mirror of
https://github.com/gosticks/wordpress-develop.git
synced 2026-10-05 07:07:04 +00:00
Taxonomy: Introduce more fine grained capabilities for managing taxonomy terms.
This introduces the singular `edit_term`, `delete_term`, and `assign_term` meta capabilities for terms, and switches the base capability name for tags from `manage_categories` to `manage_post_tags` and the corresponding `edit_post_tags`, `delete_post_tags`, and `assign_post_tags`. All of these capabilities ultimately map to `manage_categories` so by default there is no change in the behaviour of the capabilities for categories, tags, or custom taxonomies. The `map_meta_cap` filter and the `capabilities` argument when registering a taxonomy now allow for control over editing, deleting, and assigning individual terms, as well as a separation of capabilities for tags from those of categories. Fixes #35614 Props johnjamesjacoby for feedback git-svn-id: https://develop.svn.wordpress.org/trunk@38698 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
@@ -635,7 +635,7 @@ function wp_admin_bar_edit_menu( $wp_admin_bar ) {
|
||||
) );
|
||||
} elseif ( ! empty( $current_object->taxonomy )
|
||||
&& ( $tax = get_taxonomy( $current_object->taxonomy ) )
|
||||
&& current_user_can( $tax->cap->edit_terms )
|
||||
&& current_user_can( 'edit_term', $current_object->term_id )
|
||||
&& $edit_term_link = get_edit_term_link( $current_object->term_id, $current_object->taxonomy ) )
|
||||
{
|
||||
$wp_admin_bar->add_menu( array(
|
||||
|
||||
@@ -402,6 +402,43 @@ function map_meta_cap( $cap, $user_id ) {
|
||||
case 'delete_site':
|
||||
$caps[] = 'manage_options';
|
||||
break;
|
||||
case 'edit_term':
|
||||
case 'delete_term':
|
||||
case 'assign_term':
|
||||
$term_id = $args[0];
|
||||
$term = get_term( $term_id );
|
||||
if ( ! $term || is_wp_error( $term ) ) {
|
||||
$caps[] = 'do_not_allow';
|
||||
break;
|
||||
}
|
||||
|
||||
$tax = get_taxonomy( $term->taxonomy );
|
||||
if ( ! $tax ) {
|
||||
$caps[] = 'do_not_allow';
|
||||
break;
|
||||
}
|
||||
|
||||
if ( 'delete_term' === $cap && ( $term->term_id == get_option( 'default_' . $term->taxonomy ) ) ) {
|
||||
$caps[] = 'do_not_allow';
|
||||
break;
|
||||
}
|
||||
|
||||
$taxo_cap = $cap . 's';
|
||||
|
||||
$caps = map_meta_cap( $tax->cap->$taxo_cap, $user_id, $term_id );
|
||||
|
||||
break;
|
||||
case 'manage_post_tags':
|
||||
case 'edit_categories':
|
||||
case 'edit_post_tags':
|
||||
case 'delete_categories':
|
||||
case 'delete_post_tags':
|
||||
$caps[] = 'manage_categories';
|
||||
break;
|
||||
case 'assign_categories':
|
||||
case 'assign_post_tags':
|
||||
$caps[] = 'edit_posts';
|
||||
break;
|
||||
case 'create_sites':
|
||||
case 'delete_sites':
|
||||
case 'manage_network':
|
||||
|
||||
@@ -1886,8 +1886,9 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
|
||||
$taxonomy = get_taxonomy( $content_struct['taxonomy'] );
|
||||
|
||||
if ( ! current_user_can( $taxonomy->cap->manage_terms ) )
|
||||
if ( ! current_user_can( $taxonomy->cap->edit_terms ) ) {
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to create terms in this taxonomy.' ) );
|
||||
}
|
||||
|
||||
$taxonomy = (array) $taxonomy;
|
||||
|
||||
@@ -1973,9 +1974,6 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
|
||||
$taxonomy = get_taxonomy( $content_struct['taxonomy'] );
|
||||
|
||||
if ( ! current_user_can( $taxonomy->cap->edit_terms ) )
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to edit terms in this taxonomy.' ) );
|
||||
|
||||
$taxonomy = (array) $taxonomy;
|
||||
|
||||
// hold the data of the term
|
||||
@@ -1989,6 +1987,10 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
if ( ! $term )
|
||||
return new IXR_Error( 404, __( 'Invalid term ID.' ) );
|
||||
|
||||
if ( ! current_user_can( 'edit_term', $term_id ) ) {
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to edit this term.' ) );
|
||||
}
|
||||
|
||||
if ( isset( $content_struct['name'] ) ) {
|
||||
$term_data['name'] = trim( $content_struct['name'] );
|
||||
|
||||
@@ -2068,10 +2070,6 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
return new IXR_Error( 403, __( 'Invalid taxonomy.' ) );
|
||||
|
||||
$taxonomy = get_taxonomy( $taxonomy );
|
||||
|
||||
if ( ! current_user_can( $taxonomy->cap->delete_terms ) )
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to delete terms in this taxonomy.' ) );
|
||||
|
||||
$term = get_term( $term_id, $taxonomy->name );
|
||||
|
||||
if ( is_wp_error( $term ) )
|
||||
@@ -2080,6 +2078,10 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
if ( ! $term )
|
||||
return new IXR_Error( 404, __( 'Invalid term ID.' ) );
|
||||
|
||||
if ( ! current_user_can( 'delete_term', $term_id ) ) {
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to delete this term.' ) );
|
||||
}
|
||||
|
||||
$result = wp_delete_term( $term_id, $taxonomy->name );
|
||||
|
||||
if ( is_wp_error( $result ) )
|
||||
@@ -2140,9 +2142,6 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
|
||||
$taxonomy = get_taxonomy( $taxonomy );
|
||||
|
||||
if ( ! current_user_can( $taxonomy->cap->assign_terms ) )
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to assign terms in this taxonomy.' ) );
|
||||
|
||||
$term = get_term( $term_id , $taxonomy->name, ARRAY_A );
|
||||
|
||||
if ( is_wp_error( $term ) )
|
||||
@@ -2151,6 +2150,10 @@ class wp_xmlrpc_server extends IXR_Server {
|
||||
if ( ! $term )
|
||||
return new IXR_Error( 404, __( 'Invalid term ID.' ) );
|
||||
|
||||
if ( ! current_user_can( 'assign_term', $term_id ) ) {
|
||||
return new IXR_Error( 401, __( 'Sorry, you are not allowed to assign this term.' ) );
|
||||
}
|
||||
|
||||
return $this->_prepare_term( $term );
|
||||
}
|
||||
|
||||
|
||||
@@ -930,7 +930,7 @@ function get_edit_term_link( $term_id, $taxonomy = '', $object_type = '' ) {
|
||||
}
|
||||
|
||||
$tax = get_taxonomy( $term->taxonomy );
|
||||
if ( ! $tax || ! current_user_can( $tax->cap->edit_terms ) ) {
|
||||
if ( ! $tax || ! current_user_can( 'edit_term', $term->term_id ) ) {
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -984,7 +984,7 @@ function edit_term_link( $link = '', $before = '', $after = '', $term = null, $e
|
||||
return;
|
||||
|
||||
$tax = get_taxonomy( $term->taxonomy );
|
||||
if ( ! current_user_can( $tax->cap->edit_terms ) ) {
|
||||
if ( ! current_user_can( 'edit_term', $term->term_id ) ) {
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -61,6 +61,12 @@ function create_initial_taxonomies() {
|
||||
'show_ui' => true,
|
||||
'show_admin_column' => true,
|
||||
'_builtin' => true,
|
||||
'capabilities' => array(
|
||||
'manage_terms' => 'manage_categories',
|
||||
'edit_terms' => 'edit_categories',
|
||||
'delete_terms' => 'delete_categories',
|
||||
'assign_terms' => 'assign_categories',
|
||||
),
|
||||
) );
|
||||
|
||||
register_taxonomy( 'post_tag', 'post', array(
|
||||
@@ -71,6 +77,12 @@ function create_initial_taxonomies() {
|
||||
'show_ui' => true,
|
||||
'show_admin_column' => true,
|
||||
'_builtin' => true,
|
||||
'capabilities' => array(
|
||||
'manage_terms' => 'manage_post_tags',
|
||||
'edit_terms' => 'edit_post_tags',
|
||||
'delete_terms' => 'delete_post_tags',
|
||||
'assign_terms' => 'assign_post_tags',
|
||||
),
|
||||
) );
|
||||
|
||||
register_taxonomy( 'nav_menu', 'nav_menu_item', array(
|
||||
|
||||
Reference in New Issue
Block a user