PluginProbe
Tutor LMS – eLearning and online course solution / 1.8.10
Tutor LMS – eLearning and online course solution v1.8.10
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 4.0.2 4.0.1 4.0.0 3.9.15 3.9.14 3.9.13 3.9.12 3.9.11 trunk 1.0.0 1.0.0-alpha 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 All 191 releases
← All changes | classes/FormHandler.php +59 -133 3.9.141.8.10 View file →
@@ -1,66 +1,38 @@
1 1 <?php
2 2 /**
3 - * Manage Form
3 + * FormHandler class
4 4 *
5 + * @author: themeum
6 + * @author_uri: https://themeum.com
5 7 * @package Tutor
6 - * @author Themeum <support@themeum.com>
7 - * @link https://themeum.com
8 - * @since 1.4.3
8 + * @since v.1.4.3
9 9 */
10 10
11 11 namespace TUTOR;
12 12
13 -if ( ! defined( 'ABSPATH' ) ) {
13 +
14 +if ( ! defined( 'ABSPATH' ) )
14 15 exit;
15 -}
16 16
17 -/**
18 - * FormHandler class
19 - *
20 - * @since 1.4.3
21 - */
17 +
22 18 class FormHandler {
23 19
24 - /**
25 - * Constructor
26 - *
27 - * @since 1.4.3
28 - * @return void
29 - */
30 20 public function __construct() {
31 - add_action( 'tutor_action_tutor_retrieve_password', array( $this, 'tutor_retrieve_password' ) );
32 - add_action( 'tutor_action_tutor_process_reset_password', array( $this, 'tutor_process_reset_password' ) );
21 + add_action('tutor_action_tutor_retrieve_password', array($this, 'tutor_retrieve_password'));
22 + add_action('tutor_action_tutor_process_reset_password', array($this, 'tutor_process_reset_password'));
33 23
34 24 add_action( 'tutor_reset_password_notification', array( $this, 'reset_password_notification' ), 10, 2 );
35 25 add_filter( 'tutor_lostpassword_url', array( $this, 'lostpassword_url' ) );
36 26 }
37 27
38 - /**
39 - * Retrieve Password
40 - *
41 - * @since 1.4.3
42 - * @return void|bool
43 - */
44 - public function tutor_retrieve_password() {
28 + public function tutor_retrieve_password(){
45 29 tutils()->checking_nonce();
46 30
47 - /**
48 - * To check spam or other logic before form process.
49 - *
50 - * @since 2.1.10
51 - */
52 - $before_form_process = apply_filters( 'tutor_before_retrieve_password_form_process', null );
53 - if ( is_wp_error( $before_form_process ) ) {
54 - tutor_flash_set( 'danger', $before_form_process->get_error_message() );
55 - return false;
56 - }
31 + $login = sanitize_user( tutils()->array_get('user_login', $_POST));
57 32
58 - //phpcs:ignore WordPress.Security.NonceVerification.Missing
59 - $login = sanitize_user( tutils()->array_get( 'user_login', $_POST ) );
60 -
61 33 if ( empty( $login ) ) {
62 - tutor_flash_set( 'danger', __( 'Enter a username or email address.', 'tutor' ) );
34 + tutor_flash_set('danger', __( 'Enter a username or email address.', 'tutor' ));
63 35 return false;
64 36 } else {
65 37 // Check on username first, as customers can use emails as usernames.
66 38 $user_data = get_user_by( 'login', $login );
@@ -75,19 +47,19 @@
75 47
76 48 do_action( 'lostpassword_post', $errors );
77 49
78 50 if ( $errors->get_error_code() ) {
79 - tutor_flash_set( 'danger', $errors->get_error_message() );
51 + tutor_flash_set('danger', $errors->get_error_message() );
80 52 return false;
81 53 }
82 54
83 55 if ( ! $user_data ) {
84 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
56 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
85 57 return false;
86 58 }
87 59
88 60 if ( is_multisite() && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) {
89 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
61 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
90 62 return false;
91 63 }
92 64
93 65 // Redefining user_login ensures we return the right case in the email.
@@ -97,129 +69,98 @@
97 69
98 70 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
99 71
100 72 if ( ! $allow ) {
101 - tutor_flash_set( 'danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
73 + tutor_flash_set('danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
102 74 return false;
103 75 } elseif ( is_wp_error( $allow ) ) {
104 - tutor_flash_set( 'danger', $allow->get_error_message() );
76 + tutor_flash_set('danger', $allow->get_error_message() );
105 77 return false;
106 78 }
107 79
108 80 // Get password reset key (function introduced in WordPress 4.4).
109 - $key = get_password_reset_key( $user_data );
81 + $key = get_password_reset_key($user_data);
110 82
111 83 // Send email notification.
112 84 do_action( 'tutor_reset_password_notification', $user_login, $key );
113 85 }
114 86
115 - /**
116 - * Send notification for rest password
117 - *
118 - * @since 1.4.3
119 - *
120 - * @param string $user_login username.
121 - * @param string $reset_key reset key.
122 - *
123 - * @return void
124 - */
125 - public function reset_password_notification( $user_login = '', $reset_key = '' ) {
126 - $this->send_notification( $user_login, $reset_key );
87 + public function reset_password_notification( $user_login = '', $reset_key = ''){
88 + $this->sendNotification($user_login, $reset_key);
127 89
128 - $html = '<h3>' . __( 'Check your E-Mail', 'tutor' ) . '</h3>';
129 - $html .= '<p> ' . __( "We've sent an email to this account's email address. Click the link in the email to reset your password.", 'tutor' ) . '</p>';
130 - $html .= '<p>' . __( " If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor' ) . '</p>';
131 - tutor_flash_set( 'success', $html );
90 + $html = "<h3>".__('Check your E-Mail', 'tutor')."</h3>";
91 + $html .= "<p>".__("We've sent an email to this account's email address. Click the link in the email to reset your password", 'tutor')."</p>";
92 + $html .= "<p>".__("If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor')."</p>";
93 + tutor_flash_set('success', $html);
132 94 }
133 95
134 - /**
135 - * Get lost password URL
136 - *
137 - * @since 1.4.3
138 - *
139 - * @param string $url URL.
140 - * @return string
141 - */
142 - public function lostpassword_url( $url ) {
143 - return tutils()->tutor_dashboard_url( 'retrieve-password' );
96 + public function lostpassword_url($url){
97 + return tutils()->tutor_dashboard_url('retrieve-password');
144 98 }
145 99
146 - /**
147 - * Handle reset password request
148 - *
149 - * @since 1.4.3
150 - * @return void|bool
151 - */
152 - public function tutor_process_reset_password() {
100 + public function tutor_process_reset_password(){
153 101 tutils()->checking_nonce();
154 102
155 - $reset_key = Input::post( 'reset_key' );
156 - $user_id = Input::post( 'user_id', 0, Input::TYPE_INT );
157 - $password = Input::post( 'password' );
158 - $confirm_password = Input::post( 'confirm_password' );
103 + $reset_key = sanitize_text_field(tutils()->array_get('reset_key', $_POST));
104 + $user_id = (int) sanitize_text_field(tutils()->array_get('user_id', $_POST));
105 + $password = sanitize_text_field(tutils()->array_get('password', $_POST));
106 + $confirm_password = sanitize_text_field(tutils()->array_get('confirm_password', $_POST));
159 107
160 - $user = get_user_by( 'ID', $user_id );
108 + $user = get_user_by('ID', $user_id);
161 109 $user = check_password_reset_key( $reset_key, $user->user_login );
162 110
163 111 if ( is_wp_error( $user ) ) {
164 - tutor_flash_set( 'danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor' ) );
112 + tutor_flash_set('danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor') );
165 113 return false;
166 114 }
167 115
116 +
168 117 if ( $user instanceof \WP_User ) {
169 - if ( ! $password ) {
170 - tutor_flash_set( 'danger', __( 'Please enter your password.', 'tutor' ) );
118 + if ( !$password ) {
119 + tutor_flash_set('danger', __( 'Please enter your password.', 'tutor') );
171 120 return false;
172 121 }
173 122
174 - if ( $password !== $confirm_password ) {
175 - tutor_flash_set( 'danger', __( 'Passwords do not match.', 'tutor' ) );
123 + if ( $password !== $confirm_password) {
124 + tutor_flash_set('danger', __( 'Passwords do not match.', 'tutor') );
176 125 return false;
177 126 }
178 127
179 - tutils()->reset_password( $user, $password );
128 + tutils()->reset_password($user, $password);
180 129
181 130 do_action( 'tutor_user_reset_password', $user );
182 131
183 132 // Perform the login.
184 - $creds = array(
185 - 'user_login' => $user->user_login,
186 - 'user_password' => $password,
187 - 'remember' => true,
188 - );
189 - $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
133 + $creds = array('user_login' => $user->user_login, 'user_password' => $password, 'remember' => true);
134 + $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
190 135
191 136 do_action( 'tutor_user_reset_password_login', $user );
192 137
193 - wp_safe_redirect( tutor_utils()->tutor_dashboard_url() );
138 + wp_safe_redirect( tutils()->tutor_dashboard_url() );
194 139 exit;
195 140 }
196 141 }
197 142
198 143 /**
199 - * Send Password Reset E-Mail to user.
144 + * @param $user_login
145 + * @param $reset_key
146 + *
147 + * Send E-Mail notification
200 148 * We are sending directly right now, later we will introduce centralised E-Mail notification System...
201 - *
202 - * @since 1.4.3
203 - *
204 - * @param string $user_login login username.
205 - * @param string $reset_key password reset key.
206 - *
207 - * @return void
208 149 */
209 - public function send_notification( $user_login, $reset_key ) {
150 + public function sendNotification($user_login, $reset_key){
151 + //Send the E-Mail to user
210 152
211 153 $user_data = get_user_by( 'login', $user_login );
212 154
213 155 $variable = array(
214 156 'user_login' => $user_login,
215 - 'reset_key' => $reset_key,
216 - 'user_id' => $user_data->ID,
157 + 'reset_key' => $reset_key,
158 + 'user_id' => $user_data->ID,
217 159 );
218 160
219 - $html = tutor_get_template_html( 'email.send-reset-password', $variable );
220 - /* translators: %s: site name */
221 - $subject = sprintf( __( 'Password Reset Request for %s', 'tutor' ), get_option( 'blogname' ) );
161 + $html = tutor_get_template_html('email.send-reset-password', $variable);
162 + $subject = sprintf(__( 'Password Reset Request for %s', 'tutor' ), get_option( 'blogname' ));
222 163
223 164 $header = 'Content-Type: text/html' . "\r\n";
224 165
225 166 add_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
@@ -224,35 +165,20 @@
224 165
225 166 add_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
226 167 add_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
227 168
228 - wp_mail( $user_data->user_email, $subject, $html, $header );
169 + wp_mail($user_data->user_email, $subject, $html, $header);
229 170
230 171 remove_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
231 172 remove_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
232 173 }
233 174
234 - /**
235 - * Get e-mail from address
236 - *
237 - * @since 1.4.3
238 - * @return string
239 - */
240 - public function get_from_address() {
241 - $from_address = get_tutor_option( 'email_from_address' );
242 - $default = ! $from_address ? get_option( 'admin_email' ) : $from_address;
243 - return apply_filters( 'tutor_email_from_address', $default );
175 + public function get_from_address(){
176 + return apply_filters('tutor_email_from_address', get_tutor_option('email_from_address'));
244 177 }
245 178
246 - /**
247 - * Get e-mail from name
248 - *
249 - * @since 1.4.3
250 - * @return string
251 - */
252 - public function get_from_name() {
253 - $from_name = get_tutor_option( 'email_from_name' );
254 - $default = ! $from_name ? get_option( 'blogname' ) : $from_name;
255 - return apply_filters( 'tutor_email_from_name', $default );
179 + public function get_from_name(){
180 + return apply_filters('tutor_email_from_name', get_tutor_option('email_from_name'));
256 181 }
257 182
258 -}
183 +
184 +}