PluginProbe
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor / 3.16.4
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor v3.16.4
4.0.3 4.0.2 4.0.1 4.0.0 3.16.6 3.16.5 3.16.4 3.16.3 3.16.2 3.16.1 3.16.0 3.15.9 3.9.9 3.9.5 3.9.6 3.9.7 3.9.8 1.1.7 1.1.8 1.1.9 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 All 341 releases
profile-builder / front-end / class-formbuilder.php

class-formbuilder.php in User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 3.16.4, at front-end/class-formbuilder.php

965 lines 52.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly
3
4 class Profile_Builder_Form_Creator{
5 private $defaults = array(
6 'form_type' => '',
7 'form_fields' => array(),
8 'form_name' => '',
9 'role' => '', //used only for the register-form settings
10 'redirect_url' => '',
11 'logout_redirect_url' => '', //used only for the register-form settings
12 'automatic_login' => '', //used only for the register-form
13 'redirect_priority' => 'normal',
14 'ID' => null
15 );
16 public $args;
17
18
19 // Constructor method for the class
20 function __construct( $args ) {
21
22 /* we should stop the execution of the forms if they are in the wp_head hook because it should not be there.
23 SEO plugins can execute shortcodes in the auto generated descriptions */
24 if( apply_filters( 'wppb_dont_render_form_in_wp_head_hook', true ) ){
25 global $wp_current_filter;
26 if( !empty( $wp_current_filter ) && is_array( $wp_current_filter ) ){
27 foreach( $wp_current_filter as $filter ){
28 if( $filter == 'wp_head' )
29 return;
30 }
31 }
32 }
33
34 // Merge the input arguments and the defaults
35 $this->args = wp_parse_args( $args, $this->defaults );
36
37 /* set up the ID here if it is a multi form */
38 if( $this->args['form_name'] != 'unspecified' ){
39 $this->args['ID'] = Profile_Builder_Form_Creator::wppb_get_form_id_from_form_name( $this->args['form_name'], $this->args['form_type'] );
40 }
41
42 global $wppb_shortcode_on_front;
43 $wppb_shortcode_on_front = true;
44
45 global $wppb_register_edit_profile_shortcode_on_front;
46 $wppb_register_edit_profile_shortcode_on_front = true;
47
48 if( empty( $this->args['form_fields'] ) )
49 $this->args['form_fields'] = apply_filters( 'wppb_change_form_fields', get_option( 'wppb_manage_fields' ), $this->args );
50
51 if ( file_exists ( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' ) )
52 require_once( WPPB_PLUGIN_DIR.'/front-end/default-fields/default-fields.php' );
53
54 if ( defined( 'WPPB_PAID_PLUGIN_DIR' ) && file_exists ( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' ) )
55 require_once( WPPB_PAID_PLUGIN_DIR.'/front-end/extra-fields/extra-fields.php' );
56
57 $this->wppb_retrieve_custom_settings();
58
59 if( defined( 'WPPB_PAID_PLUGIN_DIR' ) && isset( $this->args['ajax'] ) && $this->args['ajax'] === 'true' && file_exists( WPPB_PAID_PLUGIN_DIR . '/features/ajax/assets/forms-ajax-validation.js' ) ) {
60 wp_enqueue_script( 'wppb-forms-ajax-validation-script', WPPB_PAID_PLUGIN_URL . 'features/ajax/assets/forms-ajax-validation.js', array( 'jquery' ), PROFILE_BUILDER_VERSION, true );
61 wp_localize_script( 'wppb-forms-ajax-validation-script', 'submitButtonData', array( 'processingText' => __( 'Processing...', 'profile-builder' ) ) );
62
63 // AJAX validation re-renders the form and needs editor assets only when a WYSIWYG field must be reinitialized
64 if( apply_filters( 'wppb_ajax_form_should_enqueue_editor', $this->wppb_form_has_wysiwyg_field( $this->args['form_fields'] ), $this->args, $this ) )
65 wp_enqueue_editor();
66 }
67
68 // NOTE: for Multisite, the capability we check against is `remove_users` because `edit_users` is on the do not allow on multisite list for current_user_can()
69 // current_user_can( 'edit_users' ) will only return true on a Multisite for Super Administrator Users
70 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) )
71 add_action( 'wppb_before_edit_profile_fields', array( 'Profile_Builder_Form_Creator', 'wppb_edit_profile_select_user_to_edit' ), 10, 4 );
72
73 //enqueue frontend scripts for forms
74 add_action( 'wp_footer', array( $this, 'wppb_frontend_scripts' ), 9999 );
75
76 //admin_edit_roles parameter
77 if( !empty( $this->args['admin_edit_roles'] ) ){
78 add_filter( 'wppb_edit_other_users_dropdown_query_args', array( $this, 'wppb_admin_edit_roles' ), 10, 2 );
79 }
80 }
81
82 /**
83 * @param $form_name The "slug" generated from the current Form Title
84 * @param $form_type the form type of the form: register, edit_profile
85 * @return null
86 */
87 static function wppb_get_form_id_from_form_name( $form_name, $form_type ){
88 global $wpdb;
89
90 if( empty( $form_name ) || empty( $form_type ) )
91 return null;
92
93 if( $form_type == 'edit_profile' ){
94 $post_type = 'wppb-epf-cpt';
95 }elseif( $form_type == 'register' ){
96 $post_type = 'wppb-rf-cpt';
97 }
98
99 $all_forms = $wpdb->get_results(
100 "
101 SELECT ID, post_title
102 FROM $wpdb->posts
103 WHERE post_status = 'publish'
104 AND post_type = '$post_type'
105 "
106 );
107
108 if( !empty( $all_forms ) ) {
109 foreach ($all_forms as $form) {
110 if( empty( $form->post_title ) )
111 $form->post_title = '(no title)';
112
113 if ($form_name == Wordpress_Creation_Kit_PB::wck_generate_slug($form->post_title)) {
114 return $form->ID;
115 }
116 }
117 }
118
119 return null;
120 }
121
122 function wppb_retrieve_custom_settings(){
123 $this->args['login_after_register'] = apply_filters( 'wppb_automatically_login_after_register', 'No' );
124 $this->args['redirect_activated'] = apply_filters( 'wppb_redirect_default_setting', '-' );
125 $this->args['redirect_url'] = apply_filters( 'wppb_redirect_default_location', ( $this->args['redirect_url'] != '' ) ? $this->args['redirect_url'] : '' );
126 $this->args['logout_redirect_url'] = apply_filters( 'wppb_logout_redirect_default_location', ( $this->args['logout_redirect_url'] != '' ) ? $this->args['logout_redirect_url'] : '' );
127 $this->args['redirect_delay'] = apply_filters( 'wppb_redirect_default_duration', 3 );
128
129 $wppb_general_settings = get_option( 'wppb_general_settings' );
130 $this->args['login_after_register'] = ( isset( $wppb_general_settings['automaticallyLogIn'] ) ? $wppb_general_settings['automaticallyLogIn'] : $this->args['login_after_register'] );
131
132 if ( !is_null( $this->args['ID'] ) ){
133 $meta_name = ( ( $this->args['form_type'] == 'register' ) ? 'wppb_rf_page_settings' : 'wppb_epf_page_settings' );
134
135 $page_settings = get_post_meta( $this->args['ID'], $meta_name, true );
136
137 if( !empty( $page_settings[0]['set-role'] ) ){
138 if( $page_settings[0]['set-role'] == 'default role' ){
139 $selected_role = trim( get_option( 'default_role' ) );
140 }
141 else
142 $selected_role = $page_settings[0]['set-role'];
143 }
144
145 $this->args['role'] = ( isset( $selected_role ) ? $selected_role : $this->args['role'] );
146 $this->args['login_after_register'] = ( isset( $page_settings[0]['automatically-log-in'] ) ? $page_settings[0]['automatically-log-in'] : $this->args['login_after_register'] );
147 $this->args['redirect_activated'] = ( isset( $page_settings[0]['redirect'] ) ? $page_settings[0]['redirect'] : $this->args['redirect_activated'] );
148 $this->args['redirect_url'] = ( ! empty( $page_settings[0]['url'] ) && $this->args['redirect_activated'] == 'Yes' && $this->args['redirect_priority'] != 'top' ? $page_settings[0]['url'] : $this->args['redirect_url'] );
149 $this->args['redirect_delay'] = ( isset( $page_settings[0]['display-messages'] ) && $this->args['redirect_activated'] == 'Yes' ? $page_settings[0]['display-messages'] : $this->args['redirect_delay'] );
150
151 if( isset( $page_settings[0]['ajax'] ) && !empty( $page_settings[0]['ajax'] ) )
152 $this->args['ajax'] = $page_settings[0]['ajax'];
153 }
154
155 // the 'automatic_login' shortcode parameter overwrites all other settings
156 $this->args['login_after_register'] = ( $this->args['automatic_login'] != '' ) ? $this->args['automatic_login'] : $this->args['login_after_register'];
157
158 if( !empty( $this->args['role'] ) ){
159 $role_in_arg = get_role( $this->args['role'] );
160 if( !empty( $role_in_arg->capabilities['manage_options'] ) || !empty( $role_in_arg->capabilities['remove_users'] ) ){
161 if( !current_user_can( 'manage_options' ) || !current_user_can( 'remove_users' ) ){
162 $this->args['role'] = get_option('default_role');
163 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_user_role_message', '<p class="alert wppb-error" id="wppb_form_general_message">'.__( 'The role of the created user set to the default role. Only an administrator can register a user with the role assigned to this form.', 'profile-builder').'</p>' ) );
164 }
165 }
166 }
167 }
168
169 /**
170 * Check whether the current form field list contains a WYSIWYG field
171 *
172 * @param array $form_fields The form fields configured for the current form.
173 * @return bool True when a WYSIWYG field is present, false otherwise.
174 */
175 function wppb_form_has_wysiwyg_field( $form_fields ){
176 if( empty( $form_fields ) || !is_array( $form_fields ) )
177 return false;
178
179 foreach( $form_fields as $field ){
180 if( empty( $field['field'] ) )
181 continue;
182
183 if( $field['field'] === 'WYSIWYG' )
184 return true;
185 }
186
187 return false;
188 }
189
190 function wppb_form_logic() {
191 if( isset( $this->args['form_type'] ) ) {
192 if( $this->args['form_type'] == 'register' ){
193 $registration = apply_filters ( 'wppb_register_setting_override', true );//used to be get_option( 'users_can_register' )
194
195 if ( !is_user_logged_in() ){
196 if ( !$registration )
197 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Only an administrator can add new users.', 'profile-builder')).'</p>' ) );
198
199 elseif ( $registration ){
200 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '' ) );
201 }
202
203 }else{
204 $current_user_capability = apply_filters ( 'wppb_registration_user_capability', 'create_users' );
205
206 if ( current_user_can( $current_user_capability ) && $registration )
207 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Users can register themselves or you can manually create users here.', 'profile-builder')). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.esc_attr(__( 'This message is only visible by administrators', 'profile-builder' )).'"/>' . '</p>' ) );
208
209 elseif ( current_user_can( $current_user_capability ) && !$registration )
210 $this->wppb_form_content( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.esc_html(__( 'Users cannot currently register themselves, but you can manually create users here.', 'profile-builder')). '<img src="'.WPPB_PLUGIN_URL.'assets/images/pencil_delete.png" title="'.esc_attr(__( 'This message is only visible by administrators', 'profile-builder' )).'"/>' . '</p>' ) );
211
212 elseif ( !current_user_can( $current_user_capability ) ){
213 global $user_ID;
214
215 $userdata = get_userdata( $user_ID );
216 $display_name = ( ( $userdata->data->display_name == '' ) ? $userdata->data->user_login : $userdata->data->display_name );
217
218 $wppb_general_settings = get_option( 'wppb_general_settings' );
219 if ( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) )
220 $display_name = $userdata->data->user_email;
221
222 if( empty( $this->args['logout_redirect_url'] ) ) {
223 $this->args['logout_redirect_url'] = get_permalink();
224 }
225
226 // CHECK FOR REDIRECT
227 $this->args['logout_redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], 'after_logout', $this->args['logout_redirect_url'], $userdata );
228 $this->args['logout_redirect_url'] = apply_filters( 'wppb_after_logout_redirect_url', $this->args['logout_redirect_url'] );
229
230 echo wp_kses_post( apply_filters( 'wppb_register_pre_form_message', '<p class="alert" id="wppb_register_pre_form_message">'.sprintf( __( "You are currently logged in as %1s. You don't need another account. %2s", 'profile-builder' ), '<a href="'.get_author_posts_url( $user_ID ).'" title="'.$display_name.'">'.$display_name.'</a>', '<a href="'.wp_logout_url( $this->args['logout_redirect_url'] ).'" title="'.__( 'Log out of this account.', 'profile-builder' ).'">'.__( 'Logout', 'profile-builder' ).' &raquo;</a>' ).'</p>', $user_ID ) );
231 }
232 }
233
234 }elseif ( $this->args['form_type'] == 'edit_profile' ){
235 if ( !is_user_logged_in() )
236 echo wp_kses_post( apply_filters( 'wppb_edit_profile_user_not_logged_in_message', '<p class="warning" id="wppb_edit_profile_user_not_logged_in_message">'.esc_html(__( 'You must be logged in to edit your profile.', 'profile-builder' )) .'</p>' ) );
237
238 elseif ( is_user_logged_in() )
239 $this->wppb_form_content( apply_filters( 'wppb_edit_profile_logged_in_user_message', '' ) );
240
241 }
242 }
243 }
244
245 // Function used to automatically log in a user after register if that option is set on yes in register form settings
246 function wppb_log_in_user( $redirect, $redirect_old, $user_id ) {
247 if( is_user_logged_in() ) {
248 return;
249 }
250
251 $wppb_general_settings = get_option( 'wppb_general_settings' );
252 $ec_bypass_forms = wppb_toolbox_get_settings( 'forms', 'ec-bypass' );
253
254 if ( is_array( $ec_bypass_forms ) && !empty( $_POST['form_name'] ) && in_array( sanitize_text_field( $_POST['form_name'] ), $ec_bypass_forms ) )
255 $should_bypass_ec = true;
256 else $should_bypass_ec = false;
257
258 if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) && !$should_bypass_ec ) {
259 return $redirect_old;
260 }
261
262 $user_id = absint( $user_id );
263
264 if ( ! $user_id || is_wp_error( $user_id ) ) {
265 return $redirect_old;
266 }
267
268 $user = get_userdata( $user_id );
269
270 if ( ! $user ) {
271 return $redirect_old;
272 }
273
274 if ( wppb_get_admin_approval_option_value() === 'yes' ) {
275 if( !empty( $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
276 foreach ($user->roles as $role) {
277 if ( in_array( $role, $wppb_general_settings['adminApprovalOnUserRole'] ) ) {
278 return $redirect_old;
279 }
280 }
281 }
282 else {
283 return $redirect_old;
284 }
285 }
286
287 /* define redirect location */
288 if( $this->args['redirect_activated'] == 'No' ) {
289 if( isset( $_POST['_wp_http_referer'] ) ) {
290 $redirect = esc_url_raw($_POST['_wp_http_referer']);
291 } else {
292 $redirect = home_url();
293 }
294 }
295
296 if( empty( $redirect ) )
297 $redirect = wppb_curpageurl();
298
299 $redirect = apply_filters( 'wppb_login_after_reg_redirect_url', $redirect, $this );
300
301 $redirect = add_query_arg( wppb_get_autologin_query_args( $user_id ), $redirect );
302
303 // CHECK FOR REDIRECT
304 if( $this->args['redirect_activated'] == 'No' || ( empty( $this->args['redirect_delay'] ) || $this->args['redirect_delay'] == '0' ) ) {
305 $redirect = wppb_build_redirect( $redirect, 0, 'register', $this->args );
306 } else {
307 $redirect = wppb_build_redirect( $redirect, $this->args['redirect_delay'], 'register', $this->args );
308 }
309 return $redirect;
310 }
311
312 /**
313 * Function to get redirect for Register and Edit Profile forms
314 *
315 * @param string $form_type - type of the form
316 * @param string $redirect_type - type of the redirect
317 * @param string $user - username or user email
318 * @param string $user_role - user Role
319 *
320 * @return string $redirect
321 */
322 function wppb_get_redirect( $form_type, $redirect_type, $user, $user_role ) {
323 $this->args['redirect_delay'] = apply_filters( 'wppb_'. $form_type .'_redirect_delay', $this->args['redirect_delay'], $user, $this->args );
324 if( $this->args['redirect_activated'] == '-' ) {
325 $this->args['redirect_url'] = wppb_get_redirect_url( $this->args['redirect_priority'], $redirect_type, $this->args['redirect_url'], $user, $user_role );
326 $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
327 } elseif( $this->args['redirect_activated'] == 'Yes' ) {
328 $redirect = wppb_build_redirect( $this->args['redirect_url'], $this->args['redirect_delay'], $form_type, $this->args );
329 } else {
330 $redirect = '';
331 }
332
333 return $redirect;
334 }
335
336 function wppb_form_content( $message ) {
337 $field_check_errors = array();
338
339 ob_start();
340
341 // check if the form is being displayed in the Elementor editor
342 // if true remove any messages
343 $is_elementor_edit_mode_or_divi_ajax = false;
344 if( class_exists ( '\Elementor\Plugin' ) ){
345 $is_elementor_edit_mode_or_divi_ajax = \Elementor\Plugin::$instance->editor->is_edit_mode();
346 $message= "";
347 }
348
349 if ( is_array( $_POST ) && array_key_exists( 'action', $_POST ) && $_POST['action'] === 'wppb_divi_extension_ajax' ) {
350 $is_elementor_edit_mode_or_divi_ajax = true;
351 }
352
353 if( !$is_elementor_edit_mode_or_divi_ajax && isset( $_REQUEST['action'], $_REQUEST['form_name'], $this->args['form_name'] ) && $_REQUEST['form_name'] === $this->args['form_name'] ) {
354 if( ! isset( $_POST[$this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field'] ) || ! wp_verify_nonce( sanitize_text_field( $_POST[$this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field'] ), 'wppb_verify_form_submission' ) ) {
355 echo '<span class="wppb-form-error wppb-error">'. esc_html(__( 'You are not allowed to do this.', 'profile-builder' )) . '</span>';
356
357 ob_end_flush();
358
359 return;
360 }
361
362 $_REQUEST = apply_filters( 'wppb_filter_form_request_data', $_REQUEST, $this->args );
363
364 $field_check_errors = $this->wppb_test_required_form_values( $_REQUEST );
365 if( empty( $field_check_errors ) ) {
366
367 do_action( 'wppb_before_saving_form_values',$_REQUEST, $this->args );
368
369 // we only have a $user_id on default registration (no email confirmation, no multisite)
370 $user_id = $this->wppb_save_form_values( $_REQUEST );
371
372 do_action( 'wppb_after_saving_form_values',$_REQUEST, $this->args );
373
374 if( ( isset( $_SERVER['REQUEST_METHOD'] ) && 'POST' === $_SERVER['REQUEST_METHOD'] ) && ( isset( $_POST['action'] ) && $_POST['action'] === $this->args['form_type'] ) ) {
375
376 $form_message_tpl_start = apply_filters( 'wppb_form_message_tpl_start', '<p class="alert wppb-success" id="wppb_form_general_message">' );
377 $form_message_tpl_end = apply_filters( 'wppb_form_message_tpl_end', '</p>' );
378
379 if( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $_POST['custom_field_user_role'] ) ) {
380 $user_role = sanitize_text_field($_POST['custom_field_user_role']);
381 } elseif( ! current_user_can( 'manage_options' ) && $this->args['form_type'] != 'edit_profile' && isset( $this->args['role'] ) ) {
382 $user_role = $this->args['role'];
383 } else {
384 $user_role = NULL;
385 }
386
387 if( isset( $_POST['username'] ) && sanitize_user( $_POST['username'] ) != '' ) {
388 $account_name = sanitize_user( $_POST['username'] );
389 } elseif( isset( $_POST['email'] ) && ( sanitize_email( $_POST['email'] ) != '' ) ) {
390 $account_name = sanitize_email( $_POST['email'] );
391 }else{
392 /* we are in the edit form with no username or email field */
393 $current_user = wp_get_current_user();
394 if( !empty( $current_user ) )
395 $account_name = $current_user->user_login;
396 }
397
398 if( $this->args['form_type'] == 'register' ) {
399 // ec = email confirmation setting
400 // aa = admin approval setting
401 $wppb_general_settings = get_option( 'wppb_general_settings', 'false' );
402 if ( $wppb_general_settings ) {
403 if( !empty( $wppb_general_settings['emailConfirmation'] ) && apply_filters( 'wppb_email_confirmation_on_register', $wppb_general_settings['emailConfirmation'], $_POST ) == 'yes' )
404 $wppb_email_confirmation = $wppb_general_settings['emailConfirmation'];
405 else
406 $wppb_email_confirmation = 'no';
407
408
409 $wppb_admin_approval = wppb_get_admin_approval_option_value();
410
411 $account_management_settings = 'ec-' . $wppb_email_confirmation . '_' . 'aa-' . $wppb_admin_approval;
412 } else {
413 $account_management_settings = 'ec-no_aa-no';
414 }
415
416 switch( $account_management_settings ) {
417 case 'ec-no_aa-no':
418 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1\$s has been successfully created!", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
419 break;
420 case 'ec-yes_aa-no':
421 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
422 break;
423 case 'ec-no_aa-yes':
424 if( current_user_can( 'delete_users' ) ) {
425 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "The account %1\$s has been successfully created!", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
426 } else {
427 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, an administrator has to approve it. You will be notified via email.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
428 }
429 break;
430 case 'ec-yes_aa-yes':
431 $wppb_register_success_message = apply_filters( 'wppb_register_success_message', sprintf( __( "Before you can access your account %1s, you need to confirm your email address. Please check your inbox and click the activation link.", 'profile-builder' ), $account_name ), $account_name ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
432 break;
433 }
434
435 // CHECK FOR REDIRECT
436 $redirect = $this->wppb_get_redirect( 'register', 'after_registration', $account_name, $user_role );
437
438 // using case-insensitive string comparison to allow for both 'Yes' and 'yes'
439 if( strcasecmp($this->args['login_after_register'], 'Yes') == 0 ) {
440 $redirect = $this->wppb_log_in_user( $this->args['redirect_url'], $redirect, $user_id );
441 }
442
443 echo $form_message_tpl_start . wp_kses_post( $wppb_register_success_message ) . $form_message_tpl_end . $redirect; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
444
445 ob_end_flush();
446
447 //action hook after registration success
448 do_action( 'wppb_register_success', $_REQUEST, $this->args['form_name'], $user_id );
449 return;
450 } elseif( $this->args['form_type'] == 'edit_profile' ) {
451 // CHECK FOR REDIRECT
452 $redirect = $this->wppb_get_redirect( 'edit_profile', 'after_edit_profile', $account_name, $user_role );
453
454 echo $form_message_tpl_start . apply_filters( 'wppb_edit_profile_success_message', esc_html(__( 'Your profile has been successfully updated!', 'profile-builder' )) ) . $form_message_tpl_end . $redirect; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
455
456 //action hook after edit profile success
457 do_action( 'wppb_edit_profile_success', $_REQUEST, $this->args['form_name'], $user_id );
458
459 if( apply_filters( 'wppb_no_form_after_profile_update', false ) ){
460 ob_end_flush();
461 return;
462 }
463 }
464
465 }
466
467 }else
468 echo $message. wp_kses_post( apply_filters( 'wppb_general_top_error_message', '<p id="wppb_form_general_message" class="wppb-error">'.esc_html(__( 'There was an error in the submitted form', 'profile-builder' )).'</p>' ) ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped above */
469
470 }else
471 echo $message; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
472
473 // use this action hook to add extra content before the register form
474 do_action( 'wppb_before_'.$this->args['form_type'].'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'], $is_elementor_edit_mode_or_divi_ajax );
475
476 $wppb_user_role_class = '';
477 if( is_user_logged_in() ) {
478 $wppb_user = wp_get_current_user();
479
480 if( $wppb_user && isset( $wppb_user->roles ) ) {
481 foreach( $wppb_user->roles as $wppb_user_role ) {
482 $wppb_user_role_class .= ' wppb-user-role-'. $wppb_user_role;
483 }
484 }
485 } else {
486 $wppb_user_role_class = ' wppb-user-logged-out';
487 }
488 $wppb_user_role_class = apply_filters( 'wppb_user_role_form_class', $wppb_user_role_class );
489
490 /* set up form id */
491 $wppb_form_id = '';
492 if( $this->args['form_type'] == 'register' )
493 $wppb_form_id = 'wppb-register-user';
494 elseif( $this->args['form_type'] == 'edit_profile' )
495 $wppb_form_id = 'wppb-edit-user';
496 if( isset($this->args['form_name']) && $this->args['form_name'] != "unspecified" )
497 $wppb_form_id .= '-' . $this->args['form_name'];
498
499 /* set up form class */
500 $wppb_form_class = 'wppb-user-forms';
501 if( $this->args['form_type'] == 'register' )
502 $wppb_form_class .= ' wppb-register-user';
503 elseif( $this->args['form_type'] == 'edit_profile' )
504 $wppb_form_class .= ' wppb-edit-user';
505 $wppb_form_class .= $wppb_user_role_class;
506
507 ?>
508 <form enctype="multipart/form-data" method="post" id="<?php echo esc_attr( apply_filters( 'wppb_form_id', $wppb_form_id, $this ) ); ?>" class="<?php echo esc_attr( apply_filters( 'wppb_form_class', $wppb_form_class, $this ) ) . ( $this->args['ajax'] == 'true' ? ' wppb-ajax-form' : ''); ?>" action="<?php echo esc_url( apply_filters( 'wppb_form_action', wppb_curpageurl(), $this->args ) ); ?>">
509 <?php
510 do_action( 'wppb_form_args_before_output', $this->args );
511 $this->args = apply_filters( 'wppb_filter_form_args_before_output', $this->args );
512
513 echo apply_filters( 'wppb_before_form_fields', '<ul>', $this->args['form_type'], $this->args['ID'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
514 echo $this->wppb_output_form_fields( $_REQUEST, $field_check_errors, $this->args['form_fields'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
515 echo apply_filters( 'wppb_after_form_fields', '</ul>', $this->args['form_type'], $this->args['ID'], $_REQUEST ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
516
517 echo apply_filters( 'wppb_before_send_credentials_checkbox', '<ul>', $this->args['form_type'], $this->args['ID'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
518 $this->wppb_add_send_credentials_checkbox( $_REQUEST, $this->args['form_type'] );
519 echo apply_filters( 'wppb_after_send_credentials_checkbox', '</ul>', $this->args['form_type'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
520
521 echo apply_filters( 'wppb_form_bottom', '</ul>', $this->args['form_type'], $this->args['ID'], $_REQUEST ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */
522
523 $wppb_form_submit_extra_attr = apply_filters( 'wppb_form_submit_extra_attr', '', $this->args['form_type'], $this->args['ID'] );
524 ?>
525 <p class="form-submit" <?php echo $wppb_form_submit_extra_attr; /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */ ?> >
526 <?php
527 if( $this->args['form_type'] == 'register' )
528 $button_name = ( current_user_can( 'create_users' ) ? __( 'Add User', 'profile-builder' ) : __( 'Register', 'profile-builder' ) );
529
530 elseif( $this->args['form_type'] == 'edit_profile' )
531 $button_name = __( 'Update', 'profile-builder' );
532 ?>
533 <?php do_action( 'wppb_form_before_submit_button', $this->args ); ?>
534 <input name="<?php echo esc_attr( $this->args['form_type'] ); ?>" type="submit" id="<?php echo esc_attr( $this->args['form_type'] ); ?>" class="<?php echo esc_attr( apply_filters( 'wppb_'. $this->args['form_type'] .'_submit_class', "submit button" ) );?>" value="<?php echo esc_attr( apply_filters( 'wppb_'. $this->args['form_type'] .'_button_name', $button_name, $this->args['form_name'] ) ); ?>" <?php echo apply_filters( 'wppb_form_submit_button_extra_attributes', '', $this->args['form_type'] ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */?>/>
535 <input name="redirect_to" type="hidden" value="<?php echo esc_attr( $this->args['redirect_url'] ); ?>" />
536 <?php do_action( 'wppb_form_after_submit_button', $this->args ); ?>
537 <input name="action" type="hidden" id="action" value="<?php echo esc_attr( $this->args['form_type'] ); ?>" />
538 <input name="form_name" type="hidden" id="form_name" value="<?php echo esc_attr( $this->args['form_name'] ); ?>" />
539 <input name="form_id" type="hidden" id="form_id" value="<?php echo esc_attr( $this->args['ID'] ); ?>" />
540 <?php
541 $wppb_module_settings = get_option( 'wppb_module_settings' );
542
543 if( isset( $wppb_module_settings['wppb_customRedirect'] ) && $wppb_module_settings['wppb_customRedirect'] == 'show' ) {
544 if( isset( $_POST['wppb_referer_url'] ) )
545 $referer = esc_url_raw( $_POST['wppb_referer_url'] );
546 elseif( isset( $_SERVER['HTTP_REFERER'] ) )
547 $referer = esc_url_raw( $_SERVER['HTTP_REFERER'] );
548 else
549 $referer = '';
550
551 echo '<input type="hidden" name="wppb_referer_url" value="'. esc_attr( $referer ).'"/>';
552 }
553 ?>
554 </p><!-- .form-submit -->
555 <?php wp_nonce_field( 'wppb_verify_form_submission', $this->args['form_type'].'_'. $this->args['form_name'] .'_nonce_field' ); ?>
556 </form>
557 <?php
558 // use this action hook to add extra content after the register form
559 do_action( 'wppb_after_'. $this->args['form_type'] .'_fields', $this->args['form_name'], $this->args['ID'], $this->args['form_type'] );
560
561 $form_content = ob_get_clean();
562
563 echo apply_filters( 'wppb_' . $this->args['form_type'] . '_form_content', $form_content ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
564 }
565
566 function wppb_output_form_fields( $global_request, $field_check_errors, $form_fields, $called_from = NULL, $is_repeater_group = false ){
567 $wppb_generalSettings = get_option( 'wppb_general_settings' );
568 $output_fields = '';
569
570 if( !empty( $form_fields ) ){
571 $output_fields .= apply_filters( 'wppb_output_before_first_form_field', '', $this->args['ID'], $this->args['form_type'], $form_fields, $called_from );
572 foreach( $form_fields as $field ){
573 $error_var = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? ' wppb-field-error' : '' );
574 $specific_message = ( ( array_key_exists( $field['id'], $field_check_errors ) ) ? $field_check_errors[$field['id']] : '' );
575
576 $display_field = apply_filters( 'wppb_output_display_form_field', true, $field, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
577
578 if( $display_field == false )
579 continue;
580
581 $css_class = apply_filters( 'wppb_field_css_class', 'wppb-form-field wppb-'. Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ) .$error_var, $field, $error_var );
582 $output_fields .= apply_filters( 'wppb_output_before_form_field', '<li class="'. $css_class .'" id="wppb-form-element-'. $field['id'] .'">', $field, $error_var, $this->args['role'], $this->args['ID'], $this->args['form_type']);
583
584 $render_field = true;
585 if( wppb_conditional_fields_exists() && isset( $wppb_generalSettings['conditional_fields_ajax'] ) ){
586 if($wppb_generalSettings['conditional_fields_ajax'] === 'yes' && isset($field['conditional-logic-enabled']) && $field['conditional-logic-enabled'] === 'yes') {
587 $render_field = false;
588 }
589 }
590
591 if( $render_field ){
592 $output_fields .= apply_filters('wppb_output_form_field_' . Wordpress_Creation_Kit_PB::wck_generate_slug($field['field']), '', $this->args['form_type'], $field, $this->wppb_get_desired_user_id(), $field_check_errors, $global_request, $this->args['role'], $this);
593 $output_fields .= apply_filters('wppb_output_specific_error_message', $specific_message);
594 }
595
596 $output_fields .= apply_filters( 'wppb_output_after_form_field', '</li>', $field, $this->args['ID'], $this->args['form_type'], $called_from );
597 }
598
599 if ( !$is_repeater_group ) {
600 $output_fields .= apply_filters('wppb_output_after_last_form_field', '', $this->args['ID'], $this->args['form_type'], $called_from);
601 }
602 }
603
604 return apply_filters( 'wppb_output_fields_filter', $output_fields );
605 }
606
607
608 function wppb_add_send_credentials_checkbox ( $request_data, $form ){
609 if ( $form == 'edit_profile' )
610 echo '';
611
612 else{
613 $checkbox = apply_filters( 'wppb_send_credentials_checkbox_logic', '<li class="wppb-form-field wppb-send-credentials-checkbox"><label for="send_credentials_via_email"><input id="send_credentials_via_email" type="checkbox" name="send_credentials_via_email" value="sending"'.( ( isset( $request_data['send_credentials_via_email'] ) && ( $request_data['send_credentials_via_email'] == 'sending' ) ) ? ' checked' : '' ).'/>'.esc_html__( 'Send these credentials via email.', 'profile-builder').'</label></li>', $request_data, $form );
614
615 $wppb_general_settings = get_option( 'wppb_general_settings' );
616 echo ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ? '' : $checkbox ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ /* properly escaped when created */
617 }
618 }
619
620
621 function wppb_test_required_form_values( $global_request ){
622 $output_field_errors = array();
623 $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'global_request' => $global_request, 'context' => 'validate_frontend', 'form_type' => $this->args['form_type'], 'role' => $this->args['role'], 'user_id' => $this->wppb_get_desired_user_id() ) );
624 if( !empty( $form_fields ) ){
625 foreach( $form_fields as $field ){
626 $error_for_field = apply_filters( 'wppb_check_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), '', $field, $global_request, $this->args['form_type'], $this->args['role'], $this->wppb_get_desired_user_id() );
627
628 if( !empty( $error_for_field ) )
629 $output_field_errors[$field['id']] = '<span class="wppb-form-error">' . $error_for_field . '</span>';
630 }
631 }
632
633 return apply_filters( 'wppb_output_field_errors_filter', $output_field_errors, $this->args['form_fields'], $global_request, $this->args['form_type'] );
634 }
635
636 function wppb_save_form_values( $global_request ){
637 $user_id = $this->wppb_get_desired_user_id();
638 $userdata = apply_filters( 'wppb_build_userdata', array(), $global_request, $this->args );
639 $new_user_signup = false;
640
641 $wppb_general_settings = get_option( 'wppb_general_settings' );
642
643 if( $this->args['form_type'] == 'register' ){
644
645 $result = $this->wppb_register_user( $global_request, $userdata );
646 $user_id = $result['user_id'];
647 $userdata = $result['userdata'];
648 $new_user_signup = $result['new_user_signup'];
649
650 }elseif( $this->args['form_type'] == 'edit_profile' ){
651 if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
652 $user_info = get_userdata( $user_id );
653 $userdata['user_login'] = $user_info->user_login;
654 }
655
656 $userdata['ID'] = $this->wppb_get_desired_user_id();
657 $userdata = wp_unslash( $userdata );
658 /* if the user changes his password then we can't send it to the wp_update_user() function or
659 the user will be logged out and won't be logged in again because we call wp_update_user() after
660 the headers were sent( in the content as a shortcode ) */
661 if( isset( $userdata['user_pass'] ) && !empty( $userdata['user_pass'] ) ){
662 unset($userdata['user_pass']);
663 }
664
665 if( isset( $userdata['role'] ) && is_array( $userdata['role'] ) ) {
666 $user_data = get_userdata( $user_id );
667 if( $user_data ) {
668 $user_data->remove_all_caps();
669
670 foreach ($userdata['role'] as $role) {
671 if ($role !== 'administrator' || $role !== 'super-admin')//make sure this doesn't happen for any reason
672 $user_data->add_role($role);
673 }
674 }
675
676 unset( $userdata['role'] );
677 }
678
679 wp_update_user( $userdata );
680 }
681
682 if( !empty( $this->args['form_fields'] ) && !$new_user_signup ){
683 foreach( $this->args['form_fields'] as $field ){
684 if( apply_filters( 'wppb_pre_save_form_field', true, $field, $user_id, $global_request, $this->args['form_type'] ) )
685 do_action( 'wppb_save_form_field', $field, $user_id, $global_request, $this->args['form_type'] );
686 }
687
688 if ( $this->args['form_type'] == 'register' ){
689 if ( !is_wp_error( $user_id ) ){
690 $wppb_general_settings = get_option( 'wppb_general_settings' );
691 if( ( isset( $global_request['send_credentials_via_email'] ) && ( $global_request['send_credentials_via_email'] == 'sending' ) ) || apply_filters( 'wppb_register_send_credentials_via_email', false, $user_id, $this->args ) )
692 $send_credentials_via_email = 'sending';
693 else
694 $send_credentials_via_email = '';
695
696 wppb_notify_user_registration_email( get_bloginfo( 'name' ), ( isset( $userdata['user_login'] ) ? trim( $userdata['user_login'] ) : trim( $userdata['user_email'] ) ), trim( $userdata['user_email'] ), $send_credentials_via_email, trim( $userdata['user_pass'] ), ( wppb_get_admin_approval_option_value() === 'yes' ? 'yes' : 'no' ) );
697 }
698 }
699 }
700 return $user_id;
701 }
702
703 function wppb_register_user( $global_request, $userdata ){
704 $wppb_module_settings = get_option( 'wppb_module_settings' );
705 $wppb_general_settings = get_option( 'wppb_general_settings' );
706 $user_id = null;
707 $new_user_signup = false;
708
709 if( isset( $wppb_general_settings['loginWith'] ) && ( $wppb_general_settings['loginWith'] == 'email' ) ){
710 $userdata['user_login'] = apply_filters( 'wppb_generated_random_username', Wordpress_Creation_Kit_PB::wck_generate_slug( trim( $userdata['user_email'] ) ), $userdata['user_email'] );
711 }
712
713 /* filter so we can bypass Email Confirmation on register */
714 if ( isset( $wppb_general_settings['emailConfirmation'] ) )
715 $wppb_general_settings['emailConfirmation'] = apply_filters( 'wppb_email_confirmation_on_register', $wppb_general_settings['emailConfirmation'], $global_request );
716
717 if ( isset( $wppb_general_settings['emailConfirmation'] ) && ( $wppb_general_settings['emailConfirmation'] == 'yes' ) ){
718 $new_user_signup = true;
719
720 $userdata = $this->wppb_add_custom_field_values( $global_request, $userdata, $this->args['form_fields'] );
721
722 if( ! isset( $userdata['role'] ) ) {
723 $userdata['role'] = $this->args['role'];
724 }
725
726 $userdata['user_pass'] = wp_hash_password( $userdata['user_pass'] );
727
728 if( is_multisite() ){
729 /* since version 2.0.7 add this meta so we know on what blog the user registered */
730 $userdata['registered_for_blog_id'] = get_current_blog_id();
731 $userdata = wp_unslash( $userdata );
732 }
733
734 $userdata['form_name'] = $this->args['form_name'];
735
736 wppb_signup_user( $userdata['user_login'], $userdata['user_email'], $this->args['login_after_register'], $userdata );
737 }else{
738 if( ! isset( $userdata['role'] ) ) {
739 $userdata['role'] = $this->args['role'];
740 }
741
742 $userdata = wp_unslash( $userdata );
743
744 // change User Registered date and time according to timezone selected in WordPress settings
745 $wppb_get_date = wppb_get_register_date();
746
747 if( isset( $wppb_get_date ) ) {
748 $userdata['user_registered'] = $wppb_get_date;
749 }
750
751 // insert user to database
752 $user_id = wp_insert_user( $userdata );
753 }
754
755 return array( 'userdata' => $userdata, 'user_id' => $user_id, 'new_user_signup' => $new_user_signup );
756 }
757
758 function wppb_add_custom_field_values( $global_request, $meta, $form_properties ){
759 $form_fields = apply_filters( 'wppb_form_fields', $this->args['form_fields'], array( 'meta' => $meta, 'global_request' => $global_request, 'context' => 'user_signup' ) );
760 if( !empty( $form_fields ) ){
761 foreach( $form_fields as $field ){
762 if( !empty( $field['meta-name'] ) && ( ! isset( $field['field'] ) || 'Default - Biographical Info' !== $field['field'] ) ){
763 if ( ! array_key_exists( $field['meta-name'], $global_request ) ) {
764 $posted_value = '';
765 } elseif( in_array( $field['field'], array( 'URL' ), true ) ) {
766 $posted_value = esc_url_raw( $global_request[ $field['meta-name'] ] );
767 } elseif( in_array( $field['field'], array( 'Textarea' ), true ) ){
768 $meta_value = sanitize_textarea_field( wp_unslash( $global_request[ $field['meta-name'] ] ) );
769
770 if( apply_filters( 'wppb_form_field_textarea_escape_on_save', false ) )
771 $meta_value = esc_textarea( $meta_value );
772
773 $posted_value = $meta_value;
774 } elseif ( is_array( $global_request[ $field['meta-name'] ] ) ) {
775 $posted_value = array_map( 'sanitize_text_field', $global_request[ $field['meta-name'] ] );
776 } else {
777 $posted_value = sanitize_text_field( $global_request[ $field['meta-name'] ] );
778 }
779
780 $meta[$field['meta-name']] = apply_filters( 'wppb_add_to_user_signup_form_field_'.Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
781
782 }
783
784 if ( isset( $field['field'] ) && 'Default - Biographical Info' === $field['field'] ) {
785 $posted_value = '';
786 if ( array_key_exists( 'description', $global_request ) ) {
787 $posted_value = wppb_sanitize_default_biographical_info_from_request( $global_request );
788 }
789 $meta['description'] = apply_filters( 'wppb_add_to_user_signup_form_field_' . Wordpress_Creation_Kit_PB::wck_generate_slug( $field['field'] ), $posted_value, $field, $global_request );
790 }
791 }
792 }
793
794 return apply_filters( 'wppb_add_to_user_signup_form_meta', $meta, $global_request, $this->args['role'] );
795 }
796
797 /**
798 * Function that returns the id for the current logged in user or for edit profile forms for administrator it can return the id of a selected user
799 */
800 function wppb_get_desired_user_id(){
801 if( $this->args['form_type'] == 'edit_profile' ){
802 //only admins
803 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) ){
804 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) ){
805 return absint( $_GET['edit_user'] );
806 }
807 }
808 }
809
810 return get_current_user_id();
811 }
812
813 static function wppb_edit_profile_select_user_to_edit( $form_name, $id, $form_type, $is_elementor_edit_mode_or_divi_ajax ){
814
815 $display_edit_users_dropdown = apply_filters( 'wppb_display_edit_other_users_dropdown', true, $form_name );
816 if( !$display_edit_users_dropdown || $is_elementor_edit_mode_or_divi_ajax )
817 return;
818
819 /* add a hard cap: if we have more than 5000 users don't display the dropdown for performance considerations */
820 $user_count = count_users();
821 if( $user_count['total_users'] > apply_filters( 'wppb_edit_other_users_count_limit', 5000 ) )
822 return;
823
824 if( isset( $_GET['edit_user'] ) && ! empty( $_GET['edit_user'] ) )
825 $selected = absint( $_GET['edit_user'] );
826 else
827 $selected = get_current_user_id();
828
829 $query_args = array(
830 'fields' => array( 'ID', 'user_login', 'display_name' ),
831 'role' => apply_filters( 'wppb_edit_profile_user_dropdown_role', '', $form_name ),
832 'role__not_in' => array( 'administrator' ),
833 'orderby' => array( 'display_name', 'user_login' ),
834 );
835
836 $users = get_users( apply_filters( 'wppb_edit_other_users_dropdown_query_args', $query_args, $form_name ) );
837
838 if ( apply_filters( 'wppb_edit_other_users_dropdown_user_list_excludes_admin_approval', false ) &&
839 wppb_get_admin_approval_option_value() === 'yes' ) {
840 foreach ( $users as $key => $user ) {
841 if ( wp_get_object_terms( $user->ID, 'user_status' ) ) {
842 unset( $users[ $key ] );
843 }
844 }
845 }
846
847 if( !empty( $users ) ) {
848
849 /* turn it in a select2 */
850 wp_enqueue_script( 'wppb_select2_js', WPPB_PLUGIN_URL .'assets/js/select2/select2.min.js', array( 'jquery' ), PROFILE_BUILDER_VERSION );
851 wp_enqueue_style( 'wppb_select2_css', WPPB_PLUGIN_URL .'assets/css/select2/select2.min.css', array(), PROFILE_BUILDER_VERSION );
852 ?>
853 <form method="GET" action="" id="select_user_to_edit_form">
854 <p class="wppb-form-field">
855 <label for="edit_user"><?php esc_html_e('User to edit:', 'profile-builder') ?></label>
856 <select id="wppb-<?php echo !empty( $form_name ) ? esc_attr( $form_name ).'-' : ''; ?>user-to-edit" class="wppb-user-to-edit" name="edit_user">
857 <option value=""><?php echo esc_html__( 'Select User', 'profile-builder' ); ?></option>
858 <?php
859 foreach( $users as $user ){
860 ?>
861 <option value="<?php echo esc_url( add_query_arg( array( 'edit_user' => $user->ID ) ) ); ?>" <?php selected( $selected, $user->ID ); ?>>
862 <?php echo esc_html( apply_filters( 'wppb_edit_other_users_display_name', $user->display_name, $user ) ); ?>
863 </option>
864 <?php
865 }
866 ?>
867 </select>
868 </p>
869 </form>
870 <?php
871 }
872 else{
873 echo '<p id="wppb-no-other-users-to-edit">'. esc_html( apply_filters( 'wppb_no_users_to_edit_message', __( 'There are no other users to edit', 'profile-builder' ) ) ).'</p>';
874 }
875 }
876
877 public function wppb_admin_edit_roles( $query_args, $form_name ){
878 $admin_edit_roles = $this->args['admin_edit_roles'];
879
880 $admin_edit_roles = array_filter( array_map( 'trim', explode( ',', (string) $admin_edit_roles ) ) );
881 $admin_edit_roles = array_map( 'sanitize_key', $admin_edit_roles );
882 $admin_edit_roles = array_values( array_unique( $admin_edit_roles ) );
883
884 global $wp_roles;
885 if ( ! $wp_roles ) {
886 $wp_roles = wp_roles();
887 }
888
889 $roles = array();
890 foreach ( $admin_edit_roles as $admin_edit_role ){
891 if ( isset( $wp_roles->roles[$admin_edit_role] ) )
892 $roles[] = $admin_edit_role;
893 }
894
895 if ( empty( $roles ) ) {
896 return $query_args;
897 }
898
899 unset( $query_args['role'] );
900 $query_args['role__in'] = $roles;
901
902 return $query_args;
903
904 }
905
906 static function wppb_frontend_scripts(){
907
908 wp_register_script( 'wppb_front_end_script', WPPB_PLUGIN_URL. 'assets/js/script-front-end.js', array('jquery'), PROFILE_BUILDER_VERSION, true );
909
910 $wppb_toolbox_forms_settings = get_option( 'wppb_toolbox_forms_settings' );
911 if( isset( $wppb_toolbox_forms_settings[ 'disable-automatic-scrolling' ] ) ){
912 wp_add_inline_script( 'wppb_front_end_script', "var wppb_disable_automatic_scrolling = 1;", 'before' );
913 }
914
915 wp_enqueue_script( 'wppb_front_end_script' );
916 wp_print_scripts( 'wppb_front_end_script' );
917
918 if( ( !is_multisite() && current_user_can( 'edit_users' ) ) || ( is_multisite() && ( current_user_can( 'remove_users' ) || current_user_can( 'manage_options' ) ) ) ){
919 wp_enqueue_script( 'wppb_select_user_to_edit_js', WPPB_PLUGIN_URL. 'assets/js/select-user-to-edit.js', array('jquery'), PROFILE_BUILDER_VERSION, true );
920 wp_print_scripts( 'wppb_select_user_to_edit_js' );
921 }
922
923 }
924
925 /**
926 * Handle toString method
927 *
928 * @since 2.0
929 *
930 * @return string $html html for the form.
931 */
932 public function __toString() {
933 try {
934 ob_start();
935 $this->wppb_form_logic();
936 $html = ob_get_clean();
937 return "{$html}";
938 } catch (Exception $exception) {
939 return __( 'Something went wrong. Please try again!', 'profile-builder');
940 }
941 }
942 }
943
944 /* set action for automatic login after registration */
945 add_action( 'init', 'wppb_autologin_after_registration' );
946 function wppb_autologin_after_registration(){
947 if( isset( $_GET['autologin'] ) && isset( $_REQUEST['_wpnonce'] ) ){
948 $nonce = sanitize_text_field( wp_unslash( $_REQUEST['_wpnonce'] ) );
949 $uid = wppb_get_autologin_user_id( $nonce, false );
950
951 $arr_params = array( 'autologin', 'uid', '_wpnonce' );
952 $current_page_url = remove_query_arg( $arr_params, wppb_curpageurl() );
953
954 if ( ! $uid || ! get_userdata( $uid ) || ! wppb_verify_autologin_nonce( $nonce, $uid ) ) {
955 wp_redirect( $current_page_url );
956 exit;
957 }
958
959 wppb_get_autologin_user_id( $nonce, true );
960 wp_set_auth_cookie( $uid );
961 wp_redirect( $current_page_url );
962 exit;
963 }
964 }
965