| 1 |
<?php |
| 2 |
if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly |
| 3 |
|
| 4 |
/* |
| 5 |
wp_update_user only attempts to clear and reset cookies if it's updating the password. |
| 6 |
The php function setcookie(), used in both the cookie-clearing and cookie-resetting functions, |
| 7 |
adds to the page headers and therefore must be called within the first php tag on the page, |
| 8 |
and before the WordPress get_header() function. Since wp_update_user needs this, it must be at the beginning of the page as well. |
| 9 |
*/ |
| 10 |
/* set action to login user after password changed in edit profile */ |
| 11 |
add_action( 'init', 'wppb_autologin_after_password_changed' ); |
| 12 |
function wppb_autologin_after_password_changed(){ |
| 13 |
if( isset( $_POST['action'] ) && $_POST['action'] === 'edit_profile' ){ |
| 14 |
if( isset( $_POST['passw1'] ) && !empty( $_POST['passw1'] ) && !empty( $_POST['form_name'] ) && isset( $_POST['edit_profile_'. $_POST['form_name'] .'_nonce_field'] ) && wp_verify_nonce( sanitize_text_field( $_POST['edit_profile_'. $_POST['form_name'] .'_nonce_field'] ), 'wppb_verify_form_submission' ) ){ |
| 15 |
|
| 16 |
/* all the error checking filters are defined in each field file so we need them here */ |
| 17 |
if ( file_exists ( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' ) ) |
| 18 |
require_once( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' ); |
| 19 |
|
| 20 |
if ( defined( 'WPPB_PAID_PLUGIN_DIR' ) && file_exists ( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ) ) |
| 21 |
require_once( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ); |
| 22 |
|
| 23 |
/* we get the form_name through $_POST so we can apply correctly the filter so we generate the correct fields in the current form */ |
| 24 |
$form_fields = apply_filters( 'wppb_change_form_fields', get_option( 'wppb_manage_fields' ), array( 'form_type'=> 'edit_profile', 'form_fields' => array(), 'form_name' => sanitize_text_field( $_POST['form_name'] ), 'role' => '', 'ID' => Profile_Builder_Form_Creator::wppb_get_form_id_from_form_name( sanitize_text_field( $_POST['form_name'] ), 'edit_profile' ), 'context' => 'edit_profile_auto_login_after_password_change' ) ); |
| 25 |
if( !empty( $form_fields ) ){ |
| 26 |
|
| 27 |
$edited_user_id = get_current_user_id(); |
| 28 |
if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) ) { |
| 29 |
if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){ |
| 30 |
$edited_user_id = absint( $_GET['edit_user'] ); |
| 31 |
} |
| 32 |
} |
| 33 |
|
| 34 |
/* check for errors in the form through the filters */ |
| 35 |
$output_field_errors = array(); |
| 36 |
foreach( $form_fields as $field ){ |
| 37 |
//this is not perfect because we don't know the role attribute for the form here so we send it as '' in the filter, but as of v 2.9.0 it is not needed anywhere so we're good |
| 38 |
$error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $_POST, 'edit_profile', '', $edited_user_id ); |
| 39 |
if( !empty( $error_for_field ) ) |
| 40 |
$output_field_errors[$field['id']] = '<span class="wppb-form-error">' . $error_for_field . '</span>'; |
| 41 |
} |
| 42 |
|
| 43 |
/* if we have no errors change the password */ |
| 44 |
if( empty( $output_field_errors ) ) { |
| 45 |
|
| 46 |
$user_id = get_current_user_id(); |
| 47 |
if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && current_user_can( 'manage_network' ) ) ) { |
| 48 |
if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){ |
| 49 |
$user_id = absint( $_GET['edit_user'] ); |
| 50 |
} |
| 51 |
} |
| 52 |
|
| 53 |
if( !isset( $_GET['edit_user'] ) ) { |
| 54 |
// Parse the logged-in cookie before clearing it; wp_parse_auth_cookie() can return false when no cookie exists. |
| 55 |
$logged_in_cookie = wp_parse_auth_cookie('', 'logged_in'); |
| 56 |
/** This filter is documented in wp-includes/pluggable.php */ |
| 57 |
$default_cookie_life = apply_filters('auth_cookie_expiration', (2 * DAY_IN_SECONDS), $user_id, false); |
| 58 |
$remember = false; |
| 59 |
if ( is_array( $logged_in_cookie ) && isset( $logged_in_cookie['expiration'] ) ) { |
| 60 |
// If expiration is greater than the default, the user checked 'Remember Me' when they logged in. |
| 61 |
$remember = ( ( $logged_in_cookie['expiration'] - time() ) > $default_cookie_life ); |
| 62 |
} |
| 63 |
|
| 64 |
wp_clear_auth_cookie(); |
| 65 |
/* set the new password for the user */ |
| 66 |
wp_set_password($_POST['passw1'], $user_id);//phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized |
| 67 |
|
| 68 |
wp_set_auth_cookie($user_id, $remember, '', wp_get_session_token() ); |
| 69 |
} |
| 70 |
else{ |
| 71 |
wp_set_password($_POST['passw1'], $user_id); //phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized |
| 72 |
do_action( 'wppb_edit_profile_password_changed', $user_id ); |
| 73 |
} |
| 74 |
|
| 75 |
/* log out of other sessions or all sessions if the admin is editing the profile */ |
| 76 |
$sessions = WP_Session_Tokens::get_instance( $user_id ); |
| 77 |
if ( $user_id === get_current_user_id() ) { |
| 78 |
$sessions->destroy_others( wp_get_session_token() ); |
| 79 |
} else { |
| 80 |
$sessions->destroy_all(); |
| 81 |
} |
| 82 |
|
| 83 |
} |
| 84 |
} |
| 85 |
} |
| 86 |
} |
| 87 |
} |
| 88 |
|
| 89 |
|
| 90 |
function wppb_front_end_profile_info( $atts ){ |
| 91 |
|
| 92 |
$atts = shortcode_atts( array( |
| 93 |
'form_name' => 'unspecified', |
| 94 |
'redirect_url' => '', |
| 95 |
'redirect_priority' => 'normal', |
| 96 |
'ajax' => false, |
| 97 |
'admin_edit_roles' => '' |
| 98 |
), $atts, 'wppb-edit-profile' ); |
| 99 |
|
| 100 |
$form = new Profile_Builder_Form_Creator( |
| 101 |
array( 'form_type' => 'edit_profile', 'form_name' => $atts['form_name'], 'redirect_url' => $atts['redirect_url'], 'redirect_priority' => $atts['redirect_priority'], 'ajax' => $atts['ajax'], 'admin_edit_roles' => $atts['admin_edit_roles'] ) |
| 102 |
); |
| 103 |
|
| 104 |
return $form; |
| 105 |
} |
| 106 |
|