{"id":18996545,"date":"2026-08-18T16:10:01","date_gmt":"2026-08-18T16:10:01","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/cannot-change-data\/"},"modified":"2026-08-18T16:10:01","modified_gmt":"2026-08-18T16:10:01","slug":"cannot-change-data","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/cannot-change-data\/","title":{"rendered":"Cannot change data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I get a not authorized message when I try to save this table. In checking the app, both admin and editor are authorized, both got the same message.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gaetan<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">= 5.5.81 =<\/p>\n\n\n\n<ul>\n<li>Released 2026-08-18<br \/>\u2026<\/li>\n\n\n\n<li>Fixed: Allow admins only to configure lookups<\/li>\n\n\n\n<li>Fixed: Check authorization for wildcard exports<br \/>\u2026<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is released the same day the 401s appeared and explicitly touches admin\/authorization logic for the API layer. Given check_table_access() is exactly the function gating your save action, and its whole design hinges on current_user_is_admin() + the (empty) wpda_rest_api_table_access option, a behavior change to &#8220;admin-only&#8221; gating in this release is the single most likely explanation for both admin and editor now getting rejected identically \u2014 if this release tightened or altered how current_user_is_admin()\/nonce validation is evaluated specifically inside a live REST dispatch (vs. how it resolves under normal WP execution, which I confirmed still returns YES for both test accounts).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No WordPress core update or PHP version change was found in this window \u2014 this narrows cleanly to the WPDA plugin auto-update.<\/p>\n\n\n\n<ol start=\"6\">\n<li>Correlation with today&#8217;s other changes \u2014 none, timing coincidence only<\/li>\n<\/ol>\n\n\n\n<ul>\n<li>The WPSC cache_rejected_uri edit and e20bd48 are unrelated (already ruled out in the previous round, and confirmed unrelated to this page again here).<\/li>\n\n\n\n<li>No wp-config.php edits today, no cookie-domain\/site-URL changes.<\/li>\n\n\n\n<li>The only real &#8220;changed today (or yesterday evening)&#8221; event on this site is the WPDA auto-update to 5.5.81.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Bottom line: This looks like a regression introduced by WPDA&#8217;s own 5.5.81 auto-update (yesterday evening), specifically in its admin\/authorization handling for the REST write endpoints \u2014 not a caching, nonce, or cookie issue, and not related to this morning&#8217;s e20bd48 commit. I&#8217;d want to either (a) test with a fresh app-password-authenticated curl call to see the exact response, or (b) temporarily roll back to 5.5.80 to confirm saves work again, before proposing a fix \u2014 let me know which you&#8217;d like me to pursue, and whether I have your OK to create a throwaway application password on your account for a one-off diagnostic REST call (it&#8217;s reversible\/revocable, but it is a write action so I held off).<\/p>\n","protected":false},"template":"","class_list":["post-18996545","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18996545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18996545\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18996545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}