-
Notifications
You must be signed in to change notification settings - Fork 4.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix: Check permissions on duplicate pattern and template part actions. #62757
Fix: Check permissions on duplicate pattern and template part actions. #62757
Conversation
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.
To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Size Change: +31 B (0%) Total Size: 1.76 MB
ℹ️ View Unchanged
|
isTemplateOrTemplatePart && | ||
userCanCreatePostType && | ||
duplicateTemplatePartAction, | ||
isPattern && userCanCreatePostType && duplicatePatternAction, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are these both saved as blocks
CPTs?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
With that I mean: both patterns and template parts?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No, patterns are on wp_block/blocks and template parts are on wp_template_part/template_parts. But we are checking if the user can create the post type the actions are being used on userCanCreatePostType: canUser( 'create', resource ). So the same condition can apply to both.
Handled in #62823. |
Follow up to #62633.
Adds permission checks on the duplicate pattern and template_part actions.
We can not test the check on template_part because it depends on the edit_theme_options capability and as of right now, the user can never see template parts if the capability is not present, but for consistency and in case things change, we should have the check.
Testing Instructions
I pasted the following test code that removes the ability to create patterns (while still allowing to edit them).
I went to wp-admin/site-editor.php?postType=wp_block and I tried to duplicate a pattern and verified the UI did not show that option.