[wp-trac] [WordPress Trac] #11873: Contributors can restore posts trashed by editors

WordPress Trac wp-trac at lists.automattic.com
Tue Jan 12 03:06:40 UTC 2010


#11873: Contributors can restore posts trashed by editors
--------------------------+-------------------------------------------------
 Reporter:  scribu        |       Owner:     
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  3.0
Component:  Trash         |     Version:  2.9
 Severity:  normal        |    Keywords:     
--------------------------+-------------------------------------------------

Comment(by azaozz):

 Contributors shouldn't be able to trash/untrash any published posts,
 that's not their role. We should be checking
 `current_user_can('publish_posts')` and perhaps have an exception when
 post_status in pending and post_author is a contributor.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11873#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list