WP_REST_Comments_Controller::update_item_permissions_check │ public │ WP 4.7.0

Checks if a given REST request has access to update a comment.

Method of the class: WP_REST_Comments_Controller{}

No Hooks.

Returns

true|WP_Error. True if the request has access to update the item, error object otherwise.

Usage

$WP_REST_Comments_Controller = new WP_REST_Comments_Controller();
$WP_REST_Comments_Controller->update_item_permissions_check( $request );
$request(WP_REST_Request) (required)
Full details about the request.

Changelog

Since 4.7.0 Introduced.
Since 7.1.1 Target post permissions are checked when a comment's parent post is changed.

WP_REST_Comments_Controller::update_item_permissions_check() code WP 7.1.2

public function update_item_permissions_check( $request ) {
	$comment = $this->get_comment( $request['id'] );
	if ( is_wp_error( $comment ) ) {
		return $comment;
	}

	if ( ! $this->check_edit_permission( $comment ) ) {
		return new WP_Error(
			'rest_cannot_edit',
			__( 'Sorry, you are not allowed to edit this comment.' ),
			array( 'status' => rest_authorization_required_code() )
		);
	}

	/*
	 * check_edit_permission() above only establishes that the comment may be
	 * edited where it currently sits, because 'edit_comment' maps to 'edit_post'
	 * on the comment's current parent. When the parent is being changed, the new
	 * parent has to be authorized as well. Without this, a user holding
	 * edit_comment on their own comment or note could reparent it onto any post,
	 * including posts they can neither read nor edit.
	 */
	if ( isset( $request['post'] ) && (int) $request['post'] !== (int) $comment->comment_post_ID ) {
		$target_check = $this->check_target_post_permission(
			(int) $request['post'],
			$request,
			'note' === $comment->comment_type
		);

		if ( is_wp_error( $target_check ) ) {
			return $target_check;
		}
	}

	return true;
}