PluginProbe
Tutor LMS – eLearning and online course solution / 1.5.9
Tutor LMS – eLearning and online course solution v1.5.9
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 4.0.2 4.0.1 4.0.0 3.9.15 3.9.14 3.9.13 3.9.12 3.9.11 trunk 1.0.0 1.0.0-alpha 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 All 191 releases
← All changes | classes/FormHandler.php +147 -104 4.0.21.5.9 View file →
@@ -1,65 +1,101 @@
1 1 <?php
2 2 /**
3 - * Manage Form
3 + * FormHandler class
4 4 *
5 + * @author: themeum
6 + * @author_uri: https://themeum.com
5 7 * @package Tutor
6 - * @author Themeum <support@themeum.com>
7 - * @link https://themeum.com
8 - * @since 1.4.3
8 + * @since v.1.4.3
9 9 */
10 10
11 11 namespace TUTOR;
12 12
13 -if ( ! defined( 'ABSPATH' ) ) {
13 +
14 +if ( ! defined( 'ABSPATH' ) )
14 15 exit;
15 -}
16 16
17 -/**
18 - * FormHandler class
19 - *
20 - * @since 1.4.3
21 - */
17 +
22 18 class FormHandler {
23 19
24 - /**
25 - * Constructor
26 - *
27 - * @since 1.4.3
28 - * @return void
29 - */
30 20 public function __construct() {
31 - add_action( 'tutor_action_tutor_retrieve_password', array( $this, 'tutor_retrieve_password' ) );
32 - add_action( 'tutor_action_tutor_process_reset_password', array( $this, 'tutor_process_reset_password' ) );
21 + add_action('tutor_action_tutor_user_login', array($this, 'process_login'));
22 + add_action('tutor_action_tutor_retrieve_password', array($this, 'tutor_retrieve_password'));
23 + add_action('tutor_action_tutor_process_reset_password', array($this, 'tutor_process_reset_password'));
24 +
25 + add_action( 'tutor_reset_password_notification', array( $this, 'reset_password_notification' ), 10, 2 );
33 26 add_filter( 'tutor_lostpassword_url', array( $this, 'lostpassword_url' ) );
34 27 }
35 28
36 - /**
37 - * Retrieve Password
38 - *
39 - * @since 1.4.3
40 - *
41 - * @return void|bool
42 - */
43 - public function tutor_retrieve_password() {
29 + public function process_login(){
44 30 tutils()->checking_nonce();
45 31
46 - /**
47 - * To check spam or other logic before form process.
48 - *
49 - * @since 2.1.10
50 - */
51 - $before_form_process = apply_filters( 'tutor_before_retrieve_password_form_process', null );
52 - if ( is_wp_error( $before_form_process ) ) {
53 - tutor_flash_set( 'danger', $before_form_process->get_error_message() );
54 - return false;
32 +
33 + $username = tutils()->array_get('log', $_POST);
34 + $password = tutils()->array_get('pwd', $_POST);
35 +
36 +
37 + try {
38 + $creds = array(
39 + 'user_login' => trim( wp_unslash( $username ) ), // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
40 + 'user_password' => $password, // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
41 + 'remember' => isset( $_POST['rememberme'] ), // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
42 + );
43 +
44 +
45 + $validation_error = new \WP_Error();
46 + $validation_error = apply_filters( 'tutor_process_login_errors', $validation_error, $creds['user_login'], $creds['user_password'] );
47 +
48 + if ( $validation_error->get_error_code() ) {
49 + throw new \Exception( '<strong>' . __( 'Error:', 'tutor' ) . '</strong> ' . $validation_error->get_error_message() );
50 + }
51 +
52 + if ( empty( $creds['user_login'] ) ) {
53 + throw new \Exception( '<strong>' . __( 'Error:', 'tutor' ) . '</strong> ' . __( 'Username is required.', 'tutor' ) );
54 + }
55 +
56 + // On multisite, ensure user exists on current site, if not add them before allowing login.
57 + if ( is_multisite() ) {
58 + $user_data = get_user_by( is_email( $creds['user_login'] ) ? 'email' : 'login', $creds['user_login'] );
59 +
60 + if ( $user_data && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) {
61 + add_user_to_blog( get_current_blog_id(), $user_data->ID, 'customer' );
62 + }
63 + }
64 +
65 + // Perform the login.
66 + $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
67 +
68 + if ( is_wp_error( $user ) ) {
69 + $message = $user->get_error_message();
70 + $message = str_replace( '<strong>' . esc_html( $creds['user_login'] ) . '</strong>', '<strong>' . esc_html( $creds['user_login'] ) . '</strong>', $message );
71 + throw new \Exception( $message );
72 + } else {
73 + tutor_redirect_back(apply_filters('tutor_login_redirect_url', tutils()->tutor_dashboard_url()));
74 + }
75 + } catch ( \Exception $e ) {
76 + tutor_flash_set('warning', apply_filters( 'login_errors', $e->getMessage()) );
77 + do_action( 'tutor_login_failed' );
55 78 }
56 79
57 - //phpcs:ignore WordPress.Security.NonceVerification.Missing
58 - $login = sanitize_user( tutils()->array_get( 'user_login', $_POST ) );
59 80
81 +
82 + }
83 +
84 +
85 +
86 +
87 +
88 + public function tutor_retrieve_password(){
89 + tutils()->checking_nonce();
90 +
91 + //echo '<pre>';
92 + //die(print_r($_POST));
93 +
94 + $login = sanitize_user( tutils()->array_get('user_login', $_POST));
95 +
60 96 if ( empty( $login ) ) {
61 - tutor_flash_set( 'danger', __( 'Enter a username or email address.', 'tutor' ) );
97 + tutor_flash_set('danger', __( 'Enter a username or email address.', 'tutor' ));
62 98 return false;
63 99 } else {
64 100 // Check on username first, as customers can use emails as usernames.
65 101 $user_data = get_user_by( 'login', $login );
@@ -74,19 +110,19 @@
74 110
75 111 do_action( 'lostpassword_post', $errors );
76 112
77 113 if ( $errors->get_error_code() ) {
78 - tutor_flash_set( 'danger', $errors->get_error_message() );
114 + tutor_flash_set('danger', $errors->get_error_message() );
79 115 return false;
80 116 }
81 117
82 118 if ( ! $user_data ) {
83 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
119 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
84 120 return false;
85 121 }
86 122
87 123 if ( is_multisite() && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) {
88 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
124 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
89 125 return false;
90 126 }
91 127
92 128 // Redefining user_login ensures we return the right case in the email.
@@ -96,110 +132,117 @@
96 132
97 133 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
98 134
99 135 if ( ! $allow ) {
100 - tutor_flash_set( 'danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
136 + tutor_flash_set('danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
101 137 return false;
102 138 } elseif ( is_wp_error( $allow ) ) {
103 - tutor_flash_set( 'danger', $allow->get_error_message() );
139 + tutor_flash_set('danger', $allow->get_error_message() );
104 140 return false;
105 141 }
106 142
107 - $errors = retrieve_password();
108 - if ( is_wp_error( $errors ) ) {
109 - tutor_flash_set( 'danger', $errors->get_error_message() );
110 - return false;
111 - }
143 + // Get password reset key (function introduced in WordPress 4.4).
144 + $key = get_password_reset_key($user_data);
112 145
113 - $html = '<p> ' . __( "We've sent an email to this account's email address. Click the link in the email to reset your password. If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor' ) . '</p>';
114 - tutor_flash_set( 'success', $html );
146 + // Send email notification.
147 + do_action( 'tutor_reset_password_notification', $user_login, $key );
115 148 }
116 149
117 - /**
118 - * Get lost password URL
119 - *
120 - * @since 1.4.3
121 - *
122 - * @param string $url URL.
123 - * @return string
124 - */
125 - public function lostpassword_url( $url ) {
126 - return tutils()->tutor_dashboard_url( 'retrieve-password' );
150 +
151 + public function reset_password_notification( $user_login = '', $reset_key = ''){
152 + $this->sendNotification($user_login, $reset_key);
153 +
154 + $html = "<h3>".__('Check your E-Mail', 'tutor')."</h3>";
155 + $html .= "<p>".__("We've sent an email to this account's email address. Click the link in the email to reset your password", 'tutor')."</p>";
156 + $html .= "<p>".__("If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor')."</p>";
157 + tutor_flash_set('success', $html);
127 158 }
128 159
129 - /**
130 - * Handle reset password request
131 - *
132 - * @since 1.4.3
133 - * @return void|bool
134 - */
135 - public function tutor_process_reset_password() {
160 + public function lostpassword_url($url){
161 + return tutils()->tutor_dashboard_url('retrieve-password');
162 + }
163 +
164 + public function tutor_process_reset_password(){
136 165 tutils()->checking_nonce();
137 166
138 - $reset_key = Input::post( 'reset_key' );
139 - $user_id = Input::post( 'user_id', 0, Input::TYPE_INT );
140 - $password = Input::post( 'password' );
141 - $confirm_password = Input::post( 'confirm_password' );
167 + $reset_key = sanitize_text_field(tutils()->array_get('reset_key', $_POST));
168 + $user_id = (int) sanitize_text_field(tutils()->array_get('user_id', $_POST));
169 + $password = sanitize_text_field(tutils()->array_get('password', $_POST));
170 + $confirm_password = sanitize_text_field(tutils()->array_get('confirm_password', $_POST));
142 171
143 - $user = get_user_by( 'ID', $user_id );
172 + $user = get_user_by('ID', $user_id);
144 173 $user = check_password_reset_key( $reset_key, $user->user_login );
145 174
146 175 if ( is_wp_error( $user ) ) {
147 - tutor_flash_set( 'danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor' ) );
176 + tutor_flash_set('danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor') );
148 177 return false;
149 178 }
150 179
180 +
151 181 if ( $user instanceof \WP_User ) {
152 - if ( ! $password ) {
153 - tutor_flash_set( 'danger', __( 'Please enter your password.', 'tutor' ) );
182 + if ( !$password ) {
183 + tutor_flash_set('danger', __( 'Please enter your password.', 'tutor') );
154 184 return false;
155 185 }
156 186
157 - if ( $password !== $confirm_password ) {
158 - tutor_flash_set( 'danger', __( 'Passwords do not match.', 'tutor' ) );
187 + if ( $password !== $confirm_password) {
188 + tutor_flash_set('danger', __( 'Passwords do not match.', 'tutor') );
159 189 return false;
160 190 }
161 191
162 - tutils()->reset_password( $user, $password );
192 + tutils()->reset_password($user, $password);
163 193
164 194 do_action( 'tutor_user_reset_password', $user );
165 195
166 196 // Perform the login.
167 - $creds = array(
168 - 'user_login' => $user->user_login,
169 - 'user_password' => $password,
170 - 'remember' => true,
171 - );
172 - $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
197 + $creds = array('user_login' => $user->user_login, 'user_password' => $password, 'remember' => true);
198 + $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
173 199
174 200 do_action( 'tutor_user_reset_password_login', $user );
175 201
176 - wp_safe_redirect( tutor_utils()->tutor_dashboard_url() );
202 + wp_safe_redirect( tutils()->tutor_dashboard_url() );
177 203 exit;
178 204 }
179 205 }
180 206
181 207 /**
182 - * Get e-mail from address
208 + * @param $user_login
209 + * @param $reset_key
183 210 *
184 - * @since 1.4.3
185 - * @return string
211 + * Send E-Mail notification
212 + * We are sending directly right now, later we will introduce centralised E-Mail notification System...
186 213 */
187 - public function get_from_address() {
188 - $from_address = get_tutor_option( 'email_from_address' );
189 - $default = ! $from_address ? get_option( 'admin_email' ) : $from_address;
190 - return apply_filters( 'tutor_email_from_address', $default );
214 + public function sendNotification($user_login, $reset_key){
215 + //Send the E-Mail to user
216 +
217 + $user_data = get_user_by( 'login', $user_login );
218 +
219 + $variable = array(
220 + 'user_login' => $user_login,
221 + 'reset_key' => $reset_key,
222 + 'user_id' => $user_data->ID,
223 + );
224 +
225 + $html = tutor_get_template_html('email.send-reset-password', $variable);
226 + $subject = sprintf(__( 'Password Reset Request for %s', 'tutor' ), get_option( 'blogname' ));
227 +
228 + $header = 'Content-Type: text/html' . "\r\n";
229 +
230 + add_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
231 + add_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
232 +
233 + wp_mail($user_data->user_email, $subject, $html, $header);
234 +
235 + remove_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
236 + remove_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
191 237 }
192 238
193 - /**
194 - * Get e-mail from name
195 - *
196 - * @since 1.4.3
197 - * @return string
198 - */
199 - public function get_from_name() {
200 - $from_name = get_tutor_option( 'email_from_name' );
201 - $default = ! $from_name ? get_option( 'blogname' ) : $from_name;
202 - return apply_filters( 'tutor_email_from_name', $default );
239 + public function get_from_address(){
240 + return apply_filters('tutor_email_from_address', get_tutor_option('email_from_address'));
203 241 }
204 242
205 -}
243 + public function get_from_name(){
244 + return apply_filters('tutor_email_from_name', get_tutor_option('email_from_name'));
245 + }
246 +
247 +
248 +}