PluginProbe
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor / 2.7.1
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor v2.7.1
4.0.3 4.0.2 4.0.1 4.0.0 3.16.6 3.16.5 3.16.4 3.16.3 3.16.2 3.16.1 3.16.0 3.15.9 3.9.9 3.9.5 3.9.6 3.9.7 3.9.8 1.1.7 1.1.8 1.1.9 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 All 341 releases
← All changes | front-end/class-formbuilder.php +491 -226 2.0.2 → 2.7.1 View file →
@@ -4,17 +4,37 @@
4 4 'form_type' => '',
5 5 'form_fields' => array(),
6 6 'form_name' => '',
7 7 'role' => '', //used only for the register-form settings
8 + 'redirect_url' => '',
9 + 'logout_redirect_url' => '', //used only for the register-form settings
10 + 'redirect_priority' => 'normal',
11 + 'ID' => null
8 12 );
9 - private $args;
13 + public $args;
10 14
11 15
12 16 // Constructor method for the class
13 17 function __construct( $args ) {
18 +
19 + /* we should stop the execution of the forms if they are in the wp_head hook because it should not be there.
20 + SEO plugins can execute shortcodes in the auto generated descriptions */
21 + global $wp_current_filter;
22 + if( !empty( $wp_current_filter ) && is_array( $wp_current_filter ) ){
23 + foreach( $wp_current_filter as $filter ){
24 + if( $filter == 'wp_head' )
25 + return;
26 + }
27 + }
28 +
14 29 // Merge the input arguments and the defaults
15 30 $this->args = wp_parse_args( $args, $this->defaults );
16 31
32 + /* set up the ID here if it is a multi form */
33 + if( $this->args['form_name'] != 'unspecified' ){
34 + $this->args['ID'] = Profile_Builder_Form_Creator::wppb_get_form_id_from_form_name( $this->args['form_name'], $this->args['form_type'] );
35 + }
36 +
17 37 global $wppb_shortcode_on_front;
18 38 $wppb_shortcode_on_front = true;
19 39
20 40 if( empty( $this->args['form_fields'] ) )
@@ -24,55 +44,88 @@
24 44 require_once( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' );
25 45
26 46 if ( file_exists ( WPPB_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ) )
27 47 require_once( WPPB_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' );
28 -
48 +
29 49 $this->wppb_retrieve_custom_settings();
30 50
31 - add_action( 'wp_footer', array( &$this, 'wppb_print_script' ) ); //print scripts
51 + if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) )
52 + add_action( 'wppb_before_edit_profile_fields', array( &$this, 'wppb_edit_profile_select_user_to_edit' ) );
32 53 }
54 +
55 + /**
56 + * @param $form_name The "slug" generated from the current Form Title
57 + * @param $form_type the form type of the form: register, edit_profile
58 + * @return null
59 + */
60 + static function wppb_get_form_id_from_form_name( $form_name, $form_type ){
61 + global $wpdb;
62 +
63 + if( $form_type == 'edit_profile' ){
64 + $post_type = 'wppb-epf-cpt';
65 + }elseif( $form_type == 'register' ){
66 + $post_type = 'wppb-rf-cpt';
67 + }
68 +
69 + $all_forms = $wpdb->get_results(
70 + "
71 + SELECT ID, post_title
72 + FROM $wpdb->posts
73 + WHERE post_status = 'publish'
74 + AND post_type = '$post_type'
75 + "
76 + );
77 +
78 + if( !empty( $all_forms ) ) {
79 + foreach ($all_forms as $form) {
80 + if( empty( $form->post_title ) )
81 + $form->post_title = '(no title)';
82 +
83 + if ($form_name == Wordpress_Creation_Kit_PB::wck_generate_slug($form->post_title)) {
84 + return $form->ID;
85 + }
86 + }
87 + }
88 +
89 + return null;
90 + }
33 91
34 92 function wppb_retrieve_custom_settings(){
35 93 $this->args['login_after_register'] = apply_filters( 'wppb_automatically_login_after_register', 'No' ); //used only for the register-form settings
36 - $this->args['redirect_activated'] = apply_filters( 'wppb_redirect_default_setting', '' );
37 - $this->args['redirect_url'] = apply_filters( 'wppb_redirect_default_location', wppb_curpageurl() );
38 - /* for register forms check to see if we have a custom redirect "Redirect After Register" */
39 - if( $this->args['form_type'] == 'register' ){
40 - $wppb_module_settings = get_option( 'wppb_module_settings' );
41 - if ( isset( $wppb_module_settings['wppb_customRedirect'] ) && ( $wppb_module_settings['wppb_customRedirect'] == 'show' ) ){
42 - $custom_redirect = get_option( 'customRedirectSettings' );
43 - if ( isset( $custom_redirect['afterRegister'] ) && ( $custom_redirect['afterRegister'] == 'yes' ) && ( trim( $custom_redirect['afterRegisterTarget'] ) != '' ) ){
44 - $this->args['redirect_url'] = $this->args['custom_redirect_after_register_url'] = apply_filters( 'wppb_redirect_default_location', $custom_redirect['afterRegisterTarget'] );
94 + $this->args['redirect_activated'] = apply_filters( 'wppb_redirect_default_setting', '-' );
95 + $this->args['redirect_url'] = apply_filters( 'wppb_redirect_default_location', ( $this->args['redirect_url'] != '' ) ? $this->args['redirect_url'] : '' );
96 + $this->args['logout_redirect_url'] = apply_filters( 'wppb_logout_redirect_default_location', ( $this->args['logout_redirect_url'] != '' ) ? $this->args['logout_redirect_url'] : '' );
97 + $this->args['redirect_delay'] = apply_filters( 'wppb_redirect_default_duration', 3 );
98 +
99 + if ( !is_null( $this->args['ID'] ) ){
100 + $meta_name = ( ( $this->args['form_type'] == 'register' ) ? 'wppb_rf_page_settings' : 'wppb_epf_page_settings' );
101 +
102 + $page_settings = get_post_meta( $this->args['ID'], $meta_name, true );
103 +
104 + if( !empty( $page_settings[0]['set-role'] ) ){
105 + if( $page_settings[0]['set-role'] == 'default role' ){
106 + $selected_role = trim( get_option( 'default_role' ) );
45 107 }
108 + else
109 + $selected_role = $page_settings[0]['set-role'];
46 110 }
47 - }
48 - $this->args['redirect_delay'] = apply_filters( 'wppb_redirect_default_duration', 3 );
49 -
50 - if ( $this->args['form_name'] != 'unspecified' ){
51 - $post_type = ( ( $this->args['form_type'] == 'register' ) ? 'wppb-rf-cpt' : 'wppb-epf-cpt' );
52 - $meta_name = ( ( $this->args['form_type'] == 'register' ) ? 'wppb_rf_page_settings' : 'wppb_epf_page_settings' );
53 -
54 - $ep_r_posts = get_posts( array( 'posts_per_page' => -1, 'post_status' => apply_filters ( 'wppb_get_ep_r_posts_on_front_end', array( 'publish' ) ), 'post_type' => $post_type, 'orderby' => 'post_date', 'order' => 'ASC' ) );
55 - foreach ( $ep_r_posts as $key => $value ){
56 - if ( trim( Wordpress_Creation_Kit_PB::wck_generate_slug( $value->post_title ) ) == $this->args['form_name'] ){
57 - $page_settings = get_post_meta( $value->ID, $meta_name, true );
58 111
59 - if( !empty( $page_settings[0]['set-role'] ) ){
60 - if( $page_settings[0]['set-role'] == 'default role' ){
61 - $selected_role = trim( get_option( 'default_role' ) );
62 - }
63 - else
64 - $selected_role = $page_settings[0]['set-role'];
65 - }
66 -
67 - $this->args['role'] = ( isset( $selected_role ) ? $selected_role : $this->args['role'] );
68 - $this->args['login_after_register'] = ( isset( $page_settings[0]['automatically-log-in'] ) ? $page_settings[0]['automatically-log-in'] : $this->args['login_after_register'] );
69 - $this->args['redirect_activated'] = ( isset( $page_settings[0]['redirect'] ) ? $page_settings[0]['redirect'] : $this->args['redirect_activated'] );
70 - $this->args['redirect_url'] = ( isset( $page_settings[0]['url'] ) ? $page_settings[0]['url'] : $this->args['redirect_url'] );
71 - $this->args['redirect_delay'] = ( isset( $page_settings[0]['display-messages'] ) ? $page_settings[0]['display-messages'] : $this->args['redirect_delay'] );
72 - }
73 - }
112 + $this->args['role'] = ( isset( $selected_role ) ? $selected_role : $this->args['role'] );
113 + $this->args['login_after_register'] = ( isset( $page_settings[0]['automatically-log-in'] ) ? $page_settings[0]['automatically-log-in'] : $this->args['login_after_register'] );
114 + $this->args['redirect_activated'] = ( isset( $page_settings[0]['redirect'] ) ? $page_settings[0]['redirect'] : $this->args['redirect_activated'] );
115 + $this->args['redirect_url'] = ( ! empty( $page_settings[0]['url'] ) && $this->args['redirect_activated'] == 'Yes' && $this->args['redirect_priority'] != 'top' ? $page_settings[0]['url'] : $this->args['redirect_url'] );
116 + $this->args['redirect_delay'] = ( isset( $page_settings[0]['display-messages'] ) && $this->args['redirect_activated'] == 'Yes' ? $page_settings[0]['display-messages'] : $this->args['redirect_delay'] );
74 117 }
118 +
119 + if( !empty( $this->args['role'] ) ){
120 + $role_in_arg = get_role( $this->args['role'] );
121 + if( !empty( $role_in_arg->capabilities['manage_options'] ) || !empty( $role_in_arg->capabilities['remove_users'] ) ){
122 + if( !current_user_can( 'manage_options' ) || !current_user_can( 'remove_users' ) ){
123 + $this->args['role'] = get_option('default_role');
124 + echo apply_filters( 'wppb_register_pre_form_user_role_message', '<p class="alert" id="wppb_general_top_error_message">'.__( 'The role of the created user set to the default role. Only an administrator can register a user with the role assigned to this form.', 'profile-builder').'</p>' );
125 + }
126 + }
127 + }
75 128 }
76 129
77 130 function wppb_form_logic() {
78 131 if( $this->args['form_type'] == 'register' ){
@@ -79,9 +132,9 @@
79 132 $registration = apply_filters ( 'wppb_register_setting_override', get_option( 'users_can_register' ) );
80 133
81 134 if ( !is_user_logged_in() ){
82 135 if ( !$registration )
83 - echo apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Only an administrator can add new users.', 'profilebuilder').'</p>' );
136 + echo apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Only an administrator can add new users.', 'profile-builder').'</p>' );
84 137
85 138 elseif ( $registration ){
86 139 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '' ) );
87 140 }
@@ -89,12 +142,12 @@
89 142 }else{
90 143 $current_user_capability = apply_filters ( 'wppb_registration_user_capability', 'create_users' );
91 144
92 145 if ( current_user_can( $current_user_capability ) && $registration )
93 - $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Users can register themselves or you can manually create users here.', 'profilebuilder').'</p>' ) );
146 + $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Users can register themselves or you can manually create users here.', 'profile-builder'). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.__( 'This message is only visible by administrators', 'profile-builder' ).'"/>' . '</p>' ) );
94 147
95 148 elseif ( current_user_can( $current_user_capability ) && !$registration )
96 - $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Users cannot currently register themselves, but you can manually create users here.', 'profilebuilder').'</p>' ) );
149 + $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.__( 'Users cannot currently register themselves, but you can manually create users here.', 'profile-builder'). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.__( 'This message is only visible by administrators', 'profile-builder' ).'"/>' . '</p>' ) );
97 150
98 151 elseif ( !current_user_can( $current_user_capability ) ){
99 152 global $user_ID;
100 153
@@ -104,15 +157,23 @@
104 157 $wppb_general_settings = get_option( 'wppb_general_settings' );
105 158 if ( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) )
106 159 $display_name = $userdata->data->user_email;
107 160
108 - echo apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.sprintf( __( "You are currently logged in as %1s. You don't need another account. %2s", 'profilebuilder' ), '<a href="'.get_author_posts_url( $user_ID ).'" title="'.$display_name.'">'.$display_name.'</a>', '<a href="'.wp_logout_url( get_permalink() ).'" title="'.__( 'Log out of this account.', 'profilebuilder' ).'">'.__( 'Logout', 'profilebuilder' ).' &raquo;</a>' ).'</p>', $user_ID );
161 + if( empty( $this->args['logout_redirect_url'] ) ) {
162 + $this->args['logout_redirect_url'] = get_permalink();
163 + }
164 +
165 + // CHECK FOR REDIRECT
166 + $this->args['logout_redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], 'after_logout', $this->args['logout_redirect_url'], $userdata );
167 + $this->args['logout_redirect_url'] = apply_filters( 'wppb_after_logout_redirect_url', $this->args['logout_redirect_url'] );
168 +
169 + echo apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.sprintf( __( "You are currently logged in as %1s. You don't need another account. %2s", 'profile-builder' ), '<a href="'.get_author_posts_url( $user_ID ).'" title="'.$display_name.'">'.$display_name.'</a>', '<a href="'.wp_logout_url( $this->args['logout_redirect_url'] ).'" title="'.__( 'Log out of this account.', 'profile-builder' ).'">'.__( 'Logout', 'profile-builder' ).' &raquo;</a>' ).'</p>', $user_ID );
109 170 }
110 171 }
111 172
112 173 }elseif ( $this->args['form_type'] == 'edit_profile' ){
113 174 if ( !is_user_logged_in() )
114 - echo apply_filters( 'wppb_edit_profile_user_not_logged_in_message', '<p class="warning" id="wppb_edit_profile_user_not_logged_in_message">'.__( 'You must be logged in to edit your profile.', 'profilebuilder' ) .'</p>' );
175 + echo apply_filters( 'wppb_edit_profile_user_not_logged_in_message', '<p class="warning" id="wppb_edit_profile_user_not_logged_in_message">'.__( 'You must be logged in to edit your profile.', 'profile-builder' ) .'</p>' );
115 176
116 177 elseif ( is_user_logged_in() )
117 178 $this->wppb_form_content( apply_filters( 'wppb_edit_profile_logged_in_user_message', '' ) );
118 179
@@ -117,94 +178,130 @@
117 178 $this->wppb_form_content( apply_filters( 'wppb_edit_profile_logged_in_user_message', '' ) );
118 179
119 180 }
120 181 }
121 -
122 - function wppb_get_redirect(){
123 - if ( $this->args['login_after_register'] == 'Yes' )
124 - return $this->wppb_log_in_user();
125 - if ( $this->args['redirect_activated'] == 'No' || ( $this->args['form_type'] == 'edit_profile' && $this->args['form_name'] == 'unspecified' ) || ( $this->args['form_type'] == 'register' && $this->args['form_name'] == 'unspecified' && wppb_curpageurl() == $this->args['redirect_url'] ) )
126 - return '';
127 182
128 - /* if we don't have a preference on the form for redirect then if we have a custom redirect "after register redirect" option redirect to that if not don't do anything */
129 - if ( $this->args['redirect_activated'] == '-' ){
130 - if( !empty( $this->args['custom_redirect_after_register_url'] ) )
131 - $this->args['redirect_url'] = $this->args['custom_redirect_after_register_url'];
132 - else return '';
183 + // Function used to automatically log in a user after register if that option is set on yes in register form settings
184 + function wppb_log_in_user( $redirect, $redirect_old ) {
185 + if( is_user_logged_in() ) {
186 + return;
133 187 }
134 188
135 - $redirect_location = ( wppb_check_missing_http( $this->args['redirect_url'] ) ? 'http://'.$this->args['redirect_url'] : $this->args['redirect_url'] );
136 -
137 - $redirect_url = apply_filters( 'wppb_redirect_url', '<a href="'.$redirect_location.'">'.__( 'here', 'profilebuilder' ).'</a>' );
138 -
139 - return apply_filters ( 'wppb_redirect_message_before_returning', '<p class="redirect_message">'.sprintf( __( 'You will soon be redirected automatically. If you see this page for more than %1$d seconds, please click %2$s.%3$s', 'profilebuilder' ), $this->args['redirect_delay'], $redirect_url, '<meta http-equiv="Refresh" content="'.$this->args['redirect_delay'].';url='.$redirect_location.'" />' ).'</p>', $this->args );
140 - }
141 -
142 -
143 - function wppb_log_in_user(){
144 - if ( is_user_logged_in() )
145 - return;
146 -
147 189 $wppb_general_settings = get_option( 'wppb_general_settings' );
148 - if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) )
149 - return;
150 190
151 - if ( isset( $wppb_general_settings['adminApproval'] ) && ( $wppb_general_settings['adminApproval'] == 'yes' ) )
152 - return;
191 + if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ) {
192 + return $redirect_old;
193 + }
153 194
154 - if( !empty( $_POST['username'] ) )
155 - $username = trim( $_POST['username'] );
156 - $password = trim( $_POST['passw1'] );
195 + /* get user id */
196 + $user = get_user_by( 'email', trim( sanitize_email( $_POST['email'] ) ) );
197 + $nonce = wp_create_nonce( 'autologin-'. $user->ID .'-'. (int)( time() / 60 ) );
157 198
158 - if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
159 - $username = Wordpress_Creation_Kit_PB::wck_generate_slug( trim( $_POST['email'] ) );
199 + if ( isset( $wppb_general_settings['adminApproval'] ) && ( $wppb_general_settings['adminApproval'] == 'yes' ) ) {
200 + if( !empty( $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
201 + foreach ($user->roles as $role) {
202 + if ( in_array( $role, $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
203 + return $redirect_old;
204 + }
205 + }
206 + }
207 + else {
208 + return $redirect_old;
209 + }
160 210 }
161 211
162 - /* get user id */
163 - $user = get_user_by( 'login', $username );
164 - $nonce = wp_create_nonce( 'autologin-'.$user->ID.'-'.(int)( time() / 60 ) );
165 -
166 212 /* define redirect location */
167 - if ( $this->args['redirect_activated'] == 'No' ){
168 - $location = home_url();
169 - }else if ( $this->args['redirect_activated'] == '-' ){
170 - if( !empty( $this->args['custom_redirect_after_register_url'] ) )
171 - $location = $this->args['custom_redirect_after_register_url'];
172 - else
173 - $location = home_url();
213 + if( $this->args['redirect_activated'] == 'No' ) {
214 + if( isset( $_POST['_wp_http_referer'] ) ) {
215 + $redirect = esc_url_raw($_POST['_wp_http_referer']);
216 + } else {
217 + $redirect = home_url();
218 + }
174 219 }
175 - else{
176 - $location = ( wppb_check_missing_http( $this->args['redirect_url'] ) ? 'http://'.$this->args['redirect_url'] : $this->args['redirect_url'] );
220 +
221 + $redirect = apply_filters( 'wppb_login_after_reg_redirect_url', $redirect, $this );
222 +
223 + $redirect = add_query_arg( array( 'autologin' => 'true', 'uid' => $user->ID, '_wpnonce' => $nonce ), $redirect );
224 +
225 + // CHECK FOR REDIRECT
226 + if( $this->args['redirect_activated'] == 'No' || ( empty( $this->args['redirect_delay'] ) || $this->args['redirect_delay'] == '0' ) ) {
227 + $redirect = wppb_build_redirect( $redirect, 0, 'register', $this->args );
228 + } else {
229 + $redirect = wppb_build_redirect( $redirect, $this->args['redirect_delay'], 'register', $this->args );
230 + }
231 + return $redirect;
232 + }
233 +
234 + /**
235 + * Function to get redirect for Register and Edit Profile forms
236 + *
237 + * @param string $form_type - type of the form
238 + * @param string $redirect_type - type of the redirect
239 + * @param string $user - username or user email
240 + * @param string $user_role - user Role
241 + *
242 + * @return string $redirect
243 + */
244 + function wppb_get_redirect( $form_type, $redirect_type, $user, $user_role ) {
245 + $this->args['redirect_delay'] = apply_filters( 'wppb_'. $form_type .'_redirect_delay', $this->args['redirect_delay'], $user, $this->args );
246 + if( $this->args['redirect_activated'] == '-' ) {
247 + $this->args['redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], $redirect_type, $this->args['redirect_url'], $user, $user_role );
248 + $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
249 + } elseif( $this->args['redirect_activated'] == 'Yes' ) {
250 + $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
251 + } else {
252 + $redirect = '';
177 253 }
178 254
179 - $location .= "/?autologin=true&uid=$user->ID&_wpnonce=$nonce";
255 + return $redirect;
256 + }
180 257
181 - return "<script> window.location.replace('$location'); </script>";
182 - }
183 -
184 - function wppb_form_content( $message ){
258 + function wppb_form_content( $message ) {
185 259 $field_check_errors = array();
186 -
187 - if( isset( $_REQUEST['action'] ) ){
260 +
261 + if( isset( $_REQUEST['action'] ) && $_REQUEST['form_name'] == $this->args['form_name'] ) {
188 262 $field_check_errors = $this->wppb_test_required_form_values( $_REQUEST );
189 - if( empty( $field_check_errors ) ){
263 + if( empty( $field_check_errors ) ) {
264 +
265 + do_action( 'wppb_before_saving_form_values',$_REQUEST, $this->args );
266 +
190 267 // we only have a $user_id on default registration (no email confirmation, no multisite)
191 268 $user_id = $this->wppb_save_form_values( $_REQUEST );
192 -
193 - if ( ( 'POST' == $_SERVER['REQUEST_METHOD'] ) && ( $_POST['action'] == $this->args['form_type'] ) ){
194 269
195 - $form_message_tpl_start = apply_filters( 'wppb_form_message_tpl_start', '<p class="alert" id="wppb_form_success_message">');
196 - $form_message_tpl_end = apply_filters( 'wppb_form_message_tpl_end', '</p>');
270 + if( ( 'POST' == $_SERVER['REQUEST_METHOD'] ) && ( $_POST['action'] == $this->args['form_type'] ) ) {
197 271
198 - if( $this->args['form_type'] == 'register' ){
272 + $form_message_tpl_start = apply_filters( 'wppb_form_message_tpl_start', '<p class="alert" id="wppb_form_success_message">' );
273 + $form_message_tpl_end = apply_filters( 'wppb_form_message_tpl_end', '</p>' );
274 +
275 + if( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $_POST['custom_field_user_role'] ) ) {
276 + $user_role = sanitize_text_field($_POST['custom_field_user_role']);
277 + } elseif( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $this->args['role'] ) ) {
278 + $user_role = $this->args['role'];
279 + } else {
280 + $user_role = NULL;
281 + }
282 +
283 + if( isset( $_POST['username'] ) && ( trim( $_POST['username'] ) != '' ) ) {
284 + $account_name = sanitize_user( $_POST['username'] );
285 + } elseif( isset( $_POST['email'] ) && ( trim( $_POST['email'] ) != '' ) ) {
286 + $account_name = sanitize_email( $_POST['email'] );
287 + }else{
288 + /* we are in the edit form with no username or email field */
289 + $current_user = wp_get_current_user();
290 + if( !empty( $current_user ) )
291 + $account_name = $current_user->user_login;
292 + }
293 +
294 + if( $this->args['form_type'] == 'register' ) {
199 295 // ec = email confirmation setting
200 296 // aa = admin approval setting
201 297 $wppb_general_settings = get_option( 'wppb_general_settings', 'false' );
202 - if ( $wppb_general_settings ){
298 + if ( $wppb_general_settings ) {
203 299 if( !empty( $wppb_general_settings['emailConfirmation'] ) )
204 - $wppb_email_confirmation = $wppb_general_settings['emailConfirmation'];
300 + $wppb_email_confirmation = $wppb_general_settings['emailConfirmation'];
205 301 else
206 - $wppb_email_confirmation = 'no';
302 + $wppb_email_confirmation = 'no';
303 +
207 304 if( !empty( $wppb_general_settings['adminApproval'] ) )
208 305 $wppb_admin_approval = $wppb_general_settings['adminApproval'];
209 306 else
210 307 $wppb_admin_approval = 'no';
@@ -212,39 +309,47 @@
212 309 } else {
213 310 $account_management_settings = 'ec-no_aa-no';
214 311 }
215 312
216 - if ( isset( $_POST['username'] ) && ( trim( $_POST['username'] ) != '' ) ){
217 - $account_name = trim( $_POST['username'] );
218 - } elseif( isset( $_POST['email'] ) && ( trim( $_POST['email'] ) != '' ) ) {
219 - $account_name = trim( $_POST['email'] );
220 - }
221 -
222 - switch ( $account_management_settings ){
313 + switch( $account_management_settings ) {
223 314 case 'ec-no_aa-no':
224 - $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1s has been successfully created!", 'profilebuilder' ), $account_name ) );
315 + $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1s has been successfully created!", 'profile-builder' ), $account_name ), $account_name );
225 316 break;
226 317 case 'ec-yes_aa-no':
227 - $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profilebuilder' ), $account_name ) );
318 + $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name );
228 319 break;
229 320 case 'ec-no_aa-yes':
230 - $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, an administrator has to approve it. You will be notified via email.", 'profilebuilder' ), $account_name ) );
231 - break;
321 + if( current_user_can( 'delete_users' ) ) {
322 + $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1s has been successfully created!", 'profile-builder' ), $account_name ), $account_name );
323 + } else {
324 + $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, an administrator has to approve it. You will be notified via email.", 'profile-builder' ), $account_name ), $account_name );
325 + }
326 + break;
232 327 case 'ec-yes_aa-yes':
233 - $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profilebuilder' ), $account_name ) );
328 + $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name );
234 329 break;
235 330 }
236 - $redirect = apply_filters( 'wppb_register_redirect', $this->wppb_get_redirect() );
237 - echo $form_message_tpl_start . $wppb_register_success_message . $form_message_tpl_end . $redirect;
331 +
332 + // CHECK FOR REDIRECT
333 + $redirect = $this->wppb_get_redirect( 'register', 'after_registration', $account_name, $user_role );
334 +
335 + if( $this->args['login_after_register'] == 'Yes' ) {
336 + $redirect = $this->wppb_log_in_user( $this->args['redirect_url'], $redirect );
337 + }
338 +
339 + echo $form_message_tpl_start . $wppb_register_success_message . $form_message_tpl_end . $redirect;
238 340 //action hook after registration success
239 - do_action('wppb_register_success', $_REQUEST, $this->args['form_name'], $user_id);
341 + do_action( 'wppb_register_success', $_REQUEST, $this->args['form_name'], $user_id );
240 342 return;
241 - } elseif ( $this->args['form_type'] == 'edit_profile' ){
242 - $redirect = apply_filters( 'wppb_edit_profile_redirect', $this->wppb_get_redirect() );
243 - echo $form_message_tpl_start . apply_filters( 'wppb_edit_profile_success_message', __( 'Your profile has been successfully updated!', 'profilebuilder' ) ) . $form_message_tpl_end . $redirect;
244 - //action hook after edit profile success
245 - do_action('wppb_edit_profile_success', $_REQUEST, $this->args['form_name'], $user_id);
246 - if ( apply_filters( 'wppb_no_form_after_profile_update', false ) )
343 + } elseif( $this->args['form_type'] == 'edit_profile' ) {
344 + // CHECK FOR REDIRECT
345 + $redirect = $this->wppb_get_redirect( 'edit_profile', 'after_edit_profile', $account_name, $user_role );
346 +
347 + echo $form_message_tpl_start . apply_filters( 'wppb_edit_profile_success_message', __( 'Your profile has been successfully updated!', 'profile-builder' ) ) . $form_message_tpl_end . $redirect;
348 +
349 + //action hook after edit profile success
350 + do_action( 'wppb_edit_profile_success', $_REQUEST, $this->args['form_name'], $user_id );
351 + if( apply_filters( 'wppb_no_form_after_profile_update', false ) )
247 352 return;
248 353 }
249 354
250 355 }
@@ -249,75 +354,125 @@
249 354
250 355 }
251 356
252 357 }else
253 - echo $message.apply_filters( 'wppb_general_top_error_message', '<p id="wppb_general_top_error_message">'.__( 'There was an error in the submitted form', 'profilebuilder' ).'</p>' );
358 + echo $message.apply_filters( 'wppb_general_top_error_message', '<p id="wppb_general_top_error_message">'.__( 'There was an error in the submitted form', 'profile-builder' ).'</p>' );
254 359
255 360 }else
256 361 echo $message;
257 362
258 363 // use this action hook to add extra content before the register form
259 - do_action( 'wppb_before_'.$this->args['form_type'].'_fields' );
260 - ?>
261 - <form enctype="multipart/form-data" method="post" id="<?php if( $this->args['form_type'] == 'register' ) echo 'wppb-register-user'; else if( $this->args['form_type'] == 'edit_profile' ) echo 'wppb-edit-user' ?>" class="wppb-user-forms" action="<?php echo wppb_curpageurl(); ?>">
262 - <?php
263 - echo apply_filters( 'wppb_before_form_fields', '<ul>' );
264 - $this->wppb_output_form_fields( $_REQUEST, $field_check_errors );
265 - echo apply_filters( 'wppb_after_form_fields', '</ul>' );
266 -
267 - echo apply_filters( 'wppb_before_send_credentials_checkbox', '<ul>' );
364 + do_action( 'wppb_before_'.$this->args['form_type'].'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'] );
365 +
366 + $wppb_user_role_class = '';
367 + if( is_user_logged_in() ) {
368 + $wppb_user = wp_get_current_user();
369 +
370 + if( $wppb_user && isset( $wppb_user->roles ) ) {
371 + foreach( $wppb_user->roles as $wppb_user_role ) {
372 + $wppb_user_role_class .= ' wppb-user-role-'. $wppb_user_role;
373 + }
374 + }
375 + } else {
376 + $wppb_user_role_class = ' wppb-user-logged-out';
377 + }
378 + $wppb_user_role_class = apply_filters( 'wppb_user_role_form_class', $wppb_user_role_class );
379 +
380 + /* set up form id */
381 + $wppb_form_id = '';
382 + if( $this->args['form_type'] == 'register' )
383 + $wppb_form_id = 'wppb-register-user';
384 + elseif( $this->args['form_type'] == 'edit_profile' )
385 + $wppb_form_id = 'wppb-edit-user';
386 + if( isset($this->args['form_name']) && $this->args['form_name'] != "unspecified" )
387 + $wppb_form_id .= '-' . $this->args['form_name'];
388 +
389 + /* set up form class */
390 + $wppb_form_class = 'wppb-user-forms';
391 + if( $this->args['form_type'] == 'register' )
392 + $wppb_form_class .= ' wppb-register-user';
393 + elseif( $this->args['form_type'] == 'edit_profile' )
394 + $wppb_form_class .= ' wppb-edit-user';
395 + $wppb_form_class .= $wppb_user_role_class;
396 +
397 + ?>
398 + <form enctype="multipart/form-data" method="post" id="<?php echo apply_filters( 'wppb_form_id', $wppb_form_id, $this ); ?>" class="<?php echo apply_filters( 'wppb_form_class', $wppb_form_class, $this ); ?>" action="<?php echo apply_filters( 'wppb_form_action', '' ); ?>">
399 + <?php
400 + do_action( 'wppb_form_args_before_output', $this->args );
401 +
402 + echo apply_filters( 'wppb_before_form_fields', '<ul>', $this->args['form_type'], $this->args['ID'] );
403 + echo $this->wppb_output_form_fields( $_REQUEST, $field_check_errors, $this->args['form_fields'] );
404 + echo apply_filters( 'wppb_after_form_fields', '</ul>', $this->args['form_type'], $this->args['ID'] );
405 +
406 + echo apply_filters( 'wppb_before_send_credentials_checkbox', '<ul>', $this->args['form_type'], $this->args['ID'] );
268 407 $this->wppb_add_send_credentials_checkbox( $_REQUEST, $this->args['form_type'] );
269 - echo apply_filters( 'wppb_after_send_credentials_checkbox', '</ul>' );
408 + echo apply_filters( 'wppb_after_send_credentials_checkbox', '</ul>', $this->args['form_type'] );
409 +
410 + $wppb_form_submit_extra_attr = apply_filters( 'wppb_form_submit_extra_attr', '', $this->args['form_type'], $this->args['ID'] );
270 411 ?>
271 - <p class="form-submit">
272 - <?php
412 + <p class="form-submit" <?php echo $wppb_form_submit_extra_attr; ?> >
413 + <?php
273 414 if( $this->args['form_type'] == 'register' )
274 - $button_name = ( current_user_can( 'create_user' ) ? __( 'Add User', 'profilebuilder' ) : __( 'Register', 'profilebuilder' ) );
415 + $button_name = ( current_user_can( 'create_users' ) ? __( 'Add User', 'profile-builder' ) : __( 'Register', 'profile-builder' ) );
275 416
276 417 elseif( $this->args['form_type'] == 'edit_profile' )
277 - $button_name = __( 'Update', 'profilebuilder' );
278 - ?>
279 - <input name="<?php echo $this->args['form_type']; ?>" type="submit" id="<?php echo $this->args['form_type']; ?>" class="submit button" value="<?php echo apply_filters( 'wppb_'. $this->args['form_type'] .'_button_name', $button_name ); ?>" />
418 + $button_name = __( 'Update', 'profile-builder' );
419 + ?>
420 + <?php do_action( 'wppb_form_before_submit_button', $this->args ); ?>
421 + <input name="<?php echo $this->args['form_type']; ?>" type="submit" id="<?php echo $this->args['form_type']; ?>" class="<?php echo apply_filters( 'wppb_'. $this->args['form_type'] .'_submit_class', "submit button" );?>" value="<?php echo apply_filters( 'wppb_'. $this->args['form_type'] .'_button_name', $button_name ); ?>" <?php echo apply_filters( 'wppb_form_submit_button_extra_attributes', '', $this->args['form_type'] );?>/>
422 + <?php do_action( 'wppb_form_after_submit_button', $this->args ); ?>
280 423 <input name="action" type="hidden" id="action" value="<?php echo $this->args['form_type']; ?>" />
281 424 <input name="form_name" type="hidden" id="form_name" value="<?php echo $this->args['form_name']; ?>" />
425 + <?php
426 + $wppb_module_settings = get_option( 'wppb_module_settings' );
427 +
428 + if( isset( $wppb_module_settings['wppb_customRedirect'] ) && $wppb_module_settings['wppb_customRedirect'] == 'show' ) {
429 + if( isset( $_POST['wppb_referer_url'] ) )
430 + $referer = $_POST['wppb_referer_url'];
431 + elseif( isset( $_SERVER['HTTP_REFERER'] ) )
432 + $referer = $_SERVER['HTTP_REFERER'];
433 + else
434 + $referer = '';
435 +
436 + echo '<input type="hidden" name="wppb_referer_url" value="'.esc_url( $referer ).'"/>';
437 + }
438 + ?>
282 439 </p><!-- .form-submit -->
283 440 <?php wp_nonce_field( 'verify_form_submission', $this->args['form_type'].'_nonce_field' ); ?>
284 441 </form>
285 442 <?php
286 443 // use this action hook to add extra content after the register form
287 - do_action( 'wppb_after_'. $this->args['form_type'] .'_fields' );
444 + do_action( 'wppb_after_'. $this->args['form_type'] .'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'] );
288 445
289 446 }
290 447
291 - function wppb_output_form_fields( $global_request, $field_check_errors ){
292 -
448 + function wppb_output_form_fields( $global_request, $field_check_errors, $form_fields, $called_from = NULL ){
293 449 $output_fields = '';
294 -
295 - if( !empty( $this->args['form_fields'] ) ){
296 - foreach( $this->args['form_fields'] as $field ){
450 +
451 + if( !empty( $form_fields ) ){
452 + $output_fields .= apply_filters( 'wppb_output_before_first_form_field', '', $this->args['ID'], $this->args['form_type'], $form_fields, $called_from );
453 + foreach( $form_fields as $field ){
297 454 $error_var = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? ' wppb-field-error' : '' );
298 455 $specific_message = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? $field_check_errors[$field['id']] : '' );
299 -
300 - $output_fields .= apply_filters( 'wppb_output_before_form_field', '<li class="wppb-form-field wppb-'. Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ) .$error_var.'" id="wppb-form-element-'. $field['id'] .'">', $field, $error_var );
301 - $output_fields .= apply_filters( 'wppb_output_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $this->args['form_type'], $field, get_current_user_id(), $field_check_errors, $global_request );
456 +
457 + $display_field = apply_filters( 'wppb_output_display_form_field', true, $field, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
458 +
459 + if( $display_field == false )
460 + continue;
461 +
462 + $css_class = apply_filters( 'wppb_field_css_class', 'wppb-form-field wppb-'. Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ) .$error_var, $field, $error_var );
463 + $output_fields .= apply_filters( 'wppb_output_before_form_field', '<li class="'. $css_class .'" id="wppb-form-element-'. $field['id'] .'">', $field, $error_var, $this->args['role'] );
464 + $output_fields .= apply_filters( 'wppb_output_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $this->args['form_type'], $field, $this->wppb_get_desired_user_id(), $field_check_errors, $global_request, $this->args['role'], $this );
302 465 $output_fields .= apply_filters( 'wppb_output_specific_error_message', $specific_message );
303 - $output_fields .= apply_filters( 'wppb_output_after_form_field', '</li>', $field );
466 + $output_fields .= apply_filters( 'wppb_output_after_form_field', '</li>', $field, $this->args['ID'], $this->args['form_type'], $called_from );
304 467 }
468 +
469 + $output_fields .= apply_filters( 'wppb_output_after_last_form_field', '', $this->args['ID'], $this->args['form_type'], $called_from );
305 470 }
306 -
307 - echo apply_filters( 'wppb_output_fields_filter', $output_fields );
471 +
472 + return apply_filters( 'wppb_output_fields_filter', $output_fields );
308 473 }
309 -
310 - function wppb_print_script(){
311 - if( $this->args['form_type'] == 'edit_profile' ){
312 - wp_register_script( 'wppb-edit-profile-scripts', WPPB_PLUGIN_URL . 'assets/js/jquery-edit-profile.js', array( 'jquery' ), PROFILE_BUILDER_VERSION );
313 -
314 - $translation_array = array( 'avatar' => __( 'The avatar was successfully deleted!', 'profilebuilder' ), 'attachment' => __( 'The following attachment was successfully deleted:', 'profilebuilder' ) );
315 - wp_localize_script( 'wppb-edit-profile-scripts', 'ep', $translation_array );
316 -
317 - wp_print_scripts( 'wppb-edit-profile-scripts' );
318 - }
319 - }
474 +
320 475
321 476 function wppb_add_send_credentials_checkbox ( $request_data, $form ){
322 477 if ( $form == 'edit_profile' )
323 478 echo '';
@@ -322,17 +477,12 @@
322 477 if ( $form == 'edit_profile' )
323 478 echo '';
324 479
325 480 else{
326 - $checkbox = apply_filters( 'wppb_send_credentials_checkbox_logic', '<li class="wppb-form-field wppb-send-credentials-checkbox"><label for="send_credentials_via_email"><input id="send_credentials_via_email" type="checkbox" name="send_credentials_via_email" value="sending"'.( ( isset( $request_data['send_credentials_via_email'] ) && ( $request_data['send_credentials_via_email'] == 'sending' ) ) ? ' checked' : '' ).'/>'.__( 'Send these credentials via email.', 'profilebuilder').'</label></li>', $request_data, $form );
327 -
328 - if ( !is_multisite() ){
329 - $wppb_general_settings = get_option( 'wppb_general_settings' );
330 -
331 - echo ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ? '' : $checkbox );
332 -
333 - }else
334 - echo '';
481 + $checkbox = apply_filters( 'wppb_send_credentials_checkbox_logic', '<li class="wppb-form-field wppb-send-credentials-checkbox"><label for="send_credentials_via_email"><input id="send_credentials_via_email" type="checkbox" name="send_credentials_via_email" value="sending"'.( ( isset( $request_data['send_credentials_via_email'] ) && ( $request_data['send_credentials_via_email'] == 'sending' ) ) ? ' checked' : '' ).'/>'.__( 'Send these credentials via email.', 'profile-builder').'</label></li>', $request_data, $form );
482 +
483 + $wppb_general_settings = get_option( 'wppb_general_settings' );
484 + echo ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ? '' : $checkbox );
335 485 }
336 486 }
337 487
338 488
@@ -337,59 +487,42 @@
337 487
338 488
339 489 function wppb_test_required_form_values( $global_request ){
340 490 $output_field_errors = array();
341 -
342 - if( !empty( $this->args['form_fields'] ) ){
343 - foreach( $this->args['form_fields'] as $field ){
344 - $error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $global_request, $this->args['form_type'] );
345 -
491 + $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'global_request' => $global_request, 'context' => 'validate_frontend', 'global_request' => $global_request, 'form_type' => $this->args['form_type'], 'role' => $this->args['role'], 'user_id' => $this->wppb_get_desired_user_id() ) );
492 + if( !empty( $form_fields ) ){
493 + foreach( $form_fields as $field ){
494 + $error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $global_request, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
495 +
346 496 if( !empty( $error_for_field ) )
347 497 $output_field_errors[$field['id']] = '<span class="wppb-form-error">' . $error_for_field . '</span>';
348 498 }
349 499 }
350 -
351 - return apply_filters( 'wppb_output_field_errors_filter', $output_field_errors );
500 +
501 + return apply_filters( 'wppb_output_field_errors_filter', $output_field_errors, $this->args['form_fields'], $global_request, $this->args['form_type'] );
352 502 }
353 503
354 504 function wppb_save_form_values( $global_request ){
355 - $user_id = get_current_user_id();
505 + $user_id = $this->wppb_get_desired_user_id();
356 506 $userdata = apply_filters( 'wppb_build_userdata', array(), $global_request );
357 507 $new_user_signup = false;
358 508
359 509 $wppb_general_settings = get_option( 'wppb_general_settings' );
360 - if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
361 - $userdata['user_login'] = Wordpress_Creation_Kit_PB::wck_generate_slug( trim( $userdata['user_email'] ) );
362 - }
510 +
511 + if( $this->args['form_type'] == 'register' ){
363 512
364 - if( $this->args['form_type'] == 'register' ){
365 - if ( !is_multisite() ){
366 - if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ){
367 - $new_user_signup = true;
368 - $multisite_message = true;
369 - $userdata = $this->wppb_add_custom_field_values( $global_request, $userdata, $this->args['form_fields'] );
370 - $userdata['role'] = $this->args['role'];
371 - $userdata['user_pass'] = base64_encode( $userdata['user_pass'] );
372 - wppb_signup_user( $userdata['user_login'], $userdata['user_email'], $userdata );
373 -
374 - }else{
375 - $userdata['role'] = $this->args['role'];
376 - $userdata = wp_unslash( $userdata );
377 - $user_id = wp_insert_user( $userdata );
378 - }
379 -
380 - }else{
381 - $new_user_signup = true;
382 - $multisite_message = true;
383 - $userdata = $this->wppb_add_custom_field_values( $global_request, $userdata, $this->args['form_fields'] );
384 - $userdata['role'] = $this->args['role'];
385 - $userdata['user_pass'] = base64_encode( $userdata['user_pass'] );
386 - $userdata = wp_unslash( $userdata );
387 - wppb_signup_user( $userdata['user_login'], $userdata['user_email'], $userdata );
388 - }
389 -
513 + $result = $this->wppb_register_user( $global_request, $userdata );
514 + $user_id = $result['user_id'];
515 + $userdata = $result['userdata'];
516 + $new_user_signup = $result['new_user_signup'];
517 +
390 518 }elseif( $this->args['form_type'] == 'edit_profile' ){
391 - $userdata['ID'] = get_current_user_id();
519 + if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
520 + $user_info = get_userdata( $user_id );
521 + $userdata['user_login'] = $user_info->user_login;
522 + }
523 +
524 + $userdata['ID'] = $this->wppb_get_desired_user_id();
392 525 $userdata = wp_unslash( $userdata );
393 526 /* if the user changes his password then we can't send it to the wp_update_user() function or
394 527 the user will be logged out and won't be logged in again because we call wp_update_user() after
395 528 the headers were sent( in the content as a shortcode ) */
@@ -395,8 +528,20 @@
395 528 the headers were sent( in the content as a shortcode ) */
396 529 if( isset( $userdata['user_pass'] ) && !empty( $userdata['user_pass'] ) ){
397 530 unset($userdata['user_pass']);
398 531 }
532 +
533 + if( current_user_can( 'manage_options' ) && isset( $userdata['role'] ) && is_array( $userdata['role'] ) ) {
534 + $user_data = get_userdata( $user_id );
535 + $user_data->remove_all_caps();
536 +
537 + foreach( $userdata['role'] as $role ) {
538 + $user_data->add_role( $role );
539 + }
540 +
541 + unset( $userdata['role'] );
542 + }
543 +
399 544 wp_update_user( $userdata );
400 545 }
401 546
402 547 if( !empty( $this->args['form_fields'] ) && !$new_user_signup ){
@@ -402,9 +547,9 @@
402 547 if( !empty( $this->args['form_fields'] ) && !$new_user_signup ){
403 548 foreach( $this->args['form_fields'] as $field ){
404 549 do_action( 'wppb_save_form_field', $field, $user_id, $global_request, $this->args['form_type'] );
405 550 }
406 -
551 +
407 552 if ( $this->args['form_type'] == 'register' ){
408 553 if ( !is_wp_error( $user_id ) ){
409 554 $wppb_general_settings = get_option( 'wppb_general_settings' );
410 555 if( isset( $global_request['send_credentials_via_email'] ) && ( $global_request['send_credentials_via_email'] == 'sending' ) )
@@ -410,18 +555,71 @@
410 555 if( isset( $global_request['send_credentials_via_email'] ) && ( $global_request['send_credentials_via_email'] == 'sending' ) )
411 556 $send_credentials_via_email = 'sending';
412 557 else
413 558 $send_credentials_via_email = '';
414 - wppb_notify_user_registration_email( get_bloginfo( 'name' ), ( isset( $global_request['username'] ) ? trim( $global_request['username'] ) : trim( $global_request['email'] ) ), trim( $global_request['email'] ), $send_credentials_via_email, trim( $global_request['passw1'] ), ( isset( $wppb_general_settings['adminApproval'] ) ? $wppb_general_settings['adminApproval'] : 'no' ) );
559 + wppb_notify_user_registration_email( get_bloginfo( 'name' ), ( isset( $userdata['user_login'] ) ? trim( $userdata['user_login'] ) : trim( $userdata['user_email'] ) ), trim( $userdata['user_email'] ), $send_credentials_via_email, trim( $userdata['user_pass'] ), ( isset( $wppb_general_settings['adminApproval'] ) ? $wppb_general_settings['adminApproval'] : 'no' ) );
415 560 }
416 561 }
417 562 }
418 563 return $user_id;
419 564 }
420 -
421 - function wppb_add_custom_field_values( $global_request, $meta, $form_properties ){
422 - if( !empty( $this->args['form_fields'] ) ){
423 - foreach( $this->args['form_fields'] as $field ){
565 +
566 + function wppb_register_user( $global_request, $userdata ){
567 + $wppb_module_settings = get_option( 'wppb_module_settings' );
568 + $wppb_general_settings = get_option( 'wppb_general_settings' );
569 + $user_id = null;
570 + $new_user_signup = false;
571 +
572 + if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
573 + $userdata['user_login'] = apply_filters( 'wppb_generated_random_username', Wordpress_Creation_Kit_PB::wck_generate_slug( trim( $userdata['user_email'] ) ), $userdata['user_email'] );
574 + }
575 +
576 + /* filter so we can bypass Email Confirmation on register */
577 + $wppb_general_settings['emailConfirmation'] = apply_filters( 'wppb_email_confirmation_on_register', $wppb_general_settings['emailConfirmation'], $global_request );
578 +
579 + if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ){
580 + $new_user_signup = true;
581 +
582 + $userdata = $this->wppb_add_custom_field_values( $global_request, $userdata, $this->args['form_fields'] );
583 +
584 + if( ! isset( $userdata['role'] ) ) {
585 + $userdata['role'] = $this->args['role'];
586 + }
587 +
588 + $userdata['user_pass'] = wp_hash_password( $userdata['user_pass'] );
589 +
590 + if( is_multisite() ){
591 + /* since version 2.0.7 add this meta so we know on what blog the user registered */
592 + $userdata['registered_for_blog_id'] = get_current_blog_id();
593 + $userdata = wp_unslash( $userdata );
594 + }
595 +
596 + wppb_signup_user( $userdata['user_login'], $userdata['user_email'], $userdata );
597 + }else{
598 + if( ! isset( $userdata['role'] ) ) {
599 + $userdata['role'] = $this->args['role'];
600 + }
601 +
602 + $userdata = wp_unslash( $userdata );
603 +
604 + // change User Registered date and time according to timezone selected in WordPress settings
605 + $wppb_get_date = wppb_get_date_by_timezone();
606 +
607 + if( isset( $wppb_get_date ) ) {
608 + $userdata['user_registered'] = $wppb_get_date;
609 + }
610 +
611 + // insert user to database
612 + $user_id = wp_insert_user( $userdata );
613 + }
614 +
615 + return array( 'userdata' => $userdata, 'user_id' => $user_id, 'new_user_signup' => $new_user_signup );
616 + }
617 +
618 + function wppb_add_custom_field_values( $global_request, $meta, $form_properties ){
619 + $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'meta' => $meta, 'global_request' => $global_request, 'context' => 'user_signup' ) );
620 + if( !empty( $form_fields ) ){
621 + foreach( $form_fields as $field ){
424 622 if( !empty( $field['meta-name'] ) ){
425 623 $posted_value = ( !empty( $global_request[$field['meta-name']] ) ? $global_request[$field['meta-name']] : '' );
426 624 $meta[$field['meta-name']] = apply_filters( 'wppb_add_to_user_signup_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
427 625 }
@@ -426,12 +624,75 @@
426 624 $meta[$field['meta-name']] = apply_filters( 'wppb_add_to_user_signup_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
427 625 }
428 626 }
429 627 }
430 -
431 - return $meta;
628 +
629 + return apply_filters( 'wppb_add_to_user_signup_form_meta', $meta, $global_request, $this->args['role'] );
630 + }
631 +
632 + /**
633 + * Function that returns the id for the current logged in user or for edit profile forms for administrator it can return the id of a selected user
634 + */
635 + function wppb_get_desired_user_id(){
636 + if( $this->args['form_type'] == 'edit_profile' ){
637 + //only admins
638 + if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) ) {
639 + if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){
640 + return absint( $_GET['edit_user'] );
641 + }
642 + }
643 + }
644 +
645 + return get_current_user_id();
432 646 }
433 647
648 + function wppb_edit_profile_select_user_to_edit(){
649 +
650 + $display_edit_users_dropdown = apply_filters( 'wppb_display_edit_other_users_dropdown', true );
651 + if( !$display_edit_users_dropdown )
652 + return;
653 +
654 + /* add a hard cap: if we have more than 5000 users don't display the dropdown for performance considerations */
655 + $user_count = count_users();
656 + if( $user_count['total_users'] > apply_filters( 'wppb_edit_other_users_count_limit', 5000 ) )
657 + return;
658 +
659 + if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) )
660 + $selected = absint( $_GET['edit_user'] );
661 + else
662 + $selected = get_current_user_id();
663 +
664 + $query_args['fields'] = array( 'ID', 'user_login', 'display_name' );
665 + $query_args['role'] = apply_filters( 'wppb_edit_profile_user_dropdown_role', '' );
666 + $users = get_users( apply_filters( 'wppb_edit_other_users_dropdown_query_args', $query_args ) );
667 + if( !empty( $users ) ) {
668 +
669 + /* turn it in a select2 */
670 + wp_enqueue_script( 'wppb_select2_js', WPPB_PLUGIN_URL .'assets/js/select2/select2.min.js', array( 'jquery' ), PROFILE_BUILDER_VERSION );
671 + wp_enqueue_style( 'wppb_select2_css', WPPB_PLUGIN_URL .'assets/css/select2/select2.min.css', array(), PROFILE_BUILDER_VERSION );
672 + ?>
673 + <form method="GET" action="" id="select_user_to_edit_form">
674 + <p class="wppb-form-field">
675 + <label for="edit_user"><?php _e('User to edit:', 'profile-builder') ?></label>
676 + <select id="wppb-user-to-edit" class="wppb-user-to-edit" name="edit_user">
677 + <?php
678 + foreach( $users as $user ){
679 + ?>
680 + <option value="<?php echo $user->ID; ?>" <?php selected( $selected, $user->ID ); ?>><?php echo $user->display_name; ?></option>
681 + <?php
682 + }
683 + ?>
684 + </select>
685 + </p>
686 + <script type="text/javascript">jQuery('#wppb-user-to-edit').change(function () {
687 + window.location.href = "<?php echo htmlspecialchars_decode( esc_js( esc_url_raw( add_query_arg( array( 'edit_user' => '=' ) ) ) ) ) ?>" + jQuery(this).val();
688 + });
689 + jQuery(function(){jQuery('.wppb-user-to-edit').select2(); })</script>
690 + </form>
691 + <?php
692 + }
693 + }
694 +
434 695 /**
435 696 * Handle toString method
436 697 *
437 698 * @since 2.0
@@ -438,12 +699,16 @@
438 699 *
439 700 * @return string $html html for the form.
440 701 */
441 702 public function __toString() {
442 - ob_start();
443 - $this->wppb_form_logic();
444 - $html = ob_get_clean();
445 - return "{$html}";
703 + try {
704 + ob_start();
705 + $this->wppb_form_logic();
706 + $html = ob_get_clean();
707 + return "{$html}";
708 + } catch (Exception $exception) {
709 + return __( 'Something went wrong. Please try again!', 'profile-builder');
710 + }
446 711 }
447 712 }
448 713
449 714 /* set action for automatic login after registration */
@@ -449,9 +714,9 @@
449 714 /* set action for automatic login after registration */
450 715 add_action( 'init', 'wppb_autologin_after_registration' );
451 716 function wppb_autologin_after_registration(){
452 717 if( isset( $_GET['autologin'] ) && isset( $_GET['uid'] ) ){
453 - $uid = $_GET['uid'];
718 + $uid = absint( $_GET['uid'] );
454 719 $nonce = $_REQUEST['_wpnonce'];
455 720
456 721 $arr_params = array( 'autologin', 'uid', '_wpnonce' );
457 722 $current_page_url = remove_query_arg( $arr_params, wppb_curpageurl() );
@@ -464,5 +729,5 @@
464 729 wp_redirect( $current_page_url );
465 730 exit;
466 731 }
467 732 }
468 -}
733 +}