PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.38
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.38
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
← All changes | includes/class-forms.php +4534 -2255 1.0.101.2.38 View file →
@@ -1,5 +1,6 @@
1 1 <?php
2 +
2 3 /**
3 4 * Form related functions
4 5 *
5 6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
@@ -8,2654 +9,4932 @@
8 9 * @author GeoDirectory Team <info@wpgeodirectory.com>
9 10 */
10 11 class UsersWP_Forms {
11 12
12 - protected $generated_password;
13 + protected $generated_password;
13 14
14 - /**
15 - * Initialize UsersWP notices.
16 - *
17 - * @since 1.0.0
18 - * @package userswp
19 - *
20 - * @return void
21 - */
22 - public function init_notices() {
23 - global $uwp_notices;
24 - $uwp_notices = array();
25 - }
15 + /**
16 + * Logs the error message.
17 + *
18 + * @param array|object|string $log Error message.
19 + *
20 + * @return void
21 + * @since 1.0.0
22 + * @package userswp
23 + *
24 + */
25 + public static function uwp_error_log( $log ) {
26 + uwp_error_log( $log );
27 + }
26 28
27 - /**
28 - * Handles all UsersWP forms.
29 - *
30 - * @since 1.0.0
31 - * @package userswp
32 - *
33 - * @return void
34 - */
35 - public function handler()
36 - {
37 - global $uwp_notices;
29 + /**
30 + * Initialize UsersWP notices.
31 + *
32 + * @return void
33 + * @package userswp
34 + *
35 + * @since 1.0.0
36 + */
37 + public function init_notices() {
38 + global $uwp_notices;
39 + $uwp_notices = array();
40 + }
38 41
39 - ob_start();
42 + /**
43 + * Handles all UsersWP forms.
44 + *
45 + * @return void
46 + * @package userswp
47 + *
48 + * @since 1.0.0
49 + */
50 + public function handler() {
51 + global $uwp_notices;
40 52
41 - $errors = null;
42 - $message = null;
43 - $redirect = false;
44 - $processed = false;
53 + ob_start();
45 54
46 - $login_page = uwp_get_option('login_page', false);
47 - if ($login_page) {
48 - $login_page_url = get_permalink($login_page);
49 - } else {
50 - $login_page_url = wp_login_url();
51 - }
55 + $errors = null;
56 + $message = null;
57 + $redirect = false;
58 + $processed = false;
59 + $type = null;
52 60
53 - $redirect_page_id = uwp_get_option('login_redirect_to', '');
54 - if (empty($redirect_page_id)) {
55 - $redirect_to = home_url('/');
56 - } else {
57 - $redirect_to = get_permalink($redirect_page_id);
58 - }
59 - $redirect_to = apply_filters('uwp_login_redirect', $redirect_to);
61 + if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 + if ( ! is_wp_error( $errors ) ) {
64 + $redirect = $errors;
65 + }
66 + $message = __( 'Avatar cropped successfully.', 'userswp' );
67 + $processed = true;
68 + } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 + if ( ! is_wp_error( $errors ) ) {
71 + $redirect = $errors;
72 + }
73 + $message = __( 'Banner cropped successfully.', 'userswp' );
74 + $processed = true;
75 + } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 + $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 + if ( ! is_wp_error( $errors ) ) {
78 + $redirect = $errors;
79 + }
80 + $message = __( 'Avatar cropped successfully.', 'userswp' );
81 + $processed = true;
82 + } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 + $errors = $this->process_image_crop( $_POST, 'banner', true );
84 + if ( ! is_wp_error( $errors ) ) {
85 + $redirect = $errors;
86 + }
87 + $message = __( 'Banner cropped successfully.', 'userswp' );
88 + $processed = true;
89 + } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 + $errors = $this->process_image_reset( 'avatar' );
91 + if ( ! is_wp_error( $errors ) ) {
92 + $redirect = $errors;
93 + }
94 + $message = __( 'Avatar reset successfully.', 'userswp' );
95 + $processed = true;
96 + } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 + $errors = $this->process_image_reset( 'banner' );
98 + if ( ! is_wp_error( $errors ) ) {
99 + $redirect = $errors;
100 + }
101 + $message = __( 'Banner reset successfully.', 'userswp' );
102 + $processed = true;
103 + }
60 104
61 - if (isset($_POST['uwp_register_nonce'])) {
62 - $auto_login = uwp_get_option('uwp_registration_action', false);
63 - $errors = $this->process_register($_POST, $_FILES);
64 - if (!is_wp_error($errors)) {
65 - $message = $errors;
66 - }
67 - if ($auto_login == 'auto_approve_login') {
68 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
69 - if (empty($reg_redirect_page_id)) {
70 - $reg_redirect_to = $redirect_to;
71 - } else {
72 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
73 - }
74 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
75 - }
76 - $processed = true;
77 - } elseif (isset($_POST['uwp_login_nonce'])) {
78 - $errors = $this->process_login($_POST);
79 - if (isset($_POST['redirect_to'])) {
80 - $redirect_to = strip_tags(esc_sql($_POST['redirect_to']));
81 - }
82 - $redirect = $redirect_to;
83 - $processed = true;
84 - } elseif (isset($_POST['uwp_forgot_nonce'])) {
85 - $errors = $this->process_forgot($_POST);
86 - $message = __('Please check your email.', 'userswp');
87 - $processed = true;
88 - } elseif (isset($_POST['uwp_change_nonce'])) {
89 - $errors = $this->process_change($_POST);
90 - $message = __('Password changed successfully', 'userswp');
91 - $processed = true;
92 - } elseif (isset($_POST['uwp_reset_submit'])) {
93 - $errors = $this->process_reset($_POST);
94 - $message = sprintf(__('Password updated successfully. Please <a href="%s">login</a> with your new password', 'userswp'), $login_page_url);
95 - $processed = true;
96 - } elseif (isset($_POST['uwp_account_nonce'])) {
97 - $errors = $this->process_account($_POST, $_FILES);
98 - $message = __('Account updated successfully.', 'userswp');
99 - $processed = true;
100 - } elseif (isset($_POST['uwp_avatar_submit'])) {
101 - $errors = $this->process_upload_submit($_POST, $_FILES, 'avatar');
102 - if (!is_wp_error($errors)) {
103 - $redirect = $errors;
104 - }
105 - $message = __('Avatar cropped successfully.', 'userswp');
106 - $processed = true;
107 - } elseif (isset($_POST['uwp_banner_submit'])) {
108 - $errors = $this->process_upload_submit($_POST, $_FILES, 'banner');
109 - if (!is_wp_error($errors)) {
110 - $redirect = $errors;
111 - }
112 - $message = __('Banner cropped successfully.', 'userswp');
113 - $processed = true;
114 - } elseif (isset($_POST['uwp_avatar_crop'])) {
115 - $errors = $this->process_image_crop($_POST, 'avatar');
116 - if (!is_wp_error($errors)) {
117 - $redirect = $errors;
118 - }
119 - $message = __('Avatar cropped successfully.', 'userswp');
120 - $processed = true;
121 - } elseif (isset($_POST['uwp_banner_crop'])) {
122 - $errors = $this->process_image_crop($_POST, 'banner');
123 - if (!is_wp_error($errors)) {
124 - $redirect = $errors;
125 - }
126 - $message = __('Banner cropped successfully.', 'userswp');
127 - $processed = true;
128 - }
105 + if ( $processed ) {
129 106
130 - if ($processed) {
131 - if (is_wp_error($errors)) {
132 - echo '<div class="uwp-alert-error text-center">';
133 - echo $errors->get_error_message();
134 - echo '</div>';
135 - } else {
136 - if ($redirect) {
137 - wp_redirect($redirect);
138 - exit();
139 - } else {
140 - echo '<div class="uwp-alert-success text-center">';
141 - echo $message;
142 - echo '</div>';
143 - }
144 - }
145 - }
107 + if ( is_wp_error( $errors ) ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
116 + wp_safe_redirect( $redirect );
117 + exit();
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
125 + );
126 + }
127 + }
146 128
147 - $uwp_notices[] = ob_get_contents();
148 - ob_end_clean();
129 + if ( $type ) {
130 + $uwp_notices[] = array( $type => ob_get_contents() );
131 + } else {
132 + $uwp_notices[] = ob_get_contents();
133 + }
149 134
150 - }
135 + ob_end_clean();
136 + }
151 137
152 - /**
153 - * Displays UsersWP notices in forms.
154 - *
155 - * @since 1.0.0
156 - * @package userswp
157 - *
158 - * @param string $type Form type
159 - *
160 - * @return void
161 - */
162 - public function display_notices($type) {
163 - global $uwp_notices;
138 + /**
139 + * Processes avatar and banner uploads form submission.
140 + *
141 + * @param array $data Submitted $_POST data
142 + * @param array $files Submitted $_FILES data
143 + *
144 + * @return bool|WP_Error|string File url to crop.
145 + * @package userswp
146 + *
147 + * @since 1.0.0
148 + */
149 + public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
164 150
165 - if (is_array($uwp_notices)) {
166 - foreach ($uwp_notices as $notice) {
167 - if (!empty($notice)) {
168 - echo $notice;
169 - }
170 - }
151 + $file_obj = new UsersWP_Files();
171 152
172 - }
153 + $current_user_id = get_current_user_id();
154 + if ( ! $current_user_id ) {
155 + return false;
156 + }
173 157
174 - if ($type == 'change') {
175 - $user_id = get_current_user_id();
176 - $password_nag = get_user_option('default_password_nag', $user_id);
158 + if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
159 + return false;
160 + }
177 161
178 - if ($password_nag) {
179 - $change_page = uwp_get_option('change_page', false);
180 - $remove_nag_url = add_query_arg('uwp_remove_nag', 'yes', get_permalink($change_page));
162 + do_action( 'uwp_before_validate', $type );
181 163
182 - if (isset($_GET['uwp_remove_nag']) && $_GET['uwp_remove_nag'] == 'yes') {
183 - delete_user_meta( $user_id, 'default_password_nag' );
184 - $message = sprintf(__('We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp'), home_url('/'));
185 - echo '<div class="uwp-alert-success text-center">';
186 - echo $message;
187 - echo '</div>';
188 - } else {
189 - $message = sprintf(__('<strong>Warning</strong>: You seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp'), $remove_nag_url);
190 - echo '<div class="uwp-alert-warning text-center">';
191 - echo $message;
192 - echo '</div>';
193 - }
194 - }
195 - }
196 - }
164 + $result = $file_obj->validate_uploads( $files, $type );
197 165
198 - /**
199 - * Processes register form submission.
200 - *
201 - * @since 1.0.0
202 - * @package userswp
203 - *
204 - * @param array $data Submitted $_POST data
205 - * @param array $files Submitted $_FILES data
206 - *
207 - * @return bool|WP_Error|string
208 - */
209 - public function process_register($data = array(), $files = array()) {
166 + $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
210 167
211 - $errors = new WP_Error();
212 - $file_obj = new UsersWP_Files();
168 + if ( is_wp_error( $result ) ) {
169 + return $result;
170 + }
213 171
214 - if( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
215 - return false;
216 - }
172 + $profile_url = uwp_build_profile_tab_url( $current_user_id );
217 173
218 - if (!get_option('users_can_register')) {
219 - $errors->add('register_disabled', __('<strong>ERROR</strong>: User registration is currently not allowed.', 'userswp'));
220 - return $errors;
221 - }
174 + $url = add_query_arg(
175 + array(
176 + 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
177 + 'type' => $type,
178 + ),
179 + $profile_url
180 + );
222 181
223 - $reg_terms_page_id = uwp_get_option('register_terms_page', '');
224 - $reg_terms_page_id = apply_filters('uwp_reg_terms_page_id', $reg_terms_page_id);
225 - if (!empty($reg_terms_page_id)) {
226 - if (!isset($data['agree_terms']) || $data['agree_terms'] != 'yes') {
227 - $errors->add('accept_tos', __('<strong>ERROR</strong>: You must accept our terms and conditions.', 'userswp'));
228 - return $errors;
229 - }
230 - }
182 + return $url;
183 + }
231 184
232 - do_action('uwp_before_validate', 'register');
185 + /**
186 + * Processes avatar and banner uploads image crop.
187 + *
188 + * @param array $data Submitted $_POST data
189 + * @param string $type Image type. Default 'avatar'.
190 + * @param bool $unlink_prev_img True to remove previous image. Default false;
191 + *
192 + * @return bool|WP_Error|string Profile url.
193 + * @since 1.0.12 New param $unlink_prev_img introduced.
194 + * @package userswp
195 + *
196 + * @since 1.0.0
197 + */
198 + public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
199 + global $wpdb;
200 + if ( ! is_user_logged_in() ) {
201 + return false;
202 + }
233 203
234 - $result = uwp_validate_fields($data, 'register');
235 -
236 - $result = apply_filters('uwp_validate_result', $result, 'register');
204 + if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 + return;
206 + }
237 207
238 - if (is_wp_error($result)) {
239 - return $result;
240 - }
208 + // If is current user's profile (profile.php)
209 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
210 + $user_id = get_current_user_id();
211 + // If is another user's profile page
212 + } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
213 + $user_id = absint( $_GET['user_id'] );
214 + // Otherwise something is wrong.
215 + } else {
216 + $user_id = get_current_user_id();
217 + }
241 218
242 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'register');
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
243 222
244 - if (is_wp_error($uploads_result)) {
245 - return $uploads_result;
246 - }
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
247 227
248 - do_action('uwp_after_validate', 'register');
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
249 231
250 - $result = array_merge( $result, $uploads_result );
232 + // Retrieve current thumbnail.
233 + $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
234 + $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
235 + $thumb_postfix = '_uwp_' . $type . '_thumb';
251 236
252 - $error_code = $errors->get_error_code();
253 - if (!empty($error_code)) {
254 - return $errors;
255 - }
237 + if ( $image_url ) {
238 + if ( $type == 'avatar' ) {
239 + $avatar_size = uwp_get_upload_image_size();
240 + $full_width = $avatar_size['width'];
241 + } else {
242 + $banner_size = uwp_get_upload_image_size( 'banner' );
243 + $full_width = $banner_size['width'];
244 + }
256 245
257 - if (isset($result['password']) && !empty($result['password'])) {
258 - $password = $result['password'];
259 - $generated_password = false;
260 - } else {
261 - $password = wp_generate_password();
262 - $this->generated_password = $password;
263 - $generated_password = true;
264 - }
246 + add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
247 + $uploads = wp_upload_dir();
248 + remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
249 + $upload_url = $uploads['baseurl'];
250 + $upload_path = $uploads['basedir'];
251 + $image_path = str_replace( $upload_url, $upload_path, $image_url );
252 + $ext = $filetype['ext']; // to get extension
253 + $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
254 + $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
255 + $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
256 + //Get the new coordinates to crop the image.
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
261 + //Scale the image based on cropped width setting
262 + $scale = $full_width / $w;
263 + //$scale = 1; // no scaling
265 264
266 - $first_name = "";
267 - if (isset($result['uwp_account_first_name']) && !empty($result['uwp_account_first_name'])) {
268 - $first_name = $result['uwp_account_first_name'];
269 - }
265 + // check we are not editing another user file
266 + $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
267 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
268 + $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
270 269
271 - $last_name = "";
272 - if (isset($result['uwp_account_last_name']) && !empty($result['uwp_account_last_name'])) {
273 - $last_name = $result['uwp_account_last_name'];
274 - }
270 + // if file already exists then we should not be cropping it.
271 + if ( $file_exists ) {
272 + wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
273 + }
275 274
276 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
277 - $display_name = $result['uwp_account_display_name'];
278 - } else {
279 - if (!empty($first_name) || !empty($last_name)) {
280 - $display_name = $first_name . ' ' . $last_name;
281 - } else {
282 - $display_name = $result['uwp_account_username'];
283 - }
284 - }
275 + $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
276 + $cropped = str_replace( $upload_path, $upload_url, $cropped );
285 277
286 - $description = "";
287 - if (isset($result['uwp_account_bio']) && !empty($result['uwp_account_bio'])) {
288 - $description = $result['uwp_account_bio'];
289 - }
278 + // Remove previous avatar/banner
279 + $unlink_img = '';
280 + if ( $unlink_prev_img && $current_thumbnail ) {
281 + $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
282 + }
290 283
284 + // remove the uploads path for easy migrations
285 + $cropped = str_replace( $upload_url, '', $cropped );
286 + if ( $type == 'avatar' ) {
287 + uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
288 + } else {
289 + uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
290 + }
291 291
292 - $args = array(
293 - 'user_login' => $result['uwp_account_username'],
294 - 'user_email' => $result['uwp_account_email'],
295 - 'user_pass' => $password,
296 - 'display_name' => $display_name,
297 - 'first_name' => $first_name,
298 - 'last_name' => $last_name,
299 - 'description' => $description
300 - );
292 + if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
293 + @unlink( $unlink_img );
294 + $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
295 + if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
296 + @unlink( $unlink_ori_img );
297 + }
298 + }
299 + }
301 300
302 - $user_id = wp_insert_user( $args );
301 + if ( is_admin() ) {
302 + if ( $user_id == get_current_user_id() ) {
303 + $redirect_url = admin_url( 'profile.php' );
304 + } else {
305 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
306 + }
307 + } elseif ( uwp_current_page_url() ) {
308 + $redirect_url = uwp_current_page_url();
309 + } else {
310 + $redirect_url = uwp_build_profile_tab_url( $user_id );
311 + }
303 312
304 - if (!$user_id) {
305 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
306 - return $errors;
307 - }
313 + return $redirect_url;
314 + }
308 315
309 - $result = apply_filters('uwp_before_extra_fields_save', $result, 'register', $user_id);
310 -
311 - $save_result = $this->uwp_save_user_extra_fields($user_id, $result, 'register');
316 + /**
317 + * Normalizes a URL.
318 + *
319 + */
320 + public function normalize_url( $url ) {
312 321
313 - $save_result = apply_filters('uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id);
322 + // Normalize.
323 + $url = wp_normalize_path( $url );
314 324
315 - if (is_wp_error($save_result)) {
316 - return $save_result;
317 - }
325 + // Remove query vars.
326 + $url = strtok( $url, '?' );
318 327
319 - if (!$save_result) {
320 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
321 - }
328 + // Split.
329 + $url = explode( '/', $url );
322 330
323 - $error_code = $errors->get_error_code();
324 - if (!empty($error_code)) {
325 - return $errors;
326 - }
331 + // Clean.
332 + $url = array_diff( $url, array( '..', '.' ) );
327 333
328 - do_action('uwp_after_custom_fields_save', 'register', $data, $result, $user_id);
329 -
330 - $reg_action = uwp_get_option('uwp_registration_action', false);
334 + // Rejoin and return.
335 + return implode( '/', $url );
336 + }
331 337
332 - if ($reg_action == 'require_email_activation' && !$generated_password) {
338 + /**
339 + * Processes avatar and banner image reset.
340 + *
341 + * @param string $type Image type. Default 'avatar'.
342 + *
343 + * @return bool|WP_Error|string Profile url.
344 + * @package userswp
345 + *
346 + */
347 + public function process_image_reset( $type ) {
348 + if ( ! is_user_logged_in() ) {
349 + return false;
350 + }
333 351
334 - $email = new UsersWP_Mails();
335 - $send_result = $email->send( 'activate', $user_id );
336 -
337 - if (!$send_result) {
338 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
339 - }
340 - } else {
341 - $email = new UsersWP_Mails();
342 - $send_result = $email->send( 'register', $user_id );
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
343 355
344 - if (!$send_result) {
345 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
346 - }
347 - }
356 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
357 + $user_id = get_current_user_id();
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
360 + $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
362 + } else {
363 + $user_id = get_current_user_id();
364 + }
348 365
349 - if ($reg_action != 'require_admin_review') {
350 - $register_admin_notify = uwp_get_option('register_admin_notify', '');
351 - if ($register_admin_notify == '1') {
352 - $admin_register_send_result = $email->send_admin_email('register_admin', $user_id);
353 - if (is_wp_error($admin_register_send_result)) {
354 - return $admin_register_send_result;
366 + $errors = new WP_Error();
367 + if ( empty( $user_id ) ) {
368 + $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
369 + }
370 +
371 + $error_code = $errors->get_error_code();
372 + if ( ! empty( $error_code ) ) {
373 + return $errors;
374 + }
375 +
376 + if ( $type == 'avatar' ) {
377 + uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
378 + } elseif ( $type == 'banner' ) {
379 + uwp_update_usermeta( $user_id, 'banner_thumb', '' );
380 + } else {
381 + // Do nothing
382 + }
383 +
384 + if ( is_admin() ) {
385 + if ( $user_id == get_current_user_id() ) {
386 + $redirect_url = admin_url( 'profile.php' );
387 + } else {
388 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
389 + }
390 + } elseif ( uwp_current_page_url() ) {
391 + $redirect_url = uwp_current_page_url();
392 + } else {
393 + $redirect_url = uwp_build_profile_tab_url( $user_id );
394 + }
395 +
396 + return $redirect_url;
397 + }
398 +
399 + /**
400 + * Displays links in a dropdown
401 + *
402 + * @param $options
403 + *
404 + * @package userswp
405 + *
406 + * @since 1.0.0
407 + */
408 + public function output_dashboard_links( $options ) {
409 + if ( ! empty( $options ) ) {
410 + $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
411 + echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
412 + $this->output_options( $options );
413 + echo '</select>';
414 + }
415 + }
416 +
417 + /**
418 + * Displays options for the dashboard links
419 + *
420 + * @param $options
421 + *
422 + * @package userswp
423 + *
424 + * @since 1.0.0
425 + */
426 + public function output_options( $options ) {
427 + if ( ! empty( $options ) ) {
428 + foreach ( $options as $key => $link ) {
429 +
430 + if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
431 + $this->output_options( $link );
432 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
433 + echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
434 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
435 + echo '</optgroup>';
436 + } elseif ( ! empty( $link['text'] ) ) {
437 + echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
438 + echo esc_attr__( $link['text'], 'userswp' );
439 + echo '</option>';
440 + }
441 + }
442 + }
443 + }
444 +
445 + /**
446 + * Displays UsersWP notices in forms.
447 + *
448 + * @param string $type Form type
449 + *
450 + * @return void
451 + * @since 1.0.0
452 + * @package userswp
453 + *
454 + */
455 + public function display_notices( $type ) {
456 + global $uwp_notices;
457 +
458 + if ( is_array( $uwp_notices ) ) {
459 + foreach ( $uwp_notices as $notice ) {
460 +
461 + // If the notification is type specific then only output on that type
462 + if ( is_array( $notice ) ) {
463 + foreach ( $notice as $key => $val ) {
464 + if ( $key == $type ) {
465 + echo wp_kses_post( $val );
466 + }
467 + }
468 + } elseif ( ! empty( $notice ) ) {
469 + echo wp_kses_post( $notice );
470 + }
471 +}
472 +}
473 +
474 + if ( $type == 'change' ) {
475 + $user_id = get_current_user_id();
476 + $password_nag = get_user_option( 'default_password_nag', $user_id );
477 +
478 + if ( $password_nag ) {
479 + $change_page = uwp_get_page_id( 'change_page', false );
480 + $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
481 +
482 + if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
483 + delete_user_meta( $user_id, 'default_password_nag' );
484 + $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
485 + echo aui()->alert(
486 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
487 + 'class' => 'text-center',
488 + 'type' => 'success',
489 + 'content' => wp_kses_post( $message ),
490 + )
491 + );
492 + } else {
493 + $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
494 + echo aui()->alert(
495 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
496 + 'class' => 'text-center',
497 + 'type' => 'warning',
498 + 'content' => wp_kses_post( $message ),
499 + )
500 + );
501 + }
502 + }
503 + }
504 + }
505 +
506 + /**
507 + * Processes register form submission.
508 + *
509 + * @since 1.0.0
510 + * @package userswp
511 + *
512 + */
513 + public function process_register() {
514 +
515 + $data = $_POST;
516 +
517 + if ( ! isset( $data['uwp_register_nonce'] ) ) {
518 + return;
519 + }
520 +
521 + global $uwp_notices;
522 +
523 + if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
524 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
525 + }
526 +
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
528 + $message = aui()->alert(
529 + array(
530 + 'type' => 'error',
531 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
532 + )
533 + );
534 + if ( wp_doing_ajax() ) {
535 + wp_send_json_error( array( 'message' => $message ) );
536 + } else {
537 + $uwp_notices[] = array( 'register' => $message );
538 +
539 + return;
540 + }
541 + }
542 +
543 + $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
544 + if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
545 + $message = aui()->alert(
546 + array(
547 + 'type' => 'error',
548 + 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
549 + )
550 + );
551 + if ( wp_doing_ajax() ) {
552 + wp_send_json_error( array( 'message' => $message ) );
553 + } else {
554 + $uwp_notices[] = array( 'register' => $message );
555 +
556 + return;
557 + }
558 + }
559 +
560 + if ( ! get_option( 'users_can_register' ) ) {
561 + $message = aui()->alert(
562 + array(
563 + 'type' => 'error',
564 + 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
565 + )
566 + );
567 + if ( wp_doing_ajax() ) {
568 + wp_send_json_error( array( 'message' => $message ) );
569 + } else {
570 + $uwp_notices[] = array( 'register' => $message );
571 +
572 + return;
573 + }
574 + }
575 +
576 + $files = $_FILES;
577 + $errors = new WP_Error();
578 + $file_obj = new UsersWP_Files();
579 +
580 + do_action( 'uwp_before_validate', 'register' );
581 +
582 + $result = uwp_validate_fields( $data, 'register' );
583 +
584 + $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
585 +
586 + if ( is_wp_error( $result ) ) {
587 + $message = aui()->alert(
588 + array(
589 + 'type' => 'error',
590 + 'content' => $result->get_error_message(),
591 + )
592 + );
593 + if ( wp_doing_ajax() ) {
594 + wp_send_json_error( array( 'message' => $message ) );
595 + } else {
596 + $uwp_notices[] = array( 'register' => $message );
597 +
598 + return;
599 + }
600 + }
601 +
602 + $uploads_result = $file_obj->validate_uploads( $files, 'register' );
603 +
604 + if ( is_wp_error( $uploads_result ) ) {
605 + $message = aui()->alert(
606 + array(
607 + 'type' => 'error',
608 + 'content' => $uploads_result->get_error_message(),
609 + )
610 + );
611 + if ( wp_doing_ajax() ) {
612 + wp_send_json_error( array( 'message' => $message ) );
613 + } else {
614 + $uwp_notices[] = array( 'register' => $message );
615 +
616 + return;
617 + }
618 + }
619 +
620 + do_action( 'uwp_after_validate', $result, 'register', $data );
621 +
622 + $result = array_merge( $result, $uploads_result );
623 +
624 + if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
625 + $password = $result['password'];
626 + $generated_password = false;
627 + } else {
628 + $password = wp_generate_password();
629 + $this->generated_password = $password;
630 + $generated_password = true;
631 + }
632 +
633 + $first_name = '';
634 + if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
635 + $first_name = $result['first_name'];
636 + }
637 +
638 + $last_name = '';
639 + if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
640 + $last_name = $result['last_name'];
641 + }
642 +
643 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
644 + $display_name = $result['display_name'];
645 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
646 + $display_name = $first_name . ' ' . $last_name;
647 + } else {
648 + $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
649 + }
650 +
651 + $user_url = '';
652 + if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
653 + $user_url = esc_url_raw( $result['user_url'] );
654 + }
655 +
656 + $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
657 + $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
658 +
659 + if ( empty( $user_login ) ) {
660 + $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
661 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
662 + $new_user_login = strstr( $email, '@', true );
663 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
664 + $user_login = sanitize_user( $new_user_login, true );
665 + }
666 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
667 + $user_append_text = rand( 10, 1000 );
668 + $user_login = sanitize_user( $new_user_login . $user_append_text, true );
669 + }
670 +
671 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
672 + $user_login = $email;
673 + }
674 + }
675 + } elseif ( ! validate_username( $user_login ) ) {
676 + $message = aui()->alert(
677 + array(
678 + 'type' => 'error',
679 + 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
680 + )
681 + );
682 + if ( wp_doing_ajax() ) {
683 + wp_send_json_error( array( 'message' => $message ) );
684 + } else {
685 + $uwp_notices[] = array( 'register' => $message );
686 +
687 + return;
688 + }
689 + }
690 +
691 + $args = array(
692 + 'user_login' => sanitize_user( $user_login ),
693 + 'user_email' => sanitize_email( $email ),
694 + 'user_pass' => $password,
695 + 'display_name' => sanitize_text_field( $display_name ),
696 + 'first_name' => esc_attr( $first_name ),
697 + 'last_name' => esc_attr( $last_name ),
698 + 'user_url' => esc_url_raw( $user_url ),
699 + );
700 +
701 + $user_id = wp_insert_user( $args );
702 +
703 + if ( is_wp_error( $user_id ) ) {
704 + $message = aui()->alert(
705 + array(
706 + 'type' => 'error',
707 + 'content' => $user_id->get_error_message(),
708 + )
709 + );
710 + if ( wp_doing_ajax() ) {
711 + wp_send_json_error( array( 'message' => $message ) );
712 + } else {
713 + $uwp_notices[] = array( 'register' => $message );
714 +
715 + return;
716 + }
717 + }
718 +
719 + $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
720 +
721 + $form_id = 1;
722 +
723 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
724 + update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
725 + $form_id = (int) $data['uwp_register_form_id'];
726 + }
727 +
728 + $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
729 +
730 + if ( isset( $user_role ) && ! empty( $user_role ) ) {
731 + $user_roles = uwp_get_user_roles();
732 + $chosen_role = strtolower( $user_role );
733 + if ( ! empty( $user_roles ) ) {
734 + $wp_roles = wp_roles();
735 + if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
736 + $new_user = get_userdata( $user_id );
737 + if ( $new_user ) {
738 + $new_user->set_role( $chosen_role );
739 + }
740 + }
741 + }
742 + }
743 +
744 + $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
745 +
746 + $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
747 +
748 + if ( is_wp_error( $save_result ) ) {
749 + $message = aui()->alert(
750 + array(
751 + 'type' => 'error',
752 + 'content' => $save_result->get_error_message(),
753 + )
754 + );
755 + if ( wp_doing_ajax() ) {
756 + wp_send_json_error( array( 'message' => $message ) );
757 + } else {
758 + $uwp_notices[] = array( 'register' => $message );
759 +
760 + return;
761 + }
762 + }
763 +
764 + if ( ! $save_result ) {
765 + $message = aui()->alert(
766 + array(
767 + 'type' => 'error',
768 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
769 + )
770 + );
771 + if ( wp_doing_ajax() ) {
772 + wp_send_json_error( array( 'message' => $message ) );
773 + } else {
774 + $uwp_notices[] = array( 'register' => $message );
775 +
776 + return;
777 + }
778 + }
779 +
780 + //updating bio field after saving extra fields to reflect the points in mycred add on.
781 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
782 + $args = array(
783 + 'ID' => $user_id,
784 + 'description' => $result['bio'],
785 + );
786 + wp_update_user( $args );
787 + }
788 +
789 + do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
790 +
791 + // Unset post data to empty the form on submit
792 + $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
793 + foreach ( $data as $key => $value ) {
794 + if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
795 + unset( $_POST[ $key ] );
796 + }
797 + }
798 +
799 + $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
800 + if ( ! $reg_action ) {
801 + $reg_action = uwp_get_option( 'uwp_registration_action', false );
802 + }
803 +
804 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
805 +
806 + if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
807 +
808 + $user_data = get_userdata( $user_id );
809 + $activation_link = uwp_get_activation_link( $user_id );
810 +
811 + $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
812 +
813 + $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
814 +
815 + $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
816 +
817 + $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
818 +
819 + $email_vars = array(
820 + 'user_id' => $user_id,
821 + 'login_details' => $activate_message,
822 + 'activation_link' => $activation_link,
823 + );
824 +
825 + UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
826 +
827 + } elseif ( $reg_action != 'require_admin_review' ) {
828 +
829 + $user_data = get_userdata( $user_id );
830 +
831 + if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
832 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
833 + update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
834 + }
835 + $message_pass = $this->generated_password;
836 + $this->generated_password = false;
837 + } else {
838 + $message_pass = __( 'Password you entered during registration.', 'userswp' );
839 + }
840 +
841 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
842 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
843 + <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
844 +
845 + $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
846 +
847 + $email_vars = array(
848 + 'user_id' => $user_id,
849 + 'login_details' => $message,
850 + 'form_fields' => $form_fields,
851 + );
852 +
853 + UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
854 + }
855 +
856 + $error_code = $errors->get_error_code();
857 + if ( ! empty( $error_code ) ) {
858 + $message = aui()->alert(
859 + array(
860 + 'type' => 'error',
861 + 'content' => $result->get_error_message(),
862 + )
863 + );
864 + if ( wp_doing_ajax() ) {
865 + wp_send_json_error( array( 'message' => $message ) );
866 + } else {
867 + $uwp_notices[] = array( 'register' => $message );
868 + return;
869 + }
870 + }
871 +
872 + if ( $reg_action != 'require_admin_review' ) {
873 +
874 + $user_data = get_userdata( $user_id );
875 + $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
876 + <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
877 + <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
878 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
879 + <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
880 +
881 + $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
882 +
883 + $email_vars = array(
884 + 'user_id' => $user_id,
885 + 'extras' => $extras,
886 + 'form_fields' => $form_fields,
887 + );
888 +
889 + UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
890 +
891 + }
892 +
893 + if ( $reg_action == 'auto_approve_login' ) {
894 + $res = wp_signon(
895 + array(
896 + 'user_login' => $user_login,
897 + 'user_password' => $password,
898 + 'remember' => false,
899 + )
900 + );
901 +
902 + if ( is_wp_error( $res ) ) {
903 + $message = aui()->alert(
904 + array(
905 + 'type' => 'error',
906 + 'content' => $res->get_error_message(),
907 + )
908 + );
909 +
910 + if ( wp_doing_ajax() ) {
911 + wp_send_json_error( array( 'message' => $message ) );
912 + } else {
913 + $uwp_notices[] = array( 'register' => $message );
914 + }
915 + } else {
916 + $redirect_to = $this->get_register_redirect_url( $data, $user_id );
917 + do_action( 'uwp_after_process_register', $result, $user_id );
918 +
919 + if ( wp_doing_ajax() ) {
920 + $message = aui()->alert(
921 + array(
922 + 'type' => 'success',
923 + 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
924 + )
925 + );
926 + $response = array(
927 + 'message' => $message,
928 + 'redirect' => $redirect_to,
929 + );
930 + wp_send_json_success( $response );
931 + } else {
932 + wp_safe_redirect( $redirect_to );
933 + }
934 + exit();
935 + }
936 + } else {
937 + if ( $reg_action == 'require_email_activation' ) {
938 + $resend_link = uwp_get_register_page_url();
939 + $resend_link = add_query_arg(
940 + array(
941 + 'user_id' => $user_id,
942 + 'action' => 'uwp_resend',
943 + '_nonce' => wp_create_nonce( 'uwp_resend' ),
944 + ),
945 + $resend_link
946 + );
947 +
948 + $message = aui()->alert(
949 + array(
950 + 'type' => 'success',
951 + 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
952 + )
953 + );
954 +
955 + } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
956 +
957 + update_user_meta( $user_id, 'uwp_mod', '1' );
958 +
959 + do_action( 'uwp_require_admin_review', $user_id, $result );
960 +
961 + $message = aui()->alert(
962 + array(
963 + 'type' => 'success',
964 + 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
965 + )
966 + );
967 + } else {
968 +
969 + $login_page_url = wp_login_url();
970 +
971 + if ( $generated_password ) {
972 + $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
973 + } else {
974 + $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
975 + }
976 +
977 + $message = aui()->alert(
978 + array(
979 + 'type' => 'success',
980 + 'content' => $msg,
981 + )
982 + );
983 + }
984 +
985 + do_action( 'uwp_after_process_register', $result, $user_id );
986 +
987 + if ( wp_doing_ajax() ) {
988 + wp_send_json_success( array( 'message' => $message ) );
989 + } else {
990 + $uwp_notices[] = array( 'register' => $message );
991 + }
992 + }
993 +
994 + if ( wp_doing_ajax() ) {
995 + wp_send_json_error();
996 + } // if we got this far there is a problem
997 + }
998 +
999 + /**
1000 + * Saves UsersWP related user custom fields.
1001 + *
1002 + * @param int $user_id User ID.
1003 + * @param array $data Result array.
1004 + * @param string $type Form type.
1005 + *
1006 + * @return bool True when success. False when failure.
1007 + * @since 1.0.0
1008 + * @package userswp
1009 + *
1010 + */
1011 + public function save_user_extra_fields( $user_id, $data, $type ) {
1012 +
1013 + if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1014 + return false;
1015 + }
1016 +
1017 + // custom user fields not applicable for login and forgot
1018 + if ( $type == 'login' || $type == 'forgot' ) {
1019 + return true;
1020 + }
1021 +
1022 + if ( $type == 'account' || $type == 'register' ) {
1023 + if ( isset( $data['password'] ) ) {
1024 + unset( $data['password'] );
1025 + }
1026 + }
1027 +
1028 + if ( $type == 'register' ) {
1029 + if ( isset( $data['username'] ) ) {
1030 + unset( $data['username'] );
1031 + }
1032 + if ( isset( $data['email'] ) ) {
1033 + unset( $data['email'] );
1034 + }
1035 + }
1036 +
1037 + if ( empty( $data ) ) {
1038 + // no extra fields. so just return
1039 + return true;
1040 + } else {
1041 + foreach ( $data as $key => $value ) {
1042 + if ( 'uwp_language' == $key ) {
1043 + update_user_meta( $user_id, 'locale', $value );
1044 + }
1045 + uwp_update_usermeta( $user_id, $key, $value );
1046 + }
1047 +
1048 + return true;
1049 + }
1050 + }
1051 +
1052 + public function get_register_redirect_url( $data, $user ) {
1053 + if ( is_int( $user ) ) {
1054 + $user = get_userdata( $user );
1055 + }
1056 +
1057 + $redirect_page_id = $custom_url = '';
1058 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1059 + $form_id = (int) $data['uwp_register_form_id'];
1060 + $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1061 + $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1062 + }
1063 +
1064 + if ( ! $redirect_page_id ) {
1065 + $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1066 + $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1067 + }
1068 +
1069 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1070 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1071 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1072 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1073 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1074 + if ( uwp_is_wpml() ) {
1075 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1076 + if ( ! empty( $wpml_page_id ) ) {
1077 + $redirect_page_id = $wpml_page_id;
1078 + }
1079 + }
1080 + $redirect_to = get_permalink( $redirect_page_id );
1081 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1082 + $redirect_to = esc_url( wp_get_referer() );
1083 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1084 + $redirect_to = $custom_url;
1085 + } else {
1086 + if ( $user && $user->has_cap( 'manage_options' ) ) {
1087 + $redirect_to = admin_url();
1088 + } else {
1089 + $redirect_to = home_url( '/' );
1090 + }
1091 +
1092 + $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1093 + }
1094 +
1095 + return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1096 + }
1097 +
1098 + /**
1099 + * Processes login form submission.
1100 + *
1101 + * @since 1.0.0
1102 + * @package userswp
1103 + *
1104 + */
1105 + public function process_login() {
1106 +
1107 + $data = $_POST;
1108 +
1109 + if ( ! isset( $data['uwp_login_nonce'] ) ) {
1110 + return;
1111 + }
1112 +
1113 + if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1114 + $message = aui()->alert(
1115 + array(
1116 + 'type' => 'error',
1117 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1118 + )
1119 + );
1120 + if ( wp_doing_ajax() ) {
1121 + wp_send_json_error( array( 'message' => $message ) );
1122 + } else {
1123 + return;
1124 + }
1125 + }
1126 +
1127 + global $uwp_notices;
1128 +
1129 + do_action( 'uwp_before_validate', 'login' );
1130 +
1131 + $result = uwp_validate_fields( $data, 'login' );
1132 +
1133 + $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1134 +
1135 + if ( is_wp_error( $result ) ) {
1136 + $message = aui()->alert(
1137 + array(
1138 + 'type' => 'error',
1139 + 'content' => $result->get_error_message(),
1140 + )
1141 + );
1142 + if ( wp_doing_ajax() ) {
1143 + wp_send_json_error( array( 'message' => $message ) );
1144 + } else {
1145 + $uwp_notices[] = array( 'login' => $message );
1146 +
1147 + return;
1148 + }
1149 + }
1150 +
1151 + do_action( 'uwp_after_validate', $result, 'login', $data );
1152 +
1153 + if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1154 + $remember_me = true;
1155 + } else {
1156 + $remember_me = false;
1157 + }
1158 +
1159 + remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1160 +
1161 + global $wp2fa;
1162 + if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1163 + remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1164 + }
1165 +
1166 + $user = wp_signon(
1167 + array(
1168 + 'user_login' => $result['username'],
1169 + 'user_password' => $result['password'],
1170 + 'remember' => $remember_me,
1171 + )
1172 + );
1173 +
1174 + add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1175 +
1176 + if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177 +
1178 + $two_fa = $this->check_2fa( $user );
1179 + if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1180 + if ( is_wp_error( $two_fa ) ) {
1181 + $message = aui()->alert(
1182 + array(
1183 + 'type' => 'error',
1184 + 'content' => $two_fa->get_error_message(),
1185 + )
1186 + );
1187 + wp_send_json_error( array( 'message' => $message ) );
1188 + } else {
1189 + wp_send_json_success(
1190 + array(
1191 + 'html' => $two_fa,
1192 + 'is_2fa' => true,
1193 + )
1194 + );
1195 + }
1196 + }
1197 + }
1198 +
1199 + if ( is_wp_error( $user ) ) {
1200 + $message = aui()->alert(
1201 + array(
1202 + 'type' => 'error',
1203 + 'content' => $user->get_error_message(),
1204 + )
1205 + );
1206 + if ( wp_doing_ajax() ) {
1207 + wp_send_json_error( array( 'message' => $message ) );
1208 + } else {
1209 + $uwp_notices[] = array( 'login' => $message );
1210 +
1211 + return;
1212 + }
1213 + } else {
1214 + do_action( 'uwp_after_process_login', $data );
1215 + $message = aui()->alert(
1216 + array(
1217 + 'type' => 'success',
1218 + 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1219 + )
1220 + );
1221 + if ( wp_doing_ajax() ) {
1222 + $redirect_to = '';
1223 + if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1224 + $redirect_to = $this->get_login_redirect_url( $data, $user );
355 1225 }
356 - }
1226 + wp_send_json_success(
1227 + array(
1228 + 'message' => $message,
1229 + 'redirect' => $redirect_to,
1230 + )
1231 + );
1232 + } else {
1233 + $redirect_to = $this->get_login_redirect_url( $data, $user );
1234 + wp_safe_redirect( $redirect_to );
1235 + exit();
1236 + }
1237 +}
1238 + }
357 1239
358 - }
1240 + public function check_2fa( $user ) {
1241 + if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1242 + return;
1243 + }
359 1244
1245 + if ( ! $user ) {
1246 + $user = wp_get_current_user();
1247 + }
360 1248
361 - $error_code = $errors->get_error_code();
362 - if (!empty($error_code)) {
363 - return $errors;
364 - }
1249 + global $wp2fa;
1250 + $errors = new WP_Error();
365 1251
366 - if ($reg_action == 'auto_approve_login') {
367 - $res = wp_signon(
1252 + if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1253 + return;
1254 + }
1255 + // Invalidate the current login session to prevent from being re-used.
1256 + \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1257 +
1258 + // Also clear the cookies which are no longer valid.
1259 + wp_clear_auth_cookie();
1260 +
1261 + $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1262 + if ( ! $login_nonce ) {
1263 + $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1264 +
1265 + return $errors;
1266 + }
1267 +
1268 + $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1269 +
1270 + ob_start();
1271 + ?>
1272 +
1273 + <div class="uwp-2fa-methods-wrap">
1274 + <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1275 + autocomplete="off">
1276 + <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1277 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1278 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1279 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1280 + <?php
1281 +
1282 + // Check to see what provider is set and give the relevant authentication page.
1283 + if ( 'totp' === $provider ) {
1284 + ?>
1285 + <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1286 + <?php
1287 +
1288 + echo aui()->input(
1289 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1290 + 'type' => 'tel',
1291 + 'id' => 'authcode',
1292 + 'name' => 'authcode',
1293 + 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1294 + 'value' => '',
1295 + 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1296 + )
1297 + );
1298 +
1299 + echo aui()->button(
1300 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1301 + 'type' => 'submit',
1302 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1303 + 'name' => 'submit',
1304 + 'icon' => '',
1305 + 'content' => esc_html__( 'Log In', 'userswp' ),
1306 + )
1307 + );
1308 +
1309 + } elseif ( 'email' === $provider ) {
1310 + $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1311 + if ( empty( $has_token ) || ! $has_token ) {
1312 + \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1313 + }
1314 + ?>
1315 + <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1316 + <?php
1317 + echo aui()->input(
1318 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1319 + 'type' => 'tel',
1320 + 'id' => 'authcode',
1321 + 'name' => 'wp-2fa-email-code',
1322 + 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1323 + 'value' => '',
1324 + 'label' => esc_html__( 'Verification Code', 'userswp' ),
1325 + 'extra_attributes' => array(
1326 + 'size' => 20,
1327 + 'pattern' => '[0-9]*',
1328 + ),
1329 + )
1330 + );
1331 +
1332 + echo aui()->button(
1333 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1334 + 'type' => 'submit',
1335 + 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1336 + 'name' => 'submit',
1337 + 'icon' => '',
1338 + 'content' => esc_html__( 'Log In', 'userswp' ),
1339 + )
1340 + );
1341 +
1342 + echo aui()->button(
1343 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1344 + 'type' => 'button',
1345 + 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1346 + 'name' => 'wp-2fa-email-code-resend',
1347 + 'icon' => '',
1348 + 'content' => esc_html__( 'Resend Code', 'userswp' ),
1349 + )
1350 + );
1351 +
1352 + }
1353 + ?>
1354 + </form>
1355 + </div>
1356 +
1357 + <?php
1358 + $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1359 + if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1360 + ?>
1361 + <div class="uwp-2fa-methods-wrap" style="display:none;">
1362 + <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1363 + class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1364 + <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1365 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1366 + value="<?php echo esc_attr( $user->ID ); ?>"/>
1367 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1368 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1369 + <div class="uwp-backup-fields">
1370 + <?php
1371 + echo aui()->input(
1372 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1373 + 'type' => 'tel',
1374 + 'id' => 'authcode',
1375 + 'name' => 'wp-2fa-backup-code',
1376 + 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1377 + 'value' => '',
1378 + 'label' => esc_html__( 'Backup Code', 'userswp' ),
1379 + 'extra_attributes' => array(
1380 + 'size' => 20,
1381 + 'pattern' => '[0-9]*',
1382 + ),
1383 + )
1384 + );
1385 +
1386 + echo aui()->button(
1387 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1388 + 'type' => 'submit',
1389 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1390 + 'name' => 'submit',
1391 + 'icon' => '',
1392 + 'content' => esc_html__( 'Log In', 'userswp' ),
1393 + )
1394 + );
1395 + ?>
1396 + </div>
1397 + </form>
1398 + </div>
1399 + <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1400 + <script type="text/javascript">
1401 + jQuery('.uwp-switch-2fa-methods').on('click',
1402 + function (e) {
1403 + e.preventDefault();
1404 + jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1405 + jQuery('.uwp-2fa-methods-wrap').toggle();
1406 + return false;
1407 + }
1408 + );
1409 + </script>
1410 + <?php
1411 + }
1412 +
1413 + return ob_get_clean();
1414 + }
1415 +
1416 + public function process_login_2fa() {
1417 + if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1418 + return;
1419 + }
1420 +
1421 + $auth_id = (int) $_POST['uwp-auth-id'];
1422 + $user = get_userdata( $auth_id );
1423 + if ( ! $user ) {
1424 + $message = aui()->alert(
368 1425 array(
369 - 'user_login' => $result['uwp_account_username'],
370 - 'user_password' => $password,
371 - 'remember' => false
1426 + 'type' => 'error',
1427 + 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
372 1428 )
373 - );
1429 + );
374 1430
375 - if (is_wp_error($res)) {
376 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
377 - return $errors;
378 - } else {
379 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
380 - if (empty($reg_redirect_page_id)) {
381 - $reg_redirect_to = home_url('/');
382 - } else {
383 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
384 - }
385 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
386 - wp_redirect($redirect);
387 - exit();
388 - }
389 - } else {
390 - if ($reg_action == 'require_email_activation') {
391 - return __('An email has been sent to your registered email address. Please click the activation link to proceed.', 'userswp');
392 - } elseif ($reg_action == 'require_admin_review' && defined('UWP_MOD_VERSION')) {
393 - update_user_meta( $user_id, 'uwp_mod', '1' );
1431 + wp_send_json_error( array( 'message' => $message ) );
1432 + }
394 1433
395 - $email = new UsersWP_Mails();
396 - $send_result = $email->send( 'mod_pending', $user_id );
397 - $user_data = get_user_by('id', $user_id);
398 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
399 - if (is_wp_error($send_result)) {
400 - return $send_result;
401 - }
1434 + global $wp2fa;
402 1435
403 - $admin_send_result = $email->send_admin_email('mod_admin', $user_id);
404 - if (is_wp_error($admin_send_result)) {
405 - return $admin_send_result;
406 - }
407 -
408 - return __('Your account is under moderation. We will email you once its approved.', 'userswp');
409 - } else {
410 - $login_page = uwp_get_option('login_page', false);
411 - if ($login_page) {
412 - $login_page_url = get_permalink($login_page);
413 - } else {
414 - $login_page_url = wp_login_url();
415 - }
416 - if ($generated_password) {
417 - return sprintf(__('Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login <a href="%s">here</a>.', 'userswp'), $login_page_url);
418 - } else {
419 - return sprintf(__('Account registered successfully. Please login <a href="%s">here</a>', 'userswp'), $login_page_url);
420 - }
421 - }
422 - }
1436 + $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1437 + if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
423 1438
1439 + $message = aui()->alert(
1440 + array(
1441 + 'type' => 'error',
1442 + 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1443 + )
1444 + );
424 1445
425 - }
1446 + wp_send_json_error( array( 'message' => $message ) );
1447 + }
426 1448
427 - /**
428 - * Processes login form submission.
429 - *
430 - * @since 1.0.0
431 - * @package userswp
432 - *
433 - * @param array $data Submitted $_POST data
434 - *
435 - * @return bool|WP_Error|string
436 - */
437 - public function process_login($data) {
1449 + if ( isset( $_POST['provider'] ) ) {
1450 + $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1451 + $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1452 + if ( isset( $providers[ $provider ] ) ) {
1453 + $provider = $providers[ $provider ];
1454 + } elseif ( isset( $provider ) ) {
1455 + $provider = $provider;
1456 + } else {
1457 + $provider = $provider;
1458 + }
1459 + }
438 1460
439 - $errors = new WP_Error();
1461 + // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1462 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
440 1463
441 - if( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
442 - return false;
443 - }
1464 + }
444 1465
445 - do_action('uwp_before_validate', 'login');
1466 + // Validate TOTP.
1467 + if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
446 1468
447 - $result = uwp_validate_fields($data, 'login');
1469 + do_action( 'wp_login_failed', $user->user_login );
448 1470
449 - $result = apply_filters('uwp_validate_result', $result, 'login');
1471 + $message = aui()->alert(
1472 + array(
1473 + 'type' => 'error',
1474 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1475 + )
1476 + );
450 1477
451 - if (is_wp_error($result)) {
452 - return $result;
453 - }
1478 + wp_send_json_error( array( 'message' => $message ) );
1479 + }
454 1480
455 - do_action('uwp_after_validate', 'login');
1481 + // Validate Email.
1482 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
456 1483
457 - if (isset($data['remember_me']) && $data['remember_me'] == 'forever') {
458 - $remember_me = true;
459 - } else {
460 - $remember_me = false;
461 - }
1484 + do_action( 'wp_login_failed', $user->user_login );
462 1485
463 - $res = wp_signon(
1486 + if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1487 + $message = aui()->alert(
1488 + array(
1489 + 'type' => 'info',
1490 + 'content' => __( 'A new code has been sent.', 'userswp' ),
1491 + )
1492 + );
1493 +
1494 + wp_send_json_error( array( 'message' => $message ) );
1495 + } else {
1496 + $message = aui()->alert(
1497 + array(
1498 + 'type' => 'error',
1499 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1500 + )
1501 + );
1502 +
1503 + wp_send_json_error( array( 'message' => $message ) );
1504 + }
1505 + }
1506 +
1507 + // Backup Codes.
1508 + if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1509 +
1510 + do_action( 'wp_login_failed', $user->user_login );
1511 +
1512 + $message = aui()->alert(
1513 + array(
1514 + 'type' => 'error',
1515 + 'content' => __( 'Invalid backup code.', 'userswp' ),
1516 + )
1517 + );
1518 +
1519 + wp_send_json_error( array( 'message' => $message ) );
1520 + }
1521 +
1522 + \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1523 +
1524 + $rememberme = false;
1525 + $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1526 + if ( ! empty( $remember ) ) {
1527 + $rememberme = true;
1528 + }
1529 +
1530 + wp_set_auth_cookie( $user->ID, $rememberme );
1531 +
1532 + do_action( 'two_factor_user_authenticated', $user );
1533 +
1534 + $message = aui()->alert(
464 1535 array(
465 - 'user_login' => $result['uwp_login_username'],
466 - 'user_password' => $result['password'],
467 - 'remember' => $remember_me
1536 + 'type' => 'success',
1537 + 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
468 1538 )
469 - );
1539 + );
470 1540
471 - if (is_wp_error($res)) {
472 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
473 - return $errors;
474 - } else {
475 - $redirect_page_id = uwp_get_option('login_redirect_to', '');
476 - if (empty($redirect_page_id)) {
477 - if ( current_user_can('manage_options') ) {
478 - $redirect_to = admin_url();
479 - } else {
480 - $redirect_to = home_url('/');
481 - }
482 - } else {
483 - $redirect_to = get_permalink($redirect_page_id);
484 - }
1541 + wp_send_json_success( array( 'message' => $message ) );
1542 + }
485 1543
486 - if (isset($data['redirect_to'])) {
487 - $redirect_to = strip_tags(esc_sql($data['redirect_to']));
488 - }
1544 + public function get_login_redirect_url( $data, $user ) {
1545 + if ( is_int( $user ) ) {
1546 + $user = get_userdata( $user );
1547 + }
489 1548
490 - $redirect_to = apply_filters('uwp_login_redirect', $redirect_to);
491 - wp_redirect($redirect_to);
492 - exit();
493 - }
494 - }
1549 + $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1550 + $custom_url = uwp_get_option( 'login_redirect_custom_url' );
495 1551
496 - /**
497 - * Processes forgot password form submission.
498 - *
499 - * @since 1.0.0
500 - * @package userswp
501 - *
502 - * @param array $data Submitted $_POST data
503 - *
504 - * @return bool|WP_Error|string
505 - */
506 - public function process_forgot($data) {
1552 + if ( $user && isset( $user->roles[0] ) ) {
1553 + $user_role = $user->roles[0];
1554 + $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1555 + $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1556 + }
507 1557
508 - $errors = new WP_Error();
1558 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1559 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1560 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1561 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1562 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1563 + if ( uwp_is_wpml() ) {
1564 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1565 + if ( ! empty( $wpml_page_id ) ) {
1566 + $redirect_page_id = $wpml_page_id;
1567 + }
1568 + }
1569 + $redirect_to = get_permalink( $redirect_page_id );
1570 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1571 + $redirect_to = esc_url( wp_get_referer() );
1572 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1573 + $redirect_to = $custom_url;
1574 + } else {
1575 + $redirect_to = home_url( '/' );
1576 + $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1577 + }
509 1578
510 - if( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
511 - return false;
512 - }
1579 + return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1580 + }
513 1581
514 - do_action('uwp_before_validate', 'forgot');
1582 + /**
1583 + * Processes forgot password form submission.
1584 + *
1585 + * @since 1.0.0
1586 + * @package userswp
1587 + *
1588 + */
1589 + public function process_forgot() {
515 1590
516 - $result = uwp_validate_fields($data, 'forgot');
1591 + $data = $_POST;
517 1592
518 - $result = apply_filters('uwp_validate_result', $result, 'forgot');
1593 + if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1594 + return;
1595 + }
519 1596
520 - if (is_wp_error($result)) {
521 - return $result;
522 - }
1597 + if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1598 + $message = aui()->alert(
1599 + array(
1600 + 'type' => 'error',
1601 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1602 + )
1603 + );
1604 + if ( wp_doing_ajax() ) {
1605 + wp_send_json_error( $message );
1606 + } else {
1607 + return;
1608 + }
1609 + }
523 1610
524 - do_action('uwp_after_validate', 'forgot');
1611 + global $uwp_notices;
525 1612
1613 + do_action( 'uwp_before_validate', 'forgot' );
526 1614
527 - $user_data = get_user_by('email', $data['uwp_forgot_email']);
1615 + $result = uwp_validate_fields( $data, 'forgot' );
528 1616
529 - // make sure user account is active before account reset
530 - $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
531 - if ($mod_value == 'email_unconfirmed') {
532 - $errors->add('activate_account', __('<strong>Error</strong>: Your account is not activated yet. Please activate your account first.', 'userswp'));
533 - }
1617 + $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
534 1618
535 - $error_code = $errors->get_error_code();
536 - if (!empty($error_code)) {
537 - return $errors;
538 - }
539 -
540 - $email = new UsersWP_Mails();
541 - $send_result = $email->send( 'forgot', $user_data->ID );
542 -
543 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
544 - if (is_wp_error($send_result)) {
545 - return $send_result;
546 - }
1619 + if ( is_wp_error( $result ) ) {
1620 + $message = aui()->alert(
1621 + array(
1622 + 'type' => 'error',
1623 + 'content' => $result->get_error_message(),
1624 + )
1625 + );
1626 + if ( wp_doing_ajax() ) {
1627 + wp_send_json_error( $message );
1628 + } else {
1629 + $uwp_notices[] = array( 'forgot' => $message );
547 1630
548 - return true;
549 - }
1631 + return;
1632 + }
1633 + }
550 1634
551 - /**
552 - * Processes change password form submission.
553 - *
554 - * @since 1.0.0
555 - * @package userswp
556 - *
557 - * @param array $data Submitted $_POST data
558 - *
559 - * @return bool|WP_Error|string
560 - */
561 - public function process_change($data) {
1635 + do_action( 'uwp_after_validate', $result, 'forgot', $data );
562 1636
563 - $errors = new WP_Error();
1637 + $user_data = get_user_by( 'email', $data['email'] );
564 1638
565 - if( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
566 - return false;
567 - }
1639 + // if no user we fake it and bail
1640 + if ( ! $user_data ) {
1641 + $args = apply_filters(
1642 + 'uwp_forgot_error_message',
1643 + array(
1644 + 'type' => 'error',
1645 + 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1646 + )
1647 + );
568 1648
569 - do_action('uwp_before_validate', 'change');
1649 + $message = aui()->alert( $args );
1650 + if ( wp_doing_ajax() ) {
1651 + wp_send_json_success( $message );
1652 + } else {
1653 + $uwp_notices[] = array( 'forgot' => $message );
570 1654
571 - $result = uwp_validate_fields($data, 'change');
1655 + return;
1656 + }
1657 + }
572 1658
573 - $result = apply_filters('uwp_validate_result', $result, 'change');
1659 + // make sure user account is active before account reset
1660 + $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1661 + if ( $mod_value == 'email_unconfirmed' ) {
1662 + $message = aui()->alert(
1663 + array(
1664 + 'type' => 'error',
1665 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1666 + )
1667 + );
1668 + if ( wp_doing_ajax() ) {
1669 + wp_send_json_error( $message );
1670 + } else {
1671 + $uwp_notices[] = array( 'forgot' => $message );
574 1672
575 - if (is_wp_error($result)) {
576 - return $result;
577 - }
1673 + return;
1674 + }
1675 + }
578 1676
579 - do_action('uwp_after_validate', 'change');
1677 + $user_data = get_userdata( $user_data->ID );
580 1678
581 - $user_data = get_user_by('id', get_current_user_id());
1679 + $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
582 1680
583 - if (is_wp_error($user_data)) {
584 - return $user_data;
585 - }
1681 + if ( ! $allow ) {
1682 + return false;
1683 + } elseif ( is_wp_error( $allow ) ) {
1684 + return false;
1685 + }
586 1686
587 - $email = new UsersWP_Mails();
588 - $send_result = $email->send( 'change', $user_data->ID );
1687 + $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
589 1688
590 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
591 - if (is_wp_error($send_result)) {
592 - return $send_result;
593 - }
1689 + global $wpdb, $wp_hasher;
1690 + $reset_link = '';
594 1691
595 - wp_set_password( $data['uwp_change_password'], $user_data->ID );
596 - wp_set_auth_cookie( $user_data->ID, false);
1692 + if ( $as_password ) {
1693 + $new_pass = wp_generate_password( 12, false );
1694 + wp_set_password( $new_pass, $user_data->ID );
1695 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
1696 + update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
1697 + }
1698 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
1699 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1700 + $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
597 1701
598 - return true;
599 - }
1702 + } else {
1703 + $key = wp_generate_password( 20, false );
1704 + do_action( 'retrieve_password_key', $user_data->user_login, $key );
600 1705
601 - /**
602 - * Processes reset password form submission.
603 - *
604 - * @since 1.0.0
605 - * @package userswp
606 - *
607 - * @param array $data Submitted $_POST data
608 - *
609 - * @return bool|WP_Error|string
610 - */
611 - public function process_reset($data) {
1706 + if ( empty( $wp_hasher ) ) {
1707 + require_once ABSPATH . 'wp-includes/class-phpass.php';
1708 + $wp_hasher = new PasswordHash( 8, true );
1709 + }
1710 + $hashed = $wp_hasher->HashPassword( $key );
1711 + $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1712 + $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1713 + $message .= home_url( '/' ) . '</p>';
1714 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1715 + $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
1716 + $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
1717 + $reset_page = uwp_get_page_id( 'reset_page', false );
1718 + if ( $reset_page ) {
1719 + $reset_link = add_query_arg(
1720 + array(
1721 + 'key' => $key,
1722 + 'login' => rawurlencode( $user_data->user_login ),
1723 + ),
1724 + get_permalink( $reset_page )
1725 + );
1726 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1727 + } else {
1728 + $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
1729 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1730 + }
1731 + $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
1732 + }
612 1733
613 - $errors = new WP_Error();
1734 + $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
614 1735
615 - if( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
616 - return false;
617 - }
1736 + $email_vars = array(
1737 + 'user_id' => $user_data->ID,
1738 + 'login_details' => $message,
1739 + 'reset_link' => $reset_link,
1740 + );
618 1741
619 - do_action('uwp_before_validate', 'reset');
1742 + UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
620 1743
621 - $result = uwp_validate_fields($data, 'reset');
1744 + do_action( 'uwp_after_process_forgot', $data );
622 1745
623 - $result = apply_filters('uwp_validate_result', $result, 'reset');
1746 + $message = aui()->alert(
1747 + array(
1748 + 'type' => 'success',
1749 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
1750 + )
1751 + );
1752 + if ( wp_doing_ajax() ) {
1753 + wp_send_json_success( $message );
1754 + } else {
1755 + $uwp_notices[] = array( 'forgot' => $message );
1756 + }
1757 + }
624 1758
625 - if (is_wp_error($result)) {
626 - return $result;
627 - }
1759 + /**
1760 + * Processes change password form submission.
1761 + *
1762 + * @since 1.0.0
1763 + * @package userswp
1764 + *
1765 + */
1766 + public function process_change() {
628 1767
629 - do_action('uwp_after_validate', 'reset');
1768 + $data = $_POST;
630 1769
631 - $login = $data['uwp_reset_username'];
632 - $key = $data['uwp_reset_key'];
633 - $user_data = check_password_reset_key( $key, $login );
1770 + if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
1771 + return;
1772 + }
634 1773
635 - if (is_wp_error($user_data)) {
636 - return $user_data;
637 - }
1774 + global $uwp_notices;
638 1775
639 - $email = new UsersWP_Mails();
640 - $send_result = $email->send( 'reset', $user_data->ID );
1776 + if ( is_uwp_account_page() ) {
1777 + $notice_type = 'account';
1778 + } else {
1779 + $notice_type = 'change';
1780 + }
641 1781
642 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
643 - if (is_wp_error($send_result)) {
644 - return $send_result;
645 - }
1782 + do_action( 'uwp_before_validate', 'change' );
646 1783
647 - wp_set_password( $data['uwp_reset_password'], $user_data->ID );
1784 + $result = uwp_validate_fields( $data, 'change' );
648 1785
649 - return true;
650 - }
1786 + $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
651 1787
652 -
653 - /**
654 - * Modifies the mail subject based on the admin notification type.
655 - *
656 - * @since 1.0.0
657 - * @package userswp
658 - * @subpackage userswp/includes
659 - * @param string $subject Unmodified mail subject.
660 - * @param string $type Notification type.
661 - * @return string Modified mail subject.
662 - */
663 - public function init_mail_subject($subject, $type) {
664 - switch ($type) {
665 - case "register":
666 - $subject = uwp_get_option('registration_success_email_subject', '');
667 - break;
668 - case "activate":
669 - $subject = uwp_get_option('registration_activate_email_subject', '');
670 - break;
671 - case "forgot":
672 - $subject = uwp_get_option('forgot_password_email_subject', '');
673 - break;
674 - case "reset":
675 - $subject = uwp_get_option('reset_password_email_subject', '');
676 - break;
677 - case "change":
678 - $subject = uwp_get_option('change_password_email_subject', '');
679 - break;
680 - case "account":
681 - $subject = uwp_get_option('account_update_email_subject', '');
682 - break;
683 - }
684 - return $subject;
685 - }
1788 + if ( is_wp_error( $result ) ) {
1789 + $message = aui()->alert(
1790 + array(
1791 + 'type' => 'error',
1792 + 'content' => $result->get_error_message(),
1793 + )
1794 + );
1795 + $uwp_notices[] = array( $notice_type => $message );
686 1796
687 - /**
688 - * Modifies the mail content based on the admin notification type.
689 - *
690 - * @since 1.0.0
691 - * @package userswp
692 - * @subpackage userswp/includes
693 - * @param string $content Unmodified mail content.
694 - * @param string $type Notification type.
695 - * @return string Modified mail content.
696 - */
697 - public function init_mail_content($content, $type) {
698 - switch ($type) {
699 - case "register":
700 - $content = uwp_get_option('registration_success_email_content', '');
701 - break;
702 - case "activate":
703 - $content = uwp_get_option('registration_activate_email_content', '');
704 - break;
705 - case "forgot":
706 - $content = uwp_get_option('forgot_password_email_content', '');
707 - break;
708 - case "reset":
709 - $content = uwp_get_option('reset_password_email_content', '');
710 - break;
711 - case "change":
712 - $content = uwp_get_option('change_password_email_content', '');
713 - break;
714 - case "account":
715 - $content = uwp_get_option('account_update_email_content', '');
716 - break;
717 - }
718 - return $content;
719 - }
1797 + return;
1798 + }
720 1799
721 - /**
722 - * Modifies the mail extras based on the notification type.
723 - *
724 - * @since 1.0.0
725 - * @package userswp
726 - * @subpackage userswp/includes
727 - * @param string $extras Unmodified mail extras.
728 - * @param string $type Notification type.
729 - * @return string Modified mail extras.
730 - */
731 - public function init_mail_extras($extras, $type, $user_id) {
732 - switch ($type) {
733 - case "activate":
734 - $extras = $this->generate_activate_message($user_id);
735 - break;
736 - case "register":
737 - $extras = $this->generate_register_message($user_id);
738 - break;
739 - case "forgot":
740 - $extras = $this->generate_forgot_message($user_id);
741 - }
742 - return $extras;
743 - }
744 -
745 - /**
746 - * Modifies the admin mail subject based on the admin notification type.
747 - *
748 - * @since 1.0.0
749 - * @package userswp
750 - * @subpackage userswp/includes
751 - * @param string $subject Unmodified admin mail subject.
752 - * @param string $type Admin notification type.
753 - * @return string Modified admin mail subject.
754 - */
755 - public function init_admin_mail_subject($subject, $type) {
756 - switch ($type) {
757 - case "register_admin":
758 - $subject = uwp_get_option('registration_success_email_subject_admin', '');
759 - break;
760 - }
761 - return $subject;
762 - }
1800 + do_action( 'uwp_after_validate', $result, 'change', $data );
763 1801
764 - /**
765 - * Modifies the admin mail content based on the admin notification type.
766 - *
767 - * @since 1.0.0
768 - * @package userswp
769 - * @subpackage userswp/includes
770 - * @param string $content Unmodified admin mail content.
771 - * @param string $type Admin notification type.
772 - * @return string Modified admin mail content.
773 - */
774 - public function init_admin_mail_content($content, $type) {
775 - switch ($type) {
776 - case "register_admin":
777 - $content = uwp_get_option('registration_success_email_content_admin', '');
778 - break;
779 - }
780 - return $content;
781 - }
1802 + $user_data = get_user_by( 'id', get_current_user_id() );
782 1803
783 - /**
784 - * Modifies the admin mail extras based on the notification type.
785 - *
786 - * @since 1.0.0
787 - * @package userswp
788 - * @subpackage userswp/includes
789 - * @param string $extras Unmodified mail extras.
790 - * @param string $type Notification type.
791 - * @return string Modified mail extras.
792 - */
793 - public function init_admin_mail_extras($extras, $type, $user_id) {
794 - switch ($type) {
795 - case "register_admin":
796 - $user_data = get_userdata($user_id);
797 - $extras = __('<p><b>' . __('User Information :', 'userswp') . '</b></p>
798 - <p>' . __('First Name:', 'userswp') . ' ' . $user_data->first_name . '</p>
799 - <p>' . __('Last Name:', 'userswp') . ' ' . $user_data->last_name . '</p>
800 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
801 - <p>' . __('Email:', 'userswp') . ' ' . $user_data->user_email . '</p>');
802 - break;
803 - }
804 - return $extras;
805 - }
1804 + if ( ! $user_data ) {
1805 + $message = aui()->alert(
1806 + array(
1807 + 'type' => 'error',
1808 + 'content' => $user_data->get_error_message(),
1809 + )
1810 + );
1811 + $uwp_notices[] = array( $notice_type => $message );
806 1812
807 - /**
808 - * Generates activate email message.
809 - *
810 - * @since 1.0.0
811 - * @package userswp
812 - *
813 - * @param int $user_id User ID.
814 - *
815 - * @return bool|string Message.
816 - */
817 - public function generate_activate_message($user_id) {
1813 + return;
1814 + }
818 1815
819 - $user_data = get_userdata($user_id);
820 - global $wpdb;
821 - $key = wp_generate_password( 20, false );
822 - do_action( 'uwp_activation_key', $user_data->user_login, $key );
1816 + $email_vars = array(
1817 + 'user_id' => $user_data->ID,
1818 + );
823 1819
824 - global $wp_hasher;
825 - if ( empty( $wp_hasher ) ) {
826 - require_once ABSPATH . 'wp-includes/class-phpass.php';
827 - $wp_hasher = new PasswordHash( 8, true );
828 - }
829 - $hashed = $wp_hasher->HashPassword( $key );
830 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
831 - update_user_meta( $user_id, 'uwp_mod', 'email_unconfirmed' );
832 - $message = __('To activate your account, visit the following address:', 'userswp') . "\r\n\r\n";
833 - $act_url = add_query_arg(
1820 + UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
1821 +
1822 + wp_set_password( $result['password'], $user_data->ID );
1823 +
1824 + $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
1825 + if ( $password_nag ) {
1826 + delete_user_meta( $user_data->ID, 'default_password_nag' );
1827 + }
1828 +
1829 + delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
1830 +
1831 + $message = aui()->alert(
834 1832 array(
835 - 'uwp_activate' => 'yes',
836 - 'key' => $key,
837 - 'login' => $user_data->user_login
838 - ),
839 - site_url()
840 - );
1833 + 'type' => 'success',
1834 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
1835 + )
1836 + );
841 1837
842 - $message .= "<a href='".$act_url."' target='_blank'>".$act_url."</a>" . "\r\n";
1838 + $uwp_notices[] = array( $notice_type => $message );
843 1839
844 - $activate_message = __('<p><b>' . __('Please activate your account :', 'userswp') . '</b></p>
845 - <p>' . $message . '</p>');
1840 + do_action( 'uwp_after_process_change', $data );
846 1841
847 - return $activate_message;
1842 + wp_logout();
1843 + exit();
1844 + }
848 1845
849 - }
1846 + /**
1847 + * Processes reset password form submission.
1848 + *
1849 + * @since 1.0.0
1850 + * @package userswp
1851 + *
1852 + */
1853 + public function process_reset() {
850 1854
851 - /**
852 - * Generates register email message.
853 - *
854 - * @since 1.0.0
855 - * @package userswp
856 - *
857 - * @param int $user_id User ID.
858 - *
859 - * @return bool|string Message.
860 - */
861 - public function generate_register_message($user_id) {
1855 + $data = $_POST;
862 1856
863 - $user_data = get_userdata($user_id);
864 - if(isset($this->generated_password) && !empty($this->generated_password)) {
865 - update_user_meta($user_id, 'default_password_nag', true); //Set up the Password change nag.
866 - $message_pass = $this->generated_password;
867 - $this->generated_password = false;
868 - } else {
869 - $message_pass = __("Password you entered", 'userswp');
870 - }
871 - $message = __('<p><b>' . __('Your login Information :', 'userswp') . '</b></p>
872 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
873 - <p>' . __('Password:', 'userswp') . ' ' . $message_pass . '</p>');
1857 + if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
1858 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
1859 + }
874 1860
875 - return $message;
1861 + if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
1862 + return;
1863 + }
876 1864
877 - }
878 -
879 - /**
880 - * Generates forgot password email message.
881 - *
882 - * @since 1.0.0
883 - * @package userswp
884 - *
885 - * @param int $user_id User ID.
886 - *
887 - * @return bool|string Message.
888 - */
889 - public function generate_forgot_message($user_id) {
1865 + global $uwp_notices;
890 1866
891 - $user_data = get_userdata($user_id);
892 - global $wpdb, $wp_hasher;
1867 + do_action( 'uwp_before_validate', 'reset' );
893 1868
894 - $allow = apply_filters('allow_password_reset', true, $user_data->ID);
895 - if ( ! $allow )
896 - return false;
897 - else if ( is_wp_error($allow) )
898 - return false;
1869 + $result = uwp_validate_fields( $data, 'reset' );
899 1870
900 - $as_password = apply_filters('uwp_forgot_message_as_password', false);
1871 + $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
901 1872
902 - if ($as_password) {
903 - $new_pass = wp_generate_password(12, false);
904 - wp_set_password($new_pass, $user_data->ID);
905 - update_user_meta($user_data->ID, 'default_password_nag', true); //Set up the Password change nag.
906 - $message = '<p><b>' . __('Your login Information :', 'userswp') . '</b></p>';
907 - $message .= '<p>' . sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "</p>";
908 - $message .= '<p>' . sprintf(__('Password: %s', 'userswp'), $new_pass) . "</p>";
1873 + if ( is_wp_error( $result ) ) {
1874 + $message = aui()->alert(
1875 + array(
1876 + 'type' => 'error',
1877 + 'content' => $result->get_error_message(),
1878 + )
1879 + );
1880 + $uwp_notices[] = array( 'reset' => $message );
909 1881
910 - } else {
911 - $key = wp_generate_password( 20, false );
912 - do_action( 'retrieve_password_key', $user_data->user_login, $key );
1882 + return;
1883 + }
913 1884
914 - if ( empty( $wp_hasher ) ) {
915 - require_once ABSPATH . 'wp-includes/class-phpass.php';
916 - $wp_hasher = new PasswordHash( 8, true );
917 - }
918 - $hashed = $wp_hasher->HashPassword( $key );
919 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
920 - $message = __('Someone requested that the password be reset for the following account:', 'userswp') . "\r\n\r\n";
921 - $message .= home_url( '/' ) . "\r\n\r\n";
922 - $message .= sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "\r\n\r\n";
923 - $message .= __('If this was a mistake, just ignore this email and nothing will happen.', 'userswp') . "\r\n\r\n";
924 - $message .= __('To reset your password, visit the following address:', 'userswp') . "\r\n\r\n";
925 - $reset_page = uwp_get_option('reset_page', false);
926 - if ($reset_page) {
927 - $reset_link = add_query_arg( array(
928 - 'key' => $key,
929 - 'login' => rawurlencode($user_data->user_login),
930 - ), get_permalink($reset_page) );
931 - $message .= "<a href='".$reset_link."' target='_blank'>".$reset_link."</a>" . "\r\n";
932 - } else {
933 - $message .= site_url("reset?key=$key&login=" . rawurlencode($user_data->user_login), 'login') . "\r\n";
934 - }
935 - }
1885 + do_action( 'uwp_after_validate', $result, 'reset', $data );
936 1886
1887 + $login = sanitize_text_field( $data['uwp_reset_username'] );
1888 + $key = sanitize_text_field( $data['uwp_reset_key'] );
937 1889
938 - return $message;
1890 + $user = get_user_by( 'login', $login );
1891 + if ( ! $user ) {
1892 + $message = aui()->alert(
1893 + array(
1894 + 'type' => 'error',
1895 + 'content' => __( 'Invalid username.', 'userswp' ),
1896 + )
1897 + );
1898 + $uwp_notices[] = array( 'reset' => $message );
939 1899
940 - }
1900 + return;
1901 + }
941 1902
942 - /**
943 - * Processes account form submission.
944 - *
945 - * @since 1.0.0
946 - * @package userswp
947 - *
948 - * @param array $data Submitted $_POST data
949 - * @param array $files Submitted $_FILES data
950 - *
951 - * @return bool|WP_Error|string
952 - */
953 - public function process_account($data = array(), $files = array()) {
1903 + clean_user_cache( $user );
954 1904
955 - $file_obj = new UsersWP_Files();
956 -
957 - $current_user_id = get_current_user_id();
958 - if (!$current_user_id) {
959 - return false;
960 - }
1905 + $user_data = check_password_reset_key( $key, $login );
961 1906
962 - $errors = new WP_Error();
1907 + if ( is_wp_error( $user_data ) ) {
1908 + $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
1909 + $message = aui()->alert(
1910 + array(
1911 + 'type' => 'error',
1912 + 'content' => $error,
1913 + )
1914 + );
1915 + $uwp_notices[] = array( 'reset' => $message );
963 1916
964 - if( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
965 - return false;
966 - }
1917 + return;
1918 + }
967 1919
968 - do_action('uwp_before_validate', 'account');
1920 + $email_vars = array(
1921 + 'user_id' => $user_data->ID,
1922 + );
969 1923
970 - $result = uwp_validate_fields($data, 'account');
1924 + UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
971 1925
972 - $result = apply_filters('uwp_validate_result', $result, 'account');
1926 + wp_set_password( $data['password'], $user_data->ID );
973 1927
974 - if (is_wp_error($result)) {
975 - return $result;
976 - }
1928 + $login_page_url = uwp_get_login_page_url();
1929 + $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
1930 + $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
1931 + $message = aui()->alert(
1932 + array(
1933 + 'type' => 'success',
1934 + 'content' => $message,
1935 + )
1936 + );
1937 + $uwp_notices[] = array( 'reset' => $message );
977 1938
978 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'account');
1939 + do_action( 'uwp_after_process_reset', $data );
1940 + }
979 1941
980 - if (is_wp_error($uploads_result)) {
981 - return $uploads_result;
982 - }
1942 + /**
1943 + * Processes account form submission.
1944 + *
1945 + * @since 1.0.0
1946 + * @package userswp
1947 + *
1948 + */
1949 + public function process_account() {
983 1950
984 - do_action('uwp_after_validate', 'account');
1951 + $data = wp_unslash( $_POST );
1952 + $files = $_FILES;
985 1953
986 - //unset if value is empty for files
987 - foreach ($uploads_result as $upload_file_key => $upload_file_value) {
988 - if (empty($upload_file_value)) {
989 - unset($uploads_result[$upload_file_key]);
990 - }
991 - }
1954 + if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
1955 + return;
1956 + }
992 1957
993 - $result = array_merge( $result, $uploads_result );
1958 + if ( ! is_user_logged_in() ) {
1959 + return;
1960 + }
994 1961
1962 + global $uwp_notices;
1963 + $file_obj = new UsersWP_Files();
995 1964
996 - $args = array(
997 - 'ID' => $current_user_id
998 - );
1965 + do_action( 'uwp_before_validate', 'account' );
999 1966
1000 - if (isset($result['uwp_account_email'])) {
1001 - $args['user_email'] = $result['uwp_account_email'];
1002 - }
1967 + $result = uwp_validate_fields( $data, 'account' );
1003 1968
1004 - if (isset($result['uwp_account_first_name']) && isset($result['uwp_account_last_name'])) {
1005 - $args['display_name'] = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
1006 - }
1969 + $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
1007 1970
1008 - if (isset($result['uwp_account_first_name'])) {
1009 - $args['first_name'] = $result['uwp_account_first_name'];
1010 - }
1971 + if ( is_wp_error( $result ) ) {
1972 + $message = aui()->alert(
1973 + array(
1974 + 'type' => 'error',
1975 + 'content' => $result->get_error_message(),
1976 + )
1977 + );
1978 + $uwp_notices[] = array( 'account' => $message );
1011 1979
1012 - if (isset($result['uwp_account_last_name'])) {
1013 - $args['last_name'] = $result['uwp_account_last_name'];
1014 - }
1980 + return;
1981 + }
1015 1982
1016 - if (isset($result['uwp_account_bio'])) {
1017 - $args['description'] = $result['uwp_account_bio'];
1018 - }
1983 + $uploads_result = $file_obj->validate_uploads( $files, 'account' );
1019 1984
1020 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
1021 - $args['display_name'] = $result['uwp_account_display_name'];
1022 - }
1985 + if ( is_wp_error( $uploads_result ) ) {
1986 + $message = aui()->alert(
1987 + array(
1988 + 'type' => 'error',
1989 + 'content' => $uploads_result->get_error_message(),
1990 + )
1991 + );
1992 + $uwp_notices[] = array( 'account' => $message );
1023 1993
1024 - if (isset($result['password'])) {
1025 - $args['user_pass'] = $result['password'];
1026 - }
1994 + return;
1995 + }
1027 1996
1028 - $user_id = wp_update_user( $args );
1997 + do_action( 'uwp_after_validate', $result, 'account', $data );
1029 1998
1030 - if (!$user_id) {
1031 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
1032 - return $errors;
1033 - }
1999 + //unset if value is empty for files
2000 + foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2001 + if ( empty( $upload_file_value ) ) {
2002 + unset( $uploads_result[ $upload_file_key ] );
2003 + }
2004 + }
1034 2005
1035 - $res = $this->uwp_save_user_extra_fields($user_id, $result, 'account');
2006 + $result = array_merge( $result, $uploads_result );
1036 2007
1037 - if (!$res) {
1038 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
1039 - }
2008 + $args = array(
2009 + 'ID' => get_current_user_id(),
2010 + );
1040 2011
1041 - $error_code = $errors->get_error_code();
1042 - if (!empty($error_code)) {
1043 - return $errors;
1044 - }
2012 + if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2013 + $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2014 + }
1045 2015
2016 + if ( isset( $result['first_name'] ) ) {
2017 + $args['first_name'] = $result['first_name'];
2018 + }
1046 2019
1047 - if (uwp_get_option('enable_account_update_notification') == '1') {
1048 - $user_data = get_user_by('id', $user_id);
2020 + if ( isset( $result['last_name'] ) ) {
2021 + $args['last_name'] = $result['last_name'];
2022 + }
1049 2023
1050 - $email = new UsersWP_Mails();
1051 - $send_result = $email->send( 'account', $user_data->ID );
2024 + if ( isset( $result['user_url'] ) ) {
2025 + $args['user_url'] = $result['user_url'];
2026 + }
1052 2027
1053 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
1054 - if (is_wp_error($send_result)) {
1055 - return $send_result;
1056 - }
1057 -
1058 - }
1059 -
1060 - return true;
2028 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2029 + $args['display_name'] = $result['display_name'];
2030 + }
1061 2031
1062 - }
2032 + if ( isset( $result['password'] ) ) {
2033 + $args['user_pass'] = $result['password'];
2034 + }
1063 2035
1064 - /**
1065 - * Processes avatar and banner uploads form submission.
1066 - *
1067 - * @since 1.0.0
1068 - * @package userswp
1069 - *
1070 - * @param array $data Submitted $_POST data
1071 - * @param array $files Submitted $_FILES data
1072 - *
1073 - * @return bool|WP_Error|string File url to crop.
1074 - */
1075 - public function process_upload_submit($data = array(), $files = array(), $type = 'avatar') {
2036 + $user_id = wp_update_user( $args );
1076 2037
1077 - $file_obj = new UsersWP_Files();
1078 -
1079 - $current_user_id = get_current_user_id();
1080 - if (!$current_user_id) {
1081 - return false;
1082 - }
2038 + if ( is_wp_error( $user_id ) ) {
2039 + $message = aui()->alert(
2040 + array(
2041 + 'type' => 'error',
2042 + 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2043 + )
2044 + );
2045 + $uwp_notices[] = array( 'account' => $message );
1083 2046
1084 - if( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
1085 - return false;
1086 - }
2047 + return;
2048 + }
1087 2049
1088 - do_action('uwp_before_validate', $type);
2050 + $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
1089 2051
1090 - $result = $file_obj->uwp_validate_uploads($files, $type);
2052 + if ( ! $res ) {
2053 + $message = aui()->alert(
2054 + array(
2055 + 'type' => 'error',
2056 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2057 + )
2058 + );
2059 + $uwp_notices[] = array( 'account' => $message );
1091 2060
1092 - $result = apply_filters('uwp_validate_result', $result, $type);
2061 + return;
2062 + }
1093 2063
1094 - if (is_wp_error($result)) {
1095 - return $result;
1096 - }
2064 + //updating bio field after saving extra fields to reflect the points in mycred add on.
2065 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2066 + $args = array(
2067 + 'ID' => $user_id,
2068 + 'description' => $result['bio'],
2069 + );
2070 + wp_update_user( $args );
2071 + }
1097 2072
1098 - $profile_url = uwp_build_profile_tab_url($current_user_id);
2073 + $user_data = get_userdata( $user_id );
1099 2074
1100 - $url = add_query_arg(
1101 - array(
1102 - 'uwp_crop' => $result['uwp_'.$type.'_file'],
1103 - 'type' => $type
1104 - ),
1105 - $profile_url);
2075 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
1106 2076
1107 - return $url;
2077 + if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
1108 2078
1109 - }
2079 + if ( email_exists( trim( $result['email'] ) ) ) {
2080 + $message = aui()->alert(
2081 + array(
2082 + 'type' => 'error',
2083 + 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2084 + )
2085 + );
1110 2086
1111 - /**
1112 - * Processes avatar and banner uploads image crop.
1113 - *
1114 - * @since 1.0.0
1115 - * @package userswp
1116 - *
1117 - * @param array $data Submitted $_POST data
1118 - *
1119 - * @return bool|WP_Error|string Profile url.
1120 - */
1121 - public function process_image_crop($data = array(), $type = 'avatar') {
1122 -
1123 - if (!is_user_logged_in()) {
1124 - return false;
2087 + $uwp_notices[] = array( 'account' => $message );
2088 + return;
2089 +
2090 + }
2091 +
2092 + $hash = md5( $result['email'] . time() . wp_rand() );
2093 + $new_admin_email = array(
2094 + 'hash' => $hash,
2095 + 'newemail' => $result['email'],
2096 + );
2097 +
2098 + update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2099 +
2100 + $new_email_link = add_query_arg(
2101 + array(
2102 + 'uwp_new_email' => 'yes',
2103 + 'key' => $hash,
2104 + 'login' => $user_data->user_login,
2105 + ),
2106 + uwp_get_account_page_url()
2107 + );
2108 +
2109 + $email_vars = array(
2110 + 'user_id' => $user_id,
2111 + 'new_email' => $result['email'],
2112 + 'new_email_link' => esc_url( $new_email_link ),
2113 + );
2114 +
2115 + UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2116 +
2117 + $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2118 + $message = aui()->alert(
2119 + array(
2120 + 'type' => 'success',
2121 + 'content' => $message,
2122 + )
2123 + );
2124 +
2125 + $uwp_notices[] = array( 'account' => $message );
2126 +
2127 + } else {
2128 + $email_vars = array(
2129 + 'user_id' => $user_id,
2130 + 'form_fields' => $form_fields,
2131 + );
2132 +
2133 + UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2134 +
2135 + $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2136 + $message = aui()->alert(
2137 + array(
2138 + 'type' => 'success',
2139 + 'content' => $message,
2140 + )
2141 + );
2142 +
2143 + $uwp_notices[] = array( 'account' => $message );
1125 2144 }
1126 2145
1127 - // If is current user's profile (profile.php)
1128 - if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
1129 - $user_id = get_current_user_id();
1130 - // If is another user's profile page
1131 - } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
1132 - $user_id = $_GET['user_id'];
1133 - // Otherwise something is wrong.
1134 - } else {
1135 - $user_id = get_current_user_id();
1136 - }
1137 - $image_url = $data['uwp_crop'];
1138 -
1139 - $errors = new WP_Error();
1140 - if (empty($image_url)) {
1141 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
1142 - }
2146 + do_action( 'uwp_after_process_account', $data, $user_id );
2147 + }
1143 2148
1144 - $error_code = $errors->get_error_code();
1145 - if (!empty($error_code)) {
1146 - return $errors;
1147 - }
1148 -
1149 - if ($image_url) {
1150 - if ($type == 'avatar') {
1151 - $full_width = apply_filters('uwp_avatar_image_width', 150);
1152 - } else {
1153 - $full_width = apply_filters('uwp_banner_image_width', uwp_get_option('profile_banner_width', 1000));
1154 - }
2149 + /**
2150 + * Modifies the forms field in email based on the form type.
2151 + *
2152 + * @param string $form_fields Form fields.
2153 + * @param string $type Form type.
2154 + * @param int $user_id User ID.
2155 + *
2156 + * @return string Modified mail field.
2157 + * @package userswp
2158 + * @subpackage userswp/includes
2159 + *
2160 + */
2161 + public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2162 + switch ( $type ) {
2163 + case 'register':
2164 + $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2165 + $fields = get_register_form_fields( $form_id );
2166 + $user_data = get_userdata( $user_id );
2167 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2168 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2169 + $excluded = uwp_get_excluded_fields();
2170 + foreach ( $fields as $key => $field ) {
2171 + if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2172 + continue;
2173 + }
2174 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2175 + $field_value = $user_data->user_email;
2176 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2177 + $field_value = $user_data->user_login;
2178 + } elseif ( $field->htmlvar_name == 'bio' ) {
2179 + $field_value = get_user_meta( $user_id, 'description', true );
2180 + } else {
2181 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2182 + }
1155 2183
1156 - $image_url = esc_url($image_url);
1157 - $uploads = wp_upload_dir();
1158 - $upload_url = $uploads['baseurl'];
1159 - $upload_path = $uploads['basedir'];
1160 - $image_url = str_replace($upload_url, $upload_path, $image_url);
1161 - $ext = pathinfo($image_url, PATHINFO_EXTENSION); // to get extension
1162 - $name =pathinfo($image_url, PATHINFO_FILENAME); //file name without extension
1163 - $thumb_image_name = $name.'_uwp_'.$type.'_thumb'.'.'.$ext;
1164 - $thumb_image_location = str_replace($name.'.'.$ext, $thumb_image_name, $image_url);
1165 - //Get the new coordinates to crop the image.
1166 - $x = $data["x"];
1167 - $y = $data["y"];
1168 - $w = $data["w"];
1169 - $h = $data["h"];
1170 - //Scale the image based on cropped width setting
1171 - $scale = $full_width/$w;
1172 - //$scale = 1; // no scaling
1173 - $cropped = uwp_resizeThumbnailImage($thumb_image_location, $image_url,$x, $y, $w, $h,$scale);
1174 - $cropped = str_replace($upload_path, $upload_url, $cropped);
2184 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2185 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2186 + }
1175 2187
1176 - // remove the uploads path for easy migrations
1177 - $cropped = str_replace($upload_url, '', $cropped);
1178 - if ($type == 'avatar') {
1179 - uwp_update_usermeta($user_id, 'uwp_account_avatar_thumb', $cropped);
1180 - } else {
1181 - uwp_update_usermeta($user_id, 'uwp_account_banner_thumb', $cropped);
1182 - }
1183 - }
2188 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2189 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2190 + }
2191 + }
2192 + }
2193 + break;
2194 + case 'account':
2195 + $fields = get_account_form_fields();
2196 + $user_data = get_userdata( $user_id );
2197 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2198 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2199 + foreach ( $fields as $key => $field ) {
2200 + if ( $field->is_active != '1' ) {
2201 + continue;
2202 + }
2203 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2204 + $field_value = $user_data->user_email;
2205 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2206 + $field_value = $user_data->user_login;
2207 + } elseif ( $field->htmlvar_name == 'bio' ) {
2208 + $field_value = get_user_meta( $user_id, 'description', true );
2209 + } else {
2210 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2211 + }
1184 2212
1185 - if (is_admin()) {
1186 - if ($user_id == get_current_user_id()) {
1187 - $profile_url = admin_url( 'profile.php' );
1188 - } else {
1189 - $profile_url = admin_url( 'user-edit.php?user_id='.$user_id );
1190 - }
1191 - } else {
1192 - $profile_url = uwp_build_profile_tab_url($user_id);
1193 - }
1194 - return $profile_url;
2213 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2214 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2215 + }
1195 2216
1196 - }
2217 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2218 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2219 + }
2220 + }
2221 + }
2222 + break;
2223 + }
1197 2224
1198 - /**
1199 - * Saves UsersWP related user custom fields.
1200 - *
1201 - * @since 1.0.0
1202 - * @package userswp
1203 - *
1204 - * @param int $user_id User ID.
1205 - * @param array $data Result array.
1206 - * @param string $type Form type.
1207 - *
1208 - * @return bool True when success. False when failure.
1209 - */
1210 - public function uwp_save_user_extra_fields($user_id, $data, $type) {
2225 + return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2226 + }
1211 2227
1212 - if (empty($user_id) || empty($data) || empty($type)) {
1213 - return false;
1214 - }
2228 + /**
2229 + *
2230 + *
2231 + * @return void
2232 + * @since 1.0.12 Unlink file.
2233 + * @package userswp
2234 + * @since 1.0.0
2235 + */
2236 + public function upload_file_remove() {
2237 + check_ajax_referer( 'uwp_basic_nonce', 'security' );
1215 2238
1216 - // custom user fields not applicable for login and forgot
1217 - if ($type == 'login' || $type == 'forgot') {
1218 - return true;
1219 - }
1220 -
2239 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2240 + $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
1221 2241
1222 - if ($type == 'account' || $type == 'register') {
1223 - if (isset($data['password'])) {
1224 - unset($data['password']);
1225 - }
1226 - }
2242 + if ( empty( $user_id ) ) {
2243 + wp_die( -1 );
2244 + }
1227 2245
1228 - if ($type == 'register') {
1229 - if (isset($data['uwp_account_username'])) {
1230 - unset($data['uwp_account_username']);
1231 - }
1232 - if (isset($data['uwp_account_email'])) {
1233 - unset($data['uwp_account_email']);
1234 - }
1235 - if (isset($data['uwp_account_display_name'])) {
1236 - unset($data['uwp_account_display_name']);
1237 - }
1238 - if (isset($data['uwp_account_first_name'])) {
1239 - unset($data['uwp_account_first_name']);
1240 - }
1241 - if (isset($data['uwp_account_last_name'])) {
1242 - unset($data['uwp_account_last_name']);
1243 - }
1244 - if (isset($data['uwp_account_bio'])) {
1245 - unset($data['uwp_account_bio']);
1246 - }
1247 - }
2246 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2247 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2248 + }
1248 2249
1249 - if (empty($data)) {
1250 - // no extra fields. so just return
1251 - return true;
1252 - } else {
1253 - foreach($data as $key => $value) {
1254 - uwp_update_usermeta($user_id, $key, $value);
1255 - }
1256 - return true;
1257 - }
1258 - }
2250 + // Remove file
2251 + if ( $htmlvar == 'banner_thumb' ) {
2252 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2253 + $type = 'banner';
2254 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2255 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2256 + $type = 'avatar';
2257 + } else {
2258 + $file = '';
2259 + $type = '';
2260 + }
1259 2261
1260 - /**
1261 - * Logs the error message.
1262 - *
1263 - * @since 1.0.0
1264 - * @package userswp
1265 - *
1266 - * @param array|object|string $log Error message.
1267 - *
1268 - * @return void
1269 - */
1270 - public static function uwp_error_log($log){
2262 + uwp_update_usermeta( $user_id, $htmlvar, '' );
1271 2263
1272 - $should_log = apply_filters( 'uwp_log_errors', WP_DEBUG);
1273 - if ( true === $should_log ) {
1274 - if ( is_array( $log ) || is_object( $log ) ) {
1275 - error_log( print_r( $log, true ) );
1276 - } else {
1277 - error_log( $log );
1278 - }
1279 - }
1280 - }
2264 + if ( $file ) {
2265 + $uploads = wp_upload_dir();
2266 + $upload_path = $uploads['basedir'];
2267 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
1281 2268
1282 - /**
1283 - *
1284 - *
1285 - * @since 1.0.0
1286 - * @package userswp
1287 - * @return void
1288 - */
1289 - public function uwp_upload_file_remove() {
2269 + if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2270 + @unlink( $unlink_file );
2271 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
1290 2272
1291 - $htmlvar = strip_tags(esc_sql($_POST['htmlvar']));
1292 - $user_id = (int) strip_tags(esc_sql($_POST['uid']));
1293 - $permission = false;
1294 - if ($user_id == get_current_user_id()) {
1295 - $permission = true;
1296 - } else {
1297 - if (current_user_can('manage_options')) {
1298 - $permission = true;
1299 - }
1300 - }
1301 - if ($permission) {
1302 - uwp_update_usermeta($user_id, $htmlvar, '');
1303 - }
1304 - die();
1305 - }
1306 -
1307 -
1308 - /**
1309 - * Form field template for datepicker field type.
1310 - *
1311 - * @since 1.0.0
1312 - * @package userswp
1313 - *
1314 - * @param string $html Form field html
1315 - * @param object $field Field info.
1316 - * @param string $value Form field default value.
1317 - * @param string $form_type Form type
1318 - *
1319 - * @return string Modified form field html.
1320 - */
1321 - public function uwp_form_input_datepicker($html, $field, $value, $form_type){
2273 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2274 + @unlink( $unlink_ori_file );
2275 + }
2276 + }
2277 + }
1322 2278
1323 - // Check if there is a field specific filter.
1324 - if(has_filter("uwp_form_input_html_datepicker_{$field->htmlvar_name}")){
1325 - $html = apply_filters("uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1326 - }
2279 + wp_send_json_success();
1327 2280
1328 - // If no html then we run the standard output.
1329 - if(empty($html)) {
2281 + wp_die();
2282 + }
1330 2283
1331 - ob_start(); // Start buffering;
2284 + /**
2285 + * Form field template for datepicker field type.
2286 + *
2287 + * @param string $html Form field html
2288 + * @param object $field Field info.
2289 + * @param string $value Form field default value.
2290 + * @param string $form_type Form type
2291 + *
2292 + * @return string Modified form field html.
2293 + * @package userswp
2294 + *
2295 + * @since 1.0.0
2296 + */
2297 + public function form_input_datepicker( $html, $field, $value, $form_type ) {
1332 2298
1333 - $extra_fields = unserialize($field->extra_fields);
2299 + // Check if there is a field specific filter.
2300 + if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2301 + $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2302 + }
1334 2303
1335 - if ($extra_fields['date_format'] == '')
1336 - $extra_fields['date_format'] = 'yy-mm-dd';
2304 + // If no html then we run the standard output.
2305 + if ( empty( $html ) ) {
1337 2306
1338 - $date_format = $extra_fields['date_format'];
1339 - $jquery_date_format = $date_format;
2307 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2308 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2309 + $bs_sr_only = $design_style ? 'sr-only' : '';
2310 + $bs_form_control = $design_style ? 'form-control' : '';
2311 + $extra_attributes = array();
2312 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2313 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1340 2314
1341 - if (!empty($value) && !is_string($value)) {
1342 - $value = date('Y-m-d', $value);
1343 - }
2315 + ob_start(); // Start buffering;
1344 2316
2317 + $extra_fields = unserialize( $field->extra_fields );
1345 2318
1346 - // check if we need to change the format or not
1347 - $date_format_len = strlen(str_replace(' ', '', $date_format));
1348 - if($date_format_len>5){// if greater then 5 then it's the old style format.
2319 + if ( $extra_fields['date_format'] == '' ) {
2320 + $extra_fields['date_format'] = 'yy-mm-dd';
2321 + }
1349 2322
1350 - $search = array('dd','d','DD','mm','m','MM','yy'); //jQuery UI datepicker format
1351 - $replace = array('d','j','l','m','n','F','Y');//PHP date format
2323 + $date_format = $extra_fields['date_format'];
2324 + $jquery_date_format = $date_format;
1352 2325
1353 - $date_format = str_replace($search, $replace, $date_format);
1354 - }else{
1355 - $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
1356 - }
1357 - if($value=='0000-00-00'){$value='';}//if date not set, then mark it empty
1358 - $value = uwp_date($value, 'Y-m-d', $date_format);
1359 - ?>
1360 - <script type="text/javascript">
2326 + // check if we need to change the format or not
2327 + $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2328 + if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
1361 2329
1362 - jQuery(function () {
2330 + $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2331 + $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
1363 2332
1364 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker({changeMonth: true, changeYear: true
1365 - <?php if($field->htmlvar_name == 'uwp_account_dob'){ echo ", yearRange: '1900:+0'"; } else { echo ", yearRange: '1900:2050'"; }?>
1366 - <?php echo apply_filters("uwp_datepicker_extra_{$field->htmlvar_name}",'');?>});
2333 + $date_format = str_replace( $search, $replace, $date_format );
2334 + } else {
2335 + $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2336 + }
1367 2337
1368 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("option", "dateFormat", '<?php echo $jquery_date_format;?>');
2338 + if ( ! empty( $value ) && ! is_string( $value ) ) {
2339 + $value = date( 'Y-m-d', $value );
2340 + }
1369 2341
1370 - <?php if(!empty($value)){?>
1371 - var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo $value;?>');
1372 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("setDate", parsedDate);
1373 - <?php } ?>
2342 + if ( $value == '0000-00-00' ) {
2343 + $value = '';
2344 + }//if date not set, then mark it empty
2345 + $value = uwp_date( $value, 'Y-m-d', $date_format );
2346 + $site_title = uwp_get_form_label( $field );
1374 2347
1375 - });
2348 + // bootstrap
2349 + if ( $design_style ) {
2350 + // flatpickr attributes
2351 + $extra_attributes['data-alt-input'] = 'true';
2352 + $extra_attributes['data-alt-format'] = $date_format;
2353 + $extra_attributes['data-date-format'] = 'Y-m-d';
1376 2354
1377 - </script>
1378 - <div id="<?php echo $field->htmlvar_name;?>_row"
1379 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp-fieldset-details">
2355 + if ( 'dob' == $field->htmlvar_name ) {
2356 + $extra_attributes['data-max-date'] = 'today';
2357 + }
1380 2358
1381 - <?php
1382 - $site_title = uwp_get_form_label($field);
1383 - if (!is_admin()) { ?>
1384 - <label>
1385 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1386 - <?php if ($field->is_required) echo '<span>*</span>';?>
1387 - </label>
1388 - <?php } ?>
2359 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1389 2360
1390 - <input name="<?php echo $field->htmlvar_name;?>"
1391 - id="<?php echo $field->htmlvar_name;?>"
1392 - placeholder="<?php echo $site_title; ?>"
1393 - title="<?php echo $site_title; ?>"
1394 - type="text"
1395 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1396 - value="<?php echo esc_attr($value);?>" class="uwp_textfield"/>
2361 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2362 + array(
2363 + 'id' => esc_attr( $field->htmlvar_name ),
2364 + 'name' => esc_attr( $field->htmlvar_name ),
2365 + 'required' => ! empty( $field->is_required ) ? true : false,
2366 + 'label' => wp_kses_post( $site_title . $required ),
2367 + 'label_show' => true,
2368 + 'label_type' => 'hidden',
2369 + 'type' => 'datepicker',
2370 + 'title' => esc_html( $site_title ),
2371 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2372 + 'class' => '',
2373 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2374 + 'value' => esc_attr( $value ),
2375 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2376 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2377 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2378 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2379 + )
2380 + );
2381 + } else {
2382 + ?>
2383 + <script type="text/javascript">
1397 2384
1398 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1399 - <?php if ($field->is_required) { ?>
1400 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1401 - <?php } ?>
1402 - </div>
2385 + jQuery(function () {
2386 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2387 + changeMonth: true, changeYear: true
2388 + <?php
2389 + if ( $field->htmlvar_name == 'dob' ) {
2390 + echo ", yearRange: '1900:+0'";
2391 + } else {
2392 + echo ", yearRange: '1900:2050'";
2393 + }
2394 + ?>
2395 + <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
1403 2396
1404 - <?php
1405 - $html = ob_get_clean();
1406 - }
2397 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
1407 2398
1408 - return $html;
1409 - }
2399 + <?php if ( ! empty( $value ) ) { ?>
2400 + var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2401 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2402 + <?php } ?>
1410 2403
1411 - /**
1412 - * Form field template for time field type.
1413 - *
1414 - * @since 1.0.0
1415 - * @package userswp
1416 - *
1417 - * @param string $html Form field html
1418 - * @param object $field Field info.
1419 - * @param string $value Form field default value.
1420 - * @param string $form_type Form type
1421 - *
1422 - * @return string Modified form field html.
1423 - */
1424 - public function uwp_form_input_time($html, $field, $value, $form_type){
2404 + });
1425 2405
1426 - if(has_filter("uwp_form_input_html_time_{$field->htmlvar_name}")){
2406 + </script>
2407 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2408 + class="
2409 + <?php
2410 + if ( $field->is_required ) {
2411 + echo 'required_field';
2412 + }
2413 + ?>
2414 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1427 2415
1428 - $html = apply_filters("uwp_form_input_html_time_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1429 - }
2416 + <?php
1430 2417
1431 - // If no html then we run the standard output.
1432 - if(empty($html)) {
2418 + if ( ! is_admin() ) {
2419 + ?>
2420 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2421 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2422 + <?php
2423 + if ( $field->is_required ) {
2424 + echo '<span>*</span>';
2425 + }
2426 + ?>
2427 + </label>
2428 + <?php } ?>
1433 2429
1434 - ob_start(); // Start buffering;
2430 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2431 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2432 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2433 + title="<?php echo esc_attr( $site_title ); ?>"
2434 + type="text"
2435 + <?php
2436 + if ( $field->is_required == 1 ) {
2437 + echo 'required="required"';
2438 + }
2439 + ?>
2440 + value="<?php echo esc_attr( $value ); ?>"
2441 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
1435 2442
1436 - if ($value != '')
1437 - $value = date('H:i', strtotime($value));
1438 - ?>
1439 - <script type="text/javascript">
1440 - jQuery(document).ready(function () {
2443 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2444 + <?php if ( $field->is_required ) { ?>
2445 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2446 + <?php } ?>
2447 + </div>
1441 2448
1442 - jQuery('#<?php echo $field->htmlvar_name;?>').timepicker({
1443 - showPeriod: true,
1444 - showLeadingZero: true
1445 - });
1446 - });
1447 - </script>
1448 - <div id="<?php echo $field->htmlvar_name;?>_row"
1449 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp-fieldset-details">
2449 + <?php
2450 + }
1450 2451
1451 - <?php
1452 - $site_title = uwp_get_form_label($field);
1453 - if (!is_admin()) { ?>
1454 - <label>
1455 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1456 - <?php if ($field->is_required) echo '<span>*</span>';?>
1457 - </label>
1458 - <?php } ?>
2452 + $html = ob_get_clean();
2453 + }
1459 2454
1460 - <input readonly="readonly" name="<?php echo $field->htmlvar_name;?>"
1461 - id="<?php echo $field->htmlvar_name;?>"
1462 - value="<?php echo esc_attr($value);?>"
1463 - placeholder="<?php echo $site_title; ?>"
1464 - type="text"
1465 - class="uwp_textfield"/>
2455 + return $html;
2456 + }
1466 2457
1467 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1468 - <?php if ($field->is_required) { ?>
1469 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1470 - <?php } ?>
1471 - </div>
1472 - <?php
1473 - $html = ob_get_clean();
1474 - }
2458 + /**
2459 + * Form field template for time field type.
2460 + *
2461 + * @param string $html Form field html
2462 + * @param object $field Field info.
2463 + * @param string $value Form field default value.
2464 + * @param string $form_type Form type
2465 + *
2466 + * @return string Modified form field html.
2467 + * @package userswp
2468 + *
2469 + * @since 1.0.0
2470 + */
2471 + public function form_input_time( $html, $field, $value, $form_type ) {
1475 2472
1476 - return $html;
1477 - }
2473 + if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
1478 2474
1479 - /**
1480 - * Form field template for select field type.
1481 - *
1482 - * @since 1.0.0
1483 - * @package userswp
1484 - *
1485 - * @param string $html Form field html
1486 - * @param object $field Field info.
1487 - * @param string $value Form field default value.
1488 - * @param string $form_type Form type
1489 - *
1490 - * @return string Modified form field html.
1491 - */
1492 - public function uwp_form_input_select($html, $field, $value, $form_type){
2475 + $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2476 + }
1493 2477
1494 - // Check if there is a field specific filter.
1495 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
1496 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1497 - }
2478 + // If no html then we run the standard output.
2479 + if ( empty( $html ) ) {
1498 2480
1499 - // Check if there is a field type specific filter.
1500 - if(has_filter("uwp_form_input_html_select_{$field->field_type_key}")){
1501 - $html = apply_filters("uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type);
1502 - }
2481 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2482 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2483 + $bs_sr_only = $design_style ? 'sr-only' : '';
2484 + $bs_form_control = $design_style ? 'form-control bg-white' : '';
2485 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2486 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1503 2487
1504 - // If no html then we run the standard output.
1505 - if(empty($html)) {
2488 + ob_start(); // Start buffering;
1506 2489
1507 - ob_start(); // Start buffering;
2490 + if ( $value != '' ) {
2491 + $value = date( 'H:i', strtotime( $value ) );
2492 + }
1508 2493
1509 - ?>
1510 - <div id="<?php echo $field->htmlvar_name;?>_row"
1511 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row">
2494 + // flatpickr attributes
2495 + $extra_attributes['data-enable-time'] = 'true';
2496 + $extra_attributes['data-no-calendar'] = 'true';
2497 + $extra_attributes['data-date-format'] = 'H:i';
2498 + $site_title = uwp_get_form_label( $field );
2499 + $label_type = is_admin() ? '' : 'top';
1512 2500
1513 - <?php
1514 - $site_title = uwp_get_form_label($field);
1515 - if (!is_admin()) { ?>
1516 - <label>
1517 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1518 - <?php if ($field->is_required) echo '<span>*</span>';?>
1519 - </label>
1520 - <?php } ?>
2501 + if ( $design_style ) {
2502 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1521 2503
1522 - <?php
1523 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1524 - $select_options = '';
1525 - if (!empty($option_values_arr)) {
1526 - foreach ($option_values_arr as $option_row) {
1527 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1528 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
2504 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2505 + array(
2506 + 'id' => esc_attr( $field->htmlvar_name ),
2507 + 'name' => esc_attr( $field->htmlvar_name ),
2508 + 'required' => ! empty( $field->is_required ) ? true : false,
2509 + 'label' => wp_kses_post( $site_title . $required ),
2510 + 'label_show' => true,
2511 + 'label_type' => esc_attr( $label_type ),
2512 + 'type' => 'timepicker',
2513 + 'title' => esc_html( $site_title ),
2514 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2515 + 'class' => '',
2516 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2517 + 'value' => esc_attr( $value ),
2518 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2519 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2520 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2521 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2522 + 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'uwp-search' ) . '" ></i></div>',
2523 + )
2524 + );
2525 + } else {
2526 + ?>
2527 + <script type="text/javascript">
2528 + jQuery(document).ready(function () {
2529 + jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2530 + showPeriod: true,
2531 + showLeadingZero: true
2532 + });
2533 + });
2534 + </script>
2535 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2536 + class="
2537 + <?php
2538 + if ( $field->is_required ) {
2539 + echo 'required_field';
2540 + }
2541 + ?>
2542 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1529 2543
1530 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1531 - } else {
1532 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1533 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1534 - $selected = $option_value == $value ? 'selected="selected"' : '';
2544 + <?php
2545 + $site_title = uwp_get_form_label( $field );
2546 + if ( ! is_admin() ) {
2547 + ?>
2548 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2549 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2550 + <?php
2551 + if ( $field->is_required ) {
2552 + echo '<span>*</span>';
2553 + }
2554 + ?>
2555 + </label>
2556 + <?php } ?>
1535 2557
1536 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1537 - }
1538 - }
1539 - }
1540 - ?>
1541 - <select name="<?php echo $field->htmlvar_name;?>" id="<?php echo $field->htmlvar_name;?>"
1542 - class="uwp_textfield"
1543 - title="<?php echo $site_title; ?>"
1544 - data-placeholder="<?php echo __('Choose', 'userswp') . ' ' . $site_title . '&hellip;';?>"
1545 - ><?php echo $select_options;?>
1546 - </select>
1547 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1548 - <?php if ($field->is_required) { ?>
1549 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1550 - <?php } ?>
1551 - </div>
2558 + <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2559 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2560 + value="<?php echo esc_attr( $value ); ?>"
2561 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2562 + type="text"
2563 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
1552 2564
1553 - <?php
1554 - $html = ob_get_clean();
1555 - }
2565 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2566 + <?php if ( $field->is_required ) { ?>
2567 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2568 + <?php } ?>
2569 + </div>
2570 + <?php
2571 + }
2572 + $html = ob_get_clean();
2573 + }
1556 2574
1557 - return $html;
1558 - }
2575 + return $html;
2576 + }
1559 2577
1560 - /**
1561 - * Form field template for multiselect field type.
1562 - *
1563 - * @since 1.0.0
1564 - * @package userswp
1565 - *
1566 - * @param string $html Form field html
1567 - * @param object $field Field info.
1568 - * @param string $value Form field default value.
1569 - * @param string $form_type Form type
1570 - *
1571 - * @return string Modified form field html.
1572 - */
1573 - public function uwp_form_input_multiselect($html, $field, $value, $form_type){
2578 + /**
2579 + * Form field template for select field type.
2580 + *
2581 + * @param string $html Form field html
2582 + * @param object $field Field info.
2583 + * @param string $value Form field default value.
2584 + * @param string $form_type Form type
2585 + *
2586 + * @return string Modified form field html.
2587 + * @package userswp
2588 + *
2589 + * @since 1.0.0
2590 + */
2591 + public function form_input_select( $html, $field, $value, $form_type ) {
1574 2592
1575 - // Check if there is a field specific filter.
1576 - if(has_filter("uwp_form_input_html_multiselect_{$field->htmlvar_name}")){
1577 - $html = apply_filters("uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1578 - }
2593 + // Check if there is a field specific filter.
2594 + if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2595 + $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2596 + }
1579 2597
2598 + // Check if there is a field type specific filter.
2599 + if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2600 + $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2601 + }
1580 2602
1581 - if(empty($html)) {
2603 + // If no html then we run the standard output.
2604 + if ( empty( $html ) ) {
1582 2605
1583 - ob_start(); // Start buffering;
2606 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2607 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2608 + $bs_sr_only = $design_style ? 'sr-only' : '';
2609 + $bs_form_control = $design_style ? 'form-control' : '';
2610 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2611 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1584 2612
1585 - $multi_display = 'select';
1586 - if (!empty($field->extra_fields)) {
1587 - $multi_display = unserialize($field->extra_fields);
1588 - }
1589 - ?>
1590 - <div id="<?php echo $field->htmlvar_name;?>_row"
1591 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row">
2613 + ob_start(); // Start buffering;
2614 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2615 + $site_title = uwp_get_form_label( $field );
1592 2616
1593 - <?php
1594 - $site_title = uwp_get_form_label($field);
1595 - if (!is_admin()) { ?>
1596 - <label>
1597 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1598 - <?php if ($field->is_required) echo '<span>*</span>';?>
1599 - </label>
1600 - <?php } ?>
2617 + // bootstrap
2618 + if ( $design_style ) {
1601 2619
1602 - <input type="hidden" name="<?php echo $field->htmlvar_name;?>" value=""/>
1603 - <?php if ($multi_display == 'select') { ?>
1604 - <div class="uwp_multiselect_list">
1605 - <select name="<?php echo $field->htmlvar_name;?>[]"
1606 - id="<?php echo $field->htmlvar_name;?>"
1607 - title="<?php echo $site_title; ?>"
1608 - multiple="multiple" class="uwp_chosen_select"
1609 - data-placeholder="<?php echo $site_title; ?>"
1610 - >
1611 - <?php
1612 - } else {
2620 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2621 +
2622 + echo aui()->select(
2623 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2624 + 'id' => esc_attr( $field->htmlvar_name ),
2625 + 'name' => esc_attr( $field->htmlvar_name ),
2626 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2627 + 'title' => esc_html( $site_title ),
2628 + 'value' => esc_attr( $value ),
2629 + 'required' => (bool) $field->is_required,
2630 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2631 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2632 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2633 + 'label' => wp_kses_post( $site_title . $required ),
2634 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2635 + 'select2' => true,
2636 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2637 + )
2638 + );
2639 + } else {
2640 + ?>
2641 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2642 + class="
2643 + <?php
2644 + if ( $field->is_required ) {
2645 + echo 'required_field';
2646 + }
2647 + ?>
2648 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2649 +
2650 + <?php
2651 + if ( ! is_admin() ) {
2652 + ?>
2653 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2654 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2655 + <?php
2656 + if ( $field->is_required ) {
2657 + echo '<span>*</span>';
2658 + }
1613 2659 ?>
1614 - <ul class="uwp_multi_choice">
1615 - <?php
1616 - }
2660 + </label>
2661 + <?php } ?>
1617 2662
1618 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1619 - $select_options = '';
1620 - if (!empty($option_values_arr)) {
1621 - foreach ($option_values_arr as $option_row) {
1622 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1623 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
2663 + <?php
1624 2664
1625 - if ($multi_display == 'select') {
1626 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1627 - } else {
1628 - $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
1629 - }
1630 - } else {
1631 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1632 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1633 - $selected = $option_value == $value ? 'selected="selected"' : '';
1634 - $checked = '';
2665 + $select_options = '';
2666 + if ( ! empty( $option_values_arr ) ) {
2667 + foreach ( $option_values_arr as $option_row ) {
2668 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2669 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
1635 2670
1636 - if ((!is_array($value) && trim($value) != '') || (is_array($value) && !empty($value))) {
1637 - if (!is_array($value)) {
1638 - $value_array = explode(',', $value);
1639 - } else {
1640 - $value_array = $value;
1641 - }
2671 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2672 + } else {
2673 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2674 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2675 + $selected = $option_value == $value ? 'selected="selected"' : '';
1642 2676
1643 - if (is_array($value_array)) {
1644 - if (in_array($option_value, $value_array)) {
1645 - $selected = 'selected="selected"';
1646 - $checked = 'checked="checked"';
1647 - }
1648 - }
1649 - }
2677 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2678 + }
2679 + }
2680 + }
2681 + ?>
2682 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2683 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2684 + title="<?php echo esc_attr( $site_title ); ?>"
2685 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2686 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2687 + </select>
2688 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2689 + <?php if ( $field->is_required ) { ?>
2690 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2691 + <?php } ?>
2692 + </div>
1650 2693
1651 - if ($multi_display == 'select') {
1652 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1653 - } else {
1654 - $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr($option_value) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
1655 - }
1656 - }
1657 - }
1658 - }
1659 - echo $select_options;
2694 + <?php
2695 + }
2696 + $html = ob_get_clean();
2697 + }
1660 2698
1661 - if ($multi_display == 'select') { ?></select></div>
1662 - <?php } else { ?>
1663 - </ul>
1664 - <?php } ?>
1665 - <?php if ($field->is_required) { ?>
1666 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1667 - <?php } ?>
1668 - </div>
1669 - <?php
1670 - $html = ob_get_clean();
1671 - }
2699 + return $html;
2700 + }
1672 2701
1673 - return $html;
1674 - }
2702 + /**
2703 + * Form field template for multiselect field type.
2704 + *
2705 + * @param string $html Form field html
2706 + * @param object $field Field info.
2707 + * @param string $value Form field default value.
2708 + * @param string $form_type Form type
2709 + *
2710 + * @return string Modified form field html.
2711 + * @package userswp
2712 + *
2713 + * @since 1.0.0
2714 + */
2715 + public function form_input_multiselect( $html, $field, $value, $form_type ) {
1675 2716
1676 - /**
1677 - * Form field template for file field type.
1678 - *
1679 - * @since 1.0.0
1680 - * @package userswp
1681 - *
1682 - * @param string $html Form field html
1683 - * @param object $field Field info.
1684 - * @param string $value Form field default value.
1685 - * @param string $form_type Form type
1686 - *
1687 - * @return string Modified form field html.
1688 - */
1689 - public function uwp_form_input_file($html, $field, $value, $form_type){
2717 + // Check if there is a field specific filter.
2718 + if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
2719 + $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2720 + }
1690 2721
1691 - $file_obj = new UsersWP_Files();
1692 -
1693 - // Check if there is a field specific filter.
1694 - if(has_filter("uwp_form_input_html_file_{$field->htmlvar_name}")){
1695 - $html = apply_filters("uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1696 - }
2722 + if ( empty( $html ) ) {
1697 2723
1698 - // If no html then we run the standard output.
1699 - if(empty($html)) {
2724 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2725 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2726 + $bs_sr_only = $design_style ? 'sr-only' : '';
2727 + $bs_form_control = $design_style ? 'form-control' : '';
2728 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2729 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1700 2730
1701 - ob_start(); // Start buffering;
2731 + ob_start(); // Start buffering;
1702 2732
1703 - ?>
1704 - <div id="<?php echo $field->htmlvar_name;?>_row"
1705 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
2733 + $multi_display = 'select';
2734 + if ( ! empty( $field->extra_fields ) ) {
2735 + $multi_display = unserialize( $field->extra_fields );
2736 + }
1706 2737
1707 - <?php
1708 - $site_title = uwp_get_form_label($field);
1709 - if (!is_admin()) { ?>
1710 - <label>
1711 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1712 - <?php if ($field->is_required) echo '<span>*</span>';?>
1713 - </label>
1714 - <?php } ?>
2738 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2739 + $site_title = uwp_get_form_label( $field );
2740 + $value = is_array( $value ) ? $value : esc_attr( $value );
1715 2741
1716 - <?php echo $file_obj->uwp_file_upload_preview($field, $value); ?>
1717 - <input name="<?php echo $field->htmlvar_name; ?>"
1718 - class="<?php echo $field->css_class; ?>"
1719 - placeholder="<?php echo $site_title; ?>"
1720 - title="<?php echo $site_title; ?>"
2742 + // bootstrap
2743 + if ( $design_style ) {
2744 +
2745 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2746 +
2747 + echo aui()->select(
2748 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2749 + 'id' => esc_attr( $field->htmlvar_name ),
2750 + 'name' => esc_attr( $field->htmlvar_name ),
2751 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2752 + 'title' => esc_html( $site_title ),
2753 + 'value' => $value,
2754 + 'required' => (bool) $field->is_required,
2755 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2756 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2757 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2758 + 'label' => wp_kses_post( $site_title . $required ),
2759 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2760 + 'select2' => true,
2761 + 'multiple' => true,
2762 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2763 + )
2764 + );
2765 + } else {
2766 + ?>
2767 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2768 + class="
1721 2769 <?php
1722 - if ($field->is_required == 1 ) { echo 'data-is-required="1"'; }
1723 - if ($field->is_required == 1 && !$value) { echo 'required="required"'; }
2770 + if ( $field->is_required ) {
2771 + echo 'required_field';
2772 + }
1724 2773 ?>
1725 - type="<?php echo $field->field_type; ?>">
1726 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1727 - <?php if ($field->is_required) { ?>
1728 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1729 - <?php } ?>
1730 - </div>
2774 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1731 2775
1732 - <?php
1733 - $html = ob_get_clean();
1734 - }
2776 + <?php
2777 + if ( ! is_admin() ) {
2778 + ?>
2779 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2780 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2781 + <?php
2782 + if ( $field->is_required ) {
2783 + echo '<span>*</span>';
2784 + }
2785 + ?>
2786 + </label>
2787 + <?php } ?>
1735 2788
1736 - return $html;
1737 - }
2789 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
2790 + <?php if ( $multi_display == 'select' ) { ?>
2791 + <div class="uwp_multiselect_list">
2792 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
2793 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2794 + title="<?php echo esc_attr( $site_title ); ?>"
2795 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2796 + class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2797 + >
2798 + <?php
2799 + } else {
2800 + ?>
2801 + <ul class="uwp_multi_choice">
2802 + <?php
2803 + }
1738 2804
1739 - /**
1740 - * Form field template for checkbox field type.
1741 - *
1742 - * @since 1.0.0
1743 - * @package userswp
1744 - *
1745 - * @param string $html Form field html
1746 - * @param object $field Field info.
1747 - * @param string $value Form field default value.
1748 - * @param string $form_type Form type
1749 - *
1750 - * @return string Modified form field html.
1751 - */
1752 - public function uwp_form_input_checkbox($html, $field, $value, $form_type){
2805 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2806 + $select_options = '';
2807 + if ( ! empty( $option_values_arr ) ) {
2808 + foreach ( $option_values_arr as $option_row ) {
2809 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2810 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
1753 2811
1754 - // Check if there is a field specific filter.
1755 - if(has_filter("uwp_form_input_html_checkbox_{$field->htmlvar_name}")){
1756 - $html = apply_filters("uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1757 - }
2812 + if ( $multi_display == 'select' ) {
2813 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2814 + } else {
2815 + $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
2816 + }
2817 + } else {
2818 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2819 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2820 + $selected = $option_value == $value ? 'selected="selected"' : '';
2821 + $checked = '';
1758 2822
1759 - // If no html then we run the standard output.
1760 - if(empty($html)) {
2823 + if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
2824 + if ( ! is_array( $value ) ) {
2825 + $value_array = explode( ',', $value );
2826 + } else {
2827 + $value_array = $value;
2828 + }
1761 2829
1762 - ob_start(); // Start buffering;
1763 - $site_title = uwp_get_form_label($field);
1764 - ?>
1765 - <div id="<?php echo $field->htmlvar_name;?>_row"
1766 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
1767 - <input type="hidden" name="<?php echo $field->htmlvar_name; ?>" value="0" />
1768 - <input name="<?php echo $field->htmlvar_name; ?>"
1769 - class="<?php echo $field->css_class; ?>"
1770 - placeholder="<?php echo $site_title; ?>"
1771 - title="<?php echo $site_title; ?>"
1772 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1773 - <?php if ($value == '1') { echo 'checked="checked"'; } ?>
1774 - type="<?php echo $field->field_type; ?>"
1775 - value="1">
2830 + if ( is_array( $value_array ) ) {
2831 + if ( in_array( $option_value, $value_array ) ) {
2832 + $selected = 'selected="selected"';
2833 + $checked = 'checked="checked"';
2834 + }
2835 + }
2836 + }
2837 +
2838 + if ( $multi_display == 'select' ) {
2839 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2840 + } else {
2841 + $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
2842 + }
2843 + }
2844 + }
2845 + }
2846 + echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2847 +
2848 + if ( $multi_display == 'select' ) {
2849 +
2850 + ?>
2851 + </select></div>
2852 + <?php } else { ?>
2853 + </ul>
2854 + <?php } ?>
2855 + <?php if ( $field->is_required ) { ?>
2856 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2857 + <?php } ?>
2858 + </div>
2859 + <?php
2860 + }
2861 + $html = ob_get_clean();
2862 + }
2863 +
2864 + return $html;
2865 + }
2866 +
2867 + /**
2868 + * Form field template for file field type.
2869 + *
2870 + * @param string $html Form field html
2871 + * @param object $field Field info.
2872 + * @param string $value Form field default value.
2873 + * @param string $form_type Form type
2874 + *
2875 + * @return string Modified form field html.
2876 + * @package userswp
2877 + *
2878 + * @since 1.0.0
2879 + */
2880 + public function form_input_file( $html, $field, $value, $form_type ) {
2881 +
2882 + $file_obj = new UsersWP_Files();
2883 +
2884 + // Check if there is a field specific filter.
2885 + if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
2886 + $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2887 + }
2888 +
2889 + // If no html then we run the standard output.
2890 + if ( empty( $html ) ) {
2891 +
2892 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2893 + $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
2894 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2895 + $bs_sr_only = $design_style ? 'sr-only' : '';
2896 + $bs_form_control = $design_style ? 'form-control' : '';
2897 +
2898 + ob_start(); // Start buffering;
2899 +
2900 + ?>
2901 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2902 + class="
1776 2903 <?php
1777 - echo (trim($site_title)) ? $site_title : '&nbsp;';
2904 + if ( $field->is_required ) {
2905 + echo 'required_field';
2906 + }
1778 2907 ?>
1779 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1780 - <?php if ($field->is_required) { ?>
1781 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1782 - <?php } ?>
1783 - </div>
2908 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
1784 2909
1785 - <?php
1786 - $html = ob_get_clean();
1787 - }
2910 + <?php
2911 + $site_title = uwp_get_form_label( $field );
2912 + if ( ! is_admin() && ! wp_doing_ajax() ) {
2913 + ?>
2914 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2915 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2916 + <?php
2917 + if ( $field->is_required ) {
2918 + echo ' <span class="text-danger">*</span>';
2919 + }
2920 + ?>
2921 + </label>
2922 + <?php } ?>
1788 2923
1789 - return $html;
1790 - }
2924 + <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2925 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2926 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
2927 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2928 + title="<?php echo esc_attr( $site_title ); ?>"
2929 + <?php
2930 + if ( $field->is_required == 1 ) {
2931 + echo 'data-is-required="1"';
2932 + }
2933 + if ( $field->is_required == 1 && ! $value ) {
2934 + echo 'required="required"';
2935 + }
2936 + ?>
2937 + type="<?php echo esc_attr( $field->field_type ); ?>">
2938 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2939 + <?php if ( $field->is_required ) { ?>
2940 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2941 + <?php } ?>
2942 + </div>
1791 2943
1792 - /**
1793 - * Form field template for radio field type.
1794 - *
1795 - * @since 1.0.0
1796 - * @package userswp
1797 - *
1798 - * @param string $html Form field html
1799 - * @param object $field Field info.
1800 - * @param string $value Form field default value.
1801 - * @param string $form_type Form type
1802 - *
1803 - * @return string Modified form field html.
1804 - */
1805 - public function uwp_form_input_radio($html, $field, $value, $form_type){
2944 + <?php
2945 + $html = ob_get_clean();
2946 + }
1806 2947
1807 - // Check if there is a field specific filter.
1808 - if(has_filter("uwp_form_input_html_radio_{$field->htmlvar_name}")){
1809 - $html = apply_filters("uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1810 - }
2948 + return $html;
2949 + }
1811 2950
1812 - // If no html then we run the standard output.
1813 - if(empty($html)) {
2951 + /**
2952 + * Form field template for checkbox field type.
2953 + *
2954 + * @param string $html Form field html
2955 + * @param object $field Field info.
2956 + * @param string $value Form field default value.
2957 + * @param string $form_type Form type
2958 + *
2959 + * @return string Modified form field html.
2960 + * @package userswp
2961 + *
2962 + * @since 1.0.0
2963 + */
2964 + public function form_input_checkbox( $html, $field, $value, $form_type ) {
1814 2965
1815 - ob_start(); // Start buffering;
2966 + // Check if there is a field specific filter.
2967 + if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
2968 + $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2969 + }
1816 2970
1817 - ?>
1818 - <div id="<?php echo $field->htmlvar_name;?>_row"
1819 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
2971 + // If no html then we run the standard output.
2972 + if ( empty( $html ) ) {
1820 2973
1821 - <?php
1822 - $site_title = uwp_get_form_label($field);
1823 - if (!is_admin()) { ?>
1824 - <label>
1825 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1826 - <?php if ($field->is_required) echo '<span>*</span>';?>
1827 - </label>
1828 - <?php } ?>
2974 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2975 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
2976 + $bs_sr_only = $design_style ? 'form-check-label' : '';
2977 + $bs_form_control = $design_style ? 'form-check-input' : '';
1829 2978
2979 + ob_start(); // Start buffering;
2980 + $site_title = uwp_get_form_label( $field );
1830 2981
1831 - <?php if ($field->option_values) {
1832 - $option_values = uwp_string_values_to_options($field->option_values, true);
2982 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2983 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
1833 2984
1834 - if (!empty($option_values)) {
1835 - $count = 0;
1836 - foreach ($option_values as $option_value) {
1837 - if (empty($option_value['optgroup'])) {
1838 - $count++;
1839 - if ($count == 1) {
1840 - $class = "uwp-radio-first";
1841 - } else {
1842 - $class = "";
1843 - }
1844 - ?>
1845 - <span class="uwp-radios <?php echo $class; ?>">
1846 - <input name="<?php echo $field->htmlvar_name; ?>"
1847 - id="<?php echo $field->htmlvar_name; ?>"
1848 - title="<?php echo esc_attr($option_value['label']); ?>"
1849 - <?php checked($value, $option_value['value']);?>
1850 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1851 - value="<?php echo esc_attr($option_value['value']); ?>"
1852 - class="uwp-radio" type="radio" />
1853 - <?php echo $option_value['label']; ?>
1854 - </span>
1855 - <?php
1856 - }
1857 - }
2985 + $checked = $value == '1' ? true : false;
2986 +
2987 + // bootstrap
2988 + if ( $design_style ) {
2989 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2990 +
2991 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2992 +
2993 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2994 + array(
2995 + 'id' => esc_attr( $id ),
2996 + 'name' => esc_attr( $field->htmlvar_name ),
2997 + 'type' => 'checkbox',
2998 + 'value' => '1',
2999 + 'title' => esc_html( $site_title ),
3000 + 'label' => wp_kses_post( $site_title . $required ),
3001 + 'label_show' => true,
3002 + 'required' => ! empty( $field->is_required ) ? true : false,
3003 + 'checked' => (bool) $checked,
3004 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3005 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3006 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3007 + )
3008 + );
3009 +
3010 + } else {
3011 + ?>
3012 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3013 + class="
3014 + <?php
3015 + if ( $field->is_required ) {
3016 + echo 'required_field';
3017 + }
3018 + ?>
3019 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3020 + <?php if ( ! empty( $design_style ) ) { ?>
3021 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3022 + <?php } ?>
3023 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3024 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3025 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3026 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3027 + title="<?php echo esc_attr( $site_title ); ?>"
3028 + <?php
3029 + if ( $field->is_required == 1 ) {
3030 + echo 'required="required"';
3031 + }
3032 + ?>
3033 + <?php
3034 + if ( $value == '1' ) {
3035 + echo 'checked="checked"';
3036 + }
3037 + ?>
3038 + type="<?php echo esc_attr( $field->field_type ); ?>"
3039 + value="1">
3040 + <?php
3041 + echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3042 + ?>
3043 + <?php if ( ! empty( $design_style ) ) { ?>
3044 + </label>
3045 + <?php } ?>
3046 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3047 + <?php if ( $field->is_required ) { ?>
3048 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3049 + <?php } ?>
3050 + </div>
3051 +
3052 + <?php
3053 +
3054 + }
3055 +
3056 + $html = ob_get_clean();
3057 +
3058 + }
3059 +
3060 + return $html;
3061 + }
3062 +
3063 + /**
3064 + * Form field template for radio field type.
3065 + *
3066 + * @param string $html Form field html
3067 + * @param object $field Field info.
3068 + * @param string $value Form field default value.
3069 + * @param string $form_type Form type
3070 + *
3071 + * @return string Modified form field html.
3072 + * @package userswp
3073 + *
3074 + * @since 1.0.0
3075 + */
3076 + public function form_input_radio( $html, $field, $value, $form_type ) {
3077 +
3078 + // Check if there is a field specific filter.
3079 + if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3080 + $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3081 + }
3082 +
3083 + // If no html then we run the standard output.
3084 + if ( empty( $html ) ) {
3085 +
3086 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3087 + $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3088 + $bs_sr_only = $design_style ? 'sr-only' : '';
3089 + $bs_label_class = $design_style ? 'form-check-label' : '';
3090 + $bs_form_control = $design_style ? 'form-check-input' : '';
3091 +
3092 + ob_start(); // Start buffering;
3093 +
3094 + if ( $design_style ) {
3095 +
3096 + $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3097 + $option_values = array();
3098 + if ( ! empty( $option_values_deep ) ) {
3099 + foreach ( $option_values_deep as $option ) {
3100 + $option_values[ $option['value'] ] = $option['label'];
3101 + }
3102 + }
3103 +
3104 + $site_title = uwp_get_form_label( $field );
3105 +
3106 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3107 +
3108 + echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3109 + array(
3110 + 'id' => esc_attr( $field->htmlvar_name ),
3111 + 'name' => esc_attr( $field->htmlvar_name ),
3112 + 'type' => 'radio',
3113 + 'title' => esc_html( $site_title ),
3114 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3115 + 'label_type' => 'top',
3116 + 'class' => '',
3117 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3118 + 'value' => esc_attr( $value ),
3119 + 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3120 + )
3121 + );
3122 +
3123 + } else {
3124 +
3125 + ?>
3126 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3127 + class="
3128 + <?php
3129 + if ( $field->is_required ) {
3130 + echo 'required_field';
3131 + }
3132 + ?>
3133 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3134 +
3135 + <?php
3136 + $site_title = uwp_get_form_label( $field );
3137 + if ( ! is_admin() ) {
3138 + ?>
3139 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3140 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3141 + <?php
3142 + if ( $field->is_required ) {
3143 + echo '<span>*</span>';
3144 + }
3145 + ?>
3146 + </label>
3147 + <?php } ?>
3148 +
3149 + <?php
3150 + if ( $field->option_values ) {
3151 + $option_values = uwp_string_values_to_options( $field->option_values, true );
3152 +
3153 + if ( ! empty( $option_values ) ) {
3154 + $count = 0;
3155 + foreach ( $option_values as $option_value ) {
3156 + if ( empty( $option_value['optgroup'] ) ) {
3157 + ++$count;
3158 + if ( $count == 1 ) {
3159 + $class = 'uwp-radio-first';
3160 + } else {
3161 + $class = '';
3162 + }
3163 + ?>
3164 + <?php if ( ! empty( $design_style ) ) { ?>
3165 + <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3166 + <?php } else { ?>
3167 + <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3168 + <?php } ?>
3169 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3170 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3171 + title="<?php echo esc_attr( $option_value['label'] ); ?>"
3172 + <?php checked( $value, $option_value['value'] ); ?>
3173 + <?php
3174 + if ( $field->is_required == 1 ) {
3175 + echo 'required="required"';
3176 + }
3177 + ?>
3178 + value="<?php echo esc_attr( $option_value['value'] ); ?>"
3179 + class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3180 + <?php echo esc_html( $option_value['label'] ); ?>
3181 + <?php if ( ! empty( $design_style ) ) { ?>
3182 + </label>
3183 + <?php } else { ?>
3184 + </span>
3185 + <?php
3186 + }
3187 + }
3188 + }
3189 + }
3190 + }
3191 + ?>
3192 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3193 + <?php if ( $field->is_required ) { ?>
3194 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3195 + <?php } ?>
3196 + </div>
3197 + <?php
3198 + }
3199 +
3200 + $html = ob_get_clean();
3201 + }
3202 +
3203 + return $html;
3204 + }
3205 +
3206 + /**
3207 + * Form field template for text field type.
3208 + *
3209 + * @param string $html Form field html
3210 + * @param object $field Field info.
3211 + * @param string $value Form field default value.
3212 + * @param string $form_type Form type
3213 + *
3214 + * @return string Modified form field html.
3215 + * @package userswp
3216 + *
3217 + * @since 1.0.0
3218 + */
3219 + public function form_input_text( $html, $field, $value, $form_type ) {
3220 +
3221 + // Check if there is a custom field specific filter.
3222 + if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3223 + $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3224 + }
3225 +
3226 + // If no html then we run the standard output.
3227 + if ( empty( $html ) ) {
3228 +
3229 + ob_start(); // Start buffering;
3230 +
3231 + $type = 'text';
3232 + $step = false;
3233 + //number and float validation $validation_pattern
3234 + if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3235 + $type = 'number';
3236 + } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3237 + $dp = $field->decimal_point;
3238 + switch ( $dp ) {
3239 + case '1':
3240 + $step = '0.1';
3241 + break;
3242 + case '2':
3243 + $step = '0.01';
3244 + break;
3245 + case '3':
3246 + $step = '0.001';
3247 + break;
3248 + case '4':
3249 + $step = '0.0001';
3250 + break;
3251 + case '5':
3252 + $step = '0.00001';
3253 + break;
3254 + case '6':
3255 + $step = '0.000001';
3256 + break;
3257 + case '7':
3258 + $step = '0.0000001';
3259 + break;
3260 + case '8':
3261 + $step = '0.00000001';
3262 + break;
3263 + case '9':
3264 + $step = '0.000000001';
3265 + break;
3266 + case '10':
3267 + $step = '0.0000000001';
3268 + break;
3269 + default:
3270 + $step = '0.01';
3271 + break;
3272 + }
3273 + $type = 'number';
3274 + }
3275 +
3276 + $site_title = uwp_get_form_label( $field );
3277 + $placeholder = uwp_get_field_placeholder( $field );
3278 + $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3279 + if ( $manual_label
3280 + && isset( $field->form_type )
3281 + && $field->form_type == 'login'
3282 + && $field->htmlvar_name == 'username' ) {
3283 + $site_title = __( 'Username or Email', 'userswp' );
3284 + $required = ! empty( $field->is_required ) ? ' *' : '';
3285 + $placeholder = $site_title . $required;
3286 + $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3287 + }
3288 +
3289 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3290 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3291 + $bs_sr_only = $design_style ? 'sr-only' : '';
3292 + $bs_form_control = $design_style ? 'form-control' : '';
3293 +
3294 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3295 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3296 +
3297 + // bootstrap
3298 + if ( $design_style ) {
3299 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3300 +
3301 + echo aui()->input(
3302 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3303 + 'type' => esc_attr( $type ),
3304 + 'id' => esc_attr( $field->htmlvar_name ),
3305 + 'name' => esc_attr( $field->htmlvar_name ),
3306 + 'placeholder' => esc_attr( $placeholder ),
3307 + 'title' => esc_html( $site_title ),
3308 + 'value' => esc_attr( wp_unslash( $value ) ),
3309 + 'required' => (bool) $field->is_required,
3310 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3311 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3312 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3313 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3314 + 'step' => esc_attr( $step ),
3315 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3316 + )
3317 + );
3318 + } else {
3319 + ?>
3320 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3321 + <?php
3322 + if ( $field->is_required ) {
3323 + echo 'required_field';
3324 + }
3325 + ?>
3326 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3327 + <?php
3328 +
3329 + if ( ! is_admin() ) {
3330 + ?>
3331 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3332 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3333 + <?php
3334 + if ( $field->is_required ) {
3335 + echo '<span>*</span>';
3336 + }
3337 + ?>
3338 + </label>
3339 + <?php
1858 3340 }
1859 - }
3341 + ?>
3342 +
3343 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3344 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3345 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3346 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3347 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3348 + title="<?php echo esc_attr( $site_title ); ?>"
3349 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3350 + oninput="setCustomValidity('')"
3351 + <?php
3352 + if ( $field->is_required == 1 ) {
3353 + echo 'required="required"';
3354 + }
3355 + ?>
3356 + <?php
3357 + if ( $field->for_admin_use == 1 ) {
3358 + echo 'readonly="readonly"';
3359 + }
3360 + ?>
3361 + type="<?php echo esc_attr( $type ); ?>"
3362 + <?php
3363 + if ( $step ) {
3364 + echo 'step="' . esc_attr( $step ) . '"';
3365 + }
3366 + ?>
3367 + />
3368 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3369 + <?php if ( $field->is_required ) { ?>
3370 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3371 + <?php } ?>
3372 + </div>
3373 +
3374 +
3375 + <?php
3376 + }
3377 + $html = ob_get_clean();
3378 + }
3379 +
3380 + return $html;
3381 + }
3382 +
3383 + /**
3384 + * Form field template for textarea field type.
3385 + *
3386 + * @param string $html Form field html
3387 + * @param object $field Field info.
3388 + * @param string $value Form field default value.
3389 + * @param string $form_type Form type
3390 + *
3391 + * @return string Modified form field html.
3392 + * @package userswp
3393 + *
3394 + * @since 1.0.0
3395 + */
3396 + public function form_input_textarea( $html, $field, $value, $form_type ) {
3397 +
3398 + // Check if there is a field specific filter.
3399 + if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3400 + $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3401 + }
3402 +
3403 + // If no html then we run the standard output.
3404 + if ( empty( $html ) ) {
3405 +
3406 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3407 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3408 + $bs_sr_only = $design_style ? 'sr-only' : '';
3409 + $bs_form_control = $design_style ? 'form-control' : '';
3410 + $site_title = uwp_get_form_label( $field );
3411 +
3412 + ob_start(); // Start buffering;
3413 +
3414 + // bootstrap
3415 + if ( $design_style ) {
3416 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3417 +
3418 + echo aui()->textarea(
3419 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3420 + 'id' => esc_attr( $field->htmlvar_name ),
3421 + 'name' => esc_attr( $field->htmlvar_name ),
3422 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3423 + 'title' => esc_html( $site_title ),
3424 + 'value' => wp_kses_post( stripslashes( $value ) ),
3425 + 'required' => (bool) $field->is_required,
3426 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3427 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3428 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3429 + 'rows' => '4',
3430 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3431 + )
3432 + );
3433 + } else {
3434 + ?>
3435 +
3436 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3437 + class="
3438 + <?php
3439 + if ( $field->is_required ) {
3440 + echo 'required_field';
3441 + }
3442 + ?>
3443 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3444 +
3445 + <?php
3446 +
3447 + if ( ! is_admin() ) {
3448 + ?>
3449 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3450 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3451 + <?php
3452 + if ( $field->is_required ) {
3453 + echo '<span>*</span>';
3454 + }
3455 + ?>
3456 + </label>
3457 + <?php } ?>
3458 +
3459 + <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3460 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3461 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3462 + title="<?php echo esc_attr( $site_title ); ?>"
3463 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3464 + oninput="setCustomValidity('')"
3465 + <?php
3466 + if ( $field->is_required == 1 ) {
3467 + echo 'required="required"';
3468 + }
3469 + ?>
3470 + type="<?php echo esc_attr( $field->field_type ); ?>"
3471 + rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3472 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3473 + <?php if ( $field->is_required ) { ?>
3474 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3475 + <?php } ?>
3476 + </div>
3477 +
3478 + <?php
3479 + }
3480 + $html = ob_get_clean();
3481 + }
3482 +
3483 + return $html;
3484 + }
3485 +
3486 + public function form_input_editor( $html, $field, $value, $form_type ) {
3487 +
3488 + // Check if there is a field specific filter.
3489 + if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3490 + $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3491 + }
3492 +
3493 + if ( empty( $html ) ) {
3494 +
3495 + ob_start();
3496 +
3497 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3498 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3499 + $bs_sr_only = $design_style ? 'sr-only' : '';
3500 + $site_title = uwp_get_form_label( $field );
3501 +
3502 + $content = stripslashes( $value );
3503 + $editor_id = $field->htmlvar_name;
3504 + $args = array(
3505 + 'textarea_rows' => 5,
3506 + 'media_buttons' => false,
3507 + 'quicktags' => false,
3508 + );
3509 +
3510 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3511 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3512 +
3513 + // bootstrap
3514 + if ( $design_style ) {
3515 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3516 +
3517 + echo aui()->textarea(
3518 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3519 + 'id' => esc_attr( $field->htmlvar_name ),
3520 + 'name' => esc_attr( $field->htmlvar_name ),
3521 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3522 + 'title' => esc_html( $site_title ),
3523 + 'value' => wp_kses_post( stripslashes( $value ) ),
3524 + 'required' => (bool) $field->is_required,
3525 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3526 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3527 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3528 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3529 + 'rows' => 5,
3530 + 'wysiwyg' => true,
3531 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3532 + )
3533 + );
3534 + } else {
3535 + ?>
3536 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3537 + class="
3538 + <?php
3539 + if ( $field->is_required ) {
3540 + echo 'required_field';
3541 + }
3542 + ?>
3543 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3544 +
3545 + <?php
3546 +
3547 + if ( ! is_admin() ) {
3548 + ?>
3549 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3550 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3551 + <?php
3552 + if ( $field->is_required ) {
3553 + echo '<span>*</span>';
3554 + }
3555 + ?>
3556 + </label>
3557 + <?php } ?>
3558 +
3559 + <?php wp_editor( $content, $editor_id, $args ); ?>
3560 +
3561 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3562 + <?php if ( $field->is_required ) { ?>
3563 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3564 + <?php } ?>
3565 + </div>
3566 + <?php
3567 + }
3568 + $html = ob_get_clean();
3569 + }
3570 +
3571 + return $html;
3572 + }
3573 +
3574 + /**
3575 + * Form field template for fieldset field type.
3576 + *
3577 + * @param string $html Form field html
3578 + * @param object $field Field info.
3579 + * @param string $value Form field default value.
3580 + * @param string $form_type Form type
3581 + *
3582 + * @return string Modified form field html.
3583 + * @package userswp
3584 + *
3585 + * @since 1.0.0
3586 + */
3587 + public function form_input_fieldset( $html, $field, $value, $form_type ) {
3588 + // Check if there is a custom field specific filter.
3589 + if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3590 + $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3591 + }
3592 +
3593 + // If no html then we run the standard output.
3594 + if ( empty( $html ) ) {
3595 +
3596 + ob_start(); // Start buffering;
3597 + $site_title = uwp_get_form_label( $field );
3598 + ?>
3599 + <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3600 + <?php echo esc_html( $site_title ); ?>
3601 + <?php
3602 + if ( $field->help_text != '' ) {
3603 + echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3604 + }
1860 3605 ?>
1861 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1862 - <?php if ($field->is_required) { ?>
1863 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1864 - <?php } ?>
1865 - </div>
1866 - <?php
1867 - $html = ob_get_clean();
1868 - }
3606 + </h3>
3607 + <?php
3608 + $html = ob_get_clean();
3609 + }
1869 3610
1870 - return $html;
1871 - }
3611 + return $html;
3612 + }
1872 3613
1873 - /**
1874 - * Form field template for text field type.
1875 - *
1876 - * @since 1.0.0
1877 - * @package userswp
1878 - *
1879 - * @param string $html Form field html
1880 - * @param object $field Field info.
1881 - * @param string $value Form field default value.
1882 - * @param string $form_type Form type
1883 - *
1884 - * @return string Modified form field html.
1885 - */
1886 - public function uwp_form_input_text($html, $field, $value, $form_type){
3614 + /**
3615 + * Form field template for url field type.
3616 + *
3617 + * @param string $html Form field html
3618 + * @param object $field Field info.
3619 + * @param string $value Form field default value.
3620 + * @param string $form_type Form type
3621 + *
3622 + * @return string Modified form field html.
3623 + * @package userswp
3624 + *
3625 + * @since 1.0.0
3626 + */
3627 + public function form_input_url( $html, $field, $value, $form_type ) {
1887 3628
1888 - // Check if there is a custom field specific filter.
1889 - if(has_filter("uwp_form_input_text_{$field->htmlvar_name}")){
1890 - $html = apply_filters("uwp_form_input_text_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1891 - }
3629 + // Check if there is a custom field specific filter.
3630 + if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
3631 + $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3632 + }
1892 3633
1893 - // If no html then we run the standard output.
1894 - if(empty($html)) {
3634 + // If no html then we run the standard output.
3635 + if ( empty( $html ) ) {
1895 3636
1896 - ob_start(); // Start buffering;
3637 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3638 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3639 + $bs_sr_only = $design_style ? 'sr-only' : '';
3640 + $bs_form_control = $design_style ? 'form-control' : '';
1897 3641
1898 - $type = 'text';
1899 - $step = false;
1900 - //number and float validation $validation_pattern
1901 - if(isset($field->data_type) && $field->data_type == 'INT'){
1902 - $type = 'number';
1903 - } elseif(isset($field->data_type) && $field->data_type == 'FLOAT'){
1904 - $dp = $field->decimal_point;
1905 - switch ($dp) {
1906 - case "1":
1907 - $step = "0.1";
1908 - break;
1909 - case "2":
1910 - $step = "0.01";
1911 - break;
1912 - case "3":
1913 - $step = "0.001";
1914 - break;
1915 - case "4":
1916 - $step = "0.0001";
1917 - break;
1918 - case "5":
1919 - $step = "0.00001";
1920 - break;
1921 - case "6":
1922 - $step = "0.000001";
1923 - break;
1924 - case "7":
1925 - $step = "0.0000001";
1926 - break;
1927 - case "8":
1928 - $step = "0.00000001";
1929 - break;
1930 - case "9":
1931 - $step = "0.000000001";
1932 - break;
1933 - case "10":
1934 - $step = "0.0000000001";
1935 - break;
1936 - default:
1937 - $step = "0.01";
1938 - break;
1939 - }
1940 - $type = 'number';
1941 - }
3642 + ob_start(); // Start buffering;
3643 + $site_title = uwp_get_form_label( $field );
3644 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
3645 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1942 3646
1943 - ?>
3647 + // bootstrap
3648 + if ( $design_style ) {
3649 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1944 3650
1945 - <div id="<?php echo $field->htmlvar_name;?>_row"
1946 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
3651 + echo aui()->input(
3652 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3653 + 'type' => 'url',
3654 + 'id' => esc_attr( $field->htmlvar_name ),
3655 + 'name' => esc_attr( $field->htmlvar_name ),
3656 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3657 + 'title' => esc_html( $site_title ),
3658 + 'value' => esc_attr( $value ),
3659 + 'required' => (bool) $field->is_required,
3660 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3661 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3662 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3663 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3664 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3665 + )
3666 + );
3667 + } else {
3668 + ?>
3669 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3670 + class="
3671 + <?php
3672 + if ( $field->is_required ) {
3673 + echo 'required_field';
3674 + }
3675 + ?>
3676 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1947 3677
1948 - <?php
1949 - $site_title = uwp_get_form_label($field);
1950 - $manual_label = apply_filters('uwp_login_username_label_manual', true);
1951 - if ($manual_label
1952 - && isset($field->form_type)
1953 - && $field->form_type == 'login'
1954 - && $field->htmlvar_name == 'uwp_login_username') {
1955 - $site_title = __("Username or Email", 'userswp');
1956 - }
1957 - if (!is_admin()) { ?>
1958 - <label>
1959 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1960 - <?php if ($field->is_required) echo '<span>*</span>';?>
1961 - </label>
1962 - <?php } ?>
3678 + <?php
3679 + if ( ! is_admin() ) {
3680 + ?>
3681 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3682 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3683 + <?php
3684 + if ( $field->is_required ) {
3685 + echo '<span>*</span>';
3686 + }
3687 + ?>
3688 + </label>
3689 + <?php } ?>
1963 3690
1964 - <input name="<?php echo $field->htmlvar_name;?>"
1965 - class="<?php echo $field->css_class; ?> uwp_textfield"
1966 - id="<?php echo $field->htmlvar_name;?>"
1967 - placeholder="<?php echo $site_title; ?>"
1968 - value="<?php echo esc_attr(stripslashes($value));?>"
1969 - title="<?php echo $site_title; ?>"
1970 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
1971 - oninput="setCustomValidity('')"
1972 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1973 - <?php if ($field->for_admin_use == 1) { echo 'readonly="readonly"'; } ?>
1974 - type="<?php echo $type; ?>"
1975 - <?php if ($step) { echo 'step="'.$step.'"'; } ?>
1976 - />
1977 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1978 - <?php if ($field->is_required) { ?>
1979 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1980 - <?php } ?>
1981 - </div>
3691 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3692 + class="
3693 + <?php
3694 + //echo $field->css_class;
3695 + ?>
3696 + uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3697 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3698 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3699 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3700 + title="<?php echo esc_attr( $site_title ); ?>"
3701 + <?php
3702 + if ( $field->is_required == 1 ) {
3703 + echo 'required="required"';
3704 + }
3705 + ?>
3706 + type="url"
3707 + oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
3708 + onchange="try{setCustomValidity('')}catch(e){}"
3709 + />
3710 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3711 + <?php if ( $field->is_required ) { ?>
3712 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3713 + <?php } ?>
3714 + </div>
1982 3715
3716 + <?php
3717 + }
1983 3718
1984 - <?php
1985 - $html = ob_get_clean();
1986 - }
3719 + $html = ob_get_clean();
3720 + }
1987 3721
1988 - return $html;
1989 - }
3722 + return $html;
3723 + }
1990 3724
1991 - /**
1992 - * Form field template for textarea field type.
1993 - *
1994 - * @since 1.0.0
1995 - * @package userswp
1996 - *
1997 - * @param string $html Form field html
1998 - * @param object $field Field info.
1999 - * @param string $value Form field default value.
2000 - * @param string $form_type Form type
2001 - *
2002 - * @return string Modified form field html.
2003 - */
2004 - public function uwp_form_input_textarea($html, $field, $value, $form_type){
3725 + /**
3726 + * Form field template for email field type.
3727 + *
3728 + * @param string $html Form field html
3729 + * @param object $field Field info.
3730 + * @param string $value Form field default value.
3731 + * @param string $form_type Form type
3732 + *
3733 + * @return string Modified form field html.
3734 + * @package userswp
3735 + *
3736 + * @since 1.0.0
3737 + */
3738 + public function form_input_email( $html, $field, $value, $form_type ) {
2005 3739
2006 - // Check if there is a field specific filter.
2007 - if(has_filter("uwp_form_input_textarea_{$field->htmlvar_name}")){
2008 - $html = apply_filters("uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2009 - }
3740 + // Check if there is a custom field specific filter.
3741 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
3742 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3743 + }
2010 3744
2011 - // If no html then we run the standard output.
2012 - if(empty($html)) {
3745 + // If no html then we run the standard output.
3746 + if ( empty( $html ) ) {
2013 3747
2014 - ob_start(); // Start buffering;
3748 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3749 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3750 + $bs_sr_only = $design_style ? 'sr-only' : '';
3751 + $bs_form_control = $design_style ? 'form-control' : '';
2015 3752
2016 - ?>
2017 - <div id="<?php echo $field->htmlvar_name;?>_row"
2018 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
3753 + ob_start(); // Start buffering;
3754 + $site_title = uwp_get_form_label( $field );
3755 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3756 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2019 3757
2020 - <?php
2021 - $site_title = uwp_get_form_label($field);
2022 - if (!is_admin()) { ?>
2023 - <label>
2024 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2025 - <?php if ($field->is_required) echo '<span>*</span>';?>
2026 - </label>
2027 - <?php } ?>
3758 + if ( $design_style ) {
3759 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2028 3760
2029 - <textarea name="<?php echo $field->htmlvar_name; ?>"
2030 - class="<?php echo $field->css_class; ?>"
2031 - placeholder="<?php echo $site_title; ?>"
2032 - title="<?php echo $site_title; ?>"
2033 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
2034 - oninput="setCustomValidity('')"
2035 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2036 - type="<?php echo $field->field_type; ?>"
2037 - rows="4"><?php echo stripslashes($value); ?></textarea>
2038 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2039 - <?php if ($field->is_required) { ?>
2040 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2041 - <?php } ?>
2042 - </div>
3761 + echo aui()->input(
3762 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3763 + 'type' => 'email',
3764 + 'id' => esc_attr( $field->htmlvar_name ),
3765 + 'name' => esc_attr( $field->htmlvar_name ),
3766 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3767 + 'title' => esc_html( $site_title ),
3768 + 'value' => esc_attr( wp_unslash( $value ) ),
3769 + 'required' => (bool) $field->is_required,
3770 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3771 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3772 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3773 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3774 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3775 + )
3776 + );
3777 + } else {
3778 + ?>
3779 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3780 + class="
3781 + <?php
3782 + if ( $field->is_required ) {
3783 + echo 'required_field';
3784 + }
3785 + ?>
3786 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2043 3787
2044 - <?php
2045 - $html = ob_get_clean();
2046 - }
3788 + <?php
3789 + if ( ! is_admin() ) {
3790 + ?>
3791 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3792 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3793 + <?php
3794 + if ( $field->is_required ) {
3795 + echo '<span>*</span>';
3796 + }
3797 + ?>
3798 + </label>
3799 + <?php } ?>
2047 3800
2048 - return $html;
2049 - }
3801 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3802 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3803 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3804 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3805 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3806 + title="<?php echo esc_attr( $site_title ); ?>"
3807 + <?php
3808 + if ( $field->is_required == 1 ) {
3809 + echo 'required="required"';
3810 + }
3811 + ?>
3812 + type="email"
3813 + />
3814 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3815 + <?php if ( $field->is_required ) { ?>
3816 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3817 + <?php } ?>
3818 + </div>
2050 3819
2051 - /**
2052 - * Form field template for fieldset field type.
2053 - *
2054 - * @since 1.0.0
2055 - * @package userswp
2056 - *
2057 - * @param string $html Form field html
2058 - * @param object $field Field info.
2059 - * @param string $value Form field default value.
2060 - * @param string $form_type Form type
2061 - *
2062 - * @return string Modified form field html.
2063 - */
2064 - public function uwp_form_input_fieldset($html, $field, $value, $form_type) {
2065 - // Check if there is a custom field specific filter.
2066 - if(has_filter("uwp_form_input_fieldset_{$field->htmlvar_name}")){
2067 - $html = apply_filters("uwp_form_input_fieldset_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2068 - }
2069 3820
2070 - // If no html then we run the standard output.
2071 - if(empty($html)) {
3821 + <?php
3822 + }
3823 + $html = ob_get_clean();
2072 3824
2073 - ob_start(); // Start buffering;
2074 - ?>
2075 - <h3 class="uwp_input_fieldset <?php echo $field->css_class; ?>">
2076 - <?php echo $field->site_title;; ?>
2077 - <?php if ( $field->help_text != '' ) {
2078 - echo '<small>( ' . $field->help_text . ' )</small>';
2079 - } ?></h3>
2080 - <?php
2081 - $html = ob_get_clean();
2082 - }
3825 + }
2083 3826
2084 - return $html;
2085 - }
3827 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
3828 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3829 + }
2086 3830
2087 - /**
2088 - * Form field template for url field type.
2089 - *
2090 - * @since 1.0.0
2091 - * @package userswp
2092 - *
2093 - * @param string $html Form field html
2094 - * @param object $field Field info.
2095 - * @param string $value Form field default value.
2096 - * @param string $form_type Form type
2097 - *
2098 - * @return string Modified form field html.
2099 - */
2100 - public function uwp_form_input_url($html, $field, $value, $form_type){
3831 + return $html;
3832 + }
2101 3833
3834 + /**
3835 + * Form field template for password field type.
3836 + *
3837 + * @param string $html Form field html
3838 + * @param object $field Field info.
3839 + * @param string $value Form field default value.
3840 + * @param string $form_type Form type
3841 + *
3842 + * @return string Modified form field html.
3843 + * @package userswp
3844 + *
3845 + * @since 1.0.0
3846 + */
3847 + public function form_input_password( $html, $field, $value, $form_type ) {
2102 3848
2103 - // Check if there is a custom field specific filter.
2104 - if(has_filter("uwp_form_input_url_{$field->htmlvar_name}")){
2105 - $html = apply_filters("uwp_form_input_url_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2106 - }
3849 + // Check if there is a custom field specific filter.
3850 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
3851 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3852 + }
2107 3853
2108 - // If no html then we run the standard output.
2109 - if(empty($html)) {
3854 + // If no html then we run the standard output.
3855 + if ( empty( $html ) ) {
2110 3856
2111 - ob_start(); // Start buffering;
2112 - ?>
2113 - <div id="<?php echo $field->htmlvar_name;?>_row"
2114 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
3857 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3858 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3859 + $bs_sr_only = $design_style ? 'sr-only' : '';
3860 + $bs_form_control = $design_style ? 'form-control' : '';
2115 3861
2116 - <?php
2117 - $site_title = uwp_get_form_label($field);
2118 - if (!is_admin()) { ?>
2119 - <label>
2120 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2121 - <?php if ($field->is_required) echo '<span>*</span>';?>
2122 - </label>
2123 - <?php } ?>
3862 + ob_start(); // Start buffering;
3863 + $site_title = uwp_get_form_label( $field );
2124 3864
2125 - <input name="<?php echo $field->htmlvar_name;?>"
2126 - class="<?php echo $field->css_class; ?> uwp_textfield"
2127 - id="<?php echo $field->htmlvar_name;?>"
2128 - placeholder="<?php echo $site_title; ?>"
2129 - value="<?php echo esc_attr(stripslashes($value));?>"
2130 - title="<?php echo $site_title; ?>"
2131 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2132 - type="url"
2133 - oninvalid="setCustomValidity('<?php _e('Please enter a valid URL including http://', 'userswp'); ?>')"
2134 - onchange="try{setCustomValidity('')}catch(e){}"
2135 - />
2136 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2137 - <?php if ($field->is_required) { ?>
2138 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2139 - <?php } ?>
2140 - </div>
3865 + if ( $design_style ) {
3866 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3867 + $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3868 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3869 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
2141 3870
2142 - <?php
2143 - $html = ob_get_clean();
2144 - }
3871 + echo aui()->input(
3872 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3873 + 'type' => 'password',
3874 + 'id' => esc_attr( $field->htmlvar_name ),
3875 + 'name' => esc_attr( $field->htmlvar_name ),
3876 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3877 + 'title' => esc_html( $site_title ),
3878 + 'value' => esc_attr( $value ),
3879 + 'required' => (bool) $field->is_required,
3880 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3881 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3882 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3883 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3884 + 'wrap_class' => esc_attr( $wrap_class ),
3885 + )
3886 + );
3887 + } else {
3888 + ?>
3889 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3890 + <?php
3891 + if ( $field->is_required ) {
3892 + echo 'required_field';
3893 + }
3894 + ?>
3895 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3896 + <?php
3897 + if ( ! is_admin() ) {
3898 + ?>
3899 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3900 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3901 + <?php
3902 + if ( $field->is_required ) {
3903 + echo '<span>*</span>';
3904 + }
3905 + ?>
3906 + </label>
3907 + <?php } ?>
2145 3908
2146 - return $html;
2147 - }
3909 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3910 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3911 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3912 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3913 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3914 + title="<?php echo esc_attr( $site_title ); ?>"
3915 + <?php
3916 + if ( $field->is_required == 1 ) {
3917 + echo 'required="required"';
3918 + }
3919 + ?>
3920 + type="password"
3921 + />
3922 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3923 + <?php if ( $field->is_required ) { ?>
3924 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3925 + <?php } ?>
3926 + </div>
2148 3927
2149 - /**
2150 - * Form field template for email field type.
2151 - *
2152 - * @since 1.0.0
2153 - * @package userswp
2154 - *
2155 - * @param string $html Form field html
2156 - * @param object $field Field info.
2157 - * @param string $value Form field default value.
2158 - * @param string $form_type Form type
2159 - *
2160 - * @return string Modified form field html.
2161 - */
2162 - public function uwp_form_input_email($html, $field, $value, $form_type){
2163 3928
3929 + <?php
3930 + }
2164 3931
2165 - // Check if there is a custom field specific filter.
2166 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}")){
2167 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2168 - }
3932 + $html = ob_get_clean();
3933 + }
2169 3934
2170 - // If no html then we run the standard output.
2171 - if(empty($html)) {
3935 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
3936 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3937 + }
2172 3938
2173 - ob_start(); // Start buffering;
2174 - ?>
2175 - <div id="<?php echo $field->htmlvar_name;?>_row"
2176 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
3939 + return $html;
3940 + }
2177 3941
2178 - <?php
2179 - $site_title = uwp_get_form_label($field);
2180 - if (!is_admin()) { ?>
2181 - <label>
2182 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2183 - <?php if ($field->is_required) echo '<span>*</span>';?>
2184 - </label>
2185 - <?php } ?>
3942 + /**
3943 + * Form field template for Phone field.
3944 + *
3945 + * @param string $html Form field html
3946 + * @param object $field Field info.
3947 + * @param string $value Form field default value.
3948 + * @param string $form_type Form type
3949 + *
3950 + * @return string $html Modified form field html.
3951 + * @since 1.0.0
3952 + *
3953 + */
3954 + public function form_input_phone( $html, $field, $value, $form_type ) {
3955 + if ( empty( $html ) ) {
3956 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3957 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3958 + $bs_sr_only = $design_style ? 'sr-only' : '';
3959 + $bs_form_control = $design_style ? 'form-control' : '';
3960 + ob_start(); // Start buffering;
3961 + $site_title = uwp_get_form_label( $field );
3962 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3963 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2186 3964
2187 - <input name="<?php echo $field->htmlvar_name;?>"
2188 - class="<?php echo $field->css_class; ?> uwp_textfield"
2189 - id="<?php echo $field->htmlvar_name;?>"
2190 - placeholder="<?php echo $site_title; ?>"
2191 - value="<?php echo esc_attr(stripslashes($value));?>"
2192 - title="<?php echo $site_title; ?>"
2193 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2194 - type="email"
2195 - />
2196 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2197 - <?php if ($field->is_required) { ?>
2198 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2199 - <?php } ?>
2200 - </div>
3965 + if ( $design_style ) {
3966 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2201 3967
3968 + echo aui()->input(
3969 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3970 + 'type' => 'tel',
3971 + 'id' => esc_attr( $field->htmlvar_name ),
3972 + 'name' => esc_attr( $field->htmlvar_name ),
3973 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3974 + 'title' => esc_html( $site_title ),
3975 + 'value' => esc_attr( $value ),
3976 + 'required' => (bool) $field->is_required,
3977 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3978 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3979 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3980 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3981 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3982 + )
3983 + );
3984 + } else {
3985 + ?>
3986 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3987 + class="
3988 + <?php
3989 + if ( $field->is_required ) {
3990 + echo 'required_field';
3991 + }
3992 + ?>
3993 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3994 + <?php
3995 + if ( ! is_admin() ) {
3996 + ?>
3997 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3998 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3999 + <?php
4000 + if ( $field->is_required ) {
4001 + echo '<span>*</span>';
4002 + }
4003 + ?>
4004 + </label>
4005 + <?php } ?>
4006 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4007 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4008 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4009 + title="<?php echo esc_attr( $site_title ); ?>"
4010 + <?php
4011 + if ( $field->for_admin_use == 1 ) {
4012 + echo 'readonly="readonly"';
4013 + }
4014 + ?>
4015 + <?php
4016 + if ( $field->is_required == 1 ) {
4017 + echo 'required="required"';
4018 + }
4019 + ?>
4020 + type="tel"
4021 + value="<?php echo esc_html( $value ); ?>">
4022 + </div>
4023 + <?php
4024 + }
4025 + $html = ob_get_clean();
4026 + }
2202 4027
2203 - <?php
2204 - $html = ob_get_clean();
2205 - }
4028 + return $html;
4029 + }
2206 4030
2207 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}_after")){
2208 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2209 - }
4031 + public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
2210 4032
2211 - return $html;
2212 - }
4033 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4034 + $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4035 + if ( empty( $reg_gdpr ) ) {
4036 + $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4037 + }
2213 4038
2214 - /**
2215 - * Form field template for password field type.
2216 - *
2217 - * @since 1.0.0
2218 - * @package userswp
2219 - *
2220 - * @param string $html Form field html
2221 - * @param object $field Field info.
2222 - * @param string $value Form field default value.
2223 - * @param string $form_type Form type
2224 - *
2225 - * @return string Modified form field html.
2226 - */
2227 - public function uwp_form_input_password($html, $field, $value, $form_type){
4039 + if ( ! empty( $reg_gdpr ) ) {
2228 4040
4041 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4042 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4043 + $bs_form_control = $design_style ? 'form-check-input' : '';
4044 + $site_title = uwp_get_form_label( $field );
4045 + $field->htmlvar_name = 'register_gdpr';
4046 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2229 4047
2230 - // Check if there is a custom field specific filter.
2231 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}")){
2232 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2233 - }
4048 + $gdpr_page = get_permalink( $reg_gdpr );
4049 + $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4050 + $link_end = '</a>';
4051 + $field_desc = uwp_get_field_description( $field, '' );
4052 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4053 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4054 + $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4055 + $checked = $value == '1' ? true : false;
2234 4056
2235 - // If no html then we run the standard output.
2236 - if(empty($html)) {
4057 + ob_start(); // Start buffering;
2237 4058
2238 - ob_start(); // Start buffering;
2239 - ?>
2240 - <div id="<?php echo $field->htmlvar_name;?>_row"
2241 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row">
4059 + // bootstrap
4060 + if ( $design_style ) {
4061 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4062 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2242 4063
2243 - <?php
2244 - $site_title = uwp_get_form_label($field);
2245 - if (!is_admin()) { ?>
2246 - <label>
2247 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2248 - <?php if ($field->is_required) echo '<span>*</span>';?>
2249 - </label>
2250 - <?php } ?>
4064 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4065 + array(
4066 + 'id' => esc_attr( $id ),
4067 + 'name' => esc_attr( $field->htmlvar_name ),
4068 + 'type' => 'checkbox',
4069 + 'value' => '1',
4070 + 'title' => esc_html( $site_title ),
4071 + 'label' => wp_kses_post( $content . $required ),
4072 + 'label_show' => true,
4073 + 'required' => ! empty( $field->is_required ) ? true : false,
4074 + 'checked' => (bool) $checked,
4075 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4076 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4077 + )
4078 + );
2251 4079
2252 - <input name="<?php echo $field->htmlvar_name;?>"
2253 - class="<?php echo $field->css_class; ?> uwp_textfield"
2254 - id="<?php echo $field->htmlvar_name;?>"
2255 - placeholder="<?php echo $site_title; ?>"
2256 - value="<?php echo esc_attr(stripslashes($value));?>"
2257 - title="<?php echo $site_title; ?>"
2258 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2259 - type="password"
2260 - />
2261 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2262 - <?php if ($field->is_required) { ?>
2263 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2264 - <?php } ?>
2265 - </div>
4080 + } else {
4081 + ?>
4082 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4083 + class="
4084 + <?php
4085 + if ( $field->is_required ) {
4086 + echo 'required_field';
4087 + }
4088 + ?>
4089 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4090 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4091 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4092 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4093 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4094 + title="<?php echo esc_attr( $site_title ); ?>"
4095 + <?php
4096 + if ( $value == '1' ) {
4097 + echo 'checked="checked"';
4098 + }
4099 + ?>
4100 + type="<?php echo esc_attr( $field->field_type ); ?>"
4101 + value="1">
4102 + <?php
4103 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4104 + ?>
4105 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4106 + <?php if ( $field->is_required ) { ?>
4107 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4108 + <?php } ?>
4109 + </div>
2266 4110
4111 + <?php
4112 + }
2267 4113
2268 - <?php
2269 - $html = ob_get_clean();
2270 - }
4114 + $html = ob_get_clean();
2271 4115
2272 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}_after")){
2273 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2274 - }
4116 + } else {
4117 + $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4118 + }
2275 4119
2276 - return $html;
2277 - }
4120 + return $html;
4121 + }
2278 4122
2279 - /**
2280 - * Adds enctype tag in form for file fields.
2281 - *
2282 - * @since 1.0.0
2283 - * @package userswp
2284 - *
2285 - * @return void
2286 - */
2287 - function add_multipart_to_admin_edit_form() {
2288 - global $wpdb;
2289 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2290 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2291 - if ($fields) {
2292 - echo 'enctype="multipart/form-data"';
2293 - }
2294 - }
4123 + public function form_input_register_tos( $html, $field, $value, $form_type ) {
2295 4124
2296 - /**
2297 - * Handles UsersWP custom field requests from admin.
2298 - *
2299 - * @since 1.0.0
2300 - * @package userswp
2301 - *
2302 - * @param int $user_id User ID.
2303 - *
2304 - * @return void
2305 - */
2306 - public function update_profile_extra_admin_edit($user_id) {
2307 - global $wpdb;
2308 - $file_obj = new UsersWP_Files();
2309 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2310 - //Normal fields
2311 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC");
2312 - if ($fields) {
2313 - $_POST['uwp_account_first_name'] = $_POST['first_name'];
2314 - $_POST['uwp_account_last_name'] = $_POST['last_name'];
2315 - $_POST['uwp_account_display_name'] = $_POST['nickname'];
2316 - $_POST['uwp_account_email'] = $_POST['email'];
2317 - $_POST['uwp_account_bio'] = $_POST['description'];
2318 - $result = uwp_validate_fields($_POST, 'account', $fields);
2319 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
2320 - $display_name = $result['uwp_account_display_name'];
2321 - } else {
2322 - if (!empty($first_name) || !empty($last_name)) {
2323 - $display_name = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
2324 - } else {
2325 - $user_info = get_userdata($user_id);
2326 - $display_name = $user_info->user_login;
2327 - }
2328 - }
2329 - $result['uwp_account_display_name'] = $display_name;
2330 - if (!is_wp_error($result)) {
2331 - foreach ($fields as $field) {
2332 - $value = isset($result[$field->htmlvar_name]) ? $result[$field->htmlvar_name] : '';
2333 - if ($value == '0' || !empty($value)) {
2334 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2335 - }
2336 - }
2337 - }
2338 - }
4125 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4126 + $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4127 + if ( empty( $reg_tos ) ) {
4128 + $reg_tos = uwp_get_option( 'register_terms_page', false );
4129 + }
2339 4130
2340 - //File fields
2341 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2342 - if ($fields) {
2343 - $result = $file_obj->uwp_validate_uploads($_FILES, 'account', true, $fields);
2344 - if (!is_wp_error($result)) {
2345 - foreach ($fields as $field) {
2346 - $value = $result[$field->htmlvar_name];
2347 - if ($value == '0' || !empty($value)) {
2348 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2349 - }
2350 - }
2351 - }
2352 - }
2353 - }
4131 + if ( ! empty( $reg_tos ) ) {
2354 4132
4133 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4134 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4135 + $bs_form_control = $design_style ? 'form-check-input' : '';
2355 4136
2356 - /**
2357 - * Adds search form keyword input html.
2358 - *
2359 - * @since 1.0.0
2360 - * @package userswp
2361 - *
2362 - * @param string $keyword Search keyword.
2363 - *
2364 - * @return void
2365 - */
2366 - public function uwp_users_search_form_text_field($keyword) {
2367 - ?>
2368 - <input placeholder="Search For" name="uwps" value="<?php echo $keyword; ?>" class="s search-input" type="text">
2369 - <?php
2370 - }
4137 + $site_title = uwp_get_form_label( $field );
4138 + $terms_page = get_permalink( $reg_tos );
4139 + $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4140 + $link_end = '</a>';
4141 + $field_desc = uwp_get_field_description( $field, '' );
4142 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4143 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4144 + $field->htmlvar_name = 'register_tos';
4145 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2371 4146
2372 - /**
2373 - * Adds search form submit button html.
2374 - *
2375 - * @since 1.0.0
2376 - * @package userswp
2377 - *
2378 - * @return void
2379 - */
2380 - public function uwp_users_search_form_submit() {
2381 - ?>
2382 - <input class="uwp-searchsubmit uwp-search-submit" value="Search" type="submit">
2383 - <?php
2384 - }
4147 + $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4148 + $checked = $value == '1' ? true : false;
2385 4149
2386 - /**
2387 - * Checks for errors in mail submission.
2388 - *
2389 - * @since 1.0.0
2390 - * @package userswp
2391 - *
2392 - * @param array $res Result array.
2393 - * @param object $user_data User object.
2394 - * @param WP_Error $errors Error object
2395 - *
2396 - * @return WP_Error|array Error object when error. Result array when success.
2397 - */
2398 - public function uwp_forms_check_for_send_mail_errors($res, $user_data, $errors) {
2399 - if (!$res) {
2400 - if (get_option('admin_email') == $user_data->user_email) {
2401 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please check your site error log for more details.', 'userswp'));
2402 - } else {
2403 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
2404 - }
2405 - }
4150 + ob_start();
2406 4151
2407 - $error_code = $errors->get_error_code();
2408 - if (!empty($error_code)) {
2409 - return $errors;
2410 - } else {
2411 - return $res;
2412 - }
2413 -
2414 - }
4152 + if ( $design_style ) {
4153 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4154 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2415 4155
2416 - /**
2417 - * Form field template for country field.
2418 - *
2419 - * @since 1.0.0
2420 - * @package userswp
2421 - *
2422 - * @param string $html Form field html
2423 - * @param object $field Field info.
2424 - * @param string $value Form field default value.
2425 - * @param string $form_type Form type
2426 - *
2427 - * @return string Modified form field html.
2428 - */
2429 - public function uwp_form_input_select_country($html, $field, $value, $form_type){
4156 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4157 + array(
4158 + 'id' => esc_attr( $id ),
4159 + 'name' => esc_attr( $field->htmlvar_name ),
4160 + 'type' => 'checkbox',
4161 + 'value' => '1',
4162 + 'title' => esc_html( $site_title ),
4163 + 'label' => wp_kses_post( $content . $required ),
4164 + 'label_show' => true,
4165 + 'required' => ! empty( $field->is_required ) ? true : false,
4166 + 'checked' => (bool) $checked,
4167 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4168 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4169 + )
4170 + );
2430 4171
2431 - // Check if there is a field specific filter.
2432 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
2433 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2434 - }
4172 + } else {
4173 + ?>
4174 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4175 + class="
4176 + <?php
4177 + if ( $field->is_required ) {
4178 + echo 'required_field';
4179 + }
4180 + ?>
4181 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4182 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4183 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4184 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4185 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4186 + title="<?php echo esc_attr( $site_title ); ?>"
4187 + <?php
4188 + if ( $value == '1' ) {
4189 + echo 'checked="checked"';
4190 + }
4191 + ?>
4192 + type="<?php echo esc_attr( $field->field_type ); ?>"
4193 + value="1">
4194 + <?php
4195 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4196 + ?>
4197 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4198 + <?php if ( $field->is_required ) { ?>
4199 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4200 + <?php } ?>
4201 + </div>
2435 4202
2436 - //print_r($field);
4203 + <?php
2437 4204
2438 - // If no html then we run the standard output.
2439 - if(empty($html)) {
4205 + }
2440 4206
2441 - ob_start(); // Start buffering;
4207 + $html = ob_get_clean();
2442 4208
2443 - ?>
2444 - <div id="<?php echo $field->htmlvar_name;?>_row"
2445 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row">
4209 + } else {
4210 + $html = '<input type="hidden" name="register_tos" value="-1"/>';
4211 + }
2446 4212
4213 + return $html;
4214 + }
4215 +
4216 + /**
4217 + * Adds enctype tag in form for file fields.
4218 + *
4219 + * @return void
4220 + * @package userswp
4221 + *
4222 + * @since 1.0.0
4223 + */
4224 + function add_multipart_to_admin_edit_form() {
4225 + global $wpdb;
4226 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4227 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4228 + if ( $fields ) {
4229 + echo 'enctype="multipart/form-data"';
4230 + }
4231 + }
4232 +
4233 + /**
4234 + * Handles UsersWP custom field requests from admin.
4235 + *
4236 + * @param int $user_id User ID.
4237 + *
4238 + * @return void
4239 + * @since 1.0.0
4240 + * @package userswp
4241 + *
4242 + */
4243 + public function update_profile_extra_admin_edit( $user_id ) {
4244 + global $wpdb;
4245 + $file_obj = new UsersWP_Files();
4246 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4247 + //Normal fields
4248 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4249 + if ( $fields ) {
4250 + if ( isset( $_POST['locale'] ) ) {
4251 + $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4252 + }
4253 + $result = uwp_validate_fields( $_POST, 'account', $fields );
4254 + if ( is_wp_error( $result ) ) {
4255 + die( wp_kses_post( $result->get_error_message() ) );
4256 + }
4257 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4258 + $display_name = $result['display_name'];
4259 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4260 + $display_name = $result['first_name'] . ' ' . $result['last_name'];
4261 + } else {
4262 + $user_info = get_userdata( $user_id );
4263 + $display_name = $user_info->user_login;
4264 + }
4265 + $result['display_name'] = $display_name;
4266 + if ( ! is_wp_error( $result ) ) {
4267 + foreach ( $fields as $field ) {
4268 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4269 + if ( $value == '0' || ! empty( $value ) ) {
4270 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4271 + }
4272 + }
4273 + }
4274 + }
4275 +
4276 + //File fields
4277 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4278 + if ( $fields ) {
4279 + $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4280 + if ( ! is_wp_error( $result ) ) {
4281 + foreach ( $fields as $field ) {
4282 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4283 + if ( $value == '0' || ! empty( $value ) ) {
4284 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4285 + }
4286 + }
4287 + }
4288 + }
4289 + }
4290 +
4291 + /**
4292 + * Form field template for country field.
4293 + *
4294 + * @param string $html Form field html
4295 + * @param object $field Field info.
4296 + * @param string $value Form field default value.
4297 + * @param string $form_type Form type
4298 + *
4299 + * @return string Modified form field html.
4300 + * @package userswp
4301 + *
4302 + * @since 1.0.0
4303 + */
4304 + public function form_input_select_country( $html, $field, $value, $form_type ) {
4305 +
4306 + // If no html then we run the standard output.
4307 + if ( empty( $html ) ) {
4308 +
4309 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4310 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4311 + $bs_sr_only = $design_style ? 'sr-only' : '';
4312 + $bs_form_control = $design_style ? 'form-control' : '';
4313 +
4314 + ob_start(); // Start buffering;
4315 + ?>
4316 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4317 +
4318 + <?php
4319 + $site_title = uwp_get_form_label( $field );
4320 +
4321 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4322 + ?>
4323 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4324 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4325 + <?php
4326 + if ( $field->is_required ) {
4327 + echo '<span class="text-danger">*</span>';
4328 + }
4329 + ?>
4330 + </label>
4331 + <?php
4332 + }
4333 + // if value empty set the default
4334 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4335 + $value = $field->default_value;
4336 + }
4337 + if ( $value === false ) {
4338 + $value = '';
4339 + }
4340 + $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4341 + $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4342 +
4343 + $htmlvar_name = $field->htmlvar_name;
4344 + if ( wp_doing_ajax() ) {
4345 + $htmlvar_name .= '_ajax';
4346 + }
4347 + ?>
4348 + <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4349 + <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4350 + <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4351 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4352 + <?php if ( $field->is_required ) { ?>
4353 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4354 + <?php } ?>
4355 + </div>
4356 + <?php
4357 + $html = ob_get_clean();
4358 + }
4359 +
4360 + return $html;
4361 + }
4362 +
4363 + /**
4364 + * Form field template for language field.
4365 + *
4366 + * @param string $html Form field html
4367 + * @param object $field Field info.
4368 + * @param string $value Form field default value.
4369 + * @param string $form_type Form type
4370 + *
4371 + * @return string Modified form field html.
4372 + * @package userswp
4373 + *
4374 + * @since 1.0.0
4375 + */
4376 + public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4377 +
4378 + // If no html then we run the standard output.
4379 + if ( empty( $html ) ) {
4380 +
4381 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4382 + $bs_form_group = $design_style ? 'form-group m-0' : '';
4383 + $bs_sr_only = $design_style ? 'sr-only' : '';
4384 + $bs_form_control = $design_style ? 'form-control' : '';
4385 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4386 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4387 +
4388 + ob_start(); // Start buffering;
4389 +
4390 + ?>
4391 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4392 + class="
2447 4393 <?php
2448 - $site_title = uwp_get_form_label($field);
2449 - if (!is_admin()) { ?>
2450 - <label>
2451 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2452 - <?php if ($field->is_required) echo '<span>*</span>';?>
4394 + if ( $field->is_required ) {
4395 + echo 'required_field';
4396 + }
4397 + ?>
4398 + uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4399 +
4400 + <?php
4401 + $site_title = uwp_get_form_label( $field );
4402 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4403 + ?>
4404 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4405 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4406 + <?php
4407 + if ( $field->is_required ) {
4408 + echo '<span class="text-danger">*</span>';
4409 + }
4410 + ?>
2453 4411 </label>
2454 - <?php } ?>
4412 + <?php } ?>
2455 4413
4414 + <?php
4415 + if ( empty( $field->default_value ) ) {
4416 + $field->default_value = 'site-default';
4417 + }
4418 +
4419 + // if value empty set the default
4420 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4421 + $value = $field->default_value;
4422 + }
4423 +
4424 + require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4425 + $translations = wp_get_available_translations();
4426 + $available_languages = get_available_languages();
4427 + $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
4428 +
4429 + foreach ( $available_languages as $locale ) {
4430 + if ( isset( $translations[ $locale ] ) ) {
4431 + $translation = $translations[ $locale ];
4432 + $languages[ $translation['language'] ] = $translation['native_name'];
4433 +
4434 + // Remove installed language from available translations.
4435 + unset( $translations[ $locale ] );
4436 + } else {
4437 + $languages[ $locale ] = $translation[ $locale ];
4438 + }
4439 + }
4440 +
4441 + if ( $design_style ) {
4442 +
4443 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4444 +
4445 + echo aui()->select(
4446 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4447 + 'id' => esc_attr( $field->htmlvar_name ),
4448 + 'name' => esc_attr( $field->htmlvar_name ),
4449 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4450 + 'title' => esc_attr( $site_title ),
4451 + 'value' => esc_attr( $value ),
4452 + 'required' => (bool) $field->is_required,
4453 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4454 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4455 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4456 + 'label' => wp_kses_post( $site_title . $required ),
4457 + 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4458 + 'select2' => true,
4459 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4460 + )
4461 + );
4462 + } else {
4463 + ?>
4464 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4465 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4466 + title="<?php echo esc_attr( $site_title ); ?>"
4467 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4468 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4469 + </select>
4470 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4471 + <?php if ( $field->is_required ) { ?>
4472 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2456 4473 <?php
2457 - // if value empty set the default
2458 - if($value=='' && isset($field->default_value) && $field->default_value){
2459 - $value = $field->default_value;
2460 - }
2461 - $select_country_options = apply_filters('uwp_form_input_select_country',"{defaultCountry: '$value'}",$field, $value, $form_type);
2462 - ?>
4474 + }
4475 + }
2463 4476
2464 - <input type="text" class="uwp_textfield" title="<?php echo $site_title; ?>" id="<?php echo $field->htmlvar_name;?>" />
2465 - <input type="hidden" id="<?php echo $field->htmlvar_name;?>_code" name="<?php echo $field->htmlvar_name;?>" />
4477 + $html = ob_get_clean();
4478 + }
2466 4479
2467 - <script>
2468 - jQuery("#<?php echo $field->htmlvar_name;?>").countrySelect(<?php echo $select_country_options;?>);
2469 - </script>
4480 + return $html;
4481 + }
2470 4482
4483 + /**
4484 + * Adds confirm password field in forms.
4485 + *
4486 + * @param string $html Form field html
4487 + * @param object $field Field info.
4488 + * @param string $value Form field default value.
4489 + * @param string $form_type Form type
4490 + *
4491 + * @return string Modified form field html.
4492 + * @package userswp
4493 + *
4494 + * @since 1.0.0
4495 + */
4496 + public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4497 + if ( $form_type == 'register' ) {
4498 + //confirm password field
4499 + $extra = array();
4500 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4501 + $extra = unserialize( $field->extra_fields );
4502 + }
2471 4503
2472 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2473 - <?php if ($field->is_required) { ?>
2474 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2475 - <?php } ?>
2476 - </div>
4504 + $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4505 + if ( $enable_confirm_password_field == '1' ) {
2477 4506
2478 - <?php
2479 - $html = ob_get_clean();
4507 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4508 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4509 + $bs_sr_only = $design_style ? 'sr-only' : '';
4510 + $bs_form_control = $design_style ? 'form-control' : '';
4511 + $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4512 + $required = '';
4513 + if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4514 + $placeholder .= ' *';
4515 + $required = ' <span class="text-danger">*</span>';
4516 + }
4517 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4518 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4519 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4520 +
4521 + ob_start(); // Start buffering;
4522 +
4523 + if ( $design_style ) {
4524 +
4525 + echo aui()->input(
4526 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4527 + 'type' => 'password',
4528 + 'id' => 'confirm_password',
4529 + 'name' => 'confirm_password',
4530 + 'placeholder' => esc_attr( $placeholder ),
4531 + 'title' => esc_attr( $site_title ),
4532 + 'value' => esc_attr( $value ),
4533 + 'required' => (bool) $field->is_required,
4534 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4535 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4536 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4537 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4538 + 'wrap_class' => esc_attr( $wrap_class ),
4539 + )
4540 + );
4541 + } else {
4542 + ?>
4543 + <div id="uwp_account_confirm_password_row"
4544 + class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4545 +
4546 + <?php
4547 +
4548 + if ( ! is_admin() ) {
4549 + ?>
4550 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4551 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4552 + <?php
4553 + if ( $field->is_required ) {
4554 + echo '<span>*</span>';
4555 + }
4556 + ?>
4557 + </label>
4558 + <?php } ?>
4559 + <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4560 + </div>
4561 +
4562 + <?php
4563 + }
4564 + $confirm_html = ob_get_clean();
4565 + $html = $html . $confirm_html;
4566 + }
4567 + }
4568 +
4569 + return $html;
4570 + }
4571 +
4572 + /**
4573 + * Adds confirm email field in forms.
4574 + *
4575 + * @param string $html Form field html
4576 + * @param object $field Field info.
4577 + * @param string $value Form field default value.
4578 + * @param string $form_type Form type
4579 + *
4580 + * @return string Modified form field html.
4581 + * @package userswp
4582 + *
4583 + * @since 1.0.0
4584 + */
4585 + public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4586 + if ( $form_type == 'register' ) {
4587 + //confirm email field
4588 + $extra = array();
4589 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4590 + $extra = unserialize( $field->extra_fields );
4591 + }
4592 + $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4593 + if ( $enable_confirm_email_field == '1' ) {
4594 +
4595 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4596 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4597 + $bs_sr_only = $design_style ? 'sr-only' : '';
4598 + $bs_form_control = $design_style ? 'form-control' : '';
4599 + $site_title = __( 'Confirm Email', 'userswp' );
4600 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4601 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4602 +
4603 + ob_start();
4604 +
4605 + if ( $design_style ) {
4606 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4607 +
4608 + echo aui()->input(
4609 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4610 + 'type' => 'email',
4611 + 'id' => esc_attr( $field->htmlvar_name ),
4612 + 'name' => 'confirm_email',
4613 + 'placeholder' => esc_attr( $site_title ),
4614 + 'title' => esc_attr( $site_title ),
4615 + 'value' => esc_attr( $value ),
4616 + 'required' => (bool) $field->is_required,
4617 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4618 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4619 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4620 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4621 + )
4622 + );
4623 + } else {
4624 + ?>
4625 + <div id="uwp_account_confirm_email_row"
4626 + class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4627 +
4628 + <?php
4629 +
4630 + if ( ! is_admin() ) {
4631 + ?>
4632 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4633 + <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
4634 + <?php
4635 + if ( $field->is_required ) {
4636 + echo '<span>*</span>';
4637 + }
4638 + ?>
4639 + </label>
4640 + <?php } ?>
4641 +
4642 + <input name="confirm_email"
4643 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4644 + id="uwp_account_confirm_email"
4645 + placeholder="<?php echo esc_attr( $site_title ); ?>"
4646 + value=""
4647 + title="<?php echo esc_attr( $site_title ); ?>"
4648 + <?php echo 'required="required"'; ?>
4649 + type="email"
4650 + />
4651 + </div>
4652 + <?php
4653 + }
4654 + $confirm_html = ob_get_clean();
4655 + $html = $html . $confirm_html;
4656 + }
4657 + }
4658 +
4659 + return $html;
4660 + }
4661 +
4662 + /**
4663 + * Handles the privacy form submission.
4664 + *
4665 + * @return void
4666 + * @package userswp
4667 + *
4668 + * @since 1.0.0
4669 + */
4670 + public function privacy_submit_handler() {
4671 + if ( isset( $_POST['uwp_privacy_submit'] ) ) {
4672 + if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
4673 + return;
4674 + }
4675 +
4676 + global $wpdb, $uwp_notices;
4677 +
4678 + // Save fields privacy settings
4679 + $extra_where = "AND is_public='2'";
4680 + $fields = get_account_form_fields( $extra_where );
4681 + $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
4682 + $user_id = get_current_user_id();
4683 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
4684 +
4685 + $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4686 + if ( ! empty( $user_meta_info->user_privacy ) ) {
4687 + $public_fields = explode( ',', $user_meta_info->user_privacy );
4688 + } else {
4689 + $public_fields = array();
4690 + }
4691 +
4692 + if ( $fields ) {
4693 +
4694 + foreach ( $fields as $field ) {
4695 + $field_name = $field->htmlvar_name . '_privacy';
4696 + $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4697 +
4698 + if ( $field_value == 'no' ) {
4699 + if ( ! in_array( $field_name, $public_fields ) ) {
4700 + $public_fields[] = $field_name;
4701 + }
4702 + } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
4703 + unset( $public_fields[ $field_name ] );
4704 + }
4705 + }
4706 +
4707 + $value = implode( ',', $public_fields );
4708 + uwp_update_usermeta( $user_id, 'user_privacy', $value );
4709 + }
4710 +
4711 + // Save tabs privacy settings
4712 + $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
4713 + $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4714 +
4715 + if ( $tabs ) {
4716 + $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
4717 + $do_tabs_update = false;
4718 + foreach ( $tabs as $tab ) {
4719 + $field_name = $tab->tab_key . '_tab_privacy';
4720 +
4721 + if ( isset( $_POST[ $field_name ] ) ) {
4722 + $do_tabs_update = true;
4723 + $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
4724 +
4725 + if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
4726 + unset( $public_fields[ $field_name ] );
4727 + } else {
4728 + $public_fields[ $field_name ] = $field_value;
4729 + }
4730 + }
4731 +}
4732 +
4733 + if ( $do_tabs_update ) {
4734 + uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
4735 + }
4736 + }
4737 +
4738 + if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
4739 + update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
4740 + } else {
4741 + update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
4742 + }
4743 +
4744 + $make_profile_private = uwp_can_make_profile_private();
4745 + if ( $make_profile_private ) {
4746 + $field_name = 'uwp_make_profile_private';
4747 + if ( isset( $_POST[ $field_name ] ) ) {
4748 + $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4749 + $user_id = get_current_user_id();
4750 + update_user_meta( $user_id, $field_name, $value );
4751 + }
4752 + }
4753 +
4754 + $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
4755 + $message = aui()->alert(
4756 + array(
4757 + 'type' => 'success',
4758 + 'content' => $message,
4759 + )
4760 + );
4761 + $uwp_notices[] = array( 'account' => $message );
4762 +
4763 + }
4764 + }
4765 +
4766 + /**
4767 + * Get the ajax login form.
4768 + *
4769 + * @since 1.2.0
4770 + */
4771 + public function ajax_login_form() {
4772 +
4773 + // add the modal error container
4774 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4775 +
4776 + $args = array(
4777 + 'form_title' => __( 'Login', 'userswp' ),
4778 + );
4779 +
4780 + // get the form
4781 + ob_start();
4782 + uwp_get_template( 'bootstrap/login.php', $args );
4783 + $form = ob_get_clean();
4784 +
4785 + // bs5
4786 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4787 + $form = aui_bs_convert_sd_output( $form );
2480 4788 }
4789 + // send ajax response
4790 + wp_send_json_success( $form );
4791 + }
2481 4792
2482 - return $html;
2483 - }
4793 + /**
4794 + * Get the ajax register form.
4795 + *
4796 + * @since 1.2.0
4797 + */
4798 + public function ajax_register_form() {
2484 4799
2485 - /**
2486 - * Prints the username link in "Edit Account" page
2487 - *
2488 - * @since 1.0.0
2489 - * @package userswp
2490 - *
2491 - * @param string $type Page type.
2492 - *
2493 - * @return void
2494 - */
2495 - public function uwp_display_username_in_account($type) {
2496 - if ($type == 'account') {
2497 - $user_id = get_current_user_id();
2498 - $user_info = get_userdata($user_id);
2499 - $display_name = $user_info->user_login;
2500 - ?>
2501 - <span class="uwp_account_page_username">
2502 - <a href="<?php echo uwp_build_profile_tab_url($user_id); ?>">( @<?php echo $display_name; ?> )</a>
2503 - </span>
2504 - <?php
2505 - }
2506 - }
4800 + // add the modal error container
4801 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2507 4802
4803 + global $wp_scripts;
4804 + if ( empty( $wp_scripts ) ) {
4805 + $wp_scripts = wp_scripts();
4806 + }
2508 4807
2509 - /**
2510 - * Adds confirm password field in forms.
2511 - *
2512 - * @since 1.0.0
2513 - * @package userswp
2514 - *
2515 - * @param string $html Form field html
2516 - * @param object $field Field info.
2517 - * @param string $value Form field default value.
2518 - * @param string $form_type Form type
2519 - *
2520 - * @return string Modified form field html.
2521 - */
2522 - public function uwp_register_confirm_password_field($html, $field, $value, $form_type) {
2523 - if ($form_type == 'register') {
2524 - //confirm password field
2525 - $extra = array();
2526 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2527 - $extra = unserialize($field->extra_fields);
2528 - }
2529 - $enable_confirm_password_field = isset($extra['confirm_password']) ? $extra['confirm_password'] : '0';
2530 - if ($enable_confirm_password_field == '1') {
2531 - ob_start(); // Start buffering;
2532 - ?>
2533 - <div id="uwp_account_confirm_password_row"
2534 - class="<?php echo 'required_field';?> uwp_form_password_row">
4808 + // do we need country code script in ajax?
4809 + $country_field = false;
4810 + $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
2535 4811
2536 - <?php
2537 - $site_title = __("Confirm Password", 'userswp');
2538 - if (!is_admin()) { ?>
2539 - <label>
2540 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2541 - <?php echo '<span>*</span>'; ?>
2542 - </label>
2543 - <?php } ?>
4812 + if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
4813 + $form_id = (int)$_POST['form_id'];
4814 + } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
4815 + $form_id = reset( $lightbox_forms );
4816 + } else {
4817 + $form_id = 1;
4818 + }
2544 4819
2545 - <input name="uwp_account_confirm_password"
2546 - class="uwp_textfield"
2547 - id="uwp_account_confirm_password"
2548 - placeholder="<?php echo $site_title; ?>"
2549 - value=""
2550 - title="<?php echo $site_title; ?>"
2551 - <?php echo 'required="required"'; ?>
2552 - type="password"
2553 - />
2554 - </div>
4820 + $fields = get_register_form_fields( $form_id );
4821 + if ( ! empty( $fields ) ) {
4822 + foreach ( $fields as $field ) {
4823 + if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
4824 + $country_field = true;
4825 + }
4826 + }
4827 + }
2555 4828
2556 - <?php
2557 - $confirm_html = ob_get_clean();
2558 - $html = $html.$confirm_html;
2559 - }
2560 - }
2561 - return $html;
2562 - }
4829 + ob_start();
2563 4830
2564 - /**
2565 - * Adds confirm email field in forms.
2566 - *
2567 - * @since 1.0.0
2568 - * @package userswp
2569 - *
2570 - * @param string $html Form field html
2571 - * @param object $field Field info.
2572 - * @param string $value Form field default value.
2573 - * @param string $form_type Form type
2574 - *
2575 - * @return string Modified form field html.
2576 - */
2577 - public function uwp_register_confirm_email_field($html, $field, $value, $form_type) {
2578 - if ($form_type == 'register') {
2579 - //confirm email field
2580 - $extra = array();
2581 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2582 - $extra = unserialize($field->extra_fields);
2583 - }
2584 - $enable_confirm_email_field = isset($extra['confirm_email']) ? $extra['confirm_email'] : '0';
2585 - if ($enable_confirm_email_field == '1') {
2586 - ob_start(); // Start buffering;
2587 - ?>
2588 - <div id="uwp_account_confirm_email_row"
2589 - class="<?php echo 'required_field';?> uwp_form_email_row">
4831 + // maybe add country code JS
4832 + if ( $country_field ) {
4833 + $country_data = uwp_get_country_data();
4834 + echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
4835 + echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
4836 + }
2590 4837
2591 - <?php
2592 - $site_title = __("Confirm Email", 'userswp');
2593 - if (!is_admin()) { ?>
2594 - <label>
2595 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2596 - <?php echo '<span>*</span>'; ?>
2597 - </label>
2598 - <?php } ?>
4838 + $args = array( 'form_title' => '' );
4839 + if ( $form_id > 0 ) {
4840 + $args['id'] = $form_id;
4841 + }
2599 4842
2600 - <input name="uwp_account_confirm_email"
2601 - class="uwp_textfield"
2602 - id="uwp_account_confirm_email"
2603 - placeholder="<?php echo $site_title; ?>"
2604 - value=""
2605 - title="<?php echo $site_title; ?>"
2606 - <?php echo 'required="required"'; ?>
2607 - type="email"
2608 - />
2609 - </div>
4843 + $args['limit'] = $lightbox_forms;
2610 4844
2611 - <?php
2612 - $confirm_html = ob_get_clean();
2613 - $html = $html.$confirm_html;
2614 - }
4845 + // get template
4846 + uwp_get_template( 'bootstrap/register.php', $args );
4847 +
4848 + // only show the JS if NOT doing a block render
4849 + if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
4850 + // load scripts
4851 + $wp_scripts->do_item( 'zxcvbn-async' );
4852 + $wp_scripts->do_item( 'wp-hooks' );
4853 + $wp_scripts->do_item( 'wp-i18n' );
4854 + $wp_scripts->do_item( 'password-strength-meter' );
4855 + ?>
4856 + <script>
4857 + // Password strength indicator script
4858 + jQuery(function ($) {
4859 +
4860 + // Load the settings like WP does.
4861 + var first, s;
4862 + s = document.createElement('script');
4863 + s.src = _zxcvbnSettings.src;
4864 + s.type = 'text/javascript';
4865 + s.async = true;
4866 + first = document.getElementsByTagName('script')[0];
4867 + first.parentNode.insertBefore(s, first);
4868 +
4869 + // Enable any pass inputs.
4870 + $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
4871 + function (event) {
4872 + var $form = $(this).closest('form');
4873 + if( ! $form.hasClass('uwp-login-form') ) {
4874 + uwp_checkPasswordStrength(
4875 + $('input[name=password]', $form), // First password field
4876 + $('input[name=confirm_password]', $form), // Second password field
4877 + $('#uwp-password-strength', $form), // Strength meter
4878 + $('input[type=submit]', $form), // Submit button
4879 + ['black', 'listed', 'word'] // Blacklisted words
4880 + );
4881 + }
4882 + }
4883 + );
4884 + });
4885 + </script>
4886 + <?php
4887 + }
4888 + $form = ob_get_clean();
4889 +
4890 + // bs5
4891 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4892 + $form = aui_bs_convert_sd_output( $form );
2615 4893 }
2616 - return $html;
2617 - }
2618 4894
4895 + // send ajax response
4896 + wp_send_json_success( $form );
4897 + }
2619 4898
2620 - /**
2621 - * Handles the privacy form submission.
2622 - *
2623 - * @since 1.0.0
2624 - * @package userswp
2625 - *
2626 - * @return void
2627 - */
2628 - public function uwp_privacy_submit_handler() {
2629 - if (isset($_POST['uwp_privacy_submit'])) {
2630 - if( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
2631 - return;
2632 - }
4899 + /**
4900 + * Get the ajax forgot password form.
4901 + *
4902 + * @since 1.2.0
4903 + */
4904 + public function ajax_forgot_password_form() {
2633 4905
2634 - $extra_where = "AND is_public='2'";
2635 - $fields = get_account_form_fields($extra_where);
2636 - $fields = apply_filters('uwp_account_privacy_fields', $fields);
2637 - if ($fields) {
2638 - foreach ($fields as $field) {
2639 - $field_name = $field->htmlvar_name.'_privacy';
2640 - if (isset($_POST[$field_name])) {
2641 - $value = strip_tags(esc_sql($_POST[$field_name]));
2642 - $user_id = get_current_user_id();
2643 - uwp_update_usermeta($user_id, $field_name, $value);
2644 - }
2645 - }
2646 - }
4906 + // add the modal error container
4907 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2647 4908
2648 - $make_profile_private = uwp_can_make_profile_private();
2649 - if ($make_profile_private) {
2650 - $field_name = 'uwp_make_profile_private';
2651 - if (isset($_POST[$field_name])) {
2652 - $value = strip_tags(esc_sql($_POST[$field_name]));
2653 - $user_id = get_current_user_id();
2654 - update_user_meta($user_id, $field_name, $value);
2655 - }
2656 - }
4909 + // get the form
4910 + ob_start();
4911 + uwp_get_template( 'bootstrap/forgot.php' );
4912 + $form = ob_get_clean();
2657 4913
4914 + // bs5
4915 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4916 + $form = aui_bs_convert_sd_output( $form );
2658 4917 }
2659 - }
2660 4918
2661 -}
4919 + // send ajax response
4920 + wp_send_json_success( $form );
4921 + }
4922 +
4923 + /**
4924 + * Output the modal error container.
4925 + *
4926 + * @param string $type
4927 + *
4928 + * @since 1.2.0
4929 + */
4930 + public function modal_error_container( $type = '' ) {
4931 + echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
4932 + }
4933 +
4934 + public function form_custom_html( $html, $field, $value, $form_type ) {
4935 +
4936 + $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
4937 +
4938 + return $html;
4939 + }
4940 +}