Skip to content

Scope GET sensei-messages with ?sender=all to message participants - #8032

Merged
albarin merged 2 commits into
trunkfrom
fix/messages-rest-sender-all-scoping
Jun 30, 2026
Merged

albarin merged 2 commits into
trunkfrom
fix/messages-rest-sender-all-scoping

Conversation

@albarin

@albarin albarin commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Proposed Changes

Aligns the GET /wp/v2/sensei-messages?sender=all filter with documented messages behaviour. Per the docs, messages are viewable only by "the teacher, the sender, and site administrators", so:

  • Site admins (manage_options) see all messages.
  • Everyone else is scoped to threads where they are the _sender or _receiver.

The ?sender=current path is unchanged. Also tidied the existing unit test and added regression coverage for the scoping.

Testing Instructions

  1. Create two Teacher users (teacherA, teacherB) and a student user.
  2. Create a course with the Contact teacher block, and assign teacherB as its teacher.
  3. As the student, go to the course, Start Course, and use the Contact Teacher button to message teacherB.
  4. Generate an application password for each teacher (Users → Profile → Application Passwords).
  5. As teacherA request GET /wp-json/wp/v2/sensei-messages?sender=all → response is [].
  6. As teacherB, the same ?sender=all request returns their own received message.
  7. As an administrator, ?sender=all returns all messages.

Automated: make test-php-filter FILTER="Sensei_REST_API_Messages_Controller_Tests" → 8 tests pass.

Non-admin results are limited to threads where the user is the _sender
or _receiver; admins are unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@albarin albarin added this to the 4.26.2 milestone Jun 29, 2026
@albarin
albarin requested a review from Copilot June 29, 2026 12:25
@github-actions

github-actions Bot commented Jun 29, 2026 •

Copy link
Copy Markdown
Contributor

WordPress Playground Preview

The changes in this pull request can previewed and tested using a WordPress Playground instance.

Open WordPress Playground Preview

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Sensei messages REST collection scoping so GET /wp/v2/sensei-messages?sender=all only returns threads the requester participates in (sender/receiver), except for site admins who can see everything—aligning endpoint behavior with documented message visibility.

Changes:

  • Adjusted sender=all query scoping to limit non-admins to message threads where they are _sender or _receiver.
  • Updated/expanded PHPUnit coverage to ensure teachers cannot view other teachers’ threads and can view their own sent + received threads.
  • Added a changelog entry for the behavior fix.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
includes/rest-api/class-sensei-rest-api-messages-controller.php Changes sender=all collection filtering to scope non-admins to participant threads via _sender/_receiver meta.
tests/unit-tests/rest-api/test-class-sensei-rest-api-messages-controller.php Removes outdated “teacher sees all” expectation; adds regression tests for teacher participant-only visibility and helper support for _receiver.
changelog/fix-messages-rest-sender-all-scoping Adds a patch-level changelog entry documenting the REST visibility alignment.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread tests/unit-tests/rest-api/test-class-sensei-rest-api-messages-controller.php Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

Comment thread includes/rest-api/class-sensei-rest-api-messages-controller.php
@albarin
albarin marked this pull request as ready for review June 29, 2026 12:46
@albarin
albarin requested a review from donnapep June 29, 2026 12:48
@albarin
albarin merged commit 532835c into trunk Jun 30, 2026
24 checks passed
@albarin
albarin deleted the fix/messages-rest-sender-all-scoping branch June 30, 2026 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants