Jake Vanderwerf
5 days ago 0dfe1d8afafc59c4a5559c498342668d5a58d6ef
inc/rest/PermissionHandler.php
@@ -30,23 +30,6 @@
         );
      }
      $requestedUserId = $request->get_param('user');
      // No user param specified - allow (controller will handle)
      if (empty($requestedUserId)) {
         return true;
      }
      $currentUserId = get_current_user_id();
      if ((int) $requestedUserId !== $currentUserId) {
         return new WP_Error(
            'forbidden',
            'You can only access your own resources',
            ['status' => 403]
         );
      }
      return true;
   }
@@ -330,6 +313,9 @@
      }
      if (!wp_verify_nonce($nonce, $action)) {
         error_log('[PermissionHandler] Validating nonce....');
         error_log('Nonce: '.print_r($nonce, true));
         error_log('Action: '.print_r($action, true));
         return new WP_Error(
            'invalid_nonce',
            'Invalid or expired security token',
@@ -343,9 +329,13 @@
   /**
    * Verify action-specific nonce (e.g., 'dash-{user_id}')
    */
   public static function verifyActionNonce(WP_REST_Request $request, string $actionPrefix, string $header = 'action_nonce'): bool|WP_Error
   public static function verifyActionNonce(WP_REST_Request $request, string $actionPrefix, string $header = 'X-Action-Nonce'): bool|WP_Error
   {
      $userId = $request->get_param('user') ?: get_current_user_id();
      $userId = get_current_user_id();
      if (!$userId) {
         return false;
      }
      $action = $actionPrefix . $userId;
      return self::verifyNonce($request, $action, $header);