From 46d681c6b825d21b3f698d793c4e630c687d90ad Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Thu, 21 May 2026 21:41:53 +0000
Subject: [PATCH] =Major CustomBlocks.php overhaul, expanding block support and customization from the editor. theme.json should now be updated on new themes to set brand colours, etc. Also note: major change to .col vs .row alignment: simplifying it to .top .bottom vs the confusion of the differences for .col/.row .start and .a-start

---
 inc/rest/PermissionHandler.php |   11 +++++++++--
 1 files changed, 9 insertions(+), 2 deletions(-)

diff --git a/inc/rest/PermissionHandler.php b/inc/rest/PermissionHandler.php
index 8d4b447..eb87fd0 100644
--- a/inc/rest/PermissionHandler.php
+++ b/inc/rest/PermissionHandler.php
@@ -330,6 +330,9 @@
 		}
 
 		if (!wp_verify_nonce($nonce, $action)) {
+			error_log('[PermissionHandler] Validating nonce....');
+			error_log('Nonce: '.print_r($nonce, true));
+			error_log('Action: '.print_r($action, true));
 			return new WP_Error(
 				'invalid_nonce',
 				'Invalid or expired security token',
@@ -343,9 +346,13 @@
 	/**
 	 * Verify action-specific nonce (e.g., 'dash-{user_id}')
 	 */
-	public static function verifyActionNonce(WP_REST_Request $request, string $actionPrefix, string $header = 'action_nonce'): bool|WP_Error
+	public static function verifyActionNonce(WP_REST_Request $request, string $actionPrefix, string $header = 'X-Action-Nonce'): bool|WP_Error
 	{
-		$userId = $request->get_param('user') ?: get_current_user_id();
+		$userId = absint($request->get_param('user'));
+		if ($userId === 0) {
+			return false;
+		}
+
 		$action = $actionPrefix . $userId;
 
 		return self::verifyNonce($request, $action, $header);

--
Gitblit v1.10.0