wppaste
WordPress

get_post_type_capabilities( object $args ): object

Since
3.0.0, 5.4.0
Source
wp-includes/post.php:1948
Builds an object with all post type capabilities out of a post type object

Description

Post type capabilities use the 'capability_type' argument as a base, if the capability is not set in the 'capabilities' argument array or if the 'capabilities' argument is not supplied.

The capability_type argument can optionally be registered as an array, with the first value being singular and the second plural, e.g. array('story, 'stories') Otherwise, an 's' will be added to the value for the plural form. After registration, capability_type will always be a string of the singular value.

By default, eight keys are accepted as part of the capabilities array:

  • edit_post, read_post, and delete_post are meta capabilities, which are then generally mapped to corresponding primitive capabilities depending on the context, which would be the post being edited/read/deleted and the user or role being checked. Thus these capabilities would generally not be granted directly to users or roles.

  • edit_posts - Controls whether objects of this post type can be edited.

  • edit_others_posts - Controls whether objects of this type owned by other users can be edited. If the post type does not support an author, then this will behave like edit_posts.

  • delete_posts - Controls whether objects of this post type can be deleted.

  • publish_posts - Controls publishing objects of this post type.

  • read_private_posts - Controls whether private objects can be read.

These five primitive capabilities are checked in core in various locations.
There are also six other primitive capabilities which are not referenced directly in core, except in map_meta_cap(), which takes the three aforementioned meta capabilities and translates them into one or more primitive capabilities that must then be checked against the user or role, depending on the context.

  • read - Controls whether objects of this post type can be read.
  • delete_private_posts - Controls whether private objects can be deleted.
  • delete_published_posts - Controls whether published objects can be deleted.
  • delete_others_posts - Controls whether objects owned by other users can be can be deleted. If the post type does not support an author, then this will behave like delete_posts.
  • edit_private_posts - Controls whether private objects can be edited.
  • edit_published_posts - Controls whether published objects can be edited.

These additional capabilities are only used in map_meta_cap(). Thus, they are only assigned by default if the post type is registered with the 'map_meta_cap' argument set to true (default is false).

Compatibility

WordPress
since 5.4.0
PHP
7.4–8.6-dev
  • 6.7.7
  • 6.8.8
  • 6.9.7
  • 7.0.4
  • 7.1.0

Present in every tracked release (6.7.7 to 7.1.0), and compiles on PHP 7.4 through 8.6-dev.

Parameters

$argsobject
Post type registration arguments.

Return value

object
Object with all the capabilities as member variables.

Performance profile

How much work a call to get_post_type_capabilities() does, and what it touches: the algorithmic scaling, the Zend instruction count per call across PHP versions, the hooks it hands control to, and the core code that calls it. Measured from the compiled opcodes, not a stopwatch, so every number is identical on any machine running the same PHP version, and every function in core is ranked by cost.

Cost class
Trivial

Touches nothing outside its own arguments.

Scaling
Constant

No loop in the body: the same number of instructions runs whatever you pass in.

Instructions
39–69

Executed per call on PHP 8.5, depending on the branch taken. The body compiles to 69.

Plugin surface
None

Nothing here hands control to plugin code.

Called by
2

2 places in core call this, so the cost is paid more often than your own code shows.

What one call costs · 4 distinct outcomes

One number would be a lie: the work depends on which branch runs. These are every distinct cost get_post_type_capabilities() can have, taken from its control-flow graph on PHP 8.5.

WhenInstructionsCalls it makes
!$args39–49array_merge()
always42–52array_merge(), _post_type_meta_capabilities()
always56–66array_merge(), array_merge()
$args59–69array_merge(), array_merge(), _post_type_meta_capabilities()

Across PHP versions

PHPCompiledExecutedBranchesNotes
8.6-dev6939–694
8.56939–694
8.46939–694
8.36939–694
8.26939–6942 fewer instructions than PHP 8.1
8.17141–714
7.47141–714

An instruction is not a fixed amount of time, so a matching count is not necessarily the same speed; what it rules out is a difference in the work itself.

Uses · 1

Used by · 2

Source code

function get_post_type_capabilities( $args ) {	if ( ! is_array( $args->capability_type ) ) {		$args->capability_type = array( $args->capability_type, $args->capability_type . 's' );	} 	// Singular base for meta capabilities, plural base for primitive capabilities.	list( $singular_base, $plural_base ) = $args->capability_type; 	$default_capabilities = array(		// Meta capabilities.		'edit_post'          => 'edit_' . $singular_base,		'read_post'          => 'read_' . $singular_base,		'delete_post'        => 'delete_' . $singular_base,		// Primitive capabilities used outside of map_meta_cap():		'edit_posts'         => 'edit_' . $plural_base,		'edit_others_posts'  => 'edit_others_' . $plural_base,		'delete_posts'       => 'delete_' . $plural_base,		'publish_posts'      => 'publish_' . $plural_base,		'read_private_posts' => 'read_private_' . $plural_base,	); 	// Primitive capabilities used within map_meta_cap():	if ( $args->map_meta_cap ) {		$default_capabilities_for_mapping = array(			'read'                   => 'read',			'delete_private_posts'   => 'delete_private_' . $plural_base,			'delete_published_posts' => 'delete_published_' . $plural_base,			'delete_others_posts'    => 'delete_others_' . $plural_base,			'edit_private_posts'     => 'edit_private_' . $plural_base,			'edit_published_posts'   => 'edit_published_' . $plural_base,		);		$default_capabilities             = array_merge( $default_capabilities, $default_capabilities_for_mapping );	} 	$capabilities = array_merge( $default_capabilities, $args->capabilities ); 	// Post creation capability simply maps to edit_posts by default:	if ( ! isset( $capabilities['create_posts'] ) ) {		$capabilities['create_posts'] = $capabilities['edit_posts'];	} 	// Remember meta capabilities for future reference.	if ( $args->map_meta_cap ) {		_post_type_meta_capabilities( $capabilities );	} 	return (object) $capabilities;}

Changelog

Introduced in 3.0.0. Unchanged from 6.7.7 through 7.1.0.

  1. 6.7.7
  2. 6.8.8
  3. 6.9.7
  4. 7.0.4
  5. 7.1.0

Signature, return type and hooks compared across 5 parsed releases.

5.4.0
'delete_posts' is included in default capabilities.from the docblock
3.0.0
Introduced.from the docblock

About this page

Parsed data
Generated from the wordpress-develop 6.7.7 tag, from src/wp-includes/post.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.
Corrections
Something wrong on this page? Report it and it gets fixed in the next regeneration.