session_id); } if ($endpoint === 'get-connected-collaboration-users-list') { $post_id = HelperFunctions::sanitize_text($_GET['post_id']); $res = Collaboration::get_connected_collaboration_users_list($post_id); wp_send_json($res); } /** * Staging GET APIs * @deprecated * @see GET /pages/{pageId}/staged-versions */ // if ('get-all-staged-versions' === $endpoint) { // $post_id = (int) HelperFunctions::sanitize_text(isset($_GET['post_id']) ? $_GET['post_id'] : null); // Staging::get_all_staged_versions($post_id, false, true); // } } /** * Check if the current request can access wp endpoints. * * @return bool */ private function user_can_access_get_apis() { if (HelperFunctions::is_api_call_from_editor_preview() && HelperFunctions::is_api_header_post_editor_preview_token_valid()) { return true; } return is_user_logged_in() && HelperFunctions::has_access( array( KIRKI_ACCESS_LEVELS['FULL_ACCESS'], KIRKI_ACCESS_LEVELS['EDITOR_ACCESS'], KIRKI_ACCESS_LEVELS['CONTENT_ACCESS'], KIRKI_ACCESS_LEVELS['VIEW_ACCESS'], ) ); } /** * Initialize the admin post apis * * @return void */ public function kirki_wp_admin_post_apis() { HelperFunctions::verify_nonce('wp_rest'); if (!HelperFunctions::user_is_admin()) { wp_send_json_error('Not authorized'); } //phpcs:ignore WordPress.Security.NonceVerification.Missing,WordPress.Security.NonceVerification.Recommended,WordPress.Security.ValidatedSanitizedInput.MissingUnslash,WordPress.Security.ValidatedSanitizedInput.InputNotSanitized $endpoint = HelperFunctions::sanitize_text(isset($_POST['endpoint']) ? $_POST['endpoint'] : null); if ($endpoint === 'save-common-data') { WpAdmin::save_common_data(); } if ($endpoint === 'update-license-validity') { WpAdmin::update_license_validity(); } // if ($endpoint === 'update-access-level') { // RBAC::update_access_level(); // } if ($endpoint === 'delete-form-row') { Form::delete_form_row(); } if ($endpoint === 'delete-form') { Form::delete_form(); } if ($endpoint === 'update-form-cell') { Form::update_form_row(); } /** * Export Template */ if ($endpoint === 'import-template') { TemplateExportImport::import(); } if ($endpoint === 'process-imported-template') { TemplateExportImport::processImport(); } if ($endpoint === 'process-export-template') { TemplateExportImport::processExport(); } if ($endpoint === 'save-editor-read-only-access-data') { Page::save_editor_read_only_access_data(); } /** * Export Template */ if ($endpoint === 'export-template') { TemplateExportImport::export(); } } /** * Return an explicit unauthorized response for unauthenticated admin AJAX requests. * * @return void */ public function kirki_wp_admin_unauthorized() { wp_send_json_error('Not authorized', 401); } /** * Initialize the admin get apis * * @return void */ public function kirki_wp_admin_get_apis() { HelperFunctions::verify_nonce('wp_rest'); if (!is_admin()) { wp_send_json_error('Not authorized', 401); } if (!HelperFunctions::user_is_admin()) { wp_send_json_error('Not authorized', 401); } //phpcs:ignore WordPress.Security.NonceVerification.Missing,WordPress.Security.NonceVerification.Recommended,WordPress.Security.ValidatedSanitizedInput.MissingUnslash,WordPress.Security.ValidatedSanitizedInput.InputNotSanitized $endpoint = HelperFunctions::sanitize_text(isset($_GET['endpoint']) ? $_GET['endpoint'] : null); if ($endpoint === 'get-common-data') { WpAdmin::get_common_data(); } // From manipulation from admin dashboard. if ($endpoint === 'get-forms') { Form::get_forms(); } if ($endpoint === 'get-form-data') { Form::get_form_data(); } if ($endpoint === 'get-wp-admin-page-data') { Page::get_pages_for_pages_panel(); } if ($endpoint === 'get-members-based-on-role') { RBAC::members_based_on_role(); } if ($endpoint === 'download-form-data') { if (!HelperFunctions::user_has_builder_access()) { wp_send_json_error('Not authorized'); } Form::download_form_data(); } // From manipulation from admin dashboard. if ($endpoint === 'get-editor-read-only-access-data') { if (!HelperFunctions::user_has_builder_access()) { wp_send_json_error('Not authorized', 401); } Page::get_editor_read_only_access_data(); } } }