| @@ -1,65 +1,38 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | /** |
| 3 | - * Manage Form | |
| 3 | + * FormHandler class | |
| 4 | 4 | * |
| 5 | + * @author: themeum | |
| 6 | + * @author_uri: https://themeum.com | |
| 5 | 7 | * @package Tutor |
| 6 | - * @author Themeum <support@themeum.com> | |
| 7 | - * @link https://themeum.com | |
| 8 | - * @since 1.4.3 | |
| 8 | + * @since v.1.4.3 | |
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | 11 | namespace TUTOR; |
| 12 | 12 | |
| 13 | -if ( ! defined( 'ABSPATH' ) ) { | |
| 13 | + | |
| 14 | +if ( ! defined( 'ABSPATH' ) ) | |
| 14 | 15 | exit; |
| 15 | -} | |
| 16 | 16 | |
| 17 | -/** | |
| 18 | - * FormHandler class | |
| 19 | - * | |
| 20 | - * @since 1.4.3 | |
| 21 | - */ | |
| 17 | + | |
| 22 | 18 | class FormHandler { |
| 23 | 19 | |
| 24 | - /** | |
| 25 | - * Constructor | |
| 26 | - * | |
| 27 | - * @since 1.4.3 | |
| 28 | - * @return void | |
| 29 | - */ | |
| 30 | 20 | public function __construct() { |
| 31 | - add_action( 'tutor_action_tutor_retrieve_password', array( $this, 'tutor_retrieve_password' ) ); | |
| 32 | - add_action( 'tutor_action_tutor_process_reset_password', array( $this, 'tutor_process_reset_password' ) ); | |
| 21 | + add_action('tutor_action_tutor_retrieve_password', array($this, 'tutor_retrieve_password')); | |
| 22 | + add_action('tutor_action_tutor_process_reset_password', array($this, 'tutor_process_reset_password')); | |
| 23 | + | |
| 24 | + add_action( 'tutor_reset_password_notification', array( $this, 'reset_password_notification' ), 10, 2 ); | |
| 33 | 25 | add_filter( 'tutor_lostpassword_url', array( $this, 'lostpassword_url' ) ); |
| 34 | 26 | } |
| 35 | 27 | |
| 36 | - /** | |
| 37 | - * Retrieve Password | |
| 38 | - * | |
| 39 | - * @since 1.4.3 | |
| 40 | - * | |
| 41 | - * @return void|bool | |
| 42 | - */ | |
| 43 | - public function tutor_retrieve_password() { | |
| 28 | + public function tutor_retrieve_password(){ | |
| 44 | 29 | tutils()->checking_nonce(); |
| 45 | 30 | |
| 46 | - /** | |
| 47 | - * To check spam or other logic before form process. | |
| 48 | - * | |
| 49 | - * @since 2.1.10 | |
| 50 | - */ | |
| 51 | - $before_form_process = apply_filters( 'tutor_before_retrieve_password_form_process', null ); | |
| 52 | - if ( is_wp_error( $before_form_process ) ) { | |
| 53 | - tutor_flash_set( 'danger', $before_form_process->get_error_message() ); | |
| 54 | - return false; | |
| 55 | - } | |
| 31 | + $login = sanitize_user( tutils()->array_get('user_login', $_POST)); | |
| 56 | 32 | |
| 57 | - //phpcs:ignore WordPress.Security.NonceVerification.Missing | |
| 58 | - $login = sanitize_user( tutils()->array_get( 'user_login', $_POST ) ); | |
| 59 | - | |
| 60 | 33 | if ( empty( $login ) ) { |
| 61 | - tutor_flash_set( 'danger', __( 'Enter a username or email address.', 'tutor' ) ); | |
| 34 | + tutor_flash_set('danger', __( 'Enter a username or email address.', 'tutor' )); | |
| 62 | 35 | return false; |
| 63 | 36 | } else { |
| 64 | 37 | // Check on username first, as customers can use emails as usernames. |
| 65 | 38 | $user_data = get_user_by( 'login', $login ); |
| @@ -74,19 +47,19 @@ | ||
| 74 | 47 | |
| 75 | 48 | do_action( 'lostpassword_post', $errors ); |
| 76 | 49 | |
| 77 | 50 | if ( $errors->get_error_code() ) { |
| 78 | - tutor_flash_set( 'danger', $errors->get_error_message() ); | |
| 51 | + tutor_flash_set('danger', $errors->get_error_message() ); | |
| 79 | 52 | return false; |
| 80 | 53 | } |
| 81 | 54 | |
| 82 | 55 | if ( ! $user_data ) { |
| 83 | - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) ); | |
| 56 | + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) ); | |
| 84 | 57 | return false; |
| 85 | 58 | } |
| 86 | 59 | |
| 87 | 60 | if ( is_multisite() && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) { |
| 88 | - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) ); | |
| 61 | + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) ); | |
| 89 | 62 | return false; |
| 90 | 63 | } |
| 91 | 64 | |
| 92 | 65 | // Redefining user_login ensures we return the right case in the email. |
| @@ -96,110 +69,116 @@ | ||
| 96 | 69 | |
| 97 | 70 | $allow = apply_filters( 'allow_password_reset', true, $user_data->ID ); |
| 98 | 71 | |
| 99 | 72 | if ( ! $allow ) { |
| 100 | - tutor_flash_set( 'danger', __( 'Password reset is not allowed for this user', 'tutor' ) ); | |
| 73 | + tutor_flash_set('danger', __( 'Password reset is not allowed for this user', 'tutor' ) ); | |
| 101 | 74 | return false; |
| 102 | 75 | } elseif ( is_wp_error( $allow ) ) { |
| 103 | - tutor_flash_set( 'danger', $allow->get_error_message() ); | |
| 76 | + tutor_flash_set('danger', $allow->get_error_message() ); | |
| 104 | 77 | return false; |
| 105 | 78 | } |
| 106 | 79 | |
| 107 | - $errors = retrieve_password(); | |
| 108 | - if ( is_wp_error( $errors ) ) { | |
| 109 | - tutor_flash_set( 'danger', $errors->get_error_message() ); | |
| 110 | - return false; | |
| 111 | - } | |
| 80 | + // Get password reset key (function introduced in WordPress 4.4). | |
| 81 | + $key = get_password_reset_key($user_data); | |
| 112 | 82 | |
| 113 | - $html = '<p> ' . __( "We've sent an email to this account's email address. Click the link in the email to reset your password. If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor' ) . '</p>'; | |
| 114 | - tutor_flash_set( 'success', $html ); | |
| 83 | + // Send email notification. | |
| 84 | + do_action( 'tutor_reset_password_notification', $user_login, $key ); | |
| 115 | 85 | } |
| 116 | 86 | |
| 117 | - /** | |
| 118 | - * Get lost password URL | |
| 119 | - * | |
| 120 | - * @since 1.4.3 | |
| 121 | - * | |
| 122 | - * @param string $url URL. | |
| 123 | - * @return string | |
| 124 | - */ | |
| 125 | - public function lostpassword_url( $url ) { | |
| 126 | - return tutils()->tutor_dashboard_url( 'retrieve-password' ); | |
| 87 | + public function reset_password_notification( $user_login = '', $reset_key = ''){ | |
| 88 | + $this->sendNotification($user_login, $reset_key); | |
| 89 | + | |
| 90 | + $html = "<h3>".__('Check your E-Mail', 'tutor')."</h3>"; | |
| 91 | + $html .= "<p>".__("We've sent an email to this account's email address. Click the link in the email to reset your password", 'tutor')."</p>"; | |
| 92 | + $html .= "<p>".__("If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor')."</p>"; | |
| 93 | + tutor_flash_set('success', $html); | |
| 127 | 94 | } |
| 128 | 95 | |
| 129 | - /** | |
| 130 | - * Handle reset password request | |
| 131 | - * | |
| 132 | - * @since 1.4.3 | |
| 133 | - * @return void|bool | |
| 134 | - */ | |
| 135 | - public function tutor_process_reset_password() { | |
| 96 | + public function lostpassword_url($url){ | |
| 97 | + return tutils()->tutor_dashboard_url('retrieve-password'); | |
| 98 | + } | |
| 99 | + | |
| 100 | + public function tutor_process_reset_password(){ | |
| 136 | 101 | tutils()->checking_nonce(); |
| 137 | 102 | |
| 138 | - $reset_key = Input::post( 'reset_key' ); | |
| 139 | - $user_id = Input::post( 'user_id', 0, Input::TYPE_INT ); | |
| 140 | - $password = Input::post( 'password' ); | |
| 141 | - $confirm_password = Input::post( 'confirm_password' ); | |
| 103 | + $reset_key = sanitize_text_field(tutils()->array_get('reset_key', $_POST)); | |
| 104 | + $user_id = (int) sanitize_text_field(tutils()->array_get('user_id', $_POST)); | |
| 105 | + $password = sanitize_text_field(tutils()->array_get('password', $_POST)); | |
| 106 | + $confirm_password = sanitize_text_field(tutils()->array_get('confirm_password', $_POST)); | |
| 142 | 107 | |
| 143 | - $user = get_user_by( 'ID', $user_id ); | |
| 108 | + $user = get_user_by('ID', $user_id); | |
| 144 | 109 | $user = check_password_reset_key( $reset_key, $user->user_login ); |
| 145 | 110 | |
| 146 | 111 | if ( is_wp_error( $user ) ) { |
| 147 | - tutor_flash_set( 'danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor' ) ); | |
| 112 | + tutor_flash_set('danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor') ); | |
| 148 | 113 | return false; |
| 149 | 114 | } |
| 150 | 115 | |
| 116 | + | |
| 151 | 117 | if ( $user instanceof \WP_User ) { |
| 152 | - if ( ! $password ) { | |
| 153 | - tutor_flash_set( 'danger', __( 'Please enter your password.', 'tutor' ) ); | |
| 118 | + if ( !$password ) { | |
| 119 | + tutor_flash_set('danger', __( 'Please enter your password.', 'tutor') ); | |
| 154 | 120 | return false; |
| 155 | 121 | } |
| 156 | 122 | |
| 157 | - if ( $password !== $confirm_password ) { | |
| 158 | - tutor_flash_set( 'danger', __( 'Passwords do not match.', 'tutor' ) ); | |
| 123 | + if ( $password !== $confirm_password) { | |
| 124 | + tutor_flash_set('danger', __( 'Passwords do not match.', 'tutor') ); | |
| 159 | 125 | return false; |
| 160 | 126 | } |
| 161 | 127 | |
| 162 | - tutils()->reset_password( $user, $password ); | |
| 128 | + tutils()->reset_password($user, $password); | |
| 163 | 129 | |
| 164 | 130 | do_action( 'tutor_user_reset_password', $user ); |
| 165 | 131 | |
| 166 | 132 | // Perform the login. |
| 167 | - $creds = array( | |
| 168 | - 'user_login' => $user->user_login, | |
| 169 | - 'user_password' => $password, | |
| 170 | - 'remember' => true, | |
| 171 | - ); | |
| 172 | - $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() ); | |
| 133 | + $creds = array('user_login' => $user->user_login, 'user_password' => $password, 'remember' => true); | |
| 134 | + $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() ); | |
| 173 | 135 | |
| 174 | 136 | do_action( 'tutor_user_reset_password_login', $user ); |
| 175 | 137 | |
| 176 | - wp_safe_redirect( tutor_utils()->tutor_dashboard_url() ); | |
| 138 | + wp_safe_redirect( tutils()->tutor_dashboard_url() ); | |
| 177 | 139 | exit; |
| 178 | 140 | } |
| 179 | 141 | } |
| 180 | 142 | |
| 181 | 143 | /** |
| 182 | - * Get e-mail from address | |
| 144 | + * @param $user_login | |
| 145 | + * @param $reset_key | |
| 183 | 146 | * |
| 184 | - * @since 1.4.3 | |
| 185 | - * @return string | |
| 147 | + * Send E-Mail notification | |
| 148 | + * We are sending directly right now, later we will introduce centralised E-Mail notification System... | |
| 186 | 149 | */ |
| 187 | - public function get_from_address() { | |
| 188 | - $from_address = get_tutor_option( 'email_from_address' ); | |
| 189 | - $default = ! $from_address ? get_option( 'admin_email' ) : $from_address; | |
| 190 | - return apply_filters( 'tutor_email_from_address', $default ); | |
| 150 | + public function sendNotification($user_login, $reset_key){ | |
| 151 | + //Send the E-Mail to user | |
| 152 | + | |
| 153 | + $user_data = get_user_by( 'login', $user_login ); | |
| 154 | + | |
| 155 | + $variable = array( | |
| 156 | + 'user_login' => $user_login, | |
| 157 | + 'reset_key' => $reset_key, | |
| 158 | + 'user_id' => $user_data->ID, | |
| 159 | + ); | |
| 160 | + | |
| 161 | + $html = tutor_get_template_html('email.send-reset-password', $variable); | |
| 162 | + $subject = sprintf(__( 'Password Reset Request for %s', 'tutor' ), get_option( 'blogname' )); | |
| 163 | + | |
| 164 | + $header = 'Content-Type: text/html' . "\r\n"; | |
| 165 | + | |
| 166 | + add_filter( 'wp_mail_from', array( $this, 'get_from_address' ) ); | |
| 167 | + add_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) ); | |
| 168 | + | |
| 169 | + wp_mail($user_data->user_email, $subject, $html, $header); | |
| 170 | + | |
| 171 | + remove_filter( 'wp_mail_from', array( $this, 'get_from_address' ) ); | |
| 172 | + remove_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) ); | |
| 191 | 173 | } |
| 192 | 174 | |
| 193 | - /** | |
| 194 | - * Get e-mail from name | |
| 195 | - * | |
| 196 | - * @since 1.4.3 | |
| 197 | - * @return string | |
| 198 | - */ | |
| 199 | - public function get_from_name() { | |
| 200 | - $from_name = get_tutor_option( 'email_from_name' ); | |
| 201 | - $default = ! $from_name ? get_option( 'blogname' ) : $from_name; | |
| 202 | - return apply_filters( 'tutor_email_from_name', $default ); | |
| 175 | + public function get_from_address(){ | |
| 176 | + return apply_filters('tutor_email_from_address', get_tutor_option('email_from_address')); | |
| 203 | 177 | } |
| 204 | 178 | |
| 205 | -} | |
| 179 | + public function get_from_name(){ | |
| 180 | + return apply_filters('tutor_email_from_name', get_tutor_option('email_from_name')); | |
| 181 | + } | |
| 182 | + | |
| 183 | + | |
| 184 | +} | |