Skip to content
This repository was archived by the owner on Sep 24, 2018. It is now read-only.
This repository was archived by the owner on Sep 24, 2018. It is now read-only.

Don't permit requesting terms cross routes #1763

@danielbachhuber

Description

@danielbachhuber

I have a category with term_taxonomy_id=1:

GET http://wordpress-develop.dev/wp-json/wp/v2/terms/category/1

I shouldn't be able to request it from the tag endpoint:

http://wordpress-develop.dev/wp-json/wp/v2/terms/tag/1

Reported in https://wordpress.org/support/topic/incorrect-route-wordpress-44-beta-4?replies=5

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions