Contents

Roles and Permissions - Plugixa Image Map

Out of the box, only administrators can use Plugixa Image Map. Everything it allows is an ordinary WordPress capability, so any role editor plugin can hand it to other roles.

The capabilities

Capability Allows
plugixa_image_map_view Seeing maps and statistics
plugixa_image_map_create Making new maps
plugixa_image_map_edit Changing and publishing maps
plugixa_image_map_delete Moving maps to the trash and deleting them
plugixa_image_map_export Exporting maps
plugixa_image_map_import Importing maps, including from Image Map Pro and spreadsheets
plugixa_image_map_manage_settings Changing the settings

These seven are the ones you give to a role. Administrators always hold all of them.

Opening the plugin

There is an eighth name, plugixa_image_map_manage, and it is not one to hand out. It means only may open the plugin: the Plugixa Image Map menu item is shown to anyone who holds it, and WordPress grants it automatically to anyone holding any one of the seven above. It allows nothing else by itself.

So the menu item appears as soon as a role has at least one of the seven, and disappears when it has none. What the person can do once inside is decided by the seven.

Giving access to another role

With WP-CLI:

wp cap add editor plugixa_image_map_view plugixa_image_map_create plugixa_image_map_edit

Or use a role editor plugin and tick the capabilities for the role.

A sensible set for an editor who maintains maps but should not delete or reconfigure: view, create, edit and export.

What follows from the rules

  • The buttons a person may not use are not shown to them.
  • The REST API and the WP-CLI commands check the same capabilities. There is no way around them from the command line: commands run as a named user.
  • Choosing or uploading a picture also needs WordPress’s own upload_files.
  • Changing Delete all maps when the plugin is deleted also needs WordPress’s own manage_options. See Settings.
  • Tooltips written by someone who may not post unfiltered HTML are cleaned more strictly, as their posts would be.

Visitors

Showing a published map needs no capability. The one thing a signed-out visitor can send to the plugin is a statistics count PRO, described in Statistics.

Quick Links