views
2 weeks ago
Dashboard.php
7 months ago
EditProfile.php
8 months ago
Login.php
1 month ago
PublicProfile.php
2 weeks ago
Register.php
7 months ago
User.php
4 months ago
UserController.php
6 months ago
PublicProfile.php
133 lines
| 1 | <?php |
| 2 | namespace WPDM\User; |
| 3 | |
| 4 | |
| 5 | use WPDM\__\__; |
| 6 | use WPDM\__\Crypt; |
| 7 | use WPDM\__\Messages; |
| 8 | |
| 9 | class PublicProfile |
| 10 | { |
| 11 | |
| 12 | public $profile_menu; |
| 13 | public $user; |
| 14 | |
| 15 | private static $instance; |
| 16 | |
| 17 | public static function getInstance() |
| 18 | { |
| 19 | if (self::$instance === null) { |
| 20 | self::$instance = new self; |
| 21 | } |
| 22 | return self::$instance; |
| 23 | } |
| 24 | |
| 25 | function __construct(){ |
| 26 | add_action("init", array($this, 'profileMenuInit')); |
| 27 | add_action("wp_ajax_wpdm_get_profile_menu_content", array($this, 'menuContent')); |
| 28 | add_action("wp_ajax_nopriv_wpdm_get_profile_menu_content", array($this, 'menuContent')); |
| 29 | add_shortcode("wpdm_user_profile", array($this, 'profile')); |
| 30 | } |
| 31 | |
| 32 | function profileMenuInit(){ |
| 33 | $this->profile_menu['downloads'] = array('icon' => 'fas fa-arrow-alt-circle-down', 'name'=> __( "Downloads" , "download-manager" ), 'content' => array($this, 'downloads')); |
| 34 | $this->profile_menu['favourites'] = array('icon' => 'fas fa-heart', 'name'=> __( "Favourites" , "download-manager" ), 'content' => array($this, 'favourites')); |
| 35 | $this->profile_menu = apply_filters("wpdm_user_profile_menu", $this->profile_menu); |
| 36 | } |
| 37 | |
| 38 | function menuContent(){ |
| 39 | $menu = wpdm_query_var('__pmenu'); |
| 40 | // Only dispatch to registered profile-menu handlers. |
| 41 | if(!isset($this->profile_menu[$menu]) || !is_callable($this->profile_menu[$menu]['content'])) die(); |
| 42 | // The profile owner id is signed into the __scp token emitted on the profile page. Requiring |
| 43 | // __pu to match the signed token blocks unauthenticated enumeration of arbitrary users' profile |
| 44 | // data ( e.g. favourites ) via a guessed/forged __pu ( CWE-862 Missing Authorization ). |
| 45 | if($this->profileUser() !== wpdm_query_var('__pu', 'int')){ status_header(403); die(); } |
| 46 | call_user_func($this->profile_menu[$menu]['content']); |
| 47 | die(); |
| 48 | } |
| 49 | |
| 50 | /** |
| 51 | * Authoritative profile-owner id, taken from the signed __scp token rather than the raw __pu |
| 52 | * request var. Returns 0 when the token is missing, invalid or forged so callers can reject. |
| 53 | */ |
| 54 | private function profileUser(){ |
| 55 | $scp = Crypt::decrypt(wpdm_query_var('__scp'), true); |
| 56 | return is_array($scp) ? (int) __::valueof($scp, '__pu') : 0; |
| 57 | } |
| 58 | |
| 59 | function profile($params = array()){ |
| 60 | global $wp_query; |
| 61 | |
| 62 | if(!isset($params) || !is_array($params)) $params = array(); |
| 63 | |
| 64 | //if(is_admin()) return ""; |
| 65 | |
| 66 | ob_start(); |
| 67 | |
| 68 | $username = urldecode(get_query_var('profile')); |
| 69 | if(is_author()) |
| 70 | $username = get_query_var('author_name'); |
| 71 | if($username) |
| 72 | $user = get_user_by('slug', $username); |
| 73 | else |
| 74 | $user = wp_get_current_user(); |
| 75 | |
| 76 | $cols = isset($params['cols'])?$params['cols']:3; |
| 77 | $items_per_page = isset($params['items_per_page'])?$params['items_per_page']:$cols*3; |
| 78 | $cols = 12/$cols; |
| 79 | $template = isset($params['template'])?$params['template']:'link-template-panel.php'; |
| 80 | $header = __::valueof($params, 'header', ['default' => 'default']); |
| 81 | $headers = ['default' => 'default.php', 'facebook' => 'facebook.php']; |
| 82 | $header = isset($headers[$header]) ? $headers[$header] : 'default.php'; |
| 83 | |
| 84 | $user_ID = $user->ID; |
| 85 | $store = get_user_meta($user_ID, '__wpdm_public_profile', true); |
| 86 | if(!is_array($store)) $store = array(); |
| 87 | $store['logo'] = isset($store['logo'])?$store['logo']:get_avatar_url($user_ID); |
| 88 | $store['title'] = isset($store['title']) && $store['title'] != '' ? $store['title'] : $user->display_name; |
| 89 | $store['intro'] = isset($store['intro']) && $store['intro'] != '' ? $store['intro'] : ''; |
| 90 | $store['description'] = isset($store['description']) && $store['description'] != '' ? $store['description'] : ''; |
| 91 | $store['banner'] = isset($store['banner']) && $store['banner'] != '' ? $store['banner'] : ''; |
| 92 | $store['bgcolor'] = isset($store['bgcolor']) && $store['bgcolor'] != '' ? $store['bgcolor'] : '#eeeeee'; |
| 93 | $store['txtcolor'] = isset($store['txtcolor']) && $store['txtcolor'] != '' ? $store['txtcolor'] : '#333333'; |
| 94 | $mydownloads = count_user_posts($user->ID, 'wpdmpro'); |
| 95 | $rgb = wpdm_hex2rgb($store['bgcolor']); |
| 96 | $first_menu = array_keys($this->profile_menu); |
| 97 | $first_menu = $first_menu[0]; |
| 98 | include WPDM()->template->locate('public-profile.php', __DIR__.'/views'); |
| 99 | return ob_get_clean(); |
| 100 | } |
| 101 | |
| 102 | |
| 103 | function downloads(){ |
| 104 | $uid = $this->profileUser(); |
| 105 | if(!$uid) die(); |
| 106 | $params = Crypt::decrypt(wpdm_query_var('__scp'), true); |
| 107 | if(!is_array($params)) $params = array(); |
| 108 | unset($params['__pu']); |
| 109 | $params['author'] = $uid; |
| 110 | $params['async'] = 1; |
| 111 | echo WPDM()->package->shortCodes->packages($params); |
| 112 | } |
| 113 | |
| 114 | function favourites(){ |
| 115 | $uid = $this->profileUser(); |
| 116 | if(!$uid) die(); |
| 117 | $params = Crypt::decrypt(wpdm_query_var('__scp'), true); |
| 118 | if(!is_array($params)) $params = array(); |
| 119 | unset($params['__pu']); |
| 120 | $myfavs = maybe_unserialize(get_user_meta($uid, '__wpdm_favs', true)); |
| 121 | if(!is_array($myfavs) || count($myfavs) === 0) { |
| 122 | Messages::info("Do not have any favourite item yet!"); |
| 123 | die(); |
| 124 | } |
| 125 | $params['post__in'] = implode(",", $myfavs); |
| 126 | echo WPDM()->package->shortCodes->packages($params); |
| 127 | |
| 128 | } |
| 129 | |
| 130 | |
| 131 | } |
| 132 | |
| 133 |