Let offering managers read the offerings catalogue
CI / Tests (PHP 8.1) (pull_request) Successful in 46s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.2) (pull_request) Successful in 56s
CI / PHPStan (pull_request) Successful in 2m56s
CI / Coding Standards (pull_request) Successful in 2m58s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
CI / Tests (PHP 8.1) (pull_request) Successful in 46s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.2) (pull_request) Successful in 56s
CI / PHPStan (pull_request) Successful in 2m56s
CI / Coding Standards (pull_request) Successful in 2m58s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
The block editor's group-class picker fetches GET /offerings, whose permission callback only accepted book_lesson — a capability held by students alone. Administrators and instructors editing a page were rejected with a 403 and the picker silently rendered an empty list. Read access now accepts book_lesson or manage_offerings. The listing is unchanged: active offerings only, public ones plus the invite-only classes the caller has been granted, without the e-transfer email. Closes #121 Co-Authored-By: Claude Opus 5 <[email protected]>
This commit is contained in:
@@ -28,7 +28,7 @@ class OfferingEndpoint {
|
||||
[
|
||||
'methods' => \WP_REST_Server::READABLE,
|
||||
'callback' => [ $this, 'index' ],
|
||||
'permission_callback' => [ $this, 'canBook' ],
|
||||
'permission_callback' => [ $this, 'canRead' ],
|
||||
'args' => [
|
||||
'instructor_id' => [
|
||||
'type' => 'integer',
|
||||
@@ -262,12 +262,16 @@ class OfferingEndpoint {
|
||||
}
|
||||
|
||||
/**
|
||||
* Reading the offerings catalogue is only needed by the logged-in student
|
||||
* booking flow, so it requires the same capability as booking — there is no
|
||||
* anonymous consumer.
|
||||
* Reading the offerings catalogue has no anonymous consumer, so it stays
|
||||
* behind a login. Students reach it through the booking flow, and studio
|
||||
* admins and instructors reach it from the block editor's group-class
|
||||
* pickers — an administrator holds `manage_offerings` but not
|
||||
* `book_lesson`, so both capabilities open the listing.
|
||||
*/
|
||||
public function canBook(): bool {
|
||||
return is_user_logged_in() && current_user_can( RoleManager::CAP_BOOK_LESSON );
|
||||
public function canRead(): bool {
|
||||
return is_user_logged_in()
|
||||
&& ( current_user_can( RoleManager::CAP_BOOK_LESSON )
|
||||
|| current_user_can( RoleManager::CAP_MANAGE_OFFERINGS ) );
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user