| @@ -155,10 +155,15 @@ | ||
| 155 | 155 | */ |
| 156 | 156 | public function get_image() { |
| 157 | 157 | $image = $this->get_prop( 'image' ); |
| 158 | 158 | |
| 159 | + if ( filter_var( $image, FILTER_VALIDATE_URL ) ) { | |
| 160 | + return $image; | |
| 161 | + } | |
| 162 | + | |
| 163 | + | |
| 159 | 164 | if ( ! $image ) { |
| 160 | - return get_avatar_url( $this->id ); | |
| 165 | + return false; | |
| 161 | 166 | } |
| 162 | 167 | |
| 163 | 168 | return wp_get_attachment_image_url( $image ); |
| 164 | 169 | } |
| @@ -195,12 +200,40 @@ | ||
| 195 | 200 | * |
| 196 | 201 | * @return mixed |
| 197 | 202 | */ |
| 198 | 203 | public function get_status() { |
| 204 | + $user = get_userdata( $this->id ); | |
| 205 | + | |
| 206 | + if ( user_can( $user, 'manage_options' ) ) { | |
| 207 | + return 1; | |
| 208 | + } | |
| 209 | + | |
| 199 | 210 | return $this->get_prop( 'status' ); |
| 200 | 211 | } |
| 201 | 212 | |
| 202 | 213 | /** |
| 214 | + * Get full name; | |
| 215 | + * | |
| 216 | + * @return string | |
| 217 | + */ | |
| 218 | + public function get_full_name() { | |
| 219 | + $first_name = $this->get_first_name(); | |
| 220 | + $last_name = $this->get_last_name(); | |
| 221 | + | |
| 222 | + if ( ! $first_name ) { | |
| 223 | + return $this->get_display_name(); | |
| 224 | + } | |
| 225 | + | |
| 226 | + if ( ! $last_name ) { | |
| 227 | + return $first_name; | |
| 228 | + } | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + return $first_name . ' ' . $last_name; | |
| 233 | + } | |
| 234 | + | |
| 235 | + /** | |
| 203 | 236 | * Get all data for a staff |
| 204 | 237 | * |
| 205 | 238 | * @return array |
| 206 | 239 | */ |
| @@ -206,14 +239,13 @@ | ||
| 206 | 239 | */ |
| 207 | 240 | public function get_data() { |
| 208 | 241 | return [ |
| 209 | 242 | 'id' => $this->get_id(), |
| 210 | - 'full_name' => $this->get_display_name(), | |
| 243 | + 'full_name' => $this->get_full_name(), | |
| 211 | 244 | 'first_name' => $this->get_first_name(), |
| 212 | 245 | 'last_name' => $this->get_last_name(), |
| 213 | 246 | 'user_name' => $this->get_user_name(), |
| 214 | 247 | 'email' => $this->get_email(), |
| 215 | - 'password' => $this->get_password(), | |
| 216 | 248 | 'phone' => $this->get_phone(), |
| 217 | 249 | 'image' => $this->get_image(), |
| 218 | 250 | 'status' => $this->get_status(), |
| 219 | 251 | 'service' => $this->get_service(), |
| @@ -290,8 +322,24 @@ | ||
| 290 | 322 | 'role' => 'timetics-staff', |
| 291 | 323 | ]; |
| 292 | 324 | |
| 293 | 325 | $args = wp_parse_args( $args, $defaults ); |
| 326 | + | |
| 327 | + $email = ! empty( $args['user_email'] ) ? $args['user_email'] : ''; | |
| 328 | + | |
| 329 | + if ( $email ) { | |
| 330 | + $user['user_email'] = $email; | |
| 331 | + } | |
| 332 | + | |
| 333 | + $user = get_user_by( 'email', $email ); | |
| 334 | + | |
| 335 | + // An existing account with this email is a conflict, not an instruction | |
| 336 | + // to promote it — silently granting the staff role let a caller take | |
| 337 | + // over any account by submitting its email. | |
| 338 | + if ( $user ) { | |
| 339 | + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) ); | |
| 340 | + } | |
| 341 | + | |
| 294 | 342 | $user_id = wp_insert_user( $args ); |
| 295 | 343 | |
| 296 | 344 | if ( ! is_wp_error( $user_id ) ) { |
| 297 | 345 | $this->set_id( $user_id ); |
| @@ -307,21 +355,33 @@ | ||
| 307 | 355 | * |
| 308 | 356 | * @return void |
| 309 | 357 | */ |
| 310 | 358 | public function update( $args = [] ) { |
| 311 | - $user = get_userdata( $this->id )->to_array(); | |
| 359 | + $user = get_userdata( $this->id )->to_array(); | |
| 360 | + $email = ! empty( $args['user_email'] ) ? $args['user_email'] : ''; | |
| 312 | 361 | |
| 313 | 362 | if ( ! empty( $args['user_pass'] ) ) { |
| 314 | 363 | $user['user_pass'] = $args['user_pass']; |
| 315 | 364 | } |
| 316 | 365 | |
| 317 | - if ( ! empty( $args['email'] ) ) { | |
| 318 | - $user['user_email'] = $args['email']; | |
| 366 | + if ( $email ) { | |
| 367 | + $user['user_email'] = $email; | |
| 319 | 368 | } |
| 320 | 369 | |
| 370 | + $user_data = get_user_by( 'email', $email ); | |
| 371 | + | |
| 372 | + // Only a conflict if it belongs to someone other than the staff member | |
| 373 | + // being edited — otherwise every update where they keep their own | |
| 374 | + // email would (incorrectly) hit this branch. See create() for why a | |
| 375 | + // match must never silently grant the staff role. | |
| 376 | + if ( $user_data && (int) $user_data->ID !== (int) $this->id ) { | |
| 377 | + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) ); | |
| 378 | + } | |
| 379 | + | |
| 321 | 380 | $updated = wp_update_user( $user ); |
| 322 | 381 | |
| 323 | 382 | if ( ! is_wp_error( $updated ) ) { |
| 383 | + | |
| 324 | 384 | $this->save_metadata( $args ); |
| 325 | 385 | } |
| 326 | 386 | |
| 327 | 387 | return $updated; |
| @@ -339,12 +399,12 @@ | ||
| 339 | 399 | } |
| 340 | 400 | |
| 341 | 401 | // Prepare meta key. |
| 342 | 402 | if( $key == 'first_name' || $key == 'last_name' ) { |
| 343 | - $meta_key = $key; | |
| 403 | + $meta_key = $key; | |
| 344 | 404 | } else { |
| 345 | 405 | $meta_key = $this->meta_prefix . $key; |
| 346 | - } | |
| 406 | + } | |
| 347 | 407 | |
| 348 | 408 | // Update appointment meta data. |
| 349 | 409 | update_user_meta( $this->id, $meta_key, $value ); |
| 350 | 410 | } |
| @@ -373,8 +433,14 @@ | ||
| 373 | 433 | if ( count( $user->roles ) > 1 ) { |
| 374 | 434 | $user->remove_role('timetics-staff'); |
| 375 | 435 | |
| 376 | 436 | return true; |
| 437 | + } | |
| 438 | + | |
| 439 | + if ( is_multisite() ) { | |
| 440 | + require_once ABSPATH . 'wp-admin/includes/ms.php'; | |
| 441 | + | |
| 442 | + return wpmu_delete_user( $this->id ); | |
| 377 | 443 | } |
| 378 | 444 | |
| 379 | 445 | return wp_delete_user( $this->id ); |
| 380 | 446 | } |