* REST API Settings Controller
* Handles requests to save Settings.
declare( strict_types = 1);
namespace Automattic\WooCommerce\Admin\API;
use Automattic\WooCommerce\Admin\Features\Settings\Init;
defined( 'ABSPATH' ) || exit;
* @extends WC_REST_Data_Controller
class Settings extends \WC_REST_Data_Controller {
protected $namespace = 'wc-admin';
protected $rest_base = 'legacy-settings';
public function register_routes() {
'methods' => \WP_REST_Server::EDITABLE,
'callback' => array( $this, 'save_settings' ),
'permission_callback' => array( $this, 'save_items_permissions_check' ),
'schema' => array( $this, 'save_items_schema' ),
* Check if a given request has access to update settings.
* @param WP_REST_Request $request Full details about the request.
* @return WP_Error|boolean
public function save_items_permissions_check( $request ) {
return current_user_can( 'manage_woocommerce' );
* @param WP_REST_Request $request Full details about the request.
* @return WP_Error|WP_REST_Response
public function save_settings( $request ) {
global $current_section, $current_tab;
if ( ! check_ajax_referer( 'wp_rest', false, false ) ) {
'woocommerce_settings_invalid_nonce',
__( 'Invalid nonce.', 'woocommerce' ),
$params = $request->get_params();
// Get current tab/section and set global variables.
$current_tab = empty( $params['tab'] ) ? 'general' : sanitize_title( wp_unslash( $params['tab'] ) ); // WPCS: input var okay, CSRF ok.
$current_section = empty( $params['section'] ) ? '' : sanitize_title( wp_unslash( $params['section'] ) ); // WPCS: input var okay, CSRF ok.
$filter_name = '' === $current_section ?
"woocommerce_save_settings_{$current_tab}" :
"woocommerce_save_settings_{$current_tab}_{$current_section}";
* Filters whether to save settings.
* @param bool $save Whether to save settings.
if ( apply_filters( $filter_name, ! empty( $_POST['save'] ) ) ) { // WPCS: input var okay, CSRF ok.
WC_Admin_Settings::save();
$setting_pages = \WC_Admin_Settings::get_settings_pages();
// Reinitialize all setting pages in case behavior is dependent on saved values.
foreach ( $setting_pages as $key => $setting_page ) {
$class_name = get_class( $setting_page );
$setting_pages[ $key ] = new $class_name();
$data = Init::get_page_data( array(), $setting_pages );
return new \WP_REST_Response(
} catch ( \Exception $e ) {
'woocommerce_settings_save_error',
// translators: %s: error message.
sprintf( __( 'Failed to save settings: %s', 'woocommerce' ), $e->getMessage() ),
* Get the schema, conforming to JSON Schema.
public function save_items_schema() {
'$schema' => 'http://json-schema.org/draft-04/schema#',
'description' => __( 'Array of options with associated values.', 'woocommerce' ),
'context' => array( 'view' ),
'description' => __( 'Settings tab.', 'woocommerce' ),
'context' => array( 'view', 'edit' ),
'description' => __( 'Settings section.', 'woocommerce' ),
'context' => array( 'view', 'edit' ),