PluginProbe
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor / 3.16.2
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor v3.16.2
4.0.2 4.0.1 4.0.0 3.16.6 3.16.5 3.16.4 3.16.3 3.16.2 3.16.1 3.16.0 3.15.9 3.9.9 3.9.5 3.9.6 3.9.7 3.9.8 1.1.7 1.1.8 1.1.9 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 All 340 releases
profile-builder / front-end / class-formbuilder.php

class-formbuilder.php in User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 3.16.2, at front-end/class-formbuilder.php

962 lines 52.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly
3
4 class Profile_Builder_Form_Creator{
5 private $defaults = array(
6 'form_type' => '',
7 'form_fields' => array(),
8 'form_name' => '',
9 'role' => '', //used only for the register-form settings
10 'redirect_url' => '',
11 'logout_redirect_url' => '', //used only for the register-form settings
12 'automatic_login' => '', //used only for the register-form
13 'redirect_priority' => 'normal',
14 'ID' => null
15 );
16 public $args;
17
18
19 // Constructor method for the class
20 function __construct( $args ) {
21
22 /* we should stop the execution of the forms if they are in the wp_head hook because it should not be there.
23 SEO plugins can execute shortcodes in the auto generated descriptions */
24 if( apply_filters( 'wppb_dont_render_form_in_wp_head_hook', true ) ){
25 global $wp_current_filter;
26 if( !empty( $wp_current_filter ) && is_array( $wp_current_filter ) ){
27 foreach( $wp_current_filter as $filter ){
28 if( $filter == 'wp_head' )
29 return;
30 }
31 }
32 }
33
34 // Merge the input arguments and the defaults
35 $this->args = wp_parse_args( $args, $this->defaults );
36
37 /* set up the ID here if it is a multi form */
38 if( $this->args['form_name'] != 'unspecified' ){
39 $this->args['ID'] = Profile_Builder_Form_Creator::wppb_get_form_id_from_form_name( $this->args['form_name'], $this->args['form_type'] );
40 }
41
42 global $wppb_shortcode_on_front;
43 $wppb_shortcode_on_front = true;
44
45 global $wppb_register_edit_profile_shortcode_on_front;
46 $wppb_register_edit_profile_shortcode_on_front = true;
47
48 if( empty( $this->args['form_fields'] ) )
49 $this->args['form_fields'] = apply_filters( 'wppb_change_form_fields', get_option( 'wppb_manage_fields' ), $this->args );
50
51 if ( file_exists ( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' ) )
52 require_once( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' );
53
54 if ( defined( 'WPPB_PAID_PLUGIN_DIR' ) && file_exists ( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ) )
55 require_once( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' );
56
57 $this->wppb_retrieve_custom_settings();
58
59 if( defined( 'WPPB_PAID_PLUGIN_DIR' ) && isset( $this->args['ajax'] ) && $this->args['ajax'] === 'true' && file_exists( WPPB_PAID_PLUGIN_DIR . '/features/ajax/assets/forms-ajax-validation.js' ) ) {
60 wp_enqueue_script( 'wppb-forms-ajax-validation-script', WPPB_PAID_PLUGIN_URL . 'features/ajax/assets/forms-ajax-validation.js', array( 'jquery' ), PROFILE_BUILDER_VERSION, true );
61 wp_localize_script( 'wppb-forms-ajax-validation-script', 'submitButtonData', array( 'processingText' => __( 'Processing...', 'profile-builder' ) ) );
62
63 // AJAX validation re-renders the form and needs editor assets only when a WYSIWYG field must be reinitialized
64 if( apply_filters( 'wppb_ajax_form_should_enqueue_editor', $this->wppb_form_has_wysiwyg_field( $this->args['form_fields'] ), $this->args, $this ) )
65 wp_enqueue_editor();
66 }
67
68 // NOTE: for Multisite, the capability we check against is `remove_users` because `edit_users` is on the do not allow on multisite list for current_user_can()
69 // current_user_can( 'edit_users' ) will only return true on a Multisite for Super Administrator Users
70 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) )
71 add_action( 'wppb_before_edit_profile_fields', array( 'Profile_Builder_Form_Creator', 'wppb_edit_profile_select_user_to_edit' ), 10, 4 );
72
73 //enqueue frontend scripts for forms
74 add_action( 'wp_footer', array( $this, 'wppb_frontend_scripts' ), 9999 );
75
76 //admin_edit_roles parameter
77 if( !empty( $this->args['admin_edit_roles'] ) ){
78 add_filter( 'wppb_edit_other_users_dropdown_query_args', array( $this, 'wppb_admin_edit_roles' ), 10, 2 );
79 }
80 }
81
82 /**
83 * @param $form_name The "slug" generated from the current Form Title
84 * @param $form_type the form type of the form: register, edit_profile
85 * @return null
86 */
87 static function wppb_get_form_id_from_form_name( $form_name, $form_type ){
88 global $wpdb;
89
90 if( empty( $form_name ) || empty( $form_type ) )
91 return null;
92
93 if( $form_type == 'edit_profile' ){
94 $post_type = 'wppb-epf-cpt';
95 }elseif( $form_type == 'register' ){
96 $post_type = 'wppb-rf-cpt';
97 }
98
99 $all_forms = $wpdb->get_results(
100 "
101 SELECT ID, post_title
102 FROM $wpdb->posts
103 WHERE post_status = 'publish'
104 AND post_type = '$post_type'
105 "
106 );
107
108 if( !empty( $all_forms ) ) {
109 foreach ($all_forms as $form) {
110 if( empty( $form->post_title ) )
111 $form->post_title = '(no title)';
112
113 if ($form_name == Wordpress_Creation_Kit_PB::wck_generate_slug($form->post_title)) {
114 return $form->ID;
115 }
116 }
117 }
118
119 return null;
120 }
121
122 function wppb_retrieve_custom_settings(){
123 $this->args['login_after_register'] = apply_filters( 'wppb_automatically_login_after_register', 'No' );
124 $this->args['redirect_activated'] = apply_filters( 'wppb_redirect_default_setting', '-' );
125 $this->args['redirect_url'] = apply_filters( 'wppb_redirect_default_location', ( $this->args['redirect_url'] != '' ) ? $this->args['redirect_url'] : '' );
126 $this->args['logout_redirect_url'] = apply_filters( 'wppb_logout_redirect_default_location', ( $this->args['logout_redirect_url'] != '' ) ? $this->args['logout_redirect_url'] : '' );
127 $this->args['redirect_delay'] = apply_filters( 'wppb_redirect_default_duration', 3 );
128
129 $wppb_general_settings = get_option( 'wppb_general_settings' );
130 $this->args['login_after_register'] = ( isset( $wppb_general_settings['automaticallyLogIn'] ) ? $wppb_general_settings['automaticallyLogIn'] : $this->args['login_after_register'] );
131
132 if ( !is_null( $this->args['ID'] ) ){
133 $meta_name = ( ( $this->args['form_type'] == 'register' ) ? 'wppb_rf_page_settings' : 'wppb_epf_page_settings' );
134
135 $page_settings = get_post_meta( $this->args['ID'], $meta_name, true );
136
137 if( !empty( $page_settings[0]['set-role'] ) ){
138 if( $page_settings[0]['set-role'] == 'default role' ){
139 $selected_role = trim( get_option( 'default_role' ) );
140 }
141 else
142 $selected_role = $page_settings[0]['set-role'];
143 }
144
145 $this->args['role'] = ( isset( $selected_role ) ? $selected_role : $this->args['role'] );
146 $this->args['login_after_register'] = ( isset( $page_settings[0]['automatically-log-in'] ) ? $page_settings[0]['automatically-log-in'] : $this->args['login_after_register'] );
147 $this->args['redirect_activated'] = ( isset( $page_settings[0]['redirect'] ) ? $page_settings[0]['redirect'] : $this->args['redirect_activated'] );
148 $this->args['redirect_url'] = ( ! empty( $page_settings[0]['url'] ) && $this->args['redirect_activated'] == 'Yes' && $this->args['redirect_priority'] != 'top' ? $page_settings[0]['url'] : $this->args['redirect_url'] );
149 $this->args['redirect_delay'] = ( isset( $page_settings[0]['display-messages'] ) && $this->args['redirect_activated'] == 'Yes' ? $page_settings[0]['display-messages'] : $this->args['redirect_delay'] );
150
151 if( isset( $page_settings[0]['ajax'] ) && !empty( $page_settings[0]['ajax'] ) )
152 $this->args['ajax'] = $page_settings[0]['ajax'];
153 }
154
155 // the 'automatic_login' shortcode parameter overwrites all other settings
156 $this->args['login_after_register'] = ( $this->args['automatic_login'] != '' ) ? $this->args['automatic_login'] : $this->args['login_after_register'];
157
158 if( !empty( $this->args['role'] ) ){
159 $role_in_arg = get_role( $this->args['role'] );
160 if( !empty( $role_in_arg->capabilities['manage_options'] ) || !empty( $role_in_arg->capabilities['remove_users'] ) ){
161 if( !current_user_can( 'manage_options' ) || !current_user_can( 'remove_users' ) ){
162 $this->args['role'] = get_option('default_role');
163 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_user_role_message', '<p class="alert wppb-error" id="wppb_form_general_message">'.__( 'The role of the created user set to the default role. Only an administrator can register a user with the role assigned to this form.', 'profile-builder').'</p>' ) );
164 }
165 }
166 }
167 }
168
169 /**
170 * Check whether the current form field list contains a WYSIWYG field
171 *
172 * @param array $form_fields The form fields configured for the current form.
173 * @return bool True when a WYSIWYG field is present, false otherwise.
174 */
175 function wppb_form_has_wysiwyg_field( $form_fields ){
176 if( empty( $form_fields ) || !is_array( $form_fields ) )
177 return false;
178
179 foreach( $form_fields as $field ){
180 if( empty( $field['field'] ) )
181 continue;
182
183 if( $field['field'] === 'WYSIWYG' )
184 return true;
185 }
186
187 return false;
188 }
189
190 function wppb_form_logic() {
191 if( isset( $this->args['form_type'] ) ) {
192 if( $this->args['form_type'] == 'register' ){
193 $registration = apply_filters ( 'wppb_register_setting_override', true );//used to be get_option( 'users_can_register' )
194
195 if ( !is_user_logged_in() ){
196 if ( !$registration )
197 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Only an administrator can add new users.', 'profile-builder')).'</p>' ) );
198
199 elseif ( $registration ){
200 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '' ) );
201 }
202
203 }else{
204 $current_user_capability = apply_filters ( 'wppb_registration_user_capability', 'create_users' );
205
206 if ( current_user_can( $current_user_capability ) && $registration )
207 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Users can register themselves or you can manually create users here.', 'profile-builder')). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.esc_attr(__( 'This message is only visible by administrators', 'profile-builder' )).'"/>' . '</p>' ) );
208
209 elseif ( current_user_can( $current_user_capability ) && !$registration )
210 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Users cannot currently register themselves, but you can manually create users here.', 'profile-builder')). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.esc_attr(__( 'This message is only visible by administrators', 'profile-builder' )).'"/>' . '</p>' ) );
211
212 elseif ( !current_user_can( $current_user_capability ) ){
213 global $user_ID;
214
215 $userdata = get_userdata( $user_ID );
216 $display_name = ( ( $userdata->data->display_name == '' ) ? $userdata->data->user_login : $userdata->data->display_name );
217
218 $wppb_general_settings = get_option( 'wppb_general_settings' );
219 if ( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) )
220 $display_name = $userdata->data->user_email;
221
222 if( empty( $this->args['logout_redirect_url'] ) ) {
223 $this->args['logout_redirect_url'] = get_permalink();
224 }
225
226 // CHECK FOR REDIRECT
227 $this->args['logout_redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], 'after_logout', $this->args['logout_redirect_url'], $userdata );
228 $this->args['logout_redirect_url'] = apply_filters( 'wppb_after_logout_redirect_url', $this->args['logout_redirect_url'] );
229
230 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.sprintf( __( "You are currently logged in as %1s. You don't need another account. %2s", 'profile-builder' ), '<a href="'.get_author_posts_url( $user_ID ).'" title="'.$display_name.'">'.$display_name.'</a>', '<a href="'.wp_logout_url( $this->args['logout_redirect_url'] ).'" title="'.__( 'Log out of this account.', 'profile-builder' ).'">'.__( 'Logout', 'profile-builder' ).' &raquo;</a>' ).'</p>', $user_ID ) );
231 }
232 }
233
234 }elseif ( $this->args['form_type'] == 'edit_profile' ){
235 if ( !is_user_logged_in() )
236 echo wp_kses_post( apply_filters( 'wppb_edit_profile_user_not_logged_in_message', '<p class="warning" id="wppb_edit_profile_user_not_logged_in_message">'.esc_html(__( 'You must be logged in to edit your profile.', 'profile-builder' )) .'</p>' ) );
237
238 elseif ( is_user_logged_in() )
239 $this->wppb_form_content( apply_filters( 'wppb_edit_profile_logged_in_user_message', '' ) );
240
241 }
242 }
243 }
244
245 // Function used to automatically log in a user after register if that option is set on yes in register form settings
246 function wppb_log_in_user( $redirect, $redirect_old ) {
247 if( is_user_logged_in() ) {
248 return;
249 }
250
251 $wppb_general_settings = get_option( 'wppb_general_settings' );
252 $ec_bypass_forms = wppb_toolbox_get_settings( 'forms', 'ec-bypass' );
253
254 if ( is_array( $ec_bypass_forms ) && !empty( $_POST['form_name'] ) && in_array( sanitize_text_field( $_POST['form_name'] ), $ec_bypass_forms ) )
255 $should_bypass_ec = true;
256 else $should_bypass_ec = false;
257
258 if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) && !$should_bypass_ec ) {
259 return $redirect_old;
260 }
261
262 /* get user id */
263 if( empty( $_POST['email'] ) )
264 return;
265
266 $user = get_user_by( 'email', trim( sanitize_email( $_POST['email'] ) ) );
267
268 if( !$user )
269 return;
270
271 $nonce = wp_create_nonce( 'autologin-'. $user->ID .'-'. (int)( time() / 60 ) );
272
273 if ( wppb_get_admin_approval_option_value() === 'yes' ) {
274 if( !empty( $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
275 foreach ($user->roles as $role) {
276 if ( in_array( $role, $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
277 return $redirect_old;
278 }
279 }
280 }
281 else {
282 return $redirect_old;
283 }
284 }
285
286 /* define redirect location */
287 if( $this->args['redirect_activated'] == 'No' ) {
288 if( isset( $_POST['_wp_http_referer'] ) ) {
289 $redirect = esc_url_raw($_POST['_wp_http_referer']);
290 } else {
291 $redirect = home_url();
292 }
293 }
294
295 if( empty( $redirect ) )
296 $redirect = wppb_curpageurl();
297
298 $redirect = apply_filters( 'wppb_login_after_reg_redirect_url', $redirect, $this );
299
300 $redirect = add_query_arg( array( 'autologin' => 'true', 'uid' => $user->ID, '_wpnonce' => $nonce ), $redirect );
301
302 // CHECK FOR REDIRECT
303 if( $this->args['redirect_activated'] == 'No' || ( empty( $this->args['redirect_delay'] ) || $this->args['redirect_delay'] == '0' ) ) {
304 $redirect = wppb_build_redirect( $redirect, 0, 'register', $this->args );
305 } else {
306 $redirect = wppb_build_redirect( $redirect, $this->args['redirect_delay'], 'register', $this->args );
307 }
308 return $redirect;
309 }
310
311 /**
312 * Function to get redirect for Register and Edit Profile forms
313 *
314 * @param string $form_type - type of the form
315 * @param string $redirect_type - type of the redirect
316 * @param string $user - username or user email
317 * @param string $user_role - user Role
318 *
319 * @return string $redirect
320 */
321 function wppb_get_redirect( $form_type, $redirect_type, $user, $user_role ) {
322 $this->args['redirect_delay'] = apply_filters( 'wppb_'. $form_type .'_redirect_delay', $this->args['redirect_delay'], $user, $this->args );
323 if( $this->args['redirect_activated'] == '-' ) {
324 $this->args['redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], $redirect_type, $this->args['redirect_url'], $user, $user_role );
325 $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
326 } elseif( $this->args['redirect_activated'] == 'Yes' ) {
327 $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
328 } else {
329 $redirect = '';
330 }
331
332 return $redirect;
333 }
334
335 function wppb_form_content( $message ) {
336 $field_check_errors = array();
337
338 ob_start();
339
340 // check if the form is being displayed in the Elementor editor
341 // if true remove any messages
342 $is_elementor_edit_mode_or_divi_ajax = false;
343 if( class_exists ( '\Elementor\Plugin' ) ){
344 $is_elementor_edit_mode_or_divi_ajax = \Elementor\Plugin::$instance->editor->is_edit_mode();
345 $message= "";
346 }
347
348 if ( is_array( $_POST ) && array_key_exists( 'action', $_POST ) && $_POST['action'] === 'wppb_divi_extension_ajax' ) {
349 $is_elementor_edit_mode_or_divi_ajax = true;
350 }
351
352 if( !$is_elementor_edit_mode_or_divi_ajax && isset( $_REQUEST['action'], $_REQUEST['form_name'], $this->args['form_name'] ) && $_REQUEST['form_name'] === $this->args['form_name'] ) {
353 if( ! isset( $_POST[$this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field'] ) || ! wp_verify_nonce( sanitize_text_field( $_POST[$this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field'] ), 'wppb_verify_form_submission' ) ) {
354 echo '<span class="wppb-form-error wppb-error">'. esc_html(__( 'You are not allowed to do this.', 'profile-builder' )) . '</span>';
355
356 ob_end_flush();
357
358 return;
359 }
360
361 $_REQUEST = apply_filters( 'wppb_filter_form_request_data', $_REQUEST, $this->args );
362
363 $field_check_errors = $this->wppb_test_required_form_values( $_REQUEST );
364 if( empty( $field_check_errors ) ) {
365
366 do_action( 'wppb_before_saving_form_values',$_REQUEST, $this->args );
367
368 // we only have a $user_id on default registration (no email confirmation, no multisite)
369 $user_id = $this->wppb_save_form_values( $_REQUEST );
370
371 do_action( 'wppb_after_saving_form_values',$_REQUEST, $this->args );
372
373 if( ( isset( $_SERVER['REQUEST_METHOD'] ) && 'POST' === $_SERVER['REQUEST_METHOD'] ) && ( isset( $_POST['action'] ) && $_POST['action'] === $this->args['form_type'] ) ) {
374
375 $form_message_tpl_start = apply_filters( 'wppb_form_message_tpl_start', '<p class="alert wppb-success" id="wppb_form_general_message">' );
376 $form_message_tpl_end = apply_filters( 'wppb_form_message_tpl_end', '</p>' );
377
378 if( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $_POST['custom_field_user_role'] ) ) {
379 $user_role = sanitize_text_field($_POST['custom_field_user_role']);
380 } elseif( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $this->args['role'] ) ) {
381 $user_role = $this->args['role'];
382 } else {
383 $user_role = NULL;
384 }
385
386 if( isset( $_POST['username'] ) && sanitize_user( $_POST['username'] ) != '' ) {
387 $account_name = sanitize_user( $_POST['username'] );
388 } elseif( isset( $_POST['email'] ) && ( sanitize_email( $_POST['email'] ) != '' ) ) {
389 $account_name = sanitize_email( $_POST['email'] );
390 }else{
391 /* we are in the edit form with no username or email field */
392 $current_user = wp_get_current_user();
393 if( !empty( $current_user ) )
394 $account_name = $current_user->user_login;
395 }
396
397 if( $this->args['form_type'] == 'register' ) {
398 // ec = email confirmation setting
399 // aa = admin approval setting
400 $wppb_general_settings = get_option( 'wppb_general_settings', 'false' );
401 if ( $wppb_general_settings ) {
402 if( !empty( $wppb_general_settings['emailConfirmation'] ) && apply_filters( 'wppb_email_confirmation_on_register', $wppb_general_settings['emailConfirmation'], $_POST ) == 'yes' )
403 $wppb_email_confirmation = $wppb_general_settings['emailConfirmation'];
404 else
405 $wppb_email_confirmation = 'no';
406
407
408 $wppb_admin_approval = wppb_get_admin_approval_option_value();
409
410 $account_management_settings = 'ec-' . $wppb_email_confirmation . '_' . 'aa-' . $wppb_admin_approval;
411 } else {
412 $account_management_settings = 'ec-no_aa-no';
413 }
414
415 switch( $account_management_settings ) {
416 case 'ec-no_aa-no':
417 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1\$s has been successfully created!", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
418 break;
419 case 'ec-yes_aa-no':
420 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
421 break;
422 case 'ec-no_aa-yes':
423 if( current_user_can( 'delete_users' ) ) {
424 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1\$s has been successfully created!", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
425 } else {
426 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, an administrator has to approve it. You will be notified via email.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
427 }
428 break;
429 case 'ec-yes_aa-yes':
430 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
431 break;
432 }
433
434 // CHECK FOR REDIRECT
435 $redirect = $this->wppb_get_redirect( 'register', 'after_registration', $account_name, $user_role );
436
437 // using case-insensitive string comparison to allow for both 'Yes' and 'yes'
438 if( strcasecmp($this->args['login_after_register'], 'Yes') == 0 ) {
439 $redirect = $this->wppb_log_in_user( $this->args['redirect_url'], $redirect );
440 }
441
442 echo $form_message_tpl_start . wp_kses_post( $wppb_register_success_message ) . $form_message_tpl_end . $redirect; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
443
444 ob_end_flush();
445
446 //action hook after registration success
447 do_action( 'wppb_register_success', $_REQUEST, $this->args['form_name'], $user_id );
448 return;
449 } elseif( $this->args['form_type'] == 'edit_profile' ) {
450 // CHECK FOR REDIRECT
451 $redirect = $this->wppb_get_redirect( 'edit_profile', 'after_edit_profile', $account_name, $user_role );
452
453 echo $form_message_tpl_start . apply_filters( 'wppb_edit_profile_success_message', esc_html(__( 'Your profile has been successfully updated!', 'profile-builder' )) ) . $form_message_tpl_end . $redirect; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
454
455 //action hook after edit profile success
456 do_action( 'wppb_edit_profile_success', $_REQUEST, $this->args['form_name'], $user_id );
457
458 if( apply_filters( 'wppb_no_form_after_profile_update', false ) ){
459 ob_end_flush();
460 return;
461 }
462 }
463
464 }
465
466 }else
467 echo $message. wp_kses_post( apply_filters( 'wppb_general_top_error_message', '<p id="wppb_form_general_message" class="wppb-error">'.esc_html(__( 'There was an error in the submitted form', 'profile-builder' )).'</p>' ) ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
468
469 }else
470 echo $message; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
471
472 // use this action hook to add extra content before the register form
473 do_action( 'wppb_before_'.$this->args['form_type'].'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'], $is_elementor_edit_mode_or_divi_ajax );
474
475 $wppb_user_role_class = '';
476 if( is_user_logged_in() ) {
477 $wppb_user = wp_get_current_user();
478
479 if( $wppb_user && isset( $wppb_user->roles ) ) {
480 foreach( $wppb_user->roles as $wppb_user_role ) {
481 $wppb_user_role_class .= ' wppb-user-role-'. $wppb_user_role;
482 }
483 }
484 } else {
485 $wppb_user_role_class = ' wppb-user-logged-out';
486 }
487 $wppb_user_role_class = apply_filters( 'wppb_user_role_form_class', $wppb_user_role_class );
488
489 /* set up form id */
490 $wppb_form_id = '';
491 if( $this->args['form_type'] == 'register' )
492 $wppb_form_id = 'wppb-register-user';
493 elseif( $this->args['form_type'] == 'edit_profile' )
494 $wppb_form_id = 'wppb-edit-user';
495 if( isset($this->args['form_name']) && $this->args['form_name'] != "unspecified" )
496 $wppb_form_id .= '-' . $this->args['form_name'];
497
498 /* set up form class */
499 $wppb_form_class = 'wppb-user-forms';
500 if( $this->args['form_type'] == 'register' )
501 $wppb_form_class .= ' wppb-register-user';
502 elseif( $this->args['form_type'] == 'edit_profile' )
503 $wppb_form_class .= ' wppb-edit-user';
504 $wppb_form_class .= $wppb_user_role_class;
505
506 ?>
507 <form enctype="multipart/form-data" method="post" id="<?php echo esc_attr( apply_filters( 'wppb_form_id', $wppb_form_id, $this ) ); ?>" class="<?php echo esc_attr( apply_filters( 'wppb_form_class', $wppb_form_class, $this ) ) . ( $this->args['ajax'] == 'true' ? ' wppb-ajax-form' : ''); ?>" action="<?php echo esc_url( apply_filters( 'wppb_form_action', wppb_curpageurl(), $this->args ) ); ?>">
508 <?php
509 do_action( 'wppb_form_args_before_output', $this->args );
510 $this->args = apply_filters( 'wppb_filter_form_args_before_output', $this->args );
511
512 echo apply_filters( 'wppb_before_form_fields', '<ul>', $this->args['form_type'], $this->args['ID'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
513 echo $this->wppb_output_form_fields( $_REQUEST, $field_check_errors, $this->args['form_fields'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
514 echo apply_filters( 'wppb_after_form_fields', '</ul>', $this->args['form_type'], $this->args['ID'], $_REQUEST ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
515
516 echo apply_filters( 'wppb_before_send_credentials_checkbox', '<ul>', $this->args['form_type'], $this->args['ID'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
517 $this->wppb_add_send_credentials_checkbox( $_REQUEST, $this->args['form_type'] );
518 echo apply_filters( 'wppb_after_send_credentials_checkbox', '</ul>', $this->args['form_type'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
519
520 echo apply_filters( 'wppb_form_bottom', '</ul>', $this->args['form_type'], $this->args['ID'], $_REQUEST ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
521
522 $wppb_form_submit_extra_attr = apply_filters( 'wppb_form_submit_extra_attr', '', $this->args['form_type'], $this->args['ID'] );
523 ?>
524 <p class="form-submit" <?php echo $wppb_form_submit_extra_attr; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */ ?> >
525 <?php
526 if( $this->args['form_type'] == 'register' )
527 $button_name = ( current_user_can( 'create_users' ) ? __( 'Add User', 'profile-builder' ) : __( 'Register', 'profile-builder' ) );
528
529 elseif( $this->args['form_type'] == 'edit_profile' )
530 $button_name = __( 'Update', 'profile-builder' );
531 ?>
532 <?php do_action( 'wppb_form_before_submit_button', $this->args ); ?>
533 <input name="<?php echo esc_attr( $this->args['form_type'] ); ?>" type="submit" id="<?php echo esc_attr( $this->args['form_type'] ); ?>" class="<?php echo esc_attr( apply_filters( 'wppb_'. $this->args['form_type'] .'_submit_class', "submit button" ) );?>" value="<?php echo esc_attr( apply_filters( 'wppb_'. $this->args['form_type'] .'_button_name', $button_name, $this->args['form_name'] ) ); ?>" <?php echo apply_filters( 'wppb_form_submit_button_extra_attributes', '', $this->args['form_type'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */?>/>
534 <input name="redirect_to" type="hidden" value="<?php echo esc_attr( $this->args['redirect_url'] ); ?>" />
535 <?php do_action( 'wppb_form_after_submit_button', $this->args ); ?>
536 <input name="action" type="hidden" id="action" value="<?php echo esc_attr( $this->args['form_type'] ); ?>" />
537 <input name="form_name" type="hidden" id="form_name" value="<?php echo esc_attr( $this->args['form_name'] ); ?>" />
538 <input name="form_id" type="hidden" id="form_id" value="<?php echo esc_attr( $this->args['ID'] ); ?>" />
539 <?php
540 $wppb_module_settings = get_option( 'wppb_module_settings' );
541
542 if( isset( $wppb_module_settings['wppb_customRedirect'] ) && $wppb_module_settings['wppb_customRedirect'] == 'show' ) {
543 if( isset( $_POST['wppb_referer_url'] ) )
544 $referer = esc_url_raw( $_POST['wppb_referer_url'] );
545 elseif( isset( $_SERVER['HTTP_REFERER'] ) )
546 $referer = esc_url_raw( $_SERVER['HTTP_REFERER'] );
547 else
548 $referer = '';
549
550 echo '<input type="hidden" name="wppb_referer_url" value="'. esc_attr( $referer ).'"/>';
551 }
552 ?>
553 </p><!-- .form-submit -->
554 <?php wp_nonce_field( 'wppb_verify_form_submission', $this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field' ); ?>
555 </form>
556 <?php
557 // use this action hook to add extra content after the register form
558 do_action( 'wppb_after_'. $this->args['form_type'] .'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'] );
559
560 $form_content = ob_get_clean();
561
562 echo apply_filters( 'wppb_' . $this->args['form_type'] . '_form_content', $form_content ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
563 }
564
565 function wppb_output_form_fields( $global_request, $field_check_errors, $form_fields, $called_from = NULL, $is_repeater_group = false ){
566 $wppb_generalSettings = get_option( 'wppb_general_settings' );
567 $output_fields = '';
568
569 if( !empty( $form_fields ) ){
570 $output_fields .= apply_filters( 'wppb_output_before_first_form_field', '', $this->args['ID'], $this->args['form_type'], $form_fields, $called_from );
571 foreach( $form_fields as $field ){
572 $error_var = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? ' wppb-field-error' : '' );
573 $specific_message = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? $field_check_errors[$field['id']] : '' );
574
575 $display_field = apply_filters( 'wppb_output_display_form_field', true, $field, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
576
577 if( $display_field == false )
578 continue;
579
580 $css_class = apply_filters( 'wppb_field_css_class', 'wppb-form-field wppb-'. Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ) .$error_var, $field, $error_var );
581 $output_fields .= apply_filters( 'wppb_output_before_form_field', '<li class="'. $css_class .'" id="wppb-form-element-'. $field['id'] .'">', $field, $error_var, $this->args['role'], $this->args['ID'], $this->args['form_type']);
582
583 $render_field = true;
584 if( wppb_conditional_fields_exists() && isset( $wppb_generalSettings['conditional_fields_ajax'] ) ){
585 if($wppb_generalSettings['conditional_fields_ajax'] === 'yes' && isset($field['conditional-logic-enabled']) && $field['conditional-logic-enabled'] === 'yes') {
586 $render_field = false;
587 }
588 }
589
590 if( $render_field ){
591 $output_fields .= apply_filters('wppb_output_form_field_' . Wordpress_Creation_Kit_PB::wck_generate_slug($field['field']), '', $this->args['form_type'], $field, $this->wppb_get_desired_user_id(), $field_check_errors, $global_request, $this->args['role'], $this);
592 $output_fields .= apply_filters('wppb_output_specific_error_message', $specific_message);
593 }
594
595 $output_fields .= apply_filters( 'wppb_output_after_form_field', '</li>', $field, $this->args['ID'], $this->args['form_type'], $called_from );
596 }
597
598 if ( !$is_repeater_group ) {
599 $output_fields .= apply_filters('wppb_output_after_last_form_field', '', $this->args['ID'], $this->args['form_type'], $called_from);
600 }
601 }
602
603 return apply_filters( 'wppb_output_fields_filter', $output_fields );
604 }
605
606
607 function wppb_add_send_credentials_checkbox ( $request_data, $form ){
608 if ( $form == 'edit_profile' )
609 echo '';
610
611 else{
612 $checkbox = apply_filters( 'wppb_send_credentials_checkbox_logic', '<li class="wppb-form-field wppb-send-credentials-checkbox"><label for="send_credentials_via_email"><input id="send_credentials_via_email" type="checkbox" name="send_credentials_via_email" value="sending"'.( ( isset( $request_data['send_credentials_via_email'] ) && ( $request_data['send_credentials_via_email'] == 'sending' ) ) ? ' checked' : '' ).'/>'.esc_html__( 'Send these credentials via email.', 'profile-builder').'</label></li>', $request_data, $form );
613
614 $wppb_general_settings = get_option( 'wppb_general_settings' );
615 echo ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ? '' : $checkbox ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
616 }
617 }
618
619
620 function wppb_test_required_form_values( $global_request ){
621 $output_field_errors = array();
622 $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'global_request' => $global_request, 'context' => 'validate_frontend', 'form_type' => $this->args['form_type'], 'role' => $this->args['role'], 'user_id' => $this->wppb_get_desired_user_id() ) );
623 if( !empty( $form_fields ) ){
624 foreach( $form_fields as $field ){
625 $error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $global_request, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
626
627 if( !empty( $error_for_field ) )
628 $output_field_errors[$field['id']] = '<span class="wppb-form-error">' . $error_for_field . '</span>';
629 }
630 }
631
632 return apply_filters( 'wppb_output_field_errors_filter', $output_field_errors, $this->args['form_fields'], $global_request, $this->args['form_type'] );
633 }
634
635 function wppb_save_form_values( $global_request ){
636 $user_id = $this->wppb_get_desired_user_id();
637 $userdata = apply_filters( 'wppb_build_userdata', array(), $global_request, $this->args );
638 $new_user_signup = false;
639
640 $wppb_general_settings = get_option( 'wppb_general_settings' );
641
642 if( $this->args['form_type'] == 'register' ){
643
644 $result = $this->wppb_register_user( $global_request, $userdata );
645 $user_id = $result['user_id'];
646 $userdata = $result['userdata'];
647 $new_user_signup = $result['new_user_signup'];
648
649 }elseif( $this->args['form_type'] == 'edit_profile' ){
650 if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
651 $user_info = get_userdata( $user_id );
652 $userdata['user_login'] = $user_info->user_login;
653 }
654
655 $userdata['ID'] = $this->wppb_get_desired_user_id();
656 $userdata = wp_unslash( $userdata );
657 /* if the user changes his password then we can't send it to the wp_update_user() function or
658 the user will be logged out and won't be logged in again because we call wp_update_user() after
659 the headers were sent( in the content as a shortcode ) */
660 if( isset( $userdata['user_pass'] ) && !empty( $userdata['user_pass'] ) ){
661 unset($userdata['user_pass']);
662 }
663
664 if( isset( $userdata['role'] ) && is_array( $userdata['role'] ) ) {
665 $user_data = get_userdata( $user_id );
666 if( $user_data ) {
667 $user_data->remove_all_caps();
668
669 foreach ($userdata['role'] as $role) {
670 if ($role !== 'administrator' || $role !== 'super-admin')//make sure this doesn't happen for any reason
671 $user_data->add_role($role);
672 }
673 }
674
675 unset( $userdata['role'] );
676 }
677
678 wp_update_user( $userdata );
679 }
680
681 if( !empty( $this->args['form_fields'] ) && !$new_user_signup ){
682 foreach( $this->args['form_fields'] as $field ){
683 if( apply_filters( 'wppb_pre_save_form_field', true, $field, $user_id, $global_request, $this->args['form_type'] ) )
684 do_action( 'wppb_save_form_field', $field, $user_id, $global_request, $this->args['form_type'] );
685 }
686
687 if ( $this->args['form_type'] == 'register' ){
688 if ( !is_wp_error( $user_id ) ){
689 $wppb_general_settings = get_option( 'wppb_general_settings' );
690 if( ( isset( $global_request['send_credentials_via_email'] ) && ( $global_request['send_credentials_via_email'] == 'sending' ) ) || apply_filters( 'wppb_register_send_credentials_via_email', false, $user_id, $this->args ) )
691 $send_credentials_via_email = 'sending';
692 else
693 $send_credentials_via_email = '';
694
695 wppb_notify_user_registration_email( get_bloginfo( 'name' ), ( isset( $userdata['user_login'] ) ? trim( $userdata['user_login'] ) : trim( $userdata['user_email'] ) ), trim( $userdata['user_email'] ), $send_credentials_via_email, trim( $userdata['user_pass'] ), ( wppb_get_admin_approval_option_value() === 'yes' ? 'yes' : 'no' ) );
696 }
697 }
698 }
699 return $user_id;
700 }
701
702 function wppb_register_user( $global_request, $userdata ){
703 $wppb_module_settings = get_option( 'wppb_module_settings' );
704 $wppb_general_settings = get_option( 'wppb_general_settings' );
705 $user_id = null;
706 $new_user_signup = false;
707
708 if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
709 $userdata['user_login'] = apply_filters( 'wppb_generated_random_username', Wordpress_Creation_Kit_PB::wck_generate_slug( trim( $userdata['user_email'] ) ), $userdata['user_email'] );
710 }
711
712 /* filter so we can bypass Email Confirmation on register */
713 if ( isset( $wppb_general_settings['emailConfirmation'] ) )
714 $wppb_general_settings['emailConfirmation'] = apply_filters( 'wppb_email_confirmation_on_register', $wppb_general_settings['emailConfirmation'], $global_request );
715
716 if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ){
717 $new_user_signup = true;
718
719 $userdata = $this->wppb_add_custom_field_values( $global_request, $userdata, $this->args['form_fields'] );
720
721 if( ! isset( $userdata['role'] ) ) {
722 $userdata['role'] = $this->args['role'];
723 }
724
725 $userdata['user_pass'] = wp_hash_password( $userdata['user_pass'] );
726
727 if( is_multisite() ){
728 /* since version 2.0.7 add this meta so we know on what blog the user registered */
729 $userdata['registered_for_blog_id'] = get_current_blog_id();
730 $userdata = wp_unslash( $userdata );
731 }
732
733 $userdata['form_name'] = $this->args['form_name'];
734
735 wppb_signup_user( $userdata['user_login'], $userdata['user_email'], $this->args['login_after_register'], $userdata );
736 }else{
737 if( ! isset( $userdata['role'] ) ) {
738 $userdata['role'] = $this->args['role'];
739 }
740
741 $userdata = wp_unslash( $userdata );
742
743 // change User Registered date and time according to timezone selected in WordPress settings
744 $wppb_get_date = wppb_get_register_date();
745
746 if( isset( $wppb_get_date ) ) {
747 $userdata['user_registered'] = $wppb_get_date;
748 }
749
750 // insert user to database
751 $user_id = wp_insert_user( $userdata );
752 }
753
754 return array( 'userdata' => $userdata, 'user_id' => $user_id, 'new_user_signup' => $new_user_signup );
755 }
756
757 function wppb_add_custom_field_values( $global_request, $meta, $form_properties ){
758 $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'meta' => $meta, 'global_request' => $global_request, 'context' => 'user_signup' ) );
759 if( !empty( $form_fields ) ){
760 foreach( $form_fields as $field ){
761 if( !empty( $field['meta-name'] ) && ( ! isset( $field['field'] ) || 'Default - Biographical Info' !== $field['field'] ) ){
762 if ( ! array_key_exists( $field['meta-name'], $global_request ) ) {
763 $posted_value = '';
764 } elseif( in_array( $field['field'], array( 'URL' ), true ) ) {
765 $posted_value = esc_url_raw( $global_request[ $field['meta-name'] ] );
766 } elseif( in_array( $field['field'], array( 'Textarea' ), true ) ){
767 $meta_value = sanitize_textarea_field( wp_unslash( $global_request[ $field['meta-name'] ] ) );
768
769 if( apply_filters( 'wppb_form_field_textarea_escape_on_save', false ) )
770 $meta_value = esc_textarea( $meta_value );
771
772 $posted_value = $meta_value;
773 } elseif ( is_array( $global_request[ $field['meta-name'] ] ) ) {
774 $posted_value = array_map( 'sanitize_text_field', $global_request[ $field['meta-name'] ] );
775 } else {
776 $posted_value = sanitize_text_field( $global_request[ $field['meta-name'] ] );
777 }
778
779 $meta[$field['meta-name']] = apply_filters( 'wppb_add_to_user_signup_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
780
781 }
782
783 if ( isset( $field['field'] ) && 'Default - Biographical Info' === $field['field'] ) {
784 $posted_value = '';
785 if ( array_key_exists( 'description', $global_request ) ) {
786 $posted_value = wppb_sanitize_default_biographical_info_from_request( $global_request );
787 }
788 $meta['description'] = apply_filters( 'wppb_add_to_user_signup_form_field_' . Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
789 }
790 }
791 }
792
793 return apply_filters( 'wppb_add_to_user_signup_form_meta', $meta, $global_request, $this->args['role'] );
794 }
795
796 /**
797 * Function that returns the id for the current logged in user or for edit profile forms for administrator it can return the id of a selected user
798 */
799 function wppb_get_desired_user_id(){
800 if( $this->args['form_type'] == 'edit_profile' ){
801 //only admins
802 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) ){
803 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){
804 return absint( $_GET['edit_user'] );
805 }
806 }
807 }
808
809 return get_current_user_id();
810 }
811
812 static function wppb_edit_profile_select_user_to_edit( $form_name, $id, $form_type, $is_elementor_edit_mode_or_divi_ajax ){
813
814 $display_edit_users_dropdown = apply_filters( 'wppb_display_edit_other_users_dropdown', true, $form_name );
815 if( !$display_edit_users_dropdown || $is_elementor_edit_mode_or_divi_ajax )
816 return;
817
818 /* add a hard cap: if we have more than 5000 users don't display the dropdown for performance considerations */
819 $user_count = count_users();
820 if( $user_count['total_users'] > apply_filters( 'wppb_edit_other_users_count_limit', 5000 ) )
821 return;
822
823 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) )
824 $selected = absint( $_GET['edit_user'] );
825 else
826 $selected = get_current_user_id();
827
828 $query_args = array(
829 'fields' => array( 'ID', 'user_login', 'display_name' ),
830 'role' => apply_filters( 'wppb_edit_profile_user_dropdown_role', '', $form_name ),
831 'role__not_in' => array( 'administrator' ),
832 'orderby' => array( 'display_name', 'user_login' ),
833 );
834
835 $users = get_users( apply_filters( 'wppb_edit_other_users_dropdown_query_args', $query_args, $form_name ) );
836
837 if ( apply_filters( 'wppb_edit_other_users_dropdown_user_list_excludes_admin_approval', false ) &&
838 wppb_get_admin_approval_option_value() === 'yes' ) {
839 foreach ( $users as $key => $user ) {
840 if ( wp_get_object_terms( $user->ID, 'user_status' ) ) {
841 unset( $users[ $key ] );
842 }
843 }
844 }
845
846 if( !empty( $users ) ) {
847
848 /* turn it in a select2 */
849 wp_enqueue_script( 'wppb_select2_js', WPPB_PLUGIN_URL .'assets/js/select2/select2.min.js', array( 'jquery' ), PROFILE_BUILDER_VERSION );
850 wp_enqueue_style( 'wppb_select2_css', WPPB_PLUGIN_URL .'assets/css/select2/select2.min.css', array(), PROFILE_BUILDER_VERSION );
851 ?>
852 <form method="GET" action="" id="select_user_to_edit_form">
853 <p class="wppb-form-field">
854 <label for="edit_user"><?php esc_html_e('User to edit:', 'profile-builder') ?></label>
855 <select id="wppb-<?php echo !empty( $form_name ) ? esc_attr( $form_name ).'-' : ''; ?>user-to-edit" class="wppb-user-to-edit" name="edit_user">
856 <option value=""><?php echo esc_html__( 'Select User', 'profile-builder' ); ?></option>
857 <?php
858 foreach( $users as $user ){
859 ?>
860 <option value="<?php echo esc_url( add_query_arg( array( 'edit_user' => $user->ID ) ) ); ?>" <?php selected( $selected, $user->ID ); ?>>
861 <?php echo esc_html( apply_filters( 'wppb_edit_other_users_display_name', $user->display_name, $user ) ); ?>
862 </option>
863 <?php
864 }
865 ?>
866 </select>
867 </p>
868 </form>
869 <?php
870 }
871 else{
872 echo '<p id="wppb-no-other-users-to-edit">'. esc_html( apply_filters( 'wppb_no_users_to_edit_message', __( 'There are no other users to edit', 'profile-builder' ) ) ).'</p>';
873 }
874 }
875
876 public function wppb_admin_edit_roles( $query_args, $form_name ){
877 $admin_edit_roles = $this->args['admin_edit_roles'];
878
879 $admin_edit_roles = array_filter( array_map( 'trim', explode( ',', (string) $admin_edit_roles ) ) );
880 $admin_edit_roles = array_map( 'sanitize_key', $admin_edit_roles );
881 $admin_edit_roles = array_values( array_unique( $admin_edit_roles ) );
882
883 global $wp_roles;
884 if ( ! $wp_roles ) {
885 $wp_roles = wp_roles();
886 }
887
888 $roles = array();
889 foreach ( $admin_edit_roles as $admin_edit_role ){
890 if ( isset( $wp_roles->roles[$admin_edit_role] ) )
891 $roles[] = $admin_edit_role;
892 }
893
894 if ( empty( $roles ) ) {
895 return $query_args;
896 }
897
898 unset( $query_args['role'] );
899 $query_args['role__in'] = $roles;
900
901 return $query_args;
902
903 }
904
905 static function wppb_frontend_scripts(){
906
907 wp_register_script( 'wppb_front_end_script', WPPB_PLUGIN_URL. 'assets/js/script-front-end.js', array('jquery'), PROFILE_BUILDER_VERSION, true );
908
909 $wppb_toolbox_forms_settings = get_option( 'wppb_toolbox_forms_settings' );
910 if( isset( $wppb_toolbox_forms_settings[ 'disable-automatic-scrolling' ] ) ){
911 wp_add_inline_script( 'wppb_front_end_script', "var wppb_disable_automatic_scrolling = 1;", 'before' );
912 }
913
914 wp_enqueue_script( 'wppb_front_end_script' );
915 wp_print_scripts( 'wppb_front_end_script' );
916
917 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) ){
918 wp_enqueue_script( 'wppb_select_user_to_edit_js', WPPB_PLUGIN_URL. 'assets/js/select-user-to-edit.js', array('jquery'), PROFILE_BUILDER_VERSION, true );
919 wp_print_scripts( 'wppb_select_user_to_edit_js' );
920 }
921
922 }
923
924 /**
925 * Handle toString method
926 *
927 * @since 2.0
928 *
929 * @return string $html html for the form.
930 */
931 public function __toString() {
932 try {
933 ob_start();
934 $this->wppb_form_logic();
935 $html = ob_get_clean();
936 return "{$html}";
937 } catch (Exception $exception) {
938 return __( 'Something went wrong. Please try again!', 'profile-builder');
939 }
940 }
941 }
942
943 /* set action for automatic login after registration */
944 add_action( 'init', 'wppb_autologin_after_registration' );
945 function wppb_autologin_after_registration(){
946 if( isset( $_GET['autologin'] ) && isset( $_GET['uid'] ) && isset( $_REQUEST['_wpnonce'] ) ){
947 $uid = absint( $_GET['uid'] );
948
949 $arr_params = array( 'autologin', 'uid', '_wpnonce' );
950 $current_page_url = remove_query_arg( $arr_params, wppb_curpageurl() );
951
952 if ( ! ( wp_verify_nonce( sanitize_text_field( $_REQUEST['_wpnonce'] ) , 'autologin-'.$uid.'-'.(int)( time() / 60 ) ) || wp_verify_nonce( sanitize_text_field( $_REQUEST['_wpnonce'] ) , 'autologin-'.$uid.'-'.(int)( time() / 60 - 1 ) ) ) ){
953 wp_redirect( $current_page_url );
954 exit;
955 } else {
956 wp_set_auth_cookie( $uid );
957 wp_redirect( $current_page_url );
958 exit;
959 }
960 }
961 }
962