Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
100.00% covered (success)
100.00%
15 / 15
100.00% covered (success)
100.00%
3 / 3
CRAP
100.00% covered (success)
100.00%
1 / 1
Order_REST_Controller
100.00% covered (success)
100.00%
15 / 15
100.00% covered (success)
100.00%
3 / 3
3
100.00% covered (success)
100.00%
1 / 1
 create_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
 update_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
 delete_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
1<?php
2/**
3 * Read-only REST controller for jp_pay_order.
4 *
5 * Orders should only be created through the internal payment processing flow,
6 * not directly via the REST API.
7 *
8 * @package automattic/jetpack-paypal-payments
9 */
10
11namespace Automattic\Jetpack\Paypal_Payments;
12
13use WP_Error;
14use WP_REST_Posts_Controller;
15
16/**
17 * Extends WP_REST_Posts_Controller to disable create, update, and delete operations.
18 */
19class Order_REST_Controller extends WP_REST_Posts_Controller {
20
21    /**
22     * Deny order creation via the REST API.
23     *
24     * @param \WP_REST_Request $request Full details about the request.
25     * @return WP_Error
26     */
27    public function create_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
28        return new WP_Error(
29            'rest_cannot_create',
30            __( 'Orders can only be created through the payment processing flow.', 'jetpack-paypal-payments' ),
31            array( 'status' => 403 )
32        );
33    }
34
35    /**
36     * Deny order updates via the REST API.
37     *
38     * @param \WP_REST_Request $request Full details about the request.
39     * @return WP_Error
40     */
41    public function update_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
42        return new WP_Error(
43            'rest_cannot_update',
44            __( 'Orders cannot be modified via the REST API.', 'jetpack-paypal-payments' ),
45            array( 'status' => 403 )
46        );
47    }
48
49    /**
50     * Deny order deletion via the REST API.
51     *
52     * @param \WP_REST_Request $request Full details about the request.
53     * @return WP_Error
54     */
55    public function delete_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
56        return new WP_Error(
57            'rest_cannot_delete',
58            __( 'Orders cannot be deleted via the REST API.', 'jetpack-paypal-payments' ),
59            array( 'status' => 403 )
60        );
61    }
62}