WP_REST_Comments_Controller::check_target_post_permission( int $post_id )
Checks that a post can receive a comment from the current user.
Description
Used when changing the parent post of an existing comment, so that attaching a comment to a post is authorized the same way whichever path it arrives by.
Parameters
- $post_id
-
(int) (Required) Target post ID.
Return
(true|WP_Error) True if the post can receive the comment, error object otherwise.
Source
File: wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
protected function check_target_post_permission( $post_id ) {
if ( ! $post_id ) {
return new WP_Error(
'rest_comment_invalid_post_id',
__( 'Sorry, you are not allowed to create this comment without a post.' ),
array( 'status' => 403 )
);
}
/*
* A comment needs either comment moderation rights or edit access to the
* post, which is what check_edit_permission() grants on the post a comment
* is moving away from. Requiring the same at the destination means both
* ends of a move are authorized alike.
*/
if ( ! current_user_can( 'moderate_comments' ) && ! current_user_can( 'edit_post', $post_id ) ) {
return new WP_Error(
'rest_cannot_edit',
__( 'Sorry, you are not allowed to edit this comment.' ),
array( 'status' => rest_authorization_required_code() )
);
}
$post = get_post( $post_id );
if ( ! $post ) {
return new WP_Error(
'rest_comment_invalid_post_id',
__( 'Sorry, you are not allowed to create this comment without a post.' ),
array( 'status' => 403 )
);
}
/*
* The create-time draft and comments-open rules are deliberately not applied
* here, because moderators move comments onto posts whose discussion has
* closed and onto drafts today. Enforcing them would break that without
* blocking anything the capability check above already permits.
*/
return true;
}
Changelog
| Version | Description |
|---|---|
| 7.1.0 | Introduced. |