From fff721dd185f5b97f7ae7a6e64189e55887ff590 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Sun, 05 Jul 2026 18:36:57 +0000
Subject: [PATCH] =Cleaning up the Square integration (still a bit more to do yet). Also majorly overhauled /rest/ files to ignore a rest request 'user' paramater, and rely on get_current_user_id() instead.

---
 inc/rest/routes/IntegrationsRoutes.php |   11 ++++++++---
 1 files changed, 8 insertions(+), 3 deletions(-)

diff --git a/inc/rest/routes/IntegrationsRoutes.php b/inc/rest/routes/IntegrationsRoutes.php
index 73112de..4bfb20b 100644
--- a/inc/rest/routes/IntegrationsRoutes.php
+++ b/inc/rest/routes/IntegrationsRoutes.php
@@ -29,7 +29,8 @@
 				'data'		=> 'array'
 			])
 			->auth('user')
-			->rateLimit(20);
+			->rateLimit(20)
+			->register();
 		Route::for('oath/connect')
 			->post([$this, 'initiateOAuth'])
 			->auth('user')
@@ -38,7 +39,8 @@
 				'service'	=> 'string|required',
 				'user_id'	=> 'int',
 				'return_url'=> 'url'
-			]);
+			])
+			->register();
 	}
 
 	/**
@@ -51,7 +53,10 @@
 		$action = $request->get_param('action');
 
 
-		$theUserID = (user_can($request->get_param('user'), 'manage_options')) ? null : $request->get_param('user');
+		$theUserID = current_user_can('manage_options') ? null : get_current_user_id();
+		if ($theUserID === false) {
+			return $this->validationError(['message' => 'Not logged in']);
+		}
 		$integration = JVB()->connect($service, $theUserID);
 
 		if (!$integration) {

--
Gitblit v1.10.0