WordPress.org

Make WordPress Core

Opened 3 years ago

Closed 2 years ago

#17909 closed enhancement (fixed)

admin-ajax.php should use edit_comment capability

Reported by: ejdanderson Owned by:
Milestone: 3.3 Priority: normal
Severity: normal Version: 3.2
Component: Administration Keywords: has-patch
Focuses: Cc:

Description

admin-ajax.php is still using the 'edit_post' capability with respect to the handling of comments, this should be using the 'edit_comment' capability introduced in 3.1

Attachments (1)

admin-ajax.diff (1.6 KB) - added by ejdanderson 3 years ago.
Replaces edit_post capability with edit_comment. I believe the 'edit_post' capability is appropriate in the 'get-comments' and 'replyto-comment' cases.

Download all attachments as: .zip

Change History (9)

ejdanderson3 years ago

Replaces edit_post capability with edit_comment. I believe the 'edit_post' capability is appropriate in the 'get-comments' and 'replyto-comment' cases.

comment:1 scribu3 years ago

  • Keywords 3.3-early added
  • Milestone changed from Awaiting Review to Future Release

comment:2 nacin3 years ago

  • Keywords 3.3-early removed
  • Milestone changed from Future Release to 3.2.1

comment:3 nacin3 years ago

  • Milestone changed from 3.2.1 to 3.2.2

comment:4 nacin3 years ago

In [18435]:

Use edit_comment rather than edit_post in admin-ajax. props ejdanderson, see #17909. for trunk.

comment:5 nacin3 years ago

Leaving this one open for 3.2.x for possible hardening.

comment:6 nacin3 years ago

  • Keywords fixed-major added

comment:7 devinreams2 years ago

  • Cc devin@… added

comment:8 nacin2 years ago

  • Keywords fixed-major removed
  • Milestone changed from 3.2.2 to 3.3
  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.