| @@ -49,29 +49,57 @@ | ||
| 49 | 49 | $user_id = absint( $_GET['edit_user'] ); |
| 50 | 50 | } |
| 51 | 51 | } |
| 52 | 52 | |
| 53 | + $session_token = ''; | |
| 54 | + | |
| 53 | 55 | if( !isset( $_GET['edit_user'] ) ) { |
| 56 | + // Keep the current session token before clearing auth cookies. Some plugins remove the logged-in | |
| 57 | + // - cookie from $_COOKIE on clear_auth_cookie, so wp_get_session_token() can be empty later in this request | |
| 58 | + $logged_in_cookie = wp_parse_auth_cookie('', 'logged_in'); | |
| 59 | + /** This filter is documented in wp-includes/pluggable.php */ | |
| 60 | + $default_cookie_life = apply_filters('auth_cookie_expiration', (2 * DAY_IN_SECONDS), $user_id, false); | |
| 61 | + $remember = false; | |
| 62 | + if ( is_array( $logged_in_cookie ) ) { | |
| 63 | + if ( isset( $logged_in_cookie['token'] ) ) { | |
| 64 | + $session_token = $logged_in_cookie['token']; | |
| 65 | + } | |
| 66 | + | |
| 67 | + if ( isset( $logged_in_cookie['expiration'] ) ) { | |
| 68 | + // If expiration is greater than the default, the user checked 'Remember Me' when they logged in | |
| 69 | + $remember = ( ( $logged_in_cookie['expiration'] - time() ) > $default_cookie_life ); | |
| 70 | + } | |
| 71 | + } | |
| 72 | + | |
| 54 | 73 | wp_clear_auth_cookie(); |
| 55 | 74 | /* set the new password for the user */ |
| 56 | 75 | wp_set_password($_POST['passw1'], $user_id);//phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized |
| 57 | - // Here we calculate the expiration length of the current auth cookie and compare it to the default expiration. | |
| 58 | - // If it's greater than this, then we know the user checked 'Remember Me' when they logged in. | |
| 59 | - $logged_in_cookie = wp_parse_auth_cookie('', 'logged_in'); | |
| 60 | - /** This filter is documented in wp-includes/pluggable.php */ | |
| 61 | - $default_cookie_life = apply_filters('auth_cookie_expiration', (2 * DAY_IN_SECONDS), $user_id, false); | |
| 62 | - $remember = (($logged_in_cookie['expiration'] - time()) > $default_cookie_life); | |
| 63 | 76 | |
| 64 | - wp_set_auth_cookie($user_id, $remember, '', wp_get_session_token() ); | |
| 77 | + wp_set_auth_cookie($user_id, $remember, '', $session_token ); | |
| 78 | + if ( ! empty( $session_token ) ) { | |
| 79 | + $cookie_life = $remember ? 14 * DAY_IN_SECONDS : 2 * DAY_IN_SECONDS; | |
| 80 | + /** This filter is documented in wp-includes/pluggable.php */ | |
| 81 | + $cookie_expiration = time() + apply_filters( 'auth_cookie_expiration', $cookie_life, $user_id, $remember ); | |
| 82 | + | |
| 83 | + // wp_set_auth_cookie() sends the new browser cookie, but it does not repopulate $_COOKIE | |
| 84 | + // - restore it for the remaining form processing, including the second nonce verification | |
| 85 | + $_COOKIE[ LOGGED_IN_COOKIE ] = wp_generate_auth_cookie( $user_id, $cookie_expiration, 'logged_in', $session_token ); | |
| 86 | + } | |
| 87 | + | |
| 88 | + wp_set_current_user( $user_id ); | |
| 89 | + do_action( 'wppb_edit_profile_password_changed', $user_id ); | |
| 65 | 90 | } |
| 66 | 91 | else{ |
| 67 | 92 | wp_set_password($_POST['passw1'], $user_id); //phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized |
| 93 | + do_action( 'wppb_edit_profile_password_changed', $user_id ); | |
| 68 | 94 | } |
| 69 | 95 | |
| 70 | 96 | /* log out of other sessions or all sessions if the admin is editing the profile */ |
| 71 | 97 | $sessions = WP_Session_Tokens::get_instance( $user_id ); |
| 72 | - if ( $user_id === get_current_user_id() ) { | |
| 73 | - $sessions->destroy_others( wp_get_session_token() ); | |
| 98 | + if ( $user_id === get_current_user_id() ) { | |
| 99 | + // Reuse the captured token so destroying other sessions does not depend on the current $_COOKIE state | |
| 100 | + $current_session_token = ! empty( $session_token ) ? $session_token : wp_get_session_token(); | |
| 101 | + $sessions->destroy_others( $current_session_token ); | |
| 74 | 102 | } else { |
| 75 | 103 | $sessions->destroy_all(); |
| 76 | 104 | } |
| 77 | 105 | |
| @@ -82,11 +110,19 @@ | ||
| 82 | 110 | } |
| 83 | 111 | |
| 84 | 112 | |
| 85 | 113 | function wppb_front_end_profile_info( $atts ){ |
| 86 | - // get value set in the shortcode as parameter, still need to default to something else than empty string | |
| 87 | - extract( shortcode_atts( array( 'form_name' => 'unspecified', 'redirect_url' => '', 'redirect_priority' => 'normal' ), $atts, 'wppb-edit-profile' ) ); | |
| 88 | 114 | |
| 89 | - $form = new Profile_Builder_Form_Creator( array( 'form_type' => 'edit_profile', 'form_name' => $form_name, 'redirect_url' => $redirect_url, 'redirect_priority' => $redirect_priority ) ); | |
| 115 | + $atts = shortcode_atts( array( | |
| 116 | + 'form_name' => 'unspecified', | |
| 117 | + 'redirect_url' => '', | |
| 118 | + 'redirect_priority' => 'normal', | |
| 119 | + 'ajax' => false, | |
| 120 | + 'admin_edit_roles' => '' | |
| 121 | + ), $atts, 'wppb-edit-profile' ); | |
| 90 | 122 | |
| 123 | + $form = new Profile_Builder_Form_Creator( | |
| 124 | + array( 'form_type' => 'edit_profile', 'form_name' => $atts['form_name'], 'redirect_url' => $atts['redirect_url'], 'redirect_priority' => $atts['redirect_priority'], 'ajax' => $atts['ajax'], 'admin_edit_roles' => $atts['admin_edit_roles'] ) | |
| 125 | + ); | |
| 126 | + | |
| 91 | 127 | return $form; |
| 92 | -} | |
| 128 | +} | |