-
Notifications
You must be signed in to change notification settings - Fork 72
Enforce strict user capability checks when deleting test orders #11122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enforce strict user capability checks when deleting test orders #11122
Conversation
Test the buildOption 1. Jetpack Beta
Option 2. Jurassic Ninja - available for logged-in A12s🚀 Launch a JN site with this branch 🚀 ℹ️ Install this Tampermonkey script to get more options. Build info:
Note: the build is updated when a new commit is pushed to this PR. |
|
Size Change: 0 B Total Size: 873 kB ℹ️ View Unchanged
|
elazzabi
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Better safe than sorry. Good addition ![]()
dmallory42
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me. Change makes sense and works as expected, thanks for adding this!
|
This PR was cherry-picked into the |
Related to #11103
Changes proposed in this Pull Request
Better safe than sorry: even if the WooCommerce Debug Tools have access checks, we should make sure we have backstops in place. When deleting test orders we add an explicit check for the
manage_woocommercecapability.Also, we were missing the right parameter to force delete test orders and skip trash.
Testing instructions
npm run changelogto add a changelog file, choosepatchto leave it empty if the change is not significant. You can add multiple changelog files in one PR by running this command a few times.Post merge