[wp-trac] [WordPress Trac] #15326: Always check capabilites in admin pages

WordPress Trac wp-trac at lists.automattic.com
Thu Dec 16 09:18:31 UTC 2010


#15326: Always check capabilites in admin pages
-------------------------+--------------------
 Reporter:  westi        |       Owner:  westi
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  3.1
Component:  Security     |     Version:  3.1
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+--------------------

Comment (by nacin):

 (In [16992]) Replace check_permissions() with ajax_user_can(). New method
 returns true/false to current_user_can(), which we then handle in admin
 ajax. see #15326.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/15326#comment:13>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list