Limit module editing, deletion, and course assignment to the owner - #8089
Conversation
e1ca7ec to
21791d2
Compare
Teachers hold manage_modules so they can manage their own modules, but WordPress maps the edit_term and delete_term meta capabilities to that primitive capability with no ownership check. Add a map_meta_cap filter that denies those operations on a module the current non-admin user does not own. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The module course-assignment handler wrote object terms for arbitrary course IDs from the request without checking permission. Skip courses the current user cannot edit in both the detach and attach loops of save_module_course. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
21791d2 to
a9123e2
Compare
There was a problem hiding this comment.
Pull request overview
This PR tightens authorization around Sensei “module” taxonomy management so that non-admin users with manage_modules can only edit/delete modules they own, and can only attach/detach modules to courses they’re allowed to edit.
Changes:
- Added a
map_meta_capfilter to denyedit_term/delete_termon module terms not owned by the current non-admin user. - Updated module ↔ course sync on the module edit screen to skip attaching/detaching for courses the current user cannot edit.
- Added PHPUnit coverage for module list scoping, term capability enforcement, and course assignment restrictions; added a changelog entry.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
includes/class-sensei-modules.php |
Adds ownership-based term-cap restriction and course-edit-cap checks during module↔course syncing. |
tests/unit-tests/test-class-modules.php |
Adds unit tests validating the new ownership and course-assignment authorization behavior. |
changelog/fix-module-ownership-authorization |
Records the user-facing fix in the changelog. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The unresolvable-author edge case will be fixed holistically in a follow-up. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
@claude please review |
Code ReviewThe approach is solid — locking down 1. Redundant DB query in
|
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
donnapep
left a comment
There was a problem hiding this comment.
Left a few comments, a couple of which I'd consider blockers.
get_term() is already scoped to the module taxonomy, so the returned WP_Term can only ever belong to it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Editors hold manage_modules but not manage_options, so the ownership bypass wrongly restricted them. Gate it on edit_others_courses instead. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Name the tests after filter_module_terms and restrict_module_term_management instead of concept names with no matching method. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Match the helper already used elsewhere for course-edit permission instead of a raw edit_post capability check. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The pre-Act login had no effect on the course-based edit check. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Closes https://linear.app/a8c/issue/SEN-79
Proposed Changes
Teachers hold the
manage_modulescapability so they can manage their ownmodules, but that capability was applied without any per-module ownership
check. This restricts two operations to the module's owner:
edit_termanddelete_termmeta capabilities straight tomanage_modules, ignoring whichmodule it is. A
map_meta_capfilter now denies those operations on a modulethe current non-admin user does not own.
module edit screen synced a module's course associations from the submitted
IDs with no permission check.
save_module_course()now skips any course thecurrent user cannot edit, in both the attach and detach loops.
Administrators are unaffected. The restriction applies to all non-admin
holders of
manage_modules, teachers and editors (editors were alreadyscoped to their own modules on the read side, so this aligns write access with
what they could already see).
Tip
Might be easier to review commit by commit, since they are quite self-contained.
Testing instructions
Manual testing instructions can be found in the Linear issue
Automated tests
make test-php-filter FILTER="Sensei_Class_Modules_Test"