Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | |
100.00% |
15 / 15 |
|
100.00% |
3 / 3 |
CRAP | |
100.00% |
1 / 1 |
| Order_REST_Controller | |
100.00% |
15 / 15 |
|
100.00% |
3 / 3 |
3 | |
100.00% |
1 / 1 |
| create_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| update_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| delete_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| 1 | <?php |
| 2 | /** |
| 3 | * Read-only REST controller for jp_pay_order. |
| 4 | * |
| 5 | * Orders should only be created through the internal payment processing flow, |
| 6 | * not directly via the REST API. |
| 7 | * |
| 8 | * @package automattic/jetpack-paypal-payments |
| 9 | */ |
| 10 | |
| 11 | namespace Automattic\Jetpack\Paypal_Payments; |
| 12 | |
| 13 | use WP_Error; |
| 14 | use WP_REST_Posts_Controller; |
| 15 | |
| 16 | /** |
| 17 | * Extends WP_REST_Posts_Controller to disable create, update, and delete operations. |
| 18 | */ |
| 19 | class Order_REST_Controller extends WP_REST_Posts_Controller { |
| 20 | |
| 21 | /** |
| 22 | * Deny order creation via the REST API. |
| 23 | * |
| 24 | * @param \WP_REST_Request $request Full details about the request. |
| 25 | * @return WP_Error |
| 26 | */ |
| 27 | public function create_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 28 | return new WP_Error( |
| 29 | 'rest_cannot_create', |
| 30 | __( 'Orders can only be created through the payment processing flow.', 'jetpack-paypal-payments' ), |
| 31 | array( 'status' => 403 ) |
| 32 | ); |
| 33 | } |
| 34 | |
| 35 | /** |
| 36 | * Deny order updates via the REST API. |
| 37 | * |
| 38 | * @param \WP_REST_Request $request Full details about the request. |
| 39 | * @return WP_Error |
| 40 | */ |
| 41 | public function update_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 42 | return new WP_Error( |
| 43 | 'rest_cannot_update', |
| 44 | __( 'Orders cannot be modified via the REST API.', 'jetpack-paypal-payments' ), |
| 45 | array( 'status' => 403 ) |
| 46 | ); |
| 47 | } |
| 48 | |
| 49 | /** |
| 50 | * Deny order deletion via the REST API. |
| 51 | * |
| 52 | * @param \WP_REST_Request $request Full details about the request. |
| 53 | * @return WP_Error |
| 54 | */ |
| 55 | public function delete_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 56 | return new WP_Error( |
| 57 | 'rest_cannot_delete', |
| 58 | __( 'Orders cannot be deleted via the REST API.', 'jetpack-paypal-payments' ), |
| 59 | array( 'status' => 403 ) |
| 60 | ); |
| 61 | } |
| 62 | } |