Add capability check to async-upload. Props xknown. fixes #5848

git-svn-id: https://develop.svn.wordpress.org/trunk@6830 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Ryan Boren 2008-02-13 23:16:11 +00:00
parent 5f46a6db39
commit 27f47369b3

View File

@ -16,6 +16,10 @@ unset($current_user);
require_once('admin.php');
header('Content-Type: text/plain');
if ( !current_user_can('upload_files') )
wp_die(__('You do not have permission to upload files.'));
$id = media_handle_upload('async-upload', $_REQUEST['post_id']);
if (is_wp_error($id)) {
echo '<div id="media-upload-error">'.wp_specialchars($id->get_error_message()).'</div>';