PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.3
Advanced Access Manager – Access Governance for WordPress v5.3
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Backend / Feature / Subject / User.php
advanced-access-manager / Application / Backend / Feature / Subject Last commit date
Role.php 8 years ago User.php 8 years ago
User.php
267 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * User view manager
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Backend_Feature_Subject_User {
17
18 /**
19 * Retrieve list of users
20 *
21 * Based on filters, get list of users
22 *
23 * @return string JSON encoded list of users
24 *
25 * @access public
26 */
27 public function getTable() {
28 $response = array(
29 'recordsTotal' => 0,
30 'recordsFiltered' => 0,
31 'draw' => AAM_Core_Request::request('draw'),
32 'data' => array(),
33 );
34
35 if (current_user_can('list_users')) {
36 //get total number of users
37 $total = count_users();
38 $result = $this->query();
39
40 $response['recordsTotal'] = $total['total_users'];
41 $response['recordsFiltered'] = $result->get_total();
42
43 foreach ($result->get_results() as $row) {
44 $response['data'][] = $this->prepareRow(
45 new AAM_Core_Subject_User($row->ID)
46 );
47 }
48 }
49
50 return json_encode($response);
51 }
52
53 /**
54 * Save user expiration
55 *
56 * @return string
57 *
58 * @access public
59 */
60 public function saveExpiration() {
61 $response = array(
62 'status' => 'failure',
63 'reason' => __('Operation is not permitted', AAM_KEY)
64 );
65
66 $userId = filter_input(INPUT_POST, 'user');
67 $expires = filter_input(INPUT_POST, 'expires');
68 $action = filter_input(INPUT_POST, 'after');
69 $role = filter_input(INPUT_POST, 'role');
70
71 if (current_user_can('edit_users')) {
72 if ($userId != get_current_user_id()) {
73 if ($this->isAllowed(new AAM_Core_Subject_User($userId))) {
74 $this->updateUserExpiration($userId, $expires, $action, $role);
75 $response['status'] = 'success';
76 }
77 } else {
78 $response['reason'] = __('You cannot set expiration to yourself', AAM_KEY);
79 }
80 }
81
82 return json_encode($response);
83 }
84
85 /**
86 * Query database for list of users
87 *
88 * Based on filters and settings get the list of users from database
89 *
90 * @return \WP_User_Query
91 *
92 * @access public
93 */
94 public function query() {
95 $search = trim(AAM_Core_Request::request('search.value'));
96
97 $args = array(
98 'blog_id' => get_current_blog_id(),
99 'fields' => 'all',
100 'number' => AAM_Core_Request::request('length'),
101 'offset' => AAM_Core_Request::request('start'),
102 'search' => ($search ? $search . '*' : ''),
103 'search_columns' => array(
104 'user_login', 'user_email', 'display_name'
105 ),
106 'orderby' => 'user_nicename',
107 'order' => 'ASC'
108 );
109
110 return new WP_User_Query($args);
111 }
112
113 /**
114 * Block user
115 *
116 * @return string
117 *
118 * @access public
119 */
120 public function block() {
121 $result = false;
122
123 if (current_user_can('aam_toggle_users') && current_user_can('edit_users')) {
124 $subject = AAM_Backend_Subject::getInstance();
125
126 if ($this->isAllowed($subject->get())) {
127 //user is not allowed to lock himself
128 if ($subject->getId() != get_current_user_id()) {
129 $result = $subject->block();
130 }
131 }
132 }
133
134 return json_encode(array('status' => ($result ? 'success' : 'failure')));
135 }
136
137 /**
138 * Prepare row
139 *
140 * @param AAM_Core_Subject_User $user
141 *
142 * @return array
143 *
144 * @access protected
145 */
146 protected function prepareRow(AAM_Core_Subject_User $user) {
147 return array(
148 $user->ID,
149 implode(', ', $this->getUserRoles($user->roles)),
150 ($user->display_name ? $user->display_name : $user->user_nicename),
151 implode(',', $this->prepareRowActions($user)),
152 AAM_Core_API::maxLevel($user->allcaps),
153 $this->getUserExpiration($user)
154 );
155 }
156
157 /**
158 * Get list of user roles
159 *
160 * @param array $roles
161 *
162 * @return array
163 *
164 * @access protected
165 */
166 protected function getUserRoles($roles) {
167 $response = array();
168
169 $names = AAM_Core_API::getRoles()->get_names();
170
171 if (is_array($roles)) {
172 foreach($roles as $role) {
173 if (array_key_exists($role, $names)) {
174 $response[] = translate_user_role($names[$role]);
175 }
176 }
177 }
178
179 return $response;
180 }
181
182 /**
183 * Prepare user row actions
184 *
185 * @param WP_User $user
186 *
187 * @return array
188 *
189 * @access protected
190 */
191 protected function prepareRowActions(AAM_Core_Subject_User $user) {
192 if ($this->isAllowed($user) || ($user->ID == get_current_user_id())) {
193 $actions = array('manage');
194
195 if (AAM_Core_Config::get('secure-login', true)
196 && current_user_can('aam_toggle_users')) {
197 $actions[] = ($user->user_status ? 'unlock' : 'lock');
198 }
199
200 if (current_user_can('edit_users')) {
201 $actions[] = 'edit';
202 $actions[] = 'ttl';
203 }
204
205 if (current_user_can('aam_switch_users')) {
206 $actions[] = 'switch';
207 }
208 } else {
209 $actions = array();
210 }
211
212 return $actions;
213 }
214
215 /**
216 * Update user expiration
217 *
218 * @param int $user
219 * @param string $expires
220 * @param string $action
221 * @param string $role
222 *
223 * @return bool
224 *
225 * @access protected
226 */
227 protected function updateUserExpiration($user, $expires, $action, $role = '') {
228 if (trim($expires)) {
229 update_user_meta(
230 $user,
231 'aam_user_expiration',
232 date('Y-m-d H:i:s', strtotime($expires)) . "|" . ($action ? $action : 'delete') . '|' . $role
233 );
234 } else {
235 delete_user_meta($user, 'aam_user_expiration');
236 }
237 }
238
239 /**
240 * Get user expiration
241 *
242 * @param WP_User $user
243 *
244 * @return string
245 *
246 * @access protected
247 */
248 protected function getUserExpiration(AAM_Core_Subject_User $user) {
249 return get_user_meta($user->ID, 'aam_user_expiration', true);
250 }
251
252 /**
253 * Check max user allowance
254 *
255 * @param AAM_Core_Subject_User $user
256 *
257 * @return boolean
258 *
259 * @access protected
260 */
261 protected function isAllowed(AAM_Core_Subject_User $user) {
262 $max = AAM_Core_API::maxLevel(AAM::getUser()->allcaps);
263
264 return $max >= AAM_Core_API::maxLevel($user->allcaps);
265 }
266
267 }