Contents
Roles and Permissions - Plugixa Image Map
Out of the box, only administrators can use Plugixa Image Map. Everything it allows is an ordinary WordPress capability, so any role editor plugin can hand it to other roles.
The capabilities
| Capability | Allows |
|---|---|
plugixa_image_map_view |
Seeing maps and statistics |
plugixa_image_map_create |
Making new maps |
plugixa_image_map_edit |
Changing and publishing maps |
plugixa_image_map_delete |
Moving maps to the trash and deleting them |
plugixa_image_map_export |
Exporting maps |
plugixa_image_map_import |
Importing maps, including from Image Map Pro and spreadsheets |
plugixa_image_map_manage_settings |
Changing the settings |
These seven are the ones you give to a role. Administrators always hold all of them.
Opening the plugin
There is an eighth name, plugixa_image_map_manage, and it is not one to hand
out. It means only may open the plugin: the Plugixa Image Map menu item is
shown to anyone who holds it, and WordPress grants it automatically to anyone
holding any one of the seven above. It allows nothing else by itself.
So the menu item appears as soon as a role has at least one of the seven, and disappears when it has none. What the person can do once inside is decided by the seven.
Giving access to another role
With WP-CLI:
wp cap add editor plugixa_image_map_view plugixa_image_map_create plugixa_image_map_edit
Or use a role editor plugin and tick the capabilities for the role.
A sensible set for an editor who maintains maps but should not delete or reconfigure: view, create, edit and export.
What follows from the rules
- The buttons a person may not use are not shown to them.
- The REST API and the WP-CLI commands check the same capabilities. There is no way around them from the command line: commands run as a named user.
- Choosing or uploading a picture also needs WordPress’s own
upload_files. - Changing Delete all maps when the plugin is deleted also needs WordPress’s
own
manage_options. See Settings. - Tooltips written by someone who may not post unfiltered HTML are cleaned more strictly, as their posts would be.
Visitors
Showing a published map needs no capability. The one thing a signed-out visitor can send to the plugin is a statistics count PRO, described in Statistics.