WordPress.org

Make WordPress Core

Opened 4 years ago

Closed 3 years ago

#17909 closed enhancement (fixed)

admin-ajax.php should use edit_comment capability

Reported by: ejdanderson Owned by:
Milestone: 3.3 Priority: normal
Severity: normal Version: 3.2
Component: Administration Keywords: has-patch
Focuses: Cc:

Description

admin-ajax.php is still using the 'edit_post' capability with respect to the handling of comments, this should be using the 'edit_comment' capability introduced in 3.1

Attachments (1)

admin-ajax.diff (1.6 KB) - added by ejdanderson 4 years ago.
Replaces edit_post capability with edit_comment. I believe the 'edit_post' capability is appropriate in the 'get-comments' and 'replyto-comment' cases.

Download all attachments as: .zip

Change History (9)

@ejdanderson4 years ago

Replaces edit_post capability with edit_comment. I believe the 'edit_post' capability is appropriate in the 'get-comments' and 'replyto-comment' cases.

comment:1 @scribu4 years ago

  • Keywords 3.3-early added
  • Milestone changed from Awaiting Review to Future Release

comment:2 @nacin4 years ago

  • Keywords 3.3-early removed
  • Milestone changed from Future Release to 3.2.1

comment:3 @nacin4 years ago

  • Milestone changed from 3.2.1 to 3.2.2

comment:4 @nacin4 years ago

In [18435]:

Use edit_comment rather than edit_post in admin-ajax. props ejdanderson, see #17909. for trunk.

comment:5 @nacin4 years ago

Leaving this one open for 3.2.x for possible hardening.

comment:6 @nacin4 years ago

  • Keywords fixed-major added

comment:7 @devinreams3 years ago

  • Cc devin@… added

comment:8 @nacin3 years ago

  • Keywords fixed-major removed
  • Milestone changed from 3.2.2 to 3.3
  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.