PluginProbe ʕ •ᴥ•ʔ
Download Manager / 3.3.68
Download Manager v3.3.68
3.3.68 3.3.67 3.3.66 3.3.65 3.3.64 3.3.63 3.3.62 3.3.61 3.3.60 3.3.59 3.3.58 3.3.57 3.3.56 trunk 2.1.3 2.3.0 2.5.96 2.5.97 2.6.2 2.6.96 2.8.3 2.9.99 3.0.4 3.1.05 3.1.07 3.1.08 3.1.11 3.1.12 3.1.14 3.1.17 3.1.18 3.1.22 3.1.23 3.1.24 3.1.25 3.1.26 3.1.27 3.1.28 3.2.04 3.2.13 3.2.14 3.2.16 3.2.18 3.2.19 3.2.21 3.2.22 3.2.23 3.2.24 3.2.25 3.2.27 3.2.28 3.2.29 3.2.30 3.2.31 3.2.32 3.2.33 3.2.34 3.2.35 3.2.37 3.2.38 3.2.39 3.2.40 3.2.41 3.2.42 3.2.43 3.2.44 3.2.45 3.2.46 3.2.47 3.2.48 3.2.49 3.2.50 3.2.51 3.2.52 3.2.53 3.2.54 3.2.55 3.2.56 3.2.57 3.2.58 3.2.59 3.2.60 3.2.61 3.2.63 3.2.64 3.2.65 3.2.66 3.2.67 3.2.68 3.2.69 3.2.70 3.2.71 3.2.72 3.2.73 3.2.74 3.2.75 3.2.76 3.2.77 3.2.78 3.2.79 3.2.80 3.2.81 3.2.82 3.2.83 3.2.84 3.2.85 3.2.86 3.2.87 3.2.88 3.2.89 3.2.90 3.2.91 3.2.92 3.2.93 3.2.94 3.2.95 3.2.96 3.2.97 3.2.98 3.2.99 3.3.00 3.3.01 3.3.02 3.3.03 3.3.04 3.3.05 3.3.06 3.3.07 3.3.08 3.3.09 3.3.10 3.3.11 3.3.12 3.3.13 3.3.14 3.3.15 3.3.16 3.3.17 3.3.18 3.3.19 3.3.20 3.3.21 3.3.22 3.3.23 3.3.24 3.3.25 3.3.26 3.3.27 3.3.28 3.3.29 3.3.30 3.3.31 3.3.32 3.3.33 3.3.34 3.3.35 3.3.36 3.3.37 3.3.38 3.3.39 3.3.40 3.3.41 3.3.42 3.3.43 3.3.44 3.3.45 3.3.46 3.3.47 3.3.48 3.3.49 3.3.50 3.3.51 3.3.52 3.3.53 3.3.54 3.3.55
download-manager / src / User / PublicProfile.php
download-manager / src / User Last commit date
views 2 weeks ago Dashboard.php 7 months ago EditProfile.php 8 months ago Login.php 1 month ago PublicProfile.php 2 weeks ago Register.php 7 months ago User.php 4 months ago UserController.php 6 months ago
PublicProfile.php
133 lines
1 <?php
2 namespace WPDM\User;
3
4
5 use WPDM\__\__;
6 use WPDM\__\Crypt;
7 use WPDM\__\Messages;
8
9 class PublicProfile
10 {
11
12 public $profile_menu;
13 public $user;
14
15 private static $instance;
16
17 public static function getInstance()
18 {
19 if (self::$instance === null) {
20 self::$instance = new self;
21 }
22 return self::$instance;
23 }
24
25 function __construct(){
26 add_action("init", array($this, 'profileMenuInit'));
27 add_action("wp_ajax_wpdm_get_profile_menu_content", array($this, 'menuContent'));
28 add_action("wp_ajax_nopriv_wpdm_get_profile_menu_content", array($this, 'menuContent'));
29 add_shortcode("wpdm_user_profile", array($this, 'profile'));
30 }
31
32 function profileMenuInit(){
33 $this->profile_menu['downloads'] = array('icon' => 'fas fa-arrow-alt-circle-down', 'name'=> __( "Downloads" , "download-manager" ), 'content' => array($this, 'downloads'));
34 $this->profile_menu['favourites'] = array('icon' => 'fas fa-heart', 'name'=> __( "Favourites" , "download-manager" ), 'content' => array($this, 'favourites'));
35 $this->profile_menu = apply_filters("wpdm_user_profile_menu", $this->profile_menu);
36 }
37
38 function menuContent(){
39 $menu = wpdm_query_var('__pmenu');
40 // Only dispatch to registered profile-menu handlers.
41 if(!isset($this->profile_menu[$menu]) || !is_callable($this->profile_menu[$menu]['content'])) die();
42 // The profile owner id is signed into the __scp token emitted on the profile page. Requiring
43 // __pu to match the signed token blocks unauthenticated enumeration of arbitrary users' profile
44 // data ( e.g. favourites ) via a guessed/forged __pu ( CWE-862 Missing Authorization ).
45 if($this->profileUser() !== wpdm_query_var('__pu', 'int')){ status_header(403); die(); }
46 call_user_func($this->profile_menu[$menu]['content']);
47 die();
48 }
49
50 /**
51 * Authoritative profile-owner id, taken from the signed __scp token rather than the raw __pu
52 * request var. Returns 0 when the token is missing, invalid or forged so callers can reject.
53 */
54 private function profileUser(){
55 $scp = Crypt::decrypt(wpdm_query_var('__scp'), true);
56 return is_array($scp) ? (int) __::valueof($scp, '__pu') : 0;
57 }
58
59 function profile($params = array()){
60 global $wp_query;
61
62 if(!isset($params) || !is_array($params)) $params = array();
63
64 //if(is_admin()) return "";
65
66 ob_start();
67
68 $username = urldecode(get_query_var('profile'));
69 if(is_author())
70 $username = get_query_var('author_name');
71 if($username)
72 $user = get_user_by('slug', $username);
73 else
74 $user = wp_get_current_user();
75
76 $cols = isset($params['cols'])?$params['cols']:3;
77 $items_per_page = isset($params['items_per_page'])?$params['items_per_page']:$cols*3;
78 $cols = 12/$cols;
79 $template = isset($params['template'])?$params['template']:'link-template-panel.php';
80 $header = __::valueof($params, 'header', ['default' => 'default']);
81 $headers = ['default' => 'default.php', 'facebook' => 'facebook.php'];
82 $header = isset($headers[$header]) ? $headers[$header] : 'default.php';
83
84 $user_ID = $user->ID;
85 $store = get_user_meta($user_ID, '__wpdm_public_profile', true);
86 if(!is_array($store)) $store = array();
87 $store['logo'] = isset($store['logo'])?$store['logo']:get_avatar_url($user_ID);
88 $store['title'] = isset($store['title']) && $store['title'] != '' ? $store['title'] : $user->display_name;
89 $store['intro'] = isset($store['intro']) && $store['intro'] != '' ? $store['intro'] : '';
90 $store['description'] = isset($store['description']) && $store['description'] != '' ? $store['description'] : '';
91 $store['banner'] = isset($store['banner']) && $store['banner'] != '' ? $store['banner'] : '';
92 $store['bgcolor'] = isset($store['bgcolor']) && $store['bgcolor'] != '' ? $store['bgcolor'] : '#eeeeee';
93 $store['txtcolor'] = isset($store['txtcolor']) && $store['txtcolor'] != '' ? $store['txtcolor'] : '#333333';
94 $mydownloads = count_user_posts($user->ID, 'wpdmpro');
95 $rgb = wpdm_hex2rgb($store['bgcolor']);
96 $first_menu = array_keys($this->profile_menu);
97 $first_menu = $first_menu[0];
98 include WPDM()->template->locate('public-profile.php', __DIR__.'/views');
99 return ob_get_clean();
100 }
101
102
103 function downloads(){
104 $uid = $this->profileUser();
105 if(!$uid) die();
106 $params = Crypt::decrypt(wpdm_query_var('__scp'), true);
107 if(!is_array($params)) $params = array();
108 unset($params['__pu']);
109 $params['author'] = $uid;
110 $params['async'] = 1;
111 echo WPDM()->package->shortCodes->packages($params);
112 }
113
114 function favourites(){
115 $uid = $this->profileUser();
116 if(!$uid) die();
117 $params = Crypt::decrypt(wpdm_query_var('__scp'), true);
118 if(!is_array($params)) $params = array();
119 unset($params['__pu']);
120 $myfavs = maybe_unserialize(get_user_meta($uid, '__wpdm_favs', true));
121 if(!is_array($myfavs) || count($myfavs) === 0) {
122 Messages::info("Do not have any favourite item yet!");
123 die();
124 }
125 $params['post__in'] = implode(",", $myfavs);
126 echo WPDM()->package->shortCodes->packages($params);
127
128 }
129
130
131 }
132
133