PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/staff.php +31 -3 1.0.13 → 1.0.64 View file →
@@ -322,8 +322,24 @@
322 322 'role' => 'timetics-staff',
323 323 ];
324 324
325 325 $args = wp_parse_args( $args, $defaults );
326 +
327 + $email = ! empty( $args['user_email'] ) ? $args['user_email'] : '';
328 +
329 + if ( $email ) {
330 + $user['user_email'] = $email;
331 + }
332 +
333 + $user = get_user_by( 'email', $email );
334 +
335 + // An existing account with this email is a conflict, not an instruction
336 + // to promote it — silently granting the staff role let a caller take
337 + // over any account by submitting its email.
338 + if ( $user ) {
339 + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) );
340 + }
341 +
326 342 $user_id = wp_insert_user( $args );
327 343
328 344 if ( ! is_wp_error( $user_id ) ) {
329 345 $this->set_id( $user_id );
@@ -339,21 +355,33 @@
339 355 *
340 356 * @return void
341 357 */
342 358 public function update( $args = [] ) {
343 - $user = get_userdata( $this->id )->to_array();
359 + $user = get_userdata( $this->id )->to_array();
360 + $email = ! empty( $args['user_email'] ) ? $args['user_email'] : '';
344 361
345 362 if ( ! empty( $args['user_pass'] ) ) {
346 363 $user['user_pass'] = $args['user_pass'];
347 364 }
348 365
349 - if ( ! empty( $args['email'] ) ) {
350 - $user['user_email'] = $args['email'];
366 + if ( $email ) {
367 + $user['user_email'] = $email;
351 368 }
352 369
370 + $user_data = get_user_by( 'email', $email );
371 +
372 + // Only a conflict if it belongs to someone other than the staff member
373 + // being edited — otherwise every update where they keep their own
374 + // email would (incorrectly) hit this branch. See create() for why a
375 + // match must never silently grant the staff role.
376 + if ( $user_data && (int) $user_data->ID !== (int) $this->id ) {
377 + return new \WP_Error( 'timetics_staff_email_exists', __( 'A user with this email address already exists.', 'timetics' ) );
378 + }
379 +
353 380 $updated = wp_update_user( $user );
354 381
355 382 if ( ! is_wp_error( $updated ) ) {
383 +
356 384 $this->save_metadata( $args );
357 385 }
358 386
359 387 return $updated;