PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / 5.8.2
Advanced Access Manager – Access Governance for WordPress v5.8.2
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / Application / Backend / Feature / Subject / User.php
advanced-access-manager / Application / Backend / Feature / Subject Last commit date
Role.php 7 years ago User.php 7 years ago
User.php
315 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * User view manager
12 *
13 * @package AAM
14 * @author Vasyl Martyniuk <vasyl@vasyltech.com>
15 */
16 class AAM_Backend_Feature_Subject_User {
17
18 /**
19 * Retrieve list of users
20 *
21 * Based on filters, get list of users
22 *
23 * @return string JSON encoded list of users
24 *
25 * @access public
26 */
27 public function getTable() {
28 $response = array(
29 'recordsTotal' => 0,
30 'recordsFiltered' => 0,
31 'draw' => AAM_Core_Request::request('draw'),
32 'data' => array(),
33 );
34
35 // TODO: The list_users is legacy and can be removed in Oct 2021
36 if (current_user_can('aam_manage_users') || current_user_can('list_users')) {
37 //get total number of users
38 $total = count_users();
39 $result = $this->query();
40
41 $response['recordsTotal'] = $total['total_users'];
42 $response['recordsFiltered'] = $result->get_total();
43
44 foreach ($result->get_results() as $row) {
45 $user = new AAM_Core_Subject_User($row->ID);
46 $user->initialize(true);
47 $response['data'][] = $this->prepareRow($user);
48 }
49 }
50
51 return wp_json_encode($response);
52 }
53
54 /**
55 * Save user expiration
56 *
57 * @return string
58 *
59 * @access public
60 */
61 public function saveExpiration() {
62 $response = array(
63 'status' => 'failure',
64 'reason' => __('Operation is not permitted', AAM_KEY)
65 );
66
67 $userId = filter_input(INPUT_POST, 'user');
68 $expires = filter_input(INPUT_POST, 'expires');
69 $action = filter_input(INPUT_POST, 'after');
70 $role = filter_input(INPUT_POST, 'role');
71
72 if (current_user_can('edit_users')) {
73 if ($userId != get_current_user_id()) {
74 if ($this->isAllowed(new AAM_Core_Subject_User($userId))) {
75 $this->updateUserExpiration($userId, $expires, $action, $role);
76 $response = array('status' => 'success');
77 }
78 } else {
79 $response['reason'] = __('You cannot set expiration to yourself', AAM_KEY);
80 }
81 }
82
83 return wp_json_encode($response);
84 }
85
86 /**
87 *
88 * @return type
89 */
90 public function generateJWT() {
91 $userId = filter_input(INPUT_POST, 'user');
92 $expires = filter_input(INPUT_POST, 'expires');
93
94 $jwt = AAM_Core_JwtAuth::generateJWT($userId, $expires);
95
96 return wp_json_encode(array(
97 'status' => 'success',
98 'jwt' => $jwt->token
99 ));
100 }
101
102 /**
103 * Query database for list of users
104 *
105 * Based on filters and settings get the list of users from database
106 *
107 * @return \WP_User_Query
108 *
109 * @access public
110 */
111 public function query() {
112 $search = trim(AAM_Core_Request::request('search.value'));
113 $role = trim(AAM_Core_Request::request('role'));
114
115 $args = array(
116 'blog_id' => get_current_blog_id(),
117 'fields' => 'all',
118 'number' => AAM_Core_Request::request('length'),
119 'offset' => AAM_Core_Request::request('start'),
120 'search' => ($search ? $search . '*' : ''),
121 'search_columns' => array(
122 'user_login', 'user_email', 'display_name'
123 ),
124 'orderby' => 'display_name',
125 'order' => $this->getOrderDirection()
126 );
127
128 if (!empty($role)) {
129 $args['role__in'] = $role;
130 }
131
132 return new WP_User_Query($args);
133 }
134
135 /**
136 *
137 * @return type
138 */
139 protected function getOrderDirection() {
140 $dir = 'asc';
141 $order = AAM_Core_Request::post('order.0');
142
143 if (!empty($order['column']) && ($order['column'] === '2')) {
144 $dir = !empty($order['dir']) ? $order['dir'] : 'asc';
145 }
146
147 return strtoupper($dir);
148 }
149
150 /**
151 * Block user
152 *
153 * @return string
154 *
155 * @access public
156 */
157 public function block() {
158 $result = false;
159
160 if (current_user_can('aam_toggle_users') && current_user_can('edit_users')) {
161 $subject = AAM_Backend_Subject::getInstance();
162
163 if ($this->isAllowed($subject->get())) {
164 //user is not allowed to lock himself
165 if (intval($subject->getId()) !== get_current_user_id()) {
166 $result = $subject->block();
167 }
168 }
169 }
170
171 return wp_json_encode(array('status' => ($result ? 'success' : 'failure')));
172 }
173
174 /**
175 * Prepare row
176 *
177 * @param AAM_Core_Subject_User $user
178 *
179 * @return array
180 *
181 * @access protected
182 */
183 protected function prepareRow(AAM_Core_Subject_User $user) {
184 return array(
185 $user->ID,
186 implode(', ', $this->getUserRoles($user->roles)),
187 ($user->display_name ? $user->display_name : $user->user_nicename),
188 implode(',', $this->prepareRowActions($user)),
189 AAM_Core_API::maxLevel($user->getMaxLevel()),
190 $this->getUserExpiration($user)
191 );
192 }
193
194 /**
195 * Get list of user roles
196 *
197 * @param array $roles
198 *
199 * @return array
200 *
201 * @access protected
202 */
203 protected function getUserRoles($roles) {
204 $response = array();
205
206 $names = AAM_Core_API::getRoles()->get_names();
207
208 if (is_array($roles)) {
209 foreach($roles as $role) {
210 if (array_key_exists($role, $names)) {
211 $response[] = translate_user_role($names[$role]);
212 }
213 }
214 }
215
216 return $response;
217 }
218
219 /**
220 * Prepare user row actions
221 *
222 * @param WP_User $user
223 *
224 * @return array
225 *
226 * @access protected
227 */
228 protected function prepareRowActions(AAM_Core_Subject_User $user) {
229 if ($this->isAllowed($user) || ($user->ID === get_current_user_id())) {
230 $ui = AAM_Core_Request::post('ui', 'main');
231 $id = AAM_Core_Request::post('id');
232
233 if ($ui === 'principal') {
234 $object = $user->getObject('policy');
235 $actions = array(($object->has($id) ? 'detach' : 'attach'));
236 } else {
237 $actions = array('manage');
238
239 if (AAM_Core_Config::get('core.settings.secureLogin', true)
240 && current_user_can('aam_toggle_users')) {
241 $actions[] = ($user->user_status ? 'unlock' : 'lock');
242 }
243
244 if (current_user_can('edit_users')) {
245 $actions[] = 'edit';
246 } else {
247 $actions[] = 'no-edit';
248 }
249
250 if (current_user_can('aam_switch_users')) {
251 $actions[] = 'switch';
252 } else {
253 $actions[] = 'no-switch';
254 }
255 }
256 } else {
257 $actions = array();
258 }
259
260 return $actions;
261 }
262
263 /**
264 * Update user expiration
265 *
266 * @param int $user
267 * @param string $expires
268 * @param string $action
269 * @param string $role
270 *
271 * @return bool
272 *
273 * @access protected
274 */
275 protected function updateUserExpiration($user, $expires, $action, $role = '') {
276 if (trim($expires)) {
277 update_user_meta(
278 $user,
279 'aam_user_expiration',
280 $expires . "|" . ($action ? $action : 'delete') . '|' . $role
281 );
282 } else {
283 delete_user_meta($user, 'aam_user_expiration');
284 }
285 }
286
287 /**
288 * Get user expiration
289 *
290 * @param WP_User $user
291 *
292 * @return string
293 *
294 * @access protected
295 */
296 protected function getUserExpiration(AAM_Core_Subject_User $user) {
297 return get_user_meta($user->ID, 'aam_user_expiration', true);
298 }
299
300 /**
301 * Check max user allowance
302 *
303 * @param AAM_Core_Subject_User $user
304 *
305 * @return boolean
306 *
307 * @access protected
308 */
309 protected function isAllowed(AAM_Core_Subject_User $user) {
310 $max = AAM::getUser()->getMaxLevel();
311
312 return $max >= AAM_Core_API::maxLevel($user->allcaps);
313 }
314
315 }