summaryrefslogtreecommitdiffstatshomepage
path: root/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php
diff options
context:
space:
mode:
Diffstat (limited to 'src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php')
-rw-r--r--src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php203
1 files changed, 167 insertions, 36 deletions
diff --git a/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php b/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php
index 301d41dbf6..19e745a415 100644
--- a/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php
+++ b/src/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php
@@ -173,7 +173,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
return false;
}
- return new WP_Error( 'rest_invalid_param', __( 'Invalid user parameter(s).' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_invalid_param',
+ __( 'Invalid user parameter(s).' ),
+ array( 'status' => 400 )
+ );
}
/**
@@ -187,15 +191,27 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
public function get_items_permissions_check( $request ) {
// Check if roles is specified in GET request and if user can list users.
if ( ! empty( $request['roles'] ) && ! current_user_can( 'list_users' ) ) {
- return new WP_Error( 'rest_user_cannot_view', __( 'Sorry, you are not allowed to filter users by role.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_user_cannot_view',
+ __( 'Sorry, you are not allowed to filter users by role.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
if ( 'edit' === $request['context'] && ! current_user_can( 'list_users' ) ) {
- return new WP_Error( 'rest_forbidden_context', __( 'Sorry, you are not allowed to list users.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_forbidden_context',
+ __( 'Sorry, you are not allowed to list users.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
if ( in_array( $request['orderby'], array( 'email', 'registered_date' ), true ) && ! current_user_can( 'list_users' ) ) {
- return new WP_Error( 'rest_forbidden_orderby', __( 'Sorry, you are not allowed to order users by this parameter.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_forbidden_orderby',
+ __( 'Sorry, you are not allowed to order users by this parameter.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
if ( 'authors' === $request['who'] ) {
@@ -208,7 +224,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
}
}
- return new WP_Error( 'rest_forbidden_who', __( 'Sorry, you are not allowed to query users by this parameter.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_forbidden_who',
+ __( 'Sorry, you are not allowed to query users by this parameter.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
return true;
@@ -358,7 +378,12 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
* @return WP_User|WP_Error True if ID is valid, WP_Error otherwise.
*/
protected function get_user( $id ) {
- $error = new WP_Error( 'rest_user_invalid_id', __( 'Invalid user ID.' ), array( 'status' => 404 ) );
+ $error = new WP_Error(
+ 'rest_user_invalid_id',
+ __( 'Invalid user ID.' ),
+ array( 'status' => 404 )
+ );
+
if ( (int) $id <= 0 ) {
return $error;
}
@@ -396,9 +421,17 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
}
if ( 'edit' === $request['context'] && ! current_user_can( 'list_users' ) ) {
- return new WP_Error( 'rest_user_cannot_view', __( 'Sorry, you are not allowed to list users.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_user_cannot_view',
+ __( 'Sorry, you are not allowed to list users.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
} elseif ( ! count_user_posts( $user->ID, $types ) && ! current_user_can( 'edit_user', $user->ID ) && ! current_user_can( 'list_users' ) ) {
- return new WP_Error( 'rest_user_cannot_view', __( 'Sorry, you are not allowed to list users.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_user_cannot_view',
+ __( 'Sorry, you are not allowed to list users.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
return true;
@@ -436,7 +469,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$current_user_id = get_current_user_id();
if ( empty( $current_user_id ) ) {
- return new WP_Error( 'rest_not_logged_in', __( 'You are not currently logged in.' ), array( 'status' => 401 ) );
+ return new WP_Error(
+ 'rest_not_logged_in',
+ __( 'You are not currently logged in.' ),
+ array( 'status' => 401 )
+ );
}
$user = wp_get_current_user();
@@ -457,7 +494,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
public function create_item_permissions_check( $request ) {
if ( ! current_user_can( 'create_users' ) ) {
- return new WP_Error( 'rest_cannot_create_user', __( 'Sorry, you are not allowed to create new users.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_cannot_create_user',
+ __( 'Sorry, you are not allowed to create new users.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
return true;
@@ -473,7 +514,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
*/
public function create_item( $request ) {
if ( ! empty( $request['id'] ) ) {
- return new WP_Error( 'rest_user_exists', __( 'Cannot create existing user.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_exists',
+ __( 'Cannot create existing user.' ),
+ array( 'status' => 400 )
+ );
}
$schema = $this->get_item_schema();
@@ -492,12 +537,19 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$ret = wpmu_validate_user_signup( $user->user_login, $user->user_email );
if ( is_wp_error( $ret['errors'] ) && $ret['errors']->has_errors() ) {
- $error = new WP_Error( 'rest_invalid_param', __( 'Invalid user parameter(s).' ), array( 'status' => 400 ) );
+ $error = new WP_Error(
+ 'rest_invalid_param',
+ __( 'Invalid user parameter(s).' ),
+ array( 'status' => 400 )
+ );
+
foreach ( $ret['errors']->errors as $code => $messages ) {
foreach ( $messages as $message ) {
$error->add( $code, $message );
}
+
$error_data = $error->get_error_data( $code );
+
if ( $error_data ) {
$error->add_data( $error_data, $code );
}
@@ -510,7 +562,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$user_id = wpmu_create_user( $user->user_login, $user->user_pass, $user->user_email );
if ( ! $user_id ) {
- return new WP_Error( 'rest_user_create', __( 'Error creating new user.' ), array( 'status' => 500 ) );
+ return new WP_Error(
+ 'rest_user_create',
+ __( 'Error creating new user.' ),
+ array( 'status' => 500 )
+ );
}
$user->ID = $user_id;
@@ -602,7 +658,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
if ( ! empty( $request['roles'] ) ) {
if ( ! current_user_can( 'promote_user', $user->ID ) ) {
- return new WP_Error( 'rest_cannot_edit_roles', __( 'Sorry, you are not allowed to edit roles of this user.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_cannot_edit_roles',
+ __( 'Sorry, you are not allowed to edit roles of this user.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
$request_params = array_keys( $request->get_params() );
@@ -615,7 +675,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
}
if ( ! current_user_can( 'edit_user', $user->ID ) ) {
- return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to edit this user.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_cannot_edit',
+ __( 'Sorry, you are not allowed to edit this user.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
return true;
@@ -638,21 +702,37 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$id = $user->ID;
if ( ! $user ) {
- return new WP_Error( 'rest_user_invalid_id', __( 'Invalid user ID.' ), array( 'status' => 404 ) );
+ return new WP_Error(
+ 'rest_user_invalid_id',
+ __( 'Invalid user ID.' ),
+ array( 'status' => 404 )
+ );
}
$owner_id = email_exists( $request['email'] );
if ( $owner_id && $owner_id !== $id ) {
- return new WP_Error( 'rest_user_invalid_email', __( 'Invalid email address.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_email',
+ __( 'Invalid email address.' ),
+ array( 'status' => 400 )
+ );
}
if ( ! empty( $request['username'] ) && $request['username'] !== $user->user_login ) {
- return new WP_Error( 'rest_user_invalid_argument', __( "Username isn't editable." ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_argument',
+ __( "Username isn't editable." ),
+ array( 'status' => 400 )
+ );
}
if ( ! empty( $request['slug'] ) && $request['slug'] !== $user->user_nicename && get_user_by( 'slug', $request['slug'] ) ) {
- return new WP_Error( 'rest_user_invalid_slug', __( 'Invalid slug.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_slug',
+ __( 'Invalid slug.' ),
+ array( 'status' => 400 )
+ );
}
if ( ! empty( $request['roles'] ) ) {
@@ -754,7 +834,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
}
if ( ! current_user_can( 'delete_user', $user->ID ) ) {
- return new WP_Error( 'rest_user_cannot_delete', __( 'Sorry, you are not allowed to delete this user.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_user_cannot_delete',
+ __( 'Sorry, you are not allowed to delete this user.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
return true;
@@ -771,9 +855,15 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
public function delete_item( $request ) {
// We don't support delete requests in multisite.
if ( is_multisite() ) {
- return new WP_Error( 'rest_cannot_delete', __( 'The user cannot be deleted.' ), array( 'status' => 501 ) );
+ return new WP_Error(
+ 'rest_cannot_delete',
+ __( 'The user cannot be deleted.' ),
+ array( 'status' => 501 )
+ );
}
+
$user = $this->get_user( $request['id'] );
+
if ( is_wp_error( $user ) ) {
return $user;
}
@@ -784,13 +874,21 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
// We don't support trashing for users.
if ( ! $force ) {
- /* translators: %s: force=true */
- return new WP_Error( 'rest_trash_not_supported', sprintf( __( "Users do not support trashing. Set '%s' to delete." ), 'force=true' ), array( 'status' => 501 ) );
+ return new WP_Error(
+ 'rest_trash_not_supported',
+ /* translators: %s: force=true */
+ sprintf( __( "Users do not support trashing. Set '%s' to delete." ), 'force=true' ),
+ array( 'status' => 501 )
+ );
}
if ( ! empty( $reassign ) ) {
if ( $reassign === $id || ! get_userdata( $reassign ) ) {
- return new WP_Error( 'rest_user_invalid_reassign', __( 'Invalid user ID for reassignment.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_reassign',
+ __( 'Invalid user ID for reassignment.' ),
+ array( 'status' => 400 )
+ );
}
}
@@ -804,7 +902,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$result = wp_delete_user( $id, $reassign );
if ( ! $result ) {
- return new WP_Error( 'rest_cannot_delete', __( 'The user cannot be deleted.' ), array( 'status' => 500 ) );
+ return new WP_Error(
+ 'rest_cannot_delete',
+ __( 'The user cannot be deleted.' ),
+ array( 'status' => 500 )
+ );
}
$response = new WP_REST_Response();
@@ -1000,7 +1102,7 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$schema = $this->get_item_schema();
- // required arguments.
+ // Required arguments.
if ( isset( $request['email'] ) && ! empty( $schema['properties']['email'] ) ) {
$prepared_user->user_email = $request['email'];
}
@@ -1013,7 +1115,7 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$prepared_user->user_pass = $request['password'];
}
- // optional arguments.
+ // Optional arguments.
if ( isset( $request['id'] ) ) {
$prepared_user->ID = absint( $request['id'] );
}
@@ -1050,7 +1152,7 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$prepared_user->locale = $request['locale'];
}
- // setting roles will be handled outside of this function.
+ // Setting roles will be handled outside of this function.
if ( isset( $request['roles'] ) ) {
$prepared_user->role = false;
}
@@ -1082,8 +1184,12 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
foreach ( $roles as $role ) {
if ( ! isset( $wp_roles->role_objects[ $role ] ) ) {
- /* translators: %s: Role key. */
- return new WP_Error( 'rest_user_invalid_role', sprintf( __( 'The role %s does not exist.' ), $role ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_role',
+ /* translators: %s: Role key. */
+ sprintf( __( 'The role %s does not exist.' ), $role ),
+ array( 'status' => 400 )
+ );
}
$potential_role = $wp_roles->role_objects[ $role ];
@@ -1097,7 +1203,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
&& get_current_user_id() === $user_id
&& ! $potential_role->has_cap( 'edit_users' )
) {
- return new WP_Error( 'rest_user_invalid_role', __( 'Sorry, you are not allowed to give users that role.' ), array( 'status' => rest_authorization_required_code() ) );
+ return new WP_Error(
+ 'rest_user_invalid_role',
+ __( 'Sorry, you are not allowed to give users that role.' ),
+ array( 'status' => rest_authorization_required_code() )
+ );
}
/** Include admin functions to get access to get_editable_roles() */
@@ -1107,7 +1217,11 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$editable_roles = get_editable_roles();
if ( empty( $editable_roles[ $role ] ) ) {
- return new WP_Error( 'rest_user_invalid_role', __( 'Sorry, you are not allowed to give users that role.' ), array( 'status' => 403 ) );
+ return new WP_Error(
+ 'rest_user_invalid_role',
+ __( 'Sorry, you are not allowed to give users that role.' ),
+ array( 'status' => 403 )
+ );
}
}
@@ -1130,14 +1244,22 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$username = (string) $value;
if ( ! validate_username( $username ) ) {
- return new WP_Error( 'rest_user_invalid_username', __( 'Username contains invalid characters.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_username',
+ __( 'Username contains invalid characters.' ),
+ array( 'status' => 400 )
+ );
}
/** This filter is documented in wp-includes/user.php */
$illegal_logins = (array) apply_filters( 'illegal_user_logins', array() );
if ( in_array( strtolower( $username ), array_map( 'strtolower', $illegal_logins ), true ) ) {
- return new WP_Error( 'rest_user_invalid_username', __( 'Sorry, that username is not allowed.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_username',
+ __( 'Sorry, that username is not allowed.' ),
+ array( 'status' => 400 )
+ );
}
return $username;
@@ -1159,11 +1281,19 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$password = (string) $value;
if ( empty( $password ) ) {
- return new WP_Error( 'rest_user_invalid_password', __( 'Passwords cannot be empty.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_password',
+ __( 'Passwords cannot be empty.' ),
+ array( 'status' => 400 )
+ );
}
if ( false !== strpos( $password, '\\' ) ) {
- return new WP_Error( 'rest_user_invalid_password', __( 'Passwords cannot contain the "\\" character.' ), array( 'status' => 400 ) );
+ return new WP_Error(
+ 'rest_user_invalid_password',
+ __( 'Passwords cannot contain the "\\" character.' ),
+ array( 'status' => 400 )
+ );
}
return $password;
@@ -1338,6 +1468,7 @@ class WP_REST_Users_Controller extends WP_REST_Controller {
$schema['properties']['meta'] = $this->meta->get_field_schema();
$this->schema = $schema;
+
return $this->add_additional_fields_schema( $this->schema );
}