From fff721dd185f5b97f7ae7a6e64189e55887ff590 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Sun, 05 Jul 2026 18:36:57 +0000
Subject: [PATCH] =Cleaning up the Square integration (still a bit more to do yet). Also majorly overhauled /rest/ files to ignore a rest request 'user' paramater, and rely on get_current_user_id() instead.

---
 inc/rest/routes/UploadRoutes.php |   30 +++++++++++++-----------------
 1 files changed, 13 insertions(+), 17 deletions(-)

diff --git a/inc/rest/routes/UploadRoutes.php b/inc/rest/routes/UploadRoutes.php
index 5222e4d..a0e8afa 100644
--- a/inc/rest/routes/UploadRoutes.php
+++ b/inc/rest/routes/UploadRoutes.php
@@ -105,7 +105,6 @@
 			->args([
 				'id' 		=> 'string|required',
 				'content' 	=> 'string|required',
-				'user'		=> 'int|required'
 			])
 			->register();
 
@@ -114,7 +113,6 @@
 			->auth(PermissionHandler::combine(['nonce']))
 			->rateLimit(30)
 			->args([
-				'user'	=> 'int|required',
 				'items'	=> 'array|required',
 				'id'    => 'string'
 			])
@@ -174,15 +172,13 @@
 					break;
 				// User ID
 				case 'user':
-					if ($this->userCheck($value)) {
-						$args['user'] = (int) $value;
-						if (!array_key_exists('post_id', $args) &&
-							!array_key_exists('post_id', $data) &&
-							!array_key_exists('term_id', $data) &&
-							!array_key_exists('item_id', $data)) {
-							$args['post_id'] = (int)get_user_meta((int) $value, BASE.'profile_link', true);
-						}
+					if (!array_key_exists('post_id', $args) &&
+						!array_key_exists('post_id', $data) &&
+						!array_key_exists('term_id', $data) &&
+						!array_key_exists('item_id', $data)) {
+						$args['post_id'] = (int)get_user_meta((int) $value, BASE.'profile_link', true);
 					}
+
 					break;
 				// Operation ID
 				case 'id':
@@ -261,13 +257,13 @@
 				case 'field_key':
 				case 'field_type':
 				case 'subtype':
-				case 'item_id':
 				case 'context':
 					if (is_string($value)) {
 						$args[$key] = sanitize_text_field($value);
 					}
 					break;
 			}
+			$args['user'] = get_current_user_id();
 		}
         return $args;
     }
@@ -286,8 +282,8 @@
 			$files = $request->get_file_params();
 			$args = $this->buildUploadArgs($request);
 
-
-			if (!$args['user']) {
+			$userID = get_current_user_id();
+			if (!$userID) {
 				 return $this->unauthorized();
 			}
 			if (!$args['content']) {
@@ -417,7 +413,7 @@
 		error_log('With ID: '.print_r($args['upload'], true));
 		$queuedProcessing = JVB()->queue()->queueOperation(
 			$operation_type,
-			$args['user'],
+			get_current_user_id(),
 			array_merge(
 				['secured_files' => $secured_data['files']],
 				$args
@@ -441,7 +437,7 @@
 			if (!$queuedProcessing['updated_existing']) {
 				JVB()->queue()->queueOperation(
 					'attach_upload_to_content',
-					$args['user'],
+					get_current_user_id(),
 					$args,
 					[
 						'priority'      => 'high',
@@ -454,7 +450,7 @@
 
 		JVB()->queue()->queueOperation(
 			'temporary_cleanup',
-			$args['user'],
+			get_current_user_id(),
 			[
 				'files'     => $secured_data['files'],
 				'context'   => $args,
@@ -1159,7 +1155,7 @@
 			$files = $request->get_file_params();
 			$args = $this->buildUploadArgs($request);
 
-			if (!array_key_exists('user', $args) || $args['user'] === 0){
+			if (!$args['user']) {
 				return $this->unauthorized();
 			}
 			if (!array_key_exists('content', $args) || empty($args['content'])) {

--
Gitblit v1.10.0