Make WordPress Core

Changeset 63912


Ignore:
Timestamp:
09/24/2026 05:30:50 AM (4 days ago)
Author:
ramonopoly
Message:

REST API: Check for a missing post before the comment status capability.

WP_REST_Comments_Controller::create_item_permissions_check() used to check whether the caller was allowed to set the status parameter before it checked that a post was supplied at all.

A request that carried a status but no post was therefore rejected with rest_comment_invalid_status, "Sorry, you are not allowed to edit 'status' for comments", which points at the wrong parameter. The actual problem was the missing post.

This commit moves the missing-post guard above the status capability check. No logic changes.

Developed in: ​https://github.com/WordPress/wordpress-develop/pull/12764

Props ramonopoly, andrewserong, mukesh27.

Fixes #65761.

Location:
trunk
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php

    r63790 r63912  
    569569                }
    570570
     571                if ( empty( $request['post'] ) ) {
     572                        return new WP_Error(
     573                                'rest_comment_invalid_post_id',
     574                                __( 'Sorry, you are not allowed to create this comment without a post.' ),
     575                                array( 'status' => 403 )
     576                        );
     577                }
     578
    571579                $edit_cap = $is_note ? array( 'edit_post', (int) $request['post'] ) : array( 'moderate_comments' );
    572580                if ( isset( $request['status'] ) && ! current_user_can( ...$edit_cap ) ) {
    … …  
    576584                                sprintf( __( "Sorry, you are not allowed to edit '%s' for comments." ), 'status' ),
    577585                                array( 'status' => rest_authorization_required_code() )
    578                         );
    579                 }
    580 
    581                 if ( empty( $request['post'] ) ) {
    582                         return new WP_Error(
    583                                 'rest_comment_invalid_post_id',
    584                                 __( 'Sorry, you are not allowed to create this comment without a post.' ),
    585                                 array( 'status' => 403 )
    586586                        );
    587587                }
  • trunk/tests/phpunit/tests/rest-api/rest-comments-controller.php

    r63896 r63912  
    20252025        }
    20262026
     2027        /**
     2028         * A missing post should be reported as a missing post, even when the request
     2029         * also sets `status` and the user is not allowed to set it.
     2030         *
     2031         * @ticket 65761
     2032         */
     2033        public function test_create_comment_status_and_no_post_id_no_permission() {
     2034                wp_set_current_user( self::$author_id );
     2035
     2036                $params = array(
     2037                        'author_name'  => 'Homer Jay Simpson',
     2038                        'author_email' => 'chunkylover53@aol.com',
     2039                        'author_url'   => 'http://compuglobalhypermeganet.com',
     2040                        'content'      => 'Here\’s to alcohol: the cause of, and solution to, all of life\’s problems.',
     2041                        'status'       => 'approved',
     2042                );
     2043
     2044                $request = new WP_REST_Request( 'POST', '/wp/v2/comments' );
     2045                $request->add_header( 'Content-Type', 'application/json' );
     2046                $request->set_body( wp_json_encode( $params ) );
     2047
     2048                $response = rest_get_server()->dispatch( $request );
     2049                $this->assertErrorResponse( 'rest_comment_invalid_post_id', $response, 403 );
     2050        }
     2051
    20272052        public function test_create_comment_invalid_post_id() {
    20282053                wp_set_current_user( self::$admin_id );
    … …  
    38153840
    38163841        /**
     3842         * A missing post should be reported as a missing post for notes too.
     3843         *
     3844         * Without a post, the `status` capability check falls back to
     3845         * `current_user_can( 'edit_post', 0 )`, which no role can satisfy. An
     3846         * administrator is used here to show the missing post is reported even for a
     3847         * user holding every capability.
     3848         *
     3849         * @ticket 65761
     3850         */
     3851        public function test_create_note_status_and_no_post_id() {
     3852                wp_set_current_user( self::$admin_id );
     3853
     3854                $params = array(
     3855                        'author_name'  => 'Ishmael',
     3856                        'author_email' => 'herman-melville@earthlink.net',
     3857                        'author_url'   => 'https://en.wikipedia.org/wiki/Herman_Melville',
     3858                        'content'      => 'Comic Book Guy',
     3859                        'type'         => 'note',
     3860                        'status'       => 'hold',
     3861                );
     3862
     3863                $request = new WP_REST_Request( 'POST', '/wp/v2/comments' );
     3864                $request->add_header( 'Content-Type', 'application/json' );
     3865                $request->set_body( wp_json_encode( $params ) );
     3866
     3867                $response = rest_get_server()->dispatch( $request );
     3868                $this->assertErrorResponse( 'rest_comment_invalid_post_id', $response, 403 );
     3869        }
     3870
     3871        /**
    38173872         * @ticket 64096
    38183873         */
Note: See TracChangeset for help on using the changeset viewer.