PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.38
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.38
1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 All 174 releases
← All changes | includes/class-forms.php +4504 -2273 1.0.221.2.38 View file →
@@ -1,5 +1,6 @@
1 1 <?php
2 +
2 3 /**
3 4 * Form related functions
4 5 *
5 6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
@@ -8,2702 +9,4932 @@
8 9 * @author GeoDirectory Team <info@wpgeodirectory.com>
9 10 */
10 11 class UsersWP_Forms {
11 12
12 - protected $generated_password;
13 + protected $generated_password;
13 14
14 - /**
15 - * Initialize UsersWP notices.
16 - *
17 - * @since 1.0.0
18 - * @package userswp
19 - *
20 - * @return void
21 - */
22 - public function init_notices() {
23 - global $uwp_notices;
24 - $uwp_notices = array();
25 - }
15 + /**
16 + * Logs the error message.
17 + *
18 + * @param array|object|string $log Error message.
19 + *
20 + * @return void
21 + * @since 1.0.0
22 + * @package userswp
23 + *
24 + */
25 + public static function uwp_error_log( $log ) {
26 + uwp_error_log( $log );
27 + }
26 28
27 - /**
28 - * Handles all UsersWP forms.
29 - *
30 - * @since 1.0.0
31 - * @package userswp
32 - *
33 - * @return void
34 - */
35 - public function handler()
36 - {
37 - global $uwp_notices;
29 + /**
30 + * Initialize UsersWP notices.
31 + *
32 + * @return void
33 + * @package userswp
34 + *
35 + * @since 1.0.0
36 + */
37 + public function init_notices() {
38 + global $uwp_notices;
39 + $uwp_notices = array();
40 + }
38 41
39 - ob_start();
42 + /**
43 + * Handles all UsersWP forms.
44 + *
45 + * @return void
46 + * @package userswp
47 + *
48 + * @since 1.0.0
49 + */
50 + public function handler() {
51 + global $uwp_notices;
40 52
41 - $errors = null;
42 - $message = null;
43 - $redirect = false;
44 - $processed = false;
45 - $type = null;
53 + ob_start();
46 54
47 - $login_page_url = wp_login_url();
55 + $errors = null;
56 + $message = null;
57 + $redirect = false;
58 + $processed = false;
59 + $type = null;
48 60
49 - if (isset($_POST['uwp_register_nonce'])) {
50 - $auto_login = uwp_get_option('uwp_registration_action', false);
51 - $errors = $this->process_register($_POST, $_FILES);
52 - if (!is_wp_error($errors)) {
53 - $message = $errors;
54 - }
55 - $force_redirect = apply_filters('uwp_registration_force_redirect', false, $_POST, $_FILES);
56 - if ($auto_login == 'auto_approve_login' || $force_redirect) {
57 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
58 - if(isset( $_REQUEST['redirect_to'] )){
59 - $reg_redirect_to = esc_url($_REQUEST['redirect_to']);
60 - } elseif ( isset($reg_redirect_page_id) && (int)$reg_redirect_page_id > 0) {
61 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
62 - } else {
63 - $reg_redirect_to = home_url('/');
64 - }
65 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
66 - }
67 - $processed = true;
68 - $type = 'register';
69 - } elseif (isset($_POST['uwp_login_nonce'])) {
70 - $errors = $this->process_login($_POST);
71 - $redirect_page_id = uwp_get_option('login_redirect_to', -1);
72 - if (isset($redirect_page_id) && (int)$redirect_page_id > 0) {
73 - $redirect_to = get_permalink($redirect_page_id);
74 - } elseif(isset( $_REQUEST['redirect_to'] ) && !empty($data['redirect_to'])){
75 - $redirect_to = esc_url($_REQUEST['redirect_to']);
76 - } else {
77 - $redirect_to = home_url('/');
78 - }
79 - $redirect = apply_filters('uwp_login_redirect', $redirect_to);
80 - $processed = true;
81 - $type = 'login';
82 - } elseif (isset($_POST['uwp_forgot_nonce'])) {
83 - $errors = $this->process_forgot($_POST);
84 - $message = __('Please check your email.', 'userswp');
85 - $processed = true;
86 - } elseif (isset($_POST['uwp_change_nonce'])) {
87 - $errors = $this->process_change($_POST);
88 - $message = __('Password changed successfully', 'userswp');
89 - $processed = true;
90 - } elseif (isset($_POST['uwp_reset_submit'])) {
91 - $errors = $this->process_reset($_POST);
92 - $message = sprintf(__('Password updated successfully. Please <a href="%s">login</a> with your new password', 'userswp'), $login_page_url);
93 - $processed = true;
94 - } elseif (isset($_POST['uwp_account_nonce'])) {
95 - $errors = $this->process_account($_POST, $_FILES);
96 - $message = __('Account updated successfully.', 'userswp');
97 - $processed = true;
98 - } elseif (isset($_POST['uwp_avatar_submit'])) {
99 - $errors = $this->process_upload_submit($_POST, $_FILES, 'avatar');
100 - if (!is_wp_error($errors)) {
101 - $redirect = $errors;
102 - }
103 - $message = __('Avatar cropped successfully.', 'userswp');
104 - $processed = true;
105 - } elseif (isset($_POST['uwp_banner_submit'])) {
106 - $errors = $this->process_upload_submit($_POST, $_FILES, 'banner');
107 - if (!is_wp_error($errors)) {
108 - $redirect = $errors;
109 - }
110 - $message = __('Banner cropped successfully.', 'userswp');
111 - $processed = true;
112 - } elseif (isset($_POST['uwp_avatar_crop'])) {
113 - $errors = $this->process_image_crop($_POST, 'avatar', true);
114 - if (!is_wp_error($errors)) {
115 - $redirect = $errors;
116 - }
117 - $message = __('Avatar cropped successfully.', 'userswp');
118 - $processed = true;
119 - } elseif (isset($_POST['uwp_banner_crop'])) {
120 - $errors = $this->process_image_crop($_POST, 'banner', true);
121 - if (!is_wp_error($errors)) {
122 - $redirect = $errors;
123 - }
124 - $message = __('Banner cropped successfully.', 'userswp');
125 - $processed = true;
126 - }
61 + if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 + if ( ! is_wp_error( $errors ) ) {
64 + $redirect = $errors;
65 + }
66 + $message = __( 'Avatar cropped successfully.', 'userswp' );
67 + $processed = true;
68 + } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 + if ( ! is_wp_error( $errors ) ) {
71 + $redirect = $errors;
72 + }
73 + $message = __( 'Banner cropped successfully.', 'userswp' );
74 + $processed = true;
75 + } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 + $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 + if ( ! is_wp_error( $errors ) ) {
78 + $redirect = $errors;
79 + }
80 + $message = __( 'Avatar cropped successfully.', 'userswp' );
81 + $processed = true;
82 + } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 + $errors = $this->process_image_crop( $_POST, 'banner', true );
84 + if ( ! is_wp_error( $errors ) ) {
85 + $redirect = $errors;
86 + }
87 + $message = __( 'Banner cropped successfully.', 'userswp' );
88 + $processed = true;
89 + } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 + $errors = $this->process_image_reset( 'avatar' );
91 + if ( ! is_wp_error( $errors ) ) {
92 + $redirect = $errors;
93 + }
94 + $message = __( 'Avatar reset successfully.', 'userswp' );
95 + $processed = true;
96 + } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 + $errors = $this->process_image_reset( 'banner' );
98 + if ( ! is_wp_error( $errors ) ) {
99 + $redirect = $errors;
100 + }
101 + $message = __( 'Banner reset successfully.', 'userswp' );
102 + $processed = true;
103 + }
127 104
128 - if ($processed) {
129 - if (is_wp_error($errors)) {
130 - echo '<div class="uwp-alert-error text-center">';
131 - echo $errors->get_error_message();
132 - echo '</div>';
133 - } else {
134 - if ($redirect) {
135 - wp_safe_redirect($redirect);
136 - exit();
137 - } else {
138 - echo '<div class="uwp-alert-success text-center">';
139 - echo $message;
140 - echo '</div>';
141 - }
142 - }
143 - }
105 + if ( $processed ) {
144 106
145 - if($type){
146 - $uwp_notices[] = array($type => ob_get_contents());
147 - }else{
148 - $uwp_notices[] = ob_get_contents();
149 - }
107 + if ( is_wp_error( $errors ) ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
116 + wp_safe_redirect( $redirect );
117 + exit();
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
125 + );
126 + }
127 + }
150 128
129 + if ( $type ) {
130 + $uwp_notices[] = array( $type => ob_get_contents() );
131 + } else {
132 + $uwp_notices[] = ob_get_contents();
133 + }
151 134
152 - ob_end_clean();
135 + ob_end_clean();
136 + }
153 137
154 - }
138 + /**
139 + * Processes avatar and banner uploads form submission.
140 + *
141 + * @param array $data Submitted $_POST data
142 + * @param array $files Submitted $_FILES data
143 + *
144 + * @return bool|WP_Error|string File url to crop.
145 + * @package userswp
146 + *
147 + * @since 1.0.0
148 + */
149 + public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
155 150
156 - public function output_dashboard_links($options){
157 - if(!empty($options)){
158 - echo "<select onchange='window.location = jQuery(this).val();'>";
159 - $this->output_options($options);
160 - echo "<select>";
161 - }
162 - }
151 + $file_obj = new UsersWP_Files();
163 152
164 - public function output_options($options){
165 - if(!empty($options)){
166 - foreach($options as $key => $link){
153 + $current_user_id = get_current_user_id();
154 + if ( ! $current_user_id ) {
155 + return false;
156 + }
167 157
168 - if(!isset($link['text']) && isset($link[0]) && is_array($link[0])){
169 - $this->output_options($link);
170 - }else{
171 - if(!empty($link['optgroup']) && $link['optgroup']=='open'){
172 - echo "<optgroup label='".esc_attr($link['text'])."'>";
173 - }elseif(!empty($link['optgroup']) && $link['optgroup']=='close'){
174 - echo "</optgroup>";
175 - }elseif(!empty($link['text'])){
176 - $disabled = !empty($link['disabled']) ? 'disabled' : '';
177 - $selected = !empty($link['selected']) ? 'selected' : '';
178 - $value = !empty($link['url']) ? esc_url($link['url']) : '';
179 - $display_none = !empty($link['display_none']) ? 'style="display:none;"' : '';
180 - echo "<option $disabled $selected value='$value' $display_none>";
181 - echo esc_attr($link['text']);
182 - echo "</option>";
183 - }
184 - }
185 - }
186 - }
187 - }
158 + if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
159 + return false;
160 + }
188 161
189 - /**
190 - * Displays UsersWP notices in forms.
191 - *
192 - * @since 1.0.0
193 - * @package userswp
194 - *
195 - * @param string $type Form type
196 - *
197 - * @return void
198 - */
199 - public function display_notices($type) {
200 - global $uwp_notices;
162 + do_action( 'uwp_before_validate', $type );
201 163
202 - if (is_array($uwp_notices)) {
203 - foreach ($uwp_notices as $notice) {
164 + $result = $file_obj->validate_uploads( $files, $type );
204 165
205 - // If the notification is type specific then only output on that type
206 - if(is_array($notice)){
207 - foreach($notice as $key => $val){
208 - if( $key == $type ){ echo $val; }
209 - }
210 - }else{
211 - if (!empty($notice)) {
212 - echo $notice;
213 - }
214 - }
166 + $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
215 167
216 - }
168 + if ( is_wp_error( $result ) ) {
169 + return $result;
170 + }
217 171
218 - }
172 + $profile_url = uwp_build_profile_tab_url( $current_user_id );
219 173
220 - if ($type == 'change') {
221 - $user_id = get_current_user_id();
222 - $password_nag = get_user_option('default_password_nag', $user_id);
174 + $url = add_query_arg(
175 + array(
176 + 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
177 + 'type' => $type,
178 + ),
179 + $profile_url
180 + );
223 181
224 - if ($password_nag) {
225 - $change_page = uwp_get_page_id('change_page', false);
226 - $remove_nag_url = add_query_arg('uwp_remove_nag', 'yes', get_permalink($change_page));
182 + return $url;
183 + }
227 184
228 - if (isset($_GET['uwp_remove_nag']) && $_GET['uwp_remove_nag'] == 'yes') {
229 - delete_user_meta( $user_id, 'default_password_nag' );
230 - $message = sprintf(__('We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp'), home_url('/'));
231 - echo '<div class="uwp-alert-success text-center">';
232 - echo $message;
233 - echo '</div>';
234 - } else {
235 - $message = sprintf(__('<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp'), $remove_nag_url);
236 - echo '<div class="uwp-alert-warning text-center">';
237 - echo $message;
238 - echo '</div>';
239 - }
240 - }
241 - }
242 - }
185 + /**
186 + * Processes avatar and banner uploads image crop.
187 + *
188 + * @param array $data Submitted $_POST data
189 + * @param string $type Image type. Default 'avatar'.
190 + * @param bool $unlink_prev_img True to remove previous image. Default false;
191 + *
192 + * @return bool|WP_Error|string Profile url.
193 + * @since 1.0.12 New param $unlink_prev_img introduced.
194 + * @package userswp
195 + *
196 + * @since 1.0.0
197 + */
198 + public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
199 + global $wpdb;
200 + if ( ! is_user_logged_in() ) {
201 + return false;
202 + }
243 203
244 - /**
245 - * Processes register form submission.
246 - *
247 - * @since 1.0.0
248 - * @package userswp
249 - *
250 - * @param array $data Submitted $_POST data
251 - * @param array $files Submitted $_FILES data
252 - *
253 - * @return bool|WP_Error|string
254 - */
255 - public function process_register($data = array(), $files = array()) {
204 + if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 + return;
206 + }
256 207
257 - $errors = new WP_Error();
258 - $file_obj = new UsersWP_Files();
208 + // If is current user's profile (profile.php)
209 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
210 + $user_id = get_current_user_id();
211 + // If is another user's profile page
212 + } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
213 + $user_id = absint( $_GET['user_id'] );
214 + // Otherwise something is wrong.
215 + } else {
216 + $user_id = get_current_user_id();
217 + }
259 218
260 - if( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
261 - return false;
262 - }
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
263 222
264 - if (!get_option('users_can_register')) {
265 - $errors->add('register_disabled', __('<strong>ERROR</strong>: User registration is currently not allowed.', 'userswp'));
266 - return $errors;
267 - }
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
268 227
269 - $reg_terms_page_id = uwp_get_option('register_terms_page', '');
270 - $reg_terms_page_id = apply_filters('uwp_reg_terms_page_id', $reg_terms_page_id);
271 - if (!empty($reg_terms_page_id)) {
272 - if (!isset($data['agree_terms']) || $data['agree_terms'] != 'yes') {
273 - $errors->add('accept_tos', __('<strong>ERROR</strong>: You must accept our terms and conditions.', 'userswp'));
274 - return $errors;
275 - }
276 - }
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
277 231
278 - do_action('uwp_before_validate', 'register');
232 + // Retrieve current thumbnail.
233 + $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
234 + $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
235 + $thumb_postfix = '_uwp_' . $type . '_thumb';
279 236
280 - $result = uwp_validate_fields($data, 'register');
281 -
282 - $result = apply_filters('uwp_validate_result', $result, 'register', $data);
237 + if ( $image_url ) {
238 + if ( $type == 'avatar' ) {
239 + $avatar_size = uwp_get_upload_image_size();
240 + $full_width = $avatar_size['width'];
241 + } else {
242 + $banner_size = uwp_get_upload_image_size( 'banner' );
243 + $full_width = $banner_size['width'];
244 + }
283 245
284 - if (is_wp_error($result)) {
285 - return $result;
286 - }
246 + add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
247 + $uploads = wp_upload_dir();
248 + remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
249 + $upload_url = $uploads['baseurl'];
250 + $upload_path = $uploads['basedir'];
251 + $image_path = str_replace( $upload_url, $upload_path, $image_url );
252 + $ext = $filetype['ext']; // to get extension
253 + $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
254 + $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
255 + $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
256 + //Get the new coordinates to crop the image.
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
261 + //Scale the image based on cropped width setting
262 + $scale = $full_width / $w;
263 + //$scale = 1; // no scaling
287 264
288 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'register');
265 + // check we are not editing another user file
266 + $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
267 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
268 + $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
289 269
290 - if (is_wp_error($uploads_result)) {
291 - return $uploads_result;
292 - }
270 + // if file already exists then we should not be cropping it.
271 + if ( $file_exists ) {
272 + wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
273 + }
293 274
294 - do_action('uwp_after_validate', 'register');
275 + $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
276 + $cropped = str_replace( $upload_path, $upload_url, $cropped );
295 277
296 - $result = array_merge( $result, $uploads_result );
278 + // Remove previous avatar/banner
279 + $unlink_img = '';
280 + if ( $unlink_prev_img && $current_thumbnail ) {
281 + $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
282 + }
297 283
298 - $error_code = $errors->get_error_code();
299 - if (!empty($error_code)) {
300 - return $errors;
301 - }
284 + // remove the uploads path for easy migrations
285 + $cropped = str_replace( $upload_url, '', $cropped );
286 + if ( $type == 'avatar' ) {
287 + uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
288 + } else {
289 + uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
290 + }
302 291
303 - if (isset($result['password']) && !empty($result['password'])) {
304 - $password = $result['password'];
305 - $generated_password = false;
306 - } else {
307 - $password = wp_generate_password();
308 - $this->generated_password = $password;
309 - $generated_password = true;
310 - }
292 + if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
293 + @unlink( $unlink_img );
294 + $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
295 + if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
296 + @unlink( $unlink_ori_img );
297 + }
298 + }
299 + }
311 300
312 - $first_name = "";
313 - if (isset($result['uwp_account_first_name']) && !empty($result['uwp_account_first_name'])) {
314 - $first_name = $result['uwp_account_first_name'];
315 - }
301 + if ( is_admin() ) {
302 + if ( $user_id == get_current_user_id() ) {
303 + $redirect_url = admin_url( 'profile.php' );
304 + } else {
305 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
306 + }
307 + } elseif ( uwp_current_page_url() ) {
308 + $redirect_url = uwp_current_page_url();
309 + } else {
310 + $redirect_url = uwp_build_profile_tab_url( $user_id );
311 + }
316 312
317 - $last_name = "";
318 - if (isset($result['uwp_account_last_name']) && !empty($result['uwp_account_last_name'])) {
319 - $last_name = $result['uwp_account_last_name'];
320 - }
313 + return $redirect_url;
314 + }
321 315
322 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
323 - $display_name = $result['uwp_account_display_name'];
324 - } else {
325 - if (!empty($first_name) || !empty($last_name)) {
326 - $display_name = $first_name . ' ' . $last_name;
327 - } else {
328 - $display_name = $result['uwp_account_username'];
329 - }
330 - }
316 + /**
317 + * Normalizes a URL.
318 + *
319 + */
320 + public function normalize_url( $url ) {
331 321
332 - $description = "";
333 - if (isset($result['uwp_account_bio']) && !empty($result['uwp_account_bio'])) {
334 - $description = $result['uwp_account_bio'];
335 - }
322 + // Normalize.
323 + $url = wp_normalize_path( $url );
336 324
325 + // Remove query vars.
326 + $url = strtok( $url, '?' );
337 327
338 - $args = array(
339 - 'user_login' => $result['uwp_account_username'],
340 - 'user_email' => $result['uwp_account_email'],
341 - 'user_pass' => $password,
342 - 'display_name' => $display_name,
343 - 'first_name' => $first_name,
344 - 'last_name' => $last_name,
345 - 'description' => $description
346 - );
328 + // Split.
329 + $url = explode( '/', $url );
347 330
348 - $user_id = wp_insert_user( $args );
331 + // Clean.
332 + $url = array_diff( $url, array( '..', '.' ) );
349 333
350 - if (!$user_id) {
351 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
352 - return $errors;
353 - }
334 + // Rejoin and return.
335 + return implode( '/', $url );
336 + }
354 337
355 - $result = apply_filters('uwp_before_extra_fields_save', $result, 'register', $user_id);
338 + /**
339 + * Processes avatar and banner image reset.
340 + *
341 + * @param string $type Image type. Default 'avatar'.
342 + *
343 + * @return bool|WP_Error|string Profile url.
344 + * @package userswp
345 + *
346 + */
347 + public function process_image_reset( $type ) {
348 + if ( ! is_user_logged_in() ) {
349 + return false;
350 + }
356 351
357 - $save_result = $this->uwp_save_user_extra_fields($user_id, $result, 'register');
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
358 355
359 - $save_result = apply_filters('uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id);
356 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
357 + $user_id = get_current_user_id();
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
360 + $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
362 + } else {
363 + $user_id = get_current_user_id();
364 + }
360 365
361 - if (is_wp_error($save_result)) {
362 - return $save_result;
363 - }
366 + $errors = new WP_Error();
367 + if ( empty( $user_id ) ) {
368 + $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
369 + }
364 370
365 - if (!$save_result) {
366 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
367 - }
371 + $error_code = $errors->get_error_code();
372 + if ( ! empty( $error_code ) ) {
373 + return $errors;
374 + }
368 375
369 - $error_code = $errors->get_error_code();
370 - if (!empty($error_code)) {
371 - return $errors;
372 - }
376 + if ( $type == 'avatar' ) {
377 + uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
378 + } elseif ( $type == 'banner' ) {
379 + uwp_update_usermeta( $user_id, 'banner_thumb', '' );
380 + } else {
381 + // Do nothing
382 + }
373 383
374 - do_action('uwp_after_custom_fields_save', 'register', $data, $result, $user_id);
384 + if ( is_admin() ) {
385 + if ( $user_id == get_current_user_id() ) {
386 + $redirect_url = admin_url( 'profile.php' );
387 + } else {
388 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
389 + }
390 + } elseif ( uwp_current_page_url() ) {
391 + $redirect_url = uwp_current_page_url();
392 + } else {
393 + $redirect_url = uwp_build_profile_tab_url( $user_id );
394 + }
375 395
376 - $reg_action = uwp_get_option('uwp_registration_action', false);
396 + return $redirect_url;
397 + }
377 398
378 - if ($reg_action == 'require_email_activation' && !$generated_password) {
399 + /**
400 + * Displays links in a dropdown
401 + *
402 + * @param $options
403 + *
404 + * @package userswp
405 + *
406 + * @since 1.0.0
407 + */
408 + public function output_dashboard_links( $options ) {
409 + if ( ! empty( $options ) ) {
410 + $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
411 + echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
412 + $this->output_options( $options );
413 + echo '</select>';
414 + }
415 + }
379 416
380 - $email = new UsersWP_Mails();
381 - $send_result = $email->send( 'activate', $user_id );
417 + /**
418 + * Displays options for the dashboard links
419 + *
420 + * @param $options
421 + *
422 + * @package userswp
423 + *
424 + * @since 1.0.0
425 + */
426 + public function output_options( $options ) {
427 + if ( ! empty( $options ) ) {
428 + foreach ( $options as $key => $link ) {
382 429
383 - if (!$send_result) {
384 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
385 - }
386 - } else {
387 - $email = new UsersWP_Mails();
388 - $send_result = $email->send( 'register', $user_id );
430 + if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
431 + $this->output_options( $link );
432 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
433 + echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
434 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
435 + echo '</optgroup>';
436 + } elseif ( ! empty( $link['text'] ) ) {
437 + echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
438 + echo esc_attr__( $link['text'], 'userswp' );
439 + echo '</option>';
440 + }
441 + }
442 + }
443 + }
389 444
390 - if (!$send_result) {
391 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
392 - }
393 - }
445 + /**
446 + * Displays UsersWP notices in forms.
447 + *
448 + * @param string $type Form type
449 + *
450 + * @return void
451 + * @since 1.0.0
452 + * @package userswp
453 + *
454 + */
455 + public function display_notices( $type ) {
456 + global $uwp_notices;
394 457
395 - if ($reg_action != 'require_admin_review') {
396 - $register_admin_notify = uwp_get_option('register_admin_notify', '');
397 - if ($register_admin_notify == '1') {
398 - $admin_register_send_result = $email->send_admin_email('register_admin', $user_id);
399 - if (is_wp_error($admin_register_send_result)) {
400 - return $admin_register_send_result;
401 - }
402 - }
458 + if ( is_array( $uwp_notices ) ) {
459 + foreach ( $uwp_notices as $notice ) {
403 460
404 - }
461 + // If the notification is type specific then only output on that type
462 + if ( is_array( $notice ) ) {
463 + foreach ( $notice as $key => $val ) {
464 + if ( $key == $type ) {
465 + echo wp_kses_post( $val );
466 + }
467 + }
468 + } elseif ( ! empty( $notice ) ) {
469 + echo wp_kses_post( $notice );
470 + }
471 +}
472 +}
405 473
474 + if ( $type == 'change' ) {
475 + $user_id = get_current_user_id();
476 + $password_nag = get_user_option( 'default_password_nag', $user_id );
406 477
407 - $error_code = $errors->get_error_code();
408 - if (!empty($error_code)) {
409 - return $errors;
410 - }
478 + if ( $password_nag ) {
479 + $change_page = uwp_get_page_id( 'change_page', false );
480 + $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
411 481
412 - if ($reg_action == 'auto_approve_login') {
413 - $res = wp_signon(
482 + if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
483 + delete_user_meta( $user_id, 'default_password_nag' );
484 + $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
485 + echo aui()->alert(
486 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
487 + 'class' => 'text-center',
488 + 'type' => 'success',
489 + 'content' => wp_kses_post( $message ),
490 + )
491 + );
492 + } else {
493 + $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
494 + echo aui()->alert(
495 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
496 + 'class' => 'text-center',
497 + 'type' => 'warning',
498 + 'content' => wp_kses_post( $message ),
499 + )
500 + );
501 + }
502 + }
503 + }
504 + }
505 +
506 + /**
507 + * Processes register form submission.
508 + *
509 + * @since 1.0.0
510 + * @package userswp
511 + *
512 + */
513 + public function process_register() {
514 +
515 + $data = $_POST;
516 +
517 + if ( ! isset( $data['uwp_register_nonce'] ) ) {
518 + return;
519 + }
520 +
521 + global $uwp_notices;
522 +
523 + if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
524 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
525 + }
526 +
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
528 + $message = aui()->alert(
414 529 array(
415 - 'user_login' => $result['uwp_account_username'],
416 - 'user_password' => $password,
417 - 'remember' => false
530 + 'type' => 'error',
531 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
418 532 )
419 - );
533 + );
534 + if ( wp_doing_ajax() ) {
535 + wp_send_json_error( array( 'message' => $message ) );
536 + } else {
537 + $uwp_notices[] = array( 'register' => $message );
420 538
421 - if (is_wp_error($res)) {
422 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
423 - return $errors;
424 - } else {
425 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
426 - if(isset( $_REQUEST['redirect_to'] )) {
427 - $reg_redirect_to = esc_url($_REQUEST['redirect_to']);
428 - } elseif (empty($reg_redirect_page_id)) {
429 - $reg_redirect_to = home_url('/');
430 - } else {
431 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
539 + return;
540 + }
541 + }
542 +
543 + $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
544 + if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
545 + $message = aui()->alert(
546 + array(
547 + 'type' => 'error',
548 + 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
549 + )
550 + );
551 + if ( wp_doing_ajax() ) {
552 + wp_send_json_error( array( 'message' => $message ) );
553 + } else {
554 + $uwp_notices[] = array( 'register' => $message );
555 +
556 + return;
557 + }
558 + }
559 +
560 + if ( ! get_option( 'users_can_register' ) ) {
561 + $message = aui()->alert(
562 + array(
563 + 'type' => 'error',
564 + 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
565 + )
566 + );
567 + if ( wp_doing_ajax() ) {
568 + wp_send_json_error( array( 'message' => $message ) );
569 + } else {
570 + $uwp_notices[] = array( 'register' => $message );
571 +
572 + return;
573 + }
574 + }
575 +
576 + $files = $_FILES;
577 + $errors = new WP_Error();
578 + $file_obj = new UsersWP_Files();
579 +
580 + do_action( 'uwp_before_validate', 'register' );
581 +
582 + $result = uwp_validate_fields( $data, 'register' );
583 +
584 + $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
585 +
586 + if ( is_wp_error( $result ) ) {
587 + $message = aui()->alert(
588 + array(
589 + 'type' => 'error',
590 + 'content' => $result->get_error_message(),
591 + )
592 + );
593 + if ( wp_doing_ajax() ) {
594 + wp_send_json_error( array( 'message' => $message ) );
595 + } else {
596 + $uwp_notices[] = array( 'register' => $message );
597 +
598 + return;
599 + }
600 + }
601 +
602 + $uploads_result = $file_obj->validate_uploads( $files, 'register' );
603 +
604 + if ( is_wp_error( $uploads_result ) ) {
605 + $message = aui()->alert(
606 + array(
607 + 'type' => 'error',
608 + 'content' => $uploads_result->get_error_message(),
609 + )
610 + );
611 + if ( wp_doing_ajax() ) {
612 + wp_send_json_error( array( 'message' => $message ) );
613 + } else {
614 + $uwp_notices[] = array( 'register' => $message );
615 +
616 + return;
617 + }
618 + }
619 +
620 + do_action( 'uwp_after_validate', $result, 'register', $data );
621 +
622 + $result = array_merge( $result, $uploads_result );
623 +
624 + if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
625 + $password = $result['password'];
626 + $generated_password = false;
627 + } else {
628 + $password = wp_generate_password();
629 + $this->generated_password = $password;
630 + $generated_password = true;
631 + }
632 +
633 + $first_name = '';
634 + if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
635 + $first_name = $result['first_name'];
636 + }
637 +
638 + $last_name = '';
639 + if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
640 + $last_name = $result['last_name'];
641 + }
642 +
643 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
644 + $display_name = $result['display_name'];
645 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
646 + $display_name = $first_name . ' ' . $last_name;
647 + } else {
648 + $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
649 + }
650 +
651 + $user_url = '';
652 + if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
653 + $user_url = esc_url_raw( $result['user_url'] );
654 + }
655 +
656 + $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
657 + $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
658 +
659 + if ( empty( $user_login ) ) {
660 + $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
661 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
662 + $new_user_login = strstr( $email, '@', true );
663 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
664 + $user_login = sanitize_user( $new_user_login, true );
665 + }
666 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
667 + $user_append_text = rand( 10, 1000 );
668 + $user_login = sanitize_user( $new_user_login . $user_append_text, true );
669 + }
670 +
671 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
672 + $user_login = $email;
673 + }
674 + }
675 + } elseif ( ! validate_username( $user_login ) ) {
676 + $message = aui()->alert(
677 + array(
678 + 'type' => 'error',
679 + 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
680 + )
681 + );
682 + if ( wp_doing_ajax() ) {
683 + wp_send_json_error( array( 'message' => $message ) );
684 + } else {
685 + $uwp_notices[] = array( 'register' => $message );
686 +
687 + return;
688 + }
689 + }
690 +
691 + $args = array(
692 + 'user_login' => sanitize_user( $user_login ),
693 + 'user_email' => sanitize_email( $email ),
694 + 'user_pass' => $password,
695 + 'display_name' => sanitize_text_field( $display_name ),
696 + 'first_name' => esc_attr( $first_name ),
697 + 'last_name' => esc_attr( $last_name ),
698 + 'user_url' => esc_url_raw( $user_url ),
699 + );
700 +
701 + $user_id = wp_insert_user( $args );
702 +
703 + if ( is_wp_error( $user_id ) ) {
704 + $message = aui()->alert(
705 + array(
706 + 'type' => 'error',
707 + 'content' => $user_id->get_error_message(),
708 + )
709 + );
710 + if ( wp_doing_ajax() ) {
711 + wp_send_json_error( array( 'message' => $message ) );
712 + } else {
713 + $uwp_notices[] = array( 'register' => $message );
714 +
715 + return;
716 + }
717 + }
718 +
719 + $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
720 +
721 + $form_id = 1;
722 +
723 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
724 + update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
725 + $form_id = (int) $data['uwp_register_form_id'];
726 + }
727 +
728 + $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
729 +
730 + if ( isset( $user_role ) && ! empty( $user_role ) ) {
731 + $user_roles = uwp_get_user_roles();
732 + $chosen_role = strtolower( $user_role );
733 + if ( ! empty( $user_roles ) ) {
734 + $wp_roles = wp_roles();
735 + if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
736 + $new_user = get_userdata( $user_id );
737 + if ( $new_user ) {
738 + $new_user->set_role( $chosen_role );
739 + }
740 + }
741 + }
742 + }
743 +
744 + $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
745 +
746 + $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
747 +
748 + if ( is_wp_error( $save_result ) ) {
749 + $message = aui()->alert(
750 + array(
751 + 'type' => 'error',
752 + 'content' => $save_result->get_error_message(),
753 + )
754 + );
755 + if ( wp_doing_ajax() ) {
756 + wp_send_json_error( array( 'message' => $message ) );
757 + } else {
758 + $uwp_notices[] = array( 'register' => $message );
759 +
760 + return;
761 + }
762 + }
763 +
764 + if ( ! $save_result ) {
765 + $message = aui()->alert(
766 + array(
767 + 'type' => 'error',
768 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
769 + )
770 + );
771 + if ( wp_doing_ajax() ) {
772 + wp_send_json_error( array( 'message' => $message ) );
773 + } else {
774 + $uwp_notices[] = array( 'register' => $message );
775 +
776 + return;
777 + }
778 + }
779 +
780 + //updating bio field after saving extra fields to reflect the points in mycred add on.
781 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
782 + $args = array(
783 + 'ID' => $user_id,
784 + 'description' => $result['bio'],
785 + );
786 + wp_update_user( $args );
787 + }
788 +
789 + do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
790 +
791 + // Unset post data to empty the form on submit
792 + $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
793 + foreach ( $data as $key => $value ) {
794 + if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
795 + unset( $_POST[ $key ] );
796 + }
797 + }
798 +
799 + $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
800 + if ( ! $reg_action ) {
801 + $reg_action = uwp_get_option( 'uwp_registration_action', false );
802 + }
803 +
804 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
805 +
806 + if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
807 +
808 + $user_data = get_userdata( $user_id );
809 + $activation_link = uwp_get_activation_link( $user_id );
810 +
811 + $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
812 +
813 + $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
814 +
815 + $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
816 +
817 + $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
818 +
819 + $email_vars = array(
820 + 'user_id' => $user_id,
821 + 'login_details' => $activate_message,
822 + 'activation_link' => $activation_link,
823 + );
824 +
825 + UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
826 +
827 + } elseif ( $reg_action != 'require_admin_review' ) {
828 +
829 + $user_data = get_userdata( $user_id );
830 +
831 + if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
832 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
833 + update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
834 + }
835 + $message_pass = $this->generated_password;
836 + $this->generated_password = false;
837 + } else {
838 + $message_pass = __( 'Password you entered during registration.', 'userswp' );
839 + }
840 +
841 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
842 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
843 + <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
844 +
845 + $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
846 +
847 + $email_vars = array(
848 + 'user_id' => $user_id,
849 + 'login_details' => $message,
850 + 'form_fields' => $form_fields,
851 + );
852 +
853 + UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
854 + }
855 +
856 + $error_code = $errors->get_error_code();
857 + if ( ! empty( $error_code ) ) {
858 + $message = aui()->alert(
859 + array(
860 + 'type' => 'error',
861 + 'content' => $result->get_error_message(),
862 + )
863 + );
864 + if ( wp_doing_ajax() ) {
865 + wp_send_json_error( array( 'message' => $message ) );
866 + } else {
867 + $uwp_notices[] = array( 'register' => $message );
868 + return;
869 + }
870 + }
871 +
872 + if ( $reg_action != 'require_admin_review' ) {
873 +
874 + $user_data = get_userdata( $user_id );
875 + $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
876 + <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
877 + <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
878 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
879 + <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
880 +
881 + $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
882 +
883 + $email_vars = array(
884 + 'user_id' => $user_id,
885 + 'extras' => $extras,
886 + 'form_fields' => $form_fields,
887 + );
888 +
889 + UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
890 +
891 + }
892 +
893 + if ( $reg_action == 'auto_approve_login' ) {
894 + $res = wp_signon(
895 + array(
896 + 'user_login' => $user_login,
897 + 'user_password' => $password,
898 + 'remember' => false,
899 + )
900 + );
901 +
902 + if ( is_wp_error( $res ) ) {
903 + $message = aui()->alert(
904 + array(
905 + 'type' => 'error',
906 + 'content' => $res->get_error_message(),
907 + )
908 + );
909 +
910 + if ( wp_doing_ajax() ) {
911 + wp_send_json_error( array( 'message' => $message ) );
912 + } else {
913 + $uwp_notices[] = array( 'register' => $message );
914 + }
915 + } else {
916 + $redirect_to = $this->get_register_redirect_url( $data, $user_id );
917 + do_action( 'uwp_after_process_register', $result, $user_id );
918 +
919 + if ( wp_doing_ajax() ) {
920 + $message = aui()->alert(
921 + array(
922 + 'type' => 'success',
923 + 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
924 + )
925 + );
926 + $response = array(
927 + 'message' => $message,
928 + 'redirect' => $redirect_to,
929 + );
930 + wp_send_json_success( $response );
931 + } else {
932 + wp_safe_redirect( $redirect_to );
933 + }
934 + exit();
935 + }
936 + } else {
937 + if ( $reg_action == 'require_email_activation' ) {
938 + $resend_link = uwp_get_register_page_url();
939 + $resend_link = add_query_arg(
940 + array(
941 + 'user_id' => $user_id,
942 + 'action' => 'uwp_resend',
943 + '_nonce' => wp_create_nonce( 'uwp_resend' ),
944 + ),
945 + $resend_link
946 + );
947 +
948 + $message = aui()->alert(
949 + array(
950 + 'type' => 'success',
951 + 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
952 + )
953 + );
954 +
955 + } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
956 +
957 + update_user_meta( $user_id, 'uwp_mod', '1' );
958 +
959 + do_action( 'uwp_require_admin_review', $user_id, $result );
960 +
961 + $message = aui()->alert(
962 + array(
963 + 'type' => 'success',
964 + 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
965 + )
966 + );
967 + } else {
968 +
969 + $login_page_url = wp_login_url();
970 +
971 + if ( $generated_password ) {
972 + $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
973 + } else {
974 + $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
975 + }
976 +
977 + $message = aui()->alert(
978 + array(
979 + 'type' => 'success',
980 + 'content' => $msg,
981 + )
982 + );
983 + }
984 +
985 + do_action( 'uwp_after_process_register', $result, $user_id );
986 +
987 + if ( wp_doing_ajax() ) {
988 + wp_send_json_success( array( 'message' => $message ) );
989 + } else {
990 + $uwp_notices[] = array( 'register' => $message );
991 + }
992 + }
993 +
994 + if ( wp_doing_ajax() ) {
995 + wp_send_json_error();
996 + } // if we got this far there is a problem
997 + }
998 +
999 + /**
1000 + * Saves UsersWP related user custom fields.
1001 + *
1002 + * @param int $user_id User ID.
1003 + * @param array $data Result array.
1004 + * @param string $type Form type.
1005 + *
1006 + * @return bool True when success. False when failure.
1007 + * @since 1.0.0
1008 + * @package userswp
1009 + *
1010 + */
1011 + public function save_user_extra_fields( $user_id, $data, $type ) {
1012 +
1013 + if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1014 + return false;
1015 + }
1016 +
1017 + // custom user fields not applicable for login and forgot
1018 + if ( $type == 'login' || $type == 'forgot' ) {
1019 + return true;
1020 + }
1021 +
1022 + if ( $type == 'account' || $type == 'register' ) {
1023 + if ( isset( $data['password'] ) ) {
1024 + unset( $data['password'] );
1025 + }
1026 + }
1027 +
1028 + if ( $type == 'register' ) {
1029 + if ( isset( $data['username'] ) ) {
1030 + unset( $data['username'] );
1031 + }
1032 + if ( isset( $data['email'] ) ) {
1033 + unset( $data['email'] );
1034 + }
1035 + }
1036 +
1037 + if ( empty( $data ) ) {
1038 + // no extra fields. so just return
1039 + return true;
1040 + } else {
1041 + foreach ( $data as $key => $value ) {
1042 + if ( 'uwp_language' == $key ) {
1043 + update_user_meta( $user_id, 'locale', $value );
1044 + }
1045 + uwp_update_usermeta( $user_id, $key, $value );
1046 + }
1047 +
1048 + return true;
1049 + }
1050 + }
1051 +
1052 + public function get_register_redirect_url( $data, $user ) {
1053 + if ( is_int( $user ) ) {
1054 + $user = get_userdata( $user );
1055 + }
1056 +
1057 + $redirect_page_id = $custom_url = '';
1058 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1059 + $form_id = (int) $data['uwp_register_form_id'];
1060 + $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1061 + $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1062 + }
1063 +
1064 + if ( ! $redirect_page_id ) {
1065 + $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1066 + $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1067 + }
1068 +
1069 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1070 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1071 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1072 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1073 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1074 + if ( uwp_is_wpml() ) {
1075 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1076 + if ( ! empty( $wpml_page_id ) ) {
1077 + $redirect_page_id = $wpml_page_id;
1078 + }
1079 + }
1080 + $redirect_to = get_permalink( $redirect_page_id );
1081 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1082 + $redirect_to = esc_url( wp_get_referer() );
1083 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1084 + $redirect_to = $custom_url;
1085 + } else {
1086 + if ( $user && $user->has_cap( 'manage_options' ) ) {
1087 + $redirect_to = admin_url();
1088 + } else {
1089 + $redirect_to = home_url( '/' );
1090 + }
1091 +
1092 + $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1093 + }
1094 +
1095 + return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1096 + }
1097 +
1098 + /**
1099 + * Processes login form submission.
1100 + *
1101 + * @since 1.0.0
1102 + * @package userswp
1103 + *
1104 + */
1105 + public function process_login() {
1106 +
1107 + $data = $_POST;
1108 +
1109 + if ( ! isset( $data['uwp_login_nonce'] ) ) {
1110 + return;
1111 + }
1112 +
1113 + if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1114 + $message = aui()->alert(
1115 + array(
1116 + 'type' => 'error',
1117 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1118 + )
1119 + );
1120 + if ( wp_doing_ajax() ) {
1121 + wp_send_json_error( array( 'message' => $message ) );
1122 + } else {
1123 + return;
1124 + }
1125 + }
1126 +
1127 + global $uwp_notices;
1128 +
1129 + do_action( 'uwp_before_validate', 'login' );
1130 +
1131 + $result = uwp_validate_fields( $data, 'login' );
1132 +
1133 + $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1134 +
1135 + if ( is_wp_error( $result ) ) {
1136 + $message = aui()->alert(
1137 + array(
1138 + 'type' => 'error',
1139 + 'content' => $result->get_error_message(),
1140 + )
1141 + );
1142 + if ( wp_doing_ajax() ) {
1143 + wp_send_json_error( array( 'message' => $message ) );
1144 + } else {
1145 + $uwp_notices[] = array( 'login' => $message );
1146 +
1147 + return;
1148 + }
1149 + }
1150 +
1151 + do_action( 'uwp_after_validate', $result, 'login', $data );
1152 +
1153 + if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1154 + $remember_me = true;
1155 + } else {
1156 + $remember_me = false;
1157 + }
1158 +
1159 + remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1160 +
1161 + global $wp2fa;
1162 + if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1163 + remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1164 + }
1165 +
1166 + $user = wp_signon(
1167 + array(
1168 + 'user_login' => $result['username'],
1169 + 'user_password' => $result['password'],
1170 + 'remember' => $remember_me,
1171 + )
1172 + );
1173 +
1174 + add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1175 +
1176 + if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177 +
1178 + $two_fa = $this->check_2fa( $user );
1179 + if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1180 + if ( is_wp_error( $two_fa ) ) {
1181 + $message = aui()->alert(
1182 + array(
1183 + 'type' => 'error',
1184 + 'content' => $two_fa->get_error_message(),
1185 + )
1186 + );
1187 + wp_send_json_error( array( 'message' => $message ) );
1188 + } else {
1189 + wp_send_json_success(
1190 + array(
1191 + 'html' => $two_fa,
1192 + 'is_2fa' => true,
1193 + )
1194 + );
1195 + }
1196 + }
1197 + }
1198 +
1199 + if ( is_wp_error( $user ) ) {
1200 + $message = aui()->alert(
1201 + array(
1202 + 'type' => 'error',
1203 + 'content' => $user->get_error_message(),
1204 + )
1205 + );
1206 + if ( wp_doing_ajax() ) {
1207 + wp_send_json_error( array( 'message' => $message ) );
1208 + } else {
1209 + $uwp_notices[] = array( 'login' => $message );
1210 +
1211 + return;
1212 + }
1213 + } else {
1214 + do_action( 'uwp_after_process_login', $data );
1215 + $message = aui()->alert(
1216 + array(
1217 + 'type' => 'success',
1218 + 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1219 + )
1220 + );
1221 + if ( wp_doing_ajax() ) {
1222 + $redirect_to = '';
1223 + if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1224 + $redirect_to = $this->get_login_redirect_url( $data, $user );
432 1225 }
433 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
434 - wp_redirect($redirect);
435 - exit();
436 - }
437 - } else {
438 - if ($reg_action == 'require_email_activation') {
439 - global $wp;
440 - $resend_link = uwp_current_page_url();
441 - $resend_link = add_query_arg(
1226 + wp_send_json_success(
442 1227 array(
443 - 'user_id' => $user_id,
444 - 'action' => 'uwp_resend',
445 - '_nonce' => wp_create_nonce('uwp_resend'),
446 - ),
447 - $resend_link
1228 + 'message' => $message,
1229 + 'redirect' => $redirect_to,
1230 + )
448 1231 );
449 - return sprintf(__('An email has been sent to your registered email address. Please click the activation link to proceed. %sResend%s.', 'userswp'), '<a href="'.$resend_link.'"">', '</a>');
450 - } elseif ($reg_action == 'require_admin_review' && defined('UWP_MOD_VERSION')) {
451 - update_user_meta( $user_id, 'uwp_mod', '1' );
1232 + } else {
1233 + $redirect_to = $this->get_login_redirect_url( $data, $user );
1234 + wp_safe_redirect( $redirect_to );
1235 + exit();
1236 + }
1237 +}
1238 + }
452 1239
453 - $email = new UsersWP_Mails();
454 - $send_result = $email->send( 'mod_pending', $user_id );
455 - $user_data = get_user_by('id', $user_id);
456 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
457 - if (is_wp_error($send_result)) {
458 - return $send_result;
459 - }
1240 + public function check_2fa( $user ) {
1241 + if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1242 + return;
1243 + }
460 1244
461 - $admin_send_result = $email->send_admin_email('mod_admin', $user_id);
462 - if (is_wp_error($admin_send_result)) {
463 - return $admin_send_result;
464 - }
1245 + if ( ! $user ) {
1246 + $user = wp_get_current_user();
1247 + }
465 1248
466 - return __('Your account is under moderation. We will email you once its approved.', 'userswp');
467 - } else {
1249 + global $wp2fa;
1250 + $errors = new WP_Error();
468 1251
469 - $login_page_url = wp_login_url();
1252 + if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1253 + return;
1254 + }
1255 + // Invalidate the current login session to prevent from being re-used.
1256 + \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
470 1257
471 - if ($generated_password) {
472 - return sprintf(__('Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %shere%s.', 'userswp'), '<a href="'.$login_page_url.'">', '</a>');
473 - } else {
474 - return sprintf(__('Account registered successfully. Please login %shere%s', 'userswp'), '<a href="'.$login_page_url.'">', '</a>');
475 - }
476 - }
477 - }
1258 + // Also clear the cookies which are no longer valid.
1259 + wp_clear_auth_cookie();
478 1260
1261 + $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1262 + if ( ! $login_nonce ) {
1263 + $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
479 1264
480 - }
1265 + return $errors;
1266 + }
481 1267
482 - /**
483 - * Processes login form submission.
484 - *
485 - * @since 1.0.0
486 - * @package userswp
487 - *
488 - * @param array $data Submitted $_POST data
489 - *
490 - * @return bool|WP_Error|string
491 - */
492 - public function process_login($data) {
1268 + $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
493 1269
494 - $errors = new WP_Error();
1270 + ob_start();
1271 + ?>
495 1272
496 - if( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
497 - return false;
498 - }
1273 + <div class="uwp-2fa-methods-wrap">
1274 + <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1275 + autocomplete="off">
1276 + <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1277 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1278 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1279 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1280 + <?php
499 1281
500 - do_action('uwp_before_validate', 'login');
1282 + // Check to see what provider is set and give the relevant authentication page.
1283 + if ( 'totp' === $provider ) {
1284 + ?>
1285 + <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1286 + <?php
501 1287
502 - $result = uwp_validate_fields($data, 'login');
1288 + echo aui()->input(
1289 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1290 + 'type' => 'tel',
1291 + 'id' => 'authcode',
1292 + 'name' => 'authcode',
1293 + 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1294 + 'value' => '',
1295 + 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1296 + )
1297 + );
503 1298
504 - $result = apply_filters('uwp_validate_result', $result, 'login', $data);
1299 + echo aui()->button(
1300 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1301 + 'type' => 'submit',
1302 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1303 + 'name' => 'submit',
1304 + 'icon' => '',
1305 + 'content' => esc_html__( 'Log In', 'userswp' ),
1306 + )
1307 + );
505 1308
506 - if (is_wp_error($result)) {
507 - return $result;
508 - }
1309 + } elseif ( 'email' === $provider ) {
1310 + $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1311 + if ( empty( $has_token ) || ! $has_token ) {
1312 + \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1313 + }
1314 + ?>
1315 + <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1316 + <?php
1317 + echo aui()->input(
1318 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1319 + 'type' => 'tel',
1320 + 'id' => 'authcode',
1321 + 'name' => 'wp-2fa-email-code',
1322 + 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1323 + 'value' => '',
1324 + 'label' => esc_html__( 'Verification Code', 'userswp' ),
1325 + 'extra_attributes' => array(
1326 + 'size' => 20,
1327 + 'pattern' => '[0-9]*',
1328 + ),
1329 + )
1330 + );
509 1331
510 - do_action('uwp_after_validate', 'login');
1332 + echo aui()->button(
1333 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1334 + 'type' => 'submit',
1335 + 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1336 + 'name' => 'submit',
1337 + 'icon' => '',
1338 + 'content' => esc_html__( 'Log In', 'userswp' ),
1339 + )
1340 + );
511 1341
512 - if (isset($data['remember_me']) && $data['remember_me'] == 'forever') {
513 - $remember_me = true;
514 - } else {
515 - $remember_me = false;
516 - }
1342 + echo aui()->button(
1343 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1344 + 'type' => 'button',
1345 + 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1346 + 'name' => 'wp-2fa-email-code-resend',
1347 + 'icon' => '',
1348 + 'content' => esc_html__( 'Resend Code', 'userswp' ),
1349 + )
1350 + );
517 1351
518 - remove_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1352 + }
1353 + ?>
1354 + </form>
1355 + </div>
519 1356
520 - $res = wp_signon(
1357 + <?php
1358 + $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1359 + if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1360 + ?>
1361 + <div class="uwp-2fa-methods-wrap" style="display:none;">
1362 + <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1363 + class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1364 + <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1365 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1366 + value="<?php echo esc_attr( $user->ID ); ?>"/>
1367 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1368 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1369 + <div class="uwp-backup-fields">
1370 + <?php
1371 + echo aui()->input(
1372 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1373 + 'type' => 'tel',
1374 + 'id' => 'authcode',
1375 + 'name' => 'wp-2fa-backup-code',
1376 + 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1377 + 'value' => '',
1378 + 'label' => esc_html__( 'Backup Code', 'userswp' ),
1379 + 'extra_attributes' => array(
1380 + 'size' => 20,
1381 + 'pattern' => '[0-9]*',
1382 + ),
1383 + )
1384 + );
1385 +
1386 + echo aui()->button(
1387 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1388 + 'type' => 'submit',
1389 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1390 + 'name' => 'submit',
1391 + 'icon' => '',
1392 + 'content' => esc_html__( 'Log In', 'userswp' ),
1393 + )
1394 + );
1395 + ?>
1396 + </div>
1397 + </form>
1398 + </div>
1399 + <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1400 + <script type="text/javascript">
1401 + jQuery('.uwp-switch-2fa-methods').on('click',
1402 + function (e) {
1403 + e.preventDefault();
1404 + jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1405 + jQuery('.uwp-2fa-methods-wrap').toggle();
1406 + return false;
1407 + }
1408 + );
1409 + </script>
1410 + <?php
1411 + }
1412 +
1413 + return ob_get_clean();
1414 + }
1415 +
1416 + public function process_login_2fa() {
1417 + if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1418 + return;
1419 + }
1420 +
1421 + $auth_id = (int) $_POST['uwp-auth-id'];
1422 + $user = get_userdata( $auth_id );
1423 + if ( ! $user ) {
1424 + $message = aui()->alert(
1425 + array(
1426 + 'type' => 'error',
1427 + 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1428 + )
1429 + );
1430 +
1431 + wp_send_json_error( array( 'message' => $message ) );
1432 + }
1433 +
1434 + global $wp2fa;
1435 +
1436 + $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1437 + if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1438 +
1439 + $message = aui()->alert(
1440 + array(
1441 + 'type' => 'error',
1442 + 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1443 + )
1444 + );
1445 +
1446 + wp_send_json_error( array( 'message' => $message ) );
1447 + }
1448 +
1449 + if ( isset( $_POST['provider'] ) ) {
1450 + $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1451 + $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1452 + if ( isset( $providers[ $provider ] ) ) {
1453 + $provider = $providers[ $provider ];
1454 + } elseif ( isset( $provider ) ) {
1455 + $provider = $provider;
1456 + } else {
1457 + $provider = $provider;
1458 + }
1459 + }
1460 +
1461 + // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1462 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1463 +
1464 + }
1465 +
1466 + // Validate TOTP.
1467 + if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
1468 +
1469 + do_action( 'wp_login_failed', $user->user_login );
1470 +
1471 + $message = aui()->alert(
1472 + array(
1473 + 'type' => 'error',
1474 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1475 + )
1476 + );
1477 +
1478 + wp_send_json_error( array( 'message' => $message ) );
1479 + }
1480 +
1481 + // Validate Email.
1482 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
1483 +
1484 + do_action( 'wp_login_failed', $user->user_login );
1485 +
1486 + if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1487 + $message = aui()->alert(
1488 + array(
1489 + 'type' => 'info',
1490 + 'content' => __( 'A new code has been sent.', 'userswp' ),
1491 + )
1492 + );
1493 +
1494 + wp_send_json_error( array( 'message' => $message ) );
1495 + } else {
1496 + $message = aui()->alert(
1497 + array(
1498 + 'type' => 'error',
1499 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1500 + )
1501 + );
1502 +
1503 + wp_send_json_error( array( 'message' => $message ) );
1504 + }
1505 + }
1506 +
1507 + // Backup Codes.
1508 + if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1509 +
1510 + do_action( 'wp_login_failed', $user->user_login );
1511 +
1512 + $message = aui()->alert(
1513 + array(
1514 + 'type' => 'error',
1515 + 'content' => __( 'Invalid backup code.', 'userswp' ),
1516 + )
1517 + );
1518 +
1519 + wp_send_json_error( array( 'message' => $message ) );
1520 + }
1521 +
1522 + \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1523 +
1524 + $rememberme = false;
1525 + $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1526 + if ( ! empty( $remember ) ) {
1527 + $rememberme = true;
1528 + }
1529 +
1530 + wp_set_auth_cookie( $user->ID, $rememberme );
1531 +
1532 + do_action( 'two_factor_user_authenticated', $user );
1533 +
1534 + $message = aui()->alert(
521 1535 array(
522 - 'user_login' => $result['uwp_login_username'],
523 - 'user_password' => $result['password'],
524 - 'remember' => $remember_me
1536 + 'type' => 'success',
1537 + 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
525 1538 )
526 - );
1539 + );
527 1540
528 - add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1541 + wp_send_json_success( array( 'message' => $message ) );
1542 + }
529 1543
530 - if (is_wp_error($res)) {
531 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
532 - return $errors;
533 - } else {
534 - $redirect_page_id = uwp_get_option('login_redirect_to', -1);
535 - if (isset($_REQUEST['redirect_to']) && !empty($_REQUEST['redirect_to'])) {
536 - $redirect_to = esc_url($_REQUEST['redirect_to']);
537 - } elseif (isset($data['redirect_to']) && !empty($data['redirect_to'])) {
538 - $redirect_to = esc_url($data['redirect_to']);
539 - } elseif (isset($redirect_page_id) && (int)$redirect_page_id > 0) {
540 - $redirect_to = get_permalink($redirect_page_id);
541 - } else {
542 - if ( current_user_can('manage_options') ) {
543 - $redirect_to = admin_url();
544 - } else {
545 - $redirect_to = home_url('/');
546 - }
547 - }
1544 + public function get_login_redirect_url( $data, $user ) {
1545 + if ( is_int( $user ) ) {
1546 + $user = get_userdata( $user );
1547 + }
548 1548
549 - $redirect_to = apply_filters('uwp_login_redirect', $redirect_to);
550 - wp_redirect($redirect_to);
551 - exit();
552 - }
553 - }
1549 + $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1550 + $custom_url = uwp_get_option( 'login_redirect_custom_url' );
554 1551
555 - /**
556 - * Processes forgot password form submission.
557 - *
558 - * @since 1.0.0
559 - * @package userswp
560 - *
561 - * @param array $data Submitted $_POST data
562 - *
563 - * @return bool|WP_Error|string
564 - */
565 - public function process_forgot($data) {
1552 + if ( $user && isset( $user->roles[0] ) ) {
1553 + $user_role = $user->roles[0];
1554 + $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1555 + $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1556 + }
566 1557
567 - $errors = new WP_Error();
1558 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1559 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1560 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1561 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1562 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1563 + if ( uwp_is_wpml() ) {
1564 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1565 + if ( ! empty( $wpml_page_id ) ) {
1566 + $redirect_page_id = $wpml_page_id;
1567 + }
1568 + }
1569 + $redirect_to = get_permalink( $redirect_page_id );
1570 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1571 + $redirect_to = esc_url( wp_get_referer() );
1572 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1573 + $redirect_to = $custom_url;
1574 + } else {
1575 + $redirect_to = home_url( '/' );
1576 + $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1577 + }
568 1578
569 - if( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
570 - return false;
571 - }
1579 + return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1580 + }
572 1581
573 - do_action('uwp_before_validate', 'forgot');
1582 + /**
1583 + * Processes forgot password form submission.
1584 + *
1585 + * @since 1.0.0
1586 + * @package userswp
1587 + *
1588 + */
1589 + public function process_forgot() {
574 1590
575 - $result = uwp_validate_fields($data, 'forgot');
1591 + $data = $_POST;
576 1592
577 - $result = apply_filters('uwp_validate_result', $result, 'forgot', $data);
1593 + if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1594 + return;
1595 + }
578 1596
579 - if (is_wp_error($result)) {
580 - return $result;
581 - }
1597 + if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1598 + $message = aui()->alert(
1599 + array(
1600 + 'type' => 'error',
1601 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1602 + )
1603 + );
1604 + if ( wp_doing_ajax() ) {
1605 + wp_send_json_error( $message );
1606 + } else {
1607 + return;
1608 + }
1609 + }
582 1610
583 - do_action('uwp_after_validate', 'forgot');
1611 + global $uwp_notices;
584 1612
1613 + do_action( 'uwp_before_validate', 'forgot' );
585 1614
586 - $user_data = get_user_by('email', $data['uwp_forgot_email']);
1615 + $result = uwp_validate_fields( $data, 'forgot' );
587 1616
588 - // make sure user account is active before account reset
589 - $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
590 - if ($mod_value == 'email_unconfirmed') {
591 - $errors->add('activate_account', __('<strong>Error</strong>: Your account is not activated yet. Please activate your account first.', 'userswp'));
592 - }
1617 + $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
593 1618
594 - $error_code = $errors->get_error_code();
595 - if (!empty($error_code)) {
596 - return $errors;
597 - }
598 -
599 - $email = new UsersWP_Mails();
600 - $send_result = $email->send( 'forgot', $user_data->ID );
601 -
602 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
603 - if (is_wp_error($send_result)) {
604 - return $send_result;
605 - }
1619 + if ( is_wp_error( $result ) ) {
1620 + $message = aui()->alert(
1621 + array(
1622 + 'type' => 'error',
1623 + 'content' => $result->get_error_message(),
1624 + )
1625 + );
1626 + if ( wp_doing_ajax() ) {
1627 + wp_send_json_error( $message );
1628 + } else {
1629 + $uwp_notices[] = array( 'forgot' => $message );
606 1630
607 - return true;
608 - }
1631 + return;
1632 + }
1633 + }
609 1634
610 - /**
611 - * Processes change password form submission.
612 - *
613 - * @since 1.0.0
614 - * @package userswp
615 - *
616 - * @param array $data Submitted $_POST data
617 - *
618 - * @return bool|WP_Error|string
619 - */
620 - public function process_change($data) {
1635 + do_action( 'uwp_after_validate', $result, 'forgot', $data );
621 1636
622 - $errors = new WP_Error();
1637 + $user_data = get_user_by( 'email', $data['email'] );
623 1638
624 - if( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
625 - return false;
626 - }
1639 + // if no user we fake it and bail
1640 + if ( ! $user_data ) {
1641 + $args = apply_filters(
1642 + 'uwp_forgot_error_message',
1643 + array(
1644 + 'type' => 'error',
1645 + 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1646 + )
1647 + );
627 1648
628 - do_action('uwp_before_validate', 'change');
1649 + $message = aui()->alert( $args );
1650 + if ( wp_doing_ajax() ) {
1651 + wp_send_json_success( $message );
1652 + } else {
1653 + $uwp_notices[] = array( 'forgot' => $message );
629 1654
630 - $result = uwp_validate_fields($data, 'change');
1655 + return;
1656 + }
1657 + }
631 1658
632 - $result = apply_filters('uwp_validate_result', $result, 'change', $data);
1659 + // make sure user account is active before account reset
1660 + $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1661 + if ( $mod_value == 'email_unconfirmed' ) {
1662 + $message = aui()->alert(
1663 + array(
1664 + 'type' => 'error',
1665 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1666 + )
1667 + );
1668 + if ( wp_doing_ajax() ) {
1669 + wp_send_json_error( $message );
1670 + } else {
1671 + $uwp_notices[] = array( 'forgot' => $message );
633 1672
634 - if (is_wp_error($result)) {
635 - return $result;
636 - }
1673 + return;
1674 + }
1675 + }
637 1676
638 - do_action('uwp_after_validate', 'change');
1677 + $user_data = get_userdata( $user_data->ID );
639 1678
640 - $user_data = get_user_by('id', get_current_user_id());
1679 + $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
641 1680
642 - if (is_wp_error($user_data)) {
643 - return $user_data;
644 - }
1681 + if ( ! $allow ) {
1682 + return false;
1683 + } elseif ( is_wp_error( $allow ) ) {
1684 + return false;
1685 + }
645 1686
646 - $email = new UsersWP_Mails();
647 - $send_result = $email->send( 'change', $user_data->ID );
1687 + $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
648 1688
649 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
650 - if (is_wp_error($send_result)) {
651 - return $send_result;
652 - }
1689 + global $wpdb, $wp_hasher;
1690 + $reset_link = '';
653 1691
654 - wp_set_password( $data['uwp_change_password'], $user_data->ID );
655 - wp_set_auth_cookie( $user_data->ID, false);
1692 + if ( $as_password ) {
1693 + $new_pass = wp_generate_password( 12, false );
1694 + wp_set_password( $new_pass, $user_data->ID );
1695 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
1696 + update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
1697 + }
1698 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
1699 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1700 + $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
656 1701
657 - return true;
658 - }
1702 + } else {
1703 + $key = wp_generate_password( 20, false );
1704 + do_action( 'retrieve_password_key', $user_data->user_login, $key );
659 1705
660 - /**
661 - * Processes reset password form submission.
662 - *
663 - * @since 1.0.0
664 - * @package userswp
665 - *
666 - * @param array $data Submitted $_POST data
667 - *
668 - * @return bool|WP_Error|string
669 - */
670 - public function process_reset($data) {
1706 + if ( empty( $wp_hasher ) ) {
1707 + require_once ABSPATH . 'wp-includes/class-phpass.php';
1708 + $wp_hasher = new PasswordHash( 8, true );
1709 + }
1710 + $hashed = $wp_hasher->HashPassword( $key );
1711 + $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1712 + $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1713 + $message .= home_url( '/' ) . '</p>';
1714 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1715 + $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
1716 + $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
1717 + $reset_page = uwp_get_page_id( 'reset_page', false );
1718 + if ( $reset_page ) {
1719 + $reset_link = add_query_arg(
1720 + array(
1721 + 'key' => $key,
1722 + 'login' => rawurlencode( $user_data->user_login ),
1723 + ),
1724 + get_permalink( $reset_page )
1725 + );
1726 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1727 + } else {
1728 + $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
1729 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1730 + }
1731 + $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
1732 + }
671 1733
672 - $errors = new WP_Error();
1734 + $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
673 1735
674 - if( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
675 - return false;
676 - }
1736 + $email_vars = array(
1737 + 'user_id' => $user_data->ID,
1738 + 'login_details' => $message,
1739 + 'reset_link' => $reset_link,
1740 + );
677 1741
678 - do_action('uwp_before_validate', 'reset');
1742 + UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
679 1743
680 - $result = uwp_validate_fields($data, 'reset');
1744 + do_action( 'uwp_after_process_forgot', $data );
681 1745
682 - $result = apply_filters('uwp_validate_result', $result, 'reset', $data);
1746 + $message = aui()->alert(
1747 + array(
1748 + 'type' => 'success',
1749 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
1750 + )
1751 + );
1752 + if ( wp_doing_ajax() ) {
1753 + wp_send_json_success( $message );
1754 + } else {
1755 + $uwp_notices[] = array( 'forgot' => $message );
1756 + }
1757 + }
683 1758
684 - if (is_wp_error($result)) {
685 - return $result;
686 - }
1759 + /**
1760 + * Processes change password form submission.
1761 + *
1762 + * @since 1.0.0
1763 + * @package userswp
1764 + *
1765 + */
1766 + public function process_change() {
687 1767
688 - do_action('uwp_after_validate', 'reset');
1768 + $data = $_POST;
689 1769
690 - $login = $data['uwp_reset_username'];
691 - $key = $data['uwp_reset_key'];
692 - $user_data = check_password_reset_key( $key, $login );
1770 + if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
1771 + return;
1772 + }
693 1773
694 - if (is_wp_error($user_data)) {
695 - return $user_data;
696 - }
1774 + global $uwp_notices;
697 1775
698 - $email = new UsersWP_Mails();
699 - $send_result = $email->send( 'reset', $user_data->ID );
1776 + if ( is_uwp_account_page() ) {
1777 + $notice_type = 'account';
1778 + } else {
1779 + $notice_type = 'change';
1780 + }
700 1781
701 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
702 - if (is_wp_error($send_result)) {
703 - return $send_result;
704 - }
1782 + do_action( 'uwp_before_validate', 'change' );
705 1783
706 - wp_set_password( $data['uwp_reset_password'], $user_data->ID );
1784 + $result = uwp_validate_fields( $data, 'change' );
707 1785
708 - return true;
709 - }
1786 + $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
710 1787
711 - /**
712 - * Modifies the mail extras based on the notification type.
713 - *
714 - * @since 1.0.0
715 - * @package userswp
716 - * @subpackage userswp/includes
717 - * @param string $extras Unmodified mail extras.
718 - * @param string $type Notification type.
719 - * @return string Modified mail extras.
720 - */
721 - public function init_mail_extras($extras, $type, $user_id) {
722 - switch ($type) {
723 - case "activate":
724 - $extras = $this->generate_activate_message($user_id);
725 - break;
726 - case "register":
727 - $extras = $this->generate_register_message($user_id);
728 - break;
729 - case "forgot":
730 - $extras = $this->generate_forgot_message($user_id);
731 - }
732 - return $extras;
733 - }
1788 + if ( is_wp_error( $result ) ) {
1789 + $message = aui()->alert(
1790 + array(
1791 + 'type' => 'error',
1792 + 'content' => $result->get_error_message(),
1793 + )
1794 + );
1795 + $uwp_notices[] = array( $notice_type => $message );
734 1796
735 - /**
736 - * Modifies the admin mail extras based on the notification type.
737 - *
738 - * @since 1.0.0
739 - * @package userswp
740 - * @subpackage userswp/includes
741 - * @param string $extras Unmodified mail extras.
742 - * @param string $type Notification type.
743 - * @return string Modified mail extras.
744 - */
745 - public function init_admin_mail_extras($extras, $type, $user_id) {
746 - switch ($type) {
747 - case "register_admin":
748 - $user_data = get_userdata($user_id);
749 - $extras = __('<p><b>' . __('User Information :', 'userswp') . '</b></p>
750 - <p>' . __('First Name:', 'userswp') . ' ' . $user_data->first_name . '</p>
751 - <p>' . __('Last Name:', 'userswp') . ' ' . $user_data->last_name . '</p>
752 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
753 - <p>' . __('Email:', 'userswp') . ' ' . $user_data->user_email . '</p>');
754 - break;
755 - }
756 - return $extras;
757 - }
1797 + return;
1798 + }
758 1799
759 - /**
760 - * Generates activate email message.
761 - *
762 - * @since 1.0.0
763 - * @package userswp
764 - *
765 - * @param int $user_id User ID.
766 - *
767 - * @return bool|string Message.
768 - */
769 - public function generate_activate_message($user_id) {
1800 + do_action( 'uwp_after_validate', $result, 'change', $data );
770 1801
771 - $user_data = get_userdata($user_id);
772 - global $wpdb;
773 - $key = wp_generate_password( 20, false );
774 - do_action( 'uwp_activation_key', $user_data->user_login, $key );
1802 + $user_data = get_user_by( 'id', get_current_user_id() );
775 1803
776 - global $wp_hasher;
777 - if ( empty( $wp_hasher ) ) {
778 - require_once ABSPATH . 'wp-includes/class-phpass.php';
779 - $wp_hasher = new PasswordHash( 8, true );
780 - }
781 - $hashed = $wp_hasher->HashPassword( $key );
782 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
783 - update_user_meta( $user_id, 'uwp_mod', 'email_unconfirmed' );
784 - $message = __('To activate your account, visit the following address:', 'userswp') . "\r\n\r\n";
785 - $act_url = add_query_arg(
1804 + if ( ! $user_data ) {
1805 + $message = aui()->alert(
1806 + array(
1807 + 'type' => 'error',
1808 + 'content' => $user_data->get_error_message(),
1809 + )
1810 + );
1811 + $uwp_notices[] = array( $notice_type => $message );
1812 +
1813 + return;
1814 + }
1815 +
1816 + $email_vars = array(
1817 + 'user_id' => $user_data->ID,
1818 + );
1819 +
1820 + UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
1821 +
1822 + wp_set_password( $result['password'], $user_data->ID );
1823 +
1824 + $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
1825 + if ( $password_nag ) {
1826 + delete_user_meta( $user_data->ID, 'default_password_nag' );
1827 + }
1828 +
1829 + delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
1830 +
1831 + $message = aui()->alert(
786 1832 array(
787 - 'uwp_activate' => 'yes',
788 - 'key' => $key,
789 - 'login' => $user_data->user_login
790 - ),
791 - site_url()
792 - );
1833 + 'type' => 'success',
1834 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
1835 + )
1836 + );
793 1837
794 - $message .= "<a href='".$act_url."' target='_blank'>".$act_url."</a>" . "\r\n";
1838 + $uwp_notices[] = array( $notice_type => $message );
795 1839
796 - $activate_message = '<p><b>' . __('Please activate your account :', 'userswp') . '</b></p><p>' . $message . '</p>';
1840 + do_action( 'uwp_after_process_change', $data );
797 1841
798 - return apply_filters('uwp_activation_mail_message', $activate_message, $user_id);
1842 + wp_logout();
1843 + exit();
1844 + }
799 1845
800 - }
1846 + /**
1847 + * Processes reset password form submission.
1848 + *
1849 + * @since 1.0.0
1850 + * @package userswp
1851 + *
1852 + */
1853 + public function process_reset() {
801 1854
802 - /**
803 - * Generates register email message.
804 - *
805 - * @since 1.0.0
806 - * @package userswp
807 - *
808 - * @param int $user_id User ID.
809 - *
810 - * @return bool|string Message.
811 - */
812 - public function generate_register_message($user_id) {
1855 + $data = $_POST;
813 1856
814 - $user_data = get_userdata($user_id);
815 - if(isset($this->generated_password) && !empty($this->generated_password)) {
816 - if(!uwp_get_option('change_disable_password_nag')) {
817 - update_user_meta($user_id, 'default_password_nag', true); //Set up the Password change nag.
818 - }
819 - $message_pass = $this->generated_password;
820 - $this->generated_password = false;
821 - } else {
822 - $message_pass = __("Password you entered", 'userswp');
823 - }
824 - $message = __('<p><b>' . __('Your login Information :', 'userswp') . '</b></p>
825 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
826 - <p>' . __('Password:', 'userswp') . ' ' . $message_pass . '</p>');
1857 + if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
1858 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
1859 + }
827 1860
828 - return apply_filters('uwp_register_mail_message', $message, $user_id, $this->generated_password);
1861 + if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
1862 + return;
1863 + }
829 1864
830 - }
831 -
832 - /**
833 - * Generates forgot password email message.
834 - *
835 - * @since 1.0.0
836 - * @package userswp
837 - *
838 - * @param int $user_id User ID.
839 - *
840 - * @return bool|string Message.
841 - */
842 - public function generate_forgot_message($user_id) {
1865 + global $uwp_notices;
843 1866
844 - $user_data = get_userdata($user_id);
845 - global $wpdb, $wp_hasher;
1867 + do_action( 'uwp_before_validate', 'reset' );
846 1868
847 - $allow = apply_filters('allow_password_reset', true, $user_data->ID);
848 - if ( ! $allow )
849 - return false;
850 - else if ( is_wp_error($allow) )
851 - return false;
1869 + $result = uwp_validate_fields( $data, 'reset' );
852 1870
853 - $as_password = apply_filters('uwp_forgot_message_as_password', false);
1871 + $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
854 1872
855 - if ($as_password) {
856 - $new_pass = wp_generate_password(12, false);
857 - wp_set_password($new_pass, $user_data->ID);
858 - if(!uwp_get_option('change_disable_password_nag')) {
859 - update_user_meta($user_data->ID, 'default_password_nag', true); //Set up the Password change nag.
860 - }
861 - $message = '<p><b>' . __('Your login Information :', 'userswp') . '</b></p>';
862 - $message .= '<p>' . sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "</p>";
863 - $message .= '<p>' . sprintf(__('Password: %s', 'userswp'), $new_pass) . "</p>";
1873 + if ( is_wp_error( $result ) ) {
1874 + $message = aui()->alert(
1875 + array(
1876 + 'type' => 'error',
1877 + 'content' => $result->get_error_message(),
1878 + )
1879 + );
1880 + $uwp_notices[] = array( 'reset' => $message );
864 1881
865 - } else {
866 - $key = wp_generate_password( 20, false );
867 - do_action( 'retrieve_password_key', $user_data->user_login, $key );
1882 + return;
1883 + }
868 1884
869 - if ( empty( $wp_hasher ) ) {
870 - require_once ABSPATH . 'wp-includes/class-phpass.php';
871 - $wp_hasher = new PasswordHash( 8, true );
872 - }
873 - $hashed = $wp_hasher->HashPassword( $key );
874 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
875 - $message = '<p>' .__('You have requested to reset your password for the following account:', 'userswp') . "</p>";
876 - $message .= home_url( '/' ) . "</p>";
877 - $message .= '<p>' .sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "</p>";
878 - $message .= '<p>' .__('If this was by mistake, just ignore this email and nothing will happen.', 'userswp') . "</p>";
879 - $message .= '<p>' .__('To reset your password, click the following link and follow the instructions.', 'userswp') . "</p>";
880 - $message = apply_filters('uwp_forgot_password_message', $message, $user_data);
881 - $reset_page = uwp_get_page_id('reset_page', false);
882 - if ($reset_page) {
883 - $reset_link = add_query_arg( array(
884 - 'key' => $key,
885 - 'login' => rawurlencode($user_data->user_login),
886 - ), get_permalink($reset_page) );
887 - $message .= "<a href='".$reset_link."' target='_blank'>".$reset_link."</a>" . "\r\n";
888 - } else {
889 - $message .= site_url("reset?key=$key&login=" . rawurlencode($user_data->user_login), 'login') . "\r\n";
890 - }
891 - }
1885 + do_action( 'uwp_after_validate', $result, 'reset', $data );
892 1886
1887 + $login = sanitize_text_field( $data['uwp_reset_username'] );
1888 + $key = sanitize_text_field( $data['uwp_reset_key'] );
893 1889
894 - return $message;
1890 + $user = get_user_by( 'login', $login );
1891 + if ( ! $user ) {
1892 + $message = aui()->alert(
1893 + array(
1894 + 'type' => 'error',
1895 + 'content' => __( 'Invalid username.', 'userswp' ),
1896 + )
1897 + );
1898 + $uwp_notices[] = array( 'reset' => $message );
895 1899
896 - }
1900 + return;
1901 + }
897 1902
898 - /**
899 - * Processes account form submission.
900 - *
901 - * @since 1.0.0
902 - * @package userswp
903 - *
904 - * @param array $data Submitted $_POST data
905 - * @param array $files Submitted $_FILES data
906 - *
907 - * @return bool|WP_Error|string
908 - */
909 - public function process_account($data = array(), $files = array()) {
1903 + clean_user_cache( $user );
910 1904
911 - $file_obj = new UsersWP_Files();
912 -
913 - $current_user_id = get_current_user_id();
914 - if (!$current_user_id) {
915 - return false;
916 - }
1905 + $user_data = check_password_reset_key( $key, $login );
917 1906
918 - $errors = new WP_Error();
1907 + if ( is_wp_error( $user_data ) ) {
1908 + $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
1909 + $message = aui()->alert(
1910 + array(
1911 + 'type' => 'error',
1912 + 'content' => $error,
1913 + )
1914 + );
1915 + $uwp_notices[] = array( 'reset' => $message );
919 1916
920 - if( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
921 - return false;
922 - }
1917 + return;
1918 + }
923 1919
924 - do_action('uwp_before_validate', 'account');
1920 + $email_vars = array(
1921 + 'user_id' => $user_data->ID,
1922 + );
925 1923
926 - $result = uwp_validate_fields($data, 'account');
1924 + UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
927 1925
928 - $result = apply_filters('uwp_validate_result', $result, 'account', $data);
1926 + wp_set_password( $data['password'], $user_data->ID );
929 1927
930 - if (is_wp_error($result)) {
931 - return $result;
932 - }
1928 + $login_page_url = uwp_get_login_page_url();
1929 + $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
1930 + $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
1931 + $message = aui()->alert(
1932 + array(
1933 + 'type' => 'success',
1934 + 'content' => $message,
1935 + )
1936 + );
1937 + $uwp_notices[] = array( 'reset' => $message );
933 1938
934 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'account');
1939 + do_action( 'uwp_after_process_reset', $data );
1940 + }
935 1941
936 - if (is_wp_error($uploads_result)) {
937 - return $uploads_result;
938 - }
1942 + /**
1943 + * Processes account form submission.
1944 + *
1945 + * @since 1.0.0
1946 + * @package userswp
1947 + *
1948 + */
1949 + public function process_account() {
939 1950
940 - do_action('uwp_after_validate', 'account');
1951 + $data = wp_unslash( $_POST );
1952 + $files = $_FILES;
941 1953
942 - //unset if value is empty for files
943 - foreach ($uploads_result as $upload_file_key => $upload_file_value) {
944 - if (empty($upload_file_value)) {
945 - unset($uploads_result[$upload_file_key]);
946 - }
947 - }
1954 + if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
1955 + return;
1956 + }
948 1957
949 - $result = array_merge( $result, $uploads_result );
1958 + if ( ! is_user_logged_in() ) {
1959 + return;
1960 + }
950 1961
1962 + global $uwp_notices;
1963 + $file_obj = new UsersWP_Files();
951 1964
952 - $args = array(
953 - 'ID' => $current_user_id
954 - );
1965 + do_action( 'uwp_before_validate', 'account' );
955 1966
956 - if (isset($result['uwp_account_email'])) {
957 - $args['user_email'] = $result['uwp_account_email'];
958 - }
1967 + $result = uwp_validate_fields( $data, 'account' );
959 1968
960 - if (isset($result['uwp_account_first_name']) && isset($result['uwp_account_last_name'])) {
961 - $args['display_name'] = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
962 - }
1969 + $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
963 1970
964 - if (isset($result['uwp_account_first_name'])) {
965 - $args['first_name'] = $result['uwp_account_first_name'];
966 - }
1971 + if ( is_wp_error( $result ) ) {
1972 + $message = aui()->alert(
1973 + array(
1974 + 'type' => 'error',
1975 + 'content' => $result->get_error_message(),
1976 + )
1977 + );
1978 + $uwp_notices[] = array( 'account' => $message );
967 1979
968 - if (isset($result['uwp_account_last_name'])) {
969 - $args['last_name'] = $result['uwp_account_last_name'];
970 - }
1980 + return;
1981 + }
971 1982
972 - if (isset($result['uwp_account_bio'])) {
973 - $args['description'] = $result['uwp_account_bio'];
974 - }
1983 + $uploads_result = $file_obj->validate_uploads( $files, 'account' );
975 1984
976 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
977 - $args['display_name'] = $result['uwp_account_display_name'];
978 - }
1985 + if ( is_wp_error( $uploads_result ) ) {
1986 + $message = aui()->alert(
1987 + array(
1988 + 'type' => 'error',
1989 + 'content' => $uploads_result->get_error_message(),
1990 + )
1991 + );
1992 + $uwp_notices[] = array( 'account' => $message );
979 1993
980 - if (isset($result['password'])) {
981 - $args['user_pass'] = $result['password'];
982 - }
1994 + return;
1995 + }
983 1996
984 - $user_id = wp_update_user( $args );
1997 + do_action( 'uwp_after_validate', $result, 'account', $data );
985 1998
986 - if (!$user_id) {
987 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
988 - return $errors;
989 - }
1999 + //unset if value is empty for files
2000 + foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2001 + if ( empty( $upload_file_value ) ) {
2002 + unset( $uploads_result[ $upload_file_key ] );
2003 + }
2004 + }
990 2005
991 - $res = $this->uwp_save_user_extra_fields($user_id, $result, 'account');
2006 + $result = array_merge( $result, $uploads_result );
992 2007
993 - if (!$res) {
994 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
995 - }
2008 + $args = array(
2009 + 'ID' => get_current_user_id(),
2010 + );
996 2011
997 - $error_code = $errors->get_error_code();
998 - if (!empty($error_code)) {
999 - return $errors;
1000 - }
2012 + if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2013 + $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2014 + }
1001 2015
2016 + if ( isset( $result['first_name'] ) ) {
2017 + $args['first_name'] = $result['first_name'];
2018 + }
1002 2019
1003 - if (uwp_get_option('enable_account_update_notification') == '1') {
1004 - $user_data = get_user_by('id', $user_id);
2020 + if ( isset( $result['last_name'] ) ) {
2021 + $args['last_name'] = $result['last_name'];
2022 + }
1005 2023
1006 - $email = new UsersWP_Mails();
1007 - $send_result = $email->send( 'account', $user_data->ID );
2024 + if ( isset( $result['user_url'] ) ) {
2025 + $args['user_url'] = $result['user_url'];
2026 + }
1008 2027
1009 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
1010 - if (is_wp_error($send_result)) {
1011 - return $send_result;
1012 - }
1013 -
1014 - }
1015 -
1016 - return true;
2028 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2029 + $args['display_name'] = $result['display_name'];
2030 + }
1017 2031
1018 - }
2032 + if ( isset( $result['password'] ) ) {
2033 + $args['user_pass'] = $result['password'];
2034 + }
1019 2035
1020 - /**
1021 - * Processes avatar and banner uploads form submission.
1022 - *
1023 - * @since 1.0.0
1024 - * @package userswp
1025 - *
1026 - * @param array $data Submitted $_POST data
1027 - * @param array $files Submitted $_FILES data
1028 - *
1029 - * @return bool|WP_Error|string File url to crop.
1030 - */
1031 - public function process_upload_submit($data = array(), $files = array(), $type = 'avatar') {
2036 + $user_id = wp_update_user( $args );
1032 2037
1033 - $file_obj = new UsersWP_Files();
1034 -
1035 - $current_user_id = get_current_user_id();
1036 - if (!$current_user_id) {
1037 - return false;
1038 - }
2038 + if ( is_wp_error( $user_id ) ) {
2039 + $message = aui()->alert(
2040 + array(
2041 + 'type' => 'error',
2042 + 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2043 + )
2044 + );
2045 + $uwp_notices[] = array( 'account' => $message );
1039 2046
1040 - if( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
1041 - return false;
1042 - }
2047 + return;
2048 + }
1043 2049
1044 - do_action('uwp_before_validate', $type);
2050 + $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
1045 2051
1046 - $result = $file_obj->uwp_validate_uploads($files, $type);
2052 + if ( ! $res ) {
2053 + $message = aui()->alert(
2054 + array(
2055 + 'type' => 'error',
2056 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2057 + )
2058 + );
2059 + $uwp_notices[] = array( 'account' => $message );
1047 2060
1048 - $result = apply_filters('uwp_validate_result', $result, $type, $data);
2061 + return;
2062 + }
1049 2063
1050 - if (is_wp_error($result)) {
1051 - return $result;
1052 - }
2064 + //updating bio field after saving extra fields to reflect the points in mycred add on.
2065 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2066 + $args = array(
2067 + 'ID' => $user_id,
2068 + 'description' => $result['bio'],
2069 + );
2070 + wp_update_user( $args );
2071 + }
1053 2072
1054 - $profile_url = uwp_build_profile_tab_url($current_user_id);
2073 + $user_data = get_userdata( $user_id );
1055 2074
1056 - $url = add_query_arg(
1057 - array(
1058 - 'uwp_crop' => $result['uwp_'.$type.'_file'],
1059 - 'type' => $type
1060 - ),
1061 - $profile_url);
2075 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
1062 2076
1063 - return $url;
2077 + if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
1064 2078
1065 - }
2079 + if ( email_exists( trim( $result['email'] ) ) ) {
2080 + $message = aui()->alert(
2081 + array(
2082 + 'type' => 'error',
2083 + 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2084 + )
2085 + );
1066 2086
1067 - /**
1068 - * Processes avatar and banner uploads image crop.
1069 - *
1070 - * @since 1.0.0
1071 - * @since 1.0.12 New param $unlink_prev_img introduced.
1072 - * @package userswp
1073 - *
1074 - * @param array $data Submitted $_POST data
1075 - * @param string $type Image type. Default 'avatar'.
1076 - * @param bool $unlink_prev_img True to remove previous image. Default false;
1077 - *
1078 - * @return bool|WP_Error|string Profile url.
1079 - */
1080 - public function process_image_crop($data = array(), $type = 'avatar', $unlink_prev_img = false) {
1081 -
1082 - if (!is_user_logged_in()) {
1083 - return false;
2087 + $uwp_notices[] = array( 'account' => $message );
2088 + return;
2089 +
2090 + }
2091 +
2092 + $hash = md5( $result['email'] . time() . wp_rand() );
2093 + $new_admin_email = array(
2094 + 'hash' => $hash,
2095 + 'newemail' => $result['email'],
2096 + );
2097 +
2098 + update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2099 +
2100 + $new_email_link = add_query_arg(
2101 + array(
2102 + 'uwp_new_email' => 'yes',
2103 + 'key' => $hash,
2104 + 'login' => $user_data->user_login,
2105 + ),
2106 + uwp_get_account_page_url()
2107 + );
2108 +
2109 + $email_vars = array(
2110 + 'user_id' => $user_id,
2111 + 'new_email' => $result['email'],
2112 + 'new_email_link' => esc_url( $new_email_link ),
2113 + );
2114 +
2115 + UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2116 +
2117 + $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2118 + $message = aui()->alert(
2119 + array(
2120 + 'type' => 'success',
2121 + 'content' => $message,
2122 + )
2123 + );
2124 +
2125 + $uwp_notices[] = array( 'account' => $message );
2126 +
2127 + } else {
2128 + $email_vars = array(
2129 + 'user_id' => $user_id,
2130 + 'form_fields' => $form_fields,
2131 + );
2132 +
2133 + UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2134 +
2135 + $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2136 + $message = aui()->alert(
2137 + array(
2138 + 'type' => 'success',
2139 + 'content' => $message,
2140 + )
2141 + );
2142 +
2143 + $uwp_notices[] = array( 'account' => $message );
1084 2144 }
1085 2145
1086 - // If is current user's profile (profile.php)
1087 - if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
1088 - $user_id = get_current_user_id();
1089 - // If is another user's profile page
1090 - } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
1091 - $user_id = $_GET['user_id'];
1092 - // Otherwise something is wrong.
1093 - } else {
1094 - $user_id = get_current_user_id();
1095 - }
1096 - $image_url = $data['uwp_crop'];
1097 -
1098 - $errors = new WP_Error();
1099 - if (empty($image_url)) {
1100 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
1101 - }
2146 + do_action( 'uwp_after_process_account', $data, $user_id );
2147 + }
1102 2148
1103 - $error_code = $errors->get_error_code();
1104 - if (!empty($error_code)) {
1105 - return $errors;
1106 - }
1107 -
1108 - if ($image_url) {
1109 - if ($type == 'avatar') {
1110 - $full_width = apply_filters('uwp_avatar_image_width', 150);
1111 - } else {
1112 - $full_width = apply_filters('uwp_banner_image_width', uwp_get_option('profile_banner_width', 1000));
1113 - }
2149 + /**
2150 + * Modifies the forms field in email based on the form type.
2151 + *
2152 + * @param string $form_fields Form fields.
2153 + * @param string $type Form type.
2154 + * @param int $user_id User ID.
2155 + *
2156 + * @return string Modified mail field.
2157 + * @package userswp
2158 + * @subpackage userswp/includes
2159 + *
2160 + */
2161 + public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2162 + switch ( $type ) {
2163 + case 'register':
2164 + $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2165 + $fields = get_register_form_fields( $form_id );
2166 + $user_data = get_userdata( $user_id );
2167 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2168 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2169 + $excluded = uwp_get_excluded_fields();
2170 + foreach ( $fields as $key => $field ) {
2171 + if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2172 + continue;
2173 + }
2174 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2175 + $field_value = $user_data->user_email;
2176 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2177 + $field_value = $user_data->user_login;
2178 + } elseif ( $field->htmlvar_name == 'bio' ) {
2179 + $field_value = get_user_meta( $user_id, 'description', true );
2180 + } else {
2181 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2182 + }
1114 2183
1115 - $image_url = esc_url($image_url);
1116 - add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
1117 - $uploads = wp_upload_dir();
1118 - remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
1119 - $upload_url = $uploads['baseurl'];
1120 - $upload_path = $uploads['basedir'];
1121 - $image_url = str_replace($upload_url, $upload_path, $image_url);
1122 - $ext = pathinfo($image_url, PATHINFO_EXTENSION); // to get extension
1123 - $name =pathinfo($image_url, PATHINFO_FILENAME); //file name without extension
1124 - $thumb_image_name = $name.'_uwp_'.$type.'_thumb'.'.'.$ext;
1125 - $thumb_image_location = str_replace($name.'.'.$ext, $thumb_image_name, $image_url);
1126 - //Get the new coordinates to crop the image.
1127 - $x = $data["x"];
1128 - $y = $data["y"];
1129 - $w = $data["w"];
1130 - $h = $data["h"];
1131 - //Scale the image based on cropped width setting
1132 - $scale = $full_width/$w;
1133 - //$scale = 1; // no scaling
1134 - $cropped = uwp_resizeThumbnailImage($thumb_image_location, $image_url,$x, $y, $w, $h,$scale);
1135 - $cropped = str_replace($upload_path, $upload_url, $cropped);
2184 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2185 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2186 + }
1136 2187
1137 - // Remove previous avatar/banner
1138 - $unlink_img = '';
1139 - if ($unlink_prev_img) {
1140 - if ($type == 'avatar') {
1141 - $previous_img = uwp_get_usermeta($user_id, 'uwp_account_avatar_thumb');
1142 - } else if ($type == 'banner') {
1143 - $previous_img = uwp_get_usermeta($user_id, 'uwp_account_banner_thumb');
1144 - } else {
1145 - $previous_img = '';
2188 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2189 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2190 + }
2191 + }
1146 2192 }
1147 -
1148 - if ($previous_img) {
1149 - $unlink_img = untrailingslashit($upload_path) . '/' . ltrim($previous_img, '/');
2193 + break;
2194 + case 'account':
2195 + $fields = get_account_form_fields();
2196 + $user_data = get_userdata( $user_id );
2197 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2198 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2199 + foreach ( $fields as $key => $field ) {
2200 + if ( $field->is_active != '1' ) {
2201 + continue;
2202 + }
2203 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2204 + $field_value = $user_data->user_email;
2205 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2206 + $field_value = $user_data->user_login;
2207 + } elseif ( $field->htmlvar_name == 'bio' ) {
2208 + $field_value = get_user_meta( $user_id, 'description', true );
2209 + } else {
2210 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2211 + }
2212 +
2213 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2214 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2215 + }
2216 +
2217 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2218 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2219 + }
2220 + }
1150 2221 }
2222 + break;
2223 + }
2224 +
2225 + return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2226 + }
2227 +
2228 + /**
2229 + *
2230 + *
2231 + * @return void
2232 + * @since 1.0.12 Unlink file.
2233 + * @package userswp
2234 + * @since 1.0.0
2235 + */
2236 + public function upload_file_remove() {
2237 + check_ajax_referer( 'uwp_basic_nonce', 'security' );
2238 +
2239 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2240 + $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2241 +
2242 + if ( empty( $user_id ) ) {
2243 + wp_die( -1 );
2244 + }
2245 +
2246 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2247 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2248 + }
2249 +
2250 + // Remove file
2251 + if ( $htmlvar == 'banner_thumb' ) {
2252 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2253 + $type = 'banner';
2254 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2255 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2256 + $type = 'avatar';
2257 + } else {
2258 + $file = '';
2259 + $type = '';
2260 + }
2261 +
2262 + uwp_update_usermeta( $user_id, $htmlvar, '' );
2263 +
2264 + if ( $file ) {
2265 + $uploads = wp_upload_dir();
2266 + $upload_path = $uploads['basedir'];
2267 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2268 +
2269 + if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2270 + @unlink( $unlink_file );
2271 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2272 +
2273 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2274 + @unlink( $unlink_ori_file );
2275 + }
1151 2276 }
2277 + }
1152 2278
1153 - // remove the uploads path for easy migrations
1154 - $cropped = str_replace($upload_url, '', $cropped);
1155 - if ($type == 'avatar') {
1156 - uwp_update_usermeta($user_id, 'uwp_account_avatar_thumb', $cropped);
1157 - } else {
1158 - uwp_update_usermeta($user_id, 'uwp_account_banner_thumb', $cropped);
1159 - }
1160 -
1161 - if ($unlink_img && $unlink_img != $thumb_image_location && is_file($unlink_img) && file_exists($unlink_img)) {
1162 - @unlink($unlink_img);
1163 - $unlink_ori_img = str_replace('_uwp_'.$type.'_thumb'.'.', '.', $unlink_img);
1164 - if (is_file($unlink_ori_img) && file_exists($unlink_ori_img)) {
1165 - @unlink($unlink_ori_img);
2279 + wp_send_json_success();
2280 +
2281 + wp_die();
2282 + }
2283 +
2284 + /**
2285 + * Form field template for datepicker field type.
2286 + *
2287 + * @param string $html Form field html
2288 + * @param object $field Field info.
2289 + * @param string $value Form field default value.
2290 + * @param string $form_type Form type
2291 + *
2292 + * @return string Modified form field html.
2293 + * @package userswp
2294 + *
2295 + * @since 1.0.0
2296 + */
2297 + public function form_input_datepicker( $html, $field, $value, $form_type ) {
2298 +
2299 + // Check if there is a field specific filter.
2300 + if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2301 + $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2302 + }
2303 +
2304 + // If no html then we run the standard output.
2305 + if ( empty( $html ) ) {
2306 +
2307 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2308 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2309 + $bs_sr_only = $design_style ? 'sr-only' : '';
2310 + $bs_form_control = $design_style ? 'form-control' : '';
2311 + $extra_attributes = array();
2312 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2313 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2314 +
2315 + ob_start(); // Start buffering;
2316 +
2317 + $extra_fields = unserialize( $field->extra_fields );
2318 +
2319 + if ( $extra_fields['date_format'] == '' ) {
2320 + $extra_fields['date_format'] = 'yy-mm-dd';
2321 + }
2322 +
2323 + $date_format = $extra_fields['date_format'];
2324 + $jquery_date_format = $date_format;
2325 +
2326 + // check if we need to change the format or not
2327 + $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2328 + if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2329 +
2330 + $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2331 + $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2332 +
2333 + $date_format = str_replace( $search, $replace, $date_format );
2334 + } else {
2335 + $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2336 + }
2337 +
2338 + if ( ! empty( $value ) && ! is_string( $value ) ) {
2339 + $value = date( 'Y-m-d', $value );
2340 + }
2341 +
2342 + if ( $value == '0000-00-00' ) {
2343 + $value = '';
2344 + }//if date not set, then mark it empty
2345 + $value = uwp_date( $value, 'Y-m-d', $date_format );
2346 + $site_title = uwp_get_form_label( $field );
2347 +
2348 + // bootstrap
2349 + if ( $design_style ) {
2350 + // flatpickr attributes
2351 + $extra_attributes['data-alt-input'] = 'true';
2352 + $extra_attributes['data-alt-format'] = $date_format;
2353 + $extra_attributes['data-date-format'] = 'Y-m-d';
2354 +
2355 + if ( 'dob' == $field->htmlvar_name ) {
2356 + $extra_attributes['data-max-date'] = 'today';
1166 2357 }
2358 +
2359 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2360 +
2361 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2362 + array(
2363 + 'id' => esc_attr( $field->htmlvar_name ),
2364 + 'name' => esc_attr( $field->htmlvar_name ),
2365 + 'required' => ! empty( $field->is_required ) ? true : false,
2366 + 'label' => wp_kses_post( $site_title . $required ),
2367 + 'label_show' => true,
2368 + 'label_type' => 'hidden',
2369 + 'type' => 'datepicker',
2370 + 'title' => esc_html( $site_title ),
2371 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2372 + 'class' => '',
2373 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2374 + 'value' => esc_attr( $value ),
2375 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2376 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2377 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2378 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2379 + )
2380 + );
2381 + } else {
2382 + ?>
2383 + <script type="text/javascript">
2384 +
2385 + jQuery(function () {
2386 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2387 + changeMonth: true, changeYear: true
2388 + <?php
2389 + if ( $field->htmlvar_name == 'dob' ) {
2390 + echo ", yearRange: '1900:+0'";
2391 + } else {
2392 + echo ", yearRange: '1900:2050'";
2393 + }
2394 + ?>
2395 + <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2396 +
2397 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2398 +
2399 + <?php if ( ! empty( $value ) ) { ?>
2400 + var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2401 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2402 + <?php } ?>
2403 +
2404 + });
2405 +
2406 + </script>
2407 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2408 + class="
2409 + <?php
2410 + if ( $field->is_required ) {
2411 + echo 'required_field';
2412 + }
2413 + ?>
2414 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2415 +
2416 + <?php
2417 +
2418 + if ( ! is_admin() ) {
2419 + ?>
2420 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2421 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2422 + <?php
2423 + if ( $field->is_required ) {
2424 + echo '<span>*</span>';
2425 + }
2426 + ?>
2427 + </label>
2428 + <?php } ?>
2429 +
2430 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2431 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2432 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2433 + title="<?php echo esc_attr( $site_title ); ?>"
2434 + type="text"
2435 + <?php
2436 + if ( $field->is_required == 1 ) {
2437 + echo 'required="required"';
2438 + }
2439 + ?>
2440 + value="<?php echo esc_attr( $value ); ?>"
2441 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2442 +
2443 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2444 + <?php if ( $field->is_required ) { ?>
2445 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2446 + <?php } ?>
2447 + </div>
2448 +
2449 + <?php
1167 2450 }
1168 - }
1169 2451
1170 - if (is_admin()) {
1171 - if ($user_id == get_current_user_id()) {
1172 - $profile_url = admin_url( 'profile.php' );
1173 - } else {
1174 - $profile_url = admin_url( 'user-edit.php?user_id='.$user_id );
1175 - }
1176 - } else {
1177 - $profile_url = uwp_build_profile_tab_url($user_id);
1178 - }
1179 - return $profile_url;
2452 + $html = ob_get_clean();
2453 + }
1180 2454
1181 - }
2455 + return $html;
2456 + }
1182 2457
1183 - /**
1184 - * Saves UsersWP related user custom fields.
1185 - *
1186 - * @since 1.0.0
1187 - * @package userswp
1188 - *
1189 - * @param int $user_id User ID.
1190 - * @param array $data Result array.
1191 - * @param string $type Form type.
1192 - *
1193 - * @return bool True when success. False when failure.
1194 - */
1195 - public function uwp_save_user_extra_fields($user_id, $data, $type) {
2458 + /**
2459 + * Form field template for time field type.
2460 + *
2461 + * @param string $html Form field html
2462 + * @param object $field Field info.
2463 + * @param string $value Form field default value.
2464 + * @param string $form_type Form type
2465 + *
2466 + * @return string Modified form field html.
2467 + * @package userswp
2468 + *
2469 + * @since 1.0.0
2470 + */
2471 + public function form_input_time( $html, $field, $value, $form_type ) {
1196 2472
1197 - if (empty($user_id) || empty($data) || empty($type)) {
1198 - return false;
1199 - }
2473 + if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
1200 2474
1201 - // custom user fields not applicable for login and forgot
1202 - if ($type == 'login' || $type == 'forgot') {
1203 - return true;
1204 - }
1205 -
2475 + $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2476 + }
1206 2477
1207 - if ($type == 'account' || $type == 'register') {
1208 - if (isset($data['password'])) {
1209 - unset($data['password']);
1210 - }
1211 - }
2478 + // If no html then we run the standard output.
2479 + if ( empty( $html ) ) {
1212 2480
1213 - if ($type == 'register') {
1214 - if (isset($data['uwp_account_username'])) {
1215 - unset($data['uwp_account_username']);
1216 - }
1217 - if (isset($data['uwp_account_email'])) {
1218 - unset($data['uwp_account_email']);
1219 - }
1220 - if (isset($data['uwp_account_display_name'])) {
1221 - unset($data['uwp_account_display_name']);
1222 - }
1223 - if (isset($data['uwp_account_first_name'])) {
1224 - unset($data['uwp_account_first_name']);
1225 - }
1226 - if (isset($data['uwp_account_last_name'])) {
1227 - unset($data['uwp_account_last_name']);
1228 - }
1229 - if (isset($data['uwp_account_bio'])) {
1230 - unset($data['uwp_account_bio']);
1231 - }
1232 - }
2481 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2482 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2483 + $bs_sr_only = $design_style ? 'sr-only' : '';
2484 + $bs_form_control = $design_style ? 'form-control bg-white' : '';
2485 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2486 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1233 2487
1234 - if (empty($data)) {
1235 - // no extra fields. so just return
1236 - return true;
1237 - } else {
1238 - foreach($data as $key => $value) {
1239 - uwp_update_usermeta($user_id, $key, $value);
1240 - }
1241 - return true;
1242 - }
1243 - }
2488 + ob_start(); // Start buffering;
1244 2489
1245 - /**
1246 - * Logs the error message.
1247 - *
1248 - * @since 1.0.0
1249 - * @package userswp
1250 - *
1251 - * @param array|object|string $log Error message.
1252 - *
1253 - * @return void
1254 - */
1255 - public static function uwp_error_log($log){
2490 + if ( $value != '' ) {
2491 + $value = date( 'H:i', strtotime( $value ) );
2492 + }
1256 2493
1257 - $should_log = apply_filters( 'uwp_log_errors', WP_DEBUG);
1258 - if ( true === $should_log ) {
1259 - if ( is_array( $log ) || is_object( $log ) ) {
1260 - error_log( print_r( $log, true ) );
1261 - } else {
1262 - error_log( $log );
1263 - }
1264 - }
1265 - }
2494 + // flatpickr attributes
2495 + $extra_attributes['data-enable-time'] = 'true';
2496 + $extra_attributes['data-no-calendar'] = 'true';
2497 + $extra_attributes['data-date-format'] = 'H:i';
2498 + $site_title = uwp_get_form_label( $field );
2499 + $label_type = is_admin() ? '' : 'top';
1266 2500
1267 - /**
1268 - *
1269 - *
1270 - * @since 1.0.0
1271 - * @since 1.0.12 Unlink file.
1272 - * @package userswp
1273 - * @return void
1274 - */
1275 - public function uwp_upload_file_remove() {
2501 + if ( $design_style ) {
2502 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1276 2503
1277 - $htmlvar = strip_tags(esc_sql($_POST['htmlvar']));
1278 - $user_id = (int) strip_tags(esc_sql($_POST['uid']));
1279 - $permission = false;
1280 - if ($user_id == get_current_user_id()) {
1281 - $permission = true;
1282 - } else {
1283 - if (current_user_can('manage_options')) {
1284 - $permission = true;
1285 - }
1286 - }
1287 - if ($permission) {
1288 - // Remove file
1289 - if ($htmlvar == "uwp_account_banner_thumb") {
1290 - $file = uwp_get_usermeta($user_id, 'uwp_account_banner_thumb');
1291 - $type = 'banner';
1292 - } elseif ($htmlvar == "uwp_account_avatar_thumb") {
1293 - $file = uwp_get_usermeta($user_id, 'uwp_account_avatar_thumb');
1294 - $type = 'avatar';
2504 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2505 + array(
2506 + 'id' => esc_attr( $field->htmlvar_name ),
2507 + 'name' => esc_attr( $field->htmlvar_name ),
2508 + 'required' => ! empty( $field->is_required ) ? true : false,
2509 + 'label' => wp_kses_post( $site_title . $required ),
2510 + 'label_show' => true,
2511 + 'label_type' => esc_attr( $label_type ),
2512 + 'type' => 'timepicker',
2513 + 'title' => esc_html( $site_title ),
2514 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2515 + 'class' => '',
2516 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2517 + 'value' => esc_attr( $value ),
2518 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2519 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2520 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2521 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2522 + 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'uwp-search' ) . '" ></i></div>',
2523 + )
2524 + );
1295 2525 } else {
1296 - $file = '';
1297 - $type = '';
2526 + ?>
2527 + <script type="text/javascript">
2528 + jQuery(document).ready(function () {
2529 + jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2530 + showPeriod: true,
2531 + showLeadingZero: true
2532 + });
2533 + });
2534 + </script>
2535 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2536 + class="
2537 + <?php
2538 + if ( $field->is_required ) {
2539 + echo 'required_field';
2540 + }
2541 + ?>
2542 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2543 +
2544 + <?php
2545 + $site_title = uwp_get_form_label( $field );
2546 + if ( ! is_admin() ) {
2547 + ?>
2548 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2549 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2550 + <?php
2551 + if ( $field->is_required ) {
2552 + echo '<span>*</span>';
2553 + }
2554 + ?>
2555 + </label>
2556 + <?php } ?>
2557 +
2558 + <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2559 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2560 + value="<?php echo esc_attr( $value ); ?>"
2561 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2562 + type="text"
2563 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2564 +
2565 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2566 + <?php if ( $field->is_required ) { ?>
2567 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2568 + <?php } ?>
2569 + </div>
2570 + <?php
1298 2571 }
2572 + $html = ob_get_clean();
2573 + }
1299 2574
1300 - uwp_update_usermeta($user_id, $htmlvar, '');
2575 + return $html;
2576 + }
1301 2577
1302 - if ($file) {
1303 - $uploads = wp_upload_dir();
1304 - $upload_path = $uploads['basedir'];
1305 - $unlink_file = untrailingslashit($upload_path) . '/' . ltrim($file, '/');
2578 + /**
2579 + * Form field template for select field type.
2580 + *
2581 + * @param string $html Form field html
2582 + * @param object $field Field info.
2583 + * @param string $value Form field default value.
2584 + * @param string $form_type Form type
2585 + *
2586 + * @return string Modified form field html.
2587 + * @package userswp
2588 + *
2589 + * @since 1.0.0
2590 + */
2591 + public function form_input_select( $html, $field, $value, $form_type ) {
1306 2592
1307 - if (is_file($unlink_file) && file_exists($unlink_file)) {
1308 - @unlink($unlink_file);
1309 - $unlink_ori_file = str_replace('_uwp_'.$type.'_thumb'.'.', '.', $unlink_file);
1310 - if (is_file($unlink_ori_file) && file_exists($unlink_ori_file)) {
1311 - @unlink($unlink_ori_file);
2593 + // Check if there is a field specific filter.
2594 + if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2595 + $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2596 + }
2597 +
2598 + // Check if there is a field type specific filter.
2599 + if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2600 + $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2601 + }
2602 +
2603 + // If no html then we run the standard output.
2604 + if ( empty( $html ) ) {
2605 +
2606 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2607 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2608 + $bs_sr_only = $design_style ? 'sr-only' : '';
2609 + $bs_form_control = $design_style ? 'form-control' : '';
2610 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2611 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2612 +
2613 + ob_start(); // Start buffering;
2614 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2615 + $site_title = uwp_get_form_label( $field );
2616 +
2617 + // bootstrap
2618 + if ( $design_style ) {
2619 +
2620 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2621 +
2622 + echo aui()->select(
2623 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2624 + 'id' => esc_attr( $field->htmlvar_name ),
2625 + 'name' => esc_attr( $field->htmlvar_name ),
2626 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2627 + 'title' => esc_html( $site_title ),
2628 + 'value' => esc_attr( $value ),
2629 + 'required' => (bool) $field->is_required,
2630 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2631 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2632 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2633 + 'label' => wp_kses_post( $site_title . $required ),
2634 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2635 + 'select2' => true,
2636 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2637 + )
2638 + );
2639 + } else {
2640 + ?>
2641 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2642 + class="
2643 + <?php
2644 + if ( $field->is_required ) {
2645 + echo 'required_field';
1312 2646 }
1313 - }
2647 + ?>
2648 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2649 +
2650 + <?php
2651 + if ( ! is_admin() ) {
2652 + ?>
2653 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2654 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2655 + <?php
2656 + if ( $field->is_required ) {
2657 + echo '<span>*</span>';
2658 + }
2659 + ?>
2660 + </label>
2661 + <?php } ?>
2662 +
2663 + <?php
2664 +
2665 + $select_options = '';
2666 + if ( ! empty( $option_values_arr ) ) {
2667 + foreach ( $option_values_arr as $option_row ) {
2668 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2669 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2670 +
2671 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2672 + } else {
2673 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2674 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2675 + $selected = $option_value == $value ? 'selected="selected"' : '';
2676 +
2677 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2678 + }
2679 + }
2680 + }
2681 + ?>
2682 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2683 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2684 + title="<?php echo esc_attr( $site_title ); ?>"
2685 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2686 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2687 + </select>
2688 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2689 + <?php if ( $field->is_required ) { ?>
2690 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2691 + <?php } ?>
2692 + </div>
2693 +
2694 + <?php
1314 2695 }
1315 - }
1316 - die();
1317 - }
1318 -
1319 -
1320 - /**
1321 - * Form field template for datepicker field type.
1322 - *
1323 - * @since 1.0.0
1324 - * @package userswp
1325 - *
1326 - * @param string $html Form field html
1327 - * @param object $field Field info.
1328 - * @param string $value Form field default value.
1329 - * @param string $form_type Form type
1330 - *
1331 - * @return string Modified form field html.
1332 - */
1333 - public function uwp_form_input_datepicker($html, $field, $value, $form_type){
2696 + $html = ob_get_clean();
2697 + }
1334 2698
1335 - // Check if there is a field specific filter.
1336 - if(has_filter("uwp_form_input_html_datepicker_{$field->htmlvar_name}")){
1337 - $html = apply_filters("uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1338 - }
2699 + return $html;
2700 + }
1339 2701
1340 - // If no html then we run the standard output.
1341 - if(empty($html)) {
2702 + /**
2703 + * Form field template for multiselect field type.
2704 + *
2705 + * @param string $html Form field html
2706 + * @param object $field Field info.
2707 + * @param string $value Form field default value.
2708 + * @param string $form_type Form type
2709 + *
2710 + * @return string Modified form field html.
2711 + * @package userswp
2712 + *
2713 + * @since 1.0.0
2714 + */
2715 + public function form_input_multiselect( $html, $field, $value, $form_type ) {
1342 2716
1343 - ob_start(); // Start buffering;
2717 + // Check if there is a field specific filter.
2718 + if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
2719 + $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2720 + }
1344 2721
1345 - $extra_fields = unserialize($field->extra_fields);
2722 + if ( empty( $html ) ) {
1346 2723
1347 - if ($extra_fields['date_format'] == '')
1348 - $extra_fields['date_format'] = 'yy-mm-dd';
2724 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2725 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2726 + $bs_sr_only = $design_style ? 'sr-only' : '';
2727 + $bs_form_control = $design_style ? 'form-control' : '';
2728 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2729 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1349 2730
1350 - $date_format = $extra_fields['date_format'];
1351 - $jquery_date_format = $date_format;
2731 + ob_start(); // Start buffering;
1352 2732
1353 - if (!empty($value) && !is_string($value)) {
1354 - $value = date('Y-m-d', $value);
1355 - }
2733 + $multi_display = 'select';
2734 + if ( ! empty( $field->extra_fields ) ) {
2735 + $multi_display = unserialize( $field->extra_fields );
2736 + }
1356 2737
2738 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2739 + $site_title = uwp_get_form_label( $field );
2740 + $value = is_array( $value ) ? $value : esc_attr( $value );
1357 2741
1358 - // check if we need to change the format or not
1359 - $date_format_len = strlen(str_replace(' ', '', $date_format));
1360 - if($date_format_len>5){// if greater then 5 then it's the old style format.
2742 + // bootstrap
2743 + if ( $design_style ) {
1361 2744
1362 - $search = array('dd','d','DD','mm','m','MM','yy'); //jQuery UI datepicker format
1363 - $replace = array('d','j','l','m','n','F','Y');//PHP date format
2745 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1364 2746
1365 - $date_format = str_replace($search, $replace, $date_format);
1366 - }else{
1367 - $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
1368 - }
1369 - if($value=='0000-00-00'){$value='';}//if date not set, then mark it empty
1370 - $value = uwp_date($value, 'Y-m-d', $date_format);
1371 - ?>
1372 - <script type="text/javascript">
2747 + echo aui()->select(
2748 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2749 + 'id' => esc_attr( $field->htmlvar_name ),
2750 + 'name' => esc_attr( $field->htmlvar_name ),
2751 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2752 + 'title' => esc_html( $site_title ),
2753 + 'value' => $value,
2754 + 'required' => (bool) $field->is_required,
2755 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2756 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2757 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2758 + 'label' => wp_kses_post( $site_title . $required ),
2759 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2760 + 'select2' => true,
2761 + 'multiple' => true,
2762 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2763 + )
2764 + );
2765 + } else {
2766 + ?>
2767 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2768 + class="
2769 + <?php
2770 + if ( $field->is_required ) {
2771 + echo 'required_field';
2772 + }
2773 + ?>
2774 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1373 2775
1374 - jQuery(function () {
2776 + <?php
2777 + if ( ! is_admin() ) {
2778 + ?>
2779 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2780 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2781 + <?php
2782 + if ( $field->is_required ) {
2783 + echo '<span>*</span>';
2784 + }
2785 + ?>
2786 + </label>
2787 + <?php } ?>
1375 2788
1376 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker({changeMonth: true, changeYear: true
1377 - <?php if($field->htmlvar_name == 'uwp_account_dob'){ echo ", yearRange: '1900:+0'"; } else { echo ", yearRange: '1900:2050'"; }?>
1378 - <?php echo apply_filters("uwp_datepicker_extra_{$field->htmlvar_name}",'');?>});
2789 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
2790 + <?php if ( $multi_display == 'select' ) { ?>
2791 + <div class="uwp_multiselect_list">
2792 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
2793 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2794 + title="<?php echo esc_attr( $site_title ); ?>"
2795 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2796 + class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2797 + >
2798 + <?php
2799 + } else {
2800 + ?>
2801 + <ul class="uwp_multi_choice">
2802 + <?php
2803 + }
1379 2804
1380 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("option", "dateFormat", '<?php echo $jquery_date_format;?>');
2805 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2806 + $select_options = '';
2807 + if ( ! empty( $option_values_arr ) ) {
2808 + foreach ( $option_values_arr as $option_row ) {
2809 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2810 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
1381 2811
1382 - <?php if(!empty($value)){?>
1383 - var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo $value;?>');
1384 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("setDate", parsedDate);
1385 - <?php } ?>
2812 + if ( $multi_display == 'select' ) {
2813 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2814 + } else {
2815 + $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
2816 + }
2817 + } else {
2818 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2819 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2820 + $selected = $option_value == $value ? 'selected="selected"' : '';
2821 + $checked = '';
1386 2822
1387 - });
2823 + if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
2824 + if ( ! is_array( $value ) ) {
2825 + $value_array = explode( ',', $value );
2826 + } else {
2827 + $value_array = $value;
2828 + }
1388 2829
1389 - </script>
1390 - <div id="<?php echo $field->htmlvar_name;?>_row"
1391 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp_clear uwp-fieldset-details">
2830 + if ( is_array( $value_array ) ) {
2831 + if ( in_array( $option_value, $value_array ) ) {
2832 + $selected = 'selected="selected"';
2833 + $checked = 'checked="checked"';
2834 + }
2835 + }
2836 + }
1392 2837
2838 + if ( $multi_display == 'select' ) {
2839 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2840 + } else {
2841 + $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
2842 + }
2843 + }
2844 + }
2845 + }
2846 + echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2847 +
2848 + if ( $multi_display == 'select' ) {
2849 +
2850 + ?>
2851 + </select></div>
2852 + <?php } else { ?>
2853 + </ul>
2854 + <?php } ?>
2855 + <?php if ( $field->is_required ) { ?>
2856 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2857 + <?php } ?>
2858 + </div>
2859 + <?php
2860 + }
2861 + $html = ob_get_clean();
2862 + }
2863 +
2864 + return $html;
2865 + }
2866 +
2867 + /**
2868 + * Form field template for file field type.
2869 + *
2870 + * @param string $html Form field html
2871 + * @param object $field Field info.
2872 + * @param string $value Form field default value.
2873 + * @param string $form_type Form type
2874 + *
2875 + * @return string Modified form field html.
2876 + * @package userswp
2877 + *
2878 + * @since 1.0.0
2879 + */
2880 + public function form_input_file( $html, $field, $value, $form_type ) {
2881 +
2882 + $file_obj = new UsersWP_Files();
2883 +
2884 + // Check if there is a field specific filter.
2885 + if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
2886 + $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2887 + }
2888 +
2889 + // If no html then we run the standard output.
2890 + if ( empty( $html ) ) {
2891 +
2892 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2893 + $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
2894 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2895 + $bs_sr_only = $design_style ? 'sr-only' : '';
2896 + $bs_form_control = $design_style ? 'form-control' : '';
2897 +
2898 + ob_start(); // Start buffering;
2899 +
2900 + ?>
2901 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2902 + class="
1393 2903 <?php
1394 - $site_title = uwp_get_form_label($field);
1395 - if (!is_admin()) { ?>
1396 - <label>
1397 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1398 - <?php if ($field->is_required) echo '<span>*</span>';?>
1399 - </label>
1400 - <?php } ?>
2904 + if ( $field->is_required ) {
2905 + echo 'required_field';
2906 + }
2907 + ?>
2908 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
1401 2909
1402 - <input name="<?php echo $field->htmlvar_name;?>"
1403 - id="<?php echo $field->htmlvar_name;?>"
1404 - placeholder="<?php echo $site_title; ?>"
1405 - title="<?php echo $site_title; ?>"
1406 - type="text"
1407 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1408 - value="<?php echo esc_attr($value);?>" class="uwp_textfield"/>
2910 + <?php
2911 + $site_title = uwp_get_form_label( $field );
2912 + if ( ! is_admin() && ! wp_doing_ajax() ) {
2913 + ?>
2914 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2915 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2916 + <?php
2917 + if ( $field->is_required ) {
2918 + echo ' <span class="text-danger">*</span>';
2919 + }
2920 + ?>
2921 + </label>
2922 + <?php } ?>
1409 2923
1410 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1411 - <?php if ($field->is_required) { ?>
1412 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1413 - <?php } ?>
1414 - </div>
2924 + <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2925 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2926 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
2927 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2928 + title="<?php echo esc_attr( $site_title ); ?>"
2929 + <?php
2930 + if ( $field->is_required == 1 ) {
2931 + echo 'data-is-required="1"';
2932 + }
2933 + if ( $field->is_required == 1 && ! $value ) {
2934 + echo 'required="required"';
2935 + }
2936 + ?>
2937 + type="<?php echo esc_attr( $field->field_type ); ?>">
2938 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2939 + <?php if ( $field->is_required ) { ?>
2940 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2941 + <?php } ?>
2942 + </div>
1415 2943
1416 - <?php
1417 - $html = ob_get_clean();
1418 - }
2944 + <?php
2945 + $html = ob_get_clean();
2946 + }
1419 2947
1420 - return $html;
1421 - }
2948 + return $html;
2949 + }
1422 2950
1423 - /**
1424 - * Form field template for time field type.
1425 - *
1426 - * @since 1.0.0
1427 - * @package userswp
1428 - *
1429 - * @param string $html Form field html
1430 - * @param object $field Field info.
1431 - * @param string $value Form field default value.
1432 - * @param string $form_type Form type
1433 - *
1434 - * @return string Modified form field html.
1435 - */
1436 - public function uwp_form_input_time($html, $field, $value, $form_type){
2951 + /**
2952 + * Form field template for checkbox field type.
2953 + *
2954 + * @param string $html Form field html
2955 + * @param object $field Field info.
2956 + * @param string $value Form field default value.
2957 + * @param string $form_type Form type
2958 + *
2959 + * @return string Modified form field html.
2960 + * @package userswp
2961 + *
2962 + * @since 1.0.0
2963 + */
2964 + public function form_input_checkbox( $html, $field, $value, $form_type ) {
1437 2965
1438 - if(has_filter("uwp_form_input_html_time_{$field->htmlvar_name}")){
2966 + // Check if there is a field specific filter.
2967 + if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
2968 + $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2969 + }
1439 2970
1440 - $html = apply_filters("uwp_form_input_html_time_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1441 - }
2971 + // If no html then we run the standard output.
2972 + if ( empty( $html ) ) {
1442 2973
1443 - // If no html then we run the standard output.
1444 - if(empty($html)) {
2974 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2975 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
2976 + $bs_sr_only = $design_style ? 'form-check-label' : '';
2977 + $bs_form_control = $design_style ? 'form-check-input' : '';
1445 2978
1446 - ob_start(); // Start buffering;
2979 + ob_start(); // Start buffering;
2980 + $site_title = uwp_get_form_label( $field );
1447 2981
1448 - if ($value != '')
1449 - $value = date('H:i', strtotime($value));
1450 - ?>
1451 - <script type="text/javascript">
1452 - jQuery(document).ready(function () {
2982 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2983 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
1453 2984
1454 - jQuery('#<?php echo $field->htmlvar_name;?>').timepicker({
1455 - showPeriod: true,
1456 - showLeadingZero: true
1457 - });
1458 - });
1459 - </script>
1460 - <div id="<?php echo $field->htmlvar_name;?>_row"
1461 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp_clear uwp-fieldset-details">
2985 + $checked = $value == '1' ? true : false;
1462 2986
1463 - <?php
1464 - $site_title = uwp_get_form_label($field);
1465 - if (!is_admin()) { ?>
1466 - <label>
1467 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1468 - <?php if ($field->is_required) echo '<span>*</span>';?>
1469 - </label>
1470 - <?php } ?>
2987 + // bootstrap
2988 + if ( $design_style ) {
2989 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1471 2990
1472 - <input readonly="readonly" name="<?php echo $field->htmlvar_name;?>"
1473 - id="<?php echo $field->htmlvar_name;?>"
1474 - value="<?php echo esc_attr($value);?>"
1475 - placeholder="<?php echo $site_title; ?>"
1476 - type="text"
1477 - class="uwp_textfield"/>
2991 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
1478 2992
1479 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1480 - <?php if ($field->is_required) { ?>
1481 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1482 - <?php } ?>
1483 - </div>
1484 - <?php
1485 - $html = ob_get_clean();
1486 - }
2993 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2994 + array(
2995 + 'id' => esc_attr( $id ),
2996 + 'name' => esc_attr( $field->htmlvar_name ),
2997 + 'type' => 'checkbox',
2998 + 'value' => '1',
2999 + 'title' => esc_html( $site_title ),
3000 + 'label' => wp_kses_post( $site_title . $required ),
3001 + 'label_show' => true,
3002 + 'required' => ! empty( $field->is_required ) ? true : false,
3003 + 'checked' => (bool) $checked,
3004 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3005 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3006 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3007 + )
3008 + );
1487 3009
1488 - return $html;
1489 - }
3010 + } else {
3011 + ?>
3012 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3013 + class="
3014 + <?php
3015 + if ( $field->is_required ) {
3016 + echo 'required_field';
3017 + }
3018 + ?>
3019 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3020 + <?php if ( ! empty( $design_style ) ) { ?>
3021 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3022 + <?php } ?>
3023 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3024 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3025 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3026 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3027 + title="<?php echo esc_attr( $site_title ); ?>"
3028 + <?php
3029 + if ( $field->is_required == 1 ) {
3030 + echo 'required="required"';
3031 + }
3032 + ?>
3033 + <?php
3034 + if ( $value == '1' ) {
3035 + echo 'checked="checked"';
3036 + }
3037 + ?>
3038 + type="<?php echo esc_attr( $field->field_type ); ?>"
3039 + value="1">
3040 + <?php
3041 + echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3042 + ?>
3043 + <?php if ( ! empty( $design_style ) ) { ?>
3044 + </label>
3045 + <?php } ?>
3046 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3047 + <?php if ( $field->is_required ) { ?>
3048 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3049 + <?php } ?>
3050 + </div>
1490 3051
1491 - /**
1492 - * Form field template for select field type.
1493 - *
1494 - * @since 1.0.0
1495 - * @package userswp
1496 - *
1497 - * @param string $html Form field html
1498 - * @param object $field Field info.
1499 - * @param string $value Form field default value.
1500 - * @param string $form_type Form type
1501 - *
1502 - * @return string Modified form field html.
1503 - */
1504 - public function uwp_form_input_select($html, $field, $value, $form_type){
3052 + <?php
1505 3053
1506 - // Check if there is a field specific filter.
1507 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
1508 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1509 - }
3054 + }
1510 3055
1511 - // Check if there is a field type specific filter.
1512 - if(has_filter("uwp_form_input_html_select_{$field->field_type_key}")){
1513 - $html = apply_filters("uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type);
1514 - }
3056 + $html = ob_get_clean();
1515 3057
1516 - // If no html then we run the standard output.
1517 - if(empty($html)) {
3058 + }
1518 3059
1519 - ob_start(); // Start buffering;
3060 + return $html;
3061 + }
1520 3062
1521 - ?>
1522 - <div id="<?php echo $field->htmlvar_name;?>_row"
1523 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
3063 + /**
3064 + * Form field template for radio field type.
3065 + *
3066 + * @param string $html Form field html
3067 + * @param object $field Field info.
3068 + * @param string $value Form field default value.
3069 + * @param string $form_type Form type
3070 + *
3071 + * @return string Modified form field html.
3072 + * @package userswp
3073 + *
3074 + * @since 1.0.0
3075 + */
3076 + public function form_input_radio( $html, $field, $value, $form_type ) {
1524 3077
1525 - <?php
1526 - $site_title = uwp_get_form_label($field);
1527 - if (!is_admin()) { ?>
1528 - <label>
1529 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1530 - <?php if ($field->is_required) echo '<span>*</span>';?>
1531 - </label>
1532 - <?php } ?>
3078 + // Check if there is a field specific filter.
3079 + if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3080 + $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3081 + }
1533 3082
1534 - <?php
1535 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1536 - $select_options = '';
1537 - if (!empty($option_values_arr)) {
1538 - foreach ($option_values_arr as $option_row) {
1539 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1540 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
3083 + // If no html then we run the standard output.
3084 + if ( empty( $html ) ) {
1541 3085
1542 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1543 - } else {
1544 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1545 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1546 - $selected = $option_value == $value ? 'selected="selected"' : '';
3086 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3087 + $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3088 + $bs_sr_only = $design_style ? 'sr-only' : '';
3089 + $bs_label_class = $design_style ? 'form-check-label' : '';
3090 + $bs_form_control = $design_style ? 'form-check-input' : '';
1547 3091
1548 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1549 - }
3092 + ob_start(); // Start buffering;
3093 +
3094 + if ( $design_style ) {
3095 +
3096 + $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3097 + $option_values = array();
3098 + if ( ! empty( $option_values_deep ) ) {
3099 + foreach ( $option_values_deep as $option ) {
3100 + $option_values[ $option['value'] ] = $option['label'];
3101 + }
3102 + }
3103 +
3104 + $site_title = uwp_get_form_label( $field );
3105 +
3106 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3107 +
3108 + echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3109 + array(
3110 + 'id' => esc_attr( $field->htmlvar_name ),
3111 + 'name' => esc_attr( $field->htmlvar_name ),
3112 + 'type' => 'radio',
3113 + 'title' => esc_html( $site_title ),
3114 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3115 + 'label_type' => 'top',
3116 + 'class' => '',
3117 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3118 + 'value' => esc_attr( $value ),
3119 + 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3120 + )
3121 + );
3122 +
3123 + } else {
3124 +
3125 + ?>
3126 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3127 + class="
3128 + <?php
3129 + if ( $field->is_required ) {
3130 + echo 'required_field';
3131 + }
3132 + ?>
3133 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3134 +
3135 + <?php
3136 + $site_title = uwp_get_form_label( $field );
3137 + if ( ! is_admin() ) {
3138 + ?>
3139 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3140 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3141 + <?php
3142 + if ( $field->is_required ) {
3143 + echo '<span>*</span>';
3144 + }
3145 + ?>
3146 + </label>
3147 + <?php } ?>
3148 +
3149 + <?php
3150 + if ( $field->option_values ) {
3151 + $option_values = uwp_string_values_to_options( $field->option_values, true );
3152 +
3153 + if ( ! empty( $option_values ) ) {
3154 + $count = 0;
3155 + foreach ( $option_values as $option_value ) {
3156 + if ( empty( $option_value['optgroup'] ) ) {
3157 + ++$count;
3158 + if ( $count == 1 ) {
3159 + $class = 'uwp-radio-first';
3160 + } else {
3161 + $class = '';
3162 + }
3163 + ?>
3164 + <?php if ( ! empty( $design_style ) ) { ?>
3165 + <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3166 + <?php } else { ?>
3167 + <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3168 + <?php } ?>
3169 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3170 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3171 + title="<?php echo esc_attr( $option_value['label'] ); ?>"
3172 + <?php checked( $value, $option_value['value'] ); ?>
3173 + <?php
3174 + if ( $field->is_required == 1 ) {
3175 + echo 'required="required"';
3176 + }
3177 + ?>
3178 + value="<?php echo esc_attr( $option_value['value'] ); ?>"
3179 + class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3180 + <?php echo esc_html( $option_value['label'] ); ?>
3181 + <?php if ( ! empty( $design_style ) ) { ?>
3182 + </label>
3183 + <?php } else { ?>
3184 + </span>
3185 + <?php
3186 + }
3187 + }
3188 + }
3189 + }
3190 + }
3191 + ?>
3192 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3193 + <?php if ( $field->is_required ) { ?>
3194 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3195 + <?php } ?>
3196 + </div>
3197 + <?php
3198 + }
3199 +
3200 + $html = ob_get_clean();
3201 + }
3202 +
3203 + return $html;
3204 + }
3205 +
3206 + /**
3207 + * Form field template for text field type.
3208 + *
3209 + * @param string $html Form field html
3210 + * @param object $field Field info.
3211 + * @param string $value Form field default value.
3212 + * @param string $form_type Form type
3213 + *
3214 + * @return string Modified form field html.
3215 + * @package userswp
3216 + *
3217 + * @since 1.0.0
3218 + */
3219 + public function form_input_text( $html, $field, $value, $form_type ) {
3220 +
3221 + // Check if there is a custom field specific filter.
3222 + if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3223 + $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3224 + }
3225 +
3226 + // If no html then we run the standard output.
3227 + if ( empty( $html ) ) {
3228 +
3229 + ob_start(); // Start buffering;
3230 +
3231 + $type = 'text';
3232 + $step = false;
3233 + //number and float validation $validation_pattern
3234 + if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3235 + $type = 'number';
3236 + } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3237 + $dp = $field->decimal_point;
3238 + switch ( $dp ) {
3239 + case '1':
3240 + $step = '0.1';
3241 + break;
3242 + case '2':
3243 + $step = '0.01';
3244 + break;
3245 + case '3':
3246 + $step = '0.001';
3247 + break;
3248 + case '4':
3249 + $step = '0.0001';
3250 + break;
3251 + case '5':
3252 + $step = '0.00001';
3253 + break;
3254 + case '6':
3255 + $step = '0.000001';
3256 + break;
3257 + case '7':
3258 + $step = '0.0000001';
3259 + break;
3260 + case '8':
3261 + $step = '0.00000001';
3262 + break;
3263 + case '9':
3264 + $step = '0.000000001';
3265 + break;
3266 + case '10':
3267 + $step = '0.0000000001';
3268 + break;
3269 + default:
3270 + $step = '0.01';
3271 + break;
3272 + }
3273 + $type = 'number';
3274 + }
3275 +
3276 + $site_title = uwp_get_form_label( $field );
3277 + $placeholder = uwp_get_field_placeholder( $field );
3278 + $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3279 + if ( $manual_label
3280 + && isset( $field->form_type )
3281 + && $field->form_type == 'login'
3282 + && $field->htmlvar_name == 'username' ) {
3283 + $site_title = __( 'Username or Email', 'userswp' );
3284 + $required = ! empty( $field->is_required ) ? ' *' : '';
3285 + $placeholder = $site_title . $required;
3286 + $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3287 + }
3288 +
3289 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3290 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3291 + $bs_sr_only = $design_style ? 'sr-only' : '';
3292 + $bs_form_control = $design_style ? 'form-control' : '';
3293 +
3294 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3295 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3296 +
3297 + // bootstrap
3298 + if ( $design_style ) {
3299 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3300 +
3301 + echo aui()->input(
3302 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3303 + 'type' => esc_attr( $type ),
3304 + 'id' => esc_attr( $field->htmlvar_name ),
3305 + 'name' => esc_attr( $field->htmlvar_name ),
3306 + 'placeholder' => esc_attr( $placeholder ),
3307 + 'title' => esc_html( $site_title ),
3308 + 'value' => esc_attr( wp_unslash( $value ) ),
3309 + 'required' => (bool) $field->is_required,
3310 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3311 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3312 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3313 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3314 + 'step' => esc_attr( $step ),
3315 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3316 + )
3317 + );
3318 + } else {
3319 + ?>
3320 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3321 + <?php
3322 + if ( $field->is_required ) {
3323 + echo 'required_field';
3324 + }
3325 + ?>
3326 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3327 + <?php
3328 +
3329 + if ( ! is_admin() ) {
3330 + ?>
3331 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3332 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3333 + <?php
3334 + if ( $field->is_required ) {
3335 + echo '<span>*</span>';
3336 + }
3337 + ?>
3338 + </label>
3339 + <?php
1550 3340 }
1551 - }
1552 - ?>
1553 - <select name="<?php echo $field->htmlvar_name;?>" id="<?php echo $field->htmlvar_name;?>"
1554 - class="uwp_textfield"
1555 - title="<?php echo $site_title; ?>"
1556 - data-placeholder="<?php echo __('Choose', 'userswp') . ' ' . $site_title . '&hellip;';?>"
1557 - ><?php echo $select_options;?>
1558 - </select>
1559 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1560 - <?php if ($field->is_required) { ?>
1561 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1562 - <?php } ?>
1563 - </div>
3341 + ?>
1564 3342
1565 - <?php
1566 - $html = ob_get_clean();
1567 - }
3343 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3344 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3345 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3346 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3347 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3348 + title="<?php echo esc_attr( $site_title ); ?>"
3349 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3350 + oninput="setCustomValidity('')"
3351 + <?php
3352 + if ( $field->is_required == 1 ) {
3353 + echo 'required="required"';
3354 + }
3355 + ?>
3356 + <?php
3357 + if ( $field->for_admin_use == 1 ) {
3358 + echo 'readonly="readonly"';
3359 + }
3360 + ?>
3361 + type="<?php echo esc_attr( $type ); ?>"
3362 + <?php
3363 + if ( $step ) {
3364 + echo 'step="' . esc_attr( $step ) . '"';
3365 + }
3366 + ?>
3367 + />
3368 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3369 + <?php if ( $field->is_required ) { ?>
3370 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3371 + <?php } ?>
3372 + </div>
1568 3373
1569 - return $html;
1570 - }
1571 3374
1572 - /**
1573 - * Form field template for multiselect field type.
1574 - *
1575 - * @since 1.0.0
1576 - * @package userswp
1577 - *
1578 - * @param string $html Form field html
1579 - * @param object $field Field info.
1580 - * @param string $value Form field default value.
1581 - * @param string $form_type Form type
1582 - *
1583 - * @return string Modified form field html.
1584 - */
1585 - public function uwp_form_input_multiselect($html, $field, $value, $form_type){
3375 + <?php
3376 + }
3377 + $html = ob_get_clean();
3378 + }
1586 3379
1587 - // Check if there is a field specific filter.
1588 - if(has_filter("uwp_form_input_html_multiselect_{$field->htmlvar_name}")){
1589 - $html = apply_filters("uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1590 - }
3380 + return $html;
3381 + }
1591 3382
3383 + /**
3384 + * Form field template for textarea field type.
3385 + *
3386 + * @param string $html Form field html
3387 + * @param object $field Field info.
3388 + * @param string $value Form field default value.
3389 + * @param string $form_type Form type
3390 + *
3391 + * @return string Modified form field html.
3392 + * @package userswp
3393 + *
3394 + * @since 1.0.0
3395 + */
3396 + public function form_input_textarea( $html, $field, $value, $form_type ) {
1592 3397
1593 - if(empty($html)) {
3398 + // Check if there is a field specific filter.
3399 + if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3400 + $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3401 + }
1594 3402
1595 - ob_start(); // Start buffering;
3403 + // If no html then we run the standard output.
3404 + if ( empty( $html ) ) {
1596 3405
1597 - $multi_display = 'select';
1598 - if (!empty($field->extra_fields)) {
1599 - $multi_display = unserialize($field->extra_fields);
1600 - }
1601 - ?>
1602 - <div id="<?php echo $field->htmlvar_name;?>_row"
1603 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
3406 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3407 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3408 + $bs_sr_only = $design_style ? 'sr-only' : '';
3409 + $bs_form_control = $design_style ? 'form-control' : '';
3410 + $site_title = uwp_get_form_label( $field );
1604 3411
1605 - <?php
1606 - $site_title = uwp_get_form_label($field);
1607 - if (!is_admin()) { ?>
1608 - <label>
1609 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1610 - <?php if ($field->is_required) echo '<span>*</span>';?>
1611 - </label>
1612 - <?php } ?>
3412 + ob_start(); // Start buffering;
1613 3413
1614 - <input type="hidden" name="<?php echo $field->htmlvar_name;?>" value=""/>
1615 - <?php if ($multi_display == 'select') { ?>
1616 - <div class="uwp_multiselect_list">
1617 - <select name="<?php echo $field->htmlvar_name;?>[]"
1618 - id="<?php echo $field->htmlvar_name;?>"
1619 - title="<?php echo $site_title; ?>"
1620 - multiple="multiple" class="uwp_chosen_select"
1621 - data-placeholder="<?php echo $site_title; ?>"
1622 - >
1623 - <?php
1624 - } else {
3414 + // bootstrap
3415 + if ( $design_style ) {
3416 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3417 +
3418 + echo aui()->textarea(
3419 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3420 + 'id' => esc_attr( $field->htmlvar_name ),
3421 + 'name' => esc_attr( $field->htmlvar_name ),
3422 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3423 + 'title' => esc_html( $site_title ),
3424 + 'value' => wp_kses_post( stripslashes( $value ) ),
3425 + 'required' => (bool) $field->is_required,
3426 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3427 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3428 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3429 + 'rows' => '4',
3430 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3431 + )
3432 + );
3433 + } else {
3434 + ?>
3435 +
3436 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3437 + class="
3438 + <?php
3439 + if ( $field->is_required ) {
3440 + echo 'required_field';
3441 + }
3442 + ?>
3443 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3444 +
3445 + <?php
3446 +
3447 + if ( ! is_admin() ) {
3448 + ?>
3449 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3450 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3451 + <?php
3452 + if ( $field->is_required ) {
3453 + echo '<span>*</span>';
3454 + }
1625 3455 ?>
1626 - <ul class="uwp_multi_choice">
1627 - <?php
1628 - }
3456 + </label>
3457 + <?php } ?>
1629 3458
1630 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1631 - $select_options = '';
1632 - if (!empty($option_values_arr)) {
1633 - foreach ($option_values_arr as $option_row) {
1634 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1635 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
3459 + <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3460 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3461 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3462 + title="<?php echo esc_attr( $site_title ); ?>"
3463 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3464 + oninput="setCustomValidity('')"
3465 + <?php
3466 + if ( $field->is_required == 1 ) {
3467 + echo 'required="required"';
3468 + }
3469 + ?>
3470 + type="<?php echo esc_attr( $field->field_type ); ?>"
3471 + rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3472 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3473 + <?php if ( $field->is_required ) { ?>
3474 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3475 + <?php } ?>
3476 + </div>
1636 3477
1637 - if ($multi_display == 'select') {
1638 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1639 - } else {
1640 - $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
1641 - }
1642 - } else {
1643 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1644 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1645 - $selected = $option_value == $value ? 'selected="selected"' : '';
1646 - $checked = '';
3478 + <?php
3479 + }
3480 + $html = ob_get_clean();
3481 + }
1647 3482
1648 - if ((!is_array($value) && trim($value) != '') || (is_array($value) && !empty($value))) {
1649 - if (!is_array($value)) {
1650 - $value_array = explode(',', $value);
1651 - } else {
1652 - $value_array = $value;
1653 - }
3483 + return $html;
3484 + }
1654 3485
1655 - if (is_array($value_array)) {
1656 - if (in_array($option_value, $value_array)) {
1657 - $selected = 'selected="selected"';
1658 - $checked = 'checked="checked"';
1659 - }
1660 - }
1661 - }
3486 + public function form_input_editor( $html, $field, $value, $form_type ) {
1662 3487
1663 - if ($multi_display == 'select') {
1664 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1665 - } else {
1666 - $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr($option_value) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
1667 - }
1668 - }
1669 - }
1670 - }
1671 - echo $select_options;
3488 + // Check if there is a field specific filter.
3489 + if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3490 + $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3491 + }
1672 3492
1673 - if ($multi_display == 'select') { ?></select></div>
1674 - <?php } else { ?>
1675 - </ul>
1676 - <?php } ?>
1677 - <?php if ($field->is_required) { ?>
1678 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1679 - <?php } ?>
1680 - </div>
1681 - <?php
1682 - $html = ob_get_clean();
1683 - }
3493 + if ( empty( $html ) ) {
1684 3494
1685 - return $html;
1686 - }
3495 + ob_start();
1687 3496
1688 - /**
1689 - * Form field template for file field type.
1690 - *
1691 - * @since 1.0.0
1692 - * @package userswp
1693 - *
1694 - * @param string $html Form field html
1695 - * @param object $field Field info.
1696 - * @param string $value Form field default value.
1697 - * @param string $form_type Form type
1698 - *
1699 - * @return string Modified form field html.
1700 - */
1701 - public function uwp_form_input_file($html, $field, $value, $form_type){
3497 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3498 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3499 + $bs_sr_only = $design_style ? 'sr-only' : '';
3500 + $site_title = uwp_get_form_label( $field );
1702 3501
1703 - $file_obj = new UsersWP_Files();
1704 -
1705 - // Check if there is a field specific filter.
1706 - if(has_filter("uwp_form_input_html_file_{$field->htmlvar_name}")){
1707 - $html = apply_filters("uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1708 - }
3502 + $content = stripslashes( $value );
3503 + $editor_id = $field->htmlvar_name;
3504 + $args = array(
3505 + 'textarea_rows' => 5,
3506 + 'media_buttons' => false,
3507 + 'quicktags' => false,
3508 + );
1709 3509
1710 - // If no html then we run the standard output.
1711 - if(empty($html)) {
3510 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3511 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1712 3512
1713 - ob_start(); // Start buffering;
3513 + // bootstrap
3514 + if ( $design_style ) {
3515 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1714 3516
1715 - ?>
1716 - <div id="<?php echo $field->htmlvar_name;?>_row"
1717 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
3517 + echo aui()->textarea(
3518 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3519 + 'id' => esc_attr( $field->htmlvar_name ),
3520 + 'name' => esc_attr( $field->htmlvar_name ),
3521 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3522 + 'title' => esc_html( $site_title ),
3523 + 'value' => wp_kses_post( stripslashes( $value ) ),
3524 + 'required' => (bool) $field->is_required,
3525 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3526 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3527 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3528 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3529 + 'rows' => 5,
3530 + 'wysiwyg' => true,
3531 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3532 + )
3533 + );
3534 + } else {
3535 + ?>
3536 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3537 + class="
3538 + <?php
3539 + if ( $field->is_required ) {
3540 + echo 'required_field';
3541 + }
3542 + ?>
3543 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1718 3544
1719 - <?php
1720 - $site_title = uwp_get_form_label($field);
1721 - if (!is_admin()) { ?>
1722 - <label>
1723 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1724 - <?php if ($field->is_required) echo '<span>*</span>';?>
1725 - </label>
1726 - <?php } ?>
3545 + <?php
1727 3546
1728 - <?php echo $file_obj->uwp_file_upload_preview($field, $value); ?>
1729 - <input name="<?php echo $field->htmlvar_name; ?>"
1730 - class="<?php echo $field->css_class; ?>"
1731 - placeholder="<?php echo $site_title; ?>"
1732 - title="<?php echo $site_title; ?>"
3547 + if ( ! is_admin() ) {
3548 + ?>
3549 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3550 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3551 + <?php
3552 + if ( $field->is_required ) {
3553 + echo '<span>*</span>';
3554 + }
3555 + ?>
3556 + </label>
3557 + <?php } ?>
3558 +
3559 + <?php wp_editor( $content, $editor_id, $args ); ?>
3560 +
3561 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3562 + <?php if ( $field->is_required ) { ?>
3563 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3564 + <?php } ?>
3565 + </div>
3566 + <?php
3567 + }
3568 + $html = ob_get_clean();
3569 + }
3570 +
3571 + return $html;
3572 + }
3573 +
3574 + /**
3575 + * Form field template for fieldset field type.
3576 + *
3577 + * @param string $html Form field html
3578 + * @param object $field Field info.
3579 + * @param string $value Form field default value.
3580 + * @param string $form_type Form type
3581 + *
3582 + * @return string Modified form field html.
3583 + * @package userswp
3584 + *
3585 + * @since 1.0.0
3586 + */
3587 + public function form_input_fieldset( $html, $field, $value, $form_type ) {
3588 + // Check if there is a custom field specific filter.
3589 + if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3590 + $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3591 + }
3592 +
3593 + // If no html then we run the standard output.
3594 + if ( empty( $html ) ) {
3595 +
3596 + ob_start(); // Start buffering;
3597 + $site_title = uwp_get_form_label( $field );
3598 + ?>
3599 + <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3600 + <?php echo esc_html( $site_title ); ?>
3601 + <?php
3602 + if ( $field->help_text != '' ) {
3603 + echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3604 + }
3605 + ?>
3606 + </h3>
3607 + <?php
3608 + $html = ob_get_clean();
3609 + }
3610 +
3611 + return $html;
3612 + }
3613 +
3614 + /**
3615 + * Form field template for url field type.
3616 + *
3617 + * @param string $html Form field html
3618 + * @param object $field Field info.
3619 + * @param string $value Form field default value.
3620 + * @param string $form_type Form type
3621 + *
3622 + * @return string Modified form field html.
3623 + * @package userswp
3624 + *
3625 + * @since 1.0.0
3626 + */
3627 + public function form_input_url( $html, $field, $value, $form_type ) {
3628 +
3629 + // Check if there is a custom field specific filter.
3630 + if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
3631 + $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3632 + }
3633 +
3634 + // If no html then we run the standard output.
3635 + if ( empty( $html ) ) {
3636 +
3637 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3638 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3639 + $bs_sr_only = $design_style ? 'sr-only' : '';
3640 + $bs_form_control = $design_style ? 'form-control' : '';
3641 +
3642 + ob_start(); // Start buffering;
3643 + $site_title = uwp_get_form_label( $field );
3644 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
3645 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3646 +
3647 + // bootstrap
3648 + if ( $design_style ) {
3649 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3650 +
3651 + echo aui()->input(
3652 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3653 + 'type' => 'url',
3654 + 'id' => esc_attr( $field->htmlvar_name ),
3655 + 'name' => esc_attr( $field->htmlvar_name ),
3656 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3657 + 'title' => esc_html( $site_title ),
3658 + 'value' => esc_attr( $value ),
3659 + 'required' => (bool) $field->is_required,
3660 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3661 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3662 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3663 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3664 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3665 + )
3666 + );
3667 + } else {
3668 + ?>
3669 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3670 + class="
1733 3671 <?php
1734 - if ($field->is_required == 1 ) { echo 'data-is-required="1"'; }
1735 - if ($field->is_required == 1 && !$value) { echo 'required="required"'; }
3672 + if ( $field->is_required ) {
3673 + echo 'required_field';
3674 + }
1736 3675 ?>
1737 - type="<?php echo $field->field_type; ?>">
1738 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1739 - <?php if ($field->is_required) { ?>
1740 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1741 - <?php } ?>
1742 - </div>
3676 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1743 3677
1744 - <?php
1745 - $html = ob_get_clean();
1746 - }
3678 + <?php
3679 + if ( ! is_admin() ) {
3680 + ?>
3681 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3682 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3683 + <?php
3684 + if ( $field->is_required ) {
3685 + echo '<span>*</span>';
3686 + }
3687 + ?>
3688 + </label>
3689 + <?php } ?>
1747 3690
1748 - return $html;
1749 - }
3691 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3692 + class="
3693 + <?php
3694 + //echo $field->css_class;
3695 + ?>
3696 + uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3697 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3698 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3699 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3700 + title="<?php echo esc_attr( $site_title ); ?>"
3701 + <?php
3702 + if ( $field->is_required == 1 ) {
3703 + echo 'required="required"';
3704 + }
3705 + ?>
3706 + type="url"
3707 + oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
3708 + onchange="try{setCustomValidity('')}catch(e){}"
3709 + />
3710 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3711 + <?php if ( $field->is_required ) { ?>
3712 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3713 + <?php } ?>
3714 + </div>
1750 3715
1751 - /**
1752 - * Form field template for checkbox field type.
1753 - *
1754 - * @since 1.0.0
1755 - * @package userswp
1756 - *
1757 - * @param string $html Form field html
1758 - * @param object $field Field info.
1759 - * @param string $value Form field default value.
1760 - * @param string $form_type Form type
1761 - *
1762 - * @return string Modified form field html.
1763 - */
1764 - public function uwp_form_input_checkbox($html, $field, $value, $form_type){
3716 + <?php
3717 + }
1765 3718
1766 - // Check if there is a field specific filter.
1767 - if(has_filter("uwp_form_input_html_checkbox_{$field->htmlvar_name}")){
1768 - $html = apply_filters("uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1769 - }
3719 + $html = ob_get_clean();
3720 + }
1770 3721
1771 - // If no html then we run the standard output.
1772 - if(empty($html)) {
3722 + return $html;
3723 + }
1773 3724
1774 - ob_start(); // Start buffering;
1775 - $site_title = uwp_get_form_label($field);
1776 - ?>
1777 - <div id="<?php echo $field->htmlvar_name;?>_row"
1778 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
1779 - <input type="hidden" name="<?php echo $field->htmlvar_name; ?>" value="0" />
1780 - <input name="<?php echo $field->htmlvar_name; ?>"
1781 - class="<?php echo $field->css_class; ?>"
1782 - placeholder="<?php echo $site_title; ?>"
1783 - title="<?php echo $site_title; ?>"
1784 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1785 - <?php if ($value == '1') { echo 'checked="checked"'; } ?>
1786 - type="<?php echo $field->field_type; ?>"
1787 - value="1">
1788 - <?php
1789 - echo (trim($site_title)) ? $site_title : '&nbsp;';
3725 + /**
3726 + * Form field template for email field type.
3727 + *
3728 + * @param string $html Form field html
3729 + * @param object $field Field info.
3730 + * @param string $value Form field default value.
3731 + * @param string $form_type Form type
3732 + *
3733 + * @return string Modified form field html.
3734 + * @package userswp
3735 + *
3736 + * @since 1.0.0
3737 + */
3738 + public function form_input_email( $html, $field, $value, $form_type ) {
3739 +
3740 + // Check if there is a custom field specific filter.
3741 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
3742 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3743 + }
3744 +
3745 + // If no html then we run the standard output.
3746 + if ( empty( $html ) ) {
3747 +
3748 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3749 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3750 + $bs_sr_only = $design_style ? 'sr-only' : '';
3751 + $bs_form_control = $design_style ? 'form-control' : '';
3752 +
3753 + ob_start(); // Start buffering;
3754 + $site_title = uwp_get_form_label( $field );
3755 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3756 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3757 +
3758 + if ( $design_style ) {
3759 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3760 +
3761 + echo aui()->input(
3762 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3763 + 'type' => 'email',
3764 + 'id' => esc_attr( $field->htmlvar_name ),
3765 + 'name' => esc_attr( $field->htmlvar_name ),
3766 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3767 + 'title' => esc_html( $site_title ),
3768 + 'value' => esc_attr( wp_unslash( $value ) ),
3769 + 'required' => (bool) $field->is_required,
3770 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3771 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3772 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3773 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3774 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3775 + )
3776 + );
3777 + } else {
3778 + ?>
3779 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3780 + class="
3781 + <?php
3782 + if ( $field->is_required ) {
3783 + echo 'required_field';
3784 + }
3785 + ?>
3786 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3787 +
3788 + <?php
3789 + if ( ! is_admin() ) {
3790 + ?>
3791 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3792 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3793 + <?php
3794 + if ( $field->is_required ) {
3795 + echo '<span>*</span>';
3796 + }
3797 + ?>
3798 + </label>
3799 + <?php } ?>
3800 +
3801 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3802 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3803 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3804 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3805 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3806 + title="<?php echo esc_attr( $site_title ); ?>"
3807 + <?php
3808 + if ( $field->is_required == 1 ) {
3809 + echo 'required="required"';
3810 + }
3811 + ?>
3812 + type="email"
3813 + />
3814 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3815 + <?php if ( $field->is_required ) { ?>
3816 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3817 + <?php } ?>
3818 + </div>
3819 +
3820 +
3821 + <?php
3822 + }
3823 + $html = ob_get_clean();
3824 +
3825 + }
3826 +
3827 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
3828 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3829 + }
3830 +
3831 + return $html;
3832 + }
3833 +
3834 + /**
3835 + * Form field template for password field type.
3836 + *
3837 + * @param string $html Form field html
3838 + * @param object $field Field info.
3839 + * @param string $value Form field default value.
3840 + * @param string $form_type Form type
3841 + *
3842 + * @return string Modified form field html.
3843 + * @package userswp
3844 + *
3845 + * @since 1.0.0
3846 + */
3847 + public function form_input_password( $html, $field, $value, $form_type ) {
3848 +
3849 + // Check if there is a custom field specific filter.
3850 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
3851 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3852 + }
3853 +
3854 + // If no html then we run the standard output.
3855 + if ( empty( $html ) ) {
3856 +
3857 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3858 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3859 + $bs_sr_only = $design_style ? 'sr-only' : '';
3860 + $bs_form_control = $design_style ? 'form-control' : '';
3861 +
3862 + ob_start(); // Start buffering;
3863 + $site_title = uwp_get_form_label( $field );
3864 +
3865 + if ( $design_style ) {
3866 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3867 + $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3868 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3869 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
3870 +
3871 + echo aui()->input(
3872 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3873 + 'type' => 'password',
3874 + 'id' => esc_attr( $field->htmlvar_name ),
3875 + 'name' => esc_attr( $field->htmlvar_name ),
3876 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3877 + 'title' => esc_html( $site_title ),
3878 + 'value' => esc_attr( $value ),
3879 + 'required' => (bool) $field->is_required,
3880 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3881 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3882 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3883 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3884 + 'wrap_class' => esc_attr( $wrap_class ),
3885 + )
3886 + );
3887 + } else {
3888 + ?>
3889 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3890 + <?php
3891 + if ( $field->is_required ) {
3892 + echo 'required_field';
3893 + }
1790 3894 ?>
1791 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1792 - <?php if ($field->is_required) { ?>
1793 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1794 - <?php } ?>
1795 - </div>
3895 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3896 + <?php
3897 + if ( ! is_admin() ) {
3898 + ?>
3899 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3900 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3901 + <?php
3902 + if ( $field->is_required ) {
3903 + echo '<span>*</span>';
3904 + }
3905 + ?>
3906 + </label>
3907 + <?php } ?>
1796 3908
1797 - <?php
1798 - $html = ob_get_clean();
1799 - }
3909 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3910 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3911 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3912 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3913 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3914 + title="<?php echo esc_attr( $site_title ); ?>"
3915 + <?php
3916 + if ( $field->is_required == 1 ) {
3917 + echo 'required="required"';
3918 + }
3919 + ?>
3920 + type="password"
3921 + />
3922 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3923 + <?php if ( $field->is_required ) { ?>
3924 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3925 + <?php } ?>
3926 + </div>
1800 3927
1801 - return $html;
1802 - }
1803 3928
1804 - /**
1805 - * Form field template for radio field type.
1806 - *
1807 - * @since 1.0.0
1808 - * @package userswp
1809 - *
1810 - * @param string $html Form field html
1811 - * @param object $field Field info.
1812 - * @param string $value Form field default value.
1813 - * @param string $form_type Form type
1814 - *
1815 - * @return string Modified form field html.
1816 - */
1817 - public function uwp_form_input_radio($html, $field, $value, $form_type){
3929 + <?php
3930 + }
1818 3931
1819 - // Check if there is a field specific filter.
1820 - if(has_filter("uwp_form_input_html_radio_{$field->htmlvar_name}")){
1821 - $html = apply_filters("uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1822 - }
3932 + $html = ob_get_clean();
3933 + }
1823 3934
1824 - // If no html then we run the standard output.
1825 - if(empty($html)) {
3935 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
3936 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3937 + }
1826 3938
1827 - ob_start(); // Start buffering;
3939 + return $html;
3940 + }
1828 3941
1829 - ?>
1830 - <div id="<?php echo $field->htmlvar_name;?>_row"
1831 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
3942 + /**
3943 + * Form field template for Phone field.
3944 + *
3945 + * @param string $html Form field html
3946 + * @param object $field Field info.
3947 + * @param string $value Form field default value.
3948 + * @param string $form_type Form type
3949 + *
3950 + * @return string $html Modified form field html.
3951 + * @since 1.0.0
3952 + *
3953 + */
3954 + public function form_input_phone( $html, $field, $value, $form_type ) {
3955 + if ( empty( $html ) ) {
3956 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3957 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3958 + $bs_sr_only = $design_style ? 'sr-only' : '';
3959 + $bs_form_control = $design_style ? 'form-control' : '';
3960 + ob_start(); // Start buffering;
3961 + $site_title = uwp_get_form_label( $field );
3962 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3963 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1832 3964
1833 - <?php
1834 - $site_title = uwp_get_form_label($field);
1835 - if (!is_admin()) { ?>
1836 - <label>
1837 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1838 - <?php if ($field->is_required) echo '<span>*</span>';?>
1839 - </label>
1840 - <?php } ?>
3965 + if ( $design_style ) {
3966 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1841 3967
3968 + echo aui()->input(
3969 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3970 + 'type' => 'tel',
3971 + 'id' => esc_attr( $field->htmlvar_name ),
3972 + 'name' => esc_attr( $field->htmlvar_name ),
3973 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3974 + 'title' => esc_html( $site_title ),
3975 + 'value' => esc_attr( $value ),
3976 + 'required' => (bool) $field->is_required,
3977 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3978 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3979 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3980 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3981 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3982 + )
3983 + );
3984 + } else {
3985 + ?>
3986 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3987 + class="
3988 + <?php
3989 + if ( $field->is_required ) {
3990 + echo 'required_field';
3991 + }
3992 + ?>
3993 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3994 + <?php
3995 + if ( ! is_admin() ) {
3996 + ?>
3997 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3998 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3999 + <?php
4000 + if ( $field->is_required ) {
4001 + echo '<span>*</span>';
4002 + }
4003 + ?>
4004 + </label>
4005 + <?php } ?>
4006 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4007 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4008 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4009 + title="<?php echo esc_attr( $site_title ); ?>"
4010 + <?php
4011 + if ( $field->for_admin_use == 1 ) {
4012 + echo 'readonly="readonly"';
4013 + }
4014 + ?>
4015 + <?php
4016 + if ( $field->is_required == 1 ) {
4017 + echo 'required="required"';
4018 + }
4019 + ?>
4020 + type="tel"
4021 + value="<?php echo esc_html( $value ); ?>">
4022 + </div>
4023 + <?php
4024 + }
4025 + $html = ob_get_clean();
4026 + }
1842 4027
1843 - <?php if ($field->option_values) {
1844 - $option_values = uwp_string_values_to_options($field->option_values, true);
4028 + return $html;
4029 + }
1845 4030
1846 - if (!empty($option_values)) {
1847 - $count = 0;
1848 - foreach ($option_values as $option_value) {
1849 - if (empty($option_value['optgroup'])) {
1850 - $count++;
1851 - if ($count == 1) {
1852 - $class = "uwp-radio-first";
1853 - } else {
1854 - $class = "";
1855 - }
1856 - ?>
1857 - <span class="uwp-radios <?php echo $class; ?>">
1858 - <input name="<?php echo $field->htmlvar_name; ?>"
1859 - id="<?php echo $field->htmlvar_name; ?>"
1860 - title="<?php echo esc_attr($option_value['label']); ?>"
1861 - <?php checked($value, $option_value['value']);?>
1862 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1863 - value="<?php echo esc_attr($option_value['value']); ?>"
1864 - class="uwp-radio" type="radio" />
1865 - <?php echo $option_value['label']; ?>
1866 - </span>
1867 - <?php
1868 - }
1869 - }
1870 - }
1871 - }
1872 - ?>
1873 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1874 - <?php if ($field->is_required) { ?>
1875 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1876 - <?php } ?>
1877 - </div>
1878 - <?php
1879 - $html = ob_get_clean();
1880 - }
4031 + public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
1881 4032
1882 - return $html;
1883 - }
4033 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4034 + $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4035 + if ( empty( $reg_gdpr ) ) {
4036 + $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4037 + }
1884 4038
1885 - /**
1886 - * Form field template for text field type.
1887 - *
1888 - * @since 1.0.0
1889 - * @package userswp
1890 - *
1891 - * @param string $html Form field html
1892 - * @param object $field Field info.
1893 - * @param string $value Form field default value.
1894 - * @param string $form_type Form type
1895 - *
1896 - * @return string Modified form field html.
1897 - */
1898 - public function uwp_form_input_text($html, $field, $value, $form_type){
4039 + if ( ! empty( $reg_gdpr ) ) {
1899 4040
1900 - // Check if there is a custom field specific filter.
1901 - if(has_filter("uwp_form_input_text_{$field->htmlvar_name}")){
1902 - $html = apply_filters("uwp_form_input_text_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1903 - }
4041 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4042 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4043 + $bs_form_control = $design_style ? 'form-check-input' : '';
4044 + $site_title = uwp_get_form_label( $field );
4045 + $field->htmlvar_name = 'register_gdpr';
4046 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
1904 4047
1905 - // If no html then we run the standard output.
1906 - if(empty($html)) {
4048 + $gdpr_page = get_permalink( $reg_gdpr );
4049 + $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4050 + $link_end = '</a>';
4051 + $field_desc = uwp_get_field_description( $field, '' );
4052 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4053 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4054 + $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4055 + $checked = $value == '1' ? true : false;
1907 4056
1908 - ob_start(); // Start buffering;
4057 + ob_start(); // Start buffering;
1909 4058
1910 - $type = 'text';
1911 - $step = false;
1912 - //number and float validation $validation_pattern
1913 - if(isset($field->data_type) && $field->data_type == 'INT'){
1914 - $type = 'number';
1915 - } elseif(isset($field->data_type) && $field->data_type == 'FLOAT'){
1916 - $dp = $field->decimal_point;
1917 - switch ($dp) {
1918 - case "1":
1919 - $step = "0.1";
1920 - break;
1921 - case "2":
1922 - $step = "0.01";
1923 - break;
1924 - case "3":
1925 - $step = "0.001";
1926 - break;
1927 - case "4":
1928 - $step = "0.0001";
1929 - break;
1930 - case "5":
1931 - $step = "0.00001";
1932 - break;
1933 - case "6":
1934 - $step = "0.000001";
1935 - break;
1936 - case "7":
1937 - $step = "0.0000001";
1938 - break;
1939 - case "8":
1940 - $step = "0.00000001";
1941 - break;
1942 - case "9":
1943 - $step = "0.000000001";
1944 - break;
1945 - case "10":
1946 - $step = "0.0000000001";
1947 - break;
1948 - default:
1949 - $step = "0.01";
1950 - break;
1951 - }
1952 - $type = 'number';
1953 - }
4059 + // bootstrap
4060 + if ( $design_style ) {
4061 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4062 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
1954 4063
1955 - ?>
4064 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4065 + array(
4066 + 'id' => esc_attr( $id ),
4067 + 'name' => esc_attr( $field->htmlvar_name ),
4068 + 'type' => 'checkbox',
4069 + 'value' => '1',
4070 + 'title' => esc_html( $site_title ),
4071 + 'label' => wp_kses_post( $content . $required ),
4072 + 'label_show' => true,
4073 + 'required' => ! empty( $field->is_required ) ? true : false,
4074 + 'checked' => (bool) $checked,
4075 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4076 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4077 + )
4078 + );
1956 4079
1957 - <div id="<?php echo $field->htmlvar_name;?>_row"
1958 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4080 + } else {
4081 + ?>
4082 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4083 + class="
4084 + <?php
4085 + if ( $field->is_required ) {
4086 + echo 'required_field';
4087 + }
4088 + ?>
4089 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4090 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4091 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4092 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4093 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4094 + title="<?php echo esc_attr( $site_title ); ?>"
4095 + <?php
4096 + if ( $value == '1' ) {
4097 + echo 'checked="checked"';
4098 + }
4099 + ?>
4100 + type="<?php echo esc_attr( $field->field_type ); ?>"
4101 + value="1">
4102 + <?php
4103 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4104 + ?>
4105 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4106 + <?php if ( $field->is_required ) { ?>
4107 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4108 + <?php } ?>
4109 + </div>
1959 4110
1960 - <?php
1961 - $site_title = uwp_get_form_label($field);
1962 - $manual_label = apply_filters('uwp_login_username_label_manual', true);
1963 - if ($manual_label
1964 - && isset($field->form_type)
1965 - && $field->form_type == 'login'
1966 - && $field->htmlvar_name == 'uwp_login_username') {
1967 - $site_title = __("Username or Email", 'userswp');
1968 - }
1969 - if (!is_admin()) { ?>
1970 - <label>
1971 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1972 - <?php if ($field->is_required) echo '<span>*</span>';?>
1973 - </label>
1974 - <?php } ?>
4111 + <?php
4112 + }
1975 4113
1976 - <input name="<?php echo $field->htmlvar_name;?>"
1977 - class="<?php echo $field->css_class; ?> uwp_textfield"
1978 - id="<?php echo $field->htmlvar_name;?>"
1979 - placeholder="<?php echo $site_title; ?>"
1980 - value="<?php echo esc_attr(stripslashes($value));?>"
1981 - title="<?php echo $site_title; ?>"
1982 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
1983 - oninput="setCustomValidity('')"
1984 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1985 - <?php if ($field->for_admin_use == 1) { echo 'readonly="readonly"'; } ?>
1986 - type="<?php echo $type; ?>"
1987 - <?php if ($step) { echo 'step="'.$step.'"'; } ?>
1988 - />
1989 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1990 - <?php if ($field->is_required) { ?>
1991 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1992 - <?php } ?>
1993 - </div>
4114 + $html = ob_get_clean();
1994 4115
4116 + } else {
4117 + $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4118 + }
1995 4119
1996 - <?php
1997 - $html = ob_get_clean();
1998 - }
4120 + return $html;
4121 + }
1999 4122
2000 - return $html;
2001 - }
4123 + public function form_input_register_tos( $html, $field, $value, $form_type ) {
2002 4124
2003 - /**
2004 - * Form field template for textarea field type.
2005 - *
2006 - * @since 1.0.0
2007 - * @package userswp
2008 - *
2009 - * @param string $html Form field html
2010 - * @param object $field Field info.
2011 - * @param string $value Form field default value.
2012 - * @param string $form_type Form type
2013 - *
2014 - * @return string Modified form field html.
2015 - */
2016 - public function uwp_form_input_textarea($html, $field, $value, $form_type){
4125 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4126 + $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4127 + if ( empty( $reg_tos ) ) {
4128 + $reg_tos = uwp_get_option( 'register_terms_page', false );
4129 + }
2017 4130
2018 - // Check if there is a field specific filter.
2019 - if(has_filter("uwp_form_input_textarea_{$field->htmlvar_name}")){
2020 - $html = apply_filters("uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2021 - }
4131 + if ( ! empty( $reg_tos ) ) {
2022 4132
2023 - // If no html then we run the standard output.
2024 - if(empty($html)) {
4133 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4134 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4135 + $bs_form_control = $design_style ? 'form-check-input' : '';
2025 4136
2026 - ob_start(); // Start buffering;
4137 + $site_title = uwp_get_form_label( $field );
4138 + $terms_page = get_permalink( $reg_tos );
4139 + $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4140 + $link_end = '</a>';
4141 + $field_desc = uwp_get_field_description( $field, '' );
4142 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4143 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4144 + $field->htmlvar_name = 'register_tos';
4145 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2027 4146
2028 - ?>
2029 - <div id="<?php echo $field->htmlvar_name;?>_row"
2030 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4147 + $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4148 + $checked = $value == '1' ? true : false;
2031 4149
2032 - <?php
2033 - $site_title = uwp_get_form_label($field);
2034 - if (!is_admin()) { ?>
2035 - <label>
2036 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2037 - <?php if ($field->is_required) echo '<span>*</span>';?>
2038 - </label>
2039 - <?php } ?>
4150 + ob_start();
2040 4151
2041 - <textarea name="<?php echo $field->htmlvar_name; ?>"
2042 - class="<?php echo $field->css_class; ?>"
2043 - placeholder="<?php echo $site_title; ?>"
2044 - title="<?php echo $site_title; ?>"
2045 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
2046 - oninput="setCustomValidity('')"
2047 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2048 - type="<?php echo $field->field_type; ?>"
2049 - rows="4"><?php echo stripslashes($value); ?></textarea>
2050 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2051 - <?php if ($field->is_required) { ?>
2052 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2053 - <?php } ?>
2054 - </div>
4152 + if ( $design_style ) {
4153 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4154 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2055 4155
2056 - <?php
2057 - $html = ob_get_clean();
2058 - }
4156 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4157 + array(
4158 + 'id' => esc_attr( $id ),
4159 + 'name' => esc_attr( $field->htmlvar_name ),
4160 + 'type' => 'checkbox',
4161 + 'value' => '1',
4162 + 'title' => esc_html( $site_title ),
4163 + 'label' => wp_kses_post( $content . $required ),
4164 + 'label_show' => true,
4165 + 'required' => ! empty( $field->is_required ) ? true : false,
4166 + 'checked' => (bool) $checked,
4167 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4168 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4169 + )
4170 + );
2059 4171
2060 - return $html;
2061 - }
4172 + } else {
4173 + ?>
4174 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4175 + class="
4176 + <?php
4177 + if ( $field->is_required ) {
4178 + echo 'required_field';
4179 + }
4180 + ?>
4181 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4182 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4183 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4184 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4185 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4186 + title="<?php echo esc_attr( $site_title ); ?>"
4187 + <?php
4188 + if ( $value == '1' ) {
4189 + echo 'checked="checked"';
4190 + }
4191 + ?>
4192 + type="<?php echo esc_attr( $field->field_type ); ?>"
4193 + value="1">
4194 + <?php
4195 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4196 + ?>
4197 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4198 + <?php if ( $field->is_required ) { ?>
4199 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4200 + <?php } ?>
4201 + </div>
2062 4202
2063 - /**
2064 - * Form field template for fieldset field type.
2065 - *
2066 - * @since 1.0.0
2067 - * @package userswp
2068 - *
2069 - * @param string $html Form field html
2070 - * @param object $field Field info.
2071 - * @param string $value Form field default value.
2072 - * @param string $form_type Form type
2073 - *
2074 - * @return string Modified form field html.
2075 - */
2076 - public function uwp_form_input_fieldset($html, $field, $value, $form_type) {
2077 - // Check if there is a custom field specific filter.
2078 - if(has_filter("uwp_form_input_fieldset_{$field->htmlvar_name}")){
2079 - $html = apply_filters("uwp_form_input_fieldset_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2080 - }
4203 + <?php
2081 4204
2082 - // If no html then we run the standard output.
2083 - if(empty($html)) {
4205 + }
2084 4206
2085 - ob_start(); // Start buffering;
2086 - ?>
2087 - <h3 class="uwp_input_fieldset <?php echo $field->css_class; ?>">
2088 - <?php echo $field->site_title;; ?>
2089 - <?php if ( $field->help_text != '' ) {
2090 - echo '<small>( ' . $field->help_text . ' )</small>';
2091 - } ?></h3>
2092 - <?php
2093 - $html = ob_get_clean();
2094 - }
4207 + $html = ob_get_clean();
2095 4208
2096 - return $html;
2097 - }
4209 + } else {
4210 + $html = '<input type="hidden" name="register_tos" value="-1"/>';
4211 + }
2098 4212
2099 - /**
2100 - * Form field template for url field type.
2101 - *
2102 - * @since 1.0.0
2103 - * @package userswp
2104 - *
2105 - * @param string $html Form field html
2106 - * @param object $field Field info.
2107 - * @param string $value Form field default value.
2108 - * @param string $form_type Form type
2109 - *
2110 - * @return string Modified form field html.
2111 - */
2112 - public function uwp_form_input_url($html, $field, $value, $form_type){
4213 + return $html;
4214 + }
2113 4215
4216 + /**
4217 + * Adds enctype tag in form for file fields.
4218 + *
4219 + * @return void
4220 + * @package userswp
4221 + *
4222 + * @since 1.0.0
4223 + */
4224 + function add_multipart_to_admin_edit_form() {
4225 + global $wpdb;
4226 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4227 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4228 + if ( $fields ) {
4229 + echo 'enctype="multipart/form-data"';
4230 + }
4231 + }
2114 4232
2115 - // Check if there is a custom field specific filter.
2116 - if(has_filter("uwp_form_input_url_{$field->htmlvar_name}")){
2117 - $html = apply_filters("uwp_form_input_url_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2118 - }
4233 + /**
4234 + * Handles UsersWP custom field requests from admin.
4235 + *
4236 + * @param int $user_id User ID.
4237 + *
4238 + * @return void
4239 + * @since 1.0.0
4240 + * @package userswp
4241 + *
4242 + */
4243 + public function update_profile_extra_admin_edit( $user_id ) {
4244 + global $wpdb;
4245 + $file_obj = new UsersWP_Files();
4246 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4247 + //Normal fields
4248 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4249 + if ( $fields ) {
4250 + if ( isset( $_POST['locale'] ) ) {
4251 + $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4252 + }
4253 + $result = uwp_validate_fields( $_POST, 'account', $fields );
4254 + if ( is_wp_error( $result ) ) {
4255 + die( wp_kses_post( $result->get_error_message() ) );
4256 + }
4257 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4258 + $display_name = $result['display_name'];
4259 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4260 + $display_name = $result['first_name'] . ' ' . $result['last_name'];
4261 + } else {
4262 + $user_info = get_userdata( $user_id );
4263 + $display_name = $user_info->user_login;
4264 + }
4265 + $result['display_name'] = $display_name;
4266 + if ( ! is_wp_error( $result ) ) {
4267 + foreach ( $fields as $field ) {
4268 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4269 + if ( $value == '0' || ! empty( $value ) ) {
4270 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4271 + }
4272 + }
4273 + }
4274 + }
2119 4275
2120 - // If no html then we run the standard output.
2121 - if(empty($html)) {
4276 + //File fields
4277 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4278 + if ( $fields ) {
4279 + $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4280 + if ( ! is_wp_error( $result ) ) {
4281 + foreach ( $fields as $field ) {
4282 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4283 + if ( $value == '0' || ! empty( $value ) ) {
4284 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4285 + }
4286 + }
4287 + }
4288 + }
4289 + }
2122 4290
2123 - ob_start(); // Start buffering;
2124 - ?>
2125 - <div id="<?php echo $field->htmlvar_name;?>_row"
2126 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4291 + /**
4292 + * Form field template for country field.
4293 + *
4294 + * @param string $html Form field html
4295 + * @param object $field Field info.
4296 + * @param string $value Form field default value.
4297 + * @param string $form_type Form type
4298 + *
4299 + * @return string Modified form field html.
4300 + * @package userswp
4301 + *
4302 + * @since 1.0.0
4303 + */
4304 + public function form_input_select_country( $html, $field, $value, $form_type ) {
2127 4305
4306 + // If no html then we run the standard output.
4307 + if ( empty( $html ) ) {
4308 +
4309 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4310 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4311 + $bs_sr_only = $design_style ? 'sr-only' : '';
4312 + $bs_form_control = $design_style ? 'form-control' : '';
4313 +
4314 + ob_start(); // Start buffering;
4315 + ?>
4316 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4317 +
4318 + <?php
4319 + $site_title = uwp_get_form_label( $field );
4320 +
4321 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4322 + ?>
4323 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4324 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4325 + <?php
4326 + if ( $field->is_required ) {
4327 + echo '<span class="text-danger">*</span>';
4328 + }
4329 + ?>
4330 + </label>
4331 + <?php
4332 + }
4333 + // if value empty set the default
4334 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4335 + $value = $field->default_value;
4336 + }
4337 + if ( $value === false ) {
4338 + $value = '';
4339 + }
4340 + $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4341 + $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4342 +
4343 + $htmlvar_name = $field->htmlvar_name;
4344 + if ( wp_doing_ajax() ) {
4345 + $htmlvar_name .= '_ajax';
4346 + }
4347 + ?>
4348 + <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4349 + <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4350 + <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4351 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4352 + <?php if ( $field->is_required ) { ?>
4353 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4354 + <?php } ?>
4355 + </div>
4356 + <?php
4357 + $html = ob_get_clean();
4358 + }
4359 +
4360 + return $html;
4361 + }
4362 +
4363 + /**
4364 + * Form field template for language field.
4365 + *
4366 + * @param string $html Form field html
4367 + * @param object $field Field info.
4368 + * @param string $value Form field default value.
4369 + * @param string $form_type Form type
4370 + *
4371 + * @return string Modified form field html.
4372 + * @package userswp
4373 + *
4374 + * @since 1.0.0
4375 + */
4376 + public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4377 +
4378 + // If no html then we run the standard output.
4379 + if ( empty( $html ) ) {
4380 +
4381 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4382 + $bs_form_group = $design_style ? 'form-group m-0' : '';
4383 + $bs_sr_only = $design_style ? 'sr-only' : '';
4384 + $bs_form_control = $design_style ? 'form-control' : '';
4385 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4386 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4387 +
4388 + ob_start(); // Start buffering;
4389 +
4390 + ?>
4391 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4392 + class="
2128 4393 <?php
2129 - $site_title = uwp_get_form_label($field);
2130 - if (!is_admin()) { ?>
2131 - <label>
2132 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2133 - <?php if ($field->is_required) echo '<span>*</span>';?>
4394 + if ( $field->is_required ) {
4395 + echo 'required_field';
4396 + }
4397 + ?>
4398 + uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4399 +
4400 + <?php
4401 + $site_title = uwp_get_form_label( $field );
4402 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4403 + ?>
4404 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4405 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4406 + <?php
4407 + if ( $field->is_required ) {
4408 + echo '<span class="text-danger">*</span>';
4409 + }
4410 + ?>
2134 4411 </label>
2135 - <?php } ?>
4412 + <?php } ?>
2136 4413
2137 - <input name="<?php echo $field->htmlvar_name;?>"
2138 - class="<?php echo $field->css_class; ?> uwp_textfield"
2139 - id="<?php echo $field->htmlvar_name;?>"
2140 - placeholder="<?php echo $site_title; ?>"
2141 - value="<?php echo esc_attr(stripslashes($value));?>"
2142 - title="<?php echo $site_title; ?>"
2143 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2144 - type="url"
2145 - oninvalid="setCustomValidity('<?php _e('Please enter a valid URL including http://', 'userswp'); ?>')"
2146 - onchange="try{setCustomValidity('')}catch(e){}"
2147 - />
2148 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2149 - <?php if ($field->is_required) { ?>
2150 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2151 - <?php } ?>
2152 - </div>
4414 + <?php
4415 + if ( empty( $field->default_value ) ) {
4416 + $field->default_value = 'site-default';
4417 + }
2153 4418
2154 - <?php
2155 - $html = ob_get_clean();
2156 - }
4419 + // if value empty set the default
4420 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4421 + $value = $field->default_value;
4422 + }
2157 4423
2158 - return $html;
2159 - }
4424 + require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4425 + $translations = wp_get_available_translations();
4426 + $available_languages = get_available_languages();
4427 + $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
2160 4428
2161 - /**
2162 - * Form field template for email field type.
2163 - *
2164 - * @since 1.0.0
2165 - * @package userswp
2166 - *
2167 - * @param string $html Form field html
2168 - * @param object $field Field info.
2169 - * @param string $value Form field default value.
2170 - * @param string $form_type Form type
2171 - *
2172 - * @return string Modified form field html.
2173 - */
2174 - public function uwp_form_input_email($html, $field, $value, $form_type){
4429 + foreach ( $available_languages as $locale ) {
4430 + if ( isset( $translations[ $locale ] ) ) {
4431 + $translation = $translations[ $locale ];
4432 + $languages[ $translation['language'] ] = $translation['native_name'];
2175 4433
4434 + // Remove installed language from available translations.
4435 + unset( $translations[ $locale ] );
4436 + } else {
4437 + $languages[ $locale ] = $translation[ $locale ];
4438 + }
4439 + }
2176 4440
2177 - // Check if there is a custom field specific filter.
2178 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}")){
2179 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2180 - }
4441 + if ( $design_style ) {
2181 4442
2182 - // If no html then we run the standard output.
2183 - if(empty($html)) {
4443 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2184 4444
2185 - ob_start(); // Start buffering;
2186 - ?>
2187 - <div id="<?php echo $field->htmlvar_name;?>_row"
2188 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4445 + echo aui()->select(
4446 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4447 + 'id' => esc_attr( $field->htmlvar_name ),
4448 + 'name' => esc_attr( $field->htmlvar_name ),
4449 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4450 + 'title' => esc_attr( $site_title ),
4451 + 'value' => esc_attr( $value ),
4452 + 'required' => (bool) $field->is_required,
4453 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4454 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4455 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4456 + 'label' => wp_kses_post( $site_title . $required ),
4457 + 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4458 + 'select2' => true,
4459 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4460 + )
4461 + );
4462 + } else {
4463 + ?>
4464 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4465 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4466 + title="<?php echo esc_attr( $site_title ); ?>"
4467 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4468 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4469 + </select>
4470 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4471 + <?php if ( $field->is_required ) { ?>
4472 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4473 + <?php
4474 + }
4475 + }
2189 4476
2190 - <?php
2191 - $site_title = uwp_get_form_label($field);
2192 - if (!is_admin()) { ?>
2193 - <label>
2194 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2195 - <?php if ($field->is_required) echo '<span>*</span>';?>
2196 - </label>
2197 - <?php } ?>
4477 + $html = ob_get_clean();
4478 + }
2198 4479
2199 - <input name="<?php echo $field->htmlvar_name;?>"
2200 - class="<?php echo $field->css_class; ?> uwp_textfield"
2201 - id="<?php echo $field->htmlvar_name;?>"
2202 - placeholder="<?php echo $site_title; ?>"
2203 - value="<?php echo esc_attr(stripslashes($value));?>"
2204 - title="<?php echo $site_title; ?>"
2205 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2206 - type="email"
2207 - />
2208 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2209 - <?php if ($field->is_required) { ?>
2210 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2211 - <?php } ?>
2212 - </div>
4480 + return $html;
4481 + }
2213 4482
4483 + /**
4484 + * Adds confirm password field in forms.
4485 + *
4486 + * @param string $html Form field html
4487 + * @param object $field Field info.
4488 + * @param string $value Form field default value.
4489 + * @param string $form_type Form type
4490 + *
4491 + * @return string Modified form field html.
4492 + * @package userswp
4493 + *
4494 + * @since 1.0.0
4495 + */
4496 + public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4497 + if ( $form_type == 'register' ) {
4498 + //confirm password field
4499 + $extra = array();
4500 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4501 + $extra = unserialize( $field->extra_fields );
4502 + }
2214 4503
2215 - <?php
2216 - $html = ob_get_clean();
2217 - }
4504 + $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4505 + if ( $enable_confirm_password_field == '1' ) {
2218 4506
2219 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}_after")){
2220 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2221 - }
4507 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4508 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4509 + $bs_sr_only = $design_style ? 'sr-only' : '';
4510 + $bs_form_control = $design_style ? 'form-control' : '';
4511 + $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4512 + $required = '';
4513 + if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4514 + $placeholder .= ' *';
4515 + $required = ' <span class="text-danger">*</span>';
4516 + }
4517 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4518 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4519 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
2222 4520
2223 - return $html;
2224 - }
4521 + ob_start(); // Start buffering;
2225 4522
2226 - /**
2227 - * Form field template for password field type.
2228 - *
2229 - * @since 1.0.0
2230 - * @package userswp
2231 - *
2232 - * @param string $html Form field html
2233 - * @param object $field Field info.
2234 - * @param string $value Form field default value.
2235 - * @param string $form_type Form type
2236 - *
2237 - * @return string Modified form field html.
2238 - */
2239 - public function uwp_form_input_password($html, $field, $value, $form_type){
4523 + if ( $design_style ) {
2240 4524
4525 + echo aui()->input(
4526 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4527 + 'type' => 'password',
4528 + 'id' => 'confirm_password',
4529 + 'name' => 'confirm_password',
4530 + 'placeholder' => esc_attr( $placeholder ),
4531 + 'title' => esc_attr( $site_title ),
4532 + 'value' => esc_attr( $value ),
4533 + 'required' => (bool) $field->is_required,
4534 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4535 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4536 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4537 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4538 + 'wrap_class' => esc_attr( $wrap_class ),
4539 + )
4540 + );
4541 + } else {
4542 + ?>
4543 + <div id="uwp_account_confirm_password_row"
4544 + class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2241 4545
2242 - // Check if there is a custom field specific filter.
2243 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}")){
2244 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2245 - }
4546 + <?php
2246 4547
2247 - // If no html then we run the standard output.
2248 - if(empty($html)) {
4548 + if ( ! is_admin() ) {
4549 + ?>
4550 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4551 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4552 + <?php
4553 + if ( $field->is_required ) {
4554 + echo '<span>*</span>';
4555 + }
4556 + ?>
4557 + </label>
4558 + <?php } ?>
4559 + <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4560 + </div>
2249 4561
2250 - ob_start(); // Start buffering;
2251 - ?>
2252 - <div id="<?php echo $field->htmlvar_name;?>_row"
2253 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4562 + <?php
4563 + }
4564 + $confirm_html = ob_get_clean();
4565 + $html = $html . $confirm_html;
4566 + }
4567 + }
2254 4568
2255 - <?php
2256 - $site_title = uwp_get_form_label($field);
2257 - if (!is_admin()) { ?>
2258 - <label>
2259 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2260 - <?php if ($field->is_required) echo '<span>*</span>';?>
2261 - </label>
2262 - <?php } ?>
4569 + return $html;
4570 + }
2263 4571
2264 - <input name="<?php echo $field->htmlvar_name;?>"
2265 - class="<?php echo $field->css_class; ?> uwp_textfield"
2266 - id="<?php echo $field->htmlvar_name;?>"
2267 - placeholder="<?php echo $site_title; ?>"
2268 - value="<?php echo esc_attr(stripslashes($value));?>"
2269 - title="<?php echo $site_title; ?>"
2270 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2271 - type="password"
2272 - />
2273 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2274 - <?php if ($field->is_required) { ?>
2275 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2276 - <?php } ?>
2277 - </div>
4572 + /**
4573 + * Adds confirm email field in forms.
4574 + *
4575 + * @param string $html Form field html
4576 + * @param object $field Field info.
4577 + * @param string $value Form field default value.
4578 + * @param string $form_type Form type
4579 + *
4580 + * @return string Modified form field html.
4581 + * @package userswp
4582 + *
4583 + * @since 1.0.0
4584 + */
4585 + public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4586 + if ( $form_type == 'register' ) {
4587 + //confirm email field
4588 + $extra = array();
4589 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4590 + $extra = unserialize( $field->extra_fields );
4591 + }
4592 + $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4593 + if ( $enable_confirm_email_field == '1' ) {
2278 4594
4595 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4596 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4597 + $bs_sr_only = $design_style ? 'sr-only' : '';
4598 + $bs_form_control = $design_style ? 'form-control' : '';
4599 + $site_title = __( 'Confirm Email', 'userswp' );
4600 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4601 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2279 4602
2280 - <?php
2281 - $html = ob_get_clean();
2282 - }
4603 + ob_start();
2283 4604
2284 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}_after")){
2285 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2286 - }
4605 + if ( $design_style ) {
4606 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2287 4607
2288 - return $html;
2289 - }
4608 + echo aui()->input(
4609 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4610 + 'type' => 'email',
4611 + 'id' => esc_attr( $field->htmlvar_name ),
4612 + 'name' => 'confirm_email',
4613 + 'placeholder' => esc_attr( $site_title ),
4614 + 'title' => esc_attr( $site_title ),
4615 + 'value' => esc_attr( $value ),
4616 + 'required' => (bool) $field->is_required,
4617 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4618 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4619 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4620 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4621 + )
4622 + );
4623 + } else {
4624 + ?>
4625 + <div id="uwp_account_confirm_email_row"
4626 + class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2290 4627
4628 + <?php
2291 4629
4630 + if ( ! is_admin() ) {
4631 + ?>
4632 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4633 + <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
4634 + <?php
4635 + if ( $field->is_required ) {
4636 + echo '<span>*</span>';
4637 + }
4638 + ?>
4639 + </label>
4640 + <?php } ?>
2292 4641
2293 - /**
2294 - * Adds enctype tag in form for file fields.
2295 - *
2296 - * @since 1.0.0
2297 - * @package userswp
2298 - *
2299 - * @return void
2300 - */
2301 - function add_multipart_to_admin_edit_form() {
2302 - global $wpdb;
2303 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2304 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2305 - if ($fields) {
2306 - echo 'enctype="multipart/form-data"';
2307 - }
2308 - }
4642 + <input name="confirm_email"
4643 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4644 + id="uwp_account_confirm_email"
4645 + placeholder="<?php echo esc_attr( $site_title ); ?>"
4646 + value=""
4647 + title="<?php echo esc_attr( $site_title ); ?>"
4648 + <?php echo 'required="required"'; ?>
4649 + type="email"
4650 + />
4651 + </div>
4652 + <?php
4653 + }
4654 + $confirm_html = ob_get_clean();
4655 + $html = $html . $confirm_html;
4656 + }
4657 + }
2309 4658
2310 - /**
2311 - * Handles UsersWP custom field requests from admin.
2312 - *
2313 - * @since 1.0.0
2314 - * @package userswp
2315 - *
2316 - * @param int $user_id User ID.
2317 - *
2318 - * @return void
2319 - */
2320 - public function update_profile_extra_admin_edit($user_id) {
2321 - global $wpdb;
2322 - $file_obj = new UsersWP_Files();
2323 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2324 - //Normal fields
2325 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC");
2326 - if ($fields) {
2327 - $_POST['uwp_account_first_name'] = $_POST['first_name'];
2328 - $_POST['uwp_account_last_name'] = $_POST['last_name'];
2329 - $_POST['uwp_account_display_name'] = $_POST['nickname'];
2330 - $_POST['uwp_account_email'] = $_POST['email'];
2331 - $result = uwp_validate_fields($_POST, 'account', $fields);
2332 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
2333 - $display_name = $result['uwp_account_display_name'];
2334 - } else {
2335 - if (!empty($first_name) || !empty($last_name)) {
2336 - $display_name = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
2337 - } else {
2338 - $user_info = get_userdata($user_id);
2339 - $display_name = $user_info->user_login;
2340 - }
2341 - }
2342 - $result['uwp_account_display_name'] = $display_name;
2343 - if (!is_wp_error($result)) {
2344 - foreach ($fields as $field) {
2345 - $value = isset($result[$field->htmlvar_name]) ? $result[$field->htmlvar_name] : '';
2346 - if ($value == '0' || !empty($value)) {
2347 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2348 - }
2349 - }
2350 - }
2351 - }
4659 + return $html;
4660 + }
2352 4661
2353 - //File fields
2354 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2355 - if ($fields) {
2356 - $result = $file_obj->uwp_validate_uploads($_FILES, 'account', true, $fields);
2357 - if (!is_wp_error($result)) {
2358 - foreach ($fields as $field) {
2359 - $value = $result[$field->htmlvar_name];
2360 - if ($value == '0' || !empty($value)) {
2361 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2362 - }
2363 - }
2364 - }
2365 - }
2366 - }
4662 + /**
4663 + * Handles the privacy form submission.
4664 + *
4665 + * @return void
4666 + * @package userswp
4667 + *
4668 + * @since 1.0.0
4669 + */
4670 + public function privacy_submit_handler() {
4671 + if ( isset( $_POST['uwp_privacy_submit'] ) ) {
4672 + if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
4673 + return;
4674 + }
2367 4675
4676 + global $wpdb, $uwp_notices;
2368 4677
2369 - /**
2370 - * Adds search form keyword input html.
2371 - *
2372 - * @since 1.0.0
2373 - * @package userswp
2374 - *
2375 - * @param string $keyword Search keyword.
2376 - *
2377 - * @return void
2378 - */
2379 - public function uwp_users_search_form_text_field($keyword) {
2380 - ?>
2381 - <input placeholder="<?php _e('Search For', 'userswp'); ?>" name="uwps" value="<?php echo $keyword; ?>" class="s search-input" type="text">
2382 - <?php
2383 - }
4678 + // Save fields privacy settings
4679 + $extra_where = "AND is_public='2'";
4680 + $fields = get_account_form_fields( $extra_where );
4681 + $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
4682 + $user_id = get_current_user_id();
4683 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
2384 4684
2385 - /**
2386 - * Adds search form submit button html.
2387 - *
2388 - * @since 1.0.0
2389 - * @package userswp
2390 - *
2391 - * @return void
2392 - */
2393 - public function uwp_users_search_form_submit() {
2394 - ?>
2395 - <input class="uwp-searchsubmit uwp-search-submit" value="<?php _e('Search', 'userswp'); ?>" type="submit">
2396 - <?php
2397 - }
4685 + $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4686 + if ( ! empty( $user_meta_info->user_privacy ) ) {
4687 + $public_fields = explode( ',', $user_meta_info->user_privacy );
4688 + } else {
4689 + $public_fields = array();
4690 + }
2398 4691
2399 - /**
2400 - * Checks for errors in mail submission.
2401 - *
2402 - * @since 1.0.0
2403 - * @package userswp
2404 - *
2405 - * @param array $res Result array.
2406 - * @param object $user_data User object.
2407 - * @param WP_Error $errors Error object
2408 - *
2409 - * @return WP_Error|array Error object when error. Result array when success.
2410 - */
2411 - public function uwp_forms_check_for_send_mail_errors($res, $user_data, $errors) {
2412 - if (!$res) {
2413 - if (get_option('admin_email') == $user_data->user_email) {
2414 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please check your site error log for more details.', 'userswp'));
2415 - } else {
2416 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
2417 - }
2418 - }
4692 + if ( $fields ) {
2419 4693
2420 - $error_code = $errors->get_error_code();
2421 - if (!empty($error_code)) {
2422 - return $errors;
2423 - } else {
2424 - return $res;
2425 - }
2426 -
2427 - }
4694 + foreach ( $fields as $field ) {
4695 + $field_name = $field->htmlvar_name . '_privacy';
4696 + $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
2428 4697
2429 - /**
2430 - * Form field template for country field.
2431 - *
2432 - * @since 1.0.0
2433 - * @package userswp
2434 - *
2435 - * @param string $html Form field html
2436 - * @param object $field Field info.
2437 - * @param string $value Form field default value.
2438 - * @param string $form_type Form type
2439 - *
2440 - * @return string Modified form field html.
2441 - */
2442 - public function uwp_form_input_select_country($html, $field, $value, $form_type){
4698 + if ( $field_value == 'no' ) {
4699 + if ( ! in_array( $field_name, $public_fields ) ) {
4700 + $public_fields[] = $field_name;
4701 + }
4702 + } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
4703 + unset( $public_fields[ $field_name ] );
4704 + }
4705 + }
2443 4706
2444 - // Check if there is a field specific filter.
2445 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
2446 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2447 - }
4707 + $value = implode( ',', $public_fields );
4708 + uwp_update_usermeta( $user_id, 'user_privacy', $value );
4709 + }
2448 4710
2449 - //print_r($field);
4711 + // Save tabs privacy settings
4712 + $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
4713 + $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
2450 4714
2451 - // If no html then we run the standard output.
2452 - if(empty($html)) {
4715 + if ( $tabs ) {
4716 + $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
4717 + $do_tabs_update = false;
4718 + foreach ( $tabs as $tab ) {
4719 + $field_name = $tab->tab_key . '_tab_privacy';
2453 4720
2454 - ob_start(); // Start buffering;
4721 + if ( isset( $_POST[ $field_name ] ) ) {
4722 + $do_tabs_update = true;
4723 + $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
2455 4724
2456 - ?>
2457 - <div id="<?php echo $field->htmlvar_name;?>_row"
2458 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
4725 + if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
4726 + unset( $public_fields[ $field_name ] );
4727 + } else {
4728 + $public_fields[ $field_name ] = $field_value;
4729 + }
4730 + }
4731 +}
2459 4732
2460 - <?php
2461 - $site_title = uwp_get_form_label($field);
2462 - if (!is_admin()) { ?>
2463 - <label>
2464 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2465 - <?php if ($field->is_required) echo '<span>*</span>';?>
2466 - </label>
2467 - <?php } ?>
4733 + if ( $do_tabs_update ) {
4734 + uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
4735 + }
4736 + }
2468 4737
2469 - <?php
2470 - // if value empty set the default
2471 - if($value=='' && isset($field->default_value) && $field->default_value){
2472 - $value = $field->default_value;
2473 - }
2474 - $select_country_options = apply_filters('uwp_form_input_select_country',"{defaultCountry: '$value'}",$field, $value, $form_type);
2475 - ?>
4738 + if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
4739 + update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
4740 + } else {
4741 + update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
4742 + }
2476 4743
2477 - <input type="text" class="uwp_textfield" title="<?php echo $site_title; ?>" id="<?php echo $field->htmlvar_name;?>" />
2478 - <input type="hidden" id="<?php echo $field->htmlvar_name;?>_code" name="<?php echo $field->htmlvar_name;?>" />
4744 + $make_profile_private = uwp_can_make_profile_private();
4745 + if ( $make_profile_private ) {
4746 + $field_name = 'uwp_make_profile_private';
4747 + if ( isset( $_POST[ $field_name ] ) ) {
4748 + $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4749 + $user_id = get_current_user_id();
4750 + update_user_meta( $user_id, $field_name, $value );
4751 + }
4752 + }
2479 4753
2480 - <script>
2481 - jQuery("#<?php echo $field->htmlvar_name;?>").countrySelect(<?php echo $select_country_options;?>);
2482 - </script>
4754 + $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
4755 + $message = aui()->alert(
4756 + array(
4757 + 'type' => 'success',
4758 + 'content' => $message,
4759 + )
4760 + );
4761 + $uwp_notices[] = array( 'account' => $message );
2483 4762
4763 + }
4764 + }
2484 4765
2485 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2486 - <?php if ($field->is_required) { ?>
2487 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2488 - <?php } ?>
2489 - </div>
4766 + /**
4767 + * Get the ajax login form.
4768 + *
4769 + * @since 1.2.0
4770 + */
4771 + public function ajax_login_form() {
2490 4772
2491 - <?php
2492 - $html = ob_get_clean();
2493 - }
4773 + // add the modal error container
4774 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2494 4775
2495 - return $html;
2496 - }
4776 + $args = array(
4777 + 'form_title' => __( 'Login', 'userswp' ),
4778 + );
2497 4779
2498 - /**
2499 - * Prints the username link in "Edit Account" page
2500 - *
2501 - * @since 1.0.0
2502 - * @package userswp
2503 - *
2504 - * @param string $type Page type.
2505 - *
2506 - * @return void
2507 - */
2508 - public function uwp_display_username_in_account($type) {
2509 - if ($type == 'account') {
2510 - $user_id = get_current_user_id();
2511 - $user_info = get_userdata($user_id);
2512 - $display_name = $user_info->user_login;
2513 - ?>
2514 - <span class="uwp_account_page_username">
2515 - <a href="<?php echo uwp_build_profile_tab_url($user_id); ?>">( @<?php echo $display_name; ?> )</a>
2516 - </span>
2517 - <?php
4780 + // get the form
4781 + ob_start();
4782 + uwp_get_template( 'bootstrap/login.php', $args );
4783 + $form = ob_get_clean();
4784 +
4785 + // bs5
4786 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4787 + $form = aui_bs_convert_sd_output( $form );
2518 4788 }
2519 - }
4789 + // send ajax response
4790 + wp_send_json_success( $form );
4791 + }
2520 4792
4793 + /**
4794 + * Get the ajax register form.
4795 + *
4796 + * @since 1.2.0
4797 + */
4798 + public function ajax_register_form() {
2521 4799
2522 - /**
2523 - * Adds confirm password field in forms.
2524 - *
2525 - * @since 1.0.0
2526 - * @package userswp
2527 - *
2528 - * @param string $html Form field html
2529 - * @param object $field Field info.
2530 - * @param string $value Form field default value.
2531 - * @param string $form_type Form type
2532 - *
2533 - * @return string Modified form field html.
2534 - */
2535 - public function uwp_register_confirm_password_field($html, $field, $value, $form_type) {
2536 - if ($form_type == 'register') {
2537 - //confirm password field
2538 - $extra = array();
2539 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2540 - $extra = unserialize($field->extra_fields);
2541 - }
2542 - $enable_confirm_password_field = isset($extra['confirm_password']) ? $extra['confirm_password'] : '0';
2543 - if ($enable_confirm_password_field == '1') {
2544 - ob_start(); // Start buffering;
2545 - ?>
2546 - <div id="uwp_account_confirm_password_row"
2547 - class="<?php echo 'required_field';?> uwp_form_password_row uwp_clear">
4800 + // add the modal error container
4801 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2548 4802
2549 - <?php
2550 - $site_title = __("Confirm Password", 'userswp');
2551 - if (!is_admin()) { ?>
2552 - <label>
2553 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2554 - <?php echo '<span>*</span>'; ?>
2555 - </label>
2556 - <?php } ?>
4803 + global $wp_scripts;
4804 + if ( empty( $wp_scripts ) ) {
4805 + $wp_scripts = wp_scripts();
4806 + }
2557 4807
2558 - <input name="uwp_account_confirm_password"
2559 - class="uwp_textfield"
2560 - id="uwp_account_confirm_password"
2561 - placeholder="<?php echo $site_title; ?>"
2562 - value=""
2563 - title="<?php echo $site_title; ?>"
2564 - <?php echo 'required="required"'; ?>
2565 - type="password"
2566 - />
2567 - </div>
4808 + // do we need country code script in ajax?
4809 + $country_field = false;
4810 + $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
2568 4811
2569 - <?php
2570 - $confirm_html = ob_get_clean();
2571 - $html = $html.$confirm_html;
2572 - }
2573 - }
2574 - return $html;
2575 - }
4812 + if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
4813 + $form_id = (int)$_POST['form_id'];
4814 + } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
4815 + $form_id = reset( $lightbox_forms );
4816 + } else {
4817 + $form_id = 1;
4818 + }
2576 4819
2577 - /**
2578 - * Adds confirm email field in forms.
2579 - *
2580 - * @since 1.0.0
2581 - * @package userswp
2582 - *
2583 - * @param string $html Form field html
2584 - * @param object $field Field info.
2585 - * @param string $value Form field default value.
2586 - * @param string $form_type Form type
2587 - *
2588 - * @return string Modified form field html.
2589 - */
2590 - public function uwp_register_confirm_email_field($html, $field, $value, $form_type) {
2591 - if ($form_type == 'register') {
2592 - //confirm email field
2593 - $extra = array();
2594 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2595 - $extra = unserialize($field->extra_fields);
2596 - }
2597 - $enable_confirm_email_field = isset($extra['confirm_email']) ? $extra['confirm_email'] : '0';
2598 - if ($enable_confirm_email_field == '1') {
2599 - ob_start(); // Start buffering;
2600 - ?>
2601 - <div id="uwp_account_confirm_email_row"
2602 - class="<?php echo 'required_field';?> uwp_form_email_row uwp_clear">
4820 + $fields = get_register_form_fields( $form_id );
4821 + if ( ! empty( $fields ) ) {
4822 + foreach ( $fields as $field ) {
4823 + if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
4824 + $country_field = true;
4825 + }
4826 + }
4827 + }
2603 4828
2604 - <?php
2605 - $site_title = __("Confirm Email", 'userswp');
2606 - if (!is_admin()) { ?>
2607 - <label>
2608 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2609 - <?php echo '<span>*</span>'; ?>
2610 - </label>
2611 - <?php } ?>
4829 + ob_start();
2612 4830
2613 - <input name="uwp_account_confirm_email"
2614 - class="uwp_textfield"
2615 - id="uwp_account_confirm_email"
2616 - placeholder="<?php echo $site_title; ?>"
2617 - value=""
2618 - title="<?php echo $site_title; ?>"
2619 - <?php echo 'required="required"'; ?>
2620 - type="email"
2621 - />
2622 - </div>
4831 + // maybe add country code JS
4832 + if ( $country_field ) {
4833 + $country_data = uwp_get_country_data();
4834 + echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
4835 + echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
4836 + }
2623 4837
2624 - <?php
2625 - $confirm_html = ob_get_clean();
2626 - $html = $html.$confirm_html;
2627 - }
2628 - }
2629 - return $html;
2630 - }
4838 + $args = array( 'form_title' => '' );
4839 + if ( $form_id > 0 ) {
4840 + $args['id'] = $form_id;
4841 + }
2631 4842
4843 + $args['limit'] = $lightbox_forms;
2632 4844
2633 - /**
2634 - * Handles the privacy form submission.
2635 - *
2636 - * @since 1.0.0
2637 - * @package userswp
2638 - *
2639 - * @return void
2640 - */
2641 - public function uwp_privacy_submit_handler() {
2642 - if (isset($_POST['uwp_privacy_submit'])) {
2643 - if( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
2644 - return;
2645 - }
4845 + // get template
4846 + uwp_get_template( 'bootstrap/register.php', $args );
2646 4847
2647 - $extra_where = "AND is_public='2'";
2648 - $fields = get_account_form_fields($extra_where);
2649 - $fields = apply_filters('uwp_account_privacy_fields', $fields);
2650 - $user_id = get_current_user_id();
2651 - global $wpdb;
2652 - $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
4848 + // only show the JS if NOT doing a block render
4849 + if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
4850 + // load scripts
4851 + $wp_scripts->do_item( 'zxcvbn-async' );
4852 + $wp_scripts->do_item( 'wp-hooks' );
4853 + $wp_scripts->do_item( 'wp-i18n' );
4854 + $wp_scripts->do_item( 'password-strength-meter' );
4855 + ?>
4856 + <script>
4857 + // Password strength indicator script
4858 + jQuery(function ($) {
2653 4859
2654 - if ($fields) {
2655 - foreach ($fields as $field) {
2656 - $field_name = $field->htmlvar_name.'_privacy';
4860 + // Load the settings like WP does.
4861 + var first, s;
4862 + s = document.createElement('script');
4863 + s.src = _zxcvbnSettings.src;
4864 + s.type = 'text/javascript';
4865 + s.async = true;
4866 + first = document.getElementsByTagName('script')[0];
4867 + first.parentNode.insertBefore(s, first);
2657 4868
2658 - $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy FROM $meta_table WHERE user_id = %d", $user_id ) );
2659 - $field_value = strip_tags(esc_sql($_POST[$field_name]));
2660 - $value = '';
4869 + // Enable any pass inputs.
4870 + $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
4871 + function (event) {
4872 + var $form = $(this).closest('form');
4873 + if( ! $form.hasClass('uwp-login-form') ) {
4874 + uwp_checkPasswordStrength(
4875 + $('input[name=password]', $form), // First password field
4876 + $('input[name=confirm_password]', $form), // Second password field
4877 + $('#uwp-password-strength', $form), // Strength meter
4878 + $('input[type=submit]', $form), // Submit button
4879 + ['black', 'listed', 'word'] // Blacklisted words
4880 + );
4881 + }
4882 + }
4883 + );
4884 + });
4885 + </script>
4886 + <?php
4887 + }
4888 + $form = ob_get_clean();
2661 4889
2662 - if (!empty($user_meta_info->user_privacy)) {
2663 - $public_fields = explode(',', $user_meta_info->user_privacy);
2664 - if ($field_value == 'no') {
2665 - if (!in_array($field_name, $public_fields)) {
2666 - $public_fields[] = $field_name;
2667 - }
2668 - $value = implode(',', $public_fields);
2669 - } else {
2670 - if (($field_name = array_search($field_name, $public_fields)) !== false) {
2671 - unset($public_fields[$field_name]);
2672 - }
2673 - $value = implode(',', $public_fields);
2674 - }
2675 - } else {
2676 - if ($field_value == 'no') {
2677 - $public_fields = array($field_name);
2678 - $value = implode(',', $public_fields);
2679 - } else {
2680 - // For yes values no need to update since its a public field.
2681 - // We store only the private fields.
2682 - }
4890 + // bs5
4891 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4892 + $form = aui_bs_convert_sd_output( $form );
4893 + }
2683 4894
2684 - }
4895 + // send ajax response
4896 + wp_send_json_success( $form );
4897 + }
2685 4898
2686 - uwp_update_usermeta($user_id, 'user_privacy', $value);
2687 - }
2688 - }
4899 + /**
4900 + * Get the ajax forgot password form.
4901 + *
4902 + * @since 1.2.0
4903 + */
4904 + public function ajax_forgot_password_form() {
2689 4905
2690 - if (isset($_POST['uwp_hide_from_listing']) && 1 == $_POST['uwp_hide_from_listing']) {
2691 - update_user_meta($user_id, 'uwp_hide_from_listing', 1);
2692 - } else {
2693 - update_user_meta($user_id, 'uwp_hide_from_listing', 0);
2694 - }
4906 + // add the modal error container
4907 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2695 4908
2696 - $make_profile_private = uwp_can_make_profile_private();
2697 - if ($make_profile_private) {
2698 - $field_name = 'uwp_make_profile_private';
2699 - if (isset($_POST[$field_name])) {
2700 - $value = strip_tags(esc_sql($_POST[$field_name]));
2701 - $user_id = get_current_user_id();
2702 - update_user_meta($user_id, $field_name, $value);
2703 - }
2704 - }
4909 + // get the form
4910 + ob_start();
4911 + uwp_get_template( 'bootstrap/forgot.php' );
4912 + $form = ob_get_clean();
2705 4913
4914 + // bs5
4915 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4916 + $form = aui_bs_convert_sd_output( $form );
2706 4917 }
2707 - }
2708 4918
2709 -}
4919 + // send ajax response
4920 + wp_send_json_success( $form );
4921 + }
4922 +
4923 + /**
4924 + * Output the modal error container.
4925 + *
4926 + * @param string $type
4927 + *
4928 + * @since 1.2.0
4929 + */
4930 + public function modal_error_container( $type = '' ) {
4931 + echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
4932 + }
4933 +
4934 + public function form_custom_html( $html, $field, $value, $form_type ) {
4935 +
4936 + $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
4937 +
4938 + return $html;
4939 + }
4940 +}