d01d7cf85d first commit лет назад: 4 woocommerce-th-a46e2cdf66e3645fd11b123961dc9b40.json d01d7cf85d first commit лет назад: 4 woocommerce-th-a55d428c84e9a3179fe241ec600a0f03.json d01d7cf85d first commit лет назад: 4 woocommerce-th-a65b4ddf263e8c410e9bcbfd6e6d72e4.json d01d7cf85d first commit лет назад: 4 woocommerce-th-a8b73b087444470c8f4396b7142908f6.json d01d7cf85d first commit лет назад: 4 woocommerce-th-abb904b047b7be3be9d638e2c6144691.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ae1c49c8c0597593a9c36e106a04bd60.json d01d7cf85d first commit лет назад: 4 woocommerce-th-aed4ce3ede1d44a8fecfe0edfbf8421c.json d01d7cf85d first commit лет назад: 4 woocommerce-th-af52ab8cb2e7713cf3037751dd593965.json d01d7cf85d first commit лет назад: 4 woocommerce-th-afbede9cda22f594a80ae8b178e0e98c.json d01d7cf85d first commit лет назад: 4 woocommerce-th-afd1e270efc2e8283acfd50ccab18d2b.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b007baff76144318d6c33cd26f4bfdb9.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b0a592b6fe83588c5d1b8ed6850b6a74.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b155b7bf28890099b74a84417cbaafe9.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b1bb8fbd24d68a9c893faf1a6f7b493b.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b1bcbab1d6a7ca6b0433d67776f347f1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b239ff15197a133498a4b025f002dee5.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b2e956ee35340f6e47f27f8a54309ac3.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b31f51fa0bb40ceb060aaa9f77ca1771.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b3f83696a2cb49f571043ce14a384a76.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b4bf1e55ca6145f38f1b2f104201da21.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b826befd7acca93e8e4c12b7cd2fc7f1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-b9bf1ca91d393a30e2461ef709f8fa10.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ba8d2fb7c85928310d4f3a907b7d9bdd.json d01d7cf85d first commit лет назад: 4 woocommerce-th-bb0f027faa1257de4b730158475093de.json d01d7cf85d first commit лет назад: 4 woocommerce-th-bb5c5935ec0d64e8880b1c7794470460.json d01d7cf85d first commit лет назад: 4 woocommerce-th-bc1f4f7aec77a0a6dd229cc910f601f1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-bc9c3f9eda462d6d9968c1dca51e7c62.json d01d7cf85d first commit лет назад: 4 woocommerce-th-bcb06ab6e8931a862dec9c07c66df45b.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c06829f63f73ae430c10ae700fb1eb6d.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c0faba84c7842505f8893c2c327a9f78.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c13acd243559529a685813d9871026a1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c1bc39bcdee2da3c0b62bcd5372120f4.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c22945301f466e2d78d6e80404a22664.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c2435bc8dfd186b147aba658416d115e.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c257c024e3db4e010644d2c7be3c7090.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c2d9a34cf502bd5b5a80ca646a1420b3.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c5702ace609dd30ccabd4c999de43096.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c608fe5deda8db7667c8431ca6fd222a.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c6c5331d3afe1391f2ca83e991ccc086.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c70671124b0e00661f88fe1616dfc9f0.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c8cbe8ef95155db152b270d441fc8528.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c8ddf2164475a213274d06873bfbb73a.json d01d7cf85d first commit лет назад: 4 woocommerce-th-c93706e596cbd46fb0d621f4fe3efb80.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ca3cd4394cb082bde7555ebd3bb5f143.json d01d7cf85d first commit лет назад: 4 woocommerce-th-cb71ce5ddcc7c808172e80a0dc9833d5.json d01d7cf85d first commit лет назад: 4 woocommerce-th-cc16013df9d4b0a0ba45297b90b06f20.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ccc500b0b722a0c96712f1634cbb7289.json d01d7cf85d first commit лет назад: 4 woocommerce-th-cd9fc1d9fc46b55bb32d0fd471457690.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ce3f8f2f3e0f3c58f8aea5b7aa5cc6f4.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d05ee634b22d05f0055b724443f05a68.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d0d05e0dda872b433f260969b4d53b30.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d0fa7cd1cd624e53cc7b4fde655c20af.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d2b4400b6de0e69404e0f7f61d16bc55.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d3e57c518feb58ab8ea4f9d2d8e66160.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d4c505e96199e8c818fc6d24151d9c4a.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d5ea33028f13b50f40bbcce807e37fc0.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d6f4faa954a31ef3d5b74c2dfe13f141.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d7bbe90eb59636eb8a6f31c7979ab6f5.json d01d7cf85d first commit лет назад: 4 woocommerce-th-d80020dab74131d7f0c108526c0fbebe.json d01d7cf85d first commit лет назад: 4 woocommerce-th-da92a9b2d4c08762c60d7c4c569eb5db.json d01d7cf85d first commit лет назад: 4 woocommerce-th-de12a4697822740a2fbaeb47c5062af1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-deed2aed3392b43c83c7cea296b154af.json d01d7cf85d first commit лет назад: 4 woocommerce-th-df51042cba56a4e9fcac0e5db643906a.json d01d7cf85d first commit лет назад: 4 woocommerce-th-dfb09f9953676bbc1de4eb2b9f232c6d.json d01d7cf85d first commit лет назад: 4 woocommerce-th-dfbfe3d556f60ebbd62c2b5c8e0fa466.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e03ec35386c2705c11cebd6288b33cf8.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e0bde0ac58f55fc6b1426844e6697db3.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e0f9c7d89b1b130a9023c5c2fde2815e.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e41c58d5fb39f750efcbf65a2b55460b.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e44671e4528b0da3a0fd6feaf8abadca.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e4fbc8d7fc7a16bd8cf2e0522a199de0.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e690486b33a7bb1944a37f6e734d734f.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e80539b9960e930bf0dcd334d99eb128.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e885442559cb44e8b827f0e0ca0a14c9.json d01d7cf85d first commit лет назад: 4 woocommerce-th-e88dc35c02f6fa832e90fac5a122323c.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ea6fb371f81c4d3584bbc795fa4ac09c.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ed9b16000a6d37c51bf23c61f4df878e.json d01d7cf85d first commit лет назад: 4 woocommerce-th-ef5798395d7601ab6fea0f1efd60f40a.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f31b0aa0c71dd74b7103120610ca6253.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f34924aeff974b0bdbfac124c23fbfe3.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f39008456fd28b2f79cdb0964ff294e1.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f3f1cc4f5811d4bf8a04a58feca06858.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f56e66fd08c07abc78cd844f7e83af8c.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f60049653c419cfb1e3dc8876e7a8bdb.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f686a272add740773cdcb730afdb5454.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f976da155dfdd080588c50ccda5af747.json d01d7cf85d first commit лет назад: 4 woocommerce-th-f9c56a0cbb6710505047e6c835953c82.json d01d7cf85d first commit лет назад: 4 woocommerce-th-fb2ef023bdd44902b5a309e25e0b7792.json d01d7cf85d first commit лет назад: 4 woocommerce-th-fc1fe56fadfdeeb25d1bc441581d92b6.json d01d7cf85d first commit лет назад: 4 woocommerce-th-fc4895b6508f32c16c4d8bc69f8162b6.json d01d7cf85d first commit лет назад: 4 woocommerce-th-fd20fc8ea1484781160e8ea0d229d5e9.json d01d7cf85d first commit лет назад: 4 woocommerce-th-fffdec5db595ec0ca7d043c87bae79b8.json d01d7cf85d first commit лет назад: 4 woocommerce-th-wc-admin-app.json d01d7cf85d first commit лет назад: 4 woocommerce-th.mo d01d7cf85d first commit лет назад: 4 woocommerce-th.po d01d7cf85d first commit лет назад: 4 tum/whitesports - Gogs: Simplico Git Service

Нет описания

class-wc-api-resource.php 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410
  1. <?php
  2. /**
  3. * WooCommerce API Resource class
  4. *
  5. * Provides shared functionality for resource-specific API classes
  6. *
  7. * @author WooThemes
  8. * @category API
  9. * @package WooCommerce\RestApi
  10. * @since 2.1
  11. * @version 2.1
  12. */
  13. if ( ! defined( 'ABSPATH' ) ) {
  14. exit; // Exit if accessed directly
  15. }
  16. class WC_API_Resource {
  17. /** @var WC_API_Server the API server */
  18. protected $server;
  19. /** @var string sub-classes override this to set a resource-specific base route */
  20. protected $base;
  21. /**
  22. * Setup class
  23. *
  24. * @since 2.1
  25. * @param WC_API_Server $server
  26. */
  27. public function __construct( WC_API_Server $server ) {
  28. $this->server = $server;
  29. // automatically register routes for sub-classes
  30. add_filter( 'woocommerce_api_endpoints', array( $this, 'register_routes' ) );
  31. // remove fields from responses when requests specify certain fields
  32. // note these are hooked at a later priority so data added via filters (e.g. customer data to the order response)
  33. // still has the fields filtered properly
  34. foreach ( array( 'order', 'coupon', 'customer', 'product', 'report' ) as $resource ) {
  35. add_filter( "woocommerce_api_{$resource}_response", array( $this, 'maybe_add_meta' ), 15, 2 );
  36. add_filter( "woocommerce_api_{$resource}_response", array( $this, 'filter_response_fields' ), 20, 3 );
  37. }
  38. }
  39. /**
  40. * Validate the request by checking:
  41. *
  42. * 1) the ID is a valid integer
  43. * 2) the ID returns a valid post object and matches the provided post type
  44. * 3) the current user has the proper permissions to read/edit/delete the post
  45. *
  46. * @since 2.1
  47. * @param string|int $id the post ID
  48. * @param string $type the post type, either `shop_order`, `shop_coupon`, or `product`
  49. * @param string $context the context of the request, either `read`, `edit` or `delete`
  50. * @return int|WP_Error valid post ID or WP_Error if any of the checks fails
  51. */
  52. protected function validate_request( $id, $type, $context ) {
  53. if ( 'shop_order' === $type || 'shop_coupon' === $type ) {
  54. $resource_name = str_replace( 'shop_', '', $type );
  55. } else {
  56. $resource_name = $type;
  57. }
  58. $id = absint( $id );
  59. // validate ID
  60. if ( empty( $id ) ) {
  61. return new WP_Error( "woocommerce_api_invalid_{$resource_name}_id", sprintf( __( 'Invalid %s ID', 'woocommerce' ), $type ), array( 'status' => 404 ) );
  62. }
  63. // only custom post types have per-post type/permission checks
  64. if ( 'customer' !== $type ) {
  65. $post = get_post( $id );
  66. // for checking permissions, product variations are the same as the product post type
  67. $post_type = ( 'product_variation' === $post->post_type ) ? 'product' : $post->post_type;
  68. // validate post type
  69. if ( $type !== $post_type ) {
  70. return new WP_Error( "woocommerce_api_invalid_{$resource_name}", sprintf( __( 'Invalid %s', 'woocommerce' ), $resource_name ), array( 'status' => 404 ) );
  71. }
  72. // validate permissions
  73. switch ( $context ) {
  74. case 'read':
  75. if ( ! $this->is_readable( $post ) ) {
  76. return new WP_Error( "woocommerce_api_user_cannot_read_{$resource_name}", sprintf( __( 'You do not have permission to read this %s', 'woocommerce' ), $resource_name ), array( 'status' => 401 ) );
  77. }
  78. break;
  79. case 'edit':
  80. if ( ! $this->is_editable( $post ) ) {
  81. return new WP_Error( "woocommerce_api_user_cannot_edit_{$resource_name}", sprintf( __( 'You do not have permission to edit this %s', 'woocommerce' ), $resource_name ), array( 'status' => 401 ) );
  82. }
  83. break;
  84. case 'delete':
  85. if ( ! $this->is_deletable( $post ) ) {
  86. return new WP_Error( "woocommerce_api_user_cannot_delete_{$resource_name}", sprintf( __( 'You do not have permission to delete this %s', 'woocommerce' ), $resource_name ), array( 'status' => 401 ) );
  87. }
  88. break;
  89. }
  90. }
  91. return $id;
  92. }
  93. /**
  94. * Add common request arguments to argument list before WP_Query is run
  95. *
  96. * @since 2.1
  97. * @param array $base_args required arguments for the query (e.g. `post_type`, etc)
  98. * @param array $request_args arguments provided in the request
  99. * @return array
  100. */
  101. protected function merge_query_args( $base_args, $request_args ) {
  102. $args = array();
  103. // date
  104. if ( ! empty( $request_args['created_at_min'] ) || ! empty( $request_args['created_at_max'] ) || ! empty( $request_args['updated_at_min'] ) || ! empty( $request_args['updated_at_max'] ) ) {
  105. $args['date_query'] = array();
  106. // resources created after specified date
  107. if ( ! empty( $request_args['created_at_min'] ) ) {
  108. $args['date_query'][] = array( 'column' => 'post_date_gmt', 'after' => $this->server->parse_datetime( $request_args['created_at_min'] ), 'inclusive' => true );
  109. }
  110. // resources created before specified date
  111. if ( ! empty( $request_args['created_at_max'] ) ) {
  112. $args['date_query'][] = array( 'column' => 'post_date_gmt', 'before' => $this->server->parse_datetime( $request_args['created_at_max'] ), 'inclusive' => true );
  113. }
  114. // resources updated after specified date
  115. if ( ! empty( $request_args['updated_at_min'] ) ) {
  116. $args['date_query'][] = array( 'column' => 'post_modified_gmt', 'after' => $this->server->parse_datetime( $request_args['updated_at_min'] ), 'inclusive' => true );
  117. }
  118. // resources updated before specified date
  119. if ( ! empty( $request_args['updated_at_max'] ) ) {
  120. $args['date_query'][] = array( 'column' => 'post_modified_gmt', 'before' => $this->server->parse_datetime( $request_args['updated_at_max'] ), 'inclusive' => true );
  121. }
  122. }
  123. // search
  124. if ( ! empty( $request_args['q'] ) ) {
  125. $args['s'] = $request_args['q'];
  126. }
  127. // resources per response
  128. if ( ! empty( $request_args['limit'] ) ) {
  129. $args['posts_per_page'] = $request_args['limit'];
  130. }
  131. // resource offset
  132. if ( ! empty( $request_args['offset'] ) ) {
  133. $args['offset'] = $request_args['offset'];
  134. }
  135. // resource page
  136. $args['paged'] = ( isset( $request_args['page'] ) ) ? absint( $request_args['page'] ) : 1;
  137. return array_merge( $base_args, $args );
  138. }
  139. /**
  140. * Add meta to resources when requested by the client. Meta is added as a top-level
  141. * `<resource_name>_meta` attribute (e.g. `order_meta`) as a list of key/value pairs
  142. *
  143. * @since 2.1
  144. * @param array $data the resource data
  145. * @param object $resource the resource object (e.g WC_Order)
  146. * @return mixed
  147. */
  148. public function maybe_add_meta( $data, $resource ) {
  149. if ( isset( $this->server->params['GET']['filter']['meta'] ) && 'true' === $this->server->params['GET']['filter']['meta'] && is_object( $resource ) ) {
  150. // don't attempt to add meta more than once
  151. if ( preg_grep( '/[a-z]+_meta/', array_keys( $data ) ) ) {
  152. return $data;
  153. }
  154. // define the top-level property name for the meta
  155. switch ( get_class( $resource ) ) {
  156. case 'WC_Order':
  157. $meta_name = 'order_meta';
  158. break;
  159. case 'WC_Coupon':
  160. $meta_name = 'coupon_meta';
  161. break;
  162. case 'WP_User':
  163. $meta_name = 'customer_meta';
  164. break;
  165. default:
  166. $meta_name = 'product_meta';
  167. break;
  168. }
  169. if ( is_a( $resource, 'WP_User' ) ) {
  170. // customer meta
  171. $meta = (array) get_user_meta( $resource->ID );
  172. } else {
  173. // coupon/order/product meta
  174. $meta = (array) get_post_meta( $resource->get_id() );
  175. }
  176. foreach ( $meta as $meta_key => $meta_value ) {
  177. // don't add hidden meta by default
  178. if ( ! is_protected_meta( $meta_key ) ) {
  179. $data[ $meta_name ][ $meta_key ] = maybe_unserialize( $meta_value[0] );
  180. }
  181. }
  182. }
  183. return $data;
  184. }
  185. /**
  186. * Restrict the fields included in the response if the request specified certain only certain fields should be returned
  187. *
  188. * @since 2.1
  189. * @param array $data the response data
  190. * @param object $resource the object that provided the response data, e.g. WC_Coupon or WC_Order
  191. * @param array|string the requested list of fields to include in the response
  192. * @return array response data
  193. */
  194. public function filter_response_fields( $data, $resource, $fields ) {
  195. if ( ! is_array( $data ) || empty( $fields ) ) {
  196. return $data;
  197. }
  198. $fields = explode( ',', $fields );
  199. $sub_fields = array();
  200. // get sub fields
  201. foreach ( $fields as $field ) {
  202. if ( false !== strpos( $field, '.' ) ) {
  203. list( $name, $value ) = explode( '.', $field );
  204. $sub_fields[ $name ] = $value;
  205. }
  206. }
  207. // iterate through top-level fields
  208. foreach ( $data as $data_field => $data_value ) {
  209. // if a field has sub-fields and the top-level field has sub-fields to filter
  210. if ( is_array( $data_value ) && in_array( $data_field, array_keys( $sub_fields ) ) ) {
  211. // iterate through each sub-field
  212. foreach ( $data_value as $sub_field => $sub_field_value ) {
  213. // remove non-matching sub-fields
  214. if ( ! in_array( $sub_field, $sub_fields ) ) {
  215. unset( $data[ $data_field ][ $sub_field ] );
  216. }
  217. }
  218. } else {
  219. // remove non-matching top-level fields
  220. if ( ! in_array( $data_field, $fields ) ) {
  221. unset( $data[ $data_field ] );
  222. }
  223. }
  224. }
  225. return $data;
  226. }
  227. /**
  228. * Delete a given resource
  229. *
  230. * @since 2.1
  231. * @param int $id the resource ID
  232. * @param string $type the resource post type, or `customer`
  233. * @param bool $force true to permanently delete resource, false to move to trash (not supported for `customer`)
  234. * @return array|WP_Error
  235. */
  236. protected function delete( $id, $type, $force = false ) {
  237. if ( 'shop_order' === $type || 'shop_coupon' === $type ) {
  238. $resource_name = str_replace( 'shop_', '', $type );
  239. } else {
  240. $resource_name = $type;
  241. }
  242. if ( 'customer' === $type ) {
  243. $result = wp_delete_user( $id );
  244. if ( $result ) {
  245. return array( 'message' => __( 'Permanently deleted customer', 'woocommerce' ) );
  246. } else {
  247. return new WP_Error( 'woocommerce_api_cannot_delete_customer', __( 'The customer cannot be deleted', 'woocommerce' ), array( 'status' => 500 ) );
  248. }
  249. } else {
  250. // delete order/coupon/product
  251. $result = ( $force ) ? wp_delete_post( $id, true ) : wp_trash_post( $id );
  252. if ( ! $result ) {
  253. return new WP_Error( "woocommerce_api_cannot_delete_{$resource_name}", sprintf( __( 'This %s cannot be deleted', 'woocommerce' ), $resource_name ), array( 'status' => 500 ) );
  254. }
  255. if ( $force ) {
  256. return array( 'message' => sprintf( __( 'Permanently deleted %s', 'woocommerce' ), $resource_name ) );
  257. } else {
  258. $this->server->send_status( '202' );
  259. return array( 'message' => sprintf( __( 'Deleted %s', 'woocommerce' ), $resource_name ) );
  260. }
  261. }
  262. }
  263. /**
  264. * Checks if the given post is readable by the current user
  265. *
  266. * @since 2.1
  267. * @see WC_API_Resource::check_permission()
  268. * @param WP_Post|int $post
  269. * @return bool
  270. */
  271. protected function is_readable( $post ) {
  272. return $this->check_permission( $post, 'read' );
  273. }
  274. /**
  275. * Checks if the given post is editable by the current user
  276. *
  277. * @since 2.1
  278. * @see WC_API_Resource::check_permission()
  279. * @param WP_Post|int $post
  280. * @return bool
  281. */
  282. protected function is_editable( $post ) {
  283. return $this->check_permission( $post, 'edit' );
  284. }
  285. /**
  286. * Checks if the given post is deletable by the current user
  287. *
  288. * @since 2.1
  289. * @see WC_API_Resource::check_permission()
  290. * @param WP_Post|int $post
  291. * @return bool
  292. */
  293. protected function is_deletable( $post ) {
  294. return $this->check_permission( $post, 'delete' );
  295. }
  296. /**
  297. * Checks the permissions for the current user given a post and context
  298. *
  299. * @since 2.1
  300. * @param WP_Post|int $post
  301. * @param string $context the type of permission to check, either `read`, `write`, or `delete`
  302. * @return bool true if the current user has the permissions to perform the context on the post
  303. */
  304. private function check_permission( $post, $context ) {
  305. if ( ! is_a( $post, 'WP_Post' ) ) {
  306. $post = get_post( $post );
  307. }
  308. if ( is_null( $post ) ) {
  309. return false;
  310. }
  311. $post_type = get_post_type_object( $post->post_type );
  312. if ( 'read' === $context ) {
  313. return current_user_can( $post_type->cap->read_private_posts, $post->ID );
  314. } elseif ( 'edit' === $context ) {
  315. return current_user_can( $post_type->cap->edit_post, $post->ID );
  316. } elseif ( 'delete' === $context ) {
  317. return current_user_can( $post_type->cap->delete_post, $post->ID );
  318. } else {
  319. return false;
  320. }
  321. }
  322. }