Changeset 63912
Legend:
- Unmodified
- Added
- Removed
-
trunk/src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
r63790 r63912 569 569 } 570 570 571 if ( empty( $request['post'] ) ) { 572 return new WP_Error( 573 'rest_comment_invalid_post_id', 574 __( 'Sorry, you are not allowed to create this comment without a post.' ), 575 array( 'status' => 403 ) 576 ); 577 } 578 571 579 $edit_cap = $is_note ? array( 'edit_post', (int) $request['post'] ) : array( 'moderate_comments' ); 572 580 if ( isset( $request['status'] ) && ! current_user_can( ...$edit_cap ) ) { … … 576 584 sprintf( __( "Sorry, you are not allowed to edit '%s' for comments." ), 'status' ), 577 585 array( 'status' => rest_authorization_required_code() ) 578 );579 }580 581 if ( empty( $request['post'] ) ) {582 return new WP_Error(583 'rest_comment_invalid_post_id',584 __( 'Sorry, you are not allowed to create this comment without a post.' ),585 array( 'status' => 403 )586 586 ); 587 587 } -
trunk/tests/phpunit/tests/rest-api/rest-comments-controller.php
r63896 r63912 2025 2025 } 2026 2026 2027 /** 2028 * A missing post should be reported as a missing post, even when the request 2029 * also sets `status` and the user is not allowed to set it. 2030 * 2031 * @ticket 65761 2032 */ 2033 public function test_create_comment_status_and_no_post_id_no_permission() { 2034 wp_set_current_user( self::$author_id ); 2035 2036 $params = array( 2037 'author_name' => 'Homer Jay Simpson', 2038 'author_email' => 'chunkylover53@aol.com', 2039 'author_url' => 'http://compuglobalhypermeganet.com', 2040 'content' => 'Here\’s to alcohol: the cause of, and solution to, all of life\’s problems.', 2041 'status' => 'approved', 2042 ); 2043 2044 $request = new WP_REST_Request( 'POST', '/wp/v2/comments' ); 2045 $request->add_header( 'Content-Type', 'application/json' ); 2046 $request->set_body( wp_json_encode( $params ) ); 2047 2048 $response = rest_get_server()->dispatch( $request ); 2049 $this->assertErrorResponse( 'rest_comment_invalid_post_id', $response, 403 ); 2050 } 2051 2027 2052 public function test_create_comment_invalid_post_id() { 2028 2053 wp_set_current_user( self::$admin_id ); … … 3815 3840 3816 3841 /** 3842 * A missing post should be reported as a missing post for notes too. 3843 * 3844 * Without a post, the `status` capability check falls back to 3845 * `current_user_can( 'edit_post', 0 )`, which no role can satisfy. An 3846 * administrator is used here to show the missing post is reported even for a 3847 * user holding every capability. 3848 * 3849 * @ticket 65761 3850 */ 3851 public function test_create_note_status_and_no_post_id() { 3852 wp_set_current_user( self::$admin_id ); 3853 3854 $params = array( 3855 'author_name' => 'Ishmael', 3856 'author_email' => 'herman-melville@earthlink.net', 3857 'author_url' => 'https://en.wikipedia.org/wiki/Herman_Melville', 3858 'content' => 'Comic Book Guy', 3859 'type' => 'note', 3860 'status' => 'hold', 3861 ); 3862 3863 $request = new WP_REST_Request( 'POST', '/wp/v2/comments' ); 3864 $request->add_header( 'Content-Type', 'application/json' ); 3865 $request->set_body( wp_json_encode( $params ) ); 3866 3867 $response = rest_get_server()->dispatch( $request ); 3868 $this->assertErrorResponse( 'rest_comment_invalid_post_id', $response, 403 ); 3869 } 3870 3871 /** 3817 3872 * @ticket 64096 3818 3873 */
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)