From fff721dd185f5b97f7ae7a6e64189e55887ff590 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Sun, 05 Jul 2026 18:36:57 +0000
Subject: [PATCH] =Cleaning up the Square integration (still a bit more to do yet). Also majorly overhauled /rest/ files to ignore a rest request 'user' paramater, and rely on get_current_user_id() instead.

---
 inc/rest/routes/UploadRoutes.php |   53 ++++++++++++++++++++++++++++++-----------------------
 1 files changed, 30 insertions(+), 23 deletions(-)

diff --git a/inc/rest/routes/UploadRoutes.php b/inc/rest/routes/UploadRoutes.php
index e46aa84..a0e8afa 100644
--- a/inc/rest/routes/UploadRoutes.php
+++ b/inc/rest/routes/UploadRoutes.php
@@ -105,7 +105,6 @@
 			->args([
 				'id' 		=> 'string|required',
 				'content' 	=> 'string|required',
-				'user'		=> 'int|required'
 			])
 			->register();
 
@@ -114,7 +113,6 @@
 			->auth(PermissionHandler::combine(['nonce']))
 			->rateLimit(30)
 			->args([
-				'user'	=> 'int|required',
 				'items'	=> 'array|required',
 				'id'    => 'string'
 			])
@@ -130,6 +128,8 @@
     {
         $data = $request->get_params();
 		$args = [];
+		$registrar = Registrar::getInstance($data['content']??'');
+
 		foreach ($data as $key => $value) {
 			switch ($key) {
 				case 'depends_on':
@@ -140,15 +140,25 @@
 				case 'item_id':
 					if (is_numeric($value)) {
 						$args['item_id'] = absint($value);
-						if (!array_key_exists('post_id', $args)) {
-							$args['post_id'] = absint($value);
+						if ($registrar) {
+							switch ($registrar->getType()) {
+								case 'post':
+									$args['post_id'] = absint($value);
+									break;
+								case 'term':
+									$args['term_id'] = absint($value);
+									break;
+								case 'user':
+									$args['user_id'] = absint($value);
+									break;
+							}
 						}
 					}
 					break;
 				// Post Type/Taxonomy
 				case 'content':
-					$key = str_replace('-', '_', $key);
-					if ($value === 'options' || array_key_exists($value, Registrar::getRegistered('post')) || Registrar::getInstance($key)->hasFeature('is_content')??false) {
+					$value = str_replace('-', '_', $value);
+					if ($value === 'options' || $registrar) {
 						$args['content'] = $value;
 					}
 					break;
@@ -162,15 +172,13 @@
 					break;
 				// User ID
 				case 'user':
-					if ($this->userCheck($value)) {
-						$args['user'] = (int) $value;
-						if (!array_key_exists('post_id', $args) &&
-							!array_key_exists('post_id', $data) &&
-							!array_key_exists('term_id', $data) &&
-							!array_key_exists('item_id', $data)) {
-							$args['post_id'] = (int)get_user_meta((int) $value, BASE.'link', true);
-						}
+					if (!array_key_exists('post_id', $args) &&
+						!array_key_exists('post_id', $data) &&
+						!array_key_exists('term_id', $data) &&
+						!array_key_exists('item_id', $data)) {
+						$args['post_id'] = (int)get_user_meta((int) $value, BASE.'profile_link', true);
 					}
+
 					break;
 				// Operation ID
 				case 'id':
@@ -249,13 +257,13 @@
 				case 'field_key':
 				case 'field_type':
 				case 'subtype':
-				case 'item_id':
 				case 'context':
 					if (is_string($value)) {
 						$args[$key] = sanitize_text_field($value);
 					}
 					break;
 			}
+			$args['user'] = get_current_user_id();
 		}
         return $args;
     }
@@ -274,8 +282,8 @@
 			$files = $request->get_file_params();
 			$args = $this->buildUploadArgs($request);
 
-
-			if (!$args['user']) {
+			$userID = get_current_user_id();
+			if (!$userID) {
 				 return $this->unauthorized();
 			}
 			if (!$args['content']) {
@@ -405,7 +413,7 @@
 		error_log('With ID: '.print_r($args['upload'], true));
 		$queuedProcessing = JVB()->queue()->queueOperation(
 			$operation_type,
-			$args['user'],
+			get_current_user_id(),
 			array_merge(
 				['secured_files' => $secured_data['files']],
 				$args
@@ -429,7 +437,7 @@
 			if (!$queuedProcessing['updated_existing']) {
 				JVB()->queue()->queueOperation(
 					'attach_upload_to_content',
-					$args['user'],
+					get_current_user_id(),
 					$args,
 					[
 						'priority'      => 'high',
@@ -442,7 +450,7 @@
 
 		JVB()->queue()->queueOperation(
 			'temporary_cleanup',
-			$args['user'],
+			get_current_user_id(),
 			[
 				'files'     => $secured_data['files'],
 				'context'   => $args,
@@ -627,7 +635,7 @@
 		} elseif (array_key_exists('term_id', $data)) {
 			$meta = Meta::forTerm($data['term_id']);
 		} else {
-			$link = (int)get_user_meta($data['user'], BASE.'link');
+			$link = (int)get_user_meta($data['user'], BASE.'profile_link');
 			$meta = Meta::forPost($link);
 		}
 
@@ -640,7 +648,6 @@
 
 		// Update with comma-separated string
 		$meta->set($data['field_name'], implode(',', $all_ids));
-		$meta->save();
 	}
 
 	/**
@@ -1148,7 +1155,7 @@
 			$files = $request->get_file_params();
 			$args = $this->buildUploadArgs($request);
 
-			if (!array_key_exists('user', $args) || $args['user'] === 0){
+			if (!$args['user']) {
 				return $this->unauthorized();
 			}
 			if (!array_key_exists('content', $args) || empty($args['content'])) {

--
Gitblit v1.10.0