Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | |
92.59% |
25 / 27 |
|
100.00% |
6 / 6 |
CRAP | |
100.00% |
1 / 1 |
| Order_REST_Controller | |
100.00% |
25 / 25 |
|
100.00% |
6 / 6 |
9 | |
100.00% |
1 / 1 |
| get_items_permissions_check | |
100.00% |
7 / 7 |
|
100.00% |
1 / 1 |
2 | |||
| check_read_permission | |
100.00% |
1 / 1 |
|
100.00% |
1 / 1 |
2 | |||
| current_user_can_read_orders | |
100.00% |
2 / 2 |
|
100.00% |
1 / 1 |
2 | |||
| create_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| update_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| delete_item_permissions_check | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
1 | |||
| 1 | <?php |
| 2 | /** |
| 3 | * Read-only REST controller for jp_pay_order. |
| 4 | * |
| 5 | * Orders should only be created through the internal payment processing flow, |
| 6 | * not directly via the REST API. |
| 7 | * |
| 8 | * @package automattic/jetpack-paypal-payments |
| 9 | */ |
| 10 | |
| 11 | namespace Automattic\Jetpack\Paypal_Payments; |
| 12 | |
| 13 | use WP_Error; |
| 14 | use WP_REST_Posts_Controller; |
| 15 | |
| 16 | if ( ! defined( 'ABSPATH' ) ) { |
| 17 | exit( 0 ); |
| 18 | } |
| 19 | |
| 20 | /** |
| 21 | * Extends WP_REST_Posts_Controller to restrict reads and disable create, update, and delete operations. |
| 22 | */ |
| 23 | class Order_REST_Controller extends WP_REST_Posts_Controller { |
| 24 | |
| 25 | /** |
| 26 | * Require the capability to read private posts before listing orders. |
| 27 | * |
| 28 | * Orders hold buyer details, so reading them requires an explicit capability. |
| 29 | * |
| 30 | * @param \WP_REST_Request $request Full details about the request. |
| 31 | * @return true|WP_Error |
| 32 | */ |
| 33 | public function get_items_permissions_check( $request ) { |
| 34 | if ( ! $this->current_user_can_read_orders() ) { |
| 35 | return new WP_Error( |
| 36 | 'rest_cannot_view', |
| 37 | __( 'Sorry, you are not allowed to view orders.', 'jetpack-paypal-payments' ), |
| 38 | array( 'status' => rest_authorization_required_code() ) |
| 39 | ); |
| 40 | } |
| 41 | |
| 42 | return parent::get_items_permissions_check( $request ); |
| 43 | } |
| 44 | |
| 45 | /** |
| 46 | * Gate every single-order read, and every order the collection route would return. |
| 47 | * |
| 48 | * @param \WP_Post $post Post object. |
| 49 | * @return bool |
| 50 | */ |
| 51 | public function check_read_permission( $post ) { |
| 52 | return $this->current_user_can_read_orders() && parent::check_read_permission( $post ); |
| 53 | } |
| 54 | |
| 55 | /** |
| 56 | * Whether the current user may read orders. |
| 57 | * |
| 58 | * @return bool |
| 59 | */ |
| 60 | private function current_user_can_read_orders() { |
| 61 | $post_type = get_post_type_object( $this->post_type ); |
| 62 | |
| 63 | return $post_type !== null && current_user_can( $post_type->cap->read_private_posts ); |
| 64 | } |
| 65 | |
| 66 | /** |
| 67 | * Deny order creation via the REST API. |
| 68 | * |
| 69 | * @param \WP_REST_Request $request Full details about the request. |
| 70 | * @return WP_Error |
| 71 | */ |
| 72 | public function create_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 73 | return new WP_Error( |
| 74 | 'rest_cannot_create', |
| 75 | __( 'Orders can only be created through the payment processing flow.', 'jetpack-paypal-payments' ), |
| 76 | array( 'status' => 403 ) |
| 77 | ); |
| 78 | } |
| 79 | |
| 80 | /** |
| 81 | * Deny order updates via the REST API. |
| 82 | * |
| 83 | * @param \WP_REST_Request $request Full details about the request. |
| 84 | * @return WP_Error |
| 85 | */ |
| 86 | public function update_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 87 | return new WP_Error( |
| 88 | 'rest_cannot_update', |
| 89 | __( 'Orders cannot be modified via the REST API.', 'jetpack-paypal-payments' ), |
| 90 | array( 'status' => 403 ) |
| 91 | ); |
| 92 | } |
| 93 | |
| 94 | /** |
| 95 | * Deny order deletion via the REST API. |
| 96 | * |
| 97 | * @param \WP_REST_Request $request Full details about the request. |
| 98 | * @return WP_Error |
| 99 | */ |
| 100 | public function delete_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable |
| 101 | return new WP_Error( |
| 102 | 'rest_cannot_delete', |
| 103 | __( 'Orders cannot be deleted via the REST API.', 'jetpack-paypal-payments' ), |
| 104 | array( 'status' => 403 ) |
| 105 | ); |
| 106 | } |
| 107 | } |