Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
92.59% covered (success)
92.59%
25 / 27
100.00% covered (success)
100.00%
6 / 6
CRAP
100.00% covered (success)
100.00%
1 / 1
Order_REST_Controller
100.00% covered (success)
100.00%
25 / 25
100.00% covered (success)
100.00%
6 / 6
9
100.00% covered (success)
100.00%
1 / 1
 get_items_permissions_check
100.00% covered (success)
100.00%
7 / 7
100.00% covered (success)
100.00%
1 / 1
2
 check_read_permission
100.00% covered (success)
100.00%
1 / 1
100.00% covered (success)
100.00%
1 / 1
2
 current_user_can_read_orders
100.00% covered (success)
100.00%
2 / 2
100.00% covered (success)
100.00%
1 / 1
2
 create_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
 update_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
 delete_item_permissions_check
100.00% covered (success)
100.00%
5 / 5
100.00% covered (success)
100.00%
1 / 1
1
1<?php
2/**
3 * Read-only REST controller for jp_pay_order.
4 *
5 * Orders should only be created through the internal payment processing flow,
6 * not directly via the REST API.
7 *
8 * @package automattic/jetpack-paypal-payments
9 */
10
11namespace Automattic\Jetpack\Paypal_Payments;
12
13use WP_Error;
14use WP_REST_Posts_Controller;
15
16if ( ! defined( 'ABSPATH' ) ) {
17    exit( 0 );
18}
19
20/**
21 * Extends WP_REST_Posts_Controller to restrict reads and disable create, update, and delete operations.
22 */
23class Order_REST_Controller extends WP_REST_Posts_Controller {
24
25    /**
26     * Require the capability to read private posts before listing orders.
27     *
28     * Orders hold buyer details, so reading them requires an explicit capability.
29     *
30     * @param \WP_REST_Request $request Full details about the request.
31     * @return true|WP_Error
32     */
33    public function get_items_permissions_check( $request ) {
34        if ( ! $this->current_user_can_read_orders() ) {
35            return new WP_Error(
36                'rest_cannot_view',
37                __( 'Sorry, you are not allowed to view orders.', 'jetpack-paypal-payments' ),
38                array( 'status' => rest_authorization_required_code() )
39            );
40        }
41
42        return parent::get_items_permissions_check( $request );
43    }
44
45    /**
46     * Gate every single-order read, and every order the collection route would return.
47     *
48     * @param \WP_Post $post Post object.
49     * @return bool
50     */
51    public function check_read_permission( $post ) {
52        return $this->current_user_can_read_orders() && parent::check_read_permission( $post );
53    }
54
55    /**
56     * Whether the current user may read orders.
57     *
58     * @return bool
59     */
60    private function current_user_can_read_orders() {
61        $post_type = get_post_type_object( $this->post_type );
62
63        return $post_type !== null && current_user_can( $post_type->cap->read_private_posts );
64    }
65
66    /**
67     * Deny order creation via the REST API.
68     *
69     * @param \WP_REST_Request $request Full details about the request.
70     * @return WP_Error
71     */
72    public function create_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
73        return new WP_Error(
74            'rest_cannot_create',
75            __( 'Orders can only be created through the payment processing flow.', 'jetpack-paypal-payments' ),
76            array( 'status' => 403 )
77        );
78    }
79
80    /**
81     * Deny order updates via the REST API.
82     *
83     * @param \WP_REST_Request $request Full details about the request.
84     * @return WP_Error
85     */
86    public function update_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
87        return new WP_Error(
88            'rest_cannot_update',
89            __( 'Orders cannot be modified via the REST API.', 'jetpack-paypal-payments' ),
90            array( 'status' => 403 )
91        );
92    }
93
94    /**
95     * Deny order deletion via the REST API.
96     *
97     * @param \WP_REST_Request $request Full details about the request.
98     * @return WP_Error
99     */
100    public function delete_item_permissions_check( $request ) { // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.UnusedVariable
101        return new WP_Error(
102            'rest_cannot_delete',
103            __( 'Orders cannot be deleted via the REST API.', 'jetpack-paypal-payments' ),
104            array( 'status' => 403 )
105        );
106    }
107}