PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.29
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.29
1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 1.0.23 All 172 releases
userswp / includes / class-forms.php

class-forms.php in UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 1.2.29, at includes/class-forms.php

4,941 lines 170.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * Form related functions
5 *
6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
7 *
8 * @since 1.0.0
9 * @author GeoDirectory Team <info@wpgeodirectory.com>
10 */
11 class UsersWP_Forms {
12
13 protected $generated_password;
14
15 /**
16 * Logs the error message.
17 *
18 * @param array|object|string $log Error message.
19 *
20 * @return void
21 * @since 1.0.0
22 * @package userswp
23 *
24 */
25 public static function uwp_error_log( $log ) {
26 uwp_error_log( $log );
27 }
28
29 /**
30 * Initialize UsersWP notices.
31 *
32 * @return void
33 * @package userswp
34 *
35 * @since 1.0.0
36 */
37 public function init_notices() {
38 global $uwp_notices;
39 $uwp_notices = array();
40 }
41
42 /**
43 * Handles all UsersWP forms.
44 *
45 * @return void
46 * @package userswp
47 *
48 * @since 1.0.0
49 */
50 public function handler() {
51 global $uwp_notices;
52
53 ob_start();
54
55 $errors = null;
56 $message = null;
57 $redirect = false;
58 $processed = false;
59 $type = null;
60
61 if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 if ( ! is_wp_error( $errors ) ) {
64 $redirect = $errors;
65 }
66 $message = __( 'Avatar cropped successfully.', 'userswp' );
67 $processed = true;
68 } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 if ( ! is_wp_error( $errors ) ) {
71 $redirect = $errors;
72 }
73 $message = __( 'Banner cropped successfully.', 'userswp' );
74 $processed = true;
75 } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 if ( ! is_wp_error( $errors ) ) {
78 $redirect = $errors;
79 }
80 $message = __( 'Avatar cropped successfully.', 'userswp' );
81 $processed = true;
82 } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 $errors = $this->process_image_crop( $_POST, 'banner', true );
84 if ( ! is_wp_error( $errors ) ) {
85 $redirect = $errors;
86 }
87 $message = __( 'Banner cropped successfully.', 'userswp' );
88 $processed = true;
89 } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 $errors = $this->process_image_reset( 'avatar' );
91 if ( ! is_wp_error( $errors ) ) {
92 $redirect = $errors;
93 }
94 $message = __( 'Avatar reset successfully.', 'userswp' );
95 $processed = true;
96 } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 $errors = $this->process_image_reset( 'banner' );
98 if ( ! is_wp_error( $errors ) ) {
99 $redirect = $errors;
100 }
101 $message = __( 'Banner reset successfully.', 'userswp' );
102 $processed = true;
103 }
104
105 if ( $processed ) {
106
107 if ( is_wp_error( $errors ) ) {
108 echo aui()->alert(
109 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 'type' => 'error',
111 'class' => 'text-center',
112 'content' => wp_kses_post( $errors->get_error_message() ),
113 )
114 );
115 } elseif ( $redirect ) {
116 wp_safe_redirect( $redirect );
117 exit();
118 } else {
119 echo aui()->alert(
120 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 'type' => 'success',
122 'class' => 'text-center',
123 'content' => wp_kses_post( $message ),
124 )
125 );
126 }
127 }
128
129 if ( $type ) {
130 $uwp_notices[] = array( $type => ob_get_contents() );
131 } else {
132 $uwp_notices[] = ob_get_contents();
133 }
134
135 ob_end_clean();
136 }
137
138 /**
139 * Processes avatar and banner uploads form submission.
140 *
141 * @param array $data Submitted $_POST data
142 * @param array $files Submitted $_FILES data
143 *
144 * @return bool|WP_Error|string File url to crop.
145 * @package userswp
146 *
147 * @since 1.0.0
148 */
149 public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
150
151 $file_obj = new UsersWP_Files();
152
153 $current_user_id = get_current_user_id();
154 if ( ! $current_user_id ) {
155 return false;
156 }
157
158 if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
159 return false;
160 }
161
162 do_action( 'uwp_before_validate', $type );
163
164 $result = $file_obj->validate_uploads( $files, $type );
165
166 $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
167
168 if ( is_wp_error( $result ) ) {
169 return $result;
170 }
171
172 $profile_url = uwp_build_profile_tab_url( $current_user_id );
173
174 $url = add_query_arg(
175 array(
176 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
177 'type' => $type,
178 ),
179 $profile_url
180 );
181
182 return $url;
183 }
184
185 /**
186 * Processes avatar and banner uploads image crop.
187 *
188 * @param array $data Submitted $_POST data
189 * @param string $type Image type. Default 'avatar'.
190 * @param bool $unlink_prev_img True to remove previous image. Default false;
191 *
192 * @return bool|WP_Error|string Profile url.
193 * @since 1.0.12 New param $unlink_prev_img introduced.
194 * @package userswp
195 *
196 * @since 1.0.0
197 */
198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
199 global $wpdb;
200 if ( ! is_user_logged_in() ) {
201 return false;
202 }
203
204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 return;
206 }
207
208 // If is current user's profile (profile.php)
209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
210 $user_id = get_current_user_id();
211 // If is another user's profile page
212 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
213 $user_id = absint( $_GET['user_id'] );
214 // Otherwise something is wrong.
215 } else {
216 $user_id = get_current_user_id();
217 }
218
219 // Ensure we have a valid URL with an allowed meme type.
220 $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 $filetype = wp_check_filetype( $image_url );
222
223 $errors = new WP_Error();
224 if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 }
227
228 if ( $errors->has_errors() ) {
229 return $errors;
230 }
231
232 // Retrieve current thumbnail.
233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
235 $thumb_postfix = '_uwp_' . $type . '_thumb';
236
237 if ( $image_url ) {
238 if ( $type == 'avatar' ) {
239 $avatar_size = uwp_get_upload_image_size();
240 $full_width = $avatar_size['width'];
241 } else {
242 $banner_size = uwp_get_upload_image_size( 'banner' );
243 $full_width = $banner_size['width'];
244 }
245
246 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
247 $uploads = wp_upload_dir();
248 remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
249 $upload_url = $uploads['baseurl'];
250 $upload_path = $uploads['basedir'];
251 $image_path = str_replace( $upload_url, $upload_path, $image_url );
252 $ext = $filetype['ext']; // to get extension
253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
256 //Get the new coordinates to crop the image.
257 $x = $data['x'];
258 $y = $data['y'];
259 $w = $data['w'];
260 $h = $data['h'];
261 //Scale the image based on cropped width setting
262 $scale = $full_width / $w;
263 //$scale = 1; // no scaling
264
265 // check we are not editing another user file
266 $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
267 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
268 $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
269
270 // if file already exists then we should not be cropping it.
271 if ( $file_exists ) {
272 wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
273 }
274
275 $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
276 $cropped = str_replace( $upload_path, $upload_url, $cropped );
277
278 // Remove previous avatar/banner
279 $unlink_img = '';
280 if ( $unlink_prev_img && $current_thumbnail ) {
281 $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
282 }
283
284 // remove the uploads path for easy migrations
285 $cropped = str_replace( $upload_url, '', $cropped );
286 if ( $type == 'avatar' ) {
287 uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
288 } else {
289 uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
290 }
291
292 if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
293 @unlink( $unlink_img );
294 $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
295 if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
296 @unlink( $unlink_ori_img );
297 }
298 }
299 }
300
301 if ( is_admin() ) {
302 if ( $user_id == get_current_user_id() ) {
303 $redirect_url = admin_url( 'profile.php' );
304 } else {
305 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
306 }
307 } elseif ( uwp_current_page_url() ) {
308 $redirect_url = uwp_current_page_url();
309 } else {
310 $redirect_url = uwp_build_profile_tab_url( $user_id );
311 }
312
313 return $redirect_url;
314 }
315
316 /**
317 * Normalizes a URL.
318 *
319 */
320 public function normalize_url( $url ) {
321
322 // Normalize.
323 $url = wp_normalize_path( $url );
324
325 // Remove query vars.
326 $url = strtok( $url, '?' );
327
328 // Split.
329 $url = explode( '/', $url );
330
331 // Clean.
332 $url = array_diff( $url, array( '..', '.' ) );
333
334 // Rejoin and return.
335 return implode( '/', $url );
336 }
337
338 /**
339 * Processes avatar and banner image reset.
340 *
341 * @param string $type Image type. Default 'avatar'.
342 *
343 * @return bool|WP_Error|string Profile url.
344 * @package userswp
345 *
346 */
347 public function process_image_reset( $type ) {
348 if ( ! is_user_logged_in() ) {
349 return false;
350 }
351
352 if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 return;
354 }
355
356 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
357 $user_id = get_current_user_id();
358 // If is another user's profile page
359 } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
360 $user_id = absint( $_GET['user_id'] );
361 // Otherwise something is wrong.
362 } else {
363 $user_id = get_current_user_id();
364 }
365
366 $errors = new WP_Error();
367 if ( empty( $user_id ) ) {
368 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
369 }
370
371 $error_code = $errors->get_error_code();
372 if ( ! empty( $error_code ) ) {
373 return $errors;
374 }
375
376 if ( $type == 'avatar' ) {
377 uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
378 } elseif ( $type == 'banner' ) {
379 uwp_update_usermeta( $user_id, 'banner_thumb', '' );
380 } else {
381 // Do nothing
382 }
383
384 if ( is_admin() ) {
385 if ( $user_id == get_current_user_id() ) {
386 $redirect_url = admin_url( 'profile.php' );
387 } else {
388 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
389 }
390 } elseif ( uwp_current_page_url() ) {
391 $redirect_url = uwp_current_page_url();
392 } else {
393 $redirect_url = uwp_build_profile_tab_url( $user_id );
394 }
395
396 return $redirect_url;
397 }
398
399 /**
400 * Displays links in a dropdown
401 *
402 * @param $options
403 *
404 * @package userswp
405 *
406 * @since 1.0.0
407 */
408 public function output_dashboard_links( $options ) {
409 if ( ! empty( $options ) ) {
410 $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
411 echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
412 $this->output_options( $options );
413 echo '</select>';
414 }
415 }
416
417 /**
418 * Displays options for the dashboard links
419 *
420 * @param $options
421 *
422 * @package userswp
423 *
424 * @since 1.0.0
425 */
426 public function output_options( $options ) {
427 if ( ! empty( $options ) ) {
428 foreach ( $options as $key => $link ) {
429
430 if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
431 $this->output_options( $link );
432 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
433 echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
434 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
435 echo '</optgroup>';
436 } elseif ( ! empty( $link['text'] ) ) {
437 echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
438 echo esc_attr__( $link['text'], 'userswp' );
439 echo '</option>';
440 }
441 }
442 }
443 }
444
445 /**
446 * Displays UsersWP notices in forms.
447 *
448 * @param string $type Form type
449 *
450 * @return void
451 * @since 1.0.0
452 * @package userswp
453 *
454 */
455 public function display_notices( $type ) {
456 global $uwp_notices;
457
458 if ( is_array( $uwp_notices ) ) {
459 foreach ( $uwp_notices as $notice ) {
460
461 // If the notification is type specific then only output on that type
462 if ( is_array( $notice ) ) {
463 foreach ( $notice as $key => $val ) {
464 if ( $key == $type ) {
465 echo wp_kses_post( $val );
466 }
467 }
468 } elseif ( ! empty( $notice ) ) {
469 echo wp_kses_post( $notice );
470 }
471 }
472 }
473
474 if ( $type == 'change' ) {
475 $user_id = get_current_user_id();
476 $password_nag = get_user_option( 'default_password_nag', $user_id );
477
478 if ( $password_nag ) {
479 $change_page = uwp_get_page_id( 'change_page', false );
480 $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
481
482 if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
483 delete_user_meta( $user_id, 'default_password_nag' );
484 $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
485 echo aui()->alert(
486 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
487 'class' => 'text-center',
488 'type' => 'success',
489 'content' => wp_kses_post( $message ),
490 )
491 );
492 } else {
493 $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
494 echo aui()->alert(
495 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
496 'class' => 'text-center',
497 'type' => 'warning',
498 'content' => wp_kses_post( $message ),
499 )
500 );
501 }
502 }
503 }
504 }
505
506 /**
507 * Processes register form submission.
508 *
509 * @since 1.0.0
510 * @package userswp
511 *
512 */
513 public function process_register() {
514
515 $data = $_POST;
516
517 if ( ! isset( $data['uwp_register_nonce'] ) ) {
518 return;
519 }
520
521 global $uwp_notices;
522
523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
525 }
526
527 if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
528 $message = aui()->alert(
529 array(
530 'type' => 'error',
531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
532 )
533 );
534 if ( wp_doing_ajax() ) {
535 wp_send_json_error( array( 'message' => $message ) );
536 } else {
537 $uwp_notices[] = array( 'register' => $message );
538
539 return;
540 }
541 }
542
543 $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
544 if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
545 $message = aui()->alert(
546 array(
547 'type' => 'error',
548 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
549 )
550 );
551 if ( wp_doing_ajax() ) {
552 wp_send_json_error( array( 'message' => $message ) );
553 } else {
554 $uwp_notices[] = array( 'register' => $message );
555
556 return;
557 }
558 }
559
560 if ( ! get_option( 'users_can_register' ) ) {
561 $message = aui()->alert(
562 array(
563 'type' => 'error',
564 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
565 )
566 );
567 if ( wp_doing_ajax() ) {
568 wp_send_json_error( array( 'message' => $message ) );
569 } else {
570 $uwp_notices[] = array( 'register' => $message );
571
572 return;
573 }
574 }
575
576 $files = $_FILES;
577 $errors = new WP_Error();
578 $file_obj = new UsersWP_Files();
579
580 do_action( 'uwp_before_validate', 'register' );
581
582 $result = uwp_validate_fields( $data, 'register' );
583
584 $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
585
586 if ( is_wp_error( $result ) ) {
587 $message = aui()->alert(
588 array(
589 'type' => 'error',
590 'content' => $result->get_error_message(),
591 )
592 );
593 if ( wp_doing_ajax() ) {
594 wp_send_json_error( array( 'message' => $message ) );
595 } else {
596 $uwp_notices[] = array( 'register' => $message );
597
598 return;
599 }
600 }
601
602 $uploads_result = $file_obj->validate_uploads( $files, 'register' );
603
604 if ( is_wp_error( $uploads_result ) ) {
605 $message = aui()->alert(
606 array(
607 'type' => 'error',
608 'content' => $uploads_result->get_error_message(),
609 )
610 );
611 if ( wp_doing_ajax() ) {
612 wp_send_json_error( array( 'message' => $message ) );
613 } else {
614 $uwp_notices[] = array( 'register' => $message );
615
616 return;
617 }
618 }
619
620 do_action( 'uwp_after_validate', $result, 'register', $data );
621
622 $result = array_merge( $result, $uploads_result );
623
624 if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
625 $password = $result['password'];
626 $generated_password = false;
627 } else {
628 $password = wp_generate_password();
629 $this->generated_password = $password;
630 $generated_password = true;
631 }
632
633 $first_name = '';
634 if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
635 $first_name = $result['first_name'];
636 }
637
638 $last_name = '';
639 if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
640 $last_name = $result['last_name'];
641 }
642
643 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
644 $display_name = $result['display_name'];
645 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
646 $display_name = $first_name . ' ' . $last_name;
647 } else {
648 $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
649 }
650
651 $user_url = '';
652 if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
653 $user_url = esc_url_raw( $result['user_url'] );
654 }
655
656 $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
657 $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
658
659 if ( empty( $user_login ) ) {
660 $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
661 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
662 $new_user_login = strstr( $email, '@', true );
663 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
664 $user_login = sanitize_user( $new_user_login, true );
665 }
666 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
667 $user_append_text = rand( 10, 1000 );
668 $user_login = sanitize_user( $new_user_login . $user_append_text, true );
669 }
670
671 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
672 $user_login = $email;
673 }
674 }
675 } elseif ( ! validate_username( $user_login ) ) {
676 $message = aui()->alert(
677 array(
678 'type' => 'error',
679 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
680 )
681 );
682 if ( wp_doing_ajax() ) {
683 wp_send_json_error( array( 'message' => $message ) );
684 } else {
685 $uwp_notices[] = array( 'register' => $message );
686
687 return;
688 }
689 }
690
691 $args = array(
692 'user_login' => sanitize_user( $user_login ),
693 'user_email' => sanitize_email( $email ),
694 'user_pass' => $password,
695 'display_name' => sanitize_text_field( $display_name ),
696 'first_name' => esc_attr( $first_name ),
697 'last_name' => esc_attr( $last_name ),
698 'user_url' => esc_url_raw( $user_url ),
699 );
700
701 $user_id = wp_insert_user( $args );
702
703 if ( is_wp_error( $user_id ) ) {
704 $message = aui()->alert(
705 array(
706 'type' => 'error',
707 'content' => $user_id->get_error_message(),
708 )
709 );
710 if ( wp_doing_ajax() ) {
711 wp_send_json_error( array( 'message' => $message ) );
712 } else {
713 $uwp_notices[] = array( 'register' => $message );
714
715 return;
716 }
717 }
718
719 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
720
721 $form_id = 1;
722
723 if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
724 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
725 $form_id = (int) $data['uwp_register_form_id'];
726 }
727
728 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
729
730 if ( isset( $user_role ) && ! empty( $user_role ) ) {
731 $user_roles = uwp_get_user_roles();
732 $chosen_role = strtolower( $user_role );
733 if ( ! empty( $user_roles ) ) {
734 $wp_roles = wp_roles();
735 if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
736 $new_user = get_userdata( $user_id );
737 if ( $new_user ) {
738 $new_user->set_role( $chosen_role );
739 }
740 }
741 }
742 }
743
744 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
745
746 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
747
748 if ( is_wp_error( $save_result ) ) {
749 $message = aui()->alert(
750 array(
751 'type' => 'error',
752 'content' => $save_result->get_error_message(),
753 )
754 );
755 if ( wp_doing_ajax() ) {
756 wp_send_json_error( array( 'message' => $message ) );
757 } else {
758 $uwp_notices[] = array( 'register' => $message );
759
760 return;
761 }
762 }
763
764 if ( ! $save_result ) {
765 $message = aui()->alert(
766 array(
767 'type' => 'error',
768 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
769 )
770 );
771 if ( wp_doing_ajax() ) {
772 wp_send_json_error( array( 'message' => $message ) );
773 } else {
774 $uwp_notices[] = array( 'register' => $message );
775
776 return;
777 }
778 }
779
780 //updating bio field after saving extra fields to reflect the points in mycred add on.
781 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
782 $args = array(
783 'ID' => $user_id,
784 'description' => $result['bio'],
785 );
786 wp_update_user( $args );
787 }
788
789 do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
790
791 // Unset post data to empty the form on submit
792 $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
793 foreach ( $data as $key => $value ) {
794 if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
795 unset( $_POST[ $key ] );
796 }
797 }
798
799 $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
800 if ( ! $reg_action ) {
801 $reg_action = uwp_get_option( 'uwp_registration_action', false );
802 }
803
804 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
805
806 if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
807
808 $user_data = get_userdata( $user_id );
809 $activation_link = uwp_get_activation_link( $user_id );
810
811 $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
812
813 $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
814
815 $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
816
817 $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
818
819 $email_vars = array(
820 'user_id' => $user_id,
821 'login_details' => $activate_message,
822 'activation_link' => $activation_link,
823 );
824
825 UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
826
827 } elseif ( $reg_action != 'require_admin_review' ) {
828
829 $user_data = get_userdata( $user_id );
830
831 if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
832 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
833 update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
834 }
835 $message_pass = $this->generated_password;
836 $this->generated_password = false;
837 } else {
838 $message_pass = __( 'Password you entered during registration.', 'userswp' );
839 }
840
841 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
842 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
843 <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
844
845 $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
846
847 $email_vars = array(
848 'user_id' => $user_id,
849 'login_details' => $message,
850 'form_fields' => $form_fields,
851 );
852
853 UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
854 }
855
856 $error_code = $errors->get_error_code();
857 if ( ! empty( $error_code ) ) {
858 $message = aui()->alert(
859 array(
860 'type' => 'error',
861 'content' => $result->get_error_message(),
862 )
863 );
864 if ( wp_doing_ajax() ) {
865 wp_send_json_error( array( 'message' => $message ) );
866 } else {
867 $uwp_notices[] = array( 'register' => $message );
868 return;
869 }
870 }
871
872 if ( $reg_action != 'require_admin_review' ) {
873
874 $user_data = get_userdata( $user_id );
875 $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
876 <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
877 <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
878 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
879 <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
880
881 $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
882
883 $email_vars = array(
884 'user_id' => $user_id,
885 'extras' => $extras,
886 'form_fields' => $form_fields,
887 );
888
889 UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
890
891 }
892
893 if ( $reg_action == 'auto_approve_login' ) {
894 $res = wp_signon(
895 array(
896 'user_login' => $user_login,
897 'user_password' => $password,
898 'remember' => false,
899 )
900 );
901
902 if ( is_wp_error( $res ) ) {
903 $message = aui()->alert(
904 array(
905 'type' => 'error',
906 'content' => $res->get_error_message(),
907 )
908 );
909
910 if ( wp_doing_ajax() ) {
911 wp_send_json_error( array( 'message' => $message ) );
912 } else {
913 $uwp_notices[] = array( 'register' => $message );
914 }
915 } else {
916 $redirect_to = $this->get_register_redirect_url( $data, $user_id );
917 do_action( 'uwp_after_process_register', $result, $user_id );
918
919 if ( wp_doing_ajax() ) {
920 $message = aui()->alert(
921 array(
922 'type' => 'success',
923 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
924 )
925 );
926 $response = array(
927 'message' => $message,
928 'redirect' => $redirect_to,
929 );
930 wp_send_json_success( $response );
931 } else {
932 wp_safe_redirect( $redirect_to );
933 }
934 exit();
935 }
936 } else {
937 if ( $reg_action == 'require_email_activation' ) {
938 $resend_link = uwp_get_register_page_url();
939 $resend_link = add_query_arg(
940 array(
941 'user_id' => $user_id,
942 'action' => 'uwp_resend',
943 '_nonce' => wp_create_nonce( 'uwp_resend' ),
944 ),
945 $resend_link
946 );
947
948 $message = aui()->alert(
949 array(
950 'type' => 'success',
951 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
952 )
953 );
954
955 } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
956
957 update_user_meta( $user_id, 'uwp_mod', '1' );
958
959 do_action( 'uwp_require_admin_review', $user_id, $result );
960
961 $message = aui()->alert(
962 array(
963 'type' => 'success',
964 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
965 )
966 );
967 } else {
968
969 $login_page_url = wp_login_url();
970
971 if ( $generated_password ) {
972 $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
973 } else {
974 $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
975 }
976
977 $message = aui()->alert(
978 array(
979 'type' => 'success',
980 'content' => $msg,
981 )
982 );
983 }
984
985 do_action( 'uwp_after_process_register', $result, $user_id );
986
987 if ( wp_doing_ajax() ) {
988 wp_send_json_success( array( 'message' => $message ) );
989 } else {
990 $uwp_notices[] = array( 'register' => $message );
991 }
992 }
993
994 if ( wp_doing_ajax() ) {
995 wp_send_json_error();
996 } // if we got this far there is a problem
997 }
998
999 /**
1000 * Saves UsersWP related user custom fields.
1001 *
1002 * @param int $user_id User ID.
1003 * @param array $data Result array.
1004 * @param string $type Form type.
1005 *
1006 * @return bool True when success. False when failure.
1007 * @since 1.0.0
1008 * @package userswp
1009 *
1010 */
1011 public function save_user_extra_fields( $user_id, $data, $type ) {
1012
1013 if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1014 return false;
1015 }
1016
1017 // custom user fields not applicable for login and forgot
1018 if ( $type == 'login' || $type == 'forgot' ) {
1019 return true;
1020 }
1021
1022 if ( $type == 'account' || $type == 'register' ) {
1023 if ( isset( $data['password'] ) ) {
1024 unset( $data['password'] );
1025 }
1026 }
1027
1028 if ( $type == 'register' ) {
1029 if ( isset( $data['username'] ) ) {
1030 unset( $data['username'] );
1031 }
1032 if ( isset( $data['email'] ) ) {
1033 unset( $data['email'] );
1034 }
1035 }
1036
1037 if ( empty( $data ) ) {
1038 // no extra fields. so just return
1039 return true;
1040 } else {
1041 foreach ( $data as $key => $value ) {
1042 if ( 'uwp_language' == $key ) {
1043 update_user_meta( $user_id, 'locale', $value );
1044 }
1045 uwp_update_usermeta( $user_id, $key, $value );
1046 }
1047
1048 return true;
1049 }
1050 }
1051
1052 public function get_register_redirect_url( $data, $user ) {
1053 if ( is_int( $user ) ) {
1054 $user = get_userdata( $user );
1055 }
1056
1057 $redirect_page_id = $custom_url = '';
1058 if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1059 $form_id = (int) $data['uwp_register_form_id'];
1060 $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1061 $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1062 }
1063
1064 if ( ! $redirect_page_id ) {
1065 $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1066 $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1067 }
1068
1069 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1070 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1071 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1072 $redirect_to = esc_url_raw( $data['redirect_to'] );
1073 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1074 if ( uwp_is_wpml() ) {
1075 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1076 if ( ! empty( $wpml_page_id ) ) {
1077 $redirect_page_id = $wpml_page_id;
1078 }
1079 }
1080 $redirect_to = get_permalink( $redirect_page_id );
1081 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1082 $redirect_to = esc_url( wp_get_referer() );
1083 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1084 $redirect_to = $custom_url;
1085 } else {
1086 if ( $user && $user->has_cap( 'manage_options' ) ) {
1087 $redirect_to = admin_url();
1088 } else {
1089 $redirect_to = home_url( '/' );
1090 }
1091
1092 $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1093 }
1094
1095 return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1096 }
1097
1098 /**
1099 * Processes login form submission.
1100 *
1101 * @since 1.0.0
1102 * @package userswp
1103 *
1104 */
1105 public function process_login() {
1106
1107 $data = $_POST;
1108
1109 if ( ! isset( $data['uwp_login_nonce'] ) ) {
1110 return;
1111 }
1112
1113 if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1114 $message = aui()->alert(
1115 array(
1116 'type' => 'error',
1117 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1118 )
1119 );
1120 if ( wp_doing_ajax() ) {
1121 wp_send_json_error( array( 'message' => $message ) );
1122 } else {
1123 return;
1124 }
1125 }
1126
1127 global $uwp_notices;
1128
1129 do_action( 'uwp_before_validate', 'login' );
1130
1131 $result = uwp_validate_fields( $data, 'login' );
1132
1133 $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1134
1135 if ( is_wp_error( $result ) ) {
1136 $message = aui()->alert(
1137 array(
1138 'type' => 'error',
1139 'content' => $result->get_error_message(),
1140 )
1141 );
1142 if ( wp_doing_ajax() ) {
1143 wp_send_json_error( array( 'message' => $message ) );
1144 } else {
1145 $uwp_notices[] = array( 'login' => $message );
1146
1147 return;
1148 }
1149 }
1150
1151 do_action( 'uwp_after_validate', $result, 'login', $data );
1152
1153 if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1154 $remember_me = true;
1155 } else {
1156 $remember_me = false;
1157 }
1158
1159 remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1160
1161 global $wp2fa;
1162 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1163 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1164 }
1165
1166 $user = wp_signon(
1167 array(
1168 'user_login' => $result['username'],
1169 'user_password' => $result['password'],
1170 'remember' => $remember_me,
1171 )
1172 );
1173
1174 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1175
1176 if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177
1178 $two_fa = $this->check_2fa( $user );
1179 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1180 if ( is_wp_error( $two_fa ) ) {
1181 $message = aui()->alert(
1182 array(
1183 'type' => 'error',
1184 'content' => $two_fa->get_error_message(),
1185 )
1186 );
1187 wp_send_json_error( array( 'message' => $message ) );
1188 } else {
1189 wp_send_json_success(
1190 array(
1191 'html' => $two_fa,
1192 'is_2fa' => true,
1193 )
1194 );
1195 }
1196 }
1197 }
1198
1199 if ( is_wp_error( $user ) ) {
1200 $message = aui()->alert(
1201 array(
1202 'type' => 'error',
1203 'content' => $user->get_error_message(),
1204 )
1205 );
1206 if ( wp_doing_ajax() ) {
1207 wp_send_json_error( array( 'message' => $message ) );
1208 } else {
1209 $uwp_notices[] = array( 'login' => $message );
1210
1211 return;
1212 }
1213 } else {
1214 do_action( 'uwp_after_process_login', $data );
1215 $message = aui()->alert(
1216 array(
1217 'type' => 'success',
1218 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1219 )
1220 );
1221 if ( wp_doing_ajax() ) {
1222 $redirect_to = '';
1223 if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1224 $redirect_to = $this->get_login_redirect_url( $data, $user );
1225 }
1226 wp_send_json_success(
1227 array(
1228 'message' => $message,
1229 'redirect' => $redirect_to,
1230 )
1231 );
1232 } else {
1233 $redirect_to = $this->get_login_redirect_url( $data, $user );
1234 wp_safe_redirect( $redirect_to );
1235 exit();
1236 }
1237 }
1238 }
1239
1240 public function check_2fa( $user ) {
1241 if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1242 return;
1243 }
1244
1245 if ( ! $user ) {
1246 $user = wp_get_current_user();
1247 }
1248
1249 global $wp2fa;
1250 $errors = new WP_Error();
1251
1252 if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1253 return;
1254 }
1255 // Invalidate the current login session to prevent from being re-used.
1256 \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1257
1258 // Also clear the cookies which are no longer valid.
1259 wp_clear_auth_cookie();
1260
1261 $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1262 if ( ! $login_nonce ) {
1263 $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1264
1265 return $errors;
1266 }
1267
1268 $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1269
1270 ob_start();
1271 ?>
1272
1273 <div class="uwp-2fa-methods-wrap">
1274 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1275 autocomplete="off">
1276 <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1277 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1278 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1279 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1280 <?php
1281
1282 // Check to see what provider is set and give the relevant authentication page.
1283 if ( 'totp' === $provider ) {
1284 ?>
1285 <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1286 <?php
1287
1288 echo aui()->input(
1289 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1290 'type' => 'tel',
1291 'id' => 'authcode',
1292 'name' => 'authcode',
1293 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1294 'value' => '',
1295 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1296 )
1297 );
1298
1299 echo aui()->button(
1300 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1301 'type' => 'submit',
1302 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1303 'name' => 'submit',
1304 'icon' => '',
1305 'content' => esc_html__( 'Log In', 'userswp' ),
1306 )
1307 );
1308
1309 } elseif ( 'email' === $provider ) {
1310 $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1311 if ( empty( $has_token ) || ! $has_token ) {
1312 \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1313 }
1314 ?>
1315 <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1316 <?php
1317 echo aui()->input(
1318 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1319 'type' => 'tel',
1320 'id' => 'authcode',
1321 'name' => 'wp-2fa-email-code',
1322 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1323 'value' => '',
1324 'label' => esc_html__( 'Verification Code', 'userswp' ),
1325 'extra_attributes' => array(
1326 'size' => 20,
1327 'pattern' => '[0-9]*',
1328 ),
1329 )
1330 );
1331
1332 echo aui()->button(
1333 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1334 'type' => 'submit',
1335 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1336 'name' => 'submit',
1337 'icon' => '',
1338 'content' => esc_html__( 'Log In', 'userswp' ),
1339 )
1340 );
1341
1342 echo aui()->button(
1343 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1344 'type' => 'button',
1345 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1346 'name' => 'wp-2fa-email-code-resend',
1347 'icon' => '',
1348 'content' => esc_html__( 'Resend Code', 'userswp' ),
1349 )
1350 );
1351
1352 }
1353 ?>
1354 </form>
1355 </div>
1356
1357 <?php
1358 $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1359 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1360 ?>
1361 <div class="uwp-2fa-methods-wrap" style="display:none;">
1362 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1363 class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1364 <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1365 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1366 value="<?php echo esc_attr( $user->ID ); ?>"/>
1367 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1368 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1369 <div class="uwp-backup-fields">
1370 <?php
1371 echo aui()->input(
1372 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1373 'type' => 'tel',
1374 'id' => 'authcode',
1375 'name' => 'wp-2fa-backup-code',
1376 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1377 'value' => '',
1378 'label' => esc_html__( 'Backup Code', 'userswp' ),
1379 'extra_attributes' => array(
1380 'size' => 20,
1381 'pattern' => '[0-9]*',
1382 ),
1383 )
1384 );
1385
1386 echo aui()->button(
1387 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1388 'type' => 'submit',
1389 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1390 'name' => 'submit',
1391 'icon' => '',
1392 'content' => esc_html__( 'Log In', 'userswp' ),
1393 )
1394 );
1395 ?>
1396 </div>
1397 </form>
1398 </div>
1399 <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1400 <script type="text/javascript">
1401 jQuery('.uwp-switch-2fa-methods').on('click',
1402 function (e) {
1403 e.preventDefault();
1404 jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1405 jQuery('.uwp-2fa-methods-wrap').toggle();
1406 return false;
1407 }
1408 );
1409 </script>
1410 <?php
1411 }
1412
1413 return ob_get_clean();
1414 }
1415
1416 public function process_login_2fa() {
1417 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1418 return;
1419 }
1420
1421 $auth_id = (int) $_POST['uwp-auth-id'];
1422 $user = get_userdata( $auth_id );
1423 if ( ! $user ) {
1424 $message = aui()->alert(
1425 array(
1426 'type' => 'error',
1427 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1428 )
1429 );
1430
1431 wp_send_json_error( array( 'message' => $message ) );
1432 }
1433
1434 global $wp2fa;
1435
1436 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1437 if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1438
1439 $message = aui()->alert(
1440 array(
1441 'type' => 'error',
1442 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1443 )
1444 );
1445
1446 wp_send_json_error( array( 'message' => $message ) );
1447 }
1448
1449 if ( isset( $_POST['provider'] ) ) {
1450 $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1451 $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1452 if ( isset( $providers[ $provider ] ) ) {
1453 $provider = $providers[ $provider ];
1454 } elseif ( isset( $provider ) ) {
1455 $provider = $provider;
1456 } else {
1457 $provider = $provider;
1458 }
1459 }
1460
1461 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1462 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1463
1464 }
1465
1466 // Validate TOTP.
1467 if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
1468
1469 do_action( 'wp_login_failed', $user->user_login );
1470
1471 $message = aui()->alert(
1472 array(
1473 'type' => 'error',
1474 'content' => __( 'Invalid verification code.', 'userswp' ),
1475 )
1476 );
1477
1478 wp_send_json_error( array( 'message' => $message ) );
1479 }
1480
1481 // Validate Email.
1482 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
1483
1484 do_action( 'wp_login_failed', $user->user_login );
1485
1486 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1487 $message = aui()->alert(
1488 array(
1489 'type' => 'info',
1490 'content' => __( 'A new code has been sent.', 'userswp' ),
1491 )
1492 );
1493
1494 wp_send_json_error( array( 'message' => $message ) );
1495 } else {
1496 $message = aui()->alert(
1497 array(
1498 'type' => 'error',
1499 'content' => __( 'Invalid verification code.', 'userswp' ),
1500 )
1501 );
1502
1503 wp_send_json_error( array( 'message' => $message ) );
1504 }
1505 }
1506
1507 // Backup Codes.
1508 if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1509
1510 do_action( 'wp_login_failed', $user->user_login );
1511
1512 $message = aui()->alert(
1513 array(
1514 'type' => 'error',
1515 'content' => __( 'Invalid backup code.', 'userswp' ),
1516 )
1517 );
1518
1519 wp_send_json_error( array( 'message' => $message ) );
1520 }
1521
1522 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1523
1524 $rememberme = false;
1525 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1526 if ( ! empty( $remember ) ) {
1527 $rememberme = true;
1528 }
1529
1530 wp_set_auth_cookie( $user->ID, $rememberme );
1531
1532 do_action( 'two_factor_user_authenticated', $user );
1533
1534 $message = aui()->alert(
1535 array(
1536 'type' => 'success',
1537 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1538 )
1539 );
1540
1541 wp_send_json_success( array( 'message' => $message ) );
1542 }
1543
1544 public function get_login_redirect_url( $data, $user ) {
1545 if ( is_int( $user ) ) {
1546 $user = get_userdata( $user );
1547 }
1548
1549 $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1550 $custom_url = uwp_get_option( 'login_redirect_custom_url' );
1551
1552 if ( $user && isset( $user->roles[0] ) ) {
1553 $user_role = $user->roles[0];
1554 $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1555 $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1556 }
1557
1558 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1559 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1560 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1561 $redirect_to = esc_url_raw( $data['redirect_to'] );
1562 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1563 if ( uwp_is_wpml() ) {
1564 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1565 if ( ! empty( $wpml_page_id ) ) {
1566 $redirect_page_id = $wpml_page_id;
1567 }
1568 }
1569 $redirect_to = get_permalink( $redirect_page_id );
1570 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1571 $redirect_to = esc_url( wp_get_referer() );
1572 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1573 $redirect_to = $custom_url;
1574 } else {
1575 $redirect_to = home_url( '/' );
1576 $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1577 }
1578
1579 return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1580 }
1581
1582 /**
1583 * Processes forgot password form submission.
1584 *
1585 * @since 1.0.0
1586 * @package userswp
1587 *
1588 */
1589 public function process_forgot() {
1590
1591 $data = $_POST;
1592
1593 if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1594 return;
1595 }
1596
1597 if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1598 $message = aui()->alert(
1599 array(
1600 'type' => 'error',
1601 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1602 )
1603 );
1604 if ( wp_doing_ajax() ) {
1605 wp_send_json_error( $message );
1606 } else {
1607 return;
1608 }
1609 }
1610
1611 global $uwp_notices;
1612
1613 do_action( 'uwp_before_validate', 'forgot' );
1614
1615 $result = uwp_validate_fields( $data, 'forgot' );
1616
1617 $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
1618
1619 if ( is_wp_error( $result ) ) {
1620 $message = aui()->alert(
1621 array(
1622 'type' => 'error',
1623 'content' => $result->get_error_message(),
1624 )
1625 );
1626 if ( wp_doing_ajax() ) {
1627 wp_send_json_error( $message );
1628 } else {
1629 $uwp_notices[] = array( 'forgot' => $message );
1630
1631 return;
1632 }
1633 }
1634
1635 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1636
1637 $user_data = get_user_by( 'email', $data['email'] );
1638
1639 // if no user we fake it and bail
1640 if ( ! $user_data ) {
1641 $args = apply_filters(
1642 'uwp_forgot_error_message',
1643 array(
1644 'type' => 'error',
1645 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1646 )
1647 );
1648
1649 $message = aui()->alert( $args );
1650 if ( wp_doing_ajax() ) {
1651 wp_send_json_success( $message );
1652 } else {
1653 $uwp_notices[] = array( 'forgot' => $message );
1654
1655 return;
1656 }
1657 }
1658
1659 // make sure user account is active before account reset
1660 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1661 if ( $mod_value == 'email_unconfirmed' ) {
1662 $message = aui()->alert(
1663 array(
1664 'type' => 'error',
1665 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1666 )
1667 );
1668 if ( wp_doing_ajax() ) {
1669 wp_send_json_error( $message );
1670 } else {
1671 $uwp_notices[] = array( 'forgot' => $message );
1672
1673 return;
1674 }
1675 }
1676
1677 $user_data = get_userdata( $user_data->ID );
1678
1679 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
1680
1681 if ( ! $allow ) {
1682 return false;
1683 } elseif ( is_wp_error( $allow ) ) {
1684 return false;
1685 }
1686
1687 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
1688
1689 global $wpdb, $wp_hasher;
1690 $reset_link = '';
1691
1692 if ( $as_password ) {
1693 $new_pass = wp_generate_password( 12, false );
1694 wp_set_password( $new_pass, $user_data->ID );
1695 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
1696 update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
1697 }
1698 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
1699 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1700 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
1701
1702 } else {
1703 $key = wp_generate_password( 20, false );
1704 do_action( 'retrieve_password_key', $user_data->user_login, $key );
1705
1706 if ( empty( $wp_hasher ) ) {
1707 require_once ABSPATH . 'wp-includes/class-phpass.php';
1708 $wp_hasher = new PasswordHash( 8, true );
1709 }
1710 $hashed = $wp_hasher->HashPassword( $key );
1711 $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1712 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1713 $message .= home_url( '/' ) . '</p>';
1714 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1715 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
1716 $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
1717 $reset_page = uwp_get_page_id( 'reset_page', false );
1718 if ( $reset_page ) {
1719 $reset_link = add_query_arg(
1720 array(
1721 'key' => $key,
1722 'login' => rawurlencode( $user_data->user_login ),
1723 ),
1724 get_permalink( $reset_page )
1725 );
1726 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1727 } else {
1728 $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
1729 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1730 }
1731 $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
1732 }
1733
1734 $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
1735
1736 $email_vars = array(
1737 'user_id' => $user_data->ID,
1738 'login_details' => $message,
1739 'reset_link' => $reset_link,
1740 );
1741
1742 UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
1743
1744 do_action( 'uwp_after_process_forgot', $data );
1745
1746 $message = aui()->alert(
1747 array(
1748 'type' => 'success',
1749 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
1750 )
1751 );
1752 if ( wp_doing_ajax() ) {
1753 wp_send_json_success( $message );
1754 } else {
1755 $uwp_notices[] = array( 'forgot' => $message );
1756 }
1757 }
1758
1759 /**
1760 * Processes change password form submission.
1761 *
1762 * @since 1.0.0
1763 * @package userswp
1764 *
1765 */
1766 public function process_change() {
1767
1768 $data = $_POST;
1769
1770 if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
1771 return;
1772 }
1773
1774 global $uwp_notices;
1775
1776 if ( is_uwp_account_page() ) {
1777 $notice_type = 'account';
1778 } else {
1779 $notice_type = 'change';
1780 }
1781
1782 do_action( 'uwp_before_validate', 'change' );
1783
1784 $result = uwp_validate_fields( $data, 'change' );
1785
1786 $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
1787
1788 if ( is_wp_error( $result ) ) {
1789 $message = aui()->alert(
1790 array(
1791 'type' => 'error',
1792 'content' => $result->get_error_message(),
1793 )
1794 );
1795 $uwp_notices[] = array( $notice_type => $message );
1796
1797 return;
1798 }
1799
1800 do_action( 'uwp_after_validate', $result, 'change', $data );
1801
1802 $user_data = get_user_by( 'id', get_current_user_id() );
1803
1804 if ( ! $user_data ) {
1805 $message = aui()->alert(
1806 array(
1807 'type' => 'error',
1808 'content' => $user_data->get_error_message(),
1809 )
1810 );
1811 $uwp_notices[] = array( $notice_type => $message );
1812
1813 return;
1814 }
1815
1816 $email_vars = array(
1817 'user_id' => $user_data->ID,
1818 );
1819
1820 UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
1821
1822 wp_set_password( $result['password'], $user_data->ID );
1823
1824 $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
1825 if ( $password_nag ) {
1826 delete_user_meta( $user_data->ID, 'default_password_nag' );
1827 }
1828
1829 delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
1830
1831 $message = aui()->alert(
1832 array(
1833 'type' => 'success',
1834 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
1835 )
1836 );
1837
1838 $uwp_notices[] = array( $notice_type => $message );
1839
1840 do_action( 'uwp_after_process_change', $data );
1841
1842 wp_logout();
1843 exit();
1844 }
1845
1846 /**
1847 * Processes reset password form submission.
1848 *
1849 * @since 1.0.0
1850 * @package userswp
1851 *
1852 */
1853 public function process_reset() {
1854
1855 $data = $_POST;
1856
1857 if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
1858 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
1859 }
1860
1861 if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
1862 return;
1863 }
1864
1865 global $uwp_notices;
1866
1867 do_action( 'uwp_before_validate', 'reset' );
1868
1869 $result = uwp_validate_fields( $data, 'reset' );
1870
1871 $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
1872
1873 if ( is_wp_error( $result ) ) {
1874 $message = aui()->alert(
1875 array(
1876 'type' => 'error',
1877 'content' => $result->get_error_message(),
1878 )
1879 );
1880 $uwp_notices[] = array( 'reset' => $message );
1881
1882 return;
1883 }
1884
1885 do_action( 'uwp_after_validate', $result, 'reset', $data );
1886
1887 $login = sanitize_text_field( $data['uwp_reset_username'] );
1888 $key = sanitize_text_field( $data['uwp_reset_key'] );
1889
1890 $user = get_user_by( 'login', $login );
1891 if ( ! $user ) {
1892 $message = aui()->alert(
1893 array(
1894 'type' => 'error',
1895 'content' => __( 'Invalid username.', 'userswp' ),
1896 )
1897 );
1898 $uwp_notices[] = array( 'reset' => $message );
1899
1900 return;
1901 }
1902
1903 clean_user_cache( $user );
1904
1905 $user_data = check_password_reset_key( $key, $login );
1906
1907 if ( is_wp_error( $user_data ) ) {
1908 $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
1909 $message = aui()->alert(
1910 array(
1911 'type' => 'error',
1912 'content' => $error,
1913 )
1914 );
1915 $uwp_notices[] = array( 'reset' => $message );
1916
1917 return;
1918 }
1919
1920 $email_vars = array(
1921 'user_id' => $user_data->ID,
1922 );
1923
1924 UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
1925
1926 wp_set_password( $data['password'], $user_data->ID );
1927
1928 $login_page_url = uwp_get_login_page_url();
1929 $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
1930 $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
1931 $message = aui()->alert(
1932 array(
1933 'type' => 'success',
1934 'content' => $message,
1935 )
1936 );
1937 $uwp_notices[] = array( 'reset' => $message );
1938
1939 do_action( 'uwp_after_process_reset', $data );
1940 }
1941
1942 /**
1943 * Processes account form submission.
1944 *
1945 * @since 1.0.0
1946 * @package userswp
1947 *
1948 */
1949 public function process_account() {
1950
1951 $data = wp_unslash( $_POST );
1952 $files = $_FILES;
1953
1954 if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
1955 return;
1956 }
1957
1958 if ( ! is_user_logged_in() ) {
1959 return;
1960 }
1961
1962 global $uwp_notices;
1963 $file_obj = new UsersWP_Files();
1964
1965 do_action( 'uwp_before_validate', 'account' );
1966
1967 $result = uwp_validate_fields( $data, 'account' );
1968
1969 $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
1970
1971 if ( is_wp_error( $result ) ) {
1972 $message = aui()->alert(
1973 array(
1974 'type' => 'error',
1975 'content' => $result->get_error_message(),
1976 )
1977 );
1978 $uwp_notices[] = array( 'account' => $message );
1979
1980 return;
1981 }
1982
1983 $uploads_result = $file_obj->validate_uploads( $files, 'account' );
1984
1985 if ( is_wp_error( $uploads_result ) ) {
1986 $message = aui()->alert(
1987 array(
1988 'type' => 'error',
1989 'content' => $uploads_result->get_error_message(),
1990 )
1991 );
1992 $uwp_notices[] = array( 'account' => $message );
1993
1994 return;
1995 }
1996
1997 do_action( 'uwp_after_validate', $result, 'account', $data );
1998
1999 //unset if value is empty for files
2000 foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2001 if ( empty( $upload_file_value ) ) {
2002 unset( $uploads_result[ $upload_file_key ] );
2003 }
2004 }
2005
2006 $result = array_merge( $result, $uploads_result );
2007
2008 $args = array(
2009 'ID' => get_current_user_id(),
2010 );
2011
2012 if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2013 $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2014 }
2015
2016 if ( isset( $result['first_name'] ) ) {
2017 $args['first_name'] = $result['first_name'];
2018 }
2019
2020 if ( isset( $result['last_name'] ) ) {
2021 $args['last_name'] = $result['last_name'];
2022 }
2023
2024 if ( isset( $result['user_url'] ) ) {
2025 $args['user_url'] = $result['user_url'];
2026 }
2027
2028 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2029 $args['display_name'] = $result['display_name'];
2030 }
2031
2032 if ( isset( $result['password'] ) ) {
2033 $args['user_pass'] = $result['password'];
2034 }
2035
2036 $user_id = wp_update_user( $args );
2037
2038 if ( is_wp_error( $user_id ) ) {
2039 $message = aui()->alert(
2040 array(
2041 'type' => 'error',
2042 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2043 )
2044 );
2045 $uwp_notices[] = array( 'account' => $message );
2046
2047 return;
2048 }
2049
2050 $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
2051
2052 if ( ! $res ) {
2053 $message = aui()->alert(
2054 array(
2055 'type' => 'error',
2056 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2057 )
2058 );
2059 $uwp_notices[] = array( 'account' => $message );
2060
2061 return;
2062 }
2063
2064 //updating bio field after saving extra fields to reflect the points in mycred add on.
2065 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2066 $args = array(
2067 'ID' => $user_id,
2068 'description' => $result['bio'],
2069 );
2070 wp_update_user( $args );
2071 }
2072
2073 $user_data = get_userdata( $user_id );
2074
2075 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
2076
2077 if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
2078
2079 if ( email_exists( trim( $result['email'] ) ) ) {
2080 $message = aui()->alert(
2081 array(
2082 'type' => 'error',
2083 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2084 )
2085 );
2086
2087 $uwp_notices[] = array( 'account' => $message );
2088 return;
2089
2090 }
2091
2092 $hash = md5( $result['email'] . time() . wp_rand() );
2093 $new_admin_email = array(
2094 'hash' => $hash,
2095 'newemail' => $result['email'],
2096 );
2097
2098 update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2099
2100 $new_email_link = add_query_arg(
2101 array(
2102 'uwp_new_email' => 'yes',
2103 'key' => $hash,
2104 'login' => $user_data->user_login,
2105 ),
2106 uwp_get_account_page_url()
2107 );
2108
2109 $email_vars = array(
2110 'user_id' => $user_id,
2111 'new_email' => $result['email'],
2112 'new_email_link' => esc_url( $new_email_link ),
2113 );
2114
2115 UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2116
2117 $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2118 $message = aui()->alert(
2119 array(
2120 'type' => 'success',
2121 'content' => $message,
2122 )
2123 );
2124
2125 $uwp_notices[] = array( 'account' => $message );
2126
2127 } else {
2128 $email_vars = array(
2129 'user_id' => $user_id,
2130 'form_fields' => $form_fields,
2131 );
2132
2133 UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2134
2135 $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2136 $message = aui()->alert(
2137 array(
2138 'type' => 'success',
2139 'content' => $message,
2140 )
2141 );
2142
2143 $uwp_notices[] = array( 'account' => $message );
2144 }
2145
2146 do_action( 'uwp_after_process_account', $data, $user_id );
2147 }
2148
2149 /**
2150 * Modifies the forms field in email based on the form type.
2151 *
2152 * @param string $form_fields Form fields.
2153 * @param string $type Form type.
2154 * @param int $user_id User ID.
2155 *
2156 * @return string Modified mail field.
2157 * @package userswp
2158 * @subpackage userswp/includes
2159 *
2160 */
2161 public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2162 switch ( $type ) {
2163 case 'register':
2164 $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2165 $fields = get_register_form_fields( $form_id );
2166 $user_data = get_userdata( $user_id );
2167 if ( ! empty( $fields ) && is_array( $fields ) ) {
2168 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2169 $excluded = uwp_get_excluded_fields();
2170 foreach ( $fields as $key => $field ) {
2171 if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2172 continue;
2173 }
2174 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2175 $field_value = $user_data->user_email;
2176 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2177 $field_value = $user_data->user_login;
2178 } elseif ( $field->htmlvar_name == 'bio' ) {
2179 $field_value = get_user_meta( $user_id, 'description', true );
2180 } else {
2181 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2182 }
2183
2184 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2185 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2186 }
2187
2188 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2189 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2190 }
2191 }
2192 }
2193 break;
2194 case 'account':
2195 $fields = get_account_form_fields();
2196 $user_data = get_userdata( $user_id );
2197 if ( ! empty( $fields ) && is_array( $fields ) ) {
2198 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2199 foreach ( $fields as $key => $field ) {
2200 if ( $field->is_active != '1' ) {
2201 continue;
2202 }
2203 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2204 $field_value = $user_data->user_email;
2205 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2206 $field_value = $user_data->user_login;
2207 } elseif ( $field->htmlvar_name == 'bio' ) {
2208 $field_value = get_user_meta( $user_id, 'description', true );
2209 } else {
2210 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2211 }
2212
2213 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2214 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2215 }
2216
2217 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2218 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2219 }
2220 }
2221 }
2222 break;
2223 }
2224
2225 return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2226 }
2227
2228 /**
2229 *
2230 *
2231 * @return void
2232 * @since 1.0.12 Unlink file.
2233 * @package userswp
2234 * @since 1.0.0
2235 */
2236 public function upload_file_remove() {
2237 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2238
2239 $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2240 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2241
2242 if ( empty( $user_id ) ) {
2243 wp_die( -1 );
2244 }
2245
2246 if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2247 wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2248 }
2249
2250 // Remove file
2251 if ( $htmlvar == 'banner_thumb' ) {
2252 $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2253 $type = 'banner';
2254 } elseif ( $htmlvar == 'avatar_thumb' ) {
2255 $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2256 $type = 'avatar';
2257 } else {
2258 $file = '';
2259 $type = '';
2260 }
2261
2262 uwp_update_usermeta( $user_id, $htmlvar, '' );
2263
2264 if ( $file ) {
2265 $uploads = wp_upload_dir();
2266 $upload_path = $uploads['basedir'];
2267 $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2268
2269 if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2270 @unlink( $unlink_file );
2271 $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2272
2273 if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2274 @unlink( $unlink_ori_file );
2275 }
2276 }
2277 }
2278
2279 wp_send_json_success();
2280
2281 wp_die();
2282 }
2283
2284 /**
2285 * Form field template for datepicker field type.
2286 *
2287 * @param string $html Form field html
2288 * @param object $field Field info.
2289 * @param string $value Form field default value.
2290 * @param string $form_type Form type
2291 *
2292 * @return string Modified form field html.
2293 * @package userswp
2294 *
2295 * @since 1.0.0
2296 */
2297 public function form_input_datepicker( $html, $field, $value, $form_type ) {
2298
2299 // Check if there is a field specific filter.
2300 if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2301 $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2302 }
2303
2304 // If no html then we run the standard output.
2305 if ( empty( $html ) ) {
2306
2307 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2308 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2309 $bs_sr_only = $design_style ? 'sr-only' : '';
2310 $bs_form_control = $design_style ? 'form-control' : '';
2311 $extra_attributes = array();
2312 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2313 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2314
2315 ob_start(); // Start buffering;
2316
2317 $extra_fields = unserialize( $field->extra_fields );
2318
2319 if ( $extra_fields['date_format'] == '' ) {
2320 $extra_fields['date_format'] = 'yy-mm-dd';
2321 }
2322
2323 $date_format = $extra_fields['date_format'];
2324 $jquery_date_format = $date_format;
2325
2326 // check if we need to change the format or not
2327 $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2328 if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2329
2330 $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2331 $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2332
2333 $date_format = str_replace( $search, $replace, $date_format );
2334 } else {
2335 $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2336 }
2337
2338 if ( ! empty( $value ) && ! is_string( $value ) ) {
2339 $value = date( 'Y-m-d', $value );
2340 }
2341
2342 if ( $value == '0000-00-00' ) {
2343 $value = '';
2344 }//if date not set, then mark it empty
2345 $value = uwp_date( $value, 'Y-m-d', $date_format );
2346 $site_title = uwp_get_form_label( $field );
2347
2348 // bootstrap
2349 if ( $design_style ) {
2350 // flatpickr attributes
2351 $extra_attributes['data-alt-input'] = 'true';
2352 $extra_attributes['data-alt-format'] = $date_format;
2353 $extra_attributes['data-date-format'] = 'Y-m-d';
2354
2355 if ( 'dob' == $field->htmlvar_name ) {
2356 $extra_attributes['data-max-date'] = 'today';
2357 }
2358
2359 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2360
2361 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2362 array(
2363 'id' => esc_attr( $field->htmlvar_name ),
2364 'name' => esc_attr( $field->htmlvar_name ),
2365 'required' => ! empty( $field->is_required ) ? true : false,
2366 'label' => wp_kses_post( $site_title . $required ),
2367 'label_show' => true,
2368 'label_type' => 'hidden',
2369 'type' => 'datepicker',
2370 'title' => esc_html( $site_title ),
2371 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2372 'class' => '',
2373 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2374 'value' => esc_attr( $value ),
2375 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2376 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2377 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2378 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2379 )
2380 );
2381 } else {
2382 ?>
2383 <script type="text/javascript">
2384
2385 jQuery(function () {
2386 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2387 changeMonth: true, changeYear: true
2388 <?php
2389 if ( $field->htmlvar_name == 'dob' ) {
2390 echo ", yearRange: '1900:+0'";
2391 } else {
2392 echo ", yearRange: '1900:2050'";
2393 }
2394 ?>
2395 <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2396
2397 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2398
2399 <?php if ( ! empty( $value ) ) { ?>
2400 var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2401 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2402 <?php } ?>
2403
2404 });
2405
2406 </script>
2407 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2408 class="
2409 <?php
2410 if ( $field->is_required ) {
2411 echo 'required_field';
2412 }
2413 ?>
2414 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2415
2416 <?php
2417
2418 if ( ! is_admin() ) {
2419 ?>
2420 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2421 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2422 <?php
2423 if ( $field->is_required ) {
2424 echo '<span>*</span>';
2425 }
2426 ?>
2427 </label>
2428 <?php } ?>
2429
2430 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2431 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2432 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2433 title="<?php echo esc_attr( $site_title ); ?>"
2434 type="text"
2435 <?php
2436 if ( $field->is_required == 1 ) {
2437 echo 'required="required"';
2438 }
2439 ?>
2440 value="<?php echo esc_attr( $value ); ?>"
2441 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2442
2443 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2444 <?php if ( $field->is_required ) { ?>
2445 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2446 <?php } ?>
2447 </div>
2448
2449 <?php
2450 }
2451
2452 $html = ob_get_clean();
2453 }
2454
2455 return $html;
2456 }
2457
2458 /**
2459 * Form field template for time field type.
2460 *
2461 * @param string $html Form field html
2462 * @param object $field Field info.
2463 * @param string $value Form field default value.
2464 * @param string $form_type Form type
2465 *
2466 * @return string Modified form field html.
2467 * @package userswp
2468 *
2469 * @since 1.0.0
2470 */
2471 public function form_input_time( $html, $field, $value, $form_type ) {
2472
2473 if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
2474
2475 $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2476 }
2477
2478 // If no html then we run the standard output.
2479 if ( empty( $html ) ) {
2480
2481 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2482 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2483 $bs_sr_only = $design_style ? 'sr-only' : '';
2484 $bs_form_control = $design_style ? 'form-control bg-white' : '';
2485 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2486 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2487
2488 ob_start(); // Start buffering;
2489
2490 if ( $value != '' ) {
2491 $value = date( 'H:i', strtotime( $value ) );
2492 }
2493
2494 // flatpickr attributes
2495 $extra_attributes['data-enable-time'] = 'true';
2496 $extra_attributes['data-no-calendar'] = 'true';
2497 $extra_attributes['data-date-format'] = 'H:i';
2498 $site_title = uwp_get_form_label( $field );
2499 $label_type = is_admin() ? '' : 'top';
2500
2501 if ( $design_style ) {
2502 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2503
2504 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2505 array(
2506 'id' => esc_attr( $field->htmlvar_name ),
2507 'name' => esc_attr( $field->htmlvar_name ),
2508 'required' => ! empty( $field->is_required ) ? true : false,
2509 'label' => wp_kses_post( $site_title . $required ),
2510 'label_show' => true,
2511 'label_type' => esc_attr( $label_type ),
2512 'type' => 'timepicker',
2513 'title' => esc_html( $site_title ),
2514 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2515 'class' => '',
2516 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2517 'value' => esc_attr( $value ),
2518 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2519 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2520 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2521 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2522 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'uwp-search' ) . '" ></i></div>',
2523 )
2524 );
2525 } else {
2526 ?>
2527 <script type="text/javascript">
2528 jQuery(document).ready(function () {
2529 jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2530 showPeriod: true,
2531 showLeadingZero: true
2532 });
2533 });
2534 </script>
2535 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2536 class="
2537 <?php
2538 if ( $field->is_required ) {
2539 echo 'required_field';
2540 }
2541 ?>
2542 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2543
2544 <?php
2545 $site_title = uwp_get_form_label( $field );
2546 if ( ! is_admin() ) {
2547 ?>
2548 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2549 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2550 <?php
2551 if ( $field->is_required ) {
2552 echo '<span>*</span>';
2553 }
2554 ?>
2555 </label>
2556 <?php } ?>
2557
2558 <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2559 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2560 value="<?php echo esc_attr( $value ); ?>"
2561 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2562 type="text"
2563 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2564
2565 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2566 <?php if ( $field->is_required ) { ?>
2567 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2568 <?php } ?>
2569 </div>
2570 <?php
2571 }
2572 $html = ob_get_clean();
2573 }
2574
2575 return $html;
2576 }
2577
2578 /**
2579 * Form field template for select field type.
2580 *
2581 * @param string $html Form field html
2582 * @param object $field Field info.
2583 * @param string $value Form field default value.
2584 * @param string $form_type Form type
2585 *
2586 * @return string Modified form field html.
2587 * @package userswp
2588 *
2589 * @since 1.0.0
2590 */
2591 public function form_input_select( $html, $field, $value, $form_type ) {
2592
2593 // Check if there is a field specific filter.
2594 if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2595 $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2596 }
2597
2598 // Check if there is a field type specific filter.
2599 if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2600 $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2601 }
2602
2603 // If no html then we run the standard output.
2604 if ( empty( $html ) ) {
2605
2606 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2607 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2608 $bs_sr_only = $design_style ? 'sr-only' : '';
2609 $bs_form_control = $design_style ? 'form-control' : '';
2610 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2611 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2612
2613 ob_start(); // Start buffering;
2614 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2615 $site_title = uwp_get_form_label( $field );
2616
2617 // bootstrap
2618 if ( $design_style ) {
2619
2620 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2621
2622 echo aui()->select(
2623 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2624 'id' => esc_attr( $field->htmlvar_name ),
2625 'name' => esc_attr( $field->htmlvar_name ),
2626 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2627 'title' => esc_html( $site_title ),
2628 'value' => esc_attr( $value ),
2629 'required' => (bool) $field->is_required,
2630 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2631 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2632 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2633 'label' => wp_kses_post( $site_title . $required ),
2634 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2635 'select2' => true,
2636 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2637 )
2638 );
2639 } else {
2640 ?>
2641 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2642 class="
2643 <?php
2644 if ( $field->is_required ) {
2645 echo 'required_field';
2646 }
2647 ?>
2648 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2649
2650 <?php
2651 if ( ! is_admin() ) {
2652 ?>
2653 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2654 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2655 <?php
2656 if ( $field->is_required ) {
2657 echo '<span>*</span>';
2658 }
2659 ?>
2660 </label>
2661 <?php } ?>
2662
2663 <?php
2664
2665 $select_options = '';
2666 if ( ! empty( $option_values_arr ) ) {
2667 foreach ( $option_values_arr as $option_row ) {
2668 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2669 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2670
2671 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2672 } else {
2673 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2674 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2675 $selected = $option_value == $value ? 'selected="selected"' : '';
2676
2677 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2678 }
2679 }
2680 }
2681 ?>
2682 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2683 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2684 title="<?php echo esc_attr( $site_title ); ?>"
2685 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2686 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2687 </select>
2688 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2689 <?php if ( $field->is_required ) { ?>
2690 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2691 <?php } ?>
2692 </div>
2693
2694 <?php
2695 }
2696 $html = ob_get_clean();
2697 }
2698
2699 return $html;
2700 }
2701
2702 /**
2703 * Form field template for multiselect field type.
2704 *
2705 * @param string $html Form field html
2706 * @param object $field Field info.
2707 * @param string $value Form field default value.
2708 * @param string $form_type Form type
2709 *
2710 * @return string Modified form field html.
2711 * @package userswp
2712 *
2713 * @since 1.0.0
2714 */
2715 public function form_input_multiselect( $html, $field, $value, $form_type ) {
2716
2717 // Check if there is a field specific filter.
2718 if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
2719 $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2720 }
2721
2722 if ( empty( $html ) ) {
2723
2724 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2725 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2726 $bs_sr_only = $design_style ? 'sr-only' : '';
2727 $bs_form_control = $design_style ? 'form-control' : '';
2728 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2729 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2730
2731 ob_start(); // Start buffering;
2732
2733 $multi_display = 'select';
2734 if ( ! empty( $field->extra_fields ) ) {
2735 $multi_display = unserialize( $field->extra_fields );
2736 }
2737
2738 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2739 $site_title = uwp_get_form_label( $field );
2740 $value = is_array( $value ) ? $value : esc_attr( $value );
2741
2742 // bootstrap
2743 if ( $design_style ) {
2744
2745 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2746
2747 echo aui()->select(
2748 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2749 'id' => esc_attr( $field->htmlvar_name ),
2750 'name' => esc_attr( $field->htmlvar_name ),
2751 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2752 'title' => esc_html( $site_title ),
2753 'value' => $value,
2754 'required' => (bool) $field->is_required,
2755 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2756 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2757 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2758 'label' => wp_kses_post( $site_title . $required ),
2759 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2760 'select2' => true,
2761 'multiple' => true,
2762 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2763 )
2764 );
2765 } else {
2766 ?>
2767 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2768 class="
2769 <?php
2770 if ( $field->is_required ) {
2771 echo 'required_field';
2772 }
2773 ?>
2774 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2775
2776 <?php
2777 if ( ! is_admin() ) {
2778 ?>
2779 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2780 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2781 <?php
2782 if ( $field->is_required ) {
2783 echo '<span>*</span>';
2784 }
2785 ?>
2786 </label>
2787 <?php } ?>
2788
2789 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
2790 <?php if ( $multi_display == 'select' ) { ?>
2791 <div class="uwp_multiselect_list">
2792 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
2793 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2794 title="<?php echo esc_attr( $site_title ); ?>"
2795 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2796 class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2797 >
2798 <?php
2799 } else {
2800 ?>
2801 <ul class="uwp_multi_choice">
2802 <?php
2803 }
2804
2805 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2806 $select_options = '';
2807 if ( ! empty( $option_values_arr ) ) {
2808 foreach ( $option_values_arr as $option_row ) {
2809 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2810 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2811
2812 if ( $multi_display == 'select' ) {
2813 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2814 } else {
2815 $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
2816 }
2817 } else {
2818 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2819 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2820 $selected = $option_value == $value ? 'selected="selected"' : '';
2821 $checked = '';
2822
2823 if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
2824 if ( ! is_array( $value ) ) {
2825 $value_array = explode( ',', $value );
2826 } else {
2827 $value_array = $value;
2828 }
2829
2830 if ( is_array( $value_array ) ) {
2831 if ( in_array( $option_value, $value_array ) ) {
2832 $selected = 'selected="selected"';
2833 $checked = 'checked="checked"';
2834 }
2835 }
2836 }
2837
2838 if ( $multi_display == 'select' ) {
2839 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2840 } else {
2841 $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
2842 }
2843 }
2844 }
2845 }
2846 echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2847
2848 if ( $multi_display == 'select' ) {
2849
2850 ?>
2851 </select></div>
2852 <?php } else { ?>
2853 </ul>
2854 <?php } ?>
2855 <?php if ( $field->is_required ) { ?>
2856 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2857 <?php } ?>
2858 </div>
2859 <?php
2860 }
2861 $html = ob_get_clean();
2862 }
2863
2864 return $html;
2865 }
2866
2867 /**
2868 * Form field template for file field type.
2869 *
2870 * @param string $html Form field html
2871 * @param object $field Field info.
2872 * @param string $value Form field default value.
2873 * @param string $form_type Form type
2874 *
2875 * @return string Modified form field html.
2876 * @package userswp
2877 *
2878 * @since 1.0.0
2879 */
2880 public function form_input_file( $html, $field, $value, $form_type ) {
2881
2882 $file_obj = new UsersWP_Files();
2883
2884 // Check if there is a field specific filter.
2885 if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
2886 $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2887 }
2888
2889 // If no html then we run the standard output.
2890 if ( empty( $html ) ) {
2891
2892 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2893 $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
2894 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2895 $bs_sr_only = $design_style ? 'sr-only' : '';
2896 $bs_form_control = $design_style ? 'form-control' : '';
2897
2898 ob_start(); // Start buffering;
2899
2900 ?>
2901 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2902 class="
2903 <?php
2904 if ( $field->is_required ) {
2905 echo 'required_field';
2906 }
2907 ?>
2908 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
2909
2910 <?php
2911 $site_title = uwp_get_form_label( $field );
2912 if ( ! is_admin() && ! wp_doing_ajax() ) {
2913 ?>
2914 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2915 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2916 <?php
2917 if ( $field->is_required ) {
2918 echo ' <span class="text-danger">*</span>';
2919 }
2920 ?>
2921 </label>
2922 <?php } ?>
2923
2924 <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2925 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2926 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
2927 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2928 title="<?php echo esc_attr( $site_title ); ?>"
2929 <?php
2930 if ( $field->is_required == 1 ) {
2931 echo 'data-is-required="1"';
2932 }
2933 if ( $field->is_required == 1 && ! $value ) {
2934 echo 'required="required"';
2935 }
2936 ?>
2937 type="<?php echo esc_attr( $field->field_type ); ?>">
2938 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2939 <?php if ( $field->is_required ) { ?>
2940 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2941 <?php } ?>
2942 </div>
2943
2944 <?php
2945 $html = ob_get_clean();
2946 }
2947
2948 return $html;
2949 }
2950
2951 /**
2952 * Form field template for checkbox field type.
2953 *
2954 * @param string $html Form field html
2955 * @param object $field Field info.
2956 * @param string $value Form field default value.
2957 * @param string $form_type Form type
2958 *
2959 * @return string Modified form field html.
2960 * @package userswp
2961 *
2962 * @since 1.0.0
2963 */
2964 public function form_input_checkbox( $html, $field, $value, $form_type ) {
2965
2966 // Check if there is a field specific filter.
2967 if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
2968 $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2969 }
2970
2971 // If no html then we run the standard output.
2972 if ( empty( $html ) ) {
2973
2974 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2975 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
2976 $bs_sr_only = $design_style ? 'form-check-label' : '';
2977 $bs_form_control = $design_style ? 'form-check-input' : '';
2978
2979 ob_start(); // Start buffering;
2980 $site_title = uwp_get_form_label( $field );
2981
2982 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2983 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2984
2985 $checked = $value == '1' ? true : false;
2986
2987 // bootstrap
2988 if ( $design_style ) {
2989 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2990
2991 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2992
2993 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2994 array(
2995 'id' => esc_attr( $id ),
2996 'name' => esc_attr( $field->htmlvar_name ),
2997 'type' => 'checkbox',
2998 'value' => '1',
2999 'title' => esc_html( $site_title ),
3000 'label' => wp_kses_post( $site_title . $required ),
3001 'label_show' => true,
3002 'required' => ! empty( $field->is_required ) ? true : false,
3003 'checked' => (bool) $checked,
3004 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3005 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3006 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3007 )
3008 );
3009
3010 } else {
3011 ?>
3012 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3013 class="
3014 <?php
3015 if ( $field->is_required ) {
3016 echo 'required_field';
3017 }
3018 ?>
3019 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3020 <?php if ( ! empty( $design_style ) ) { ?>
3021 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3022 <?php } ?>
3023 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3024 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3025 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3026 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3027 title="<?php echo esc_attr( $site_title ); ?>"
3028 <?php
3029 if ( $field->is_required == 1 ) {
3030 echo 'required="required"';
3031 }
3032 ?>
3033 <?php
3034 if ( $value == '1' ) {
3035 echo 'checked="checked"';
3036 }
3037 ?>
3038 type="<?php echo esc_attr( $field->field_type ); ?>"
3039 value="1">
3040 <?php
3041 echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3042 ?>
3043 <?php if ( ! empty( $design_style ) ) { ?>
3044 </label>
3045 <?php } ?>
3046 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3047 <?php if ( $field->is_required ) { ?>
3048 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3049 <?php } ?>
3050 </div>
3051
3052 <?php
3053
3054 }
3055
3056 $html = ob_get_clean();
3057
3058 }
3059
3060 return $html;
3061 }
3062
3063 /**
3064 * Form field template for radio field type.
3065 *
3066 * @param string $html Form field html
3067 * @param object $field Field info.
3068 * @param string $value Form field default value.
3069 * @param string $form_type Form type
3070 *
3071 * @return string Modified form field html.
3072 * @package userswp
3073 *
3074 * @since 1.0.0
3075 */
3076 public function form_input_radio( $html, $field, $value, $form_type ) {
3077
3078 // Check if there is a field specific filter.
3079 if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3080 $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3081 }
3082
3083 // If no html then we run the standard output.
3084 if ( empty( $html ) ) {
3085
3086 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3087 $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3088 $bs_sr_only = $design_style ? 'sr-only' : '';
3089 $bs_label_class = $design_style ? 'form-check-label' : '';
3090 $bs_form_control = $design_style ? 'form-check-input' : '';
3091
3092 ob_start(); // Start buffering;
3093
3094 if ( $design_style ) {
3095
3096 $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3097 $option_values = array();
3098 if ( ! empty( $option_values_deep ) ) {
3099 foreach ( $option_values_deep as $option ) {
3100 $option_values[ $option['value'] ] = $option['label'];
3101 }
3102 }
3103
3104 $site_title = uwp_get_form_label( $field );
3105
3106 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3107
3108 echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3109 array(
3110 'id' => esc_attr( $field->htmlvar_name ),
3111 'name' => esc_attr( $field->htmlvar_name ),
3112 'type' => 'radio',
3113 'title' => esc_html( $site_title ),
3114 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3115 'label_type' => 'top',
3116 'class' => '',
3117 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3118 'value' => esc_attr( $value ),
3119 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3120 )
3121 );
3122
3123 } else {
3124
3125 ?>
3126 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3127 class="
3128 <?php
3129 if ( $field->is_required ) {
3130 echo 'required_field';
3131 }
3132 ?>
3133 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3134
3135 <?php
3136 $site_title = uwp_get_form_label( $field );
3137 if ( ! is_admin() ) {
3138 ?>
3139 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3140 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3141 <?php
3142 if ( $field->is_required ) {
3143 echo '<span>*</span>';
3144 }
3145 ?>
3146 </label>
3147 <?php } ?>
3148
3149 <?php
3150 if ( $field->option_values ) {
3151 $option_values = uwp_string_values_to_options( $field->option_values, true );
3152
3153 if ( ! empty( $option_values ) ) {
3154 $count = 0;
3155 foreach ( $option_values as $option_value ) {
3156 if ( empty( $option_value['optgroup'] ) ) {
3157 ++$count;
3158 if ( $count == 1 ) {
3159 $class = 'uwp-radio-first';
3160 } else {
3161 $class = '';
3162 }
3163 ?>
3164 <?php if ( ! empty( $design_style ) ) { ?>
3165 <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3166 <?php } else { ?>
3167 <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3168 <?php } ?>
3169 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3170 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3171 title="<?php echo esc_attr( $option_value['label'] ); ?>"
3172 <?php checked( $value, $option_value['value'] ); ?>
3173 <?php
3174 if ( $field->is_required == 1 ) {
3175 echo 'required="required"';
3176 }
3177 ?>
3178 value="<?php echo esc_attr( $option_value['value'] ); ?>"
3179 class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3180 <?php echo esc_html( $option_value['label'] ); ?>
3181 <?php if ( ! empty( $design_style ) ) { ?>
3182 </label>
3183 <?php } else { ?>
3184 </span>
3185 <?php
3186 }
3187 }
3188 }
3189 }
3190 }
3191 ?>
3192 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3193 <?php if ( $field->is_required ) { ?>
3194 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3195 <?php } ?>
3196 </div>
3197 <?php
3198 }
3199
3200 $html = ob_get_clean();
3201 }
3202
3203 return $html;
3204 }
3205
3206 /**
3207 * Form field template for text field type.
3208 *
3209 * @param string $html Form field html
3210 * @param object $field Field info.
3211 * @param string $value Form field default value.
3212 * @param string $form_type Form type
3213 *
3214 * @return string Modified form field html.
3215 * @package userswp
3216 *
3217 * @since 1.0.0
3218 */
3219 public function form_input_text( $html, $field, $value, $form_type ) {
3220
3221 // Check if there is a custom field specific filter.
3222 if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3223 $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3224 }
3225
3226 // If no html then we run the standard output.
3227 if ( empty( $html ) ) {
3228
3229 ob_start(); // Start buffering;
3230
3231 $type = 'text';
3232 $step = false;
3233 //number and float validation $validation_pattern
3234 if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3235 $type = 'number';
3236 } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3237 $dp = $field->decimal_point;
3238 switch ( $dp ) {
3239 case '1':
3240 $step = '0.1';
3241 break;
3242 case '2':
3243 $step = '0.01';
3244 break;
3245 case '3':
3246 $step = '0.001';
3247 break;
3248 case '4':
3249 $step = '0.0001';
3250 break;
3251 case '5':
3252 $step = '0.00001';
3253 break;
3254 case '6':
3255 $step = '0.000001';
3256 break;
3257 case '7':
3258 $step = '0.0000001';
3259 break;
3260 case '8':
3261 $step = '0.00000001';
3262 break;
3263 case '9':
3264 $step = '0.000000001';
3265 break;
3266 case '10':
3267 $step = '0.0000000001';
3268 break;
3269 default:
3270 $step = '0.01';
3271 break;
3272 }
3273 $type = 'number';
3274 }
3275
3276 $site_title = uwp_get_form_label( $field );
3277 $placeholder = uwp_get_field_placeholder( $field );
3278 $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3279 if ( $manual_label
3280 && isset( $field->form_type )
3281 && $field->form_type == 'login'
3282 && $field->htmlvar_name == 'username' ) {
3283 $site_title = __( 'Username or Email', 'userswp' );
3284 $required = ! empty( $field->is_required ) ? ' *' : '';
3285 $placeholder = $site_title . $required;
3286 $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3287 }
3288
3289 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3290 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3291 $bs_sr_only = $design_style ? 'sr-only' : '';
3292 $bs_form_control = $design_style ? 'form-control' : '';
3293
3294 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3295 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3296
3297 // bootstrap
3298 if ( $design_style ) {
3299 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3300
3301 echo aui()->input(
3302 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3303 'type' => esc_attr( $type ),
3304 'id' => esc_attr( $field->htmlvar_name ),
3305 'name' => esc_attr( $field->htmlvar_name ),
3306 'placeholder' => esc_attr( $placeholder ),
3307 'title' => esc_html( $site_title ),
3308 'value' => esc_attr( wp_unslash( $value ) ),
3309 'required' => (bool) $field->is_required,
3310 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3311 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3312 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3313 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3314 'step' => esc_attr( $step ),
3315 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3316 )
3317 );
3318 } else {
3319 ?>
3320 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3321 <?php
3322 if ( $field->is_required ) {
3323 echo 'required_field';
3324 }
3325 ?>
3326 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3327 <?php
3328
3329 if ( ! is_admin() ) {
3330 ?>
3331 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3332 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3333 <?php
3334 if ( $field->is_required ) {
3335 echo '<span>*</span>';
3336 }
3337 ?>
3338 </label>
3339 <?php
3340 }
3341 ?>
3342
3343 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3344 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3345 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3346 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3347 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3348 title="<?php echo esc_attr( $site_title ); ?>"
3349 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3350 oninput="setCustomValidity('')"
3351 <?php
3352 if ( $field->is_required == 1 ) {
3353 echo 'required="required"';
3354 }
3355 ?>
3356 <?php
3357 if ( $field->for_admin_use == 1 ) {
3358 echo 'readonly="readonly"';
3359 }
3360 ?>
3361 type="<?php echo esc_attr( $type ); ?>"
3362 <?php
3363 if ( $step ) {
3364 echo 'step="' . esc_attr( $step ) . '"';
3365 }
3366 ?>
3367 />
3368 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3369 <?php if ( $field->is_required ) { ?>
3370 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3371 <?php } ?>
3372 </div>
3373
3374
3375 <?php
3376 }
3377 $html = ob_get_clean();
3378 }
3379
3380 return $html;
3381 }
3382
3383 /**
3384 * Form field template for textarea field type.
3385 *
3386 * @param string $html Form field html
3387 * @param object $field Field info.
3388 * @param string $value Form field default value.
3389 * @param string $form_type Form type
3390 *
3391 * @return string Modified form field html.
3392 * @package userswp
3393 *
3394 * @since 1.0.0
3395 */
3396 public function form_input_textarea( $html, $field, $value, $form_type ) {
3397
3398 // Check if there is a field specific filter.
3399 if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3400 $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3401 }
3402
3403 // If no html then we run the standard output.
3404 if ( empty( $html ) ) {
3405
3406 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3407 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3408 $bs_sr_only = $design_style ? 'sr-only' : '';
3409 $bs_form_control = $design_style ? 'form-control' : '';
3410 $site_title = uwp_get_form_label( $field );
3411
3412 ob_start(); // Start buffering;
3413
3414 // bootstrap
3415 if ( $design_style ) {
3416 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3417
3418 echo aui()->textarea(
3419 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3420 'id' => esc_attr( $field->htmlvar_name ),
3421 'name' => esc_attr( $field->htmlvar_name ),
3422 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3423 'title' => esc_html( $site_title ),
3424 'value' => wp_kses_post( stripslashes( $value ) ),
3425 'required' => (bool) $field->is_required,
3426 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3427 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3428 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3429 'rows' => '4',
3430 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3431 )
3432 );
3433 } else {
3434 ?>
3435
3436 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3437 class="
3438 <?php
3439 if ( $field->is_required ) {
3440 echo 'required_field';
3441 }
3442 ?>
3443 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3444
3445 <?php
3446
3447 if ( ! is_admin() ) {
3448 ?>
3449 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3450 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3451 <?php
3452 if ( $field->is_required ) {
3453 echo '<span>*</span>';
3454 }
3455 ?>
3456 </label>
3457 <?php } ?>
3458
3459 <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3460 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3461 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3462 title="<?php echo esc_attr( $site_title ); ?>"
3463 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3464 oninput="setCustomValidity('')"
3465 <?php
3466 if ( $field->is_required == 1 ) {
3467 echo 'required="required"';
3468 }
3469 ?>
3470 type="<?php echo esc_attr( $field->field_type ); ?>"
3471 rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3472 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3473 <?php if ( $field->is_required ) { ?>
3474 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3475 <?php } ?>
3476 </div>
3477
3478 <?php
3479 }
3480 $html = ob_get_clean();
3481 }
3482
3483 return $html;
3484 }
3485
3486 public function form_input_editor( $html, $field, $value, $form_type ) {
3487
3488 // Check if there is a field specific filter.
3489 if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3490 $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3491 }
3492
3493 if ( empty( $html ) ) {
3494
3495 ob_start();
3496
3497 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3498 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3499 $bs_sr_only = $design_style ? 'sr-only' : '';
3500 $site_title = uwp_get_form_label( $field );
3501
3502 $content = stripslashes( $value );
3503 $editor_id = $field->htmlvar_name;
3504 $args = array(
3505 'textarea_rows' => 5,
3506 'media_buttons' => false,
3507 'quicktags' => false,
3508 );
3509
3510 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3511 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3512
3513 // bootstrap
3514 if ( $design_style ) {
3515 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3516
3517 echo aui()->textarea(
3518 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3519 'id' => esc_attr( $field->htmlvar_name ),
3520 'name' => esc_attr( $field->htmlvar_name ),
3521 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3522 'title' => esc_html( $site_title ),
3523 'value' => wp_kses_post( stripslashes( $value ) ),
3524 'required' => (bool) $field->is_required,
3525 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3526 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3527 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3528 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3529 'rows' => 5,
3530 'wysiwyg' => true,
3531 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3532 )
3533 );
3534 } else {
3535 ?>
3536 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3537 class="
3538 <?php
3539 if ( $field->is_required ) {
3540 echo 'required_field';
3541 }
3542 ?>
3543 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3544
3545 <?php
3546
3547 if ( ! is_admin() ) {
3548 ?>
3549 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3550 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3551 <?php
3552 if ( $field->is_required ) {
3553 echo '<span>*</span>';
3554 }
3555 ?>
3556 </label>
3557 <?php } ?>
3558
3559 <?php wp_editor( $content, $editor_id, $args ); ?>
3560
3561 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3562 <?php if ( $field->is_required ) { ?>
3563 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3564 <?php } ?>
3565 </div>
3566 <?php
3567 }
3568 $html = ob_get_clean();
3569 }
3570
3571 return $html;
3572 }
3573
3574 /**
3575 * Form field template for fieldset field type.
3576 *
3577 * @param string $html Form field html
3578 * @param object $field Field info.
3579 * @param string $value Form field default value.
3580 * @param string $form_type Form type
3581 *
3582 * @return string Modified form field html.
3583 * @package userswp
3584 *
3585 * @since 1.0.0
3586 */
3587 public function form_input_fieldset( $html, $field, $value, $form_type ) {
3588 // Check if there is a custom field specific filter.
3589 if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3590 $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3591 }
3592
3593 // If no html then we run the standard output.
3594 if ( empty( $html ) ) {
3595
3596 ob_start(); // Start buffering;
3597 $site_title = uwp_get_form_label( $field );
3598 ?>
3599 <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3600 <?php echo esc_html( $site_title ); ?>
3601 <?php
3602 if ( $field->help_text != '' ) {
3603 echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3604 }
3605 ?>
3606 </h3>
3607 <?php
3608 $html = ob_get_clean();
3609 }
3610
3611 return $html;
3612 }
3613
3614 /**
3615 * Form field template for url field type.
3616 *
3617 * @param string $html Form field html
3618 * @param object $field Field info.
3619 * @param string $value Form field default value.
3620 * @param string $form_type Form type
3621 *
3622 * @return string Modified form field html.
3623 * @package userswp
3624 *
3625 * @since 1.0.0
3626 */
3627 public function form_input_url( $html, $field, $value, $form_type ) {
3628
3629 // Check if there is a custom field specific filter.
3630 if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
3631 $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3632 }
3633
3634 // If no html then we run the standard output.
3635 if ( empty( $html ) ) {
3636
3637 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3638 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3639 $bs_sr_only = $design_style ? 'sr-only' : '';
3640 $bs_form_control = $design_style ? 'form-control' : '';
3641
3642 ob_start(); // Start buffering;
3643 $site_title = uwp_get_form_label( $field );
3644 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
3645 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3646
3647 // bootstrap
3648 if ( $design_style ) {
3649 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3650
3651 echo aui()->input(
3652 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3653 'type' => 'url',
3654 'id' => esc_attr( $field->htmlvar_name ),
3655 'name' => esc_attr( $field->htmlvar_name ),
3656 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3657 'title' => esc_html( $site_title ),
3658 'value' => esc_attr( $value ),
3659 'required' => (bool) $field->is_required,
3660 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3661 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3662 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3663 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3664 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3665 )
3666 );
3667 } else {
3668 ?>
3669 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3670 class="
3671 <?php
3672 if ( $field->is_required ) {
3673 echo 'required_field';
3674 }
3675 ?>
3676 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3677
3678 <?php
3679 if ( ! is_admin() ) {
3680 ?>
3681 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3682 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3683 <?php
3684 if ( $field->is_required ) {
3685 echo '<span>*</span>';
3686 }
3687 ?>
3688 </label>
3689 <?php } ?>
3690
3691 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3692 class="
3693 <?php
3694 //echo $field->css_class;
3695 ?>
3696 uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3697 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3698 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3699 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3700 title="<?php echo esc_attr( $site_title ); ?>"
3701 <?php
3702 if ( $field->is_required == 1 ) {
3703 echo 'required="required"';
3704 }
3705 ?>
3706 type="url"
3707 oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
3708 onchange="try{setCustomValidity('')}catch(e){}"
3709 />
3710 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3711 <?php if ( $field->is_required ) { ?>
3712 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3713 <?php } ?>
3714 </div>
3715
3716 <?php
3717 }
3718
3719 $html = ob_get_clean();
3720 }
3721
3722 return $html;
3723 }
3724
3725 /**
3726 * Form field template for email field type.
3727 *
3728 * @param string $html Form field html
3729 * @param object $field Field info.
3730 * @param string $value Form field default value.
3731 * @param string $form_type Form type
3732 *
3733 * @return string Modified form field html.
3734 * @package userswp
3735 *
3736 * @since 1.0.0
3737 */
3738 public function form_input_email( $html, $field, $value, $form_type ) {
3739
3740 // Check if there is a custom field specific filter.
3741 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
3742 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3743 }
3744
3745 // If no html then we run the standard output.
3746 if ( empty( $html ) ) {
3747
3748 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3749 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3750 $bs_sr_only = $design_style ? 'sr-only' : '';
3751 $bs_form_control = $design_style ? 'form-control' : '';
3752
3753 ob_start(); // Start buffering;
3754 $site_title = uwp_get_form_label( $field );
3755 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3756 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3757
3758 if ( $design_style ) {
3759 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3760
3761 echo aui()->input(
3762 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3763 'type' => 'email',
3764 'id' => esc_attr( $field->htmlvar_name ),
3765 'name' => esc_attr( $field->htmlvar_name ),
3766 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3767 'title' => esc_html( $site_title ),
3768 'value' => esc_attr( wp_unslash( $value ) ),
3769 'required' => (bool) $field->is_required,
3770 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3771 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3772 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3773 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3774 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3775 )
3776 );
3777 } else {
3778 ?>
3779 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3780 class="
3781 <?php
3782 if ( $field->is_required ) {
3783 echo 'required_field';
3784 }
3785 ?>
3786 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3787
3788 <?php
3789 if ( ! is_admin() ) {
3790 ?>
3791 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3792 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3793 <?php
3794 if ( $field->is_required ) {
3795 echo '<span>*</span>';
3796 }
3797 ?>
3798 </label>
3799 <?php } ?>
3800
3801 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3802 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3803 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3804 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3805 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3806 title="<?php echo esc_attr( $site_title ); ?>"
3807 <?php
3808 if ( $field->is_required == 1 ) {
3809 echo 'required="required"';
3810 }
3811 ?>
3812 type="email"
3813 />
3814 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3815 <?php if ( $field->is_required ) { ?>
3816 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3817 <?php } ?>
3818 </div>
3819
3820
3821 <?php
3822 }
3823 $html = ob_get_clean();
3824
3825 }
3826
3827 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
3828 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3829 }
3830
3831 return $html;
3832 }
3833
3834 /**
3835 * Form field template for password field type.
3836 *
3837 * @param string $html Form field html
3838 * @param object $field Field info.
3839 * @param string $value Form field default value.
3840 * @param string $form_type Form type
3841 *
3842 * @return string Modified form field html.
3843 * @package userswp
3844 *
3845 * @since 1.0.0
3846 */
3847 public function form_input_password( $html, $field, $value, $form_type ) {
3848
3849 // Check if there is a custom field specific filter.
3850 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
3851 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3852 }
3853
3854 // If no html then we run the standard output.
3855 if ( empty( $html ) ) {
3856
3857 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3858 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3859 $bs_sr_only = $design_style ? 'sr-only' : '';
3860 $bs_form_control = $design_style ? 'form-control' : '';
3861
3862 ob_start(); // Start buffering;
3863 $site_title = uwp_get_form_label( $field );
3864
3865 if ( $design_style ) {
3866 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3867 $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3868 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3869 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
3870
3871 echo aui()->input(
3872 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3873 'type' => 'password',
3874 'id' => esc_attr( $field->htmlvar_name ),
3875 'name' => esc_attr( $field->htmlvar_name ),
3876 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3877 'title' => esc_html( $site_title ),
3878 'value' => esc_attr( $value ),
3879 'required' => (bool) $field->is_required,
3880 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3881 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3882 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3883 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3884 'wrap_class' => esc_attr( $wrap_class ),
3885 )
3886 );
3887 } else {
3888 ?>
3889 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3890 <?php
3891 if ( $field->is_required ) {
3892 echo 'required_field';
3893 }
3894 ?>
3895 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3896 <?php
3897 if ( ! is_admin() ) {
3898 ?>
3899 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3900 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3901 <?php
3902 if ( $field->is_required ) {
3903 echo '<span>*</span>';
3904 }
3905 ?>
3906 </label>
3907 <?php } ?>
3908
3909 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3910 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3911 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3912 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3913 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3914 title="<?php echo esc_attr( $site_title ); ?>"
3915 <?php
3916 if ( $field->is_required == 1 ) {
3917 echo 'required="required"';
3918 }
3919 ?>
3920 type="password"
3921 />
3922 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3923 <?php if ( $field->is_required ) { ?>
3924 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3925 <?php } ?>
3926 </div>
3927
3928
3929 <?php
3930 }
3931
3932 $html = ob_get_clean();
3933 }
3934
3935 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
3936 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3937 }
3938
3939 return $html;
3940 }
3941
3942 /**
3943 * Form field template for Phone field.
3944 *
3945 * @param string $html Form field html
3946 * @param object $field Field info.
3947 * @param string $value Form field default value.
3948 * @param string $form_type Form type
3949 *
3950 * @return string $html Modified form field html.
3951 * @since 1.0.0
3952 *
3953 */
3954 public function form_input_phone( $html, $field, $value, $form_type ) {
3955 if ( empty( $html ) ) {
3956 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3957 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3958 $bs_sr_only = $design_style ? 'sr-only' : '';
3959 $bs_form_control = $design_style ? 'form-control' : '';
3960 ob_start(); // Start buffering;
3961 $site_title = uwp_get_form_label( $field );
3962 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3963 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3964
3965 if ( $design_style ) {
3966 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3967
3968 echo aui()->input(
3969 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3970 'type' => 'tel',
3971 'id' => esc_attr( $field->htmlvar_name ),
3972 'name' => esc_attr( $field->htmlvar_name ),
3973 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3974 'title' => esc_html( $site_title ),
3975 'value' => esc_attr( $value ),
3976 'required' => (bool) $field->is_required,
3977 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3978 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3979 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3980 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3981 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3982 )
3983 );
3984 } else {
3985 ?>
3986 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3987 class="
3988 <?php
3989 if ( $field->is_required ) {
3990 echo 'required_field';
3991 }
3992 ?>
3993 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3994 <?php
3995 if ( ! is_admin() ) {
3996 ?>
3997 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3998 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3999 <?php
4000 if ( $field->is_required ) {
4001 echo '<span>*</span>';
4002 }
4003 ?>
4004 </label>
4005 <?php } ?>
4006 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4007 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4008 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4009 title="<?php echo esc_attr( $site_title ); ?>"
4010 <?php
4011 if ( $field->for_admin_use == 1 ) {
4012 echo 'readonly="readonly"';
4013 }
4014 ?>
4015 <?php
4016 if ( $field->is_required == 1 ) {
4017 echo 'required="required"';
4018 }
4019 ?>
4020 type="tel"
4021 value="<?php echo esc_html( $value ); ?>">
4022 </div>
4023 <?php
4024 }
4025 $html = ob_get_clean();
4026 }
4027
4028 return $html;
4029 }
4030
4031 public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
4032
4033 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4034 $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4035 if ( empty( $reg_gdpr ) ) {
4036 $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4037 }
4038
4039 if ( ! empty( $reg_gdpr ) ) {
4040
4041 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4042 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4043 $bs_form_control = $design_style ? 'form-check-input' : '';
4044 $site_title = uwp_get_form_label( $field );
4045 $field->htmlvar_name = 'register_gdpr';
4046 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4047
4048 $gdpr_page = get_permalink( $reg_gdpr );
4049 $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4050 $link_end = '</a>';
4051 $field_desc = uwp_get_field_description( $field, '' );
4052 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4053 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4054 $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4055 $checked = $value == '1' ? true : false;
4056
4057 ob_start(); // Start buffering;
4058
4059 // bootstrap
4060 if ( $design_style ) {
4061 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4062 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4063
4064 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4065 array(
4066 'id' => esc_attr( $id ),
4067 'name' => esc_attr( $field->htmlvar_name ),
4068 'type' => 'checkbox',
4069 'value' => '1',
4070 'title' => esc_html( $site_title ),
4071 'label' => wp_kses_post( $content . $required ),
4072 'label_show' => true,
4073 'required' => ! empty( $field->is_required ) ? true : false,
4074 'checked' => (bool) $checked,
4075 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4076 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4077 )
4078 );
4079
4080 } else {
4081 ?>
4082 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4083 class="
4084 <?php
4085 if ( $field->is_required ) {
4086 echo 'required_field';
4087 }
4088 ?>
4089 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4090 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4091 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4092 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4093 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4094 title="<?php echo esc_attr( $site_title ); ?>"
4095 <?php
4096 if ( $value == '1' ) {
4097 echo 'checked="checked"';
4098 }
4099 ?>
4100 type="<?php echo esc_attr( $field->field_type ); ?>"
4101 value="1">
4102 <?php
4103 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4104 ?>
4105 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4106 <?php if ( $field->is_required ) { ?>
4107 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4108 <?php } ?>
4109 </div>
4110
4111 <?php
4112 }
4113
4114 $html = ob_get_clean();
4115
4116 } else {
4117 $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4118 }
4119
4120 return $html;
4121 }
4122
4123 public function form_input_register_tos( $html, $field, $value, $form_type ) {
4124
4125 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4126 $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4127 if ( empty( $reg_tos ) ) {
4128 $reg_tos = uwp_get_option( 'register_terms_page', false );
4129 }
4130
4131 if ( ! empty( $reg_tos ) ) {
4132
4133 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4134 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4135 $bs_form_control = $design_style ? 'form-check-input' : '';
4136
4137 $site_title = uwp_get_form_label( $field );
4138 $terms_page = get_permalink( $reg_tos );
4139 $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4140 $link_end = '</a>';
4141 $field_desc = uwp_get_field_description( $field, '' );
4142 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4143 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4144 $field->htmlvar_name = 'register_tos';
4145 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4146
4147 $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4148 $checked = $value == '1' ? true : false;
4149
4150 ob_start();
4151
4152 if ( $design_style ) {
4153 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4154 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4155
4156 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4157 array(
4158 'id' => esc_attr( $id ),
4159 'name' => esc_attr( $field->htmlvar_name ),
4160 'type' => 'checkbox',
4161 'value' => '1',
4162 'title' => esc_html( $site_title ),
4163 'label' => wp_kses_post( $content . $required ),
4164 'label_show' => true,
4165 'required' => ! empty( $field->is_required ) ? true : false,
4166 'checked' => (bool) $checked,
4167 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4168 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4169 )
4170 );
4171
4172 } else {
4173 ?>
4174 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4175 class="
4176 <?php
4177 if ( $field->is_required ) {
4178 echo 'required_field';
4179 }
4180 ?>
4181 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4182 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4183 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4184 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4185 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4186 title="<?php echo esc_attr( $site_title ); ?>"
4187 <?php
4188 if ( $value == '1' ) {
4189 echo 'checked="checked"';
4190 }
4191 ?>
4192 type="<?php echo esc_attr( $field->field_type ); ?>"
4193 value="1">
4194 <?php
4195 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4196 ?>
4197 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4198 <?php if ( $field->is_required ) { ?>
4199 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4200 <?php } ?>
4201 </div>
4202
4203 <?php
4204
4205 }
4206
4207 $html = ob_get_clean();
4208
4209 } else {
4210 $html = '<input type="hidden" name="register_tos" value="-1"/>';
4211 }
4212
4213 return $html;
4214 }
4215
4216 /**
4217 * Adds enctype tag in form for file fields.
4218 *
4219 * @return void
4220 * @package userswp
4221 *
4222 * @since 1.0.0
4223 */
4224 function add_multipart_to_admin_edit_form() {
4225 global $wpdb;
4226 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4227 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4228 if ( $fields ) {
4229 echo 'enctype="multipart/form-data"';
4230 }
4231 }
4232
4233 /**
4234 * Handles UsersWP custom field requests from admin.
4235 *
4236 * @param int $user_id User ID.
4237 *
4238 * @return void
4239 * @since 1.0.0
4240 * @package userswp
4241 *
4242 */
4243 public function update_profile_extra_admin_edit( $user_id ) {
4244 global $wpdb;
4245 $file_obj = new UsersWP_Files();
4246 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4247 //Normal fields
4248 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4249 if ( $fields ) {
4250 if ( isset( $_POST['locale'] ) ) {
4251 $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4252 }
4253 $result = uwp_validate_fields( $_POST, 'account', $fields );
4254 if ( is_wp_error( $result ) ) {
4255 die( wp_kses_post( $result->get_error_message() ) );
4256 }
4257 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4258 $display_name = $result['display_name'];
4259 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4260 $display_name = $result['first_name'] . ' ' . $result['last_name'];
4261 } else {
4262 $user_info = get_userdata( $user_id );
4263 $display_name = $user_info->user_login;
4264 }
4265 $result['display_name'] = $display_name;
4266 if ( ! is_wp_error( $result ) ) {
4267 foreach ( $fields as $field ) {
4268 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4269 if ( $value == '0' || ! empty( $value ) ) {
4270 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4271 }
4272 }
4273 }
4274 }
4275
4276 //File fields
4277 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4278 if ( $fields ) {
4279 $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4280 if ( ! is_wp_error( $result ) ) {
4281 foreach ( $fields as $field ) {
4282 $value = $result[ $field->htmlvar_name ];
4283 if ( $value == '0' || ! empty( $value ) ) {
4284 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4285 }
4286 }
4287 }
4288 }
4289 }
4290
4291 /**
4292 * Form field template for country field.
4293 *
4294 * @param string $html Form field html
4295 * @param object $field Field info.
4296 * @param string $value Form field default value.
4297 * @param string $form_type Form type
4298 *
4299 * @return string Modified form field html.
4300 * @package userswp
4301 *
4302 * @since 1.0.0
4303 */
4304 public function form_input_select_country( $html, $field, $value, $form_type ) {
4305
4306 // If no html then we run the standard output.
4307 if ( empty( $html ) ) {
4308
4309 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4310 $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4311 $bs_sr_only = $design_style ? 'sr-only' : '';
4312 $bs_form_control = $design_style ? 'form-control' : '';
4313
4314 ob_start(); // Start buffering;
4315 ?>
4316 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4317
4318 <?php
4319 $site_title = uwp_get_form_label( $field );
4320
4321 if ( ! is_admin() && ! wp_doing_ajax() ) {
4322 ?>
4323 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4324 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4325 <?php
4326 if ( $field->is_required ) {
4327 echo '<span class="text-danger">*</span>';
4328 }
4329 ?>
4330 </label>
4331 <?php
4332 }
4333 // if value empty set the default
4334 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4335 $value = $field->default_value;
4336 }
4337 if ( $value === false ) {
4338 $value = '';
4339 }
4340 $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4341 $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4342
4343 $htmlvar_name = $field->htmlvar_name;
4344 if ( wp_doing_ajax() ) {
4345 $htmlvar_name .= '_ajax';
4346 }
4347 ?>
4348 <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4349 <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4350 <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4351 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4352 <?php if ( $field->is_required ) { ?>
4353 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4354 <?php } ?>
4355 </div>
4356 <?php
4357 $html = ob_get_clean();
4358 }
4359
4360 return $html;
4361 }
4362
4363 /**
4364 * Form field template for language field.
4365 *
4366 * @param string $html Form field html
4367 * @param object $field Field info.
4368 * @param string $value Form field default value.
4369 * @param string $form_type Form type
4370 *
4371 * @return string Modified form field html.
4372 * @package userswp
4373 *
4374 * @since 1.0.0
4375 */
4376 public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4377
4378 // If no html then we run the standard output.
4379 if ( empty( $html ) ) {
4380
4381 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4382 $bs_form_group = $design_style ? 'form-group m-0' : '';
4383 $bs_sr_only = $design_style ? 'sr-only' : '';
4384 $bs_form_control = $design_style ? 'form-control' : '';
4385 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4386 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4387
4388 ob_start(); // Start buffering;
4389
4390 ?>
4391 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4392 class="
4393 <?php
4394 if ( $field->is_required ) {
4395 echo 'required_field';
4396 }
4397 ?>
4398 uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4399
4400 <?php
4401 $site_title = uwp_get_form_label( $field );
4402 if ( ! is_admin() && ! wp_doing_ajax() ) {
4403 ?>
4404 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4405 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4406 <?php
4407 if ( $field->is_required ) {
4408 echo '<span class="text-danger">*</span>';
4409 }
4410 ?>
4411 </label>
4412 <?php } ?>
4413
4414 <?php
4415 if ( empty( $field->default_value ) ) {
4416 $field->default_value = 'site-default';
4417 }
4418
4419 // if value empty set the default
4420 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4421 $value = $field->default_value;
4422 }
4423
4424 require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4425 $translations = wp_get_available_translations();
4426 $available_languages = get_available_languages();
4427 $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
4428
4429 foreach ( $available_languages as $locale ) {
4430 if ( isset( $translations[ $locale ] ) ) {
4431 $translation = $translations[ $locale ];
4432 $languages[ $translation['language'] ] = $translation['native_name'];
4433
4434 // Remove installed language from available translations.
4435 unset( $translations[ $locale ] );
4436 } else {
4437 $languages[ $locale ] = $translation[ $locale ];
4438 }
4439 }
4440
4441 if ( $design_style ) {
4442
4443 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4444
4445 echo aui()->select(
4446 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4447 'id' => esc_attr( $field->htmlvar_name ),
4448 'name' => esc_attr( $field->htmlvar_name ),
4449 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4450 'title' => esc_attr( $site_title ),
4451 'value' => esc_attr( $value ),
4452 'required' => (bool) $field->is_required,
4453 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4454 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4455 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4456 'label' => wp_kses_post( $site_title . $required ),
4457 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4458 'select2' => true,
4459 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4460 )
4461 );
4462 } else {
4463 ?>
4464 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4465 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4466 title="<?php echo esc_attr( $site_title ); ?>"
4467 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4468 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4469 </select>
4470 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4471 <?php if ( $field->is_required ) { ?>
4472 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4473 <?php
4474 }
4475 }
4476
4477 $html = ob_get_clean();
4478 }
4479
4480 return $html;
4481 }
4482
4483 /**
4484 * Adds confirm password field in forms.
4485 *
4486 * @param string $html Form field html
4487 * @param object $field Field info.
4488 * @param string $value Form field default value.
4489 * @param string $form_type Form type
4490 *
4491 * @return string Modified form field html.
4492 * @package userswp
4493 *
4494 * @since 1.0.0
4495 */
4496 public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4497 if ( $form_type == 'register' ) {
4498 //confirm password field
4499 $extra = array();
4500 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4501 $extra = unserialize( $field->extra_fields );
4502 }
4503
4504 $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4505 if ( $enable_confirm_password_field == '1' ) {
4506
4507 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4508 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4509 $bs_sr_only = $design_style ? 'sr-only' : '';
4510 $bs_form_control = $design_style ? 'form-control' : '';
4511 $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4512 $required = '';
4513 if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4514 $placeholder .= ' *';
4515 $required = ' <span class="text-danger">*</span>';
4516 }
4517 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4518 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4519 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4520
4521 ob_start(); // Start buffering;
4522
4523 if ( $design_style ) {
4524
4525 echo aui()->input(
4526 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4527 'type' => 'password',
4528 'id' => 'confirm_password',
4529 'name' => 'confirm_password',
4530 'placeholder' => esc_attr( $placeholder ),
4531 'title' => esc_attr( $site_title ),
4532 'value' => esc_attr( $value ),
4533 'required' => (bool) $field->is_required,
4534 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4535 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4536 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4537 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4538 'wrap_class' => esc_attr( $wrap_class ),
4539 )
4540 );
4541 } else {
4542 ?>
4543 <div id="uwp_account_confirm_password_row"
4544 class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4545
4546 <?php
4547
4548 if ( ! is_admin() ) {
4549 ?>
4550 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4551 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4552 <?php
4553 if ( $field->is_required ) {
4554 echo '<span>*</span>';
4555 }
4556 ?>
4557 </label>
4558 <?php } ?>
4559 <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4560 </div>
4561
4562 <?php
4563 }
4564 $confirm_html = ob_get_clean();
4565 $html = $html . $confirm_html;
4566 }
4567 }
4568
4569 return $html;
4570 }
4571
4572 /**
4573 * Adds confirm email field in forms.
4574 *
4575 * @param string $html Form field html
4576 * @param object $field Field info.
4577 * @param string $value Form field default value.
4578 * @param string $form_type Form type
4579 *
4580 * @return string Modified form field html.
4581 * @package userswp
4582 *
4583 * @since 1.0.0
4584 */
4585 public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4586 if ( $form_type == 'register' ) {
4587 //confirm email field
4588 $extra = array();
4589 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4590 $extra = unserialize( $field->extra_fields );
4591 }
4592 $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4593 if ( $enable_confirm_email_field == '1' ) {
4594
4595 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4596 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4597 $bs_sr_only = $design_style ? 'sr-only' : '';
4598 $bs_form_control = $design_style ? 'form-control' : '';
4599 $site_title = __( 'Confirm Email', 'userswp' );
4600 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4601 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4602
4603 ob_start();
4604
4605 if ( $design_style ) {
4606 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4607
4608 echo aui()->input(
4609 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4610 'type' => 'email',
4611 'id' => esc_attr( $field->htmlvar_name ),
4612 'name' => 'confirm_email',
4613 'placeholder' => esc_attr( $site_title ),
4614 'title' => esc_attr( $site_title ),
4615 'value' => esc_attr( $value ),
4616 'required' => (bool) $field->is_required,
4617 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4618 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4619 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4620 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4621 )
4622 );
4623 } else {
4624 ?>
4625 <div id="uwp_account_confirm_email_row"
4626 class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4627
4628 <?php
4629
4630 if ( ! is_admin() ) {
4631 ?>
4632 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4633 <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
4634 <?php
4635 if ( $field->is_required ) {
4636 echo '<span>*</span>';
4637 }
4638 ?>
4639 </label>
4640 <?php } ?>
4641
4642 <input name="confirm_email"
4643 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4644 id="uwp_account_confirm_email"
4645 placeholder="<?php echo esc_attr( $site_title ); ?>"
4646 value=""
4647 title="<?php echo esc_attr( $site_title ); ?>"
4648 <?php echo 'required="required"'; ?>
4649 type="email"
4650 />
4651 </div>
4652 <?php
4653 }
4654 $confirm_html = ob_get_clean();
4655 $html = $html . $confirm_html;
4656 }
4657 }
4658
4659 return $html;
4660 }
4661
4662 /**
4663 * Handles the privacy form submission.
4664 *
4665 * @return void
4666 * @package userswp
4667 *
4668 * @since 1.0.0
4669 */
4670 public function privacy_submit_handler() {
4671 if ( isset( $_POST['uwp_privacy_submit'] ) ) {
4672 if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
4673 return;
4674 }
4675
4676 global $wpdb, $uwp_notices;
4677
4678 // Save fields privacy settings
4679 $extra_where = "AND is_public='2'";
4680 $fields = get_account_form_fields( $extra_where );
4681 $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
4682 $user_id = get_current_user_id();
4683 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
4684
4685 $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4686 if ( ! empty( $user_meta_info->user_privacy ) ) {
4687 $public_fields = explode( ',', $user_meta_info->user_privacy );
4688 } else {
4689 $public_fields = array();
4690 }
4691
4692 if ( $fields ) {
4693
4694 foreach ( $fields as $field ) {
4695 $field_name = $field->htmlvar_name . '_privacy';
4696 $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4697
4698 if ( $field_value == 'no' ) {
4699 if ( ! in_array( $field_name, $public_fields ) ) {
4700 $public_fields[] = $field_name;
4701 }
4702 } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
4703 unset( $public_fields[ $field_name ] );
4704 }
4705 }
4706
4707 $value = implode( ',', $public_fields );
4708 uwp_update_usermeta( $user_id, 'user_privacy', $value );
4709 }
4710
4711 // Save tabs privacy settings
4712 $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
4713 $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4714
4715 if ( $tabs ) {
4716 $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
4717 $do_tabs_update = false;
4718 foreach ( $tabs as $tab ) {
4719 $field_name = $tab->tab_key . '_tab_privacy';
4720
4721 if ( isset( $_POST[ $field_name ] ) ) {
4722 $do_tabs_update = true;
4723 $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
4724
4725 if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
4726 unset( $public_fields[ $field_name ] );
4727 } else {
4728 $public_fields[ $field_name ] = $field_value;
4729 }
4730 }
4731 }
4732
4733 if ( $do_tabs_update ) {
4734 uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
4735 }
4736 }
4737
4738 if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
4739 update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
4740 } else {
4741 update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
4742 }
4743
4744 $make_profile_private = uwp_can_make_profile_private();
4745 if ( $make_profile_private ) {
4746 $field_name = 'uwp_make_profile_private';
4747 if ( isset( $_POST[ $field_name ] ) ) {
4748 $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4749 $user_id = get_current_user_id();
4750 update_user_meta( $user_id, $field_name, $value );
4751 }
4752 }
4753
4754 $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
4755 $message = aui()->alert(
4756 array(
4757 'type' => 'success',
4758 'content' => $message,
4759 )
4760 );
4761 $uwp_notices[] = array( 'account' => $message );
4762
4763 }
4764 }
4765
4766 /**
4767 * Get the ajax login form.
4768 *
4769 * @since 1.2.0
4770 */
4771 public function ajax_login_form() {
4772
4773 // add the modal error container
4774 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4775
4776 $args = array(
4777 'form_title' => __( 'Login', 'userswp' ),
4778 );
4779
4780 // get the form
4781 ob_start();
4782 uwp_get_template( 'bootstrap/login.php', $args );
4783 $form = ob_get_clean();
4784
4785 // bs5
4786 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4787 $form = aui_bs_convert_sd_output( $form );
4788 }
4789 // send ajax response
4790 wp_send_json_success( $form );
4791 }
4792
4793 /**
4794 * Get the ajax register form.
4795 *
4796 * @since 1.2.0
4797 */
4798 public function ajax_register_form() {
4799
4800 // add the modal error container
4801 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4802
4803 global $wp_scripts;
4804 if ( empty( $wp_scripts ) ) {
4805 $wp_scripts = wp_scripts();
4806 }
4807
4808 // do we need country code script in ajax?
4809 $country_field = false;
4810 $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
4811
4812 if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
4813 $form_id = (int)$_POST['form_id'];
4814 } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
4815 $form_id = reset( $lightbox_forms );
4816 } else {
4817 $form_id = 1;
4818 }
4819
4820 $fields = get_register_form_fields( $form_id );
4821 if ( ! empty( $fields ) ) {
4822 foreach ( $fields as $field ) {
4823 if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
4824 $country_field = true;
4825 }
4826 }
4827 }
4828
4829 ob_start();
4830
4831 // maybe add country code JS
4832 if ( $country_field ) {
4833 $country_data = uwp_get_country_data();
4834 echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
4835 echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
4836 }
4837
4838 $args = array( 'form_title' => '' );
4839 if ( $form_id > 0 ) {
4840 $args['id'] = $form_id;
4841 }
4842
4843 $args['limit'] = $lightbox_forms;
4844
4845 // get template
4846 uwp_get_template( 'bootstrap/register.php', $args );
4847
4848 // only show the JS if NOT doing a block render
4849 if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
4850 // load scripts
4851 $wp_scripts->do_item( 'zxcvbn-async' );
4852 $wp_scripts->do_item( 'wp-hooks' );
4853 $wp_scripts->do_item( 'wp-i18n' );
4854 $wp_scripts->do_item( 'password-strength-meter' );
4855 ?>
4856 <script>
4857 // Password strength indicator script
4858 jQuery(function ($) {
4859
4860 // Load the settings like WP does.
4861 var first, s;
4862 s = document.createElement('script');
4863 s.src = _zxcvbnSettings.src;
4864 s.type = 'text/javascript';
4865 s.async = true;
4866 first = document.getElementsByTagName('script')[0];
4867 first.parentNode.insertBefore(s, first);
4868
4869 // Enable any pass inputs.
4870 $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
4871 function (event) {
4872 var $form = $(this).closest('form');
4873 if( ! $form.hasClass('uwp-login-form') ) {
4874 uwp_checkPasswordStrength(
4875 $('input[name=password]', $form), // First password field
4876 $('input[name=confirm_password]', $form), // Second password field
4877 $('#uwp-password-strength', $form), // Strength meter
4878 $('input[type=submit]', $form), // Submit button
4879 ['black', 'listed', 'word'] // Blacklisted words
4880 );
4881 }
4882 }
4883 );
4884 });
4885 </script>
4886 <?php
4887 }
4888 $form = ob_get_clean();
4889
4890 // bs5
4891 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4892 $form = aui_bs_convert_sd_output( $form );
4893 }
4894
4895 // send ajax response
4896 wp_send_json_success( $form );
4897 }
4898
4899 /**
4900 * Get the ajax forgot password form.
4901 *
4902 * @since 1.2.0
4903 */
4904 public function ajax_forgot_password_form() {
4905
4906 // add the modal error container
4907 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4908
4909 // get the form
4910 ob_start();
4911 uwp_get_template( 'bootstrap/forgot.php' );
4912 $form = ob_get_clean();
4913
4914 // bs5
4915 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4916 $form = aui_bs_convert_sd_output( $form );
4917 }
4918
4919 // send ajax response
4920 wp_send_json_success( $form );
4921 }
4922
4923 /**
4924 * Output the modal error container.
4925 *
4926 * @param string $type
4927 *
4928 * @since 1.2.0
4929 */
4930 public function modal_error_container( $type = '' ) {
4931 echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
4932 }
4933
4934 public function form_custom_html( $html, $field, $value, $form_type ) {
4935
4936 $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
4937
4938 return $html;
4939 }
4940 }
4941