can( 'edit_user', $user->ID ) ) { 487 return new WP_Error( 488 'rest_forbidden_context', 489 __( 'Sorry, you are not allowed to edit this user.' ), 486 490 array( 'status' => rest_authorization_required_code() ) 487 491 ); 488 } elseif ( ! count_user_posts( $user->ID, $types ) && ! current_user_can( 'edit_user', $user->ID ) && ! current_user_can( 'list_users' ) ) { 492 } 493 494 if ( ! current_user_can( 'edit_user', $user->ID ) && ! current_user_can( 'list_users' ) && ! count_user_posts( $user->ID, $types ) ) { 489 495 return new WP_Error( 490 496 'rest_user_cannot_view', … … 1087 1093 } 1088 1094 1089 if ( in_array( 'roles', $fields, true ) ) {1095 if ( in_array( 'roles', $fields, true ) && ( current_user_can( 'list_users' ) || current_user_can( 'edit_user', $user->ID ) ) ) { 1090 1096 // Defensively call array_values() to ensure an array is returned. 1091 1097 $data['roles'] = array_values( $user->roles );
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)