diff --git a/src/wp-includes/capabilities-functions.php b/src/wp-includes/capabilities-functions.php index 3742c18c40..0c1be98c1d 100644 --- a/src/wp-includes/capabilities-functions.php +++ b/src/wp-includes/capabilities-functions.php @@ -53,6 +53,12 @@ function map_meta_cap( $cap, $user_id ) { } $post_type = get_post_type_object( $post->post_type ); + if ( ! $post_type ) { + /* translators: 1: post type, 2: capability name */ + _doing_it_wrong( __FUNCTION__, sprintf( __( 'The post type %1$s is not registered, so it may not be reliable to check the capability "%2$s" against a post of that type.' ), $post->post_type, $cap ), '4.4.0' ); + $caps[] = 'edit_others_posts'; + break; + } if ( ! $post_type->map_meta_cap ) { $caps[] = $post_type->cap->$cap; @@ -101,6 +107,12 @@ function map_meta_cap( $cap, $user_id ) { } $post_type = get_post_type_object( $post->post_type ); + if ( ! $post_type ) { + /* translators: 1: post type, 2: capability name */ + _doing_it_wrong( __FUNCTION__, sprintf( __( 'The post type %1$s is not registered, so it may not be reliable to check the capability "%2$s" against a post of that type.' ), $post->post_type, $cap ), '4.4.0' ); + $caps[] = 'edit_others_posts'; + break; + } if ( ! $post_type->map_meta_cap ) { $caps[] = $post_type->cap->$cap; @@ -143,6 +155,12 @@ function map_meta_cap( $cap, $user_id ) { } $post_type = get_post_type_object( $post->post_type ); + if ( ! $post_type ) { + /* translators: 1: post type, 2: capability name */ + _doing_it_wrong( __FUNCTION__, sprintf( __( 'The post type %1$s is not registered, so it may not be reliable to check the capability "%2$s" against a post of that type.' ), $post->post_type, $cap ), '4.4.0' ); + $caps[] = 'edit_others_posts'; + break; + } if ( ! $post_type->map_meta_cap ) { $caps[] = $post_type->cap->$cap; @@ -169,6 +187,12 @@ function map_meta_cap( $cap, $user_id ) { case 'publish_post': $post = get_post( $args[0] ); $post_type = get_post_type_object( $post->post_type ); + if ( ! $post_type ) { + /* translators: 1: post type, 2: capability name */ + _doing_it_wrong( __FUNCTION__, sprintf( __( 'The post type %1$s is not registered, so it may not be reliable to check the capability "%2$s" against a post of that type.' ), $post->post_type, $cap ), '4.4.0' ); + $caps[] = 'edit_others_posts'; + break; + } $caps[] = $post_type->cap->publish_posts; break; diff --git a/tests/phpunit/tests/user/capabilities.php b/tests/phpunit/tests/user/capabilities.php index 78820d2f9d..aa0c16af47 100644 --- a/tests/phpunit/tests/user/capabilities.php +++ b/tests/phpunit/tests/user/capabilities.php @@ -994,4 +994,27 @@ class Tests_User_Capabilities extends WP_UnitTestCase { $this->assertFalse( current_user_can( 'edit_user', $super_admin->ID ) ); } + + /** + * @ticket 16956 + */ + function test_require_edit_others_posts_if_post_type_doesnt_exist() { + register_post_type( 'existed' ); + $post_id = $this->factory->post->create( array( 'post_type' => 'existed' ) ); + _unregister_post_type( 'existed' ); + + $subscriber_id = $this->factory->user->create( array( 'role' => 'subscriber' ) ); + $editor_id = $this->factory->user->create( array( 'role' => 'editor' ) ); + + $this->setExpectedIncorrectUsage( 'map_meta_cap' ); + foreach ( array( 'delete_post', 'edit_post', 'read_post', 'publish_post' ) as $cap ) { + wp_set_current_user( $subscriber_id ); + $this->assertSame( array( 'edit_others_posts' ), map_meta_cap( $cap, $subscriber_id, $post_id ) ); + $this->assertFalse( current_user_can( $cap, $post_id ) ); + + wp_set_current_user( $editor_id ); + $this->assertSame( array( 'edit_others_posts' ), map_meta_cap( $cap, $editor_id, $post_id ) ); + $this->assertTrue( current_user_can( $cap, $post_id ) ); + } + } }