WP_REST_Comments_Controller::update_item_permissions_check
Checks if a given REST request has access to update a comment.
Method of the class: WP_REST_Comments_Controller{}
No Hooks.
Returns
true|WP_Error. True if the request has access to update the item, error object otherwise.
Usage
$WP_REST_Comments_Controller = new WP_REST_Comments_Controller(); $WP_REST_Comments_Controller->update_item_permissions_check( $request );
- $request(WP_REST_Request) (required)
- Full details about the request.
Changelog
| Since 4.7.0 | Introduced. |
| Since 7.1.1 | Target post permissions are checked when a comment's parent post is changed. |
WP_REST_Comments_Controller::update_item_permissions_check() WP REST Comments Controller::update item permissions check code WP 7.1.2
public function update_item_permissions_check( $request ) {
$comment = $this->get_comment( $request['id'] );
if ( is_wp_error( $comment ) ) {
return $comment;
}
if ( ! $this->check_edit_permission( $comment ) ) {
return new WP_Error(
'rest_cannot_edit',
__( 'Sorry, you are not allowed to edit this comment.' ),
array( 'status' => rest_authorization_required_code() )
);
}
/*
* check_edit_permission() above only establishes that the comment may be
* edited where it currently sits, because 'edit_comment' maps to 'edit_post'
* on the comment's current parent. When the parent is being changed, the new
* parent has to be authorized as well. Without this, a user holding
* edit_comment on their own comment or note could reparent it onto any post,
* including posts they can neither read nor edit.
*/
if ( isset( $request['post'] ) && (int) $request['post'] !== (int) $comment->comment_post_ID ) {
$target_check = $this->check_target_post_permission(
(int) $request['post'],
$request,
'note' === $comment->comment_type
);
if ( is_wp_error( $target_check ) ) {
return $target_check;
}
}
return true;
}