Make WordPress Core

Changeset 60817


Ignore:
Timestamp:
09/30/2025 04:50:20 PM (11 months ago)
Author:
johnbillion
Message:

REST API: Increase the specificity of capability checks for collections when the edit context is in use.

The edit access in now taken into account for each individual post, term, or user in the response.

Merges [60814] into the 6.8 branch.

Props andraganescu, desrosj, ehti, hurayraiit, iandunn, joehoyle, johnbillion, jorbin, mnelson4, noisysocks, peterwilsoncc, rmccue, timothyblynjacobs, vortfu, whyisjake, zieladam.

Location:
branches/6.8
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • branches/6.8

  • branches/6.8/src/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php

    r60200 r60817  
    464464
    465465                        foreach ( $query_result as $post ) {
    466                                 if ( ! $this->check_read_permission( $post ) ) {
     466                                if ( 'edit' === $request['context'] ) {
     467                                        $permission = $this->check_update_permission( $post );
     468                                } else {
     469                                        $permission = $this->check_read_permission( $post );
     470                                }
     471
     472                                if ( ! $permission ) {
    467473                                        continue;
    468474                                }
  • branches/6.8/src/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php

    r59970 r60817  
    366366                        $response = array();
    367367                        foreach ( $query_result as $term ) {
     368                                if ( 'edit' === $request['context'] && ! current_user_can( 'edit_term', $term->term_id ) ) {
     369                                        continue;
     370                                }
     371
    368372                                $data       = $this->prepare_item_for_response( $term, $request );
    369373                                $response[] = $this->prepare_response_for_collection( $data );
  • branches/6.8/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php

    r59970 r60817  
    221221                        return new WP_Error(
    222222                                'rest_forbidden_context',
    223                                 __( 'Sorry, you are not allowed to list users.' ),
     223                                __( 'Sorry, you are not allowed to edit users.' ),
    224224                                array( 'status' => rest_authorization_required_code() )
    225225                        );
     
    380380
    381381                        foreach ( $query->get_results() as $user ) {
     382                                if ( 'edit' === $request['context'] && ! current_user_can( 'edit_user', $user->ID ) ) {
     383                                        continue;
     384                                }
     385
    382386                                $data    = $this->prepare_item_for_response( $user, $request );
    383387                                $users[] = $this->prepare_response_for_collection( $data );
     
    480484                }
    481485
    482                 if ( 'edit' === $request['context'] && ! current_user_can( 'list_users' ) ) {
    483                         return new WP_Error(
    484                                 'rest_user_cannot_view',
    485                                 __( 'Sorry, you are not allowed to list users.' ),
     486                if ( 'edit' === $request['context'] && ! current_user_can( 'edit_user', $user->ID ) ) {
     487                        return new WP_Error(
     488                                'rest_forbidden_context',
     489                                __( 'Sorry, you are not allowed to edit this user.' ),
    486490                                array( 'status' => rest_authorization_required_code() )
    487491                        );
    488                 } elseif ( ! count_user_posts( $user->ID, $types ) && ! current_user_can( 'edit_user', $user->ID ) && ! current_user_can( 'list_users' ) ) {
     492                }
     493
     494                if ( ! current_user_can( 'edit_user', $user->ID ) && ! current_user_can( 'list_users' ) && ! count_user_posts( $user->ID, $types ) ) {
    489495                        return new WP_Error(
    490496                                'rest_user_cannot_view',
     
    10871093                }
    10881094
    1089                 if ( in_array( 'roles', $fields, true ) ) {
     1095                if ( in_array( 'roles', $fields, true ) && ( current_user_can( 'list_users' ) || current_user_can( 'edit_user', $user->ID ) ) ) {
    10901096                        // Defensively call array_values() to ensure an array is returned.
    10911097                        $data['roles'] = array_values( $user->roles );
  • branches/6.8/tests/phpunit/tests/rest-api/rest-users-controller.php

    r60143 r60817  
    13121312                $request->set_param( 'context', 'edit' );
    13131313                $response = rest_get_server()->dispatch( $request );
    1314                 $this->assertErrorResponse( 'rest_user_cannot_view', $response, 401 );
     1314                $this->assertErrorResponse( 'rest_forbidden_context', $response, 401 );
    13151315        }
    13161316
Note: See TracChangeset for help on using the changeset viewer.