From 2dcbf39e2d82997583555d80d3d172179a75428a Mon Sep 17 00:00:00 2001 From: Sergey Biryukov Date: Wed, 2 Sep 2015 18:30:58 +0000 Subject: [PATCH] Provide more helpful feedback than just "Cheatin' uh?" for permission errors in `wp-admin/options.php`. props ericlewis, kraftbj, lukecarbis, mrmist. fixes #33674. see #14530. git-svn-id: https://develop.svn.wordpress.org/trunk@33863 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-admin/options.php | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/src/wp-admin/options.php b/src/wp-admin/options.php index 752d7b46ff..a4809cf618 100644 --- a/src/wp-admin/options.php +++ b/src/wp-admin/options.php @@ -44,8 +44,13 @@ if ( empty($option_page) ) { $capability = apply_filters( "option_page_capability_{$option_page}", $capability ); } -if ( !current_user_can( $capability ) ) - wp_die( __( 'Cheatin’ uh?' ), 403 ); +if ( ! current_user_can( $capability ) ) { + wp_die( + '

' . __( 'Cheatin’ uh?' ) . '

' . + '

' . __( 'You are not allowed to manage these items.' ) . '

', + 403 + ); +} // Handle admin email change requests if ( is_multisite() ) { @@ -68,8 +73,13 @@ if ( is_multisite() ) { } } -if ( is_multisite() && !is_super_admin() && 'update' != $action ) - wp_die( __( 'Cheatin’ uh?' ), 403 ); +if ( is_multisite() && ! is_super_admin() && 'update' != $action ) { + wp_die( + '

' . __( 'Cheatin’ uh?' ) . '

' . + '

' . __( 'You are not allowed to delete these items.' ) . '

', + 403 + ); +} $whitelist_options = array( 'general' => array( 'blogname', 'blogdescription', 'gmt_offset', 'date_format', 'time_format', 'start_of_week', 'timezone_string', 'WPLANG' ),