PluginProbe
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler / 1.7.0
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler v1.7.0
1.7.0 1.6.6 1.6.5 1.6.4 1.6.3 1.6.2 1.6.1 1.6.0 1.5.4 1.5.5 1.5.3 1.5.2 1.5.1 1.5.0 1.4.2 1.4.1 1.4.0 1.3.28 1.3.27 1.3.26 1.3.25 1.3.23 1.3.22 1.3.21 1.3.20 All 50 releases
← All changes | app/Hooks/Handlers/UserHandler.php +24 -90 1.6.4 → 1.7.0 View file →
@@ -2,16 +2,10 @@
2 2
3 3 namespace FluentCart\App\Hooks\Handlers;
4 4
5 5 use FluentCart\App\Helpers\Status;
6 -use FluentCart\App\Models\AppliedCoupon;
7 -use FluentCart\App\Models\Cart;
6 +use FluentCart\App\Services\CustomerIdentity\EmailVerificationService;
8 7 use FluentCart\App\Models\Customer;
9 -use FluentCart\App\Models\CustomerAddresses;
10 -use FluentCart\App\Models\CustomerMeta;
11 -use FluentCart\App\Models\Order;
12 -use FluentCart\App\Models\OrderDownloadPermission;
13 -use FluentCart\App\Models\Subscription;
14 8 use FluentCart\Framework\Support\Arr;
15 9
16 10 class UserHandler
17 11 {
@@ -18,8 +12,10 @@
18 12 public function register()
19 13 {
20 14 add_action('delete_user', [$this, 'userDeleteHandler'], 10, 1);
21 15 add_action('user_register', [$this, 'userRegistrationHandler'], 10, 1);
16 + add_action('password_reset', [EmailVerificationService::class, 'capturePasswordResetProof'], 10, 1);
17 + add_action('after_password_reset', [EmailVerificationService::class, 'verifyAfterPasswordReset'], 10, 1);
22 18
23 19 // Let's handle auto user registration!
24 20 add_action('fluent_cart/cart_completed', [$this, 'maybeCreateUser'], 10, 1);
25 21
@@ -28,47 +24,24 @@
28 24 }
29 25
30 26 public function handleWpUserProfileUpdated($userId, $oldData, $newData = [])
31 27 {
32 - $emailChanged = $oldData->user_email !== $newData['user_email'];
33 -
34 - if (!$emailChanged) {
35 - return; // we will change the first name and last name a bit later
28 + // State is recorded only while the store requires verification; accounts
29 + // without it are treated as existing accounts if verification is enabled later.
30 + if (!EmailVerificationService::isEnabled()) {
31 + return;
36 32 }
37 33
38 - $newEmail = $newData['user_email'];
39 - $oldEmail = $oldData->user_email;
40 -
41 -
42 - $attachToCustomer = Customer::query()->where('email', $newEmail)->first();
43 -
44 -
45 - // if $attachToCustomer is empty, then simply just update the customer email
46 - if (empty($attachToCustomer)) {
47 - $oldCustomer = Customer::query()->where('email', $oldEmail)->first();
48 - Customer::query()->where('email', $oldEmail)->update(['email' => $newEmail]);
49 - do_action('fluent_cart/customer_email_changed', [
50 - 'old_customer' => $oldCustomer,
51 - 'new_customer' => $oldCustomer,
52 - 'old_email' => $oldEmail,
53 - 'new_email' => $newEmail,
54 - 'userId' => $userId
55 - ]);
56 - } else {
57 - $oldCustomer = Customer::query()->where('email', $oldEmail)->first();
58 - if (empty($oldCustomer)) {
59 - $attachToCustomer->update(['user_id' => $userId]);
60 - return;
61 - }
62 -
63 - $this->moveCustomerResources($oldCustomer->id, $attachToCustomer->id);
64 - $oldCustomer->recountStat();
65 - $attachToCustomer->recountStat();
34 + $user = $userId ? get_userdata($userId) : false;
35 + $oldEmail = is_object($oldData) && isset($oldData->user_email) ? wp_unslash($oldData->user_email) : '';
36 + if (!$user || EmailVerificationService::isSame($oldEmail, $user->user_email)) {
37 + return;
66 38 }
67 39
40 + // Account changes do not prove inbox ownership or change customer contact details.
41 + EmailVerificationService::markPending((int) $userId, $user->user_email);
68 42 }
69 43
70 -
71 44 public function maybeCreateUser($data)
72 45 {
73 46 $cart = Arr::get($data, 'cart');
74 47 $order = Arr::get($data, 'order');
@@ -73,9 +46,9 @@
73 46 $cart = Arr::get($data, 'cart');
74 47 $order = Arr::get($data, 'order');
75 48 $customer = $order->customer;
76 49
77 - if ($customer->getWpUserId(true)) {
50 + if ($customer->getWpUserId()) {
78 51 return; // User already exists
79 52 }
80 53
81 54 $willCreateUser = $order->type === Status::ORDER_TYPE_SUBSCRIPTION;
@@ -103,67 +76,28 @@
103 76 * @return void
104 77 */
105 78 public function userDeleteHandler($userId)
106 79 {
107 - $user = get_user_by('ID', $userId);
108 - if (!$user) {
80 + if (!$userId) {
109 81 return;
110 82 }
111 83
112 - // Check if the user_email is a customer
113 - $customer = Customer::query()
114 - ->where('email', $user->user_email)
115 - ->first();
116 -
117 - // remove user_id from $customer
118 - if ($customer) {
119 - $customer->update(['user_id' => NULL]);
120 - }
84 + // Unlink by identity. Matching on the account's email unlinked whichever
85 + // customer happened to hold it — possibly another account's — and left
86 + // this account's own customers pointing at a dead user id when their
87 + // contact address had drifted from the account's.
88 + Customer::query()->where('user_id', $userId)->update(['user_id' => null]);
121 89 }
122 90
123 91 public function userRegistrationHandler($userId)
124 92 {
125 - // get user by $userId
126 - $user = get_user_by('ID', $userId);
127 -
128 - // Check if the user_email is a customer
129 - $customer = Customer::query()
130 - ->where('email', $user->user_email)
131 - ->first();
132 -
133 - if ($customer) {
134 - $this->updateCustomer($customer, $user, $userId);
93 + if (!EmailVerificationService::isEnabled()) {
135 94 return;
136 95 }
137 - }
138 96
139 - private function updateCustomer(Customer $customer, object $user, int $userId): void
140 - {
141 - $data = ['user_id' => $userId];
142 -
143 - if (!empty($user->first_name)) {
144 - $data['first_name'] = $user->first_name;
97 + $user = $userId ? get_userdata($userId) : false;
98 + if ($user) {
99 + EmailVerificationService::markPending((int) $userId, $user->user_email);
145 100 }
146 -
147 - if (!empty($user->last_name)) {
148 - $data['last_name'] = $user->last_name;
149 - }
150 -
151 - $customer->update($data);
152 101 }
153 102
154 - private function moveCustomerResources($fromCustomerId, $toCustomerId)
155 - {
156 - OrderDownloadPermission::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
157 - Order::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
158 - AppliedCoupon::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
159 - Cart::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
160 - CustomerMeta::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
161 - CustomerAddresses::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
162 - Subscription::query()->where('customer_id', $fromCustomerId)->update(['customer_id' => $toCustomerId]);
163 -
164 - do_action('fluent_cart/customer_resources_moved', [
165 - 'from_customer_id' => $fromCustomerId,
166 - 'to_customer_id' => $toCustomerId
167 - ]);
168 - }
169 103 }