PluginProbe
Groups – Memberships and Access Control / 4.7.1
Groups – Memberships and Access Control v4.7.1
4.8.0 4.7.1 4.7.0 4.6.0 4.5.0 4.4.0 4.3.0 trunk 1.0.0-beta-1 1.0.0-beta-2 1.0.0-beta-3 1.0.0-beta-3b 1.0.0-beta-3c 1.0.0-beta-3d 1.1.4 1.1.5 1.10.0 1.10.1 1.10.2 1.10.3 1.11.0 1.11.1 1.11.2 1.11.3 1.12.0 All 132 releases
← All changes | lib/core/class-groups-user-group.php +86 -49 1.11.1 → 4.7.1 View file →
@@ -22,8 +22,10 @@
22 22 if ( !defined( 'ABSPATH' ) ) {
23 23 exit;
24 24 }
25 25
26 +// phpcs:disable PluginCheck.Security.DirectDB.UnescapedDBParameter, WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
27 +
26 28 /**
27 29 * User Group OPM.
28 30 */
29 31 class Groups_User_Group {
@@ -28,14 +30,17 @@
28 30 */
29 31 class Groups_User_Group {
30 32
31 33 /**
32 - * @var persisted object
34 + * @var object persisted object
35 + *
36 + * @access private - do not access this property directly, the visibility will be made private in the future
33 37 */
34 - var $user_group = null;
38 + public $user_group = null;
35 39
36 40 /**
37 41 * Hook into appropriate actions.
42 + *
38 43 * @see wp_delete_user()
39 44 * @see remove_user_from_blog()
40 45 */
41 46 public static function init() {
@@ -40,41 +45,64 @@
40 45 */
41 46 public static function init() {
42 47 // when a user is deleted, it must be removed from all groups it
43 48 // belongs to - triggered by wp_delete_user() and wpmu_delete_user()
44 - add_action( "deleted_user", array( __CLASS__, "deleted_user" ) );
49 + add_action( 'deleted_user', array( __CLASS__, 'deleted_user' ) );
45 50
46 51 // when a user is removed from a blog, the user must be removed
47 52 // from all groups in that blog that it belongs to
48 - add_action( "remove_user_from_blog", array( __CLASS__, "remove_user_from_blog" ), 10, 2 );
53 + add_action( 'remove_user_from_blog', array( __CLASS__, 'remove_user_from_blog' ), 10, 2 );
49 54 }
50 55
51 56 /**
52 57 * Create by user and group id.
53 58 * Must have been persisted.
59 + *
54 60 * @param int $user_id
55 61 * @param int $group_id
56 62 */
57 63 public function __construct( $user_id, $group_id ) {
58 64 $this->user_group = self::read( $user_id, $group_id );
65 + if ( $this->user_group === false ) {
66 + $this->user_group = null;
67 + }
59 68 }
60 69
61 70 /**
71 + * Provide the user ID related to this object.
72 + *
73 + * @return int|null
74 + */
75 + public function get_user_id() {
76 + return $this->user_id; // @phpstan-ignore property.notFound
77 + }
78 +
79 + /**
80 + * Provide the group ID related to this object.
81 + *
82 + * @return int|null
83 + */
84 + public function get_group_id() {
85 + return $this->group_id; // @phpstan-ignore property.notFound
86 + }
87 +
88 + /**
62 89 * Retrieve a property by name.
63 - *
90 + *
64 91 * Possible properties:
65 92 * - user_id
66 93 * - group_id
67 - *
94 + *
68 95 * @param string $name property's name
69 - * @return property value, will return null if property does not exist
96 + *
97 + * @return mixed property value, will return null if property does not exist
70 98 */
71 99 public function __get( $name ) {
72 100 $result = null;
73 101 if ( $this->user_group !== null ) {
74 - switch( $name ) {
75 - case "user_id" :
76 - case "group_id" :
102 + switch ( $name ) {
103 + case 'user_id' :
104 + case 'group_id' :
77 105 $result = $this->user_group->$name;
78 106 break;
79 107 }
80 108 }
@@ -82,18 +110,25 @@
82 110 }
83 111
84 112 /**
85 113 * Persist a user-group relation.
86 - *
114 + *
115 + * As of Groups 2.2.0, this is not invoked when entries for existing users are created on
116 + * plugin activation, thus the 'groups_created_user_group' action is not called for these.
117 + *
87 118 * @param array $map attributes - must provide user_id and group_id
119 + *
88 120 * @return true on success, otherwise false
89 121 */
90 122 public static function create( $map ) {
91 123
92 124 global $wpdb;
93 - extract( $map );
125 +
94 126 $result = false;
95 127
128 + $group_id = isset( $map['group_id'] ) ? $map['group_id'] : null;
129 + $user_id = isset( $map['user_id'] ) ? $map['user_id'] : null;
130 +
96 131 // avoid nonsense requests
97 132 if ( !empty( $group_id ) ) {
98 133 // make sure user and group exist
99 134 if (
@@ -107,9 +142,9 @@
107 142 $user_group_table = _groups_get_tablename( 'user_group' );
108 143 // don't try to create duplicate entries
109 144 // also it would raise an error for duplicate PK
110 145 if ( 0 === intval( $wpdb->get_var( $wpdb->prepare(
111 - "SELECT COUNT(*) FROM $user_group_table WHERE user_id = %d AND group_id = %d",
146 + "SELECT COUNT(*) FROM $user_group_table WHERE user_id = %d AND group_id = %d", // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared
112 147 Groups_Utility::id( $user_id ),
113 148 Groups_Utility::id( $group_id ) ) ) )
114 149 ) {
115 150 $data = array(
@@ -118,9 +153,9 @@
118 153 );
119 154 $formats = array( '%d', '%d' );
120 155 if ( $wpdb->insert( $user_group_table, $data, $formats ) ) {
121 156 $result = true;
122 - do_action( "groups_created_user_group", $user_id, $group_id );
157 + do_action( 'groups_created_user_group', $user_id, $group_id );
123 158 }
124 159 }
125 160 }
126 161 }
@@ -129,11 +164,12 @@
129 164 }
130 165
131 166 /**
132 167 * Retrieve a user-group relation.
133 - *
168 + *
134 169 * @param int $user_id user's id
135 170 * @param int $group_id group's id
171 + *
136 172 * @return object upon success, otherwise false
137 173 */
138 174 public static function read( $user_id, $group_id ) {
139 175 global $wpdb;
@@ -140,9 +176,9 @@
140 176 $result = false;
141 177
142 178 $user_group_table = _groups_get_tablename( 'user_group' );
143 179 $user_group = $wpdb->get_row( $wpdb->prepare(
144 - "SELECT * FROM $user_group_table WHERE user_id = %d AND group_id = %d",
180 + "SELECT * FROM $user_group_table WHERE user_id = %d AND group_id = %d", // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared
145 181 Groups_Utility::id( $user_id ),
146 182 Groups_Utility::id( $group_id )
147 183 ) );
148 184 if ( $user_group !== null ) {
@@ -152,23 +188,27 @@
152 188 }
153 189
154 190 /**
155 191 * Update user-group relation.
156 - *
157 - * This is a relation and as the relation is, this does nothing and
158 - * it SHOULD do nothing.
159 - *
192 + *
193 + * As the relation has no properties that could be updated, this method does nothing and will return false.
194 + *
160 195 * @param array $map
196 + *
161 197 * @return true on success, otherwise false
162 198 */
163 199 public static function update( $map ) {
164 200 $result = false;
165 -// if ( !empty( $user_id ) && !empty( $group_id) ) {
166 - if ( !empty( $group_id) ) {
167 - // make sure user and group exist
168 - if ( ( false !== Groups_Utility::id( $user_id ) ) && get_user_by( "id", $user_id ) && Groups_Group::read( $group_id ) ) {
169 - $result = true;
170 - do_action( "groups_updated_user_group", $user_id, $group_id );
201 + // @since 2.20.0 do not process
202 + if ( false ) {
203 + $group_id = isset( $map['group_id'] ) ? $map['group_id'] : null;
204 + $user_id = isset( $map['user_id'] ) ? $map['user_id'] : null;
205 + if ( $group_id !== null && $user_id !== null ) {
206 + // make sure user and group exist
207 + if ( ( false !== Groups_Utility::id( $user_id ) ) && get_user_by( 'id', $user_id ) && Groups_Group::read( $group_id ) ) {
208 + $result = true;
209 + do_action( 'groups_updated_user_group', $user_id, $group_id );
210 + }
171 211 }
172 212 }
173 213 return $result;
174 214 }
@@ -174,11 +214,12 @@
174 214 }
175 215
176 216 /**
177 217 * Remove user-group relation.
178 - *
218 + *
179 219 * @param int $user_id
180 220 * @param int $group_id
221 + *
181 222 * @return true if successful, false otherwise
182 223 */
183 224 public static function delete( $user_id, $group_id ) {
184 225
@@ -185,9 +226,8 @@
185 226 global $wpdb;
186 227 $result = false;
187 228
188 229 // avoid nonsense requests
189 -// if ( !empty( $user_id ) && !empty( $group_id ) ) {
190 230 if ( !empty( $group_id ) ) {
191 231 // to allow deletion of an entry after a user has been deleted,
192 232 // we don't check if the user exists
193 233 $user_group_table = _groups_get_tablename( 'user_group' );
@@ -192,9 +232,9 @@
192 232 // we don't check if the user exists
193 233 $user_group_table = _groups_get_tablename( 'user_group' );
194 234 // get rid of it
195 235 $rows = $wpdb->query( $wpdb->prepare(
196 - "DELETE FROM $user_group_table WHERE user_id = %d AND group_id = %d",
236 + "DELETE FROM $user_group_table WHERE user_id = %d AND group_id = %d", // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared
197 237 Groups_Utility::id( $user_id ),
198 238 Groups_Utility::id( $group_id )
199 239 ) );
200 240 // must have affected a row, otherwise no great success
@@ -199,9 +239,9 @@
199 239 ) );
200 240 // must have affected a row, otherwise no great success
201 241 $result = ( $rows !== false ) && ( $rows > 0 );
202 242 if ( $result ) {
203 - do_action( "groups_deleted_user_group", $user_id, $group_id );
243 + do_action( 'groups_deleted_user_group', $user_id, $group_id );
204 244 }
205 245 }
206 246 return $result;
207 247 }
@@ -208,23 +248,23 @@
208 248
209 249 /**
210 250 * Hooks into the deleted_user action to remove the deleted user from
211 251 * all groups it belongs to.
212 - *
252 + *
213 253 * @param int $user_id
214 254 */
215 255 public static function deleted_user( $user_id ) {
216 256 global $wpdb;
217 257
218 - $user_group_table = _groups_get_tablename( "user_group" );
258 + $user_group_table = _groups_get_tablename( 'user_group' );
219 259 $rows = $wpdb->get_results( $wpdb->prepare(
220 - "SELECT * FROM $user_group_table WHERE user_id = %d",
260 + "SELECT * FROM $user_group_table WHERE user_id = %d", // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared
221 261 Groups_Utility::id( $user_id )
222 262 ) );
223 263 if ( $rows ) {
224 - foreach( $rows as $row ) {
264 + foreach ( $rows as $row ) {
225 265 // don't optimize that in preference of a standard deletion
226 - // process (trigger actions ...)
266 + // process (trigger actions ...)
227 267 self::delete( $row->user_id, $row->group_id );
228 268 }
229 269 }
230 270 }
@@ -231,12 +271,12 @@
231 271
232 272 /**
233 273 * Hooks into the remove_user_from_blog action to remove the user
234 274 * from groups that belong to that blog.
235 - *
236 - * Note that this is preemptive as there is no
237 - * removed_user_from_blog action.
238 - *
275 + *
276 + * Note that this is preemptive as there is no
277 + * removed_user_from_blog action.
278 + *
239 279 * @param int $user_id
240 280 * @param int $blog_id
241 281 */
242 282 public static function remove_user_from_blog( $user_id, $blog_id ) {
@@ -246,25 +286,22 @@
246 286 }
247 287
248 288 global $wpdb;
249 289
250 - $group_table = _groups_get_tablename( "group" );
251 - $user_group_table = _groups_get_tablename( "user_group" );
252 - // We can end up here while a blog is being deleted, in that case,
290 + $group_table = _groups_get_tablename( 'group' );
291 + $user_group_table = _groups_get_tablename( 'user_group' );
292 + // We can end up here while a blog is being deleted, in that case,
253 293 // the tables have already been deleted.
254 - if ( ( $wpdb->get_var( "SHOW TABLES LIKE '" . $group_table . "'" ) == $group_table ) &&
255 - ( $wpdb->get_var( "SHOW TABLES LIKE '" . $user_group_table . "'" ) == $user_group_table )
294 + if ( ( $wpdb->get_var( "SHOW TABLES LIKE '" . $group_table . "'" ) == $group_table ) && // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
295 + ( $wpdb->get_var( "SHOW TABLES LIKE '" . $user_group_table . "'" ) == $user_group_table ) // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
256 296 ) {
257 297
258 298 $rows = $wpdb->get_results( $wpdb->prepare(
259 - "SELECT * FROM $user_group_table
260 - LEFT JOIN $group_table ON $user_group_table.group_id = $group_table.group_id
261 - WHERE $user_group_table.user_id = %d
262 - ",
299 + "SELECT * FROM $user_group_table LEFT JOIN $group_table ON $user_group_table.group_id = $group_table.group_id WHERE $user_group_table.user_id = %d", // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared
263 300 Groups_Utility::id( $user_id )
264 301 ) );
265 302 if ( $rows ) {
266 - foreach( $rows as $row ) {
303 + foreach ( $rows as $row ) {
267 304 // don't optimize that, favour standard deletion
268 305 self::delete( $row->user_id, $row->group_id );
269 306 }
270 307 }