PluginProbe
Tutor LMS – eLearning and online course solution / 1.8.10
Tutor LMS – eLearning and online course solution v1.8.10
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 4.0.2 4.0.1 4.0.0 3.9.15 3.9.14 3.9.13 3.9.12 3.9.11 trunk 1.0.0 1.0.0-alpha 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 All 191 releases
← All changes | classes/FormHandler.php +85 -106 4.0.11.8.10 View file →
@@ -1,65 +1,38 @@
1 1 <?php
2 2 /**
3 - * Manage Form
3 + * FormHandler class
4 4 *
5 + * @author: themeum
6 + * @author_uri: https://themeum.com
5 7 * @package Tutor
6 - * @author Themeum <support@themeum.com>
7 - * @link https://themeum.com
8 - * @since 1.4.3
8 + * @since v.1.4.3
9 9 */
10 10
11 11 namespace TUTOR;
12 12
13 -if ( ! defined( 'ABSPATH' ) ) {
13 +
14 +if ( ! defined( 'ABSPATH' ) )
14 15 exit;
15 -}
16 16
17 -/**
18 - * FormHandler class
19 - *
20 - * @since 1.4.3
21 - */
17 +
22 18 class FormHandler {
23 19
24 - /**
25 - * Constructor
26 - *
27 - * @since 1.4.3
28 - * @return void
29 - */
30 20 public function __construct() {
31 - add_action( 'tutor_action_tutor_retrieve_password', array( $this, 'tutor_retrieve_password' ) );
32 - add_action( 'tutor_action_tutor_process_reset_password', array( $this, 'tutor_process_reset_password' ) );
21 + add_action('tutor_action_tutor_retrieve_password', array($this, 'tutor_retrieve_password'));
22 + add_action('tutor_action_tutor_process_reset_password', array($this, 'tutor_process_reset_password'));
23 +
24 + add_action( 'tutor_reset_password_notification', array( $this, 'reset_password_notification' ), 10, 2 );
33 25 add_filter( 'tutor_lostpassword_url', array( $this, 'lostpassword_url' ) );
34 26 }
35 27
36 - /**
37 - * Retrieve Password
38 - *
39 - * @since 1.4.3
40 - *
41 - * @return void|bool
42 - */
43 - public function tutor_retrieve_password() {
28 + public function tutor_retrieve_password(){
44 29 tutils()->checking_nonce();
45 30
46 - /**
47 - * To check spam or other logic before form process.
48 - *
49 - * @since 2.1.10
50 - */
51 - $before_form_process = apply_filters( 'tutor_before_retrieve_password_form_process', null );
52 - if ( is_wp_error( $before_form_process ) ) {
53 - tutor_flash_set( 'danger', $before_form_process->get_error_message() );
54 - return false;
55 - }
31 + $login = sanitize_user( tutils()->array_get('user_login', $_POST));
56 32
57 - //phpcs:ignore WordPress.Security.NonceVerification.Missing
58 - $login = sanitize_user( tutils()->array_get( 'user_login', $_POST ) );
59 -
60 33 if ( empty( $login ) ) {
61 - tutor_flash_set( 'danger', __( 'Enter a username or email address.', 'tutor' ) );
34 + tutor_flash_set('danger', __( 'Enter a username or email address.', 'tutor' ));
62 35 return false;
63 36 } else {
64 37 // Check on username first, as customers can use emails as usernames.
65 38 $user_data = get_user_by( 'login', $login );
@@ -74,19 +47,19 @@
74 47
75 48 do_action( 'lostpassword_post', $errors );
76 49
77 50 if ( $errors->get_error_code() ) {
78 - tutor_flash_set( 'danger', $errors->get_error_message() );
51 + tutor_flash_set('danger', $errors->get_error_message() );
79 52 return false;
80 53 }
81 54
82 55 if ( ! $user_data ) {
83 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
56 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
84 57 return false;
85 58 }
86 59
87 60 if ( is_multisite() && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) {
88 - tutor_flash_set( 'danger', __( 'Invalid username or email.', 'tutor' ) );
61 + tutor_flash_set('danger', __( 'Invalid username or email.', 'tutor' ) );
89 62 return false;
90 63 }
91 64
92 65 // Redefining user_login ensures we return the right case in the email.
@@ -96,110 +69,116 @@
96 69
97 70 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
98 71
99 72 if ( ! $allow ) {
100 - tutor_flash_set( 'danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
73 + tutor_flash_set('danger', __( 'Password reset is not allowed for this user', 'tutor' ) );
101 74 return false;
102 75 } elseif ( is_wp_error( $allow ) ) {
103 - tutor_flash_set( 'danger', $allow->get_error_message() );
76 + tutor_flash_set('danger', $allow->get_error_message() );
104 77 return false;
105 78 }
106 79
107 - $errors = retrieve_password();
108 - if ( is_wp_error( $errors ) ) {
109 - tutor_flash_set( 'danger', $errors->get_error_message() );
110 - return false;
111 - }
80 + // Get password reset key (function introduced in WordPress 4.4).
81 + $key = get_password_reset_key($user_data);
112 82
113 - $html = '<p> ' . __( "We've sent an email to this account's email address. Click the link in the email to reset your password. If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor' ) . '</p>';
114 - tutor_flash_set( 'success', $html );
83 + // Send email notification.
84 + do_action( 'tutor_reset_password_notification', $user_login, $key );
115 85 }
116 86
117 - /**
118 - * Get lost password URL
119 - *
120 - * @since 1.4.3
121 - *
122 - * @param string $url URL.
123 - * @return string
124 - */
125 - public function lostpassword_url( $url ) {
126 - return tutils()->tutor_dashboard_url( 'retrieve-password' );
87 + public function reset_password_notification( $user_login = '', $reset_key = ''){
88 + $this->sendNotification($user_login, $reset_key);
89 +
90 + $html = "<h3>".__('Check your E-Mail', 'tutor')."</h3>";
91 + $html .= "<p>".__("We've sent an email to this account's email address. Click the link in the email to reset your password", 'tutor')."</p>";
92 + $html .= "<p>".__("If you don't see the email, check other places it might be, like your junk, spam, social, promotion or others folders.", 'tutor')."</p>";
93 + tutor_flash_set('success', $html);
127 94 }
128 95
129 - /**
130 - * Handle reset password request
131 - *
132 - * @since 1.4.3
133 - * @return void|bool
134 - */
135 - public function tutor_process_reset_password() {
96 + public function lostpassword_url($url){
97 + return tutils()->tutor_dashboard_url('retrieve-password');
98 + }
99 +
100 + public function tutor_process_reset_password(){
136 101 tutils()->checking_nonce();
137 102
138 - $reset_key = Input::post( 'reset_key' );
139 - $user_id = Input::post( 'user_id', 0, Input::TYPE_INT );
140 - $password = Input::post( 'password' );
141 - $confirm_password = Input::post( 'confirm_password' );
103 + $reset_key = sanitize_text_field(tutils()->array_get('reset_key', $_POST));
104 + $user_id = (int) sanitize_text_field(tutils()->array_get('user_id', $_POST));
105 + $password = sanitize_text_field(tutils()->array_get('password', $_POST));
106 + $confirm_password = sanitize_text_field(tutils()->array_get('confirm_password', $_POST));
142 107
143 - $user = get_user_by( 'ID', $user_id );
108 + $user = get_user_by('ID', $user_id);
144 109 $user = check_password_reset_key( $reset_key, $user->user_login );
145 110
146 111 if ( is_wp_error( $user ) ) {
147 - tutor_flash_set( 'danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor' ) );
112 + tutor_flash_set('danger', __( 'This key is invalid or has already been used. Please reset your password again if needed.', 'tutor') );
148 113 return false;
149 114 }
150 115
116 +
151 117 if ( $user instanceof \WP_User ) {
152 - if ( ! $password ) {
153 - tutor_flash_set( 'danger', __( 'Please enter your password.', 'tutor' ) );
118 + if ( !$password ) {
119 + tutor_flash_set('danger', __( 'Please enter your password.', 'tutor') );
154 120 return false;
155 121 }
156 122
157 - if ( $password !== $confirm_password ) {
158 - tutor_flash_set( 'danger', __( 'Passwords do not match.', 'tutor' ) );
123 + if ( $password !== $confirm_password) {
124 + tutor_flash_set('danger', __( 'Passwords do not match.', 'tutor') );
159 125 return false;
160 126 }
161 127
162 - tutils()->reset_password( $user, $password );
128 + tutils()->reset_password($user, $password);
163 129
164 130 do_action( 'tutor_user_reset_password', $user );
165 131
166 132 // Perform the login.
167 - $creds = array(
168 - 'user_login' => $user->user_login,
169 - 'user_password' => $password,
170 - 'remember' => true,
171 - );
172 - $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
133 + $creds = array('user_login' => $user->user_login, 'user_password' => $password, 'remember' => true);
134 + $user = wp_signon( apply_filters( 'tutor_login_credentials', $creds ), is_ssl() );
173 135
174 136 do_action( 'tutor_user_reset_password_login', $user );
175 137
176 - wp_safe_redirect( tutor_utils()->tutor_dashboard_url() );
138 + wp_safe_redirect( tutils()->tutor_dashboard_url() );
177 139 exit;
178 140 }
179 141 }
180 142
181 143 /**
182 - * Get e-mail from address
144 + * @param $user_login
145 + * @param $reset_key
183 146 *
184 - * @since 1.4.3
185 - * @return string
147 + * Send E-Mail notification
148 + * We are sending directly right now, later we will introduce centralised E-Mail notification System...
186 149 */
187 - public function get_from_address() {
188 - $from_address = get_tutor_option( 'email_from_address' );
189 - $default = ! $from_address ? get_option( 'admin_email' ) : $from_address;
190 - return apply_filters( 'tutor_email_from_address', $default );
150 + public function sendNotification($user_login, $reset_key){
151 + //Send the E-Mail to user
152 +
153 + $user_data = get_user_by( 'login', $user_login );
154 +
155 + $variable = array(
156 + 'user_login' => $user_login,
157 + 'reset_key' => $reset_key,
158 + 'user_id' => $user_data->ID,
159 + );
160 +
161 + $html = tutor_get_template_html('email.send-reset-password', $variable);
162 + $subject = sprintf(__( 'Password Reset Request for %s', 'tutor' ), get_option( 'blogname' ));
163 +
164 + $header = 'Content-Type: text/html' . "\r\n";
165 +
166 + add_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
167 + add_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
168 +
169 + wp_mail($user_data->user_email, $subject, $html, $header);
170 +
171 + remove_filter( 'wp_mail_from', array( $this, 'get_from_address' ) );
172 + remove_filter( 'wp_mail_from_name', array( $this, 'get_from_name' ) );
191 173 }
192 174
193 - /**
194 - * Get e-mail from name
195 - *
196 - * @since 1.4.3
197 - * @return string
198 - */
199 - public function get_from_name() {
200 - $from_name = get_tutor_option( 'email_from_name' );
201 - $default = ! $from_name ? get_option( 'blogname' ) : $from_name;
202 - return apply_filters( 'tutor_email_from_name', $default );
175 + public function get_from_address(){
176 + return apply_filters('tutor_email_from_address', get_tutor_option('email_from_address'));
203 177 }
204 178
205 -}
179 + public function get_from_name(){
180 + return apply_filters('tutor_email_from_name', get_tutor_option('email_from_name'));
181 + }
182 +
183 +
184 +}