PluginProbe
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor / 3.15.9
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor v3.15.9
4.0.2 4.0.1 4.0.0 3.16.6 3.16.5 3.16.4 3.16.3 3.16.2 3.16.1 3.16.0 3.15.9 3.9.9 3.9.5 3.9.6 3.9.7 3.9.8 1.1.7 1.1.8 1.1.9 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 All 340 releases
profile-builder / front-end / edit-profile.php

edit-profile.php in User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 3.15.9, at front-end/edit-profile.php

106 lines 6.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly
3
4 /*
5 wp_update_user only attempts to clear and reset cookies if it's updating the password.
6 The php function setcookie(), used in both the cookie-clearing and cookie-resetting functions,
7 adds to the page headers and therefore must be called within the first php tag on the page,
8 and before the WordPress get_header() function. Since wp_update_user needs this, it must be at the beginning of the page as well.
9 */
10 /* set action to login user after password changed in edit profile */
11 add_action( 'init', 'wppb_autologin_after_password_changed' );
12 function wppb_autologin_after_password_changed(){
13 if( isset( $_POST['action'] ) && $_POST['action'] === 'edit_profile' ){
14 if( isset( $_POST['passw1'] ) && !empty( $_POST['passw1'] ) && !empty( $_POST['form_name'] ) && isset( $_POST['edit_profile_'. $_POST['form_name'] .'_nonce_field'] ) && wp_verify_nonce( sanitize_text_field( $_POST['edit_profile_'. $_POST['form_name'] .'_nonce_field'] ), 'wppb_verify_form_submission' ) ){
15
16 /* all the error checking filters are defined in each field file so we need them here */
17 if ( file_exists ( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' ) )
18 require_once( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' );
19
20 if ( defined( 'WPPB_PAID_PLUGIN_DIR' ) && file_exists ( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ) )
21 require_once( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' );
22
23 /* we get the form_name through $_POST so we can apply correctly the filter so we generate the correct fields in the current form */
24 $form_fields = apply_filters( 'wppb_change_form_fields', get_option( 'wppb_manage_fields' ), array( 'form_type'=> 'edit_profile', 'form_fields' => array(), 'form_name' => sanitize_text_field( $_POST['form_name'] ), 'role' => '', 'ID' => Profile_Builder_Form_Creator::wppb_get_form_id_from_form_name( sanitize_text_field( $_POST['form_name'] ), 'edit_profile' ), 'context' => 'edit_profile_auto_login_after_password_change' ) );
25 if( !empty( $form_fields ) ){
26
27 $edited_user_id = get_current_user_id();
28 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) ) {
29 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){
30 $edited_user_id = absint( $_GET['edit_user'] );
31 }
32 }
33
34 /* check for errors in the form through the filters */
35 $output_field_errors = array();
36 foreach( $form_fields as $field ){
37 //this is not perfect because we don't know the role attribute for the form here so we send it as '' in the filter, but as of v 2.9.0 it is not needed anywhere so we're good
38 $error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $_POST, 'edit_profile', '', $edited_user_id );
39 if( !empty( $error_for_field ) )
40 $output_field_errors[$field['id']] = '<span class="wppb-form-error">' . $error_for_field . '</span>';
41 }
42
43 /* if we have no errors change the password */
44 if( empty( $output_field_errors ) ) {
45
46 $user_id = get_current_user_id();
47 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) ) {
48 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){
49 $user_id = absint( $_GET['edit_user'] );
50 }
51 }
52
53 if( !isset( $_GET['edit_user'] ) ) {
54 // Parse the logged-in cookie before clearing it; wp_parse_auth_cookie() can return false when no cookie exists.
55 $logged_in_cookie = wp_parse_auth_cookie('', 'logged_in');
56 /** This filter is documented in wp-includes/pluggable.php */
57 $default_cookie_life = apply_filters('auth_cookie_expiration', (2 * DAY_IN_SECONDS), $user_id, false);
58 $remember = false;
59 if ( is_array( $logged_in_cookie ) && isset( $logged_in_cookie['expiration'] ) ) {
60 // If expiration is greater than the default, the user checked 'Remember Me' when they logged in.
61 $remember = ( ( $logged_in_cookie['expiration'] - time() ) > $default_cookie_life );
62 }
63
64 wp_clear_auth_cookie();
65 /* set the new password for the user */
66 wp_set_password($_POST['passw1'], $user_id);//phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
67
68 wp_set_auth_cookie($user_id, $remember, '', wp_get_session_token() );
69 }
70 else{
71 wp_set_password($_POST['passw1'], $user_id); //phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
72 do_action( 'wppb_edit_profile_password_changed', $user_id );
73 }
74
75 /* log out of other sessions or all sessions if the admin is editing the profile */
76 $sessions = WP_Session_Tokens::get_instance( $user_id );
77 if ( $user_id === get_current_user_id() ) {
78 $sessions->destroy_others( wp_get_session_token() );
79 } else {
80 $sessions->destroy_all();
81 }
82
83 }
84 }
85 }
86 }
87 }
88
89
90 function wppb_front_end_profile_info( $atts ){
91
92 $atts = shortcode_atts( array(
93 'form_name' => 'unspecified',
94 'redirect_url' => '',
95 'redirect_priority' => 'normal',
96 'ajax' => false,
97 'admin_edit_roles' => ''
98 ), $atts, 'wppb-edit-profile' );
99
100 $form = new Profile_Builder_Form_Creator(
101 array( 'form_type' => 'edit_profile', 'form_name' => $atts['form_name'], 'redirect_url' => $atts['redirect_url'], 'redirect_priority' => $atts['redirect_priority'], 'ajax' => $atts['ajax'], 'admin_edit_roles' => $atts['admin_edit_roles'] )
102 );
103
104 return $form;
105 }
106