| @@ -102,26 +102,27 @@ | ||
| 102 | 102 | $processed = true; |
| 103 | 103 | } |
| 104 | 104 | |
| 105 | 105 | if ( $processed ) { |
| 106 | + | |
| 106 | 107 | if ( is_wp_error( $errors ) ) { |
| 107 | - aui()->alert( | |
| 108 | - array( | |
| 109 | - 'type' => 'error', | |
| 110 | - 'content' => wp_kses_post( $errors->get_error_message() ) | |
| 111 | - ), | |
| 112 | - true | |
| 113 | - ); | |
| 114 | - } else if ( $redirect ) { | |
| 108 | + echo aui()->alert( | |
| 109 | + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 110 | + 'type' => 'error', | |
| 111 | + 'class' => 'text-center', | |
| 112 | + 'content' => wp_kses_post( $errors->get_error_message() ), | |
| 113 | + ) | |
| 114 | + ); | |
| 115 | + } elseif ( $redirect ) { | |
| 115 | 116 | wp_safe_redirect( $redirect ); |
| 116 | 117 | exit(); |
| 117 | - } else { | |
| 118 | - aui()->alert( | |
| 119 | - array( | |
| 120 | - 'type' => 'success', | |
| 121 | - 'content' => wp_kses_post( $message ) | |
| 122 | - ), | |
| 123 | - true | |
| 118 | + } else { | |
| 119 | + echo aui()->alert( | |
| 120 | + array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 121 | + 'type' => 'success', | |
| 122 | + 'class' => 'text-center', | |
| 123 | + 'content' => wp_kses_post( $message ), | |
| 124 | + ) | |
| 124 | 125 | ); |
| 125 | 126 | } |
| 126 | 127 | } |
| 127 | 128 | |
| @@ -195,9 +196,8 @@ | ||
| 195 | 196 | * @since 1.0.0 |
| 196 | 197 | */ |
| 197 | 198 | public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) { |
| 198 | 199 | global $wpdb; |
| 199 | - | |
| 200 | 200 | if ( ! is_user_logged_in() ) { |
| 201 | 201 | return false; |
| 202 | 202 | } |
| 203 | 203 | |
| @@ -204,29 +204,8 @@ | ||
| 204 | 204 | if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) { |
| 205 | 205 | return; |
| 206 | 206 | } |
| 207 | 207 | |
| 208 | - $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : ''; | |
| 209 | - | |
| 210 | - if ( empty( $image_url ) ) { | |
| 211 | - return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) ); | |
| 212 | - } | |
| 213 | - | |
| 214 | - // Ensure we have a valid URL with an allowed meme type. | |
| 215 | - $image_url = $this->normalize_url( $image_url ); | |
| 216 | - | |
| 217 | - $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) ); | |
| 218 | - $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url ); | |
| 219 | - if ( strpos( $_image_url, $content_url ) !== 0 ) { | |
| 220 | - return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) ); | |
| 221 | - } | |
| 222 | - | |
| 223 | - $filetype = wp_check_filetype( $image_url ); | |
| 224 | - | |
| 225 | - if ( empty( $filetype['ext'] ) ) { | |
| 226 | - return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) ); | |
| 227 | - } | |
| 228 | - | |
| 229 | 208 | // If is current user's profile (profile.php) |
| 230 | 209 | if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) { |
| 231 | 210 | $user_id = get_current_user_id(); |
| 232 | 211 | // If is another user's profile page |
| @@ -236,8 +215,21 @@ | ||
| 236 | 215 | } else { |
| 237 | 216 | $user_id = get_current_user_id(); |
| 238 | 217 | } |
| 239 | 218 | |
| 219 | + // Ensure we have a valid URL with an allowed meme type. | |
| 220 | + $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) ); | |
| 221 | + $filetype = wp_check_filetype( $image_url ); | |
| 222 | + | |
| 223 | + $errors = new WP_Error(); | |
| 224 | + if ( empty( $image_url ) || empty( $filetype['ext'] ) ) { | |
| 225 | + $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) ); | |
| 226 | + } | |
| 227 | + | |
| 228 | + if ( $errors->has_errors() ) { | |
| 229 | + return $errors; | |
| 230 | + } | |
| 231 | + | |
| 240 | 232 | // Retrieve current thumbnail. |
| 241 | 233 | $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb'; |
| 242 | 234 | $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) ); |
| 243 | 235 | $thumb_postfix = '_uwp_' . $type . '_thumb'; |
| @@ -260,14 +252,13 @@ | ||
| 260 | 252 | $ext = $filetype['ext']; // to get extension |
| 261 | 253 | $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension |
| 262 | 254 | $thumb_image_name = $name . $thumb_postfix . '.' . $ext; |
| 263 | 255 | $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path ); |
| 264 | - | |
| 265 | 256 | //Get the new coordinates to crop the image. |
| 266 | - $x = $data['uwpx']; | |
| 267 | - $y = $data['uwpy']; | |
| 268 | - $w = $data['uwpw']; | |
| 269 | - $h = $data['uwph']; | |
| 257 | + $x = $data['x']; | |
| 258 | + $y = $data['y']; | |
| 259 | + $w = $data['w']; | |
| 260 | + $h = $data['h']; | |
| 270 | 261 | //Scale the image based on cropped width setting |
| 271 | 262 | $scale = $full_width / $w; |
| 272 | 263 | //$scale = 1; // no scaling |
| 273 | 264 | |
| @@ -327,11 +318,8 @@ | ||
| 327 | 318 | * |
| 328 | 319 | */ |
| 329 | 320 | public function normalize_url( $url ) { |
| 330 | 321 | |
| 331 | - if ( empty( $url ) ) { | |
| 332 | - return ''; | |
| 333 | - } | |
| 334 | 322 | // Normalize. |
| 335 | 323 | $url = wp_normalize_path( $url ); |
| 336 | 324 | |
| 337 | 325 | // Remove query vars. |
| @@ -360,20 +348,22 @@ | ||
| 360 | 348 | if ( ! is_user_logged_in() ) { |
| 361 | 349 | return false; |
| 362 | 350 | } |
| 363 | 351 | |
| 352 | + if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) { | |
| 353 | + return; | |
| 354 | + } | |
| 355 | + | |
| 364 | 356 | if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) { |
| 365 | 357 | $user_id = get_current_user_id(); |
| 366 | - } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) { | |
| 358 | + // If is another user's profile page | |
| 359 | + } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) { | |
| 367 | 360 | $user_id = absint( $_GET['user_id'] ); |
| 361 | + // Otherwise something is wrong. | |
| 368 | 362 | } else { |
| 369 | 363 | $user_id = get_current_user_id(); |
| 370 | 364 | } |
| 371 | 365 | |
| 372 | - if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) { | |
| 373 | - return; | |
| 374 | - } | |
| 375 | - | |
| 376 | 366 | $errors = new WP_Error(); |
| 377 | 367 | if ( empty( $user_id ) ) { |
| 378 | 368 | $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) ); |
| 379 | 369 | } |
| @@ -533,15 +523,9 @@ | ||
| 533 | 523 | if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) { |
| 534 | 524 | wp_die( esc_html__( 'No spam please!', 'userswp' ) ); |
| 535 | 525 | } |
| 536 | 526 | |
| 537 | - $form_id = 1; | |
| 538 | - | |
| 539 | - if ( ! empty( $data['uwp_register_form_id'] ) ) { | |
| 540 | - $form_id = (int) $data['uwp_register_form_id']; | |
| 541 | - } | |
| 542 | - | |
| 543 | - if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) { | |
| 527 | + if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) { | |
| 544 | 528 | $message = aui()->alert( |
| 545 | 529 | array( |
| 546 | 530 | 'type' => 'error', |
| 547 | 531 | 'content' => __( 'Security verification failed. Try again.', 'userswp' ), |
| @@ -713,8 +697,14 @@ | ||
| 713 | 697 | 'last_name' => esc_attr( $last_name ), |
| 714 | 698 | 'user_url' => esc_url_raw( $user_url ), |
| 715 | 699 | ); |
| 716 | 700 | |
| 701 | + $form_id = 1; | |
| 702 | + | |
| 703 | + if ( ! empty( $data['uwp_register_form_id'] ) ) { | |
| 704 | + $form_id = (int) $data['uwp_register_form_id']; | |
| 705 | + } | |
| 706 | + | |
| 717 | 707 | // Set user role by form. |
| 718 | 708 | $user_role = uwp_get_register_form_by( $form_id, 'user_role' ); |
| 719 | 709 | |
| 720 | 710 | if ( ! empty( $user_role ) ) { |
| @@ -1672,21 +1662,12 @@ | ||
| 1672 | 1662 | |
| 1673 | 1663 | // make sure user account is active before account reset |
| 1674 | 1664 | $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true ); |
| 1675 | 1665 | if ( $mod_value == 'email_unconfirmed' ) { |
| 1676 | - $resend_link = uwp_get_forgot_page_url(); | |
| 1677 | - $resend_link = add_query_arg( | |
| 1678 | - array( | |
| 1679 | - 'user_id' => $user_data->ID, | |
| 1680 | - 'action' => 'uwp_resend', | |
| 1681 | - '_nonce' => wp_create_nonce('uwp_resend'), | |
| 1682 | - ), | |
| 1683 | - $resend_link | |
| 1684 | - ); | |
| 1685 | 1666 | $message = aui()->alert( |
| 1686 | 1667 | array( |
| 1687 | 1668 | 'type' => 'error', |
| 1688 | - 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link), | |
| 1669 | + 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ), | |
| 1689 | 1670 | ) |
| 1690 | 1671 | ); |
| 1691 | 1672 | if ( wp_doing_ajax() ) { |
| 1692 | 1673 | wp_send_json_error( $message ); |
| @@ -1691,8 +1672,9 @@ | ||
| 1691 | 1672 | if ( wp_doing_ajax() ) { |
| 1692 | 1673 | wp_send_json_error( $message ); |
| 1693 | 1674 | } else { |
| 1694 | 1675 | $uwp_notices[] = array( 'forgot' => $message ); |
| 1676 | + | |
| 1695 | 1677 | return; |
| 1696 | 1678 | } |
| 1697 | 1679 | } |
| 1698 | 1680 | |
| @@ -1985,9 +1967,9 @@ | ||
| 1985 | 1967 | $file_obj = new UsersWP_Files(); |
| 1986 | 1968 | |
| 1987 | 1969 | do_action( 'uwp_before_validate', 'account' ); |
| 1988 | 1970 | |
| 1989 | - $result = uwp_validate_fields( $data, 'account', false, "AND `field_type` != 'file'" ); | |
| 1971 | + $result = uwp_validate_fields( $data, 'account' ); | |
| 1990 | 1972 | |
| 1991 | 1973 | $result = apply_filters( 'uwp_validate_result', $result, 'account', $data ); |
| 1992 | 1974 | |
| 1993 | 1975 | if ( is_wp_error( $result ) ) { |
| @@ -2255,87 +2237,46 @@ | ||
| 2255 | 2237 | * @package userswp |
| 2256 | 2238 | * @since 1.0.0 |
| 2257 | 2239 | */ |
| 2258 | 2240 | public function upload_file_remove() { |
| 2259 | - global $wpdb; | |
| 2260 | - | |
| 2261 | 2241 | check_ajax_referer( 'uwp_basic_nonce', 'security' ); |
| 2262 | 2242 | |
| 2263 | - // Check user logged in. | |
| 2264 | - if ( ! is_user_logged_in() ) { | |
| 2265 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) ); | |
| 2266 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2267 | - } | |
| 2268 | - | |
| 2243 | + $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) ); | |
| 2269 | 2244 | $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0; |
| 2270 | - $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : ''; | |
| 2271 | 2245 | |
| 2272 | - if ( empty( $user_id ) || empty( $htmlvar ) ) { | |
| 2273 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) ); | |
| 2274 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2246 | + if ( empty( $user_id ) ) { | |
| 2247 | + wp_die( -1 ); | |
| 2275 | 2248 | } |
| 2276 | 2249 | |
| 2277 | - // Validate the user / admin. | |
| 2278 | - if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) { | |
| 2279 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) ); | |
| 2280 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2250 | + if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) { | |
| 2251 | + wp_send_json_error( __( 'Invalid access!', 'userswp' ) ); | |
| 2281 | 2252 | } |
| 2282 | 2253 | |
| 2254 | + // Remove file | |
| 2283 | 2255 | if ( $htmlvar == 'banner_thumb' ) { |
| 2284 | - $field_key = 'banner'; | |
| 2256 | + $file = uwp_get_usermeta( $user_id, 'banner_thumb' ); | |
| 2285 | 2257 | $type = 'banner'; |
| 2286 | - } else if ( $htmlvar == 'avatar_thumb' ) { | |
| 2287 | - $field_key = 'avatar'; | |
| 2258 | + } elseif ( $htmlvar == 'avatar_thumb' ) { | |
| 2259 | + $file = uwp_get_usermeta( $user_id, 'avatar_thumb' ); | |
| 2288 | 2260 | $type = 'avatar'; |
| 2289 | 2261 | } else { |
| 2290 | - $field_key = $htmlvar; | |
| 2262 | + $file = ''; | |
| 2291 | 2263 | $type = ''; |
| 2292 | 2264 | } |
| 2293 | 2265 | |
| 2294 | - $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) ); | |
| 2295 | - | |
| 2296 | - // Check field exists. | |
| 2297 | - if ( empty( $field ) ) { | |
| 2298 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) ); | |
| 2299 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2300 | - } | |
| 2301 | - | |
| 2302 | - // Validate field access. | |
| 2303 | - if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) { | |
| 2304 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) ); | |
| 2305 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2306 | - } | |
| 2307 | - | |
| 2308 | - if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) { | |
| 2309 | - $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) ); | |
| 2310 | - wp_send_json_error( array( 'message' => $message ) ); | |
| 2311 | - } | |
| 2312 | - | |
| 2313 | - $value = uwp_get_usermeta( $user_id, $htmlvar ); | |
| 2314 | - | |
| 2315 | 2266 | uwp_update_usermeta( $user_id, $htmlvar, '' ); |
| 2316 | 2267 | |
| 2317 | - if ( $value && validate_file( $value ) === 0 ) { | |
| 2268 | + if ( $file ) { | |
| 2318 | 2269 | $uploads = wp_upload_dir(); |
| 2319 | 2270 | $upload_path = $uploads['basedir']; |
| 2271 | + $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' ); | |
| 2320 | 2272 | |
| 2321 | - if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) { | |
| 2322 | - // Get the relative url. | |
| 2323 | - $value = uwp_get_file_relative_url( $value ); | |
| 2324 | - } | |
| 2325 | - | |
| 2326 | - $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' ); | |
| 2327 | - | |
| 2328 | 2273 | if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) { |
| 2329 | - wp_delete_file( $unlink_file ); | |
| 2274 | + @unlink( $unlink_file ); | |
| 2275 | + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file ); | |
| 2330 | 2276 | |
| 2331 | - // For avatar/banner, also remove the original (non-thumb) file. | |
| 2332 | - if ( $type ) { | |
| 2333 | - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file ); | |
| 2334 | - | |
| 2335 | - if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) { | |
| 2336 | - wp_delete_file( $unlink_ori_file ); | |
| 2337 | - } | |
| 2277 | + if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) { | |
| 2278 | + @unlink( $unlink_ori_file ); | |
| 2338 | 2279 | } |
| 2339 | 2280 | } |
| 2340 | 2281 | } |
| 2341 | 2282 | |
| @@ -4369,9 +4310,9 @@ | ||
| 4369 | 4310 | // If no html then we run the standard output. |
| 4370 | 4311 | if ( empty( $html ) ) { |
| 4371 | 4312 | |
| 4372 | 4313 | $design_style = uwp_get_option( 'design_style', 'bootstrap' ); |
| 4373 | - $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours | |
| 4314 | + $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours | |
| 4374 | 4315 | $bs_sr_only = $design_style ? 'sr-only' : ''; |
| 4375 | 4316 | $bs_form_control = $design_style ? 'form-control' : ''; |
| 4376 | 4317 | |
| 4377 | 4318 | ob_start(); // Start buffering; |
| @@ -4934,13 +4875,13 @@ | ||
| 4934 | 4875 | function (event) { |
| 4935 | 4876 | var $form = $(this).closest('form'); |
| 4936 | 4877 | if( ! $form.hasClass('uwp-login-form') ) { |
| 4937 | 4878 | uwp_checkPasswordStrength( |
| 4938 | - $form.find('input[name=password]'), | |
| 4939 | - $form.find('input[name=confirm_password]'), | |
| 4940 | - $form.find('#uwp-password-strength'), | |
| 4941 | - $form.find('button[type="submit"], input[type="submit"]'), | |
| 4942 | - ['black', 'listed', 'word'] | |
| 4879 | + $('input[name=password]', $form), // First password field | |
| 4880 | + $('input[name=confirm_password]', $form), // Second password field | |
| 4881 | + $('#uwp-password-strength', $form), // Strength meter | |
| 4882 | + $('input[type=submit]', $form), // Submit button | |
| 4883 | + ['black', 'listed', 'word'] // Blacklisted words | |
| 4943 | 4884 | ); |
| 4944 | 4885 | } |
| 4945 | 4886 | } |
| 4946 | 4887 | ); |
| @@ -4967,15 +4908,12 @@ | ||
| 4967 | 4908 | public function ajax_forgot_password_form() { |
| 4968 | 4909 | |
| 4969 | 4910 | // add the modal error container |
| 4970 | 4911 | add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) ); |
| 4971 | - $args = array( | |
| 4972 | - 'form_title' => '', | |
| 4973 | - 'css_class' => '' | |
| 4974 | - ); | |
| 4912 | + | |
| 4975 | 4913 | // get the form |
| 4976 | 4914 | ob_start(); |
| 4977 | - uwp_get_template( 'bootstrap/forgot.php', $args ); | |
| 4915 | + uwp_get_template( 'bootstrap/forgot.php' ); | |
| 4978 | 4916 | $form = ob_get_clean(); |
| 4979 | 4917 | |
| 4980 | 4918 | // bs5 |
| 4981 | 4919 | if ( function_exists( 'aui_bs_convert_sd_output' ) ) { |