Make WordPress Core


Ignore:
Timestamp:
09/24/2026 05:30:50 AM (4 days ago)
Author:
ramonopoly
Message:

REST API: Check for a missing post before the comment status capability.

WP_REST_Comments_Controller::create_item_permissions_check() used to check whether the caller was allowed to set the status parameter before it checked that a post was supplied at all.

A request that carried a status but no post was therefore rejected with rest_comment_invalid_status, "Sorry, you are not allowed to edit 'status' for comments", which points at the wrong parameter. The actual problem was the missing post.

This commit moves the missing-post guard above the status capability check. No logic changes.

Developed in: ​https://github.com/WordPress/wordpress-develop/pull/12764

Props ramonopoly, andrewserong, mukesh27.

Fixes #65761.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php

    r63790 r63912  
    569569                }
    570570
     571                if ( empty( $request['post'] ) ) {
     572                        return new WP_Error(
     573                                'rest_comment_invalid_post_id',
     574                                __( 'Sorry, you are not allowed to create this comment without a post.' ),
     575                                array( 'status' => 403 )
     576                        );
     577                }
     578
    571579                $edit_cap = $is_note ? array( 'edit_post', (int) $request['post'] ) : array( 'moderate_comments' );
    572580                if ( isset( $request['status'] ) && ! current_user_can( ...$edit_cap ) ) {
    … …  
    576584                                sprintf( __( "Sorry, you are not allowed to edit '%s' for comments." ), 'status' ),
    577585                                array( 'status' => rest_authorization_required_code() )
    578                         );
    579                 }
    580 
    581                 if ( empty( $request['post'] ) ) {
    582                         return new WP_Error(
    583                                 'rest_comment_invalid_post_id',
    584                                 __( 'Sorry, you are not allowed to create this comment without a post.' ),
    585                                 array( 'status' => 403 )
    586586                        );
    587587                }
Note: See TracChangeset for help on using the changeset viewer.