PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.48
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.48
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
← All changes | includes/class-forms.php +4515 -2306 1.0.121.2.48 View file →
@@ -1,5 +1,6 @@
1 1 <?php
2 +
2 3 /**
3 4 * Form related functions
4 5 *
5 6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
@@ -8,2728 +9,4936 @@
8 9 * @author GeoDirectory Team <info@wpgeodirectory.com>
9 10 */
10 11 class UsersWP_Forms {
11 12
12 - protected $generated_password;
13 + protected $generated_password;
13 14
14 - /**
15 - * Initialize UsersWP notices.
16 - *
17 - * @since 1.0.0
18 - * @package userswp
19 - *
20 - * @return void
21 - */
22 - public function init_notices() {
23 - global $uwp_notices;
24 - $uwp_notices = array();
25 - }
15 + /**
16 + * Logs the error message.
17 + *
18 + * @param array|object|string $log Error message.
19 + *
20 + * @return void
21 + * @since 1.0.0
22 + * @package userswp
23 + *
24 + */
25 + public static function uwp_error_log( $log ) {
26 + uwp_error_log( $log );
27 + }
26 28
27 - /**
28 - * Handles all UsersWP forms.
29 - *
30 - * @since 1.0.0
31 - * @package userswp
32 - *
33 - * @return void
34 - */
35 - public function handler()
36 - {
37 - global $uwp_notices;
29 + /**
30 + * Initialize UsersWP notices.
31 + *
32 + * @return void
33 + * @package userswp
34 + *
35 + * @since 1.0.0
36 + */
37 + public function init_notices() {
38 + global $uwp_notices;
39 + $uwp_notices = array();
40 + }
38 41
39 - ob_start();
42 + /**
43 + * Handles all UsersWP forms.
44 + *
45 + * @return void
46 + * @package userswp
47 + *
48 + * @since 1.0.0
49 + */
50 + public function handler() {
51 + global $uwp_notices;
40 52
41 - $errors = null;
42 - $message = null;
43 - $redirect = false;
44 - $processed = false;
45 - $type = null;
53 + ob_start();
46 54
47 - $login_page_url = wp_login_url();
55 + $errors = null;
56 + $message = null;
57 + $redirect = false;
58 + $processed = false;
59 + $type = null;
48 60
49 - if (isset($_POST['uwp_register_nonce'])) {
50 - $auto_login = uwp_get_option('uwp_registration_action', false);
51 - $errors = $this->process_register($_POST, $_FILES);
52 - if (!is_wp_error($errors)) {
53 - $message = $errors;
61 + if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 + if ( ! is_wp_error( $errors ) ) {
64 + $redirect = $errors;
65 + }
66 + $message = __( 'Avatar cropped successfully.', 'userswp' );
67 + $processed = true;
68 + } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 + $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 + if ( ! is_wp_error( $errors ) ) {
71 + $redirect = $errors;
72 + }
73 + $message = __( 'Banner cropped successfully.', 'userswp' );
74 + $processed = true;
75 + } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 + $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 + if ( ! is_wp_error( $errors ) ) {
78 + $redirect = $errors;
79 + }
80 + $message = __( 'Avatar cropped successfully.', 'userswp' );
81 + $processed = true;
82 + } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 + $errors = $this->process_image_crop( $_POST, 'banner', true );
84 + if ( ! is_wp_error( $errors ) ) {
85 + $redirect = $errors;
86 + }
87 + $message = __( 'Banner cropped successfully.', 'userswp' );
88 + $processed = true;
89 + } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 + $errors = $this->process_image_reset( 'avatar' );
91 + if ( ! is_wp_error( $errors ) ) {
92 + $redirect = $errors;
93 + }
94 + $message = __( 'Avatar reset successfully.', 'userswp' );
95 + $processed = true;
96 + } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 + $errors = $this->process_image_reset( 'banner' );
98 + if ( ! is_wp_error( $errors ) ) {
99 + $redirect = $errors;
100 + }
101 + $message = __( 'Banner reset successfully.', 'userswp' );
102 + $processed = true;
103 + }
104 +
105 + if ( $processed ) {
106 +
107 + if ( is_wp_error( $errors ) ) {
108 + echo aui()->alert(
109 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 + 'type' => 'error',
111 + 'class' => 'text-center',
112 + 'content' => wp_kses_post( $errors->get_error_message() ),
113 + )
114 + );
115 + } elseif ( $redirect ) {
116 + wp_safe_redirect( $redirect );
117 + exit();
118 + } else {
119 + echo aui()->alert(
120 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 + 'type' => 'success',
122 + 'class' => 'text-center',
123 + 'content' => wp_kses_post( $message ),
124 + )
125 + );
126 + }
127 + }
128 +
129 + if ( $type ) {
130 + $uwp_notices[] = array( $type => ob_get_contents() );
131 + } else {
132 + $uwp_notices[] = ob_get_contents();
133 + }
134 +
135 + ob_end_clean();
136 + }
137 +
138 + /**
139 + * Processes avatar and banner uploads form submission.
140 + *
141 + * @param array $data Submitted $_POST data
142 + * @param array $files Submitted $_FILES data
143 + *
144 + * @return bool|WP_Error|string File url to crop.
145 + * @package userswp
146 + *
147 + * @since 1.0.0
148 + */
149 + public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
150 +
151 + $file_obj = new UsersWP_Files();
152 +
153 + $current_user_id = get_current_user_id();
154 + if ( ! $current_user_id ) {
155 + return false;
156 + }
157 +
158 + if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
159 + return false;
160 + }
161 +
162 + do_action( 'uwp_before_validate', $type );
163 +
164 + $result = $file_obj->validate_uploads( $files, $type );
165 +
166 + $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
167 +
168 + if ( is_wp_error( $result ) ) {
169 + return $result;
170 + }
171 +
172 + $profile_url = uwp_build_profile_tab_url( $current_user_id );
173 +
174 + $url = add_query_arg(
175 + array(
176 + 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
177 + 'type' => $type,
178 + ),
179 + $profile_url
180 + );
181 +
182 + return $url;
183 + }
184 +
185 + /**
186 + * Processes avatar and banner uploads image crop.
187 + *
188 + * @param array $data Submitted $_POST data
189 + * @param string $type Image type. Default 'avatar'.
190 + * @param bool $unlink_prev_img True to remove previous image. Default false;
191 + *
192 + * @return bool|WP_Error|string Profile url.
193 + * @since 1.0.12 New param $unlink_prev_img introduced.
194 + * @package userswp
195 + *
196 + * @since 1.0.0
197 + */
198 + public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
199 + global $wpdb;
200 + if ( ! is_user_logged_in() ) {
201 + return false;
202 + }
203 +
204 + if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 + return;
206 + }
207 +
208 + // If is current user's profile (profile.php)
209 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
210 + $user_id = get_current_user_id();
211 + // If is another user's profile page
212 + } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
213 + $user_id = absint( $_GET['user_id'] );
214 + // Otherwise something is wrong.
215 + } else {
216 + $user_id = get_current_user_id();
217 + }
218 +
219 + // Ensure we have a valid URL with an allowed meme type.
220 + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 + $filetype = wp_check_filetype( $image_url );
222 +
223 + $errors = new WP_Error();
224 + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 + }
227 +
228 + if ( $errors->has_errors() ) {
229 + return $errors;
230 + }
231 +
232 + // Retrieve current thumbnail.
233 + $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
234 + $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
235 + $thumb_postfix = '_uwp_' . $type . '_thumb';
236 +
237 + if ( $image_url ) {
238 + if ( $type == 'avatar' ) {
239 + $avatar_size = uwp_get_upload_image_size();
240 + $full_width = $avatar_size['width'];
241 + } else {
242 + $banner_size = uwp_get_upload_image_size( 'banner' );
243 + $full_width = $banner_size['width'];
244 + }
245 +
246 + add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
247 + $uploads = wp_upload_dir();
248 + remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
249 + $upload_url = $uploads['baseurl'];
250 + $upload_path = $uploads['basedir'];
251 + $image_path = str_replace( $upload_url, $upload_path, $image_url );
252 + $ext = $filetype['ext']; // to get extension
253 + $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
254 + $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
255 + $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
256 + //Get the new coordinates to crop the image.
257 + $x = $data['x'];
258 + $y = $data['y'];
259 + $w = $data['w'];
260 + $h = $data['h'];
261 + //Scale the image based on cropped width setting
262 + $scale = $full_width / $w;
263 + //$scale = 1; // no scaling
264 +
265 + // check we are not editing another user file
266 + $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
267 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
268 + $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
269 +
270 + // if file already exists then we should not be cropping it.
271 + if ( $file_exists ) {
272 + wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
273 + }
274 +
275 + $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
276 + $cropped = str_replace( $upload_path, $upload_url, $cropped );
277 +
278 + // Remove previous avatar/banner
279 + $unlink_img = '';
280 + if ( $unlink_prev_img && $current_thumbnail ) {
281 + $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
282 + }
283 +
284 + // remove the uploads path for easy migrations
285 + $cropped = str_replace( $upload_url, '', $cropped );
286 + if ( $type == 'avatar' ) {
287 + uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
288 + } else {
289 + uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
290 + }
291 +
292 + if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
293 + @unlink( $unlink_img );
294 + $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
295 + if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
296 + @unlink( $unlink_ori_img );
297 + }
298 + }
299 + }
300 +
301 + if ( is_admin() ) {
302 + if ( $user_id == get_current_user_id() ) {
303 + $redirect_url = admin_url( 'profile.php' );
304 + } else {
305 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
306 + }
307 + } elseif ( uwp_current_page_url() ) {
308 + $redirect_url = uwp_current_page_url();
309 + } else {
310 + $redirect_url = uwp_build_profile_tab_url( $user_id );
311 + }
312 +
313 + return $redirect_url;
314 + }
315 +
316 + /**
317 + * Normalizes a URL.
318 + *
319 + */
320 + public function normalize_url( $url ) {
321 +
322 + // Normalize.
323 + $url = wp_normalize_path( $url );
324 +
325 + // Remove query vars.
326 + $url = strtok( $url, '?' );
327 +
328 + // Split.
329 + $url = explode( '/', $url );
330 +
331 + // Clean.
332 + $url = array_diff( $url, array( '..', '.' ) );
333 +
334 + // Rejoin and return.
335 + return implode( '/', $url );
336 + }
337 +
338 + /**
339 + * Processes avatar and banner image reset.
340 + *
341 + * @param string $type Image type. Default 'avatar'.
342 + *
343 + * @return bool|WP_Error|string Profile url.
344 + * @package userswp
345 + *
346 + */
347 + public function process_image_reset( $type ) {
348 + if ( ! is_user_logged_in() ) {
349 + return false;
350 + }
351 +
352 + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 + return;
354 + }
355 +
356 + if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
357 + $user_id = get_current_user_id();
358 + // If is another user's profile page
359 + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
360 + $user_id = absint( $_GET['user_id'] );
361 + // Otherwise something is wrong.
362 + } else {
363 + $user_id = get_current_user_id();
364 + }
365 +
366 + $errors = new WP_Error();
367 + if ( empty( $user_id ) ) {
368 + $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
369 + }
370 +
371 + $error_code = $errors->get_error_code();
372 + if ( ! empty( $error_code ) ) {
373 + return $errors;
374 + }
375 +
376 + if ( $type == 'avatar' ) {
377 + uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
378 + } elseif ( $type == 'banner' ) {
379 + uwp_update_usermeta( $user_id, 'banner_thumb', '' );
380 + } else {
381 + // Do nothing
382 + }
383 +
384 + if ( is_admin() ) {
385 + if ( $user_id == get_current_user_id() ) {
386 + $redirect_url = admin_url( 'profile.php' );
387 + } else {
388 + $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
389 + }
390 + } elseif ( uwp_current_page_url() ) {
391 + $redirect_url = uwp_current_page_url();
392 + } else {
393 + $redirect_url = uwp_build_profile_tab_url( $user_id );
394 + }
395 +
396 + return $redirect_url;
397 + }
398 +
399 + /**
400 + * Displays links in a dropdown
401 + *
402 + * @param $options
403 + *
404 + * @package userswp
405 + *
406 + * @since 1.0.0
407 + */
408 + public function output_dashboard_links( $options ) {
409 + if ( ! empty( $options ) ) {
410 + $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
411 + echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
412 + $this->output_options( $options );
413 + echo '</select>';
414 + }
415 + }
416 +
417 + /**
418 + * Displays options for the dashboard links
419 + *
420 + * @param $options
421 + *
422 + * @package userswp
423 + *
424 + * @since 1.0.0
425 + */
426 + public function output_options( $options ) {
427 + if ( ! empty( $options ) ) {
428 + foreach ( $options as $key => $link ) {
429 +
430 + if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
431 + $this->output_options( $link );
432 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
433 + echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
434 + } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
435 + echo '</optgroup>';
436 + } elseif ( ! empty( $link['text'] ) ) {
437 + echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
438 + echo esc_attr__( $link['text'], 'userswp' );
439 + echo '</option>';
440 + }
441 + }
442 + }
443 + }
444 +
445 + /**
446 + * Displays UsersWP notices in forms.
447 + *
448 + * @param string $type Form type
449 + *
450 + * @return void
451 + * @since 1.0.0
452 + * @package userswp
453 + *
454 + */
455 + public function display_notices( $type ) {
456 + global $uwp_notices;
457 +
458 + if ( is_array( $uwp_notices ) ) {
459 + foreach ( $uwp_notices as $notice ) {
460 +
461 + // If the notification is type specific then only output on that type
462 + if ( is_array( $notice ) ) {
463 + foreach ( $notice as $key => $val ) {
464 + if ( $key == $type ) {
465 + echo wp_kses_post( $val );
466 + }
467 + }
468 + } elseif ( ! empty( $notice ) ) {
469 + echo wp_kses_post( $notice );
470 + }
54 471 }
55 - if ($auto_login == 'auto_approve_login') {
56 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
57 - if(isset( $_REQUEST['redirect_to'] )){
58 - $reg_redirect_to = esc_url($_REQUEST['redirect_to']);
59 - } elseif ( isset($reg_redirect_page_id) && (int)$reg_redirect_page_id > 0) {
60 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
61 - } else {
62 - $reg_redirect_to = home_url('/');
63 - }
64 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
65 - }
66 - $processed = true;
67 - $type = 'register';
68 - } elseif (isset($_POST['uwp_login_nonce'])) {
69 - $errors = $this->process_login($_POST);
70 - $redirect_page_id = uwp_get_option('login_redirect_to', -1);
71 - if (isset($redirect_page_id) && (int)$redirect_page_id > 0) {
72 - $redirect_to = get_permalink($redirect_page_id);
73 - } elseif(isset( $_REQUEST['redirect_to'] )){
74 - $redirect_to = esc_url($_REQUEST['redirect_to']);
75 - } else {
76 - $redirect_to = home_url('/');
77 - }
78 - $redirect = apply_filters('uwp_login_redirect', $redirect_to);
79 - $processed = true;
80 - $type = 'login';
81 - } elseif (isset($_POST['uwp_forgot_nonce'])) {
82 - $errors = $this->process_forgot($_POST);
83 - $message = __('Please check your email.', 'userswp');
84 - $processed = true;
85 - } elseif (isset($_POST['uwp_change_nonce'])) {
86 - $errors = $this->process_change($_POST);
87 - $message = __('Password changed successfully', 'userswp');
88 - $processed = true;
89 - } elseif (isset($_POST['uwp_reset_submit'])) {
90 - $errors = $this->process_reset($_POST);
91 - $message = sprintf(__('Password updated successfully. Please <a href="%s">login</a> with your new password', 'userswp'), $login_page_url);
92 - $processed = true;
93 - } elseif (isset($_POST['uwp_account_nonce'])) {
94 - $errors = $this->process_account($_POST, $_FILES);
95 - $message = __('Account updated successfully.', 'userswp');
96 - $processed = true;
97 - } elseif (isset($_POST['uwp_avatar_submit'])) {
98 - $errors = $this->process_upload_submit($_POST, $_FILES, 'avatar');
99 - if (!is_wp_error($errors)) {
100 - $redirect = $errors;
101 - }
102 - $message = __('Avatar cropped successfully.', 'userswp');
103 - $processed = true;
104 - } elseif (isset($_POST['uwp_banner_submit'])) {
105 - $errors = $this->process_upload_submit($_POST, $_FILES, 'banner');
106 - if (!is_wp_error($errors)) {
107 - $redirect = $errors;
108 - }
109 - $message = __('Banner cropped successfully.', 'userswp');
110 - $processed = true;
111 - } elseif (isset($_POST['uwp_avatar_crop'])) {
112 - $errors = $this->process_image_crop($_POST, 'avatar', true);
113 - if (!is_wp_error($errors)) {
114 - $redirect = $errors;
115 - }
116 - $message = __('Avatar cropped successfully.', 'userswp');
117 - $processed = true;
118 - } elseif (isset($_POST['uwp_banner_crop'])) {
119 - $errors = $this->process_image_crop($_POST, 'banner', true);
120 - if (!is_wp_error($errors)) {
121 - $redirect = $errors;
122 - }
123 - $message = __('Banner cropped successfully.', 'userswp');
124 - $processed = true;
125 472 }
126 473
127 - if ($processed) {
128 - if (is_wp_error($errors)) {
129 - echo '<div class="uwp-alert-error text-center">';
130 - echo $errors->get_error_message();
131 - echo '</div>';
132 - } else {
133 - if ($redirect) {
134 - wp_safe_redirect($redirect);
135 - exit();
136 - } else {
137 - echo '<div class="uwp-alert-success text-center">';
138 - echo $message;
139 - echo '</div>';
140 - }
141 - }
142 - }
474 + if ( $type == 'change' ) {
475 + $user_id = get_current_user_id();
476 + $password_nag = get_user_option( 'default_password_nag', $user_id );
143 477
144 - if($type){
145 - $uwp_notices[] = array($type => ob_get_contents());
146 - }else{
147 - $uwp_notices[] = ob_get_contents();
148 - }
478 + if ( $password_nag ) {
479 + $change_page = uwp_get_page_id( 'change_page', false );
480 + $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
149 481
482 + if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
483 + delete_user_meta( $user_id, 'default_password_nag' );
484 + $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
485 + echo aui()->alert(
486 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
487 + 'class' => 'text-center',
488 + 'type' => 'success',
489 + 'content' => wp_kses_post( $message ),
490 + )
491 + );
492 + } else {
493 + $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
494 + echo aui()->alert(
495 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
496 + 'class' => 'text-center',
497 + 'type' => 'warning',
498 + 'content' => wp_kses_post( $message ),
499 + )
500 + );
501 + }
502 + }
503 + }
504 + }
150 505
151 - ob_end_clean();
506 + /**
507 + * Processes register form submission.
508 + *
509 + * @since 1.0.0
510 + * @package userswp
511 + *
512 + */
513 + public function process_register() {
152 514
153 - }
515 + $data = $_POST;
154 516
155 - /**
156 - * Displays UsersWP notices in forms.
157 - *
158 - * @since 1.0.0
159 - * @package userswp
160 - *
161 - * @param string $type Form type
162 - *
163 - * @return void
164 - */
165 - public function display_notices($type) {
166 - global $uwp_notices;
517 + if ( ! isset( $data['uwp_register_nonce'] ) ) {
518 + return;
519 + }
167 520
168 - if (is_array($uwp_notices)) {
169 - foreach ($uwp_notices as $notice) {
521 + global $uwp_notices;
170 522
171 - // If the notification is type specific then only output on that type
172 - if(is_array($notice)){
173 - foreach($notice as $key => $val){
174 - if( $key == $type ){ echo $val; }
175 - }
176 - }else{
177 - if (!empty($notice)) {
178 - echo $notice;
179 - }
180 - }
523 + if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
524 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
525 + }
181 526
182 - }
527 + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
528 + $message = aui()->alert(
529 + array(
530 + 'type' => 'error',
531 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
532 + )
533 + );
534 + if ( wp_doing_ajax() ) {
535 + wp_send_json_error( array( 'message' => $message ) );
536 + } else {
537 + $uwp_notices[] = array( 'register' => $message );
183 538
184 - }
539 + return;
540 + }
541 + }
185 542
186 - if ($type == 'change') {
187 - $user_id = get_current_user_id();
188 - $password_nag = get_user_option('default_password_nag', $user_id);
543 + $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
544 + if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
545 + $message = aui()->alert(
546 + array(
547 + 'type' => 'error',
548 + 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
549 + )
550 + );
551 + if ( wp_doing_ajax() ) {
552 + wp_send_json_error( array( 'message' => $message ) );
553 + } else {
554 + $uwp_notices[] = array( 'register' => $message );
189 555
190 - if ($password_nag) {
191 - $change_page = uwp_get_option('change_page', false);
192 - $remove_nag_url = add_query_arg('uwp_remove_nag', 'yes', get_permalink($change_page));
556 + return;
557 + }
558 + }
193 559
194 - if (isset($_GET['uwp_remove_nag']) && $_GET['uwp_remove_nag'] == 'yes') {
195 - delete_user_meta( $user_id, 'default_password_nag' );
196 - $message = sprintf(__('We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp'), home_url('/'));
197 - echo '<div class="uwp-alert-success text-center">';
198 - echo $message;
199 - echo '</div>';
200 - } else {
201 - $message = sprintf(__('<strong>Warning</strong>: You seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp'), $remove_nag_url);
202 - echo '<div class="uwp-alert-warning text-center">';
203 - echo $message;
204 - echo '</div>';
205 - }
206 - }
207 - }
208 - }
560 + if ( ! get_option( 'users_can_register' ) ) {
561 + $message = aui()->alert(
562 + array(
563 + 'type' => 'error',
564 + 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
565 + )
566 + );
567 + if ( wp_doing_ajax() ) {
568 + wp_send_json_error( array( 'message' => $message ) );
569 + } else {
570 + $uwp_notices[] = array( 'register' => $message );
209 571
210 - /**
211 - * Processes register form submission.
212 - *
213 - * @since 1.0.0
214 - * @package userswp
215 - *
216 - * @param array $data Submitted $_POST data
217 - * @param array $files Submitted $_FILES data
218 - *
219 - * @return bool|WP_Error|string
220 - */
221 - public function process_register($data = array(), $files = array()) {
572 + return;
573 + }
574 + }
222 575
223 - $errors = new WP_Error();
224 - $file_obj = new UsersWP_Files();
576 + $files = $_FILES;
577 + $errors = new WP_Error();
578 + $file_obj = new UsersWP_Files();
225 579
226 - if( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
227 - return false;
228 - }
580 + do_action( 'uwp_before_validate', 'register' );
229 581
230 - if (!get_option('users_can_register')) {
231 - $errors->add('register_disabled', __('<strong>ERROR</strong>: User registration is currently not allowed.', 'userswp'));
232 - return $errors;
233 - }
582 + $result = uwp_validate_fields( $data, 'register' );
234 583
235 - $reg_terms_page_id = uwp_get_option('register_terms_page', '');
236 - $reg_terms_page_id = apply_filters('uwp_reg_terms_page_id', $reg_terms_page_id);
237 - if (!empty($reg_terms_page_id)) {
238 - if (!isset($data['agree_terms']) || $data['agree_terms'] != 'yes') {
239 - $errors->add('accept_tos', __('<strong>ERROR</strong>: You must accept our terms and conditions.', 'userswp'));
240 - return $errors;
241 - }
242 - }
584 + $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
243 585
244 - do_action('uwp_before_validate', 'register');
586 + if ( is_wp_error( $result ) ) {
587 + $message = aui()->alert(
588 + array(
589 + 'type' => 'error',
590 + 'content' => $result->get_error_message(),
591 + )
592 + );
593 + if ( wp_doing_ajax() ) {
594 + wp_send_json_error( array( 'message' => $message ) );
595 + } else {
596 + $uwp_notices[] = array( 'register' => $message );
245 597
246 - $result = uwp_validate_fields($data, 'register');
247 -
248 - $result = apply_filters('uwp_validate_result', $result, 'register', $data);
598 + return;
599 + }
600 + }
249 601
250 - if (is_wp_error($result)) {
251 - return $result;
252 - }
602 + $uploads_result = $file_obj->validate_uploads( $files, 'register' );
253 603
254 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'register');
604 + if ( is_wp_error( $uploads_result ) ) {
605 + $message = aui()->alert(
606 + array(
607 + 'type' => 'error',
608 + 'content' => $uploads_result->get_error_message(),
609 + )
610 + );
611 + if ( wp_doing_ajax() ) {
612 + wp_send_json_error( array( 'message' => $message ) );
613 + } else {
614 + $uwp_notices[] = array( 'register' => $message );
255 615
256 - if (is_wp_error($uploads_result)) {
257 - return $uploads_result;
258 - }
616 + return;
617 + }
618 + }
259 619
260 - do_action('uwp_after_validate', 'register');
620 + do_action( 'uwp_after_validate', $result, 'register', $data );
261 621
262 - $result = array_merge( $result, $uploads_result );
622 + $result = array_merge( $result, $uploads_result );
263 623
264 - $error_code = $errors->get_error_code();
265 - if (!empty($error_code)) {
266 - return $errors;
267 - }
624 + if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
625 + $password = $result['password'];
626 + $generated_password = false;
627 + } else {
628 + $password = wp_generate_password();
629 + $this->generated_password = $password;
630 + $generated_password = true;
631 + }
268 632
269 - if (isset($result['password']) && !empty($result['password'])) {
270 - $password = $result['password'];
271 - $generated_password = false;
272 - } else {
273 - $password = wp_generate_password();
274 - $this->generated_password = $password;
275 - $generated_password = true;
276 - }
633 + $first_name = '';
634 + if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
635 + $first_name = $result['first_name'];
636 + }
277 637
278 - $first_name = "";
279 - if (isset($result['uwp_account_first_name']) && !empty($result['uwp_account_first_name'])) {
280 - $first_name = $result['uwp_account_first_name'];
281 - }
638 + $last_name = '';
639 + if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
640 + $last_name = $result['last_name'];
641 + }
282 642
283 - $last_name = "";
284 - if (isset($result['uwp_account_last_name']) && !empty($result['uwp_account_last_name'])) {
285 - $last_name = $result['uwp_account_last_name'];
286 - }
643 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
644 + $display_name = $result['display_name'];
645 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
646 + $display_name = $first_name . ' ' . $last_name;
647 + } else {
648 + $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
649 + }
287 650
288 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
289 - $display_name = $result['uwp_account_display_name'];
290 - } else {
291 - if (!empty($first_name) || !empty($last_name)) {
292 - $display_name = $first_name . ' ' . $last_name;
293 - } else {
294 - $display_name = $result['uwp_account_username'];
295 - }
296 - }
651 + $user_url = '';
652 + if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
653 + $user_url = esc_url_raw( $result['user_url'] );
654 + }
297 655
298 - $description = "";
299 - if (isset($result['uwp_account_bio']) && !empty($result['uwp_account_bio'])) {
300 - $description = $result['uwp_account_bio'];
301 - }
656 + $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
657 + $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
302 658
659 + if ( empty( $user_login ) ) {
660 + $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
661 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
662 + $new_user_login = strstr( $email, '@', true );
663 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
664 + $user_login = sanitize_user( $new_user_login, true );
665 + }
666 + if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
667 + $user_append_text = rand( 10, 1000 );
668 + $user_login = sanitize_user( $new_user_login . $user_append_text, true );
669 + }
303 670
304 - $args = array(
305 - 'user_login' => $result['uwp_account_username'],
306 - 'user_email' => $result['uwp_account_email'],
307 - 'user_pass' => $password,
308 - 'display_name' => $display_name,
309 - 'first_name' => $first_name,
310 - 'last_name' => $last_name,
311 - 'description' => $description
312 - );
671 + if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
672 + $user_login = $email;
673 + }
674 + }
675 + } elseif ( ! validate_username( $user_login ) ) {
676 + $message = aui()->alert(
677 + array(
678 + 'type' => 'error',
679 + 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
680 + )
681 + );
682 + if ( wp_doing_ajax() ) {
683 + wp_send_json_error( array( 'message' => $message ) );
684 + } else {
685 + $uwp_notices[] = array( 'register' => $message );
313 686
314 - $user_id = wp_insert_user( $args );
687 + return;
688 + }
689 + }
315 690
316 - if (!$user_id) {
317 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
318 - return $errors;
319 - }
691 + $args = array(
692 + 'user_login' => sanitize_user( $user_login ),
693 + 'user_email' => sanitize_email( $email ),
694 + 'user_pass' => $password,
695 + 'display_name' => sanitize_text_field( $display_name ),
696 + 'first_name' => esc_attr( $first_name ),
697 + 'last_name' => esc_attr( $last_name ),
698 + 'user_url' => esc_url_raw( $user_url ),
699 + );
320 700
321 - $result = apply_filters('uwp_before_extra_fields_save', $result, 'register', $user_id);
701 + $form_id = 1;
322 702
323 - $save_result = $this->uwp_save_user_extra_fields($user_id, $result, 'register');
703 + if ( ! empty( $data['uwp_register_form_id'] ) ) {
704 + $form_id = (int) $data['uwp_register_form_id'];
705 + }
324 706
325 - $save_result = apply_filters('uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id);
707 + // Set user role by form.
708 + $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
326 709
327 - if (is_wp_error($save_result)) {
328 - return $save_result;
329 - }
710 + if ( ! empty( $user_role ) ) {
711 + $user_roles = uwp_get_user_roles();
712 + $chosen_role = strtolower( $user_role );
330 713
331 - if (!$save_result) {
332 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
333 - }
714 + if ( ! empty( $user_roles ) ) {
715 + $wp_roles = wp_roles();
334 716
335 - $error_code = $errors->get_error_code();
336 - if (!empty($error_code)) {
337 - return $errors;
338 - }
717 + if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
718 + $args['role'] = $chosen_role;
719 + }
720 + }
721 + }
339 722
340 - do_action('uwp_after_custom_fields_save', 'register', $data, $result, $user_id);
723 + $user_id = wp_insert_user( $args );
341 724
342 - $reg_action = uwp_get_option('uwp_registration_action', false);
725 + if ( is_wp_error( $user_id ) ) {
726 + $message = aui()->alert(
727 + array(
728 + 'type' => 'error',
729 + 'content' => $user_id->get_error_message(),
730 + )
731 + );
732 + if ( wp_doing_ajax() ) {
733 + wp_send_json_error( array( 'message' => $message ) );
734 + } else {
735 + $uwp_notices[] = array( 'register' => $message );
343 736
344 - if ($reg_action == 'require_email_activation' && !$generated_password) {
737 + return;
738 + }
739 + }
345 740
346 - $email = new UsersWP_Mails();
347 - $send_result = $email->send( 'activate', $user_id );
741 + $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
348 742
349 - if (!$send_result) {
350 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
351 - }
352 - } else {
353 - $email = new UsersWP_Mails();
354 - $send_result = $email->send( 'register', $user_id );
743 + // Save user form id.
744 + if ( ! empty( $data['uwp_register_form_id'] ) ) {
745 + update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
746 + }
355 747
356 - if (!$send_result) {
357 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
358 - }
359 - }
748 + $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
360 749
361 - if ($reg_action != 'require_admin_review') {
362 - $register_admin_notify = uwp_get_option('register_admin_notify', '');
363 - if ($register_admin_notify == '1') {
364 - $admin_register_send_result = $email->send_admin_email('register_admin', $user_id);
365 - if (is_wp_error($admin_register_send_result)) {
366 - return $admin_register_send_result;
750 + $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
751 +
752 + if ( is_wp_error( $save_result ) ) {
753 + $message = aui()->alert(
754 + array(
755 + 'type' => 'error',
756 + 'content' => $save_result->get_error_message(),
757 + )
758 + );
759 + if ( wp_doing_ajax() ) {
760 + wp_send_json_error( array( 'message' => $message ) );
761 + } else {
762 + $uwp_notices[] = array( 'register' => $message );
763 +
764 + return;
765 + }
766 + }
767 +
768 + if ( ! $save_result ) {
769 + $message = aui()->alert(
770 + array(
771 + 'type' => 'error',
772 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
773 + )
774 + );
775 + if ( wp_doing_ajax() ) {
776 + wp_send_json_error( array( 'message' => $message ) );
777 + } else {
778 + $uwp_notices[] = array( 'register' => $message );
779 +
780 + return;
781 + }
782 + }
783 +
784 + //updating bio field after saving extra fields to reflect the points in mycred add on.
785 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
786 + $args = array(
787 + 'ID' => $user_id,
788 + 'description' => $result['bio'],
789 + );
790 + wp_update_user( $args );
791 + }
792 +
793 + do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
794 +
795 + // Unset post data to empty the form on submit
796 + $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
797 + foreach ( $data as $key => $value ) {
798 + if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
799 + unset( $_POST[ $key ] );
800 + }
801 + }
802 +
803 + $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
804 + if ( ! $reg_action ) {
805 + $reg_action = uwp_get_option( 'uwp_registration_action', false );
806 + }
807 +
808 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
809 +
810 + if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
811 +
812 + $user_data = get_userdata( $user_id );
813 + $activation_link = uwp_get_activation_link( $user_id );
814 +
815 + $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
816 +
817 + $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
818 +
819 + $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
820 +
821 + $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
822 +
823 + $email_vars = array(
824 + 'user_id' => $user_id,
825 + 'login_details' => $activate_message,
826 + 'activation_link' => $activation_link,
827 + );
828 +
829 + UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
830 +
831 + } elseif ( $reg_action != 'require_admin_review' ) {
832 +
833 + $user_data = get_userdata( $user_id );
834 +
835 + if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
836 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
837 + update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
838 + }
839 + $message_pass = $this->generated_password;
840 + $this->generated_password = false;
841 + } else {
842 + $message_pass = __( 'Password you entered during registration.', 'userswp' );
843 + }
844 +
845 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
846 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
847 + <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
848 +
849 + $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
850 +
851 + $email_vars = array(
852 + 'user_id' => $user_id,
853 + 'login_details' => $message,
854 + 'form_fields' => $form_fields,
855 + );
856 +
857 + UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
858 + }
859 +
860 + $error_code = $errors->get_error_code();
861 + if ( ! empty( $error_code ) ) {
862 + $message = aui()->alert(
863 + array(
864 + 'type' => 'error',
865 + 'content' => $result->get_error_message(),
866 + )
867 + );
868 + if ( wp_doing_ajax() ) {
869 + wp_send_json_error( array( 'message' => $message ) );
870 + } else {
871 + $uwp_notices[] = array( 'register' => $message );
872 + return;
873 + }
874 + }
875 +
876 + if ( $reg_action != 'require_admin_review' ) {
877 +
878 + $user_data = get_userdata( $user_id );
879 + $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
880 + <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
881 + <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
882 + <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
883 + <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
884 +
885 + $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
886 +
887 + $email_vars = array(
888 + 'user_id' => $user_id,
889 + 'extras' => $extras,
890 + 'form_fields' => $form_fields,
891 + );
892 +
893 + UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
894 +
895 + }
896 +
897 + if ( $reg_action == 'auto_approve_login' ) {
898 + $res = wp_signon(
899 + array(
900 + 'user_login' => $user_login,
901 + 'user_password' => $password,
902 + 'remember' => false,
903 + )
904 + );
905 +
906 + if ( is_wp_error( $res ) ) {
907 + $message = aui()->alert(
908 + array(
909 + 'type' => 'error',
910 + 'content' => $res->get_error_message(),
911 + )
912 + );
913 +
914 + if ( wp_doing_ajax() ) {
915 + wp_send_json_error( array( 'message' => $message ) );
916 + } else {
917 + $uwp_notices[] = array( 'register' => $message );
918 + }
919 + } else {
920 + $redirect_to = $this->get_register_redirect_url( $data, $user_id );
921 + do_action( 'uwp_after_process_register', $result, $user_id );
922 +
923 + if ( wp_doing_ajax() ) {
924 + $message = aui()->alert(
925 + array(
926 + 'type' => 'success',
927 + 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
928 + )
929 + );
930 + $response = array(
931 + 'message' => $message,
932 + 'redirect' => $redirect_to,
933 + );
934 + wp_send_json_success( $response );
935 + } else {
936 + wp_safe_redirect( $redirect_to );
937 + }
938 + exit();
939 + }
940 + } else {
941 + if ( $reg_action == 'require_email_activation' ) {
942 + $resend_link = uwp_get_register_page_url();
943 + $resend_link = add_query_arg(
944 + array(
945 + 'user_id' => $user_id,
946 + 'action' => 'uwp_resend',
947 + '_nonce' => wp_create_nonce( 'uwp_resend' ),
948 + ),
949 + $resend_link
950 + );
951 +
952 + $message = aui()->alert(
953 + array(
954 + 'type' => 'success',
955 + 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
956 + )
957 + );
958 +
959 + } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
960 +
961 + update_user_meta( $user_id, 'uwp_mod', '1' );
962 +
963 + do_action( 'uwp_require_admin_review', $user_id, $result );
964 +
965 + $message = aui()->alert(
966 + array(
967 + 'type' => 'success',
968 + 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
969 + )
970 + );
971 + } else {
972 +
973 + $login_page_url = wp_login_url();
974 +
975 + if ( $generated_password ) {
976 + $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
977 + } else {
978 + $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
979 + }
980 +
981 + $message = aui()->alert(
982 + array(
983 + 'type' => 'success',
984 + 'content' => $msg,
985 + )
986 + );
987 + }
988 +
989 + do_action( 'uwp_after_process_register', $result, $user_id );
990 +
991 + if ( wp_doing_ajax() ) {
992 + wp_send_json_success( array( 'message' => $message ) );
993 + } else {
994 + $uwp_notices[] = array( 'register' => $message );
995 + }
996 + }
997 +
998 + if ( wp_doing_ajax() ) {
999 + wp_send_json_error();
1000 + } // if we got this far there is a problem
1001 + }
1002 +
1003 + /**
1004 + * Saves UsersWP related user custom fields.
1005 + *
1006 + * @param int $user_id User ID.
1007 + * @param array $data Result array.
1008 + * @param string $type Form type.
1009 + *
1010 + * @return bool True when success. False when failure.
1011 + * @since 1.0.0
1012 + * @package userswp
1013 + *
1014 + */
1015 + public function save_user_extra_fields( $user_id, $data, $type ) {
1016 +
1017 + if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1018 + return false;
1019 + }
1020 +
1021 + // custom user fields not applicable for login and forgot
1022 + if ( $type == 'login' || $type == 'forgot' ) {
1023 + return true;
1024 + }
1025 +
1026 + if ( $type == 'account' || $type == 'register' ) {
1027 + if ( isset( $data['password'] ) ) {
1028 + unset( $data['password'] );
1029 + }
1030 + }
1031 +
1032 + if ( $type == 'register' ) {
1033 + if ( isset( $data['username'] ) ) {
1034 + unset( $data['username'] );
1035 + }
1036 + if ( isset( $data['email'] ) ) {
1037 + unset( $data['email'] );
1038 + }
1039 + }
1040 +
1041 + if ( empty( $data ) ) {
1042 + // no extra fields. so just return
1043 + return true;
1044 + } else {
1045 + foreach ( $data as $key => $value ) {
1046 + if ( 'uwp_language' == $key ) {
1047 + update_user_meta( $user_id, 'locale', $value );
1048 + }
1049 + uwp_update_usermeta( $user_id, $key, $value );
1050 + }
1051 +
1052 + return true;
1053 + }
1054 + }
1055 +
1056 + public function get_register_redirect_url( $data, $user ) {
1057 + if ( is_int( $user ) ) {
1058 + $user = get_userdata( $user );
1059 + }
1060 +
1061 + $redirect_page_id = $custom_url = '';
1062 + if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1063 + $form_id = (int) $data['uwp_register_form_id'];
1064 + $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1065 + $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1066 + }
1067 +
1068 + if ( ! $redirect_page_id ) {
1069 + $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1070 + $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1071 + }
1072 +
1073 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1074 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1075 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1076 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1077 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1078 + if ( uwp_is_wpml() ) {
1079 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1080 + if ( ! empty( $wpml_page_id ) ) {
1081 + $redirect_page_id = $wpml_page_id;
1082 + }
1083 + }
1084 + $redirect_to = get_permalink( $redirect_page_id );
1085 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1086 + $redirect_to = esc_url( wp_get_referer() );
1087 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1088 + $redirect_to = $custom_url;
1089 + } else {
1090 + if ( $user && $user->has_cap( 'manage_options' ) ) {
1091 + $redirect_to = admin_url();
1092 + } else {
1093 + $redirect_to = home_url( '/' );
1094 + }
1095 +
1096 + $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1097 + }
1098 +
1099 + return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1100 + }
1101 +
1102 + /**
1103 + * Processes login form submission.
1104 + *
1105 + * @since 1.0.0
1106 + * @package userswp
1107 + *
1108 + */
1109 + public function process_login() {
1110 +
1111 + $data = $_POST;
1112 +
1113 + if ( ! isset( $data['uwp_login_nonce'] ) ) {
1114 + return;
1115 + }
1116 +
1117 + if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1118 + $message = aui()->alert(
1119 + array(
1120 + 'type' => 'error',
1121 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1122 + )
1123 + );
1124 + if ( wp_doing_ajax() ) {
1125 + wp_send_json_error( array( 'message' => $message ) );
1126 + } else {
1127 + return;
1128 + }
1129 + }
1130 +
1131 + global $uwp_notices;
1132 +
1133 + do_action( 'uwp_before_validate', 'login' );
1134 +
1135 + $result = uwp_validate_fields( $data, 'login' );
1136 +
1137 + $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1138 +
1139 + if ( is_wp_error( $result ) ) {
1140 + $message = aui()->alert(
1141 + array(
1142 + 'type' => 'error',
1143 + 'content' => $result->get_error_message(),
1144 + )
1145 + );
1146 + if ( wp_doing_ajax() ) {
1147 + wp_send_json_error( array( 'message' => $message ) );
1148 + } else {
1149 + $uwp_notices[] = array( 'login' => $message );
1150 +
1151 + return;
1152 + }
1153 + }
1154 +
1155 + do_action( 'uwp_after_validate', $result, 'login', $data );
1156 +
1157 + if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1158 + $remember_me = true;
1159 + } else {
1160 + $remember_me = false;
1161 + }
1162 +
1163 + remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1164 +
1165 + global $wp2fa;
1166 + if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1167 + remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1168 + }
1169 +
1170 + $user = wp_signon(
1171 + array(
1172 + 'user_login' => $result['username'],
1173 + 'user_password' => $result['password'],
1174 + 'remember' => $remember_me,
1175 + )
1176 + );
1177 +
1178 + add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1179 +
1180 + if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1181 +
1182 + $two_fa = $this->check_2fa( $user );
1183 + if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1184 + if ( is_wp_error( $two_fa ) ) {
1185 + $message = aui()->alert(
1186 + array(
1187 + 'type' => 'error',
1188 + 'content' => $two_fa->get_error_message(),
1189 + )
1190 + );
1191 + wp_send_json_error( array( 'message' => $message ) );
1192 + } else {
1193 + wp_send_json_success(
1194 + array(
1195 + 'html' => $two_fa,
1196 + 'is_2fa' => true,
1197 + )
1198 + );
1199 + }
1200 + }
1201 + }
1202 +
1203 + if ( is_wp_error( $user ) ) {
1204 + $message = aui()->alert(
1205 + array(
1206 + 'type' => 'error',
1207 + 'content' => $user->get_error_message(),
1208 + )
1209 + );
1210 + if ( wp_doing_ajax() ) {
1211 + wp_send_json_error( array( 'message' => $message ) );
1212 + } else {
1213 + $uwp_notices[] = array( 'login' => $message );
1214 +
1215 + return;
1216 + }
1217 + } else {
1218 + do_action( 'uwp_after_process_login', $data );
1219 + $message = aui()->alert(
1220 + array(
1221 + 'type' => 'success',
1222 + 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1223 + )
1224 + );
1225 + if ( wp_doing_ajax() ) {
1226 + $redirect_to = '';
1227 + if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1228 + $redirect_to = $this->get_login_redirect_url( $data, $user );
367 1229 }
368 - }
1230 + wp_send_json_success(
1231 + array(
1232 + 'message' => $message,
1233 + 'redirect' => $redirect_to,
1234 + )
1235 + );
1236 + } else {
1237 + $redirect_to = $this->get_login_redirect_url( $data, $user );
1238 + wp_safe_redirect( $redirect_to );
1239 + exit();
1240 + }
1241 +}
1242 + }
369 1243
370 - }
1244 + public function check_2fa( $user ) {
1245 + if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1246 + return;
1247 + }
371 1248
1249 + if ( ! $user ) {
1250 + $user = wp_get_current_user();
1251 + }
372 1252
373 - $error_code = $errors->get_error_code();
374 - if (!empty($error_code)) {
375 - return $errors;
376 - }
1253 + global $wp2fa;
1254 + $errors = new WP_Error();
377 1255
378 - if ($reg_action == 'auto_approve_login') {
379 - $res = wp_signon(
1256 + if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1257 + return;
1258 + }
1259 + // Invalidate the current login session to prevent from being re-used.
1260 + \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1261 +
1262 + // Also clear the cookies which are no longer valid.
1263 + wp_clear_auth_cookie();
1264 +
1265 + $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1266 + if ( ! $login_nonce ) {
1267 + $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1268 +
1269 + return $errors;
1270 + }
1271 +
1272 + $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1273 +
1274 + ob_start();
1275 + ?>
1276 +
1277 + <div class="uwp-2fa-methods-wrap">
1278 + <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1279 + autocomplete="off">
1280 + <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1281 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1282 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1283 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1284 + <?php
1285 +
1286 + // Check to see what provider is set and give the relevant authentication page.
1287 + if ( 'totp' === $provider ) {
1288 + ?>
1289 + <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1290 + <?php
1291 +
1292 + echo aui()->input(
1293 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1294 + 'type' => 'tel',
1295 + 'id' => 'authcode',
1296 + 'name' => 'authcode',
1297 + 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1298 + 'value' => '',
1299 + 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1300 + )
1301 + );
1302 +
1303 + echo aui()->button(
1304 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1305 + 'type' => 'submit',
1306 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1307 + 'name' => 'submit',
1308 + 'icon' => '',
1309 + 'content' => esc_html__( 'Log In', 'userswp' ),
1310 + )
1311 + );
1312 +
1313 + } elseif ( 'email' === $provider ) {
1314 + $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1315 + if ( empty( $has_token ) || ! $has_token ) {
1316 + \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1317 + }
1318 + ?>
1319 + <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1320 + <?php
1321 + echo aui()->input(
1322 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1323 + 'type' => 'tel',
1324 + 'id' => 'authcode',
1325 + 'name' => 'wp-2fa-email-code',
1326 + 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1327 + 'value' => '',
1328 + 'label' => esc_html__( 'Verification Code', 'userswp' ),
1329 + 'extra_attributes' => array(
1330 + 'size' => 20,
1331 + 'pattern' => '[0-9]*',
1332 + ),
1333 + )
1334 + );
1335 +
1336 + echo aui()->button(
1337 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1338 + 'type' => 'submit',
1339 + 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1340 + 'name' => 'submit',
1341 + 'icon' => '',
1342 + 'content' => esc_html__( 'Log In', 'userswp' ),
1343 + )
1344 + );
1345 +
1346 + echo aui()->button(
1347 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1348 + 'type' => 'button',
1349 + 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1350 + 'name' => 'wp-2fa-email-code-resend',
1351 + 'icon' => '',
1352 + 'content' => esc_html__( 'Resend Code', 'userswp' ),
1353 + )
1354 + );
1355 +
1356 + }
1357 + ?>
1358 + </form>
1359 + </div>
1360 +
1361 + <?php
1362 + $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1363 + if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1364 + ?>
1365 + <div class="uwp-2fa-methods-wrap" style="display:none;">
1366 + <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1367 + class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1368 + <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1369 + <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1370 + value="<?php echo esc_attr( $user->ID ); ?>"/>
1371 + <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1372 + value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1373 + <div class="uwp-backup-fields">
1374 + <?php
1375 + echo aui()->input(
1376 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1377 + 'type' => 'tel',
1378 + 'id' => 'authcode',
1379 + 'name' => 'wp-2fa-backup-code',
1380 + 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1381 + 'value' => '',
1382 + 'label' => esc_html__( 'Backup Code', 'userswp' ),
1383 + 'extra_attributes' => array(
1384 + 'size' => 20,
1385 + 'pattern' => '[0-9]*',
1386 + ),
1387 + )
1388 + );
1389 +
1390 + echo aui()->button(
1391 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1392 + 'type' => 'submit',
1393 + 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1394 + 'name' => 'submit',
1395 + 'icon' => '',
1396 + 'content' => esc_html__( 'Log In', 'userswp' ),
1397 + )
1398 + );
1399 + ?>
1400 + </div>
1401 + </form>
1402 + </div>
1403 + <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1404 + <script type="text/javascript">
1405 + jQuery('.uwp-switch-2fa-methods').on('click',
1406 + function (e) {
1407 + e.preventDefault();
1408 + jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1409 + jQuery('.uwp-2fa-methods-wrap').toggle();
1410 + return false;
1411 + }
1412 + );
1413 + </script>
1414 + <?php
1415 + }
1416 +
1417 + return ob_get_clean();
1418 + }
1419 +
1420 + public function process_login_2fa() {
1421 + if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1422 + return;
1423 + }
1424 +
1425 + $auth_id = (int) $_POST['uwp-auth-id'];
1426 + $user = get_userdata( $auth_id );
1427 + if ( ! $user ) {
1428 + $message = aui()->alert(
380 1429 array(
381 - 'user_login' => $result['uwp_account_username'],
382 - 'user_password' => $password,
383 - 'remember' => false
1430 + 'type' => 'error',
1431 + 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
384 1432 )
385 - );
1433 + );
386 1434
387 - if (is_wp_error($res)) {
388 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
389 - return $errors;
390 - } else {
391 - $reg_redirect_page_id = uwp_get_option('register_redirect_to', '');
392 - if(isset( $_REQUEST['redirect_to'] )) {
393 - $reg_redirect_to = esc_url($_REQUEST['redirect_to']);
394 - } elseif (empty($reg_redirect_page_id)) {
395 - $reg_redirect_to = home_url('/');
396 - } else {
397 - $reg_redirect_to = get_permalink($reg_redirect_page_id);
398 - }
399 - $redirect = apply_filters('uwp_register_redirect', $reg_redirect_to);
400 - wp_redirect($redirect);
401 - exit();
402 - }
403 - } else {
404 - if ($reg_action == 'require_email_activation') {
405 - return __('An email has been sent to your registered email address. Please click the activation link to proceed.', 'userswp');
406 - } elseif ($reg_action == 'require_admin_review' && defined('UWP_MOD_VERSION')) {
407 - update_user_meta( $user_id, 'uwp_mod', '1' );
1435 + wp_send_json_error( array( 'message' => $message ) );
1436 + }
408 1437
409 - $email = new UsersWP_Mails();
410 - $send_result = $email->send( 'mod_pending', $user_id );
411 - $user_data = get_user_by('id', $user_id);
412 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
413 - if (is_wp_error($send_result)) {
414 - return $send_result;
415 - }
1438 + global $wp2fa;
416 1439
417 - $admin_send_result = $email->send_admin_email('mod_admin', $user_id);
418 - if (is_wp_error($admin_send_result)) {
419 - return $admin_send_result;
420 - }
1440 + $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1441 + if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
421 1442
422 - return __('Your account is under moderation. We will email you once its approved.', 'userswp');
423 - } else {
1443 + $message = aui()->alert(
1444 + array(
1445 + 'type' => 'error',
1446 + 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1447 + )
1448 + );
424 1449
425 - $login_page_url = wp_login_url();
1450 + wp_send_json_error( array( 'message' => $message ) );
1451 + }
426 1452
427 - if ($generated_password) {
428 - return sprintf(__('Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login <a href="%s">here</a>.', 'userswp'), $login_page_url);
429 - } else {
430 - return sprintf(__('Account registered successfully. Please login <a href="%s">here</a>', 'userswp'), $login_page_url);
431 - }
432 - }
433 - }
1453 + if ( isset( $_POST['provider'] ) ) {
1454 + $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1455 + $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1456 + if ( isset( $providers[ $provider ] ) ) {
1457 + $provider = $providers[ $provider ];
1458 + } elseif ( isset( $provider ) ) {
1459 + $provider = $provider;
1460 + } else {
1461 + $provider = $provider;
1462 + }
1463 + }
434 1464
1465 + // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1466 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
435 1467
436 - }
1468 + }
437 1469
438 - /**
439 - * Processes login form submission.
440 - *
441 - * @since 1.0.0
442 - * @package userswp
443 - *
444 - * @param array $data Submitted $_POST data
445 - *
446 - * @return bool|WP_Error|string
447 - */
448 - public function process_login($data) {
1470 + // Validate TOTP.
1471 + if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
449 1472
450 - $errors = new WP_Error();
1473 + do_action( 'wp_login_failed', $user->user_login );
451 1474
452 - if( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
453 - return false;
454 - }
1475 + $message = aui()->alert(
1476 + array(
1477 + 'type' => 'error',
1478 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1479 + )
1480 + );
455 1481
456 - do_action('uwp_before_validate', 'login');
1482 + wp_send_json_error( array( 'message' => $message ) );
1483 + }
457 1484
458 - $result = uwp_validate_fields($data, 'login');
1485 + // Validate Email.
1486 + if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
459 1487
460 - $result = apply_filters('uwp_validate_result', $result, 'login', $data);
1488 + do_action( 'wp_login_failed', $user->user_login );
461 1489
462 - if (is_wp_error($result)) {
463 - return $result;
464 - }
1490 + if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1491 + $message = aui()->alert(
1492 + array(
1493 + 'type' => 'info',
1494 + 'content' => __( 'A new code has been sent.', 'userswp' ),
1495 + )
1496 + );
465 1497
466 - do_action('uwp_after_validate', 'login');
1498 + wp_send_json_error( array( 'message' => $message ) );
1499 + } else {
1500 + $message = aui()->alert(
1501 + array(
1502 + 'type' => 'error',
1503 + 'content' => __( 'Invalid verification code.', 'userswp' ),
1504 + )
1505 + );
467 1506
468 - if (isset($data['remember_me']) && $data['remember_me'] == 'forever') {
469 - $remember_me = true;
470 - } else {
471 - $remember_me = false;
472 - }
1507 + wp_send_json_error( array( 'message' => $message ) );
1508 + }
1509 + }
473 1510
474 - remove_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1511 + // Backup Codes.
1512 + if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
475 1513
476 - $res = wp_signon(
1514 + do_action( 'wp_login_failed', $user->user_login );
1515 +
1516 + $message = aui()->alert(
1517 + array(
1518 + 'type' => 'error',
1519 + 'content' => __( 'Invalid backup code.', 'userswp' ),
1520 + )
1521 + );
1522 +
1523 + wp_send_json_error( array( 'message' => $message ) );
1524 + }
1525 +
1526 + \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1527 +
1528 + $rememberme = false;
1529 + $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1530 + if ( ! empty( $remember ) ) {
1531 + $rememberme = true;
1532 + }
1533 +
1534 + wp_set_auth_cookie( $user->ID, $rememberme );
1535 +
1536 + do_action( 'two_factor_user_authenticated', $user );
1537 +
1538 + $message = aui()->alert(
477 1539 array(
478 - 'user_login' => $result['uwp_login_username'],
479 - 'user_password' => $result['password'],
480 - 'remember' => $remember_me
1540 + 'type' => 'success',
1541 + 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
481 1542 )
482 - );
1543 + );
483 1544
484 - add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1545 + wp_send_json_success( array( 'message' => $message ) );
1546 + }
485 1547
486 - if (is_wp_error($res)) {
487 - $errors->add('invalid_userorpass', __('<strong>Error</strong>: Invalid username or Password.', 'userswp'));
488 - return $errors;
489 - } else {
490 - $redirect_page_id = uwp_get_option('login_redirect_to', -1);
491 - if (isset($redirect_page_id) && (int)$redirect_page_id > 0) {
492 - $redirect_to = get_permalink($redirect_page_id);
493 - } elseif (isset($data['redirect_to'])) {
494 - $redirect_to = strip_tags(esc_sql($data['redirect_to']));
495 - } else {
496 - if ( current_user_can('manage_options') ) {
497 - $redirect_to = admin_url();
498 - } else {
499 - $redirect_to = home_url('/');
500 - }
501 - }
1548 + public function get_login_redirect_url( $data, $user ) {
1549 + if ( is_int( $user ) ) {
1550 + $user = get_userdata( $user );
1551 + }
502 1552
503 - $redirect_to = apply_filters('uwp_login_redirect', $redirect_to);
504 - wp_redirect($redirect_to);
505 - exit();
506 - }
507 - }
1553 + $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1554 + $custom_url = uwp_get_option( 'login_redirect_custom_url' );
508 1555
509 - /**
510 - * Processes forgot password form submission.
511 - *
512 - * @since 1.0.0
513 - * @package userswp
514 - *
515 - * @param array $data Submitted $_POST data
516 - *
517 - * @return bool|WP_Error|string
518 - */
519 - public function process_forgot($data) {
1556 + if ( $user && isset( $user->roles[0] ) ) {
1557 + $user_role = $user->roles[0];
1558 + $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1559 + $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1560 + }
520 1561
521 - $errors = new WP_Error();
1562 + if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1563 + $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1564 + } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1565 + $redirect_to = esc_url_raw( $data['redirect_to'] );
1566 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1567 + if ( uwp_is_wpml() ) {
1568 + $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1569 + if ( ! empty( $wpml_page_id ) ) {
1570 + $redirect_page_id = $wpml_page_id;
1571 + }
1572 + }
1573 + $redirect_to = get_permalink( $redirect_page_id );
1574 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1575 + $redirect_to = esc_url( wp_get_referer() );
1576 + } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1577 + $redirect_to = $custom_url;
1578 + } else {
1579 + $redirect_to = home_url( '/' );
1580 + $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1581 + }
522 1582
523 - if( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
524 - return false;
525 - }
1583 + return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1584 + }
526 1585
527 - do_action('uwp_before_validate', 'forgot');
1586 + /**
1587 + * Processes forgot password form submission.
1588 + *
1589 + * @since 1.0.0
1590 + * @package userswp
1591 + *
1592 + */
1593 + public function process_forgot() {
528 1594
529 - $result = uwp_validate_fields($data, 'forgot');
1595 + $data = $_POST;
530 1596
531 - $result = apply_filters('uwp_validate_result', $result, 'forgot', $data);
1597 + if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1598 + return;
1599 + }
532 1600
533 - if (is_wp_error($result)) {
534 - return $result;
535 - }
1601 + if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1602 + $message = aui()->alert(
1603 + array(
1604 + 'type' => 'error',
1605 + 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1606 + )
1607 + );
1608 + if ( wp_doing_ajax() ) {
1609 + wp_send_json_error( $message );
1610 + } else {
1611 + return;
1612 + }
1613 + }
536 1614
537 - do_action('uwp_after_validate', 'forgot');
1615 + global $uwp_notices;
538 1616
1617 + do_action( 'uwp_before_validate', 'forgot' );
539 1618
540 - $user_data = get_user_by('email', $data['uwp_forgot_email']);
1619 + $result = uwp_validate_fields( $data, 'forgot' );
541 1620
542 - // make sure user account is active before account reset
543 - $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
544 - if ($mod_value == 'email_unconfirmed') {
545 - $errors->add('activate_account', __('<strong>Error</strong>: Your account is not activated yet. Please activate your account first.', 'userswp'));
546 - }
1621 + $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
547 1622
548 - $error_code = $errors->get_error_code();
549 - if (!empty($error_code)) {
550 - return $errors;
551 - }
552 -
553 - $email = new UsersWP_Mails();
554 - $send_result = $email->send( 'forgot', $user_data->ID );
555 -
556 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
557 - if (is_wp_error($send_result)) {
558 - return $send_result;
559 - }
1623 + if ( is_wp_error( $result ) ) {
1624 + $message = aui()->alert(
1625 + array(
1626 + 'type' => 'error',
1627 + 'content' => $result->get_error_message(),
1628 + )
1629 + );
1630 + if ( wp_doing_ajax() ) {
1631 + wp_send_json_error( $message );
1632 + } else {
1633 + $uwp_notices[] = array( 'forgot' => $message );
560 1634
561 - return true;
562 - }
1635 + return;
1636 + }
1637 + }
563 1638
564 - /**
565 - * Processes change password form submission.
566 - *
567 - * @since 1.0.0
568 - * @package userswp
569 - *
570 - * @param array $data Submitted $_POST data
571 - *
572 - * @return bool|WP_Error|string
573 - */
574 - public function process_change($data) {
1639 + do_action( 'uwp_after_validate', $result, 'forgot', $data );
575 1640
576 - $errors = new WP_Error();
1641 + $user_data = get_user_by( 'email', $data['email'] );
577 1642
578 - if( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
579 - return false;
580 - }
1643 + // if no user we fake it and bail
1644 + if ( ! $user_data ) {
1645 + $args = apply_filters(
1646 + 'uwp_forgot_error_message',
1647 + array(
1648 + 'type' => 'error',
1649 + 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1650 + )
1651 + );
581 1652
582 - do_action('uwp_before_validate', 'change');
1653 + $message = aui()->alert( $args );
1654 + if ( wp_doing_ajax() ) {
1655 + wp_send_json_success( $message );
1656 + } else {
1657 + $uwp_notices[] = array( 'forgot' => $message );
583 1658
584 - $result = uwp_validate_fields($data, 'change');
1659 + return;
1660 + }
1661 + }
585 1662
586 - $result = apply_filters('uwp_validate_result', $result, 'change', $data);
1663 + // make sure user account is active before account reset
1664 + $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1665 + if ( $mod_value == 'email_unconfirmed' ) {
1666 + $message = aui()->alert(
1667 + array(
1668 + 'type' => 'error',
1669 + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1670 + )
1671 + );
1672 + if ( wp_doing_ajax() ) {
1673 + wp_send_json_error( $message );
1674 + } else {
1675 + $uwp_notices[] = array( 'forgot' => $message );
587 1676
588 - if (is_wp_error($result)) {
589 - return $result;
590 - }
1677 + return;
1678 + }
1679 + }
591 1680
592 - do_action('uwp_after_validate', 'change');
1681 + $user_data = get_userdata( $user_data->ID );
593 1682
594 - $user_data = get_user_by('id', get_current_user_id());
1683 + $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
595 1684
596 - if (is_wp_error($user_data)) {
597 - return $user_data;
598 - }
1685 + if ( ! $allow ) {
1686 + return false;
1687 + } elseif ( is_wp_error( $allow ) ) {
1688 + return false;
1689 + }
599 1690
600 - $email = new UsersWP_Mails();
601 - $send_result = $email->send( 'change', $user_data->ID );
1691 + $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
602 1692
603 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
604 - if (is_wp_error($send_result)) {
605 - return $send_result;
606 - }
1693 + global $wpdb, $wp_hasher;
1694 + $reset_link = '';
607 1695
608 - wp_set_password( $data['uwp_change_password'], $user_data->ID );
609 - wp_set_auth_cookie( $user_data->ID, false);
1696 + if ( $as_password ) {
1697 + $new_pass = wp_generate_password( 12, false );
1698 + wp_set_password( $new_pass, $user_data->ID );
1699 + if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
1700 + update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
1701 + }
1702 + $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
1703 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1704 + $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
610 1705
611 - return true;
612 - }
1706 + } else {
1707 + $key = wp_generate_password( 20, false );
1708 + do_action( 'retrieve_password_key', $user_data->user_login, $key );
613 1709
614 - /**
615 - * Processes reset password form submission.
616 - *
617 - * @since 1.0.0
618 - * @package userswp
619 - *
620 - * @param array $data Submitted $_POST data
621 - *
622 - * @return bool|WP_Error|string
623 - */
624 - public function process_reset($data) {
1710 + if ( empty( $wp_hasher ) ) {
1711 + require_once ABSPATH . 'wp-includes/class-phpass.php';
1712 + $wp_hasher = new PasswordHash( 8, true );
1713 + }
1714 + $hashed = $wp_hasher->HashPassword( $key );
1715 + $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1716 + $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1717 + $message .= home_url( '/' ) . '</p>';
1718 + $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1719 + $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
1720 + $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
1721 + $reset_page = uwp_get_page_id( 'reset_page', false );
1722 + if ( $reset_page ) {
1723 + $reset_link = add_query_arg(
1724 + array(
1725 + 'key' => $key,
1726 + 'login' => rawurlencode( $user_data->user_login ),
1727 + ),
1728 + get_permalink( $reset_page )
1729 + );
1730 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1731 + } else {
1732 + $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
1733 + $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1734 + }
1735 + $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
1736 + }
625 1737
626 - $errors = new WP_Error();
1738 + $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
627 1739
628 - if( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
629 - return false;
630 - }
1740 + $email_vars = array(
1741 + 'user_id' => $user_data->ID,
1742 + 'login_details' => $message,
1743 + 'reset_link' => $reset_link,
1744 + );
631 1745
632 - do_action('uwp_before_validate', 'reset');
1746 + UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
633 1747
634 - $result = uwp_validate_fields($data, 'reset');
1748 + do_action( 'uwp_after_process_forgot', $data );
635 1749
636 - $result = apply_filters('uwp_validate_result', $result, 'reset', $data);
1750 + $message = aui()->alert(
1751 + array(
1752 + 'type' => 'success',
1753 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
1754 + )
1755 + );
1756 + if ( wp_doing_ajax() ) {
1757 + wp_send_json_success( $message );
1758 + } else {
1759 + $uwp_notices[] = array( 'forgot' => $message );
1760 + }
1761 + }
637 1762
638 - if (is_wp_error($result)) {
639 - return $result;
640 - }
1763 + /**
1764 + * Processes change password form submission.
1765 + *
1766 + * @since 1.0.0
1767 + * @package userswp
1768 + *
1769 + */
1770 + public function process_change() {
641 1771
642 - do_action('uwp_after_validate', 'reset');
1772 + $data = $_POST;
643 1773
644 - $login = $data['uwp_reset_username'];
645 - $key = $data['uwp_reset_key'];
646 - $user_data = check_password_reset_key( $key, $login );
1774 + if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
1775 + return;
1776 + }
647 1777
648 - if (is_wp_error($user_data)) {
649 - return $user_data;
650 - }
1778 + global $uwp_notices;
651 1779
652 - $email = new UsersWP_Mails();
653 - $send_result = $email->send( 'reset', $user_data->ID );
1780 + if ( is_uwp_account_page() ) {
1781 + $notice_type = 'account';
1782 + } else {
1783 + $notice_type = 'change';
1784 + }
654 1785
655 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
656 - if (is_wp_error($send_result)) {
657 - return $send_result;
658 - }
1786 + do_action( 'uwp_before_validate', 'change' );
659 1787
660 - wp_set_password( $data['uwp_reset_password'], $user_data->ID );
1788 + $result = uwp_validate_fields( $data, 'change' );
661 1789
662 - return true;
663 - }
1790 + $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
664 1791
665 -
666 - /**
667 - * Modifies the mail subject based on the admin notification type.
668 - *
669 - * @since 1.0.0
670 - * @package userswp
671 - * @subpackage userswp/includes
672 - * @param string $subject Unmodified mail subject.
673 - * @param string $type Notification type.
674 - * @return string Modified mail subject.
675 - */
676 - public function init_mail_subject($subject, $type) {
677 - switch ($type) {
678 - case "register":
679 - $subject = uwp_get_option('registration_success_email_subject', '');
680 - break;
681 - case "activate":
682 - $subject = uwp_get_option('registration_activate_email_subject', '');
683 - break;
684 - case "forgot":
685 - $subject = uwp_get_option('forgot_password_email_subject', '');
686 - break;
687 - case "reset":
688 - $subject = uwp_get_option('reset_password_email_subject', '');
689 - break;
690 - case "change":
691 - $subject = uwp_get_option('change_password_email_subject', '');
692 - break;
693 - case "account":
694 - $subject = uwp_get_option('account_update_email_subject', '');
695 - break;
696 - }
697 - return $subject;
698 - }
1792 + if ( is_wp_error( $result ) ) {
1793 + $message = aui()->alert(
1794 + array(
1795 + 'type' => 'error',
1796 + 'content' => $result->get_error_message(),
1797 + )
1798 + );
1799 + $uwp_notices[] = array( $notice_type => $message );
699 1800
700 - /**
701 - * Modifies the mail content based on the admin notification type.
702 - *
703 - * @since 1.0.0
704 - * @package userswp
705 - * @subpackage userswp/includes
706 - * @param string $content Unmodified mail content.
707 - * @param string $type Notification type.
708 - * @return string Modified mail content.
709 - */
710 - public function init_mail_content($content, $type) {
711 - switch ($type) {
712 - case "register":
713 - $content = uwp_get_option('registration_success_email_content', '');
714 - break;
715 - case "activate":
716 - $content = uwp_get_option('registration_activate_email_content', '');
717 - break;
718 - case "forgot":
719 - $content = uwp_get_option('forgot_password_email_content', '');
720 - break;
721 - case "reset":
722 - $content = uwp_get_option('reset_password_email_content', '');
723 - break;
724 - case "change":
725 - $content = uwp_get_option('change_password_email_content', '');
726 - break;
727 - case "account":
728 - $content = uwp_get_option('account_update_email_content', '');
729 - break;
730 - }
731 - return $content;
732 - }
1801 + return;
1802 + }
733 1803
734 - /**
735 - * Modifies the mail extras based on the notification type.
736 - *
737 - * @since 1.0.0
738 - * @package userswp
739 - * @subpackage userswp/includes
740 - * @param string $extras Unmodified mail extras.
741 - * @param string $type Notification type.
742 - * @return string Modified mail extras.
743 - */
744 - public function init_mail_extras($extras, $type, $user_id) {
745 - switch ($type) {
746 - case "activate":
747 - $extras = $this->generate_activate_message($user_id);
748 - break;
749 - case "register":
750 - $extras = $this->generate_register_message($user_id);
751 - break;
752 - case "forgot":
753 - $extras = $this->generate_forgot_message($user_id);
754 - }
755 - return $extras;
756 - }
757 -
758 - /**
759 - * Modifies the admin mail subject based on the admin notification type.
760 - *
761 - * @since 1.0.0
762 - * @package userswp
763 - * @subpackage userswp/includes
764 - * @param string $subject Unmodified admin mail subject.
765 - * @param string $type Admin notification type.
766 - * @return string Modified admin mail subject.
767 - */
768 - public function init_admin_mail_subject($subject, $type) {
769 - switch ($type) {
770 - case "register_admin":
771 - $subject = uwp_get_option('registration_success_email_subject_admin', '');
772 - break;
773 - }
774 - return $subject;
775 - }
1804 + do_action( 'uwp_after_validate', $result, 'change', $data );
776 1805
777 - /**
778 - * Modifies the admin mail content based on the admin notification type.
779 - *
780 - * @since 1.0.0
781 - * @package userswp
782 - * @subpackage userswp/includes
783 - * @param string $content Unmodified admin mail content.
784 - * @param string $type Admin notification type.
785 - * @return string Modified admin mail content.
786 - */
787 - public function init_admin_mail_content($content, $type) {
788 - switch ($type) {
789 - case "register_admin":
790 - $content = uwp_get_option('registration_success_email_content_admin', '');
791 - break;
792 - }
793 - return $content;
794 - }
1806 + $user_data = get_user_by( 'id', get_current_user_id() );
795 1807
796 - /**
797 - * Modifies the admin mail extras based on the notification type.
798 - *
799 - * @since 1.0.0
800 - * @package userswp
801 - * @subpackage userswp/includes
802 - * @param string $extras Unmodified mail extras.
803 - * @param string $type Notification type.
804 - * @return string Modified mail extras.
805 - */
806 - public function init_admin_mail_extras($extras, $type, $user_id) {
807 - switch ($type) {
808 - case "register_admin":
809 - $user_data = get_userdata($user_id);
810 - $extras = __('<p><b>' . __('User Information :', 'userswp') . '</b></p>
811 - <p>' . __('First Name:', 'userswp') . ' ' . $user_data->first_name . '</p>
812 - <p>' . __('Last Name:', 'userswp') . ' ' . $user_data->last_name . '</p>
813 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
814 - <p>' . __('Email:', 'userswp') . ' ' . $user_data->user_email . '</p>');
815 - break;
816 - }
817 - return $extras;
818 - }
1808 + if ( ! $user_data ) {
1809 + $message = aui()->alert(
1810 + array(
1811 + 'type' => 'error',
1812 + 'content' => $user_data->get_error_message(),
1813 + )
1814 + );
1815 + $uwp_notices[] = array( $notice_type => $message );
819 1816
820 - /**
821 - * Generates activate email message.
822 - *
823 - * @since 1.0.0
824 - * @package userswp
825 - *
826 - * @param int $user_id User ID.
827 - *
828 - * @return bool|string Message.
829 - */
830 - public function generate_activate_message($user_id) {
1817 + return;
1818 + }
831 1819
832 - $user_data = get_userdata($user_id);
833 - global $wpdb;
834 - $key = wp_generate_password( 20, false );
835 - do_action( 'uwp_activation_key', $user_data->user_login, $key );
1820 + $email_vars = array(
1821 + 'user_id' => $user_data->ID,
1822 + );
836 1823
837 - global $wp_hasher;
838 - if ( empty( $wp_hasher ) ) {
839 - require_once ABSPATH . 'wp-includes/class-phpass.php';
840 - $wp_hasher = new PasswordHash( 8, true );
841 - }
842 - $hashed = $wp_hasher->HashPassword( $key );
843 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
844 - update_user_meta( $user_id, 'uwp_mod', 'email_unconfirmed' );
845 - $message = __('To activate your account, visit the following address:', 'userswp') . "\r\n\r\n";
846 - $act_url = add_query_arg(
1824 + UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
1825 +
1826 + wp_set_password( $result['password'], $user_data->ID );
1827 +
1828 + $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
1829 + if ( $password_nag ) {
1830 + delete_user_meta( $user_data->ID, 'default_password_nag' );
1831 + }
1832 +
1833 + delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
1834 +
1835 + $message = aui()->alert(
847 1836 array(
848 - 'uwp_activate' => 'yes',
849 - 'key' => $key,
850 - 'login' => $user_data->user_login
851 - ),
852 - site_url()
853 - );
1837 + 'type' => 'success',
1838 + 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
1839 + )
1840 + );
854 1841
855 - $message .= "<a href='".$act_url."' target='_blank'>".$act_url."</a>" . "\r\n";
1842 + $uwp_notices[] = array( $notice_type => $message );
856 1843
857 - $activate_message = __('<p><b>' . __('Please activate your account :', 'userswp') . '</b></p>
858 - <p>' . $message . '</p>');
1844 + do_action( 'uwp_after_process_change', $data );
859 1845
860 - return $activate_message;
1846 + wp_logout();
1847 + exit();
1848 + }
861 1849
862 - }
1850 + /**
1851 + * Processes reset password form submission.
1852 + *
1853 + * @since 1.0.0
1854 + * @package userswp
1855 + *
1856 + */
1857 + public function process_reset() {
863 1858
864 - /**
865 - * Generates register email message.
866 - *
867 - * @since 1.0.0
868 - * @package userswp
869 - *
870 - * @param int $user_id User ID.
871 - *
872 - * @return bool|string Message.
873 - */
874 - public function generate_register_message($user_id) {
1859 + $data = $_POST;
875 1860
876 - $user_data = get_userdata($user_id);
877 - if(isset($this->generated_password) && !empty($this->generated_password)) {
878 - update_user_meta($user_id, 'default_password_nag', true); //Set up the Password change nag.
879 - $message_pass = $this->generated_password;
880 - $this->generated_password = false;
881 - } else {
882 - $message_pass = __("Password you entered", 'userswp');
883 - }
884 - $message = __('<p><b>' . __('Your login Information :', 'userswp') . '</b></p>
885 - <p>' . __('Username:', 'userswp') . ' ' . $user_data->user_login . '</p>
886 - <p>' . __('Password:', 'userswp') . ' ' . $message_pass . '</p>');
1861 + if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
1862 + wp_die( esc_html__( 'No spam please!', 'userswp' ) );
1863 + }
887 1864
888 - return $message;
1865 + if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
1866 + return;
1867 + }
889 1868
890 - }
891 -
892 - /**
893 - * Generates forgot password email message.
894 - *
895 - * @since 1.0.0
896 - * @package userswp
897 - *
898 - * @param int $user_id User ID.
899 - *
900 - * @return bool|string Message.
901 - */
902 - public function generate_forgot_message($user_id) {
1869 + global $uwp_notices;
903 1870
904 - $user_data = get_userdata($user_id);
905 - global $wpdb, $wp_hasher;
1871 + do_action( 'uwp_before_validate', 'reset' );
906 1872
907 - $allow = apply_filters('allow_password_reset', true, $user_data->ID);
908 - if ( ! $allow )
909 - return false;
910 - else if ( is_wp_error($allow) )
911 - return false;
1873 + $result = uwp_validate_fields( $data, 'reset' );
912 1874
913 - $as_password = apply_filters('uwp_forgot_message_as_password', false);
1875 + $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
914 1876
915 - if ($as_password) {
916 - $new_pass = wp_generate_password(12, false);
917 - wp_set_password($new_pass, $user_data->ID);
918 - update_user_meta($user_data->ID, 'default_password_nag', true); //Set up the Password change nag.
919 - $message = '<p><b>' . __('Your login Information :', 'userswp') . '</b></p>';
920 - $message .= '<p>' . sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "</p>";
921 - $message .= '<p>' . sprintf(__('Password: %s', 'userswp'), $new_pass) . "</p>";
1877 + if ( is_wp_error( $result ) ) {
1878 + $message = aui()->alert(
1879 + array(
1880 + 'type' => 'error',
1881 + 'content' => $result->get_error_message(),
1882 + )
1883 + );
1884 + $uwp_notices[] = array( 'reset' => $message );
922 1885
923 - } else {
924 - $key = wp_generate_password( 20, false );
925 - do_action( 'retrieve_password_key', $user_data->user_login, $key );
1886 + return;
1887 + }
926 1888
927 - if ( empty( $wp_hasher ) ) {
928 - require_once ABSPATH . 'wp-includes/class-phpass.php';
929 - $wp_hasher = new PasswordHash( 8, true );
930 - }
931 - $hashed = $wp_hasher->HashPassword( $key );
932 - $wpdb->update( $wpdb->users, array( 'user_activation_key' => time().":".$hashed ), array( 'user_login' => $user_data->user_login ) );
933 - $message = '<p>' .__('You have requested to reset your password for the following account:', 'userswp') . "</p>";
934 - $message .= home_url( '/' ) . "</p>";
935 - $message .= '<p>' .sprintf(__('Username: %s', 'userswp'), $user_data->user_login) . "</p>";
936 - $message .= '<p>' .__('If this was by mistake, just ignore this email and nothing will happen.', 'userswp') . "</p>";
937 - $message .= '<p>' .__('To reset your password, click the following link and follow the instructions.', 'userswp') . "</p>";
938 - $reset_page = uwp_get_option('reset_page', false);
939 - if ($reset_page) {
940 - $reset_link = add_query_arg( array(
941 - 'key' => $key,
942 - 'login' => rawurlencode($user_data->user_login),
943 - ), get_permalink($reset_page) );
944 - $message .= "<a href='".$reset_link."' target='_blank'>".$reset_link."</a>" . "\r\n";
945 - } else {
946 - $message .= site_url("reset?key=$key&login=" . rawurlencode($user_data->user_login), 'login') . "\r\n";
947 - }
948 - }
1889 + do_action( 'uwp_after_validate', $result, 'reset', $data );
949 1890
1891 + $login = sanitize_text_field( $data['uwp_reset_username'] );
1892 + $key = sanitize_text_field( $data['uwp_reset_key'] );
950 1893
951 - return $message;
1894 + $user = get_user_by( 'login', $login );
1895 + if ( ! $user ) {
1896 + $message = aui()->alert(
1897 + array(
1898 + 'type' => 'error',
1899 + 'content' => __( 'Invalid username.', 'userswp' ),
1900 + )
1901 + );
1902 + $uwp_notices[] = array( 'reset' => $message );
952 1903
953 - }
1904 + return;
1905 + }
954 1906
955 - /**
956 - * Processes account form submission.
957 - *
958 - * @since 1.0.0
959 - * @package userswp
960 - *
961 - * @param array $data Submitted $_POST data
962 - * @param array $files Submitted $_FILES data
963 - *
964 - * @return bool|WP_Error|string
965 - */
966 - public function process_account($data = array(), $files = array()) {
1907 + clean_user_cache( $user );
967 1908
968 - $file_obj = new UsersWP_Files();
969 -
970 - $current_user_id = get_current_user_id();
971 - if (!$current_user_id) {
972 - return false;
973 - }
1909 + $user_data = check_password_reset_key( $key, $login );
974 1910
975 - $errors = new WP_Error();
1911 + if ( is_wp_error( $user_data ) ) {
1912 + $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
1913 + $message = aui()->alert(
1914 + array(
1915 + 'type' => 'error',
1916 + 'content' => $error,
1917 + )
1918 + );
1919 + $uwp_notices[] = array( 'reset' => $message );
976 1920
977 - if( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
978 - return false;
979 - }
1921 + return;
1922 + }
980 1923
981 - do_action('uwp_before_validate', 'account');
1924 + $email_vars = array(
1925 + 'user_id' => $user_data->ID,
1926 + );
982 1927
983 - $result = uwp_validate_fields($data, 'account');
1928 + UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
984 1929
985 - $result = apply_filters('uwp_validate_result', $result, 'account', $data);
1930 + wp_set_password( $data['password'], $user_data->ID );
986 1931
987 - if (is_wp_error($result)) {
988 - return $result;
989 - }
1932 + $login_page_url = uwp_get_login_page_url();
1933 + $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
1934 + $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
1935 + $message = aui()->alert(
1936 + array(
1937 + 'type' => 'success',
1938 + 'content' => $message,
1939 + )
1940 + );
1941 + $uwp_notices[] = array( 'reset' => $message );
990 1942
991 - $uploads_result = $file_obj->uwp_validate_uploads($files, 'account');
1943 + do_action( 'uwp_after_process_reset', $data );
1944 + }
992 1945
993 - if (is_wp_error($uploads_result)) {
994 - return $uploads_result;
995 - }
1946 + /**
1947 + * Processes account form submission.
1948 + *
1949 + * @since 1.0.0
1950 + * @package userswp
1951 + *
1952 + */
1953 + public function process_account() {
996 1954
997 - do_action('uwp_after_validate', 'account');
1955 + $data = wp_unslash( $_POST );
1956 + $files = $_FILES;
998 1957
999 - //unset if value is empty for files
1000 - foreach ($uploads_result as $upload_file_key => $upload_file_value) {
1001 - if (empty($upload_file_value)) {
1002 - unset($uploads_result[$upload_file_key]);
1003 - }
1004 - }
1958 + if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
1959 + return;
1960 + }
1005 1961
1006 - $result = array_merge( $result, $uploads_result );
1962 + if ( ! is_user_logged_in() ) {
1963 + return;
1964 + }
1007 1965
1966 + global $uwp_notices;
1967 + $file_obj = new UsersWP_Files();
1008 1968
1009 - $args = array(
1010 - 'ID' => $current_user_id
1011 - );
1969 + do_action( 'uwp_before_validate', 'account' );
1012 1970
1013 - if (isset($result['uwp_account_email'])) {
1014 - $args['user_email'] = $result['uwp_account_email'];
1015 - }
1971 + $result = uwp_validate_fields( $data, 'account' );
1016 1972
1017 - if (isset($result['uwp_account_first_name']) && isset($result['uwp_account_last_name'])) {
1018 - $args['display_name'] = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
1019 - }
1973 + $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
1020 1974
1021 - if (isset($result['uwp_account_first_name'])) {
1022 - $args['first_name'] = $result['uwp_account_first_name'];
1023 - }
1975 + if ( is_wp_error( $result ) ) {
1976 + $message = aui()->alert(
1977 + array(
1978 + 'type' => 'error',
1979 + 'content' => $result->get_error_message(),
1980 + )
1981 + );
1982 + $uwp_notices[] = array( 'account' => $message );
1024 1983
1025 - if (isset($result['uwp_account_last_name'])) {
1026 - $args['last_name'] = $result['uwp_account_last_name'];
1027 - }
1984 + return;
1985 + }
1028 1986
1029 - if (isset($result['uwp_account_bio'])) {
1030 - $args['description'] = $result['uwp_account_bio'];
1031 - }
1987 + $uploads_result = $file_obj->validate_uploads( $files, 'account' );
1032 1988
1033 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
1034 - $args['display_name'] = $result['uwp_account_display_name'];
1035 - }
1989 + if ( is_wp_error( $uploads_result ) ) {
1990 + $message = aui()->alert(
1991 + array(
1992 + 'type' => 'error',
1993 + 'content' => $uploads_result->get_error_message(),
1994 + )
1995 + );
1996 + $uwp_notices[] = array( 'account' => $message );
1036 1997
1037 - if (isset($result['password'])) {
1038 - $args['user_pass'] = $result['password'];
1039 - }
1998 + return;
1999 + }
1040 2000
1041 - $user_id = wp_update_user( $args );
2001 + do_action( 'uwp_after_validate', $result, 'account', $data );
1042 2002
1043 - if (!$user_id) {
1044 - $errors->add('registerfail', sprintf(__('<strong>Error</strong>: Something went wrong.', 'userswp'), get_option('admin_email')));
1045 - return $errors;
1046 - }
2003 + //unset if value is empty for files
2004 + foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2005 + if ( empty( $upload_file_value ) ) {
2006 + unset( $uploads_result[ $upload_file_key ] );
2007 + }
2008 + }
1047 2009
1048 - $res = $this->uwp_save_user_extra_fields($user_id, $result, 'account');
2010 + $result = array_merge( $result, $uploads_result );
1049 2011
1050 - if (!$res) {
1051 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
1052 - }
2012 + $args = array(
2013 + 'ID' => get_current_user_id(),
2014 + );
1053 2015
1054 - $error_code = $errors->get_error_code();
1055 - if (!empty($error_code)) {
1056 - return $errors;
1057 - }
2016 + if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2017 + $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2018 + }
1058 2019
2020 + if ( isset( $result['first_name'] ) ) {
2021 + $args['first_name'] = $result['first_name'];
2022 + }
1059 2023
1060 - if (uwp_get_option('enable_account_update_notification') == '1') {
1061 - $user_data = get_user_by('id', $user_id);
2024 + if ( isset( $result['last_name'] ) ) {
2025 + $args['last_name'] = $result['last_name'];
2026 + }
1062 2027
1063 - $email = new UsersWP_Mails();
1064 - $send_result = $email->send( 'account', $user_data->ID );
2028 + if ( isset( $result['user_url'] ) ) {
2029 + $args['user_url'] = $result['user_url'];
2030 + }
1065 2031
1066 - $send_result = apply_filters('uwp_forms_check_for_send_mail_errors', $send_result, $user_data, $errors);
1067 - if (is_wp_error($send_result)) {
1068 - return $send_result;
1069 - }
1070 -
1071 - }
1072 -
1073 - return true;
2032 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2033 + $args['display_name'] = $result['display_name'];
2034 + }
1074 2035
1075 - }
2036 + if ( isset( $result['password'] ) ) {
2037 + $args['user_pass'] = $result['password'];
2038 + }
1076 2039
1077 - /**
1078 - * Processes avatar and banner uploads form submission.
1079 - *
1080 - * @since 1.0.0
1081 - * @package userswp
1082 - *
1083 - * @param array $data Submitted $_POST data
1084 - * @param array $files Submitted $_FILES data
1085 - *
1086 - * @return bool|WP_Error|string File url to crop.
1087 - */
1088 - public function process_upload_submit($data = array(), $files = array(), $type = 'avatar') {
2040 + $user_id = wp_update_user( $args );
1089 2041
1090 - $file_obj = new UsersWP_Files();
1091 -
1092 - $current_user_id = get_current_user_id();
1093 - if (!$current_user_id) {
1094 - return false;
1095 - }
2042 + if ( is_wp_error( $user_id ) ) {
2043 + $message = aui()->alert(
2044 + array(
2045 + 'type' => 'error',
2046 + 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2047 + )
2048 + );
2049 + $uwp_notices[] = array( 'account' => $message );
1096 2050
1097 - if( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
1098 - return false;
1099 - }
2051 + return;
2052 + }
1100 2053
1101 - do_action('uwp_before_validate', $type);
2054 + $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
1102 2055
1103 - $result = $file_obj->uwp_validate_uploads($files, $type);
2056 + if ( ! $res ) {
2057 + $message = aui()->alert(
2058 + array(
2059 + 'type' => 'error',
2060 + 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2061 + )
2062 + );
2063 + $uwp_notices[] = array( 'account' => $message );
1104 2064
1105 - $result = apply_filters('uwp_validate_result', $result, $type, $data);
2065 + return;
2066 + }
1106 2067
1107 - if (is_wp_error($result)) {
1108 - return $result;
1109 - }
2068 + //updating bio field after saving extra fields to reflect the points in mycred add on.
2069 + if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2070 + $args = array(
2071 + 'ID' => $user_id,
2072 + 'description' => $result['bio'],
2073 + );
2074 + wp_update_user( $args );
2075 + }
1110 2076
1111 - $profile_url = uwp_build_profile_tab_url($current_user_id);
2077 + $user_data = get_userdata( $user_id );
1112 2078
1113 - $url = add_query_arg(
1114 - array(
1115 - 'uwp_crop' => $result['uwp_'.$type.'_file'],
1116 - 'type' => $type
1117 - ),
1118 - $profile_url);
2079 + $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
1119 2080
1120 - return $url;
2081 + if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
1121 2082
1122 - }
2083 + if ( email_exists( trim( $result['email'] ) ) ) {
2084 + $message = aui()->alert(
2085 + array(
2086 + 'type' => 'error',
2087 + 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2088 + )
2089 + );
1123 2090
1124 - /**
1125 - * Processes avatar and banner uploads image crop.
1126 - *
1127 - * @since 1.0.0
1128 - * @since 1.0.12 New param $unlink_prev_img introduced.
1129 - * @package userswp
1130 - *
1131 - * @param array $data Submitted $_POST data
1132 - * @param string $type Image type. Default 'avatar'.
1133 - * @param bool $unlink_prev_img True to remove previous image. Default false;
1134 - *
1135 - * @return bool|WP_Error|string Profile url.
1136 - */
1137 - public function process_image_crop($data = array(), $type = 'avatar', $unlink_prev_img = false) {
1138 -
1139 - if (!is_user_logged_in()) {
1140 - return false;
2091 + $uwp_notices[] = array( 'account' => $message );
2092 + return;
2093 +
2094 + }
2095 +
2096 + $hash = md5( $result['email'] . time() . wp_rand() );
2097 + $new_admin_email = array(
2098 + 'hash' => $hash,
2099 + 'newemail' => $result['email'],
2100 + );
2101 +
2102 + update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2103 +
2104 + $new_email_link = add_query_arg(
2105 + array(
2106 + 'uwp_new_email' => 'yes',
2107 + 'key' => $hash,
2108 + 'login' => $user_data->user_login,
2109 + ),
2110 + uwp_get_account_page_url()
2111 + );
2112 +
2113 + $email_vars = array(
2114 + 'user_id' => $user_id,
2115 + 'new_email' => $result['email'],
2116 + 'new_email_link' => esc_url( $new_email_link ),
2117 + );
2118 +
2119 + UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2120 +
2121 + $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2122 + $message = aui()->alert(
2123 + array(
2124 + 'type' => 'success',
2125 + 'content' => $message,
2126 + )
2127 + );
2128 +
2129 + $uwp_notices[] = array( 'account' => $message );
2130 +
2131 + } else {
2132 + $email_vars = array(
2133 + 'user_id' => $user_id,
2134 + 'form_fields' => $form_fields,
2135 + );
2136 +
2137 + UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2138 +
2139 + $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2140 + $message = aui()->alert(
2141 + array(
2142 + 'type' => 'success',
2143 + 'content' => $message,
2144 + )
2145 + );
2146 +
2147 + $uwp_notices[] = array( 'account' => $message );
1141 2148 }
1142 2149
1143 - // If is current user's profile (profile.php)
1144 - if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
1145 - $user_id = get_current_user_id();
1146 - // If is another user's profile page
1147 - } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
1148 - $user_id = $_GET['user_id'];
1149 - // Otherwise something is wrong.
1150 - } else {
1151 - $user_id = get_current_user_id();
1152 - }
1153 - $image_url = $data['uwp_crop'];
1154 -
1155 - $errors = new WP_Error();
1156 - if (empty($image_url)) {
1157 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong. Please contact site admin.', 'userswp'));
1158 - }
2150 + do_action( 'uwp_after_process_account', $data, $user_id );
2151 + }
1159 2152
1160 - $error_code = $errors->get_error_code();
1161 - if (!empty($error_code)) {
1162 - return $errors;
1163 - }
1164 -
1165 - if ($image_url) {
1166 - if ($type == 'avatar') {
1167 - $full_width = apply_filters('uwp_avatar_image_width', 150);
1168 - } else {
1169 - $full_width = apply_filters('uwp_banner_image_width', uwp_get_option('profile_banner_width', 1000));
1170 - }
2153 + /**
2154 + * Modifies the forms field in email based on the form type.
2155 + *
2156 + * @param string $form_fields Form fields.
2157 + * @param string $type Form type.
2158 + * @param int $user_id User ID.
2159 + *
2160 + * @return string Modified mail field.
2161 + * @package userswp
2162 + * @subpackage userswp/includes
2163 + *
2164 + */
2165 + public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2166 + switch ( $type ) {
2167 + case 'register':
2168 + $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2169 + $fields = get_register_form_fields( $form_id );
2170 + $user_data = get_userdata( $user_id );
2171 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2172 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2173 + $excluded = uwp_get_excluded_fields();
2174 + foreach ( $fields as $key => $field ) {
2175 + if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2176 + continue;
2177 + }
2178 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2179 + $field_value = $user_data->user_email;
2180 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2181 + $field_value = $user_data->user_login;
2182 + } elseif ( $field->htmlvar_name == 'bio' ) {
2183 + $field_value = get_user_meta( $user_id, 'description', true );
2184 + } else {
2185 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2186 + }
1171 2187
1172 - $image_url = esc_url($image_url);
1173 - $uploads = wp_upload_dir();
1174 - $upload_url = $uploads['baseurl'];
1175 - $upload_path = $uploads['basedir'];
1176 - $image_url = str_replace($upload_url, $upload_path, $image_url);
1177 - $ext = pathinfo($image_url, PATHINFO_EXTENSION); // to get extension
1178 - $name =pathinfo($image_url, PATHINFO_FILENAME); //file name without extension
1179 - $thumb_image_name = $name.'_uwp_'.$type.'_thumb'.'.'.$ext;
1180 - $thumb_image_location = str_replace($name.'.'.$ext, $thumb_image_name, $image_url);
1181 - //Get the new coordinates to crop the image.
1182 - $x = $data["x"];
1183 - $y = $data["y"];
1184 - $w = $data["w"];
1185 - $h = $data["h"];
1186 - //Scale the image based on cropped width setting
1187 - $scale = $full_width/$w;
1188 - //$scale = 1; // no scaling
1189 - $cropped = uwp_resizeThumbnailImage($thumb_image_location, $image_url,$x, $y, $w, $h,$scale);
1190 - $cropped = str_replace($upload_path, $upload_url, $cropped);
2188 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2189 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2190 + }
1191 2191
1192 - // Remove previous avatar/banner
1193 - $unlink_img = '';
1194 - if ($unlink_prev_img) {
1195 - if ($type == 'avatar') {
1196 - $previous_img = uwp_get_usermeta($user_id, 'uwp_account_avatar_thumb');
1197 - } else if ($type == 'banner') {
1198 - $previous_img = uwp_get_usermeta($user_id, 'uwp_account_banner_thumb');
1199 - } else {
1200 - $previous_img = '';
2192 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2193 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2194 + }
2195 + }
1201 2196 }
1202 -
1203 - if ($previous_img) {
1204 - $unlink_img = untrailingslashit($upload_path) . '/' . ltrim($previous_img, '/');
2197 + break;
2198 + case 'account':
2199 + $fields = get_account_form_fields();
2200 + $user_data = get_userdata( $user_id );
2201 + if ( ! empty( $fields ) && is_array( $fields ) ) {
2202 + $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2203 + foreach ( $fields as $key => $field ) {
2204 + if ( $field->is_active != '1' ) {
2205 + continue;
2206 + }
2207 + if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2208 + $field_value = $user_data->user_email;
2209 + } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2210 + $field_value = $user_data->user_login;
2211 + } elseif ( $field->htmlvar_name == 'bio' ) {
2212 + $field_value = get_user_meta( $user_id, 'description', true );
2213 + } else {
2214 + $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2215 + }
2216 +
2217 + if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2218 + $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2219 + }
2220 +
2221 + if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2222 + $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2223 + }
2224 + }
1205 2225 }
2226 + break;
2227 + }
2228 +
2229 + return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2230 + }
2231 +
2232 + /**
2233 + *
2234 + *
2235 + * @return void
2236 + * @since 1.0.12 Unlink file.
2237 + * @package userswp
2238 + * @since 1.0.0
2239 + */
2240 + public function upload_file_remove() {
2241 + check_ajax_referer( 'uwp_basic_nonce', 'security' );
2242 +
2243 + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2244 + $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2245 +
2246 + if ( empty( $user_id ) ) {
2247 + wp_die( -1 );
2248 + }
2249 +
2250 + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2251 + wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2252 + }
2253 +
2254 + // Remove file
2255 + if ( $htmlvar == 'banner_thumb' ) {
2256 + $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2257 + $type = 'banner';
2258 + } elseif ( $htmlvar == 'avatar_thumb' ) {
2259 + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2260 + $type = 'avatar';
2261 + } else {
2262 + $file = '';
2263 + $type = '';
2264 + }
2265 +
2266 + uwp_update_usermeta( $user_id, $htmlvar, '' );
2267 +
2268 + if ( $file ) {
2269 + $uploads = wp_upload_dir();
2270 + $upload_path = $uploads['basedir'];
2271 + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2272 +
2273 + if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2274 + @unlink( $unlink_file );
2275 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2276 +
2277 + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2278 + @unlink( $unlink_ori_file );
2279 + }
1206 2280 }
2281 + }
1207 2282
1208 - // remove the uploads path for easy migrations
1209 - $cropped = str_replace($upload_url, '', $cropped);
1210 - if ($type == 'avatar') {
1211 - uwp_update_usermeta($user_id, 'uwp_account_avatar_thumb', $cropped);
1212 - } else {
1213 - uwp_update_usermeta($user_id, 'uwp_account_banner_thumb', $cropped);
1214 - }
1215 -
1216 - if ($unlink_img && $unlink_img != $thumb_image_location && is_file($unlink_img) && file_exists($unlink_img)) {
1217 - @unlink($unlink_img);
1218 - $unlink_ori_img = str_replace('_uwp_'.$type.'_thumb'.'.', '.', $unlink_img);
1219 - if (is_file($unlink_ori_img) && file_exists($unlink_ori_img)) {
1220 - @unlink($unlink_ori_img);
2283 + wp_send_json_success();
2284 +
2285 + wp_die();
2286 + }
2287 +
2288 + /**
2289 + * Form field template for datepicker field type.
2290 + *
2291 + * @param string $html Form field html
2292 + * @param object $field Field info.
2293 + * @param string $value Form field default value.
2294 + * @param string $form_type Form type
2295 + *
2296 + * @return string Modified form field html.
2297 + * @package userswp
2298 + *
2299 + * @since 1.0.0
2300 + */
2301 + public function form_input_datepicker( $html, $field, $value, $form_type ) {
2302 +
2303 + // Check if there is a field specific filter.
2304 + if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2305 + $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2306 + }
2307 +
2308 + // If no html then we run the standard output.
2309 + if ( empty( $html ) ) {
2310 +
2311 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2312 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2313 + $bs_sr_only = $design_style ? 'sr-only' : '';
2314 + $bs_form_control = $design_style ? 'form-control' : '';
2315 + $extra_attributes = array();
2316 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2317 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2318 +
2319 + ob_start(); // Start buffering;
2320 +
2321 + $extra_fields = unserialize( $field->extra_fields );
2322 +
2323 + if ( $extra_fields['date_format'] == '' ) {
2324 + $extra_fields['date_format'] = 'yy-mm-dd';
2325 + }
2326 +
2327 + $date_format = $extra_fields['date_format'];
2328 + $jquery_date_format = $date_format;
2329 +
2330 + // check if we need to change the format or not
2331 + $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2332 + if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2333 +
2334 + $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2335 + $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2336 +
2337 + $date_format = str_replace( $search, $replace, $date_format );
2338 + } else {
2339 + $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2340 + }
2341 +
2342 + if ( ! empty( $value ) && ! is_string( $value ) ) {
2343 + $value = date( 'Y-m-d', $value );
2344 + }
2345 +
2346 + if ( $value == '0000-00-00' ) {
2347 + $value = '';
2348 + }//if date not set, then mark it empty
2349 + $value = uwp_date( $value, 'Y-m-d', $date_format );
2350 + $site_title = uwp_get_form_label( $field );
2351 +
2352 + // bootstrap
2353 + if ( $design_style ) {
2354 + // flatpickr attributes
2355 + $extra_attributes['data-alt-input'] = 'true';
2356 + $extra_attributes['data-alt-format'] = $date_format;
2357 + $extra_attributes['data-date-format'] = 'Y-m-d';
2358 +
2359 + if ( 'dob' == $field->htmlvar_name ) {
2360 + $extra_attributes['data-max-date'] = 'today';
1221 2361 }
2362 +
2363 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2364 +
2365 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2366 + array(
2367 + 'id' => esc_attr( $field->htmlvar_name ),
2368 + 'name' => esc_attr( $field->htmlvar_name ),
2369 + 'required' => ! empty( $field->is_required ) ? true : false,
2370 + 'label' => wp_kses_post( $site_title . $required ),
2371 + 'label_show' => true,
2372 + 'label_type' => 'hidden',
2373 + 'type' => 'datepicker',
2374 + 'title' => esc_html( $site_title ),
2375 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2376 + 'class' => '',
2377 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2378 + 'value' => esc_attr( $value ),
2379 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2380 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2381 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2382 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2383 + )
2384 + );
2385 + } else {
2386 + ?>
2387 + <script type="text/javascript">
2388 +
2389 + jQuery(function () {
2390 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2391 + changeMonth: true, changeYear: true
2392 + <?php
2393 + if ( $field->htmlvar_name == 'dob' ) {
2394 + echo ", yearRange: '1900:+0'";
2395 + } else {
2396 + echo ", yearRange: '1900:2050'";
2397 + }
2398 + ?>
2399 + <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2400 +
2401 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2402 +
2403 + <?php if ( ! empty( $value ) ) { ?>
2404 + var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2405 + jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2406 + <?php } ?>
2407 +
2408 + });
2409 +
2410 + </script>
2411 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2412 + class="
2413 + <?php
2414 + if ( $field->is_required ) {
2415 + echo 'required_field';
2416 + }
2417 + ?>
2418 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2419 +
2420 + <?php
2421 +
2422 + if ( ! is_admin() ) {
2423 + ?>
2424 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2425 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2426 + <?php
2427 + if ( $field->is_required ) {
2428 + echo '<span>*</span>';
2429 + }
2430 + ?>
2431 + </label>
2432 + <?php } ?>
2433 +
2434 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2435 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2436 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2437 + title="<?php echo esc_attr( $site_title ); ?>"
2438 + type="text"
2439 + <?php
2440 + if ( $field->is_required == 1 ) {
2441 + echo 'required="required"';
2442 + }
2443 + ?>
2444 + value="<?php echo esc_attr( $value ); ?>"
2445 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2446 +
2447 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2448 + <?php if ( $field->is_required ) { ?>
2449 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2450 + <?php } ?>
2451 + </div>
2452 +
2453 + <?php
1222 2454 }
1223 - }
1224 2455
1225 - if (is_admin()) {
1226 - if ($user_id == get_current_user_id()) {
1227 - $profile_url = admin_url( 'profile.php' );
1228 - } else {
1229 - $profile_url = admin_url( 'user-edit.php?user_id='.$user_id );
1230 - }
1231 - } else {
1232 - $profile_url = uwp_build_profile_tab_url($user_id);
1233 - }
1234 - return $profile_url;
2456 + $html = ob_get_clean();
2457 + }
1235 2458
1236 - }
2459 + return $html;
2460 + }
1237 2461
1238 - /**
1239 - * Saves UsersWP related user custom fields.
1240 - *
1241 - * @since 1.0.0
1242 - * @package userswp
1243 - *
1244 - * @param int $user_id User ID.
1245 - * @param array $data Result array.
1246 - * @param string $type Form type.
1247 - *
1248 - * @return bool True when success. False when failure.
1249 - */
1250 - public function uwp_save_user_extra_fields($user_id, $data, $type) {
2462 + /**
2463 + * Form field template for time field type.
2464 + *
2465 + * @param string $html Form field html
2466 + * @param object $field Field info.
2467 + * @param string $value Form field default value.
2468 + * @param string $form_type Form type
2469 + *
2470 + * @return string Modified form field html.
2471 + * @package userswp
2472 + *
2473 + * @since 1.0.0
2474 + */
2475 + public function form_input_time( $html, $field, $value, $form_type ) {
1251 2476
1252 - if (empty($user_id) || empty($data) || empty($type)) {
1253 - return false;
1254 - }
2477 + if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
1255 2478
1256 - // custom user fields not applicable for login and forgot
1257 - if ($type == 'login' || $type == 'forgot') {
1258 - return true;
1259 - }
1260 -
2479 + $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2480 + }
1261 2481
1262 - if ($type == 'account' || $type == 'register') {
1263 - if (isset($data['password'])) {
1264 - unset($data['password']);
1265 - }
1266 - }
2482 + // If no html then we run the standard output.
2483 + if ( empty( $html ) ) {
1267 2484
1268 - if ($type == 'register') {
1269 - if (isset($data['uwp_account_username'])) {
1270 - unset($data['uwp_account_username']);
1271 - }
1272 - if (isset($data['uwp_account_email'])) {
1273 - unset($data['uwp_account_email']);
1274 - }
1275 - if (isset($data['uwp_account_display_name'])) {
1276 - unset($data['uwp_account_display_name']);
1277 - }
1278 - if (isset($data['uwp_account_first_name'])) {
1279 - unset($data['uwp_account_first_name']);
1280 - }
1281 - if (isset($data['uwp_account_last_name'])) {
1282 - unset($data['uwp_account_last_name']);
1283 - }
1284 - if (isset($data['uwp_account_bio'])) {
1285 - unset($data['uwp_account_bio']);
1286 - }
1287 - }
2485 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2486 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2487 + $bs_sr_only = $design_style ? 'sr-only' : '';
2488 + $bs_form_control = $design_style ? 'form-control bg-white' : '';
2489 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2490 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1288 2491
1289 - if (empty($data)) {
1290 - // no extra fields. so just return
1291 - return true;
1292 - } else {
1293 - foreach($data as $key => $value) {
1294 - uwp_update_usermeta($user_id, $key, $value);
1295 - }
1296 - return true;
1297 - }
1298 - }
2492 + ob_start(); // Start buffering;
1299 2493
1300 - /**
1301 - * Logs the error message.
1302 - *
1303 - * @since 1.0.0
1304 - * @package userswp
1305 - *
1306 - * @param array|object|string $log Error message.
1307 - *
1308 - * @return void
1309 - */
1310 - public static function uwp_error_log($log){
2494 + if ( $value != '' ) {
2495 + $value = date( 'H:i', strtotime( $value ) );
2496 + }
1311 2497
1312 - $should_log = apply_filters( 'uwp_log_errors', WP_DEBUG);
1313 - if ( true === $should_log ) {
1314 - if ( is_array( $log ) || is_object( $log ) ) {
1315 - error_log( print_r( $log, true ) );
1316 - } else {
1317 - error_log( $log );
1318 - }
1319 - }
1320 - }
2498 + // flatpickr attributes
2499 + $extra_attributes['data-enable-time'] = 'true';
2500 + $extra_attributes['data-no-calendar'] = 'true';
2501 + $extra_attributes['data-date-format'] = 'H:i';
2502 + $site_title = uwp_get_form_label( $field );
2503 + $label_type = is_admin() ? '' : 'top';
1321 2504
1322 - /**
1323 - *
1324 - *
1325 - * @since 1.0.0
1326 - * @since 1.0.12 Unlink file.
1327 - * @package userswp
1328 - * @return void
1329 - */
1330 - public function uwp_upload_file_remove() {
2505 + if ( $design_style ) {
2506 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1331 2507
1332 - $htmlvar = strip_tags(esc_sql($_POST['htmlvar']));
1333 - $user_id = (int) strip_tags(esc_sql($_POST['uid']));
1334 - $permission = false;
1335 - if ($user_id == get_current_user_id()) {
1336 - $permission = true;
1337 - } else {
1338 - if (current_user_can('manage_options')) {
1339 - $permission = true;
1340 - }
1341 - }
1342 - if ($permission) {
1343 - // Remove file
1344 - if ($htmlvar == "uwp_account_banner_thumb") {
1345 - $file = uwp_get_usermeta($user_id, 'uwp_account_banner_thumb');
1346 - $type = 'banner';
1347 - } elseif ($htmlvar == "uwp_account_avatar_thumb") {
1348 - $file = uwp_get_usermeta($user_id, 'uwp_account_avatar_thumb');
1349 - $type = 'avatar';
2508 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2509 + array(
2510 + 'id' => esc_attr( $field->htmlvar_name ),
2511 + 'name' => esc_attr( $field->htmlvar_name ),
2512 + 'required' => ! empty( $field->is_required ) ? true : false,
2513 + 'label' => wp_kses_post( $site_title . $required ),
2514 + 'label_show' => true,
2515 + 'label_type' => esc_attr( $label_type ),
2516 + 'type' => 'timepicker',
2517 + 'title' => esc_html( $site_title ),
2518 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2519 + 'class' => '',
2520 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2521 + 'value' => esc_attr( $value ),
2522 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2523 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2524 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2525 + 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2526 + 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2527 + )
2528 + );
1350 2529 } else {
1351 - $file = '';
1352 - $type = '';
2530 + ?>
2531 + <script type="text/javascript">
2532 + jQuery(document).ready(function () {
2533 + jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2534 + showPeriod: true,
2535 + showLeadingZero: true
2536 + });
2537 + });
2538 + </script>
2539 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2540 + class="
2541 + <?php
2542 + if ( $field->is_required ) {
2543 + echo 'required_field';
2544 + }
2545 + ?>
2546 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2547 +
2548 + <?php
2549 + $site_title = uwp_get_form_label( $field );
2550 + if ( ! is_admin() ) {
2551 + ?>
2552 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2553 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2554 + <?php
2555 + if ( $field->is_required ) {
2556 + echo '<span>*</span>';
2557 + }
2558 + ?>
2559 + </label>
2560 + <?php } ?>
2561 +
2562 + <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2563 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2564 + value="<?php echo esc_attr( $value ); ?>"
2565 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2566 + type="text"
2567 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2568 +
2569 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2570 + <?php if ( $field->is_required ) { ?>
2571 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2572 + <?php } ?>
2573 + </div>
2574 + <?php
1353 2575 }
2576 + $html = ob_get_clean();
2577 + }
1354 2578
1355 - uwp_update_usermeta($user_id, $htmlvar, '');
2579 + return $html;
2580 + }
1356 2581
1357 - if ($file) {
1358 - $uploads = wp_upload_dir();
1359 - $upload_path = $uploads['basedir'];
1360 - $unlink_file = untrailingslashit($upload_path) . '/' . ltrim($file, '/');
2582 + /**
2583 + * Form field template for select field type.
2584 + *
2585 + * @param string $html Form field html
2586 + * @param object $field Field info.
2587 + * @param string $value Form field default value.
2588 + * @param string $form_type Form type
2589 + *
2590 + * @return string Modified form field html.
2591 + * @package userswp
2592 + *
2593 + * @since 1.0.0
2594 + */
2595 + public function form_input_select( $html, $field, $value, $form_type ) {
1361 2596
1362 - if (is_file($unlink_file) && file_exists($unlink_file)) {
1363 - @unlink($unlink_file);
1364 - $unlink_ori_file = str_replace('_uwp_'.$type.'_thumb'.'.', '.', $unlink_file);
1365 - if (is_file($unlink_ori_file) && file_exists($unlink_ori_file)) {
1366 - @unlink($unlink_ori_file);
2597 + // Check if there is a field specific filter.
2598 + if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2599 + $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2600 + }
2601 +
2602 + // Check if there is a field type specific filter.
2603 + if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2604 + $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2605 + }
2606 +
2607 + // If no html then we run the standard output.
2608 + if ( empty( $html ) ) {
2609 +
2610 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2611 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2612 + $bs_sr_only = $design_style ? 'sr-only' : '';
2613 + $bs_form_control = $design_style ? 'form-control' : '';
2614 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2615 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2616 +
2617 + ob_start(); // Start buffering;
2618 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2619 + $site_title = uwp_get_form_label( $field );
2620 +
2621 + // bootstrap
2622 + if ( $design_style ) {
2623 +
2624 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2625 +
2626 + echo aui()->select(
2627 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2628 + 'id' => esc_attr( $field->htmlvar_name ),
2629 + 'name' => esc_attr( $field->htmlvar_name ),
2630 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2631 + 'title' => esc_html( $site_title ),
2632 + 'value' => esc_attr( $value ),
2633 + 'required' => (bool) $field->is_required,
2634 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2635 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2636 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2637 + 'label' => wp_kses_post( $site_title . $required ),
2638 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2639 + 'select2' => true,
2640 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2641 + )
2642 + );
2643 + } else {
2644 + ?>
2645 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2646 + class="
2647 + <?php
2648 + if ( $field->is_required ) {
2649 + echo 'required_field';
1367 2650 }
1368 - }
2651 + ?>
2652 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2653 +
2654 + <?php
2655 + if ( ! is_admin() ) {
2656 + ?>
2657 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2658 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2659 + <?php
2660 + if ( $field->is_required ) {
2661 + echo '<span>*</span>';
2662 + }
2663 + ?>
2664 + </label>
2665 + <?php } ?>
2666 +
2667 + <?php
2668 +
2669 + $select_options = '';
2670 + if ( ! empty( $option_values_arr ) ) {
2671 + foreach ( $option_values_arr as $option_row ) {
2672 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2673 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2674 +
2675 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2676 + } else {
2677 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2678 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2679 + $selected = $option_value == $value ? 'selected="selected"' : '';
2680 +
2681 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2682 + }
2683 + }
2684 + }
2685 + ?>
2686 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2687 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2688 + title="<?php echo esc_attr( $site_title ); ?>"
2689 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2690 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2691 + </select>
2692 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2693 + <?php if ( $field->is_required ) { ?>
2694 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2695 + <?php } ?>
2696 + </div>
2697 +
2698 + <?php
1369 2699 }
1370 - }
1371 - die();
1372 - }
1373 -
1374 -
1375 - /**
1376 - * Form field template for datepicker field type.
1377 - *
1378 - * @since 1.0.0
1379 - * @package userswp
1380 - *
1381 - * @param string $html Form field html
1382 - * @param object $field Field info.
1383 - * @param string $value Form field default value.
1384 - * @param string $form_type Form type
1385 - *
1386 - * @return string Modified form field html.
1387 - */
1388 - public function uwp_form_input_datepicker($html, $field, $value, $form_type){
2700 + $html = ob_get_clean();
2701 + }
1389 2702
1390 - // Check if there is a field specific filter.
1391 - if(has_filter("uwp_form_input_html_datepicker_{$field->htmlvar_name}")){
1392 - $html = apply_filters("uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1393 - }
2703 + return $html;
2704 + }
1394 2705
1395 - // If no html then we run the standard output.
1396 - if(empty($html)) {
2706 + /**
2707 + * Form field template for multiselect field type.
2708 + *
2709 + * @param string $html Form field html
2710 + * @param object $field Field info.
2711 + * @param string $value Form field default value.
2712 + * @param string $form_type Form type
2713 + *
2714 + * @return string Modified form field html.
2715 + * @package userswp
2716 + *
2717 + * @since 1.0.0
2718 + */
2719 + public function form_input_multiselect( $html, $field, $value, $form_type ) {
1397 2720
1398 - ob_start(); // Start buffering;
2721 + // Check if there is a field specific filter.
2722 + if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
2723 + $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2724 + }
1399 2725
1400 - $extra_fields = unserialize($field->extra_fields);
2726 + if ( empty( $html ) ) {
1401 2727
1402 - if ($extra_fields['date_format'] == '')
1403 - $extra_fields['date_format'] = 'yy-mm-dd';
2728 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2729 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2730 + $bs_sr_only = $design_style ? 'sr-only' : '';
2731 + $bs_form_control = $design_style ? 'form-control' : '';
2732 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2733 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1404 2734
1405 - $date_format = $extra_fields['date_format'];
1406 - $jquery_date_format = $date_format;
2735 + ob_start(); // Start buffering;
1407 2736
1408 - if (!empty($value) && !is_string($value)) {
1409 - $value = date('Y-m-d', $value);
1410 - }
2737 + $multi_display = 'select';
2738 + if ( ! empty( $field->extra_fields ) ) {
2739 + $multi_display = unserialize( $field->extra_fields );
2740 + }
1411 2741
2742 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2743 + $site_title = uwp_get_form_label( $field );
2744 + $value = is_array( $value ) ? $value : esc_attr( $value );
1412 2745
1413 - // check if we need to change the format or not
1414 - $date_format_len = strlen(str_replace(' ', '', $date_format));
1415 - if($date_format_len>5){// if greater then 5 then it's the old style format.
2746 + // bootstrap
2747 + if ( $design_style ) {
1416 2748
1417 - $search = array('dd','d','DD','mm','m','MM','yy'); //jQuery UI datepicker format
1418 - $replace = array('d','j','l','m','n','F','Y');//PHP date format
2749 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1419 2750
1420 - $date_format = str_replace($search, $replace, $date_format);
1421 - }else{
1422 - $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
1423 - }
1424 - if($value=='0000-00-00'){$value='';}//if date not set, then mark it empty
1425 - $value = uwp_date($value, 'Y-m-d', $date_format);
1426 - ?>
1427 - <script type="text/javascript">
2751 + echo aui()->select(
2752 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2753 + 'id' => esc_attr( $field->htmlvar_name ),
2754 + 'name' => esc_attr( $field->htmlvar_name ),
2755 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2756 + 'title' => esc_html( $site_title ),
2757 + 'value' => $value,
2758 + 'required' => (bool) $field->is_required,
2759 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2760 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2761 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2762 + 'label' => wp_kses_post( $site_title . $required ),
2763 + 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2764 + 'select2' => true,
2765 + 'multiple' => true,
2766 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2767 + )
2768 + );
2769 + } else {
2770 + ?>
2771 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2772 + class="
2773 + <?php
2774 + if ( $field->is_required ) {
2775 + echo 'required_field';
2776 + }
2777 + ?>
2778 + uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1428 2779
1429 - jQuery(function () {
2780 + <?php
2781 + if ( ! is_admin() ) {
2782 + ?>
2783 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2784 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2785 + <?php
2786 + if ( $field->is_required ) {
2787 + echo '<span>*</span>';
2788 + }
2789 + ?>
2790 + </label>
2791 + <?php } ?>
1430 2792
1431 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker({changeMonth: true, changeYear: true
1432 - <?php if($field->htmlvar_name == 'uwp_account_dob'){ echo ", yearRange: '1900:+0'"; } else { echo ", yearRange: '1900:2050'"; }?>
1433 - <?php echo apply_filters("uwp_datepicker_extra_{$field->htmlvar_name}",'');?>});
2793 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
2794 + <?php if ( $multi_display == 'select' ) { ?>
2795 + <div class="uwp_multiselect_list">
2796 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
2797 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2798 + title="<?php echo esc_attr( $site_title ); ?>"
2799 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2800 + class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2801 + >
2802 + <?php
2803 + } else {
2804 + ?>
2805 + <ul class="uwp_multi_choice">
2806 + <?php
2807 + }
1434 2808
1435 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("option", "dateFormat", '<?php echo $jquery_date_format;?>');
2809 + $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2810 + $select_options = '';
2811 + if ( ! empty( $option_values_arr ) ) {
2812 + foreach ( $option_values_arr as $option_row ) {
2813 + if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2814 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
1436 2815
1437 - <?php if(!empty($value)){?>
1438 - var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo $value;?>');
1439 - jQuery("#<?php echo $field->htmlvar_name;?>").datepicker("setDate", parsedDate);
1440 - <?php } ?>
2816 + if ( $multi_display == 'select' ) {
2817 + $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2818 + } else {
2819 + $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
2820 + }
2821 + } else {
2822 + $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2823 + $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2824 + $selected = $option_value == $value ? 'selected="selected"' : '';
2825 + $checked = '';
1441 2826
1442 - });
2827 + if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
2828 + if ( ! is_array( $value ) ) {
2829 + $value_array = explode( ',', $value );
2830 + } else {
2831 + $value_array = $value;
2832 + }
1443 2833
1444 - </script>
1445 - <div id="<?php echo $field->htmlvar_name;?>_row"
1446 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp_clear uwp-fieldset-details">
2834 + if ( is_array( $value_array ) ) {
2835 + if ( in_array( $option_value, $value_array ) ) {
2836 + $selected = 'selected="selected"';
2837 + $checked = 'checked="checked"';
2838 + }
2839 + }
2840 + }
1447 2841
2842 + if ( $multi_display == 'select' ) {
2843 + $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2844 + } else {
2845 + $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
2846 + }
2847 + }
2848 + }
2849 + }
2850 + echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2851 +
2852 + if ( $multi_display == 'select' ) {
2853 +
2854 + ?>
2855 + </select></div>
2856 + <?php } else { ?>
2857 + </ul>
2858 + <?php } ?>
2859 + <?php if ( $field->is_required ) { ?>
2860 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2861 + <?php } ?>
2862 + </div>
2863 + <?php
2864 + }
2865 + $html = ob_get_clean();
2866 + }
2867 +
2868 + return $html;
2869 + }
2870 +
2871 + /**
2872 + * Form field template for file field type.
2873 + *
2874 + * @param string $html Form field html
2875 + * @param object $field Field info.
2876 + * @param string $value Form field default value.
2877 + * @param string $form_type Form type
2878 + *
2879 + * @return string Modified form field html.
2880 + * @package userswp
2881 + *
2882 + * @since 1.0.0
2883 + */
2884 + public function form_input_file( $html, $field, $value, $form_type ) {
2885 +
2886 + $file_obj = new UsersWP_Files();
2887 +
2888 + // Check if there is a field specific filter.
2889 + if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
2890 + $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2891 + }
2892 +
2893 + // If no html then we run the standard output.
2894 + if ( empty( $html ) ) {
2895 +
2896 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2897 + $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
2898 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
2899 + $bs_sr_only = $design_style ? 'sr-only' : '';
2900 + $bs_form_control = $design_style ? 'form-control' : '';
2901 +
2902 + ob_start(); // Start buffering;
2903 +
2904 + ?>
2905 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2906 + class="
1448 2907 <?php
1449 - $site_title = uwp_get_form_label($field);
1450 - if (!is_admin()) { ?>
1451 - <label>
1452 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1453 - <?php if ($field->is_required) echo '<span>*</span>';?>
1454 - </label>
1455 - <?php } ?>
2908 + if ( $field->is_required ) {
2909 + echo 'required_field';
2910 + }
2911 + ?>
2912 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
1456 2913
1457 - <input name="<?php echo $field->htmlvar_name;?>"
1458 - id="<?php echo $field->htmlvar_name;?>"
1459 - placeholder="<?php echo $site_title; ?>"
1460 - title="<?php echo $site_title; ?>"
1461 - type="text"
1462 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1463 - value="<?php echo esc_attr($value);?>" class="uwp_textfield"/>
2914 + <?php
2915 + $site_title = uwp_get_form_label( $field );
2916 + if ( ! is_admin() && ! wp_doing_ajax() ) {
2917 + ?>
2918 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2919 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2920 + <?php
2921 + if ( $field->is_required ) {
2922 + echo ' <span class="text-danger">*</span>';
2923 + }
2924 + ?>
2925 + </label>
2926 + <?php } ?>
1464 2927
1465 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1466 - <?php if ($field->is_required) { ?>
1467 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1468 - <?php } ?>
1469 - </div>
2928 + <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2929 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2930 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
2931 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2932 + title="<?php echo esc_attr( $site_title ); ?>"
2933 + <?php
2934 + if ( $field->is_required == 1 ) {
2935 + echo 'data-is-required="1"';
2936 + }
2937 + if ( $field->is_required == 1 && ! $value ) {
2938 + echo 'required="required"';
2939 + }
2940 + ?>
2941 + type="<?php echo esc_attr( $field->field_type ); ?>">
2942 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2943 + <?php if ( $field->is_required ) { ?>
2944 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2945 + <?php } ?>
2946 + </div>
1470 2947
1471 - <?php
1472 - $html = ob_get_clean();
1473 - }
2948 + <?php
2949 + $html = ob_get_clean();
2950 + }
1474 2951
1475 - return $html;
1476 - }
2952 + return $html;
2953 + }
1477 2954
1478 - /**
1479 - * Form field template for time field type.
1480 - *
1481 - * @since 1.0.0
1482 - * @package userswp
1483 - *
1484 - * @param string $html Form field html
1485 - * @param object $field Field info.
1486 - * @param string $value Form field default value.
1487 - * @param string $form_type Form type
1488 - *
1489 - * @return string Modified form field html.
1490 - */
1491 - public function uwp_form_input_time($html, $field, $value, $form_type){
2955 + /**
2956 + * Form field template for checkbox field type.
2957 + *
2958 + * @param string $html Form field html
2959 + * @param object $field Field info.
2960 + * @param string $value Form field default value.
2961 + * @param string $form_type Form type
2962 + *
2963 + * @return string Modified form field html.
2964 + * @package userswp
2965 + *
2966 + * @since 1.0.0
2967 + */
2968 + public function form_input_checkbox( $html, $field, $value, $form_type ) {
1492 2969
1493 - if(has_filter("uwp_form_input_html_time_{$field->htmlvar_name}")){
2970 + // Check if there is a field specific filter.
2971 + if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
2972 + $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2973 + }
1494 2974
1495 - $html = apply_filters("uwp_form_input_html_time_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1496 - }
2975 + // If no html then we run the standard output.
2976 + if ( empty( $html ) ) {
1497 2977
1498 - // If no html then we run the standard output.
1499 - if(empty($html)) {
2978 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2979 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
2980 + $bs_sr_only = $design_style ? 'form-check-label' : '';
2981 + $bs_form_control = $design_style ? 'form-check-input' : '';
1500 2982
1501 - ob_start(); // Start buffering;
2983 + ob_start(); // Start buffering;
2984 + $site_title = uwp_get_form_label( $field );
1502 2985
1503 - if ($value != '')
1504 - $value = date('H:i', strtotime($value));
1505 - ?>
1506 - <script type="text/javascript">
1507 - jQuery(document).ready(function () {
2986 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2987 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
1508 2988
1509 - jQuery('#<?php echo $field->htmlvar_name;?>').timepicker({
1510 - showPeriod: true,
1511 - showLeadingZero: true
1512 - });
1513 - });
1514 - </script>
1515 - <div id="<?php echo $field->htmlvar_name;?>_row"
1516 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row clearfix uwp_clear uwp-fieldset-details">
2989 + $checked = $value == '1' ? true : false;
1517 2990
1518 - <?php
1519 - $site_title = uwp_get_form_label($field);
1520 - if (!is_admin()) { ?>
1521 - <label>
1522 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1523 - <?php if ($field->is_required) echo '<span>*</span>';?>
1524 - </label>
1525 - <?php } ?>
2991 + // bootstrap
2992 + if ( $design_style ) {
2993 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1526 2994
1527 - <input readonly="readonly" name="<?php echo $field->htmlvar_name;?>"
1528 - id="<?php echo $field->htmlvar_name;?>"
1529 - value="<?php echo esc_attr($value);?>"
1530 - placeholder="<?php echo $site_title; ?>"
1531 - type="text"
1532 - class="uwp_textfield"/>
2995 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
1533 2996
1534 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1535 - <?php if ($field->is_required) { ?>
1536 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1537 - <?php } ?>
1538 - </div>
1539 - <?php
1540 - $html = ob_get_clean();
1541 - }
2997 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2998 + array(
2999 + 'id' => esc_attr( $id ),
3000 + 'name' => esc_attr( $field->htmlvar_name ),
3001 + 'type' => 'checkbox',
3002 + 'value' => '1',
3003 + 'title' => esc_html( $site_title ),
3004 + 'label' => wp_kses_post( $site_title . $required ),
3005 + 'label_show' => true,
3006 + 'required' => ! empty( $field->is_required ) ? true : false,
3007 + 'checked' => (bool) $checked,
3008 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3009 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3010 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3011 + )
3012 + );
1542 3013
1543 - return $html;
1544 - }
3014 + } else {
3015 + ?>
3016 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3017 + class="
3018 + <?php
3019 + if ( $field->is_required ) {
3020 + echo 'required_field';
3021 + }
3022 + ?>
3023 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3024 + <?php if ( ! empty( $design_style ) ) { ?>
3025 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3026 + <?php } ?>
3027 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3028 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3029 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3030 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3031 + title="<?php echo esc_attr( $site_title ); ?>"
3032 + <?php
3033 + if ( $field->is_required == 1 ) {
3034 + echo 'required="required"';
3035 + }
3036 + ?>
3037 + <?php
3038 + if ( $value == '1' ) {
3039 + echo 'checked="checked"';
3040 + }
3041 + ?>
3042 + type="<?php echo esc_attr( $field->field_type ); ?>"
3043 + value="1">
3044 + <?php
3045 + echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3046 + ?>
3047 + <?php if ( ! empty( $design_style ) ) { ?>
3048 + </label>
3049 + <?php } ?>
3050 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3051 + <?php if ( $field->is_required ) { ?>
3052 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3053 + <?php } ?>
3054 + </div>
1545 3055
1546 - /**
1547 - * Form field template for select field type.
1548 - *
1549 - * @since 1.0.0
1550 - * @package userswp
1551 - *
1552 - * @param string $html Form field html
1553 - * @param object $field Field info.
1554 - * @param string $value Form field default value.
1555 - * @param string $form_type Form type
1556 - *
1557 - * @return string Modified form field html.
1558 - */
1559 - public function uwp_form_input_select($html, $field, $value, $form_type){
3056 + <?php
1560 3057
1561 - // Check if there is a field specific filter.
1562 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
1563 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1564 - }
3058 + }
1565 3059
1566 - // Check if there is a field type specific filter.
1567 - if(has_filter("uwp_form_input_html_select_{$field->field_type_key}")){
1568 - $html = apply_filters("uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type);
1569 - }
3060 + $html = ob_get_clean();
1570 3061
1571 - // If no html then we run the standard output.
1572 - if(empty($html)) {
3062 + }
1573 3063
1574 - ob_start(); // Start buffering;
3064 + return $html;
3065 + }
1575 3066
1576 - ?>
1577 - <div id="<?php echo $field->htmlvar_name;?>_row"
1578 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
3067 + /**
3068 + * Form field template for radio field type.
3069 + *
3070 + * @param string $html Form field html
3071 + * @param object $field Field info.
3072 + * @param string $value Form field default value.
3073 + * @param string $form_type Form type
3074 + *
3075 + * @return string Modified form field html.
3076 + * @package userswp
3077 + *
3078 + * @since 1.0.0
3079 + */
3080 + public function form_input_radio( $html, $field, $value, $form_type ) {
1579 3081
1580 - <?php
1581 - $site_title = uwp_get_form_label($field);
1582 - if (!is_admin()) { ?>
1583 - <label>
1584 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1585 - <?php if ($field->is_required) echo '<span>*</span>';?>
1586 - </label>
1587 - <?php } ?>
3082 + // Check if there is a field specific filter.
3083 + if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3084 + $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3085 + }
1588 3086
1589 - <?php
1590 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1591 - $select_options = '';
1592 - if (!empty($option_values_arr)) {
1593 - foreach ($option_values_arr as $option_row) {
1594 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1595 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
3087 + // If no html then we run the standard output.
3088 + if ( empty( $html ) ) {
1596 3089
1597 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1598 - } else {
1599 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1600 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1601 - $selected = $option_value == $value ? 'selected="selected"' : '';
3090 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3091 + $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3092 + $bs_sr_only = $design_style ? 'sr-only' : '';
3093 + $bs_label_class = $design_style ? 'form-check-label' : '';
3094 + $bs_form_control = $design_style ? 'form-check-input' : '';
1602 3095
1603 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1604 - }
3096 + ob_start(); // Start buffering;
3097 +
3098 + if ( $design_style ) {
3099 +
3100 + $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3101 + $option_values = array();
3102 + if ( ! empty( $option_values_deep ) ) {
3103 + foreach ( $option_values_deep as $option ) {
3104 + $option_values[ $option['value'] ] = $option['label'];
3105 + }
3106 + }
3107 +
3108 + $site_title = uwp_get_form_label( $field );
3109 +
3110 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3111 +
3112 + echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3113 + array(
3114 + 'id' => esc_attr( $field->htmlvar_name ),
3115 + 'name' => esc_attr( $field->htmlvar_name ),
3116 + 'type' => 'radio',
3117 + 'title' => esc_html( $site_title ),
3118 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3119 + 'label_type' => 'top',
3120 + 'class' => '',
3121 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3122 + 'value' => esc_attr( $value ),
3123 + 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3124 + )
3125 + );
3126 +
3127 + } else {
3128 +
3129 + ?>
3130 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3131 + class="
3132 + <?php
3133 + if ( $field->is_required ) {
3134 + echo 'required_field';
3135 + }
3136 + ?>
3137 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3138 +
3139 + <?php
3140 + $site_title = uwp_get_form_label( $field );
3141 + if ( ! is_admin() ) {
3142 + ?>
3143 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3144 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3145 + <?php
3146 + if ( $field->is_required ) {
3147 + echo '<span>*</span>';
3148 + }
3149 + ?>
3150 + </label>
3151 + <?php } ?>
3152 +
3153 + <?php
3154 + if ( $field->option_values ) {
3155 + $option_values = uwp_string_values_to_options( $field->option_values, true );
3156 +
3157 + if ( ! empty( $option_values ) ) {
3158 + $count = 0;
3159 + foreach ( $option_values as $option_value ) {
3160 + if ( empty( $option_value['optgroup'] ) ) {
3161 + ++$count;
3162 + if ( $count == 1 ) {
3163 + $class = 'uwp-radio-first';
3164 + } else {
3165 + $class = '';
3166 + }
3167 + ?>
3168 + <?php if ( ! empty( $design_style ) ) { ?>
3169 + <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3170 + <?php } else { ?>
3171 + <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3172 + <?php } ?>
3173 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3174 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3175 + title="<?php echo esc_attr( $option_value['label'] ); ?>"
3176 + <?php checked( $value, $option_value['value'] ); ?>
3177 + <?php
3178 + if ( $field->is_required == 1 ) {
3179 + echo 'required="required"';
3180 + }
3181 + ?>
3182 + value="<?php echo esc_attr( $option_value['value'] ); ?>"
3183 + class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3184 + <?php echo esc_html( $option_value['label'] ); ?>
3185 + <?php if ( ! empty( $design_style ) ) { ?>
3186 + </label>
3187 + <?php } else { ?>
3188 + </span>
3189 + <?php
3190 + }
3191 + }
3192 + }
3193 + }
3194 + }
3195 + ?>
3196 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3197 + <?php if ( $field->is_required ) { ?>
3198 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3199 + <?php } ?>
3200 + </div>
3201 + <?php
3202 + }
3203 +
3204 + $html = ob_get_clean();
3205 + }
3206 +
3207 + return $html;
3208 + }
3209 +
3210 + /**
3211 + * Form field template for text field type.
3212 + *
3213 + * @param string $html Form field html
3214 + * @param object $field Field info.
3215 + * @param string $value Form field default value.
3216 + * @param string $form_type Form type
3217 + *
3218 + * @return string Modified form field html.
3219 + * @package userswp
3220 + *
3221 + * @since 1.0.0
3222 + */
3223 + public function form_input_text( $html, $field, $value, $form_type ) {
3224 +
3225 + // Check if there is a custom field specific filter.
3226 + if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3227 + $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3228 + }
3229 +
3230 + // If no html then we run the standard output.
3231 + if ( empty( $html ) ) {
3232 +
3233 + ob_start(); // Start buffering;
3234 +
3235 + $type = 'text';
3236 + $step = false;
3237 + //number and float validation $validation_pattern
3238 + if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3239 + $type = 'number';
3240 + } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3241 + $dp = $field->decimal_point;
3242 + switch ( $dp ) {
3243 + case '1':
3244 + $step = '0.1';
3245 + break;
3246 + case '2':
3247 + $step = '0.01';
3248 + break;
3249 + case '3':
3250 + $step = '0.001';
3251 + break;
3252 + case '4':
3253 + $step = '0.0001';
3254 + break;
3255 + case '5':
3256 + $step = '0.00001';
3257 + break;
3258 + case '6':
3259 + $step = '0.000001';
3260 + break;
3261 + case '7':
3262 + $step = '0.0000001';
3263 + break;
3264 + case '8':
3265 + $step = '0.00000001';
3266 + break;
3267 + case '9':
3268 + $step = '0.000000001';
3269 + break;
3270 + case '10':
3271 + $step = '0.0000000001';
3272 + break;
3273 + default:
3274 + $step = '0.01';
3275 + break;
3276 + }
3277 + $type = 'number';
3278 + }
3279 +
3280 + $site_title = uwp_get_form_label( $field );
3281 + $placeholder = uwp_get_field_placeholder( $field );
3282 + $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3283 + if ( $manual_label
3284 + && isset( $field->form_type )
3285 + && $field->form_type == 'login'
3286 + && $field->htmlvar_name == 'username' ) {
3287 + $site_title = __( 'Username or Email', 'userswp' );
3288 + $required = ! empty( $field->is_required ) ? ' *' : '';
3289 + $placeholder = $site_title . $required;
3290 + $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3291 + }
3292 +
3293 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3294 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3295 + $bs_sr_only = $design_style ? 'sr-only' : '';
3296 + $bs_form_control = $design_style ? 'form-control' : '';
3297 +
3298 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3299 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3300 +
3301 + // bootstrap
3302 + if ( $design_style ) {
3303 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3304 +
3305 + echo aui()->input(
3306 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3307 + 'type' => esc_attr( $type ),
3308 + 'id' => esc_attr( $field->htmlvar_name ),
3309 + 'name' => esc_attr( $field->htmlvar_name ),
3310 + 'placeholder' => esc_attr( $placeholder ),
3311 + 'title' => esc_html( $site_title ),
3312 + 'value' => esc_attr( wp_unslash( $value ) ),
3313 + 'required' => (bool) $field->is_required,
3314 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3315 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3316 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3317 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3318 + 'step' => esc_attr( $step ),
3319 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3320 + )
3321 + );
3322 + } else {
3323 + ?>
3324 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3325 + <?php
3326 + if ( $field->is_required ) {
3327 + echo 'required_field';
3328 + }
3329 + ?>
3330 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3331 + <?php
3332 +
3333 + if ( ! is_admin() ) {
3334 + ?>
3335 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3336 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3337 + <?php
3338 + if ( $field->is_required ) {
3339 + echo '<span>*</span>';
3340 + }
3341 + ?>
3342 + </label>
3343 + <?php
1605 3344 }
1606 - }
1607 - ?>
1608 - <select name="<?php echo $field->htmlvar_name;?>" id="<?php echo $field->htmlvar_name;?>"
1609 - class="uwp_textfield"
1610 - title="<?php echo $site_title; ?>"
1611 - data-placeholder="<?php echo __('Choose', 'userswp') . ' ' . $site_title . '&hellip;';?>"
1612 - ><?php echo $select_options;?>
1613 - </select>
1614 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1615 - <?php if ($field->is_required) { ?>
1616 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1617 - <?php } ?>
1618 - </div>
3345 + ?>
1619 3346
1620 - <?php
1621 - $html = ob_get_clean();
1622 - }
3347 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3348 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3349 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3350 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3351 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3352 + title="<?php echo esc_attr( $site_title ); ?>"
3353 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3354 + oninput="setCustomValidity('')"
3355 + <?php
3356 + if ( $field->is_required == 1 ) {
3357 + echo 'required="required"';
3358 + }
3359 + ?>
3360 + <?php
3361 + if ( $field->for_admin_use == 1 ) {
3362 + echo 'readonly="readonly"';
3363 + }
3364 + ?>
3365 + type="<?php echo esc_attr( $type ); ?>"
3366 + <?php
3367 + if ( $step ) {
3368 + echo 'step="' . esc_attr( $step ) . '"';
3369 + }
3370 + ?>
3371 + />
3372 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3373 + <?php if ( $field->is_required ) { ?>
3374 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3375 + <?php } ?>
3376 + </div>
1623 3377
1624 - return $html;
1625 - }
1626 3378
1627 - /**
1628 - * Form field template for multiselect field type.
1629 - *
1630 - * @since 1.0.0
1631 - * @package userswp
1632 - *
1633 - * @param string $html Form field html
1634 - * @param object $field Field info.
1635 - * @param string $value Form field default value.
1636 - * @param string $form_type Form type
1637 - *
1638 - * @return string Modified form field html.
1639 - */
1640 - public function uwp_form_input_multiselect($html, $field, $value, $form_type){
3379 + <?php
3380 + }
3381 + $html = ob_get_clean();
3382 + }
1641 3383
1642 - // Check if there is a field specific filter.
1643 - if(has_filter("uwp_form_input_html_multiselect_{$field->htmlvar_name}")){
1644 - $html = apply_filters("uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1645 - }
3384 + return $html;
3385 + }
1646 3386
3387 + /**
3388 + * Form field template for textarea field type.
3389 + *
3390 + * @param string $html Form field html
3391 + * @param object $field Field info.
3392 + * @param string $value Form field default value.
3393 + * @param string $form_type Form type
3394 + *
3395 + * @return string Modified form field html.
3396 + * @package userswp
3397 + *
3398 + * @since 1.0.0
3399 + */
3400 + public function form_input_textarea( $html, $field, $value, $form_type ) {
1647 3401
1648 - if(empty($html)) {
3402 + // Check if there is a field specific filter.
3403 + if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3404 + $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3405 + }
1649 3406
1650 - ob_start(); // Start buffering;
3407 + // If no html then we run the standard output.
3408 + if ( empty( $html ) ) {
1651 3409
1652 - $multi_display = 'select';
1653 - if (!empty($field->extra_fields)) {
1654 - $multi_display = unserialize($field->extra_fields);
1655 - }
1656 - ?>
1657 - <div id="<?php echo $field->htmlvar_name;?>_row"
1658 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
3410 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3411 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3412 + $bs_sr_only = $design_style ? 'sr-only' : '';
3413 + $bs_form_control = $design_style ? 'form-control' : '';
3414 + $site_title = uwp_get_form_label( $field );
1659 3415
1660 - <?php
1661 - $site_title = uwp_get_form_label($field);
1662 - if (!is_admin()) { ?>
1663 - <label>
1664 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1665 - <?php if ($field->is_required) echo '<span>*</span>';?>
1666 - </label>
1667 - <?php } ?>
3416 + ob_start(); // Start buffering;
1668 3417
1669 - <input type="hidden" name="<?php echo $field->htmlvar_name;?>" value=""/>
1670 - <?php if ($multi_display == 'select') { ?>
1671 - <div class="uwp_multiselect_list">
1672 - <select name="<?php echo $field->htmlvar_name;?>[]"
1673 - id="<?php echo $field->htmlvar_name;?>"
1674 - title="<?php echo $site_title; ?>"
1675 - multiple="multiple" class="uwp_chosen_select"
1676 - data-placeholder="<?php echo $site_title; ?>"
1677 - >
1678 - <?php
1679 - } else {
3418 + // bootstrap
3419 + if ( $design_style ) {
3420 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3421 +
3422 + echo aui()->textarea(
3423 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3424 + 'id' => esc_attr( $field->htmlvar_name ),
3425 + 'name' => esc_attr( $field->htmlvar_name ),
3426 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3427 + 'title' => esc_html( $site_title ),
3428 + 'value' => wp_kses_post( stripslashes( $value ) ),
3429 + 'required' => (bool) $field->is_required,
3430 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3431 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3432 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3433 + 'rows' => '4',
3434 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3435 + )
3436 + );
3437 + } else {
3438 + ?>
3439 +
3440 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3441 + class="
3442 + <?php
3443 + if ( $field->is_required ) {
3444 + echo 'required_field';
3445 + }
3446 + ?>
3447 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3448 +
3449 + <?php
3450 +
3451 + if ( ! is_admin() ) {
3452 + ?>
3453 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3454 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3455 + <?php
3456 + if ( $field->is_required ) {
3457 + echo '<span>*</span>';
3458 + }
1680 3459 ?>
1681 - <ul class="uwp_multi_choice">
1682 - <?php
1683 - }
3460 + </label>
3461 + <?php } ?>
1684 3462
1685 - $option_values_arr = uwp_string_values_to_options($field->option_values, true);
1686 - $select_options = '';
1687 - if (!empty($option_values_arr)) {
1688 - foreach ($option_values_arr as $option_row) {
1689 - if (isset($option_row['optgroup']) && ($option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end')) {
1690 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
3463 + <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3464 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3465 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3466 + title="<?php echo esc_attr( $site_title ); ?>"
3467 + oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3468 + oninput="setCustomValidity('')"
3469 + <?php
3470 + if ( $field->is_required == 1 ) {
3471 + echo 'required="required"';
3472 + }
3473 + ?>
3474 + type="<?php echo esc_attr( $field->field_type ); ?>"
3475 + rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3476 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3477 + <?php if ( $field->is_required ) { ?>
3478 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3479 + <?php } ?>
3480 + </div>
1691 3481
1692 - if ($multi_display == 'select') {
1693 - $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr($option_label) . '">' : '</optgroup>';
1694 - } else {
1695 - $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
1696 - }
1697 - } else {
1698 - $option_label = isset($option_row['label']) ? $option_row['label'] : '';
1699 - $option_value = isset($option_row['value']) ? $option_row['value'] : '';
1700 - $selected = $option_value == $value ? 'selected="selected"' : '';
1701 - $checked = '';
3482 + <?php
3483 + }
3484 + $html = ob_get_clean();
3485 + }
1702 3486
1703 - if ((!is_array($value) && trim($value) != '') || (is_array($value) && !empty($value))) {
1704 - if (!is_array($value)) {
1705 - $value_array = explode(',', $value);
1706 - } else {
1707 - $value_array = $value;
1708 - }
3487 + return $html;
3488 + }
1709 3489
1710 - if (is_array($value_array)) {
1711 - if (in_array($option_value, $value_array)) {
1712 - $selected = 'selected="selected"';
1713 - $checked = 'checked="checked"';
1714 - }
1715 - }
1716 - }
3490 + public function form_input_editor( $html, $field, $value, $form_type ) {
1717 3491
1718 - if ($multi_display == 'select') {
1719 - $select_options .= '<option value="' . esc_attr($option_value) . '" ' . $selected . '>' . $option_label . '</option>';
1720 - } else {
1721 - $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr($option_value) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
1722 - }
1723 - }
1724 - }
1725 - }
1726 - echo $select_options;
3492 + // Check if there is a field specific filter.
3493 + if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3494 + $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3495 + }
1727 3496
1728 - if ($multi_display == 'select') { ?></select></div>
1729 - <?php } else { ?>
1730 - </ul>
1731 - <?php } ?>
1732 - <?php if ($field->is_required) { ?>
1733 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1734 - <?php } ?>
1735 - </div>
1736 - <?php
1737 - $html = ob_get_clean();
1738 - }
3497 + if ( empty( $html ) ) {
1739 3498
1740 - return $html;
1741 - }
3499 + ob_start();
1742 3500
1743 - /**
1744 - * Form field template for file field type.
1745 - *
1746 - * @since 1.0.0
1747 - * @package userswp
1748 - *
1749 - * @param string $html Form field html
1750 - * @param object $field Field info.
1751 - * @param string $value Form field default value.
1752 - * @param string $form_type Form type
1753 - *
1754 - * @return string Modified form field html.
1755 - */
1756 - public function uwp_form_input_file($html, $field, $value, $form_type){
3501 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3502 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3503 + $bs_sr_only = $design_style ? 'sr-only' : '';
3504 + $site_title = uwp_get_form_label( $field );
1757 3505
1758 - $file_obj = new UsersWP_Files();
1759 -
1760 - // Check if there is a field specific filter.
1761 - if(has_filter("uwp_form_input_html_file_{$field->htmlvar_name}")){
1762 - $html = apply_filters("uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1763 - }
3506 + $content = stripslashes( $value );
3507 + $editor_id = $field->htmlvar_name;
3508 + $args = array(
3509 + 'textarea_rows' => 5,
3510 + 'media_buttons' => false,
3511 + 'quicktags' => false,
3512 + );
1764 3513
1765 - // If no html then we run the standard output.
1766 - if(empty($html)) {
3514 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3515 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1767 3516
1768 - ob_start(); // Start buffering;
3517 + // bootstrap
3518 + if ( $design_style ) {
3519 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1769 3520
1770 - ?>
1771 - <div id="<?php echo $field->htmlvar_name;?>_row"
1772 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
3521 + echo aui()->textarea(
3522 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3523 + 'id' => esc_attr( $field->htmlvar_name ),
3524 + 'name' => esc_attr( $field->htmlvar_name ),
3525 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3526 + 'title' => esc_html( $site_title ),
3527 + 'value' => wp_kses_post( stripslashes( $value ) ),
3528 + 'required' => (bool) $field->is_required,
3529 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3530 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3531 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3532 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3533 + 'rows' => 5,
3534 + 'wysiwyg' => true,
3535 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3536 + )
3537 + );
3538 + } else {
3539 + ?>
3540 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3541 + class="
3542 + <?php
3543 + if ( $field->is_required ) {
3544 + echo 'required_field';
3545 + }
3546 + ?>
3547 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1773 3548
1774 - <?php
1775 - $site_title = uwp_get_form_label($field);
1776 - if (!is_admin()) { ?>
1777 - <label>
1778 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1779 - <?php if ($field->is_required) echo '<span>*</span>';?>
1780 - </label>
1781 - <?php } ?>
3549 + <?php
1782 3550
1783 - <?php echo $file_obj->uwp_file_upload_preview($field, $value); ?>
1784 - <input name="<?php echo $field->htmlvar_name; ?>"
1785 - class="<?php echo $field->css_class; ?>"
1786 - placeholder="<?php echo $site_title; ?>"
1787 - title="<?php echo $site_title; ?>"
3551 + if ( ! is_admin() ) {
3552 + ?>
3553 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3554 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3555 + <?php
3556 + if ( $field->is_required ) {
3557 + echo '<span>*</span>';
3558 + }
3559 + ?>
3560 + </label>
3561 + <?php } ?>
3562 +
3563 + <?php wp_editor( $content, $editor_id, $args ); ?>
3564 +
3565 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3566 + <?php if ( $field->is_required ) { ?>
3567 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3568 + <?php } ?>
3569 + </div>
3570 + <?php
3571 + }
3572 + $html = ob_get_clean();
3573 + }
3574 +
3575 + return $html;
3576 + }
3577 +
3578 + /**
3579 + * Form field template for fieldset field type.
3580 + *
3581 + * @param string $html Form field html
3582 + * @param object $field Field info.
3583 + * @param string $value Form field default value.
3584 + * @param string $form_type Form type
3585 + *
3586 + * @return string Modified form field html.
3587 + * @package userswp
3588 + *
3589 + * @since 1.0.0
3590 + */
3591 + public function form_input_fieldset( $html, $field, $value, $form_type ) {
3592 + // Check if there is a custom field specific filter.
3593 + if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3594 + $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3595 + }
3596 +
3597 + // If no html then we run the standard output.
3598 + if ( empty( $html ) ) {
3599 +
3600 + ob_start(); // Start buffering;
3601 + $site_title = uwp_get_form_label( $field );
3602 + ?>
3603 + <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3604 + <?php echo esc_html( $site_title ); ?>
3605 + <?php
3606 + if ( $field->help_text != '' ) {
3607 + echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3608 + }
3609 + ?>
3610 + </h3>
3611 + <?php
3612 + $html = ob_get_clean();
3613 + }
3614 +
3615 + return $html;
3616 + }
3617 +
3618 + /**
3619 + * Form field template for url field type.
3620 + *
3621 + * @param string $html Form field html
3622 + * @param object $field Field info.
3623 + * @param string $value Form field default value.
3624 + * @param string $form_type Form type
3625 + *
3626 + * @return string Modified form field html.
3627 + * @package userswp
3628 + *
3629 + * @since 1.0.0
3630 + */
3631 + public function form_input_url( $html, $field, $value, $form_type ) {
3632 +
3633 + // Check if there is a custom field specific filter.
3634 + if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
3635 + $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3636 + }
3637 +
3638 + // If no html then we run the standard output.
3639 + if ( empty( $html ) ) {
3640 +
3641 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3642 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3643 + $bs_sr_only = $design_style ? 'sr-only' : '';
3644 + $bs_form_control = $design_style ? 'form-control' : '';
3645 +
3646 + ob_start(); // Start buffering;
3647 + $site_title = uwp_get_form_label( $field );
3648 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
3649 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3650 +
3651 + // bootstrap
3652 + if ( $design_style ) {
3653 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3654 +
3655 + echo aui()->input(
3656 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3657 + 'type' => 'url',
3658 + 'id' => esc_attr( $field->htmlvar_name ),
3659 + 'name' => esc_attr( $field->htmlvar_name ),
3660 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3661 + 'title' => esc_html( $site_title ),
3662 + 'value' => esc_attr( $value ),
3663 + 'required' => (bool) $field->is_required,
3664 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3665 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3666 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3667 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3668 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3669 + )
3670 + );
3671 + } else {
3672 + ?>
3673 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3674 + class="
1788 3675 <?php
1789 - if ($field->is_required == 1 ) { echo 'data-is-required="1"'; }
1790 - if ($field->is_required == 1 && !$value) { echo 'required="required"'; }
3676 + if ( $field->is_required ) {
3677 + echo 'required_field';
3678 + }
1791 3679 ?>
1792 - type="<?php echo $field->field_type; ?>">
1793 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1794 - <?php if ($field->is_required) { ?>
1795 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1796 - <?php } ?>
1797 - </div>
3680 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
1798 3681
1799 - <?php
1800 - $html = ob_get_clean();
1801 - }
3682 + <?php
3683 + if ( ! is_admin() ) {
3684 + ?>
3685 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3686 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3687 + <?php
3688 + if ( $field->is_required ) {
3689 + echo '<span>*</span>';
3690 + }
3691 + ?>
3692 + </label>
3693 + <?php } ?>
1802 3694
1803 - return $html;
1804 - }
3695 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3696 + class="
3697 + <?php
3698 + //echo $field->css_class;
3699 + ?>
3700 + uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3701 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3702 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3703 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3704 + title="<?php echo esc_attr( $site_title ); ?>"
3705 + <?php
3706 + if ( $field->is_required == 1 ) {
3707 + echo 'required="required"';
3708 + }
3709 + ?>
3710 + type="url"
3711 + oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
3712 + onchange="try{setCustomValidity('')}catch(e){}"
3713 + />
3714 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3715 + <?php if ( $field->is_required ) { ?>
3716 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3717 + <?php } ?>
3718 + </div>
1805 3719
1806 - /**
1807 - * Form field template for checkbox field type.
1808 - *
1809 - * @since 1.0.0
1810 - * @package userswp
1811 - *
1812 - * @param string $html Form field html
1813 - * @param object $field Field info.
1814 - * @param string $value Form field default value.
1815 - * @param string $form_type Form type
1816 - *
1817 - * @return string Modified form field html.
1818 - */
1819 - public function uwp_form_input_checkbox($html, $field, $value, $form_type){
3720 + <?php
3721 + }
1820 3722
1821 - // Check if there is a field specific filter.
1822 - if(has_filter("uwp_form_input_html_checkbox_{$field->htmlvar_name}")){
1823 - $html = apply_filters("uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1824 - }
3723 + $html = ob_get_clean();
3724 + }
1825 3725
1826 - // If no html then we run the standard output.
1827 - if(empty($html)) {
3726 + return $html;
3727 + }
1828 3728
1829 - ob_start(); // Start buffering;
1830 - $site_title = uwp_get_form_label($field);
1831 - ?>
1832 - <div id="<?php echo $field->htmlvar_name;?>_row"
1833 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
1834 - <input type="hidden" name="<?php echo $field->htmlvar_name; ?>" value="0" />
1835 - <input name="<?php echo $field->htmlvar_name; ?>"
1836 - class="<?php echo $field->css_class; ?>"
1837 - placeholder="<?php echo $site_title; ?>"
1838 - title="<?php echo $site_title; ?>"
1839 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1840 - <?php if ($value == '1') { echo 'checked="checked"'; } ?>
1841 - type="<?php echo $field->field_type; ?>"
1842 - value="1">
1843 - <?php
1844 - echo (trim($site_title)) ? $site_title : '&nbsp;';
3729 + /**
3730 + * Form field template for email field type.
3731 + *
3732 + * @param string $html Form field html
3733 + * @param object $field Field info.
3734 + * @param string $value Form field default value.
3735 + * @param string $form_type Form type
3736 + *
3737 + * @return string Modified form field html.
3738 + * @package userswp
3739 + *
3740 + * @since 1.0.0
3741 + */
3742 + public function form_input_email( $html, $field, $value, $form_type ) {
3743 +
3744 + // Check if there is a custom field specific filter.
3745 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
3746 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3747 + }
3748 +
3749 + // If no html then we run the standard output.
3750 + if ( empty( $html ) ) {
3751 +
3752 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3753 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3754 + $bs_sr_only = $design_style ? 'sr-only' : '';
3755 + $bs_form_control = $design_style ? 'form-control' : '';
3756 +
3757 + ob_start(); // Start buffering;
3758 + $site_title = uwp_get_form_label( $field );
3759 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3760 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3761 +
3762 + if ( $design_style ) {
3763 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3764 +
3765 + echo aui()->input(
3766 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3767 + 'type' => 'email',
3768 + 'id' => esc_attr( $field->htmlvar_name ),
3769 + 'name' => esc_attr( $field->htmlvar_name ),
3770 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3771 + 'title' => esc_html( $site_title ),
3772 + 'value' => esc_attr( wp_unslash( $value ) ),
3773 + 'required' => (bool) $field->is_required,
3774 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3775 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3776 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3777 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3778 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3779 + )
3780 + );
3781 + } else {
3782 + ?>
3783 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3784 + class="
3785 + <?php
3786 + if ( $field->is_required ) {
3787 + echo 'required_field';
3788 + }
3789 + ?>
3790 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3791 +
3792 + <?php
3793 + if ( ! is_admin() ) {
3794 + ?>
3795 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3796 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3797 + <?php
3798 + if ( $field->is_required ) {
3799 + echo '<span>*</span>';
3800 + }
3801 + ?>
3802 + </label>
3803 + <?php } ?>
3804 +
3805 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3806 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3807 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3808 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3809 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3810 + title="<?php echo esc_attr( $site_title ); ?>"
3811 + <?php
3812 + if ( $field->is_required == 1 ) {
3813 + echo 'required="required"';
3814 + }
3815 + ?>
3816 + type="email"
3817 + />
3818 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3819 + <?php if ( $field->is_required ) { ?>
3820 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3821 + <?php } ?>
3822 + </div>
3823 +
3824 +
3825 + <?php
3826 + }
3827 + $html = ob_get_clean();
3828 +
3829 + }
3830 +
3831 + if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
3832 + $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3833 + }
3834 +
3835 + return $html;
3836 + }
3837 +
3838 + /**
3839 + * Form field template for password field type.
3840 + *
3841 + * @param string $html Form field html
3842 + * @param object $field Field info.
3843 + * @param string $value Form field default value.
3844 + * @param string $form_type Form type
3845 + *
3846 + * @return string Modified form field html.
3847 + * @package userswp
3848 + *
3849 + * @since 1.0.0
3850 + */
3851 + public function form_input_password( $html, $field, $value, $form_type ) {
3852 +
3853 + // Check if there is a custom field specific filter.
3854 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
3855 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3856 + }
3857 +
3858 + // If no html then we run the standard output.
3859 + if ( empty( $html ) ) {
3860 +
3861 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3862 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3863 + $bs_sr_only = $design_style ? 'sr-only' : '';
3864 + $bs_form_control = $design_style ? 'form-control' : '';
3865 +
3866 + ob_start(); // Start buffering;
3867 + $site_title = uwp_get_form_label( $field );
3868 +
3869 + if ( $design_style ) {
3870 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3871 + $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3872 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3873 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
3874 +
3875 + echo aui()->input(
3876 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3877 + 'type' => 'password',
3878 + 'id' => esc_attr( $field->htmlvar_name ),
3879 + 'name' => esc_attr( $field->htmlvar_name ),
3880 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3881 + 'title' => esc_html( $site_title ),
3882 + 'value' => esc_attr( $value ),
3883 + 'required' => (bool) $field->is_required,
3884 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3885 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3886 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3887 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3888 + 'wrap_class' => esc_attr( $wrap_class ),
3889 + )
3890 + );
3891 + } else {
3892 + ?>
3893 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3894 + <?php
3895 + if ( $field->is_required ) {
3896 + echo 'required_field';
3897 + }
1845 3898 ?>
1846 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1847 - <?php if ($field->is_required) { ?>
1848 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1849 - <?php } ?>
1850 - </div>
3899 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3900 + <?php
3901 + if ( ! is_admin() ) {
3902 + ?>
3903 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3904 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3905 + <?php
3906 + if ( $field->is_required ) {
3907 + echo '<span>*</span>';
3908 + }
3909 + ?>
3910 + </label>
3911 + <?php } ?>
1851 3912
1852 - <?php
1853 - $html = ob_get_clean();
1854 - }
3913 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3914 + class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3915 + id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3916 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3917 + value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3918 + title="<?php echo esc_attr( $site_title ); ?>"
3919 + <?php
3920 + if ( $field->is_required == 1 ) {
3921 + echo 'required="required"';
3922 + }
3923 + ?>
3924 + type="password"
3925 + />
3926 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3927 + <?php if ( $field->is_required ) { ?>
3928 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3929 + <?php } ?>
3930 + </div>
1855 3931
1856 - return $html;
1857 - }
1858 3932
1859 - /**
1860 - * Form field template for radio field type.
1861 - *
1862 - * @since 1.0.0
1863 - * @package userswp
1864 - *
1865 - * @param string $html Form field html
1866 - * @param object $field Field info.
1867 - * @param string $value Form field default value.
1868 - * @param string $form_type Form type
1869 - *
1870 - * @return string Modified form field html.
1871 - */
1872 - public function uwp_form_input_radio($html, $field, $value, $form_type){
3933 + <?php
3934 + }
1873 3935
1874 - // Check if there is a field specific filter.
1875 - if(has_filter("uwp_form_input_html_radio_{$field->htmlvar_name}")){
1876 - $html = apply_filters("uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type);
1877 - }
3936 + $html = ob_get_clean();
3937 + }
1878 3938
1879 - // If no html then we run the standard output.
1880 - if(empty($html)) {
3939 + if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
3940 + $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3941 + }
1881 3942
1882 - ob_start(); // Start buffering;
3943 + return $html;
3944 + }
1883 3945
1884 - ?>
1885 - <div id="<?php echo $field->htmlvar_name;?>_row"
1886 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
3946 + /**
3947 + * Form field template for Phone field.
3948 + *
3949 + * @param string $html Form field html
3950 + * @param object $field Field info.
3951 + * @param string $value Form field default value.
3952 + * @param string $form_type Form type
3953 + *
3954 + * @return string $html Modified form field html.
3955 + * @since 1.0.0
3956 + *
3957 + */
3958 + public function form_input_phone( $html, $field, $value, $form_type ) {
3959 + if ( empty( $html ) ) {
3960 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3961 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
3962 + $bs_sr_only = $design_style ? 'sr-only' : '';
3963 + $bs_form_control = $design_style ? 'form-control' : '';
3964 + ob_start(); // Start buffering;
3965 + $site_title = uwp_get_form_label( $field );
3966 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3967 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
1887 3968
1888 - <?php
1889 - $site_title = uwp_get_form_label($field);
1890 - if (!is_admin()) { ?>
1891 - <label>
1892 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
1893 - <?php if ($field->is_required) echo '<span>*</span>';?>
1894 - </label>
1895 - <?php } ?>
3969 + if ( $design_style ) {
3970 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
1896 3971
3972 + echo aui()->input(
3973 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3974 + 'type' => 'tel',
3975 + 'id' => esc_attr( $field->htmlvar_name ),
3976 + 'name' => esc_attr( $field->htmlvar_name ),
3977 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3978 + 'title' => esc_html( $site_title ),
3979 + 'value' => esc_attr( $value ),
3980 + 'required' => (bool) $field->is_required,
3981 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3982 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3983 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3984 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3985 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3986 + )
3987 + );
3988 + } else {
3989 + ?>
3990 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3991 + class="
3992 + <?php
3993 + if ( $field->is_required ) {
3994 + echo 'required_field';
3995 + }
3996 + ?>
3997 + clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3998 + <?php
3999 + if ( ! is_admin() ) {
4000 + ?>
4001 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4002 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4003 + <?php
4004 + if ( $field->is_required ) {
4005 + echo '<span>*</span>';
4006 + }
4007 + ?>
4008 + </label>
4009 + <?php } ?>
4010 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4011 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4012 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4013 + title="<?php echo esc_attr( $site_title ); ?>"
4014 + <?php
4015 + if ( $field->for_admin_use == 1 ) {
4016 + echo 'readonly="readonly"';
4017 + }
4018 + ?>
4019 + <?php
4020 + if ( $field->is_required == 1 ) {
4021 + echo 'required="required"';
4022 + }
4023 + ?>
4024 + type="tel"
4025 + value="<?php echo esc_html( $value ); ?>">
4026 + </div>
4027 + <?php
4028 + }
4029 + $html = ob_get_clean();
4030 + }
1897 4031
1898 - <?php if ($field->option_values) {
1899 - $option_values = uwp_string_values_to_options($field->option_values, true);
4032 + return $html;
4033 + }
1900 4034
1901 - if (!empty($option_values)) {
1902 - $count = 0;
1903 - foreach ($option_values as $option_value) {
1904 - if (empty($option_value['optgroup'])) {
1905 - $count++;
1906 - if ($count == 1) {
1907 - $class = "uwp-radio-first";
1908 - } else {
1909 - $class = "";
1910 - }
1911 - ?>
1912 - <span class="uwp-radios <?php echo $class; ?>">
1913 - <input name="<?php echo $field->htmlvar_name; ?>"
1914 - id="<?php echo $field->htmlvar_name; ?>"
1915 - title="<?php echo esc_attr($option_value['label']); ?>"
1916 - <?php checked($value, $option_value['value']);?>
1917 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
1918 - value="<?php echo esc_attr($option_value['value']); ?>"
1919 - class="uwp-radio" type="radio" />
1920 - <?php echo $option_value['label']; ?>
1921 - </span>
1922 - <?php
1923 - }
1924 - }
1925 - }
1926 - }
1927 - ?>
1928 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
1929 - <?php if ($field->is_required) { ?>
1930 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
1931 - <?php } ?>
1932 - </div>
1933 - <?php
1934 - $html = ob_get_clean();
1935 - }
4035 + public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
1936 4036
1937 - return $html;
1938 - }
4037 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4038 + $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4039 + if ( empty( $reg_gdpr ) ) {
4040 + $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4041 + }
1939 4042
1940 - /**
1941 - * Form field template for text field type.
1942 - *
1943 - * @since 1.0.0
1944 - * @package userswp
1945 - *
1946 - * @param string $html Form field html
1947 - * @param object $field Field info.
1948 - * @param string $value Form field default value.
1949 - * @param string $form_type Form type
1950 - *
1951 - * @return string Modified form field html.
1952 - */
1953 - public function uwp_form_input_text($html, $field, $value, $form_type){
4043 + if ( ! empty( $reg_gdpr ) ) {
1954 4044
1955 - // Check if there is a custom field specific filter.
1956 - if(has_filter("uwp_form_input_text_{$field->htmlvar_name}")){
1957 - $html = apply_filters("uwp_form_input_text_{$field->htmlvar_name}",$html, $field, $value, $form_type);
1958 - }
4045 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4046 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4047 + $bs_form_control = $design_style ? 'form-check-input' : '';
4048 + $site_title = uwp_get_form_label( $field );
4049 + $field->htmlvar_name = 'register_gdpr';
4050 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
1959 4051
1960 - // If no html then we run the standard output.
1961 - if(empty($html)) {
4052 + $gdpr_page = get_permalink( $reg_gdpr );
4053 + $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4054 + $link_end = '</a>';
4055 + $field_desc = uwp_get_field_description( $field, '' );
4056 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4057 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4058 + $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4059 + $checked = $value == '1' ? true : false;
1962 4060
1963 - ob_start(); // Start buffering;
4061 + ob_start(); // Start buffering;
1964 4062
1965 - $type = 'text';
1966 - $step = false;
1967 - //number and float validation $validation_pattern
1968 - if(isset($field->data_type) && $field->data_type == 'INT'){
1969 - $type = 'number';
1970 - } elseif(isset($field->data_type) && $field->data_type == 'FLOAT'){
1971 - $dp = $field->decimal_point;
1972 - switch ($dp) {
1973 - case "1":
1974 - $step = "0.1";
1975 - break;
1976 - case "2":
1977 - $step = "0.01";
1978 - break;
1979 - case "3":
1980 - $step = "0.001";
1981 - break;
1982 - case "4":
1983 - $step = "0.0001";
1984 - break;
1985 - case "5":
1986 - $step = "0.00001";
1987 - break;
1988 - case "6":
1989 - $step = "0.000001";
1990 - break;
1991 - case "7":
1992 - $step = "0.0000001";
1993 - break;
1994 - case "8":
1995 - $step = "0.00000001";
1996 - break;
1997 - case "9":
1998 - $step = "0.000000001";
1999 - break;
2000 - case "10":
2001 - $step = "0.0000000001";
2002 - break;
2003 - default:
2004 - $step = "0.01";
2005 - break;
2006 - }
2007 - $type = 'number';
2008 - }
4063 + // bootstrap
4064 + if ( $design_style ) {
4065 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4066 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2009 4067
2010 - ?>
4068 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4069 + array(
4070 + 'id' => esc_attr( $id ),
4071 + 'name' => esc_attr( $field->htmlvar_name ),
4072 + 'type' => 'checkbox',
4073 + 'value' => '1',
4074 + 'title' => esc_html( $site_title ),
4075 + 'label' => wp_kses_post( $content . $required ),
4076 + 'label_show' => true,
4077 + 'required' => ! empty( $field->is_required ) ? true : false,
4078 + 'checked' => (bool) $checked,
4079 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4080 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4081 + )
4082 + );
2011 4083
2012 - <div id="<?php echo $field->htmlvar_name;?>_row"
2013 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4084 + } else {
4085 + ?>
4086 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4087 + class="
4088 + <?php
4089 + if ( $field->is_required ) {
4090 + echo 'required_field';
4091 + }
4092 + ?>
4093 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4094 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4095 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4096 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4097 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4098 + title="<?php echo esc_attr( $site_title ); ?>"
4099 + <?php
4100 + if ( $value == '1' ) {
4101 + echo 'checked="checked"';
4102 + }
4103 + ?>
4104 + type="<?php echo esc_attr( $field->field_type ); ?>"
4105 + value="1">
4106 + <?php
4107 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4108 + ?>
4109 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4110 + <?php if ( $field->is_required ) { ?>
4111 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4112 + <?php } ?>
4113 + </div>
2014 4114
2015 - <?php
2016 - $site_title = uwp_get_form_label($field);
2017 - $manual_label = apply_filters('uwp_login_username_label_manual', true);
2018 - if ($manual_label
2019 - && isset($field->form_type)
2020 - && $field->form_type == 'login'
2021 - && $field->htmlvar_name == 'uwp_login_username') {
2022 - $site_title = __("Username or Email", 'userswp');
2023 - }
2024 - if (!is_admin()) { ?>
2025 - <label>
2026 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2027 - <?php if ($field->is_required) echo '<span>*</span>';?>
2028 - </label>
2029 - <?php } ?>
4115 + <?php
4116 + }
2030 4117
2031 - <input name="<?php echo $field->htmlvar_name;?>"
2032 - class="<?php echo $field->css_class; ?> uwp_textfield"
2033 - id="<?php echo $field->htmlvar_name;?>"
2034 - placeholder="<?php echo $site_title; ?>"
2035 - value="<?php echo esc_attr(stripslashes($value));?>"
2036 - title="<?php echo $site_title; ?>"
2037 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
2038 - oninput="setCustomValidity('')"
2039 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2040 - <?php if ($field->for_admin_use == 1) { echo 'readonly="readonly"'; } ?>
2041 - type="<?php echo $type; ?>"
2042 - <?php if ($step) { echo 'step="'.$step.'"'; } ?>
2043 - />
2044 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2045 - <?php if ($field->is_required) { ?>
2046 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2047 - <?php } ?>
2048 - </div>
4118 + $html = ob_get_clean();
2049 4119
4120 + } else {
4121 + $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4122 + }
2050 4123
2051 - <?php
2052 - $html = ob_get_clean();
2053 - }
4124 + return $html;
4125 + }
2054 4126
2055 - return $html;
2056 - }
4127 + public function form_input_register_tos( $html, $field, $value, $form_type ) {
2057 4128
2058 - /**
2059 - * Form field template for textarea field type.
2060 - *
2061 - * @since 1.0.0
2062 - * @package userswp
2063 - *
2064 - * @param string $html Form field html
2065 - * @param object $field Field info.
2066 - * @param string $value Form field default value.
2067 - * @param string $form_type Form type
2068 - *
2069 - * @return string Modified form field html.
2070 - */
2071 - public function uwp_form_input_textarea($html, $field, $value, $form_type){
4129 + $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4130 + $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4131 + if ( empty( $reg_tos ) ) {
4132 + $reg_tos = uwp_get_option( 'register_terms_page', false );
4133 + }
2072 4134
2073 - // Check if there is a field specific filter.
2074 - if(has_filter("uwp_form_input_textarea_{$field->htmlvar_name}")){
2075 - $html = apply_filters("uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2076 - }
4135 + if ( ! empty( $reg_tos ) ) {
2077 4136
2078 - // If no html then we run the standard output.
2079 - if(empty($html)) {
4137 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4138 + $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4139 + $bs_form_control = $design_style ? 'form-check-input' : '';
2080 4140
2081 - ob_start(); // Start buffering;
4141 + $site_title = uwp_get_form_label( $field );
4142 + $terms_page = get_permalink( $reg_tos );
4143 + $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4144 + $link_end = '</a>';
4145 + $field_desc = uwp_get_field_description( $field, '' );
4146 + $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4147 + $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4148 + $field->htmlvar_name = 'register_tos';
4149 + $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2082 4150
2083 - ?>
2084 - <div id="<?php echo $field->htmlvar_name;?>_row"
2085 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4151 + $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4152 + $checked = $value == '1' ? true : false;
2086 4153
2087 - <?php
2088 - $site_title = uwp_get_form_label($field);
2089 - if (!is_admin()) { ?>
2090 - <label>
2091 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2092 - <?php if ($field->is_required) echo '<span>*</span>';?>
2093 - </label>
2094 - <?php } ?>
4154 + ob_start();
2095 4155
2096 - <textarea name="<?php echo $field->htmlvar_name; ?>"
2097 - class="<?php echo $field->css_class; ?>"
2098 - placeholder="<?php echo $site_title; ?>"
2099 - title="<?php echo $site_title; ?>"
2100 - oninvalid="this.setCustomValidity('<?php _e($field->required_msg, 'userswp'); ?>')"
2101 - oninput="setCustomValidity('')"
2102 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2103 - type="<?php echo $field->field_type; ?>"
2104 - rows="4"><?php echo stripslashes($value); ?></textarea>
2105 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2106 - <?php if ($field->is_required) { ?>
2107 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2108 - <?php } ?>
2109 - </div>
4156 + if ( $design_style ) {
4157 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4158 + echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2110 4159
2111 - <?php
2112 - $html = ob_get_clean();
2113 - }
4160 + echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4161 + array(
4162 + 'id' => esc_attr( $id ),
4163 + 'name' => esc_attr( $field->htmlvar_name ),
4164 + 'type' => 'checkbox',
4165 + 'value' => '1',
4166 + 'title' => esc_html( $site_title ),
4167 + 'label' => wp_kses_post( $content . $required ),
4168 + 'label_show' => true,
4169 + 'required' => ! empty( $field->is_required ) ? true : false,
4170 + 'checked' => (bool) $checked,
4171 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4172 + 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4173 + )
4174 + );
2114 4175
2115 - return $html;
2116 - }
4176 + } else {
4177 + ?>
4178 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4179 + class="
4180 + <?php
4181 + if ( $field->is_required ) {
4182 + echo 'required_field';
4183 + }
4184 + ?>
4185 + uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4186 + <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4187 + <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4188 + class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4189 + placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4190 + title="<?php echo esc_attr( $site_title ); ?>"
4191 + <?php
4192 + if ( $value == '1' ) {
4193 + echo 'checked="checked"';
4194 + }
4195 + ?>
4196 + type="<?php echo esc_attr( $field->field_type ); ?>"
4197 + value="1">
4198 + <?php
4199 + echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4200 + ?>
4201 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4202 + <?php if ( $field->is_required ) { ?>
4203 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4204 + <?php } ?>
4205 + </div>
2117 4206
2118 - /**
2119 - * Form field template for fieldset field type.
2120 - *
2121 - * @since 1.0.0
2122 - * @package userswp
2123 - *
2124 - * @param string $html Form field html
2125 - * @param object $field Field info.
2126 - * @param string $value Form field default value.
2127 - * @param string $form_type Form type
2128 - *
2129 - * @return string Modified form field html.
2130 - */
2131 - public function uwp_form_input_fieldset($html, $field, $value, $form_type) {
2132 - // Check if there is a custom field specific filter.
2133 - if(has_filter("uwp_form_input_fieldset_{$field->htmlvar_name}")){
2134 - $html = apply_filters("uwp_form_input_fieldset_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2135 - }
4207 + <?php
2136 4208
2137 - // If no html then we run the standard output.
2138 - if(empty($html)) {
4209 + }
2139 4210
2140 - ob_start(); // Start buffering;
2141 - ?>
2142 - <h3 class="uwp_input_fieldset <?php echo $field->css_class; ?>">
2143 - <?php echo $field->site_title;; ?>
2144 - <?php if ( $field->help_text != '' ) {
2145 - echo '<small>( ' . $field->help_text . ' )</small>';
2146 - } ?></h3>
2147 - <?php
2148 - $html = ob_get_clean();
2149 - }
4211 + $html = ob_get_clean();
2150 4212
2151 - return $html;
2152 - }
4213 + } else {
4214 + $html = '<input type="hidden" name="register_tos" value="-1"/>';
4215 + }
2153 4216
2154 - /**
2155 - * Form field template for url field type.
2156 - *
2157 - * @since 1.0.0
2158 - * @package userswp
2159 - *
2160 - * @param string $html Form field html
2161 - * @param object $field Field info.
2162 - * @param string $value Form field default value.
2163 - * @param string $form_type Form type
2164 - *
2165 - * @return string Modified form field html.
2166 - */
2167 - public function uwp_form_input_url($html, $field, $value, $form_type){
4217 + return $html;
4218 + }
2168 4219
4220 + /**
4221 + * Adds enctype tag in form for file fields.
4222 + *
4223 + * @return void
4224 + * @package userswp
4225 + *
4226 + * @since 1.0.0
4227 + */
4228 + function add_multipart_to_admin_edit_form() {
4229 + global $wpdb;
4230 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4231 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4232 + if ( $fields ) {
4233 + echo 'enctype="multipart/form-data"';
4234 + }
4235 + }
2169 4236
2170 - // Check if there is a custom field specific filter.
2171 - if(has_filter("uwp_form_input_url_{$field->htmlvar_name}")){
2172 - $html = apply_filters("uwp_form_input_url_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2173 - }
4237 + /**
4238 + * Handles UsersWP custom field requests from admin.
4239 + *
4240 + * @param int $user_id User ID.
4241 + *
4242 + * @return void
4243 + * @since 1.0.0
4244 + * @package userswp
4245 + *
4246 + */
4247 + public function update_profile_extra_admin_edit( $user_id ) {
4248 + global $wpdb;
4249 + $file_obj = new UsersWP_Files();
4250 + $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4251 + //Normal fields
4252 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4253 + if ( $fields ) {
4254 + if ( isset( $_POST['locale'] ) ) {
4255 + $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4256 + }
4257 + $result = uwp_validate_fields( $_POST, 'account', $fields );
4258 + if ( is_wp_error( $result ) ) {
4259 + die( wp_kses_post( $result->get_error_message() ) );
4260 + }
4261 + if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4262 + $display_name = $result['display_name'];
4263 + } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4264 + $display_name = $result['first_name'] . ' ' . $result['last_name'];
4265 + } else {
4266 + $user_info = get_userdata( $user_id );
4267 + $display_name = $user_info->user_login;
4268 + }
4269 + $result['display_name'] = $display_name;
4270 + if ( ! is_wp_error( $result ) ) {
4271 + foreach ( $fields as $field ) {
4272 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4273 + if ( $value == '0' || ! empty( $value ) ) {
4274 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4275 + }
4276 + }
4277 + }
4278 + }
2174 4279
2175 - // If no html then we run the standard output.
2176 - if(empty($html)) {
4280 + //File fields
4281 + $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4282 + if ( $fields ) {
4283 + $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4284 + if ( ! is_wp_error( $result ) ) {
4285 + foreach ( $fields as $field ) {
4286 + $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4287 + if ( $value == '0' || ! empty( $value ) ) {
4288 + uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4289 + }
4290 + }
4291 + }
4292 + }
4293 + }
2177 4294
2178 - ob_start(); // Start buffering;
2179 - ?>
2180 - <div id="<?php echo $field->htmlvar_name;?>_row"
2181 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4295 + /**
4296 + * Form field template for country field.
4297 + *
4298 + * @param string $html Form field html
4299 + * @param object $field Field info.
4300 + * @param string $value Form field default value.
4301 + * @param string $form_type Form type
4302 + *
4303 + * @return string Modified form field html.
4304 + * @package userswp
4305 + *
4306 + * @since 1.0.0
4307 + */
4308 + public function form_input_select_country( $html, $field, $value, $form_type ) {
2182 4309
4310 + // If no html then we run the standard output.
4311 + if ( empty( $html ) ) {
4312 +
4313 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4314 + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4315 + $bs_sr_only = $design_style ? 'sr-only' : '';
4316 + $bs_form_control = $design_style ? 'form-control' : '';
4317 +
4318 + ob_start(); // Start buffering;
4319 + ?>
4320 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4321 +
4322 + <?php
4323 + $site_title = uwp_get_form_label( $field );
4324 +
4325 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4326 + ?>
4327 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4328 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4329 + <?php
4330 + if ( $field->is_required ) {
4331 + echo '<span class="text-danger">*</span>';
4332 + }
4333 + ?>
4334 + </label>
4335 + <?php
4336 + }
4337 + // if value empty set the default
4338 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4339 + $value = $field->default_value;
4340 + }
4341 + if ( $value === false ) {
4342 + $value = '';
4343 + }
4344 + $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4345 + $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4346 +
4347 + $htmlvar_name = $field->htmlvar_name;
4348 + if ( wp_doing_ajax() ) {
4349 + $htmlvar_name .= '_ajax';
4350 + }
4351 + ?>
4352 + <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4353 + <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4354 + <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4355 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4356 + <?php if ( $field->is_required ) { ?>
4357 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4358 + <?php } ?>
4359 + </div>
4360 + <?php
4361 + $html = ob_get_clean();
4362 + }
4363 +
4364 + return $html;
4365 + }
4366 +
4367 + /**
4368 + * Form field template for language field.
4369 + *
4370 + * @param string $html Form field html
4371 + * @param object $field Field info.
4372 + * @param string $value Form field default value.
4373 + * @param string $form_type Form type
4374 + *
4375 + * @return string Modified form field html.
4376 + * @package userswp
4377 + *
4378 + * @since 1.0.0
4379 + */
4380 + public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4381 +
4382 + // If no html then we run the standard output.
4383 + if ( empty( $html ) ) {
4384 +
4385 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4386 + $bs_form_group = $design_style ? 'form-group m-0' : '';
4387 + $bs_sr_only = $design_style ? 'sr-only' : '';
4388 + $bs_form_control = $design_style ? 'form-control' : '';
4389 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4390 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4391 +
4392 + ob_start(); // Start buffering;
4393 +
4394 + ?>
4395 + <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4396 + class="
2183 4397 <?php
2184 - $site_title = uwp_get_form_label($field);
2185 - if (!is_admin()) { ?>
2186 - <label>
2187 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2188 - <?php if ($field->is_required) echo '<span>*</span>';?>
4398 + if ( $field->is_required ) {
4399 + echo 'required_field';
4400 + }
4401 + ?>
4402 + uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4403 +
4404 + <?php
4405 + $site_title = uwp_get_form_label( $field );
4406 + if ( ! is_admin() && ! wp_doing_ajax() ) {
4407 + ?>
4408 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4409 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4410 + <?php
4411 + if ( $field->is_required ) {
4412 + echo '<span class="text-danger">*</span>';
4413 + }
4414 + ?>
2189 4415 </label>
2190 - <?php } ?>
4416 + <?php } ?>
2191 4417
2192 - <input name="<?php echo $field->htmlvar_name;?>"
2193 - class="<?php echo $field->css_class; ?> uwp_textfield"
2194 - id="<?php echo $field->htmlvar_name;?>"
2195 - placeholder="<?php echo $site_title; ?>"
2196 - value="<?php echo esc_attr(stripslashes($value));?>"
2197 - title="<?php echo $site_title; ?>"
2198 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2199 - type="url"
2200 - oninvalid="setCustomValidity('<?php _e('Please enter a valid URL including http://', 'userswp'); ?>')"
2201 - onchange="try{setCustomValidity('')}catch(e){}"
2202 - />
2203 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2204 - <?php if ($field->is_required) { ?>
2205 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2206 - <?php } ?>
2207 - </div>
4418 + <?php
4419 + if ( empty( $field->default_value ) ) {
4420 + $field->default_value = 'site-default';
4421 + }
2208 4422
2209 - <?php
2210 - $html = ob_get_clean();
2211 - }
4423 + // if value empty set the default
4424 + if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4425 + $value = $field->default_value;
4426 + }
2212 4427
2213 - return $html;
2214 - }
4428 + require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4429 + $translations = wp_get_available_translations();
4430 + $available_languages = get_available_languages();
4431 + $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
2215 4432
2216 - /**
2217 - * Form field template for email field type.
2218 - *
2219 - * @since 1.0.0
2220 - * @package userswp
2221 - *
2222 - * @param string $html Form field html
2223 - * @param object $field Field info.
2224 - * @param string $value Form field default value.
2225 - * @param string $form_type Form type
2226 - *
2227 - * @return string Modified form field html.
2228 - */
2229 - public function uwp_form_input_email($html, $field, $value, $form_type){
4433 + foreach ( $available_languages as $locale ) {
4434 + if ( isset( $translations[ $locale ] ) ) {
4435 + $translation = $translations[ $locale ];
4436 + $languages[ $translation['language'] ] = $translation['native_name'];
2230 4437
4438 + // Remove installed language from available translations.
4439 + unset( $translations[ $locale ] );
4440 + } else {
4441 + $languages[ $locale ] = $translation[ $locale ];
4442 + }
4443 + }
2231 4444
2232 - // Check if there is a custom field specific filter.
2233 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}")){
2234 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2235 - }
4445 + if ( $design_style ) {
2236 4446
2237 - // If no html then we run the standard output.
2238 - if(empty($html)) {
4447 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2239 4448
2240 - ob_start(); // Start buffering;
2241 - ?>
2242 - <div id="<?php echo $field->htmlvar_name;?>_row"
2243 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4449 + echo aui()->select(
4450 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4451 + 'id' => esc_attr( $field->htmlvar_name ),
4452 + 'name' => esc_attr( $field->htmlvar_name ),
4453 + 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4454 + 'title' => esc_attr( $site_title ),
4455 + 'value' => esc_attr( $value ),
4456 + 'required' => (bool) $field->is_required,
4457 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4458 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4459 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4460 + 'label' => wp_kses_post( $site_title . $required ),
4461 + 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4462 + 'select2' => true,
4463 + 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4464 + )
4465 + );
4466 + } else {
4467 + ?>
4468 + <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4469 + class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4470 + title="<?php echo esc_attr( $site_title ); ?>"
4471 + data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4472 + ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4473 + </select>
4474 + <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4475 + <?php if ( $field->is_required ) { ?>
4476 + <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4477 + <?php
4478 + }
4479 + }
2244 4480
2245 - <?php
2246 - $site_title = uwp_get_form_label($field);
2247 - if (!is_admin()) { ?>
2248 - <label>
2249 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2250 - <?php if ($field->is_required) echo '<span>*</span>';?>
2251 - </label>
2252 - <?php } ?>
4481 + $html = ob_get_clean();
4482 + }
2253 4483
2254 - <input name="<?php echo $field->htmlvar_name;?>"
2255 - class="<?php echo $field->css_class; ?> uwp_textfield"
2256 - id="<?php echo $field->htmlvar_name;?>"
2257 - placeholder="<?php echo $site_title; ?>"
2258 - value="<?php echo esc_attr(stripslashes($value));?>"
2259 - title="<?php echo $site_title; ?>"
2260 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2261 - type="email"
2262 - />
2263 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2264 - <?php if ($field->is_required) { ?>
2265 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2266 - <?php } ?>
2267 - </div>
4484 + return $html;
4485 + }
2268 4486
4487 + /**
4488 + * Adds confirm password field in forms.
4489 + *
4490 + * @param string $html Form field html
4491 + * @param object $field Field info.
4492 + * @param string $value Form field default value.
4493 + * @param string $form_type Form type
4494 + *
4495 + * @return string Modified form field html.
4496 + * @package userswp
4497 + *
4498 + * @since 1.0.0
4499 + */
4500 + public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4501 + if ( $form_type == 'register' ) {
4502 + //confirm password field
4503 + $extra = array();
4504 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4505 + $extra = unserialize( $field->extra_fields );
4506 + }
2269 4507
2270 - <?php
2271 - $html = ob_get_clean();
2272 - }
4508 + $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4509 + if ( $enable_confirm_password_field == '1' ) {
2273 4510
2274 - if(has_filter("uwp_form_input_email_{$field->htmlvar_name}_after")){
2275 - $html = apply_filters("uwp_form_input_email_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2276 - }
4511 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4512 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4513 + $bs_sr_only = $design_style ? 'sr-only' : '';
4514 + $bs_form_control = $design_style ? 'form-control' : '';
4515 + $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4516 + $required = '';
4517 + if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4518 + $placeholder .= ' *';
4519 + $required = ' <span class="text-danger">*</span>';
4520 + }
4521 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4522 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4523 + $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
2277 4524
2278 - return $html;
2279 - }
4525 + ob_start(); // Start buffering;
2280 4526
2281 - /**
2282 - * Form field template for password field type.
2283 - *
2284 - * @since 1.0.0
2285 - * @package userswp
2286 - *
2287 - * @param string $html Form field html
2288 - * @param object $field Field info.
2289 - * @param string $value Form field default value.
2290 - * @param string $form_type Form type
2291 - *
2292 - * @return string Modified form field html.
2293 - */
2294 - public function uwp_form_input_password($html, $field, $value, $form_type){
4527 + if ( $design_style ) {
2295 4528
4529 + echo aui()->input(
4530 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4531 + 'type' => 'password',
4532 + 'id' => 'confirm_password',
4533 + 'name' => 'confirm_password',
4534 + 'placeholder' => esc_attr( $placeholder ),
4535 + 'title' => esc_attr( $site_title ),
4536 + 'value' => esc_attr( $value ),
4537 + 'required' => (bool) $field->is_required,
4538 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4539 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4540 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4541 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4542 + 'wrap_class' => esc_attr( $wrap_class ),
4543 + )
4544 + );
4545 + } else {
4546 + ?>
4547 + <div id="uwp_account_confirm_password_row"
4548 + class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2296 4549
2297 - // Check if there is a custom field specific filter.
2298 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}")){
2299 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}",$html, $field, $value, $form_type);
2300 - }
4550 + <?php
2301 4551
2302 - // If no html then we run the standard output.
2303 - if(empty($html)) {
4552 + if ( ! is_admin() ) {
4553 + ?>
4554 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4555 + <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4556 + <?php
4557 + if ( $field->is_required ) {
4558 + echo '<span>*</span>';
4559 + }
4560 + ?>
4561 + </label>
4562 + <?php } ?>
4563 + <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4564 + </div>
2304 4565
2305 - ob_start(); // Start buffering;
2306 - ?>
2307 - <div id="<?php echo $field->htmlvar_name;?>_row"
2308 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_<?php echo $field->field_type; ?>_row uwp_clear">
4566 + <?php
4567 + }
4568 + $confirm_html = ob_get_clean();
4569 + $html = $html . $confirm_html;
4570 + }
4571 + }
2309 4572
2310 - <?php
2311 - $site_title = uwp_get_form_label($field);
2312 - if (!is_admin()) { ?>
2313 - <label>
2314 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2315 - <?php if ($field->is_required) echo '<span>*</span>';?>
2316 - </label>
2317 - <?php } ?>
4573 + return $html;
4574 + }
2318 4575
2319 - <input name="<?php echo $field->htmlvar_name;?>"
2320 - class="<?php echo $field->css_class; ?> uwp_textfield"
2321 - id="<?php echo $field->htmlvar_name;?>"
2322 - placeholder="<?php echo $site_title; ?>"
2323 - value="<?php echo esc_attr(stripslashes($value));?>"
2324 - title="<?php echo $site_title; ?>"
2325 - <?php if ($field->is_required == 1) { echo 'required="required"'; } ?>
2326 - type="password"
2327 - />
2328 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2329 - <?php if ($field->is_required) { ?>
2330 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2331 - <?php } ?>
2332 - </div>
4576 + /**
4577 + * Adds confirm email field in forms.
4578 + *
4579 + * @param string $html Form field html
4580 + * @param object $field Field info.
4581 + * @param string $value Form field default value.
4582 + * @param string $form_type Form type
4583 + *
4584 + * @return string Modified form field html.
4585 + * @package userswp
4586 + *
4587 + * @since 1.0.0
4588 + */
4589 + public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4590 + if ( $form_type == 'register' ) {
4591 + //confirm email field
4592 + $extra = array();
4593 + if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4594 + $extra = unserialize( $field->extra_fields );
4595 + }
4596 + $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4597 + if ( $enable_confirm_email_field == '1' ) {
2333 4598
4599 + $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4600 + $bs_form_group = $design_style ? 'form-group mb-3' : '';
4601 + $bs_sr_only = $design_style ? 'sr-only' : '';
4602 + $bs_form_control = $design_style ? 'form-control' : '';
4603 + $site_title = __( 'Confirm Email', 'userswp' );
4604 + $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4605 + $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2334 4606
2335 - <?php
2336 - $html = ob_get_clean();
2337 - }
4607 + ob_start();
2338 4608
2339 - if(has_filter("uwp_form_input_password_{$field->htmlvar_name}_after")){
2340 - $html = apply_filters("uwp_form_input_password_{$field->htmlvar_name}_after",$html, $field, $value, $form_type);
2341 - }
4609 + if ( $design_style ) {
4610 + $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2342 4611
2343 - return $html;
2344 - }
4612 + echo aui()->input(
4613 + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4614 + 'type' => 'email',
4615 + 'id' => esc_attr( $field->htmlvar_name ),
4616 + 'name' => 'confirm_email',
4617 + 'placeholder' => esc_attr( $site_title ),
4618 + 'title' => esc_attr( $site_title ),
4619 + 'value' => esc_attr( $value ),
4620 + 'required' => (bool) $field->is_required,
4621 + 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4622 + 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4623 + 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4624 + 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4625 + )
4626 + );
4627 + } else {
4628 + ?>
4629 + <div id="uwp_account_confirm_email_row"
4630 + class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2345 4631
2346 - /**
2347 - * Adds enctype tag in form for file fields.
2348 - *
2349 - * @since 1.0.0
2350 - * @package userswp
2351 - *
2352 - * @return void
2353 - */
2354 - function add_multipart_to_admin_edit_form() {
2355 - global $wpdb;
2356 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2357 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2358 - if ($fields) {
2359 - echo 'enctype="multipart/form-data"';
2360 - }
2361 - }
4632 + <?php
2362 4633
2363 - /**
2364 - * Handles UsersWP custom field requests from admin.
2365 - *
2366 - * @since 1.0.0
2367 - * @package userswp
2368 - *
2369 - * @param int $user_id User ID.
2370 - *
2371 - * @return void
2372 - */
2373 - public function update_profile_extra_admin_edit($user_id) {
2374 - global $wpdb;
2375 - $file_obj = new UsersWP_Files();
2376 - $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
2377 - //Normal fields
2378 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC");
2379 - if ($fields) {
2380 - $_POST['uwp_account_first_name'] = $_POST['first_name'];
2381 - $_POST['uwp_account_last_name'] = $_POST['last_name'];
2382 - $_POST['uwp_account_display_name'] = $_POST['nickname'];
2383 - $_POST['uwp_account_email'] = $_POST['email'];
2384 - $_POST['uwp_account_bio'] = $_POST['description'];
2385 - $result = uwp_validate_fields($_POST, 'account', $fields);
2386 - if (isset($result['uwp_account_display_name']) && !empty($result['uwp_account_display_name'])) {
2387 - $display_name = $result['uwp_account_display_name'];
2388 - } else {
2389 - if (!empty($first_name) || !empty($last_name)) {
2390 - $display_name = $result['uwp_account_first_name'] . ' ' . $result['uwp_account_last_name'];
2391 - } else {
2392 - $user_info = get_userdata($user_id);
2393 - $display_name = $user_info->user_login;
2394 - }
2395 - }
2396 - $result['uwp_account_display_name'] = $display_name;
2397 - if (!is_wp_error($result)) {
2398 - foreach ($fields as $field) {
2399 - $value = isset($result[$field->htmlvar_name]) ? $result[$field->htmlvar_name] : '';
2400 - if ($value == '0' || !empty($value)) {
2401 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2402 - }
2403 - }
2404 - }
2405 - }
4634 + if ( ! is_admin() ) {
4635 + ?>
4636 + <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4637 + <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
4638 + <?php
4639 + if ( $field->is_required ) {
4640 + echo '<span>*</span>';
4641 + }
4642 + ?>
4643 + </label>
4644 + <?php } ?>
2406 4645
2407 - //File fields
2408 - $fields = $wpdb->get_results("SELECT * FROM " . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC");
2409 - if ($fields) {
2410 - $result = $file_obj->uwp_validate_uploads($_FILES, 'account', true, $fields);
2411 - if (!is_wp_error($result)) {
2412 - foreach ($fields as $field) {
2413 - $value = $result[$field->htmlvar_name];
2414 - if ($value == '0' || !empty($value)) {
2415 - uwp_update_usermeta($user_id, $field->htmlvar_name, $value);
2416 - }
2417 - }
2418 - }
2419 - }
2420 - }
4646 + <input name="confirm_email"
4647 + class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4648 + id="uwp_account_confirm_email"
4649 + placeholder="<?php echo esc_attr( $site_title ); ?>"
4650 + value=""
4651 + title="<?php echo esc_attr( $site_title ); ?>"
4652 + <?php echo 'required="required"'; ?>
4653 + type="email"
4654 + />
4655 + </div>
4656 + <?php
4657 + }
4658 + $confirm_html = ob_get_clean();
4659 + $html = $html . $confirm_html;
4660 + }
4661 + }
2421 4662
4663 + return $html;
4664 + }
2422 4665
2423 - /**
2424 - * Adds search form keyword input html.
2425 - *
2426 - * @since 1.0.0
2427 - * @package userswp
2428 - *
2429 - * @param string $keyword Search keyword.
2430 - *
2431 - * @return void
2432 - */
2433 - public function uwp_users_search_form_text_field($keyword) {
2434 - ?>
2435 - <input placeholder="Search For" name="uwps" value="<?php echo $keyword; ?>" class="s search-input" type="text">
2436 - <?php
2437 - }
4666 + /**
4667 + * Handles the privacy form submission.
4668 + *
4669 + * @return void
4670 + * @package userswp
4671 + *
4672 + * @since 1.0.0
4673 + */
4674 + public function privacy_submit_handler() {
4675 + if ( isset( $_POST['uwp_privacy_submit'] ) ) {
4676 + if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
4677 + return;
4678 + }
2438 4679
2439 - /**
2440 - * Adds search form submit button html.
2441 - *
2442 - * @since 1.0.0
2443 - * @package userswp
2444 - *
2445 - * @return void
2446 - */
2447 - public function uwp_users_search_form_submit() {
2448 - ?>
2449 - <input class="uwp-searchsubmit uwp-search-submit" value="Search" type="submit">
2450 - <?php
2451 - }
4680 + global $wpdb, $uwp_notices;
2452 4681
2453 - /**
2454 - * Checks for errors in mail submission.
2455 - *
2456 - * @since 1.0.0
2457 - * @package userswp
2458 - *
2459 - * @param array $res Result array.
2460 - * @param object $user_data User object.
2461 - * @param WP_Error $errors Error object
2462 - *
2463 - * @return WP_Error|array Error object when error. Result array when success.
2464 - */
2465 - public function uwp_forms_check_for_send_mail_errors($res, $user_data, $errors) {
2466 - if (!$res) {
2467 - if (get_option('admin_email') == $user_data->user_email) {
2468 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please check your site error log for more details.', 'userswp'));
2469 - } else {
2470 - $errors->add('something_wrong', __('<strong>Error</strong>: Something went wrong when sending email. Please contact site admin.', 'userswp'));
2471 - }
2472 - }
4682 + // Save fields privacy settings
4683 + $extra_where = "AND is_public='2'";
4684 + $fields = get_account_form_fields( $extra_where );
4685 + $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
4686 + $user_id = get_current_user_id();
4687 + $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
2473 4688
2474 - $error_code = $errors->get_error_code();
2475 - if (!empty($error_code)) {
2476 - return $errors;
2477 - } else {
2478 - return $res;
2479 - }
2480 -
2481 - }
4689 + $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4690 + if ( ! empty( $user_meta_info->user_privacy ) ) {
4691 + $public_fields = explode( ',', $user_meta_info->user_privacy );
4692 + } else {
4693 + $public_fields = array();
4694 + }
2482 4695
2483 - /**
2484 - * Form field template for country field.
2485 - *
2486 - * @since 1.0.0
2487 - * @package userswp
2488 - *
2489 - * @param string $html Form field html
2490 - * @param object $field Field info.
2491 - * @param string $value Form field default value.
2492 - * @param string $form_type Form type
2493 - *
2494 - * @return string Modified form field html.
2495 - */
2496 - public function uwp_form_input_select_country($html, $field, $value, $form_type){
4696 + if ( $fields ) {
2497 4697
2498 - // Check if there is a field specific filter.
2499 - if(has_filter("uwp_form_input_html_select_{$field->htmlvar_name}")){
2500 - $html = apply_filters("uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type);
2501 - }
4698 + foreach ( $fields as $field ) {
4699 + $field_name = $field->htmlvar_name . '_privacy';
4700 + $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
2502 4701
2503 - //print_r($field);
4702 + if ( $field_value == 'no' ) {
4703 + if ( ! in_array( $field_name, $public_fields ) ) {
4704 + $public_fields[] = $field_name;
4705 + }
4706 + } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
4707 + unset( $public_fields[ $field_name ] );
4708 + }
4709 + }
2504 4710
2505 - // If no html then we run the standard output.
2506 - if(empty($html)) {
4711 + $value = implode( ',', $public_fields );
4712 + uwp_update_usermeta( $user_id, 'user_privacy', $value );
4713 + }
2507 4714
2508 - ob_start(); // Start buffering;
4715 + // Save tabs privacy settings
4716 + $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
4717 + $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
2509 4718
2510 - ?>
2511 - <div id="<?php echo $field->htmlvar_name;?>_row"
2512 - class="<?php if ($field->is_required) echo 'required_field';?> uwp_form_row uwp_clear">
4719 + if ( $tabs ) {
4720 + $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
4721 + $do_tabs_update = false;
4722 + foreach ( $tabs as $tab ) {
4723 + $field_name = $tab->tab_key . '_tab_privacy';
2513 4724
2514 - <?php
2515 - $site_title = uwp_get_form_label($field);
2516 - if (!is_admin()) { ?>
2517 - <label>
2518 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2519 - <?php if ($field->is_required) echo '<span>*</span>';?>
2520 - </label>
2521 - <?php } ?>
4725 + if ( isset( $_POST[ $field_name ] ) ) {
4726 + $do_tabs_update = true;
4727 + $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
2522 4728
2523 - <?php
2524 - // if value empty set the default
2525 - if($value=='' && isset($field->default_value) && $field->default_value){
2526 - $value = $field->default_value;
2527 - }
2528 - $select_country_options = apply_filters('uwp_form_input_select_country',"{defaultCountry: '$value'}",$field, $value, $form_type);
2529 - ?>
4729 + if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
4730 + unset( $public_fields[ $field_name ] );
4731 + } else {
4732 + $public_fields[ $field_name ] = $field_value;
4733 + }
4734 + }
4735 +}
2530 4736
2531 - <input type="text" class="uwp_textfield" title="<?php echo $site_title; ?>" id="<?php echo $field->htmlvar_name;?>" />
2532 - <input type="hidden" id="<?php echo $field->htmlvar_name;?>_code" name="<?php echo $field->htmlvar_name;?>" />
4737 + if ( $do_tabs_update ) {
4738 + uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
4739 + }
4740 + }
2533 4741
2534 - <script>
2535 - jQuery("#<?php echo $field->htmlvar_name;?>").countrySelect(<?php echo $select_country_options;?>);
2536 - </script>
4742 + if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
4743 + update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
4744 + } else {
4745 + update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
4746 + }
2537 4747
4748 + $make_profile_private = uwp_can_make_profile_private();
4749 + if ( $make_profile_private ) {
4750 + $field_name = 'uwp_make_profile_private';
4751 + if ( isset( $_POST[ $field_name ] ) ) {
4752 + $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4753 + $user_id = get_current_user_id();
4754 + update_user_meta( $user_id, $field_name, $value );
4755 + }
4756 + }
2538 4757
2539 - <span class="uwp_message_note"><?php _e($field->help_text, 'userswp');?></span>
2540 - <?php if ($field->is_required) { ?>
2541 - <span class="uwp_message_error"><?php _e($field->required_msg, 'userswp'); ?></span>
2542 - <?php } ?>
2543 - </div>
4758 + $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
4759 + $message = aui()->alert(
4760 + array(
4761 + 'type' => 'success',
4762 + 'content' => $message,
4763 + )
4764 + );
4765 + $uwp_notices[] = array( 'account' => $message );
2544 4766
2545 - <?php
2546 - $html = ob_get_clean();
4767 + }
4768 + }
4769 +
4770 + /**
4771 + * Get the ajax login form.
4772 + *
4773 + * @since 1.2.0
4774 + */
4775 + public function ajax_login_form() {
4776 +
4777 + // add the modal error container
4778 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4779 +
4780 + $args = array(
4781 + 'form_title' => __( 'Login', 'userswp' ),
4782 + );
4783 +
4784 + // get the form
4785 + ob_start();
4786 + uwp_get_template( 'bootstrap/login.php', $args );
4787 + $form = ob_get_clean();
4788 +
4789 + // bs5
4790 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4791 + $form = aui_bs_convert_sd_output( $form );
2547 4792 }
4793 + // send ajax response
4794 + wp_send_json_success( $form );
4795 + }
2548 4796
2549 - return $html;
2550 - }
4797 + /**
4798 + * Get the ajax register form.
4799 + *
4800 + * @since 1.2.0
4801 + */
4802 + public function ajax_register_form() {
2551 4803
2552 - /**
2553 - * Prints the username link in "Edit Account" page
2554 - *
2555 - * @since 1.0.0
2556 - * @package userswp
2557 - *
2558 - * @param string $type Page type.
2559 - *
2560 - * @return void
2561 - */
2562 - public function uwp_display_username_in_account($type) {
2563 - if ($type == 'account') {
2564 - $user_id = get_current_user_id();
2565 - $user_info = get_userdata($user_id);
2566 - $display_name = $user_info->user_login;
2567 - ?>
2568 - <span class="uwp_account_page_username">
2569 - <a href="<?php echo uwp_build_profile_tab_url($user_id); ?>">( @<?php echo $display_name; ?> )</a>
2570 - </span>
2571 - <?php
2572 - }
2573 - }
4804 + // add the modal error container
4805 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2574 4806
4807 + global $wp_scripts;
4808 + if ( empty( $wp_scripts ) ) {
4809 + $wp_scripts = wp_scripts();
4810 + }
2575 4811
2576 - /**
2577 - * Adds confirm password field in forms.
2578 - *
2579 - * @since 1.0.0
2580 - * @package userswp
2581 - *
2582 - * @param string $html Form field html
2583 - * @param object $field Field info.
2584 - * @param string $value Form field default value.
2585 - * @param string $form_type Form type
2586 - *
2587 - * @return string Modified form field html.
2588 - */
2589 - public function uwp_register_confirm_password_field($html, $field, $value, $form_type) {
2590 - if ($form_type == 'register') {
2591 - //confirm password field
2592 - $extra = array();
2593 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2594 - $extra = unserialize($field->extra_fields);
2595 - }
2596 - $enable_confirm_password_field = isset($extra['confirm_password']) ? $extra['confirm_password'] : '0';
2597 - if ($enable_confirm_password_field == '1') {
2598 - ob_start(); // Start buffering;
2599 - ?>
2600 - <div id="uwp_account_confirm_password_row"
2601 - class="<?php echo 'required_field';?> uwp_form_password_row uwp_clear">
4812 + // do we need country code script in ajax?
4813 + $country_field = false;
4814 + $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
2602 4815
2603 - <?php
2604 - $site_title = __("Confirm Password", 'userswp');
2605 - if (!is_admin()) { ?>
2606 - <label>
2607 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2608 - <?php echo '<span>*</span>'; ?>
2609 - </label>
2610 - <?php } ?>
4816 + if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
4817 + $form_id = (int)$_POST['form_id'];
4818 + } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
4819 + $form_id = reset( $lightbox_forms );
4820 + } else {
4821 + $form_id = 1;
4822 + }
2611 4823
2612 - <input name="uwp_account_confirm_password"
2613 - class="uwp_textfield"
2614 - id="uwp_account_confirm_password"
2615 - placeholder="<?php echo $site_title; ?>"
2616 - value=""
2617 - title="<?php echo $site_title; ?>"
2618 - <?php echo 'required="required"'; ?>
2619 - type="password"
2620 - />
2621 - </div>
4824 + $fields = get_register_form_fields( $form_id );
4825 + if ( ! empty( $fields ) ) {
4826 + foreach ( $fields as $field ) {
4827 + if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
4828 + $country_field = true;
4829 + }
4830 + }
4831 + }
2622 4832
2623 - <?php
2624 - $confirm_html = ob_get_clean();
2625 - $html = $html.$confirm_html;
2626 - }
2627 - }
2628 - return $html;
2629 - }
4833 + ob_start();
2630 4834
2631 - /**
2632 - * Adds confirm email field in forms.
2633 - *
2634 - * @since 1.0.0
2635 - * @package userswp
2636 - *
2637 - * @param string $html Form field html
2638 - * @param object $field Field info.
2639 - * @param string $value Form field default value.
2640 - * @param string $form_type Form type
2641 - *
2642 - * @return string Modified form field html.
2643 - */
2644 - public function uwp_register_confirm_email_field($html, $field, $value, $form_type) {
2645 - if ($form_type == 'register') {
2646 - //confirm email field
2647 - $extra = array();
2648 - if (isset($field->extra_fields) && $field->extra_fields != '') {
2649 - $extra = unserialize($field->extra_fields);
2650 - }
2651 - $enable_confirm_email_field = isset($extra['confirm_email']) ? $extra['confirm_email'] : '0';
2652 - if ($enable_confirm_email_field == '1') {
2653 - ob_start(); // Start buffering;
2654 - ?>
2655 - <div id="uwp_account_confirm_email_row"
2656 - class="<?php echo 'required_field';?> uwp_form_email_row uwp_clear">
4835 + // maybe add country code JS
4836 + if ( $country_field ) {
4837 + $country_data = uwp_get_country_data();
4838 + echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
4839 + echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
4840 + }
2657 4841
2658 - <?php
2659 - $site_title = __("Confirm Email", 'userswp');
2660 - if (!is_admin()) { ?>
2661 - <label>
2662 - <?php echo (trim($site_title)) ? $site_title : '&nbsp;'; ?>
2663 - <?php echo '<span>*</span>'; ?>
2664 - </label>
2665 - <?php } ?>
4842 + $args = array( 'form_title' => '' );
4843 + if ( $form_id > 0 ) {
4844 + $args['id'] = $form_id;
4845 + }
2666 4846
2667 - <input name="uwp_account_confirm_email"
2668 - class="uwp_textfield"
2669 - id="uwp_account_confirm_email"
2670 - placeholder="<?php echo $site_title; ?>"
2671 - value=""
2672 - title="<?php echo $site_title; ?>"
2673 - <?php echo 'required="required"'; ?>
2674 - type="email"
2675 - />
2676 - </div>
4847 + $args['limit'] = $lightbox_forms;
2677 4848
2678 - <?php
2679 - $confirm_html = ob_get_clean();
2680 - $html = $html.$confirm_html;
2681 - }
4849 + // get template
4850 + uwp_get_template( 'bootstrap/register.php', $args );
4851 +
4852 + // only show the JS if NOT doing a block render
4853 + if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
4854 + // load scripts
4855 + $wp_scripts->do_item( 'zxcvbn-async' );
4856 + $wp_scripts->do_item( 'wp-hooks' );
4857 + $wp_scripts->do_item( 'wp-i18n' );
4858 + $wp_scripts->do_item( 'password-strength-meter' );
4859 + ?>
4860 + <script>
4861 + // Password strength indicator script
4862 + jQuery(function ($) {
4863 +
4864 + // Load the settings like WP does.
4865 + var first, s;
4866 + s = document.createElement('script');
4867 + s.src = _zxcvbnSettings.src;
4868 + s.type = 'text/javascript';
4869 + s.async = true;
4870 + first = document.getElementsByTagName('script')[0];
4871 + first.parentNode.insertBefore(s, first);
4872 +
4873 + // Enable any pass inputs.
4874 + $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
4875 + function (event) {
4876 + var $form = $(this).closest('form');
4877 + if( ! $form.hasClass('uwp-login-form') ) {
4878 + uwp_checkPasswordStrength(
4879 + $('input[name=password]', $form), // First password field
4880 + $('input[name=confirm_password]', $form), // Second password field
4881 + $('#uwp-password-strength', $form), // Strength meter
4882 + $('input[type=submit]', $form), // Submit button
4883 + ['black', 'listed', 'word'] // Blacklisted words
4884 + );
4885 + }
4886 + }
4887 + );
4888 + });
4889 + </script>
4890 + <?php
4891 + }
4892 + $form = ob_get_clean();
4893 +
4894 + // bs5
4895 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4896 + $form = aui_bs_convert_sd_output( $form );
2682 4897 }
2683 - return $html;
2684 - }
2685 4898
4899 + // send ajax response
4900 + wp_send_json_success( $form );
4901 + }
2686 4902
2687 - /**
2688 - * Handles the privacy form submission.
2689 - *
2690 - * @since 1.0.0
2691 - * @package userswp
2692 - *
2693 - * @return void
2694 - */
2695 - public function uwp_privacy_submit_handler() {
2696 - if (isset($_POST['uwp_privacy_submit'])) {
2697 - if( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
2698 - return;
2699 - }
4903 + /**
4904 + * Get the ajax forgot password form.
4905 + *
4906 + * @since 1.2.0
4907 + */
4908 + public function ajax_forgot_password_form() {
2700 4909
2701 - $extra_where = "AND is_public='2'";
2702 - $fields = get_account_form_fields($extra_where);
2703 - $fields = apply_filters('uwp_account_privacy_fields', $fields);
2704 - if ($fields) {
2705 - foreach ($fields as $field) {
2706 - $field_name = $field->htmlvar_name.'_privacy';
2707 - if (isset($_POST[$field_name])) {
2708 - $value = strip_tags(esc_sql($_POST[$field_name]));
2709 - $user_id = get_current_user_id();
2710 - uwp_update_usermeta($user_id, $field_name, $value);
2711 - }
2712 - }
2713 - }
4910 + // add the modal error container
4911 + add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
2714 4912
2715 - $user_id = get_current_user_id();
2716 - if (isset($_POST['uwp_hide_from_listing']) && 1 == $_POST['uwp_hide_from_listing']) {
2717 - update_user_meta($user_id, 'uwp_hide_from_listing', 1);
2718 - } else {
2719 - update_user_meta($user_id, 'uwp_hide_from_listing', 0);
2720 - }
4913 + // get the form
4914 + ob_start();
4915 + uwp_get_template( 'bootstrap/forgot.php' );
4916 + $form = ob_get_clean();
2721 4917
2722 - $make_profile_private = uwp_can_make_profile_private();
2723 - if ($make_profile_private) {
2724 - $field_name = 'uwp_make_profile_private';
2725 - if (isset($_POST[$field_name])) {
2726 - $value = strip_tags(esc_sql($_POST[$field_name]));
2727 - $user_id = get_current_user_id();
2728 - update_user_meta($user_id, $field_name, $value);
2729 - }
2730 - }
4918 + // bs5
4919 + if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4920 + $form = aui_bs_convert_sd_output( $form );
4921 + }
2731 4922
2732 - }
2733 - }
4923 + // send ajax response
4924 + wp_send_json_success( $form );
4925 + }
2734 4926
2735 -}
4927 + /**
4928 + * Output the modal error container.
4929 + *
4930 + * @param string $type
4931 + *
4932 + * @since 1.2.0
4933 + */
4934 + public function modal_error_container( $type = '' ) {
4935 + echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
4936 + }
4937 +
4938 + public function form_custom_html( $html, $field, $value, $form_type ) {
4939 +
4940 + $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
4941 +
4942 + return $html;
4943 + }
4944 +}