From fff721dd185f5b97f7ae7a6e64189e55887ff590 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Sun, 05 Jul 2026 18:36:57 +0000
Subject: [PATCH] =Cleaning up the Square integration (still a bit more to do yet). Also majorly overhauled /rest/ files to ignore a rest request 'user' paramater, and rely on get_current_user_id() instead.

---
 inc/rest/PermissionHandler.php |   24 +++++-------------------
 1 files changed, 5 insertions(+), 19 deletions(-)

diff --git a/inc/rest/PermissionHandler.php b/inc/rest/PermissionHandler.php
index f59f7c2..4c41989 100644
--- a/inc/rest/PermissionHandler.php
+++ b/inc/rest/PermissionHandler.php
@@ -30,23 +30,6 @@
 			);
 		}
 
-		$requestedUserId = $request->get_param('user');
-
-		// No user param specified - allow (controller will handle)
-		if (empty($requestedUserId)) {
-			return true;
-		}
-
-		$currentUserId = get_current_user_id();
-
-		if ((int) $requestedUserId !== $currentUserId) {
-			return new WP_Error(
-				'forbidden',
-				'You can only access your own resources',
-				['status' => 403]
-			);
-		}
-
 		return true;
 	}
 
@@ -330,6 +313,9 @@
 		}
 
 		if (!wp_verify_nonce($nonce, $action)) {
+			error_log('[PermissionHandler] Validating nonce....');
+			error_log('Nonce: '.print_r($nonce, true));
+			error_log('Action: '.print_r($action, true));
 			return new WP_Error(
 				'invalid_nonce',
 				'Invalid or expired security token',
@@ -345,8 +331,8 @@
 	 */
 	public static function verifyActionNonce(WP_REST_Request $request, string $actionPrefix, string $header = 'X-Action-Nonce'): bool|WP_Error
 	{
-		$userId = absint($request->get_param('user'));
-		if ($userId === 0) {
+		$userId = get_current_user_id();
+		if (!$userId) {
 			return false;
 		}
 

--
Gitblit v1.10.0