WP_REST_Comments_Controller::check_target_post_permission( int $post_id )

Checks that a post can receive a comment from the current user.


Description

Used when changing the parent post of an existing comment, so that attaching a comment to a post is authorized the same way whichever path it arrives by.


Parameters

$post_id

(int) (Required) Target post ID.


Return

(true|WP_Error) True if the post can receive the comment, error object otherwise.


Source

File: wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php

	protected function check_target_post_permission( $post_id ) {
		if ( ! $post_id ) {
			return new WP_Error(
				'rest_comment_invalid_post_id',
				__( 'Sorry, you are not allowed to create this comment without a post.' ),
				array( 'status' => 403 )
			);
		}

		/*
		 * A comment needs either comment moderation rights or edit access to the
		 * post, which is what check_edit_permission() grants on the post a comment
		 * is moving away from. Requiring the same at the destination means both
		 * ends of a move are authorized alike.
		 */
		if ( ! current_user_can( 'moderate_comments' ) && ! current_user_can( 'edit_post', $post_id ) ) {
			return new WP_Error(
				'rest_cannot_edit',
				__( 'Sorry, you are not allowed to edit this comment.' ),
				array( 'status' => rest_authorization_required_code() )
			);
		}

		$post = get_post( $post_id );

		if ( ! $post ) {
			return new WP_Error(
				'rest_comment_invalid_post_id',
				__( 'Sorry, you are not allowed to create this comment without a post.' ),
				array( 'status' => 403 )
			);
		}

		/*
		 * The create-time draft and comments-open rules are deliberately not applied
		 * here, because moderators move comments onto posts whose discussion has
		 * closed and onto drafts today. Enforcing them would break that without
		 * blocking anything the capability check above already permits.
		 */
		return true;
	}


Changelog

Changelog
Version Description
7.1.0 Introduced.