PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.51
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.51
1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 1.0.23 All 172 releases
userswp / includes / class-forms.php

class-forms.php in UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 1.2.51, at includes/class-forms.php

4,945 lines 170.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * Form related functions
5 *
6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
7 *
8 * @since 1.0.0
9 * @author GeoDirectory Team <info@wpgeodirectory.com>
10 */
11 class UsersWP_Forms {
12
13 protected $generated_password;
14
15 /**
16 * Logs the error message.
17 *
18 * @param array|object|string $log Error message.
19 *
20 * @return void
21 * @since 1.0.0
22 * @package userswp
23 *
24 */
25 public static function uwp_error_log( $log ) {
26 uwp_error_log( $log );
27 }
28
29 /**
30 * Initialize UsersWP notices.
31 *
32 * @return void
33 * @package userswp
34 *
35 * @since 1.0.0
36 */
37 public function init_notices() {
38 global $uwp_notices;
39 $uwp_notices = array();
40 }
41
42 /**
43 * Handles all UsersWP forms.
44 *
45 * @return void
46 * @package userswp
47 *
48 * @since 1.0.0
49 */
50 public function handler() {
51 global $uwp_notices;
52
53 ob_start();
54
55 $errors = null;
56 $message = null;
57 $redirect = false;
58 $processed = false;
59 $type = null;
60
61 if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 if ( ! is_wp_error( $errors ) ) {
64 $redirect = $errors;
65 }
66 $message = __( 'Avatar cropped successfully.', 'userswp' );
67 $processed = true;
68 } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 if ( ! is_wp_error( $errors ) ) {
71 $redirect = $errors;
72 }
73 $message = __( 'Banner cropped successfully.', 'userswp' );
74 $processed = true;
75 } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 if ( ! is_wp_error( $errors ) ) {
78 $redirect = $errors;
79 }
80 $message = __( 'Avatar cropped successfully.', 'userswp' );
81 $processed = true;
82 } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 $errors = $this->process_image_crop( $_POST, 'banner', true );
84 if ( ! is_wp_error( $errors ) ) {
85 $redirect = $errors;
86 }
87 $message = __( 'Banner cropped successfully.', 'userswp' );
88 $processed = true;
89 } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 $errors = $this->process_image_reset( 'avatar' );
91 if ( ! is_wp_error( $errors ) ) {
92 $redirect = $errors;
93 }
94 $message = __( 'Avatar reset successfully.', 'userswp' );
95 $processed = true;
96 } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 $errors = $this->process_image_reset( 'banner' );
98 if ( ! is_wp_error( $errors ) ) {
99 $redirect = $errors;
100 }
101 $message = __( 'Banner reset successfully.', 'userswp' );
102 $processed = true;
103 }
104
105 if ( $processed ) {
106
107 if ( is_wp_error( $errors ) ) {
108 echo aui()->alert(
109 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
110 'type' => 'error',
111 'class' => 'text-center',
112 'content' => wp_kses_post( $errors->get_error_message() ),
113 )
114 );
115 } elseif ( $redirect ) {
116 wp_safe_redirect( $redirect );
117 exit();
118 } else {
119 echo aui()->alert(
120 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
121 'type' => 'success',
122 'class' => 'text-center',
123 'content' => wp_kses_post( $message ),
124 )
125 );
126 }
127 }
128
129 if ( $type ) {
130 $uwp_notices[] = array( $type => ob_get_contents() );
131 } else {
132 $uwp_notices[] = ob_get_contents();
133 }
134
135 ob_end_clean();
136 }
137
138 /**
139 * Processes avatar and banner uploads form submission.
140 *
141 * @param array $data Submitted $_POST data
142 * @param array $files Submitted $_FILES data
143 *
144 * @return bool|WP_Error|string File url to crop.
145 * @package userswp
146 *
147 * @since 1.0.0
148 */
149 public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
150
151 $file_obj = new UsersWP_Files();
152
153 $current_user_id = get_current_user_id();
154 if ( ! $current_user_id ) {
155 return false;
156 }
157
158 if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
159 return false;
160 }
161
162 do_action( 'uwp_before_validate', $type );
163
164 $result = $file_obj->validate_uploads( $files, $type );
165
166 $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
167
168 if ( is_wp_error( $result ) ) {
169 return $result;
170 }
171
172 $profile_url = uwp_build_profile_tab_url( $current_user_id );
173
174 $url = add_query_arg(
175 array(
176 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
177 'type' => $type,
178 ),
179 $profile_url
180 );
181
182 return $url;
183 }
184
185 /**
186 * Processes avatar and banner uploads image crop.
187 *
188 * @param array $data Submitted $_POST data
189 * @param string $type Image type. Default 'avatar'.
190 * @param bool $unlink_prev_img True to remove previous image. Default false;
191 *
192 * @return bool|WP_Error|string Profile url.
193 * @since 1.0.12 New param $unlink_prev_img introduced.
194 * @package userswp
195 *
196 * @since 1.0.0
197 */
198 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
199 global $wpdb;
200 if ( ! is_user_logged_in() ) {
201 return false;
202 }
203
204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 return;
206 }
207
208 // If is current user's profile (profile.php)
209 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
210 $user_id = get_current_user_id();
211 // If is another user's profile page
212 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
213 $user_id = absint( $_GET['user_id'] );
214 // Otherwise something is wrong.
215 } else {
216 $user_id = get_current_user_id();
217 }
218
219 // Ensure we have a valid URL with an allowed meme type.
220 $image_url = $this->normalize_url( esc_url( $data['uwp_crop'] ) );
221 $filetype = wp_check_filetype( $image_url );
222
223 $errors = new WP_Error();
224 if ( empty( $image_url ) || empty( $filetype['ext'] ) ) {
225 $errors->add( 'something_wrong', __( 'Something went wrong. Please contact site admin.', 'userswp' ) );
226 }
227
228 if ( $errors->has_errors() ) {
229 return $errors;
230 }
231
232 // Retrieve current thumbnail.
233 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
234 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
235 $thumb_postfix = '_uwp_' . $type . '_thumb';
236
237 if ( $image_url ) {
238 if ( $type == 'avatar' ) {
239 $avatar_size = uwp_get_upload_image_size();
240 $full_width = $avatar_size['width'];
241 } else {
242 $banner_size = uwp_get_upload_image_size( 'banner' );
243 $full_width = $banner_size['width'];
244 }
245
246 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
247 $uploads = wp_upload_dir();
248 remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
249 $upload_url = $uploads['baseurl'];
250 $upload_path = $uploads['basedir'];
251 $image_path = str_replace( $upload_url, $upload_path, $image_url );
252 $ext = $filetype['ext']; // to get extension
253 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
254 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
255 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
256 //Get the new coordinates to crop the image.
257 $x = $data['x'];
258 $y = $data['y'];
259 $w = $data['w'];
260 $h = $data['h'];
261 //Scale the image based on cropped width setting
262 $scale = $full_width / $w;
263 //$scale = 1; // no scaling
264
265 // check we are not editing another user file
266 $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
267 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
268 $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
269
270 // if file already exists then we should not be cropping it.
271 if ( $file_exists ) {
272 wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
273 }
274
275 $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
276 $cropped = str_replace( $upload_path, $upload_url, $cropped );
277
278 // Remove previous avatar/banner
279 $unlink_img = '';
280 if ( $unlink_prev_img && $current_thumbnail ) {
281 $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
282 }
283
284 // remove the uploads path for easy migrations
285 $cropped = str_replace( $upload_url, '', $cropped );
286 if ( $type == 'avatar' ) {
287 uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
288 } else {
289 uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
290 }
291
292 if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
293 @unlink( $unlink_img );
294 $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
295 if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
296 @unlink( $unlink_ori_img );
297 }
298 }
299 }
300
301 if ( is_admin() ) {
302 if ( $user_id == get_current_user_id() ) {
303 $redirect_url = admin_url( 'profile.php' );
304 } else {
305 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
306 }
307 } elseif ( uwp_current_page_url() ) {
308 $redirect_url = uwp_current_page_url();
309 } else {
310 $redirect_url = uwp_build_profile_tab_url( $user_id );
311 }
312
313 return $redirect_url;
314 }
315
316 /**
317 * Normalizes a URL.
318 *
319 */
320 public function normalize_url( $url ) {
321
322 // Normalize.
323 $url = wp_normalize_path( $url );
324
325 // Remove query vars.
326 $url = strtok( $url, '?' );
327
328 // Split.
329 $url = explode( '/', $url );
330
331 // Clean.
332 $url = array_diff( $url, array( '..', '.' ) );
333
334 // Rejoin and return.
335 return implode( '/', $url );
336 }
337
338 /**
339 * Processes avatar and banner image reset.
340 *
341 * @param string $type Image type. Default 'avatar'.
342 *
343 * @return bool|WP_Error|string Profile url.
344 * @package userswp
345 *
346 */
347 public function process_image_reset( $type ) {
348 if ( ! is_user_logged_in() ) {
349 return false;
350 }
351
352 if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type ) ) {
353 return;
354 }
355
356 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
357 $user_id = get_current_user_id();
358 // If is another user's profile page
359 } elseif ( is_admin() && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
360 $user_id = absint( $_GET['user_id'] );
361 // Otherwise something is wrong.
362 } else {
363 $user_id = get_current_user_id();
364 }
365
366 $errors = new WP_Error();
367 if ( empty( $user_id ) ) {
368 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
369 }
370
371 $error_code = $errors->get_error_code();
372 if ( ! empty( $error_code ) ) {
373 return $errors;
374 }
375
376 if ( $type == 'avatar' ) {
377 uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
378 } elseif ( $type == 'banner' ) {
379 uwp_update_usermeta( $user_id, 'banner_thumb', '' );
380 } else {
381 // Do nothing
382 }
383
384 if ( is_admin() ) {
385 if ( $user_id == get_current_user_id() ) {
386 $redirect_url = admin_url( 'profile.php' );
387 } else {
388 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
389 }
390 } elseif ( uwp_current_page_url() ) {
391 $redirect_url = uwp_current_page_url();
392 } else {
393 $redirect_url = uwp_build_profile_tab_url( $user_id );
394 }
395
396 return $redirect_url;
397 }
398
399 /**
400 * Displays links in a dropdown
401 *
402 * @param $options
403 *
404 * @package userswp
405 *
406 * @since 1.0.0
407 */
408 public function output_dashboard_links( $options ) {
409 if ( ! empty( $options ) ) {
410 $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
411 echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
412 $this->output_options( $options );
413 echo '</select>';
414 }
415 }
416
417 /**
418 * Displays options for the dashboard links
419 *
420 * @param $options
421 *
422 * @package userswp
423 *
424 * @since 1.0.0
425 */
426 public function output_options( $options ) {
427 if ( ! empty( $options ) ) {
428 foreach ( $options as $key => $link ) {
429
430 if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
431 $this->output_options( $link );
432 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
433 echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
434 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
435 echo '</optgroup>';
436 } elseif ( ! empty( $link['text'] ) ) {
437 echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
438 echo esc_attr__( $link['text'], 'userswp' );
439 echo '</option>';
440 }
441 }
442 }
443 }
444
445 /**
446 * Displays UsersWP notices in forms.
447 *
448 * @param string $type Form type
449 *
450 * @return void
451 * @since 1.0.0
452 * @package userswp
453 *
454 */
455 public function display_notices( $type ) {
456 global $uwp_notices;
457
458 if ( is_array( $uwp_notices ) ) {
459 foreach ( $uwp_notices as $notice ) {
460
461 // If the notification is type specific then only output on that type
462 if ( is_array( $notice ) ) {
463 foreach ( $notice as $key => $val ) {
464 if ( $key == $type ) {
465 echo wp_kses_post( $val );
466 }
467 }
468 } elseif ( ! empty( $notice ) ) {
469 echo wp_kses_post( $notice );
470 }
471 }
472 }
473
474 if ( $type == 'change' ) {
475 $user_id = get_current_user_id();
476 $password_nag = get_user_option( 'default_password_nag', $user_id );
477
478 if ( $password_nag ) {
479 $change_page = uwp_get_page_id( 'change_page', false );
480 $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
481
482 if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
483 delete_user_meta( $user_id, 'default_password_nag' );
484 $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
485 echo aui()->alert(
486 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
487 'class' => 'text-center',
488 'type' => 'success',
489 'content' => wp_kses_post( $message ),
490 )
491 );
492 } else {
493 $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
494 echo aui()->alert(
495 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
496 'class' => 'text-center',
497 'type' => 'warning',
498 'content' => wp_kses_post( $message ),
499 )
500 );
501 }
502 }
503 }
504 }
505
506 /**
507 * Processes register form submission.
508 *
509 * @since 1.0.0
510 * @package userswp
511 *
512 */
513 public function process_register() {
514
515 $data = $_POST;
516
517 if ( ! isset( $data['uwp_register_nonce'] ) ) {
518 return;
519 }
520
521 global $uwp_notices;
522
523 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
524 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
525 }
526
527 if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce' ) ) {
528 $message = aui()->alert(
529 array(
530 'type' => 'error',
531 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
532 )
533 );
534 if ( wp_doing_ajax() ) {
535 wp_send_json_error( array( 'message' => $message ) );
536 } else {
537 $uwp_notices[] = array( 'register' => $message );
538
539 return;
540 }
541 }
542
543 $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
544 if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
545 $message = aui()->alert(
546 array(
547 'type' => 'error',
548 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
549 )
550 );
551 if ( wp_doing_ajax() ) {
552 wp_send_json_error( array( 'message' => $message ) );
553 } else {
554 $uwp_notices[] = array( 'register' => $message );
555
556 return;
557 }
558 }
559
560 if ( ! get_option( 'users_can_register' ) ) {
561 $message = aui()->alert(
562 array(
563 'type' => 'error',
564 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
565 )
566 );
567 if ( wp_doing_ajax() ) {
568 wp_send_json_error( array( 'message' => $message ) );
569 } else {
570 $uwp_notices[] = array( 'register' => $message );
571
572 return;
573 }
574 }
575
576 $files = $_FILES;
577 $errors = new WP_Error();
578 $file_obj = new UsersWP_Files();
579
580 do_action( 'uwp_before_validate', 'register' );
581
582 $result = uwp_validate_fields( $data, 'register' );
583
584 $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
585
586 if ( is_wp_error( $result ) ) {
587 $message = aui()->alert(
588 array(
589 'type' => 'error',
590 'content' => $result->get_error_message(),
591 )
592 );
593 if ( wp_doing_ajax() ) {
594 wp_send_json_error( array( 'message' => $message ) );
595 } else {
596 $uwp_notices[] = array( 'register' => $message );
597
598 return;
599 }
600 }
601
602 $uploads_result = $file_obj->validate_uploads( $files, 'register' );
603
604 if ( is_wp_error( $uploads_result ) ) {
605 $message = aui()->alert(
606 array(
607 'type' => 'error',
608 'content' => $uploads_result->get_error_message(),
609 )
610 );
611 if ( wp_doing_ajax() ) {
612 wp_send_json_error( array( 'message' => $message ) );
613 } else {
614 $uwp_notices[] = array( 'register' => $message );
615
616 return;
617 }
618 }
619
620 do_action( 'uwp_after_validate', $result, 'register', $data );
621
622 $result = array_merge( $result, $uploads_result );
623
624 if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
625 $password = $result['password'];
626 $generated_password = false;
627 } else {
628 $password = wp_generate_password();
629 $this->generated_password = $password;
630 $generated_password = true;
631 }
632
633 $first_name = '';
634 if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
635 $first_name = $result['first_name'];
636 }
637
638 $last_name = '';
639 if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
640 $last_name = $result['last_name'];
641 }
642
643 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
644 $display_name = $result['display_name'];
645 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
646 $display_name = $first_name . ' ' . $last_name;
647 } else {
648 $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
649 }
650
651 $user_url = '';
652 if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
653 $user_url = esc_url_raw( $result['user_url'] );
654 }
655
656 $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
657 $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
658
659 if ( empty( $user_login ) ) {
660 $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
661 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
662 $new_user_login = strstr( $email, '@', true );
663 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
664 $user_login = sanitize_user( $new_user_login, true );
665 }
666 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
667 $user_append_text = rand( 10, 1000 );
668 $user_login = sanitize_user( $new_user_login . $user_append_text, true );
669 }
670
671 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
672 $user_login = $email;
673 }
674 }
675 } elseif ( ! validate_username( $user_login ) ) {
676 $message = aui()->alert(
677 array(
678 'type' => 'error',
679 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
680 )
681 );
682 if ( wp_doing_ajax() ) {
683 wp_send_json_error( array( 'message' => $message ) );
684 } else {
685 $uwp_notices[] = array( 'register' => $message );
686
687 return;
688 }
689 }
690
691 $args = array(
692 'user_login' => sanitize_user( $user_login ),
693 'user_email' => sanitize_email( $email ),
694 'user_pass' => $password,
695 'display_name' => sanitize_text_field( $display_name ),
696 'first_name' => esc_attr( $first_name ),
697 'last_name' => esc_attr( $last_name ),
698 'user_url' => esc_url_raw( $user_url ),
699 );
700
701 $form_id = 1;
702
703 if ( ! empty( $data['uwp_register_form_id'] ) ) {
704 $form_id = (int) $data['uwp_register_form_id'];
705 }
706
707 // Set user role by form.
708 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
709
710 if ( ! empty( $user_role ) ) {
711 $user_roles = uwp_get_user_roles();
712 $chosen_role = strtolower( $user_role );
713
714 if ( ! empty( $user_roles ) ) {
715 $wp_roles = wp_roles();
716
717 if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
718 $args['role'] = $chosen_role;
719 }
720 }
721 }
722
723 $user_id = wp_insert_user( $args );
724
725 if ( is_wp_error( $user_id ) ) {
726 $message = aui()->alert(
727 array(
728 'type' => 'error',
729 'content' => $user_id->get_error_message(),
730 )
731 );
732 if ( wp_doing_ajax() ) {
733 wp_send_json_error( array( 'message' => $message ) );
734 } else {
735 $uwp_notices[] = array( 'register' => $message );
736
737 return;
738 }
739 }
740
741 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
742
743 // Save user form id.
744 if ( ! empty( $data['uwp_register_form_id'] ) ) {
745 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
746 }
747
748 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
749
750 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
751
752 if ( is_wp_error( $save_result ) ) {
753 $message = aui()->alert(
754 array(
755 'type' => 'error',
756 'content' => $save_result->get_error_message(),
757 )
758 );
759 if ( wp_doing_ajax() ) {
760 wp_send_json_error( array( 'message' => $message ) );
761 } else {
762 $uwp_notices[] = array( 'register' => $message );
763
764 return;
765 }
766 }
767
768 if ( ! $save_result ) {
769 $message = aui()->alert(
770 array(
771 'type' => 'error',
772 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
773 )
774 );
775 if ( wp_doing_ajax() ) {
776 wp_send_json_error( array( 'message' => $message ) );
777 } else {
778 $uwp_notices[] = array( 'register' => $message );
779
780 return;
781 }
782 }
783
784 //updating bio field after saving extra fields to reflect the points in mycred add on.
785 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
786 $args = array(
787 'ID' => $user_id,
788 'description' => $result['bio'],
789 );
790 wp_update_user( $args );
791 }
792
793 do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
794
795 // Unset post data to empty the form on submit
796 $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
797 foreach ( $data as $key => $value ) {
798 if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
799 unset( $_POST[ $key ] );
800 }
801 }
802
803 $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
804 if ( ! $reg_action ) {
805 $reg_action = uwp_get_option( 'uwp_registration_action', false );
806 }
807
808 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
809
810 if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
811
812 $user_data = get_userdata( $user_id );
813 $activation_link = uwp_get_activation_link( $user_id );
814
815 $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
816
817 $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
818
819 $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
820
821 $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
822
823 $email_vars = array(
824 'user_id' => $user_id,
825 'login_details' => $activate_message,
826 'activation_link' => $activation_link,
827 );
828
829 UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
830
831 } elseif ( $reg_action != 'require_admin_review' ) {
832
833 $user_data = get_userdata( $user_id );
834
835 if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
836 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
837 update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
838 }
839 $message_pass = $this->generated_password;
840 $this->generated_password = false;
841 } else {
842 $message_pass = __( 'Password you entered during registration.', 'userswp' );
843 }
844
845 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
846 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
847 <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
848
849 $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
850
851 $email_vars = array(
852 'user_id' => $user_id,
853 'login_details' => $message,
854 'form_fields' => $form_fields,
855 );
856
857 UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
858 }
859
860 $error_code = $errors->get_error_code();
861 if ( ! empty( $error_code ) ) {
862 $message = aui()->alert(
863 array(
864 'type' => 'error',
865 'content' => $result->get_error_message(),
866 )
867 );
868 if ( wp_doing_ajax() ) {
869 wp_send_json_error( array( 'message' => $message ) );
870 } else {
871 $uwp_notices[] = array( 'register' => $message );
872 return;
873 }
874 }
875
876 if ( $reg_action != 'require_admin_review' ) {
877
878 $user_data = get_userdata( $user_id );
879 $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
880 <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
881 <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
882 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
883 <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
884
885 $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
886
887 $email_vars = array(
888 'user_id' => $user_id,
889 'extras' => $extras,
890 'form_fields' => $form_fields,
891 );
892
893 UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
894
895 }
896
897 if ( $reg_action == 'auto_approve_login' ) {
898 $res = wp_signon(
899 array(
900 'user_login' => $user_login,
901 'user_password' => $password,
902 'remember' => false,
903 )
904 );
905
906 if ( is_wp_error( $res ) ) {
907 $message = aui()->alert(
908 array(
909 'type' => 'error',
910 'content' => $res->get_error_message(),
911 )
912 );
913
914 if ( wp_doing_ajax() ) {
915 wp_send_json_error( array( 'message' => $message ) );
916 } else {
917 $uwp_notices[] = array( 'register' => $message );
918 }
919 } else {
920 $redirect_to = $this->get_register_redirect_url( $data, $user_id );
921 do_action( 'uwp_after_process_register', $result, $user_id );
922
923 if ( wp_doing_ajax() ) {
924 $message = aui()->alert(
925 array(
926 'type' => 'success',
927 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
928 )
929 );
930 $response = array(
931 'message' => $message,
932 'redirect' => $redirect_to,
933 );
934 wp_send_json_success( $response );
935 } else {
936 wp_safe_redirect( $redirect_to );
937 }
938 exit();
939 }
940 } else {
941 if ( $reg_action == 'require_email_activation' ) {
942 $resend_link = uwp_get_register_page_url();
943 $resend_link = add_query_arg(
944 array(
945 'user_id' => $user_id,
946 'action' => 'uwp_resend',
947 '_nonce' => wp_create_nonce( 'uwp_resend' ),
948 ),
949 $resend_link
950 );
951
952 $message = aui()->alert(
953 array(
954 'type' => 'success',
955 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
956 )
957 );
958
959 } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
960
961 update_user_meta( $user_id, 'uwp_mod', '1' );
962
963 do_action( 'uwp_require_admin_review', $user_id, $result );
964
965 $message = aui()->alert(
966 array(
967 'type' => 'success',
968 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
969 )
970 );
971 } else {
972
973 $login_page_url = wp_login_url();
974
975 if ( $generated_password ) {
976 $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
977 } else {
978 $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
979 }
980
981 $message = aui()->alert(
982 array(
983 'type' => 'success',
984 'content' => $msg,
985 )
986 );
987 }
988
989 do_action( 'uwp_after_process_register', $result, $user_id );
990
991 if ( wp_doing_ajax() ) {
992 wp_send_json_success( array( 'message' => $message ) );
993 } else {
994 $uwp_notices[] = array( 'register' => $message );
995 }
996 }
997
998 if ( wp_doing_ajax() ) {
999 wp_send_json_error();
1000 } // if we got this far there is a problem
1001 }
1002
1003 /**
1004 * Saves UsersWP related user custom fields.
1005 *
1006 * @param int $user_id User ID.
1007 * @param array $data Result array.
1008 * @param string $type Form type.
1009 *
1010 * @return bool True when success. False when failure.
1011 * @since 1.0.0
1012 * @package userswp
1013 *
1014 */
1015 public function save_user_extra_fields( $user_id, $data, $type ) {
1016
1017 if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1018 return false;
1019 }
1020
1021 // custom user fields not applicable for login and forgot
1022 if ( $type == 'login' || $type == 'forgot' ) {
1023 return true;
1024 }
1025
1026 if ( $type == 'account' || $type == 'register' ) {
1027 if ( isset( $data['password'] ) ) {
1028 unset( $data['password'] );
1029 }
1030 }
1031
1032 if ( $type == 'register' ) {
1033 if ( isset( $data['username'] ) ) {
1034 unset( $data['username'] );
1035 }
1036 if ( isset( $data['email'] ) ) {
1037 unset( $data['email'] );
1038 }
1039 }
1040
1041 if ( empty( $data ) ) {
1042 // no extra fields. so just return
1043 return true;
1044 } else {
1045 foreach ( $data as $key => $value ) {
1046 if ( 'uwp_language' == $key ) {
1047 update_user_meta( $user_id, 'locale', $value );
1048 }
1049 uwp_update_usermeta( $user_id, $key, $value );
1050 }
1051
1052 return true;
1053 }
1054 }
1055
1056 public function get_register_redirect_url( $data, $user ) {
1057 if ( is_int( $user ) ) {
1058 $user = get_userdata( $user );
1059 }
1060
1061 $redirect_page_id = $custom_url = '';
1062 if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1063 $form_id = (int) $data['uwp_register_form_id'];
1064 $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1065 $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1066 }
1067
1068 if ( ! $redirect_page_id ) {
1069 $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1070 $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1071 }
1072
1073 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1074 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1075 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1076 $redirect_to = esc_url_raw( $data['redirect_to'] );
1077 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1078 if ( uwp_is_wpml() ) {
1079 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1080 if ( ! empty( $wpml_page_id ) ) {
1081 $redirect_page_id = $wpml_page_id;
1082 }
1083 }
1084 $redirect_to = get_permalink( $redirect_page_id );
1085 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1086 $redirect_to = esc_url( wp_get_referer() );
1087 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1088 $redirect_to = $custom_url;
1089 } else {
1090 if ( $user && $user->has_cap( 'manage_options' ) ) {
1091 $redirect_to = admin_url();
1092 } else {
1093 $redirect_to = home_url( '/' );
1094 }
1095
1096 $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1097 }
1098
1099 return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1100 }
1101
1102 /**
1103 * Processes login form submission.
1104 *
1105 * @since 1.0.0
1106 * @package userswp
1107 *
1108 */
1109 public function process_login() {
1110
1111 $data = $_POST;
1112
1113 if ( ! isset( $data['uwp_login_nonce'] ) ) {
1114 return;
1115 }
1116
1117 if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1118 $message = aui()->alert(
1119 array(
1120 'type' => 'error',
1121 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1122 )
1123 );
1124 if ( wp_doing_ajax() ) {
1125 wp_send_json_error( array( 'message' => $message ) );
1126 } else {
1127 return;
1128 }
1129 }
1130
1131 global $uwp_notices;
1132
1133 do_action( 'uwp_before_validate', 'login' );
1134
1135 $result = uwp_validate_fields( $data, 'login' );
1136
1137 $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1138
1139 if ( is_wp_error( $result ) ) {
1140 $message = aui()->alert(
1141 array(
1142 'type' => 'error',
1143 'content' => $result->get_error_message(),
1144 )
1145 );
1146 if ( wp_doing_ajax() ) {
1147 wp_send_json_error( array( 'message' => $message ) );
1148 } else {
1149 $uwp_notices[] = array( 'login' => $message );
1150
1151 return;
1152 }
1153 }
1154
1155 do_action( 'uwp_after_validate', $result, 'login', $data );
1156
1157 if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1158 $remember_me = true;
1159 } else {
1160 $remember_me = false;
1161 }
1162
1163 remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1164
1165 global $wp2fa;
1166 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1167 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1168 }
1169
1170 $user = wp_signon(
1171 array(
1172 'user_login' => $result['username'],
1173 'user_password' => $result['password'],
1174 'remember' => $remember_me,
1175 )
1176 );
1177
1178 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1179
1180 if ( wp_doing_ajax() && ! is_wp_error( $user ) && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1181
1182 $two_fa = $this->check_2fa( $user );
1183 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1184 if ( is_wp_error( $two_fa ) ) {
1185 $message = aui()->alert(
1186 array(
1187 'type' => 'error',
1188 'content' => $two_fa->get_error_message(),
1189 )
1190 );
1191 wp_send_json_error( array( 'message' => $message ) );
1192 } else {
1193 wp_send_json_success(
1194 array(
1195 'html' => $two_fa,
1196 'is_2fa' => true,
1197 )
1198 );
1199 }
1200 }
1201 }
1202
1203 if ( is_wp_error( $user ) ) {
1204 $message = aui()->alert(
1205 array(
1206 'type' => 'error',
1207 'content' => $user->get_error_message(),
1208 )
1209 );
1210 if ( wp_doing_ajax() ) {
1211 wp_send_json_error( array( 'message' => $message ) );
1212 } else {
1213 $uwp_notices[] = array( 'login' => $message );
1214
1215 return;
1216 }
1217 } else {
1218 do_action( 'uwp_after_process_login', $data );
1219 $message = aui()->alert(
1220 array(
1221 'type' => 'success',
1222 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1223 )
1224 );
1225 if ( wp_doing_ajax() ) {
1226 $redirect_to = '';
1227 if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1228 $redirect_to = $this->get_login_redirect_url( $data, $user );
1229 }
1230 wp_send_json_success(
1231 array(
1232 'message' => $message,
1233 'redirect' => $redirect_to,
1234 )
1235 );
1236 } else {
1237 $redirect_to = $this->get_login_redirect_url( $data, $user );
1238 wp_safe_redirect( $redirect_to );
1239 exit();
1240 }
1241 }
1242 }
1243
1244 public function check_2fa( $user ) {
1245 if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1246 return;
1247 }
1248
1249 if ( ! $user ) {
1250 $user = wp_get_current_user();
1251 }
1252
1253 global $wp2fa;
1254 $errors = new WP_Error();
1255
1256 if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1257 return;
1258 }
1259 // Invalidate the current login session to prevent from being re-used.
1260 \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1261
1262 // Also clear the cookies which are no longer valid.
1263 wp_clear_auth_cookie();
1264
1265 $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1266 if ( ! $login_nonce ) {
1267 $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1268
1269 return $errors;
1270 }
1271
1272 $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1273
1274 ob_start();
1275 ?>
1276
1277 <div class="uwp-2fa-methods-wrap">
1278 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1279 autocomplete="off">
1280 <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1281 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1282 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1283 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1284 <?php
1285
1286 // Check to see what provider is set and give the relevant authentication page.
1287 if ( 'totp' === $provider ) {
1288 ?>
1289 <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1290 <?php
1291
1292 echo aui()->input(
1293 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1294 'type' => 'tel',
1295 'id' => 'authcode',
1296 'name' => 'authcode',
1297 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1298 'value' => '',
1299 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1300 )
1301 );
1302
1303 echo aui()->button(
1304 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1305 'type' => 'submit',
1306 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1307 'name' => 'submit',
1308 'icon' => '',
1309 'content' => esc_html__( 'Log In', 'userswp' ),
1310 )
1311 );
1312
1313 } elseif ( 'email' === $provider ) {
1314 $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1315 if ( empty( $has_token ) || ! $has_token ) {
1316 \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1317 }
1318 ?>
1319 <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1320 <?php
1321 echo aui()->input(
1322 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1323 'type' => 'tel',
1324 'id' => 'authcode',
1325 'name' => 'wp-2fa-email-code',
1326 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1327 'value' => '',
1328 'label' => esc_html__( 'Verification Code', 'userswp' ),
1329 'extra_attributes' => array(
1330 'size' => 20,
1331 'pattern' => '[0-9]*',
1332 ),
1333 )
1334 );
1335
1336 echo aui()->button(
1337 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1338 'type' => 'submit',
1339 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1340 'name' => 'submit',
1341 'icon' => '',
1342 'content' => esc_html__( 'Log In', 'userswp' ),
1343 )
1344 );
1345
1346 echo aui()->button(
1347 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1348 'type' => 'button',
1349 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1350 'name' => 'wp-2fa-email-code-resend',
1351 'icon' => '',
1352 'content' => esc_html__( 'Resend Code', 'userswp' ),
1353 )
1354 );
1355
1356 }
1357 ?>
1358 </form>
1359 </div>
1360
1361 <?php
1362 $codes_remaining = \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1363 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1364 ?>
1365 <div class="uwp-2fa-methods-wrap" style="display:none;">
1366 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1367 class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1368 <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1369 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1370 value="<?php echo esc_attr( $user->ID ); ?>"/>
1371 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1372 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1373 <div class="uwp-backup-fields">
1374 <?php
1375 echo aui()->input(
1376 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1377 'type' => 'tel',
1378 'id' => 'authcode',
1379 'name' => 'wp-2fa-backup-code',
1380 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1381 'value' => '',
1382 'label' => esc_html__( 'Backup Code', 'userswp' ),
1383 'extra_attributes' => array(
1384 'size' => 20,
1385 'pattern' => '[0-9]*',
1386 ),
1387 )
1388 );
1389
1390 echo aui()->button(
1391 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1392 'type' => 'submit',
1393 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1394 'name' => 'submit',
1395 'icon' => '',
1396 'content' => esc_html__( 'Log In', 'userswp' ),
1397 )
1398 );
1399 ?>
1400 </div>
1401 </form>
1402 </div>
1403 <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1404 <script type="text/javascript">
1405 jQuery('.uwp-switch-2fa-methods').on('click',
1406 function (e) {
1407 e.preventDefault();
1408 jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1409 jQuery('.uwp-2fa-methods-wrap').toggle();
1410 return false;
1411 }
1412 );
1413 </script>
1414 <?php
1415 }
1416
1417 return ob_get_clean();
1418 }
1419
1420 public function process_login_2fa() {
1421 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1422 return;
1423 }
1424
1425 $auth_id = (int) $_POST['uwp-auth-id'];
1426 $user = get_userdata( $auth_id );
1427 if ( ! $user ) {
1428 $message = aui()->alert(
1429 array(
1430 'type' => 'error',
1431 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1432 )
1433 );
1434
1435 wp_send_json_error( array( 'message' => $message ) );
1436 }
1437
1438 global $wp2fa;
1439
1440 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1441 if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1442
1443 $message = aui()->alert(
1444 array(
1445 'type' => 'error',
1446 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1447 )
1448 );
1449
1450 wp_send_json_error( array( 'message' => $message ) );
1451 }
1452
1453 if ( isset( $_POST['provider'] ) ) {
1454 $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) );
1455 $providers = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1456 if ( isset( $providers[ $provider ] ) ) {
1457 $provider = $providers[ $provider ];
1458 } elseif ( isset( $provider ) ) {
1459 $provider = $provider;
1460 } else {
1461 $provider = $provider;
1462 }
1463 }
1464
1465 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1466 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1467
1468 }
1469
1470 // Validate TOTP.
1471 if ( 'totp' === $provider && true !== \WP2FA\Authenticator\Login::validate_totp_authentication( $user ) ) {
1472
1473 do_action( 'wp_login_failed', $user->user_login );
1474
1475 $message = aui()->alert(
1476 array(
1477 'type' => 'error',
1478 'content' => __( 'Invalid verification code.', 'userswp' ),
1479 )
1480 );
1481
1482 wp_send_json_error( array( 'message' => $message ) );
1483 }
1484
1485 // Validate Email.
1486 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::validate_email_authentication( $user ) ) {
1487
1488 do_action( 'wp_login_failed', $user->user_login );
1489
1490 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1491 $message = aui()->alert(
1492 array(
1493 'type' => 'info',
1494 'content' => __( 'A new code has been sent.', 'userswp' ),
1495 )
1496 );
1497
1498 wp_send_json_error( array( 'message' => $message ) );
1499 } else {
1500 $message = aui()->alert(
1501 array(
1502 'type' => 'error',
1503 'content' => __( 'Invalid verification code.', 'userswp' ),
1504 )
1505 );
1506
1507 wp_send_json_error( array( 'message' => $message ) );
1508 }
1509 }
1510
1511 // Backup Codes.
1512 if ( 'backup_codes' === $provider && true !== \WP2FA\Authenticator\Login::validate_backup_codes( $user ) ) {
1513
1514 do_action( 'wp_login_failed', $user->user_login );
1515
1516 $message = aui()->alert(
1517 array(
1518 'type' => 'error',
1519 'content' => __( 'Invalid backup code.', 'userswp' ),
1520 )
1521 );
1522
1523 wp_send_json_error( array( 'message' => $message ) );
1524 }
1525
1526 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1527
1528 $rememberme = false;
1529 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1530 if ( ! empty( $remember ) ) {
1531 $rememberme = true;
1532 }
1533
1534 wp_set_auth_cookie( $user->ID, $rememberme );
1535
1536 do_action( 'two_factor_user_authenticated', $user );
1537
1538 $message = aui()->alert(
1539 array(
1540 'type' => 'success',
1541 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1542 )
1543 );
1544
1545 wp_send_json_success( array( 'message' => $message ) );
1546 }
1547
1548 public function get_login_redirect_url( $data, $user ) {
1549 if ( is_int( $user ) ) {
1550 $user = get_userdata( $user );
1551 }
1552
1553 $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1554 $custom_url = uwp_get_option( 'login_redirect_custom_url' );
1555
1556 if ( $user && isset( $user->roles[0] ) ) {
1557 $user_role = $user->roles[0];
1558 $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1559 $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1560 }
1561
1562 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1563 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1564 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1565 $redirect_to = esc_url_raw( $data['redirect_to'] );
1566 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1567 if ( uwp_is_wpml() ) {
1568 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1569 if ( ! empty( $wpml_page_id ) ) {
1570 $redirect_page_id = $wpml_page_id;
1571 }
1572 }
1573 $redirect_to = get_permalink( $redirect_page_id );
1574 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1575 $redirect_to = esc_url( wp_get_referer() );
1576 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1577 $redirect_to = $custom_url;
1578 } else {
1579 $redirect_to = home_url( '/' );
1580 $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1581 }
1582
1583 return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1584 }
1585
1586 /**
1587 * Processes forgot password form submission.
1588 *
1589 * @since 1.0.0
1590 * @package userswp
1591 *
1592 */
1593 public function process_forgot() {
1594
1595 $data = $_POST;
1596
1597 if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1598 return;
1599 }
1600
1601 if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1602 $message = aui()->alert(
1603 array(
1604 'type' => 'error',
1605 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1606 )
1607 );
1608 if ( wp_doing_ajax() ) {
1609 wp_send_json_error( $message );
1610 } else {
1611 return;
1612 }
1613 }
1614
1615 global $uwp_notices;
1616
1617 do_action( 'uwp_before_validate', 'forgot' );
1618
1619 $result = uwp_validate_fields( $data, 'forgot' );
1620
1621 $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
1622
1623 if ( is_wp_error( $result ) ) {
1624 $message = aui()->alert(
1625 array(
1626 'type' => 'error',
1627 'content' => $result->get_error_message(),
1628 )
1629 );
1630 if ( wp_doing_ajax() ) {
1631 wp_send_json_error( $message );
1632 } else {
1633 $uwp_notices[] = array( 'forgot' => $message );
1634
1635 return;
1636 }
1637 }
1638
1639 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1640
1641 $user_data = get_user_by( 'email', $data['email'] );
1642
1643 // if no user we fake it and bail
1644 if ( ! $user_data ) {
1645 $args = apply_filters(
1646 'uwp_forgot_error_message',
1647 array(
1648 'type' => 'error',
1649 'content' => __( 'Invalid email or user doesn\'t exists.', 'userswp' ),
1650 )
1651 );
1652
1653 $message = aui()->alert( $args );
1654 if ( wp_doing_ajax() ) {
1655 wp_send_json_success( $message );
1656 } else {
1657 $uwp_notices[] = array( 'forgot' => $message );
1658
1659 return;
1660 }
1661 }
1662
1663 // make sure user account is active before account reset
1664 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1665 if ( $mod_value == 'email_unconfirmed' ) {
1666 $message = aui()->alert(
1667 array(
1668 'type' => 'error',
1669 'content' => __( 'Your account is not activated yet. Please activate your account first.', 'userswp' ),
1670 )
1671 );
1672 if ( wp_doing_ajax() ) {
1673 wp_send_json_error( $message );
1674 } else {
1675 $uwp_notices[] = array( 'forgot' => $message );
1676
1677 return;
1678 }
1679 }
1680
1681 $user_data = get_userdata( $user_data->ID );
1682
1683 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
1684
1685 if ( ! $allow ) {
1686 return false;
1687 } elseif ( is_wp_error( $allow ) ) {
1688 return false;
1689 }
1690
1691 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
1692
1693 global $wpdb, $wp_hasher;
1694 $reset_link = '';
1695
1696 if ( $as_password ) {
1697 $new_pass = wp_generate_password( 12, false );
1698 wp_set_password( $new_pass, $user_data->ID );
1699 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
1700 update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
1701 }
1702 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
1703 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1704 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
1705
1706 } else {
1707 $key = wp_generate_password( 20, false );
1708 do_action( 'retrieve_password_key', $user_data->user_login, $key );
1709
1710 if ( empty( $wp_hasher ) ) {
1711 require_once ABSPATH . 'wp-includes/class-phpass.php';
1712 $wp_hasher = new PasswordHash( 8, true );
1713 }
1714 $hashed = $wp_hasher->HashPassword( $key );
1715 $wpdb->update( $wpdb->users, array( 'user_activation_key' => time() . ':' . $hashed ), array( 'user_login' => $user_data->user_login ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1716 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
1717 $message .= home_url( '/' ) . '</p>';
1718 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
1719 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
1720 $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
1721 $reset_page = uwp_get_page_id( 'reset_page', false );
1722 if ( $reset_page ) {
1723 $reset_link = add_query_arg(
1724 array(
1725 'key' => $key,
1726 'login' => rawurlencode( $user_data->user_login ),
1727 ),
1728 get_permalink( $reset_page )
1729 );
1730 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1731 } else {
1732 $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
1733 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
1734 }
1735 $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
1736 }
1737
1738 $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
1739
1740 $email_vars = array(
1741 'user_id' => $user_data->ID,
1742 'login_details' => $message,
1743 'reset_link' => $reset_link,
1744 );
1745
1746 UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
1747
1748 do_action( 'uwp_after_process_forgot', $data );
1749
1750 $message = aui()->alert(
1751 array(
1752 'type' => 'success',
1753 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
1754 )
1755 );
1756 if ( wp_doing_ajax() ) {
1757 wp_send_json_success( $message );
1758 } else {
1759 $uwp_notices[] = array( 'forgot' => $message );
1760 }
1761 }
1762
1763 /**
1764 * Processes change password form submission.
1765 *
1766 * @since 1.0.0
1767 * @package userswp
1768 *
1769 */
1770 public function process_change() {
1771
1772 $data = $_POST;
1773
1774 if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
1775 return;
1776 }
1777
1778 global $uwp_notices;
1779
1780 if ( is_uwp_account_page() ) {
1781 $notice_type = 'account';
1782 } else {
1783 $notice_type = 'change';
1784 }
1785
1786 do_action( 'uwp_before_validate', 'change' );
1787
1788 $result = uwp_validate_fields( $data, 'change' );
1789
1790 $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
1791
1792 if ( is_wp_error( $result ) ) {
1793 $message = aui()->alert(
1794 array(
1795 'type' => 'error',
1796 'content' => $result->get_error_message(),
1797 )
1798 );
1799 $uwp_notices[] = array( $notice_type => $message );
1800
1801 return;
1802 }
1803
1804 do_action( 'uwp_after_validate', $result, 'change', $data );
1805
1806 $user_data = get_user_by( 'id', get_current_user_id() );
1807
1808 if ( ! $user_data ) {
1809 $message = aui()->alert(
1810 array(
1811 'type' => 'error',
1812 'content' => $user_data->get_error_message(),
1813 )
1814 );
1815 $uwp_notices[] = array( $notice_type => $message );
1816
1817 return;
1818 }
1819
1820 $email_vars = array(
1821 'user_id' => $user_data->ID,
1822 );
1823
1824 UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
1825
1826 wp_set_password( $result['password'], $user_data->ID );
1827
1828 $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
1829 if ( $password_nag ) {
1830 delete_user_meta( $user_data->ID, 'default_password_nag' );
1831 }
1832
1833 delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
1834
1835 $message = aui()->alert(
1836 array(
1837 'type' => 'success',
1838 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
1839 )
1840 );
1841
1842 $uwp_notices[] = array( $notice_type => $message );
1843
1844 do_action( 'uwp_after_process_change', $data );
1845
1846 wp_logout();
1847 exit();
1848 }
1849
1850 /**
1851 * Processes reset password form submission.
1852 *
1853 * @since 1.0.0
1854 * @package userswp
1855 *
1856 */
1857 public function process_reset() {
1858
1859 $data = $_POST;
1860
1861 if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
1862 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
1863 }
1864
1865 if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
1866 return;
1867 }
1868
1869 global $uwp_notices;
1870
1871 do_action( 'uwp_before_validate', 'reset' );
1872
1873 $result = uwp_validate_fields( $data, 'reset' );
1874
1875 $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
1876
1877 if ( is_wp_error( $result ) ) {
1878 $message = aui()->alert(
1879 array(
1880 'type' => 'error',
1881 'content' => $result->get_error_message(),
1882 )
1883 );
1884 $uwp_notices[] = array( 'reset' => $message );
1885
1886 return;
1887 }
1888
1889 do_action( 'uwp_after_validate', $result, 'reset', $data );
1890
1891 $login = sanitize_text_field( $data['uwp_reset_username'] );
1892 $key = sanitize_text_field( $data['uwp_reset_key'] );
1893
1894 $user = get_user_by( 'login', $login );
1895 if ( ! $user ) {
1896 $message = aui()->alert(
1897 array(
1898 'type' => 'error',
1899 'content' => __( 'Invalid username.', 'userswp' ),
1900 )
1901 );
1902 $uwp_notices[] = array( 'reset' => $message );
1903
1904 return;
1905 }
1906
1907 clean_user_cache( $user );
1908
1909 $user_data = check_password_reset_key( $key, $login );
1910
1911 if ( is_wp_error( $user_data ) ) {
1912 $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
1913 $message = aui()->alert(
1914 array(
1915 'type' => 'error',
1916 'content' => $error,
1917 )
1918 );
1919 $uwp_notices[] = array( 'reset' => $message );
1920
1921 return;
1922 }
1923
1924 $email_vars = array(
1925 'user_id' => $user_data->ID,
1926 );
1927
1928 UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
1929
1930 wp_set_password( $data['password'], $user_data->ID );
1931
1932 $login_page_url = uwp_get_login_page_url();
1933 $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
1934 $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
1935 $message = aui()->alert(
1936 array(
1937 'type' => 'success',
1938 'content' => $message,
1939 )
1940 );
1941 $uwp_notices[] = array( 'reset' => $message );
1942
1943 do_action( 'uwp_after_process_reset', $data );
1944 }
1945
1946 /**
1947 * Processes account form submission.
1948 *
1949 * @since 1.0.0
1950 * @package userswp
1951 *
1952 */
1953 public function process_account() {
1954
1955 $data = wp_unslash( $_POST );
1956 $files = $_FILES;
1957
1958 if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
1959 return;
1960 }
1961
1962 if ( ! is_user_logged_in() ) {
1963 return;
1964 }
1965
1966 global $uwp_notices;
1967 $file_obj = new UsersWP_Files();
1968
1969 do_action( 'uwp_before_validate', 'account' );
1970
1971 $result = uwp_validate_fields( $data, 'account' );
1972
1973 $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
1974
1975 if ( is_wp_error( $result ) ) {
1976 $message = aui()->alert(
1977 array(
1978 'type' => 'error',
1979 'content' => $result->get_error_message(),
1980 )
1981 );
1982 $uwp_notices[] = array( 'account' => $message );
1983
1984 return;
1985 }
1986
1987 $uploads_result = $file_obj->validate_uploads( $files, 'account' );
1988
1989 if ( is_wp_error( $uploads_result ) ) {
1990 $message = aui()->alert(
1991 array(
1992 'type' => 'error',
1993 'content' => $uploads_result->get_error_message(),
1994 )
1995 );
1996 $uwp_notices[] = array( 'account' => $message );
1997
1998 return;
1999 }
2000
2001 do_action( 'uwp_after_validate', $result, 'account', $data );
2002
2003 //unset if value is empty for files
2004 foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2005 if ( empty( $upload_file_value ) ) {
2006 unset( $uploads_result[ $upload_file_key ] );
2007 }
2008 }
2009
2010 $result = array_merge( $result, $uploads_result );
2011
2012 $args = array(
2013 'ID' => get_current_user_id(),
2014 );
2015
2016 if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2017 $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2018 }
2019
2020 if ( isset( $result['first_name'] ) ) {
2021 $args['first_name'] = $result['first_name'];
2022 }
2023
2024 if ( isset( $result['last_name'] ) ) {
2025 $args['last_name'] = $result['last_name'];
2026 }
2027
2028 if ( isset( $result['user_url'] ) ) {
2029 $args['user_url'] = $result['user_url'];
2030 }
2031
2032 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2033 $args['display_name'] = $result['display_name'];
2034 }
2035
2036 if ( isset( $result['password'] ) ) {
2037 $args['user_pass'] = $result['password'];
2038 }
2039
2040 $user_id = wp_update_user( $args );
2041
2042 if ( is_wp_error( $user_id ) ) {
2043 $message = aui()->alert(
2044 array(
2045 'type' => 'error',
2046 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2047 )
2048 );
2049 $uwp_notices[] = array( 'account' => $message );
2050
2051 return;
2052 }
2053
2054 $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
2055
2056 if ( ! $res ) {
2057 $message = aui()->alert(
2058 array(
2059 'type' => 'error',
2060 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2061 )
2062 );
2063 $uwp_notices[] = array( 'account' => $message );
2064
2065 return;
2066 }
2067
2068 //updating bio field after saving extra fields to reflect the points in mycred add on.
2069 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2070 $args = array(
2071 'ID' => $user_id,
2072 'description' => $result['bio'],
2073 );
2074 wp_update_user( $args );
2075 }
2076
2077 $user_data = get_userdata( $user_id );
2078
2079 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
2080
2081 if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
2082
2083 if ( email_exists( trim( $result['email'] ) ) ) {
2084 $message = aui()->alert(
2085 array(
2086 'type' => 'error',
2087 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2088 )
2089 );
2090
2091 $uwp_notices[] = array( 'account' => $message );
2092 return;
2093
2094 }
2095
2096 $hash = md5( $result['email'] . time() . wp_rand() );
2097 $new_admin_email = array(
2098 'hash' => $hash,
2099 'newemail' => $result['email'],
2100 );
2101
2102 update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2103
2104 $new_email_link = add_query_arg(
2105 array(
2106 'uwp_new_email' => 'yes',
2107 'key' => $hash,
2108 'login' => $user_data->user_login,
2109 ),
2110 uwp_get_account_page_url()
2111 );
2112
2113 $email_vars = array(
2114 'user_id' => $user_id,
2115 'new_email' => $result['email'],
2116 'new_email_link' => esc_url( $new_email_link ),
2117 );
2118
2119 UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2120
2121 $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2122 $message = aui()->alert(
2123 array(
2124 'type' => 'success',
2125 'content' => $message,
2126 )
2127 );
2128
2129 $uwp_notices[] = array( 'account' => $message );
2130
2131 } else {
2132 $email_vars = array(
2133 'user_id' => $user_id,
2134 'form_fields' => $form_fields,
2135 );
2136
2137 UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2138
2139 $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2140 $message = aui()->alert(
2141 array(
2142 'type' => 'success',
2143 'content' => $message,
2144 )
2145 );
2146
2147 $uwp_notices[] = array( 'account' => $message );
2148 }
2149
2150 do_action( 'uwp_after_process_account', $data, $user_id );
2151 }
2152
2153 /**
2154 * Modifies the forms field in email based on the form type.
2155 *
2156 * @param string $form_fields Form fields.
2157 * @param string $type Form type.
2158 * @param int $user_id User ID.
2159 *
2160 * @return string Modified mail field.
2161 * @package userswp
2162 * @subpackage userswp/includes
2163 *
2164 */
2165 public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2166 switch ( $type ) {
2167 case 'register':
2168 $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2169 $fields = get_register_form_fields( $form_id );
2170 $user_data = get_userdata( $user_id );
2171 if ( ! empty( $fields ) && is_array( $fields ) ) {
2172 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2173 $excluded = uwp_get_excluded_fields();
2174 foreach ( $fields as $key => $field ) {
2175 if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2176 continue;
2177 }
2178 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2179 $field_value = $user_data->user_email;
2180 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2181 $field_value = $user_data->user_login;
2182 } elseif ( $field->htmlvar_name == 'bio' ) {
2183 $field_value = get_user_meta( $user_id, 'description', true );
2184 } else {
2185 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2186 }
2187
2188 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2189 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2190 }
2191
2192 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2193 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2194 }
2195 }
2196 }
2197 break;
2198 case 'account':
2199 $fields = get_account_form_fields();
2200 $user_data = get_userdata( $user_id );
2201 if ( ! empty( $fields ) && is_array( $fields ) ) {
2202 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2203 foreach ( $fields as $key => $field ) {
2204 if ( $field->is_active != '1' ) {
2205 continue;
2206 }
2207 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2208 $field_value = $user_data->user_email;
2209 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2210 $field_value = $user_data->user_login;
2211 } elseif ( $field->htmlvar_name == 'bio' ) {
2212 $field_value = get_user_meta( $user_id, 'description', true );
2213 } else {
2214 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2215 }
2216
2217 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2218 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2219 }
2220
2221 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2222 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2223 }
2224 }
2225 }
2226 break;
2227 }
2228
2229 return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2230 }
2231
2232 /**
2233 *
2234 *
2235 * @return void
2236 * @since 1.0.12 Unlink file.
2237 * @package userswp
2238 * @since 1.0.0
2239 */
2240 public function upload_file_remove() {
2241 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2242
2243 $htmlvar = esc_sql( strip_tags( $_POST['htmlvar'] ) );
2244 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2245
2246 if ( empty( $user_id ) ) {
2247 wp_die( -1 );
2248 }
2249
2250 if ( ! ( is_user_logged_in() && ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) ) {
2251 wp_send_json_error( __( 'Invalid access!', 'userswp' ) );
2252 }
2253
2254 // Remove file
2255 if ( $htmlvar == 'banner_thumb' ) {
2256 $file = uwp_get_usermeta( $user_id, 'banner_thumb' );
2257 $type = 'banner';
2258 } elseif ( $htmlvar == 'avatar_thumb' ) {
2259 $file = uwp_get_usermeta( $user_id, 'avatar_thumb' );
2260 $type = 'avatar';
2261 } else {
2262 $file = '';
2263 $type = '';
2264 }
2265
2266 uwp_update_usermeta( $user_id, $htmlvar, '' );
2267
2268 if ( $file ) {
2269 $uploads = wp_upload_dir();
2270 $upload_path = $uploads['basedir'];
2271 $unlink_file = untrailingslashit( $upload_path ) . '/' . ltrim( $file, '/' );
2272
2273 if ( is_file( $unlink_file ) && file_exists( $unlink_file ) ) {
2274 @unlink( $unlink_file );
2275 $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_file );
2276
2277 if ( is_file( $unlink_ori_file ) && file_exists( $unlink_ori_file ) ) {
2278 @unlink( $unlink_ori_file );
2279 }
2280 }
2281 }
2282
2283 wp_send_json_success();
2284
2285 wp_die();
2286 }
2287
2288 /**
2289 * Form field template for datepicker field type.
2290 *
2291 * @param string $html Form field html
2292 * @param object $field Field info.
2293 * @param string $value Form field default value.
2294 * @param string $form_type Form type
2295 *
2296 * @return string Modified form field html.
2297 * @package userswp
2298 *
2299 * @since 1.0.0
2300 */
2301 public function form_input_datepicker( $html, $field, $value, $form_type ) {
2302
2303 // Check if there is a field specific filter.
2304 if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2305 $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2306 }
2307
2308 // If no html then we run the standard output.
2309 if ( empty( $html ) ) {
2310
2311 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2312 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2313 $bs_sr_only = $design_style ? 'sr-only' : '';
2314 $bs_form_control = $design_style ? 'form-control' : '';
2315 $extra_attributes = array();
2316 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2317 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2318
2319 ob_start(); // Start buffering;
2320
2321 $extra_fields = unserialize( $field->extra_fields );
2322
2323 if ( $extra_fields['date_format'] == '' ) {
2324 $extra_fields['date_format'] = 'yy-mm-dd';
2325 }
2326
2327 $date_format = $extra_fields['date_format'];
2328 $jquery_date_format = $date_format;
2329
2330 // check if we need to change the format or not
2331 $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2332 if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2333
2334 $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2335 $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2336
2337 $date_format = str_replace( $search, $replace, $date_format );
2338 } else {
2339 $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2340 }
2341
2342 if ( ! empty( $value ) && ! is_string( $value ) ) {
2343 $value = date( 'Y-m-d', $value );
2344 }
2345
2346 if ( $value == '0000-00-00' ) {
2347 $value = '';
2348 }//if date not set, then mark it empty
2349 $value = uwp_date( $value, 'Y-m-d', $date_format );
2350 $site_title = uwp_get_form_label( $field );
2351
2352 // bootstrap
2353 if ( $design_style ) {
2354 // flatpickr attributes
2355 $extra_attributes['data-alt-input'] = 'true';
2356 $extra_attributes['data-alt-format'] = $date_format;
2357 $extra_attributes['data-date-format'] = 'Y-m-d';
2358
2359 if ( 'dob' == $field->htmlvar_name ) {
2360 $extra_attributes['data-max-date'] = 'today';
2361 }
2362
2363 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2364
2365 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2366 array(
2367 'id' => esc_attr( $field->htmlvar_name ),
2368 'name' => esc_attr( $field->htmlvar_name ),
2369 'required' => ! empty( $field->is_required ) ? true : false,
2370 'label' => wp_kses_post( $site_title . $required ),
2371 'label_show' => true,
2372 'label_type' => 'hidden',
2373 'type' => 'datepicker',
2374 'title' => esc_html( $site_title ),
2375 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2376 'class' => '',
2377 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2378 'value' => esc_attr( $value ),
2379 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2380 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2381 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2382 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2383 )
2384 );
2385 } else {
2386 ?>
2387 <script type="text/javascript">
2388
2389 jQuery(function () {
2390 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2391 changeMonth: true, changeYear: true
2392 <?php
2393 if ( $field->htmlvar_name == 'dob' ) {
2394 echo ", yearRange: '1900:+0'";
2395 } else {
2396 echo ", yearRange: '1900:2050'";
2397 }
2398 ?>
2399 <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2400
2401 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2402
2403 <?php if ( ! empty( $value ) ) { ?>
2404 var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2405 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2406 <?php } ?>
2407
2408 });
2409
2410 </script>
2411 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2412 class="
2413 <?php
2414 if ( $field->is_required ) {
2415 echo 'required_field';
2416 }
2417 ?>
2418 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2419
2420 <?php
2421
2422 if ( ! is_admin() ) {
2423 ?>
2424 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2425 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2426 <?php
2427 if ( $field->is_required ) {
2428 echo '<span>*</span>';
2429 }
2430 ?>
2431 </label>
2432 <?php } ?>
2433
2434 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2435 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2436 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2437 title="<?php echo esc_attr( $site_title ); ?>"
2438 type="text"
2439 <?php
2440 if ( $field->is_required == 1 ) {
2441 echo 'required="required"';
2442 }
2443 ?>
2444 value="<?php echo esc_attr( $value ); ?>"
2445 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2446
2447 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2448 <?php if ( $field->is_required ) { ?>
2449 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2450 <?php } ?>
2451 </div>
2452
2453 <?php
2454 }
2455
2456 $html = ob_get_clean();
2457 }
2458
2459 return $html;
2460 }
2461
2462 /**
2463 * Form field template for time field type.
2464 *
2465 * @param string $html Form field html
2466 * @param object $field Field info.
2467 * @param string $value Form field default value.
2468 * @param string $form_type Form type
2469 *
2470 * @return string Modified form field html.
2471 * @package userswp
2472 *
2473 * @since 1.0.0
2474 */
2475 public function form_input_time( $html, $field, $value, $form_type ) {
2476
2477 if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
2478
2479 $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2480 }
2481
2482 // If no html then we run the standard output.
2483 if ( empty( $html ) ) {
2484
2485 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2486 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2487 $bs_sr_only = $design_style ? 'sr-only' : '';
2488 $bs_form_control = $design_style ? 'form-control bg-white' : '';
2489 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2490 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2491
2492 ob_start(); // Start buffering;
2493
2494 if ( $value != '' ) {
2495 $value = date( 'H:i', strtotime( $value ) );
2496 }
2497
2498 // flatpickr attributes
2499 $extra_attributes['data-enable-time'] = 'true';
2500 $extra_attributes['data-no-calendar'] = 'true';
2501 $extra_attributes['data-date-format'] = 'H:i';
2502 $site_title = uwp_get_form_label( $field );
2503 $label_type = is_admin() ? '' : 'top';
2504
2505 if ( $design_style ) {
2506 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2507
2508 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2509 array(
2510 'id' => esc_attr( $field->htmlvar_name ),
2511 'name' => esc_attr( $field->htmlvar_name ),
2512 'required' => ! empty( $field->is_required ) ? true : false,
2513 'label' => wp_kses_post( $site_title . $required ),
2514 'label_show' => true,
2515 'label_type' => esc_attr( $label_type ),
2516 'type' => 'timepicker',
2517 'title' => esc_html( $site_title ),
2518 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2519 'class' => '',
2520 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2521 'value' => esc_attr( $value ),
2522 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2523 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2524 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2525 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2526 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2527 )
2528 );
2529 } else {
2530 ?>
2531 <script type="text/javascript">
2532 jQuery(document).ready(function () {
2533 jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2534 showPeriod: true,
2535 showLeadingZero: true
2536 });
2537 });
2538 </script>
2539 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2540 class="
2541 <?php
2542 if ( $field->is_required ) {
2543 echo 'required_field';
2544 }
2545 ?>
2546 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2547
2548 <?php
2549 $site_title = uwp_get_form_label( $field );
2550 if ( ! is_admin() ) {
2551 ?>
2552 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2553 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2554 <?php
2555 if ( $field->is_required ) {
2556 echo '<span>*</span>';
2557 }
2558 ?>
2559 </label>
2560 <?php } ?>
2561
2562 <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2563 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2564 value="<?php echo esc_attr( $value ); ?>"
2565 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2566 type="text"
2567 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2568
2569 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2570 <?php if ( $field->is_required ) { ?>
2571 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2572 <?php } ?>
2573 </div>
2574 <?php
2575 }
2576 $html = ob_get_clean();
2577 }
2578
2579 return $html;
2580 }
2581
2582 /**
2583 * Form field template for select field type.
2584 *
2585 * @param string $html Form field html
2586 * @param object $field Field info.
2587 * @param string $value Form field default value.
2588 * @param string $form_type Form type
2589 *
2590 * @return string Modified form field html.
2591 * @package userswp
2592 *
2593 * @since 1.0.0
2594 */
2595 public function form_input_select( $html, $field, $value, $form_type ) {
2596
2597 // Check if there is a field specific filter.
2598 if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2599 $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2600 }
2601
2602 // Check if there is a field type specific filter.
2603 if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2604 $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2605 }
2606
2607 // If no html then we run the standard output.
2608 if ( empty( $html ) ) {
2609
2610 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2611 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2612 $bs_sr_only = $design_style ? 'sr-only' : '';
2613 $bs_form_control = $design_style ? 'form-control' : '';
2614 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2615 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2616
2617 ob_start(); // Start buffering;
2618 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2619 $site_title = uwp_get_form_label( $field );
2620
2621 // bootstrap
2622 if ( $design_style ) {
2623
2624 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2625
2626 echo aui()->select(
2627 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2628 'id' => esc_attr( $field->htmlvar_name ),
2629 'name' => esc_attr( $field->htmlvar_name ),
2630 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2631 'title' => esc_html( $site_title ),
2632 'value' => esc_attr( $value ),
2633 'required' => (bool) $field->is_required,
2634 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2635 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2636 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2637 'label' => wp_kses_post( $site_title . $required ),
2638 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2639 'select2' => true,
2640 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2641 )
2642 );
2643 } else {
2644 ?>
2645 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2646 class="
2647 <?php
2648 if ( $field->is_required ) {
2649 echo 'required_field';
2650 }
2651 ?>
2652 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2653
2654 <?php
2655 if ( ! is_admin() ) {
2656 ?>
2657 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2658 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2659 <?php
2660 if ( $field->is_required ) {
2661 echo '<span>*</span>';
2662 }
2663 ?>
2664 </label>
2665 <?php } ?>
2666
2667 <?php
2668
2669 $select_options = '';
2670 if ( ! empty( $option_values_arr ) ) {
2671 foreach ( $option_values_arr as $option_row ) {
2672 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2673 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2674
2675 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2676 } else {
2677 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2678 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2679 $selected = $option_value == $value ? 'selected="selected"' : '';
2680
2681 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2682 }
2683 }
2684 }
2685 ?>
2686 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2687 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2688 title="<?php echo esc_attr( $site_title ); ?>"
2689 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2690 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2691 </select>
2692 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2693 <?php if ( $field->is_required ) { ?>
2694 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2695 <?php } ?>
2696 </div>
2697
2698 <?php
2699 }
2700 $html = ob_get_clean();
2701 }
2702
2703 return $html;
2704 }
2705
2706 /**
2707 * Form field template for multiselect field type.
2708 *
2709 * @param string $html Form field html
2710 * @param object $field Field info.
2711 * @param string $value Form field default value.
2712 * @param string $form_type Form type
2713 *
2714 * @return string Modified form field html.
2715 * @package userswp
2716 *
2717 * @since 1.0.0
2718 */
2719 public function form_input_multiselect( $html, $field, $value, $form_type ) {
2720
2721 // Check if there is a field specific filter.
2722 if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
2723 $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2724 }
2725
2726 if ( empty( $html ) ) {
2727
2728 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2729 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2730 $bs_sr_only = $design_style ? 'sr-only' : '';
2731 $bs_form_control = $design_style ? 'form-control' : '';
2732 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2733 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2734
2735 ob_start(); // Start buffering;
2736
2737 $multi_display = 'select';
2738 if ( ! empty( $field->extra_fields ) ) {
2739 $multi_display = unserialize( $field->extra_fields );
2740 }
2741
2742 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2743 $site_title = uwp_get_form_label( $field );
2744 $value = is_array( $value ) ? $value : esc_attr( $value );
2745
2746 // bootstrap
2747 if ( $design_style ) {
2748
2749 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2750
2751 echo aui()->select(
2752 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2753 'id' => esc_attr( $field->htmlvar_name ),
2754 'name' => esc_attr( $field->htmlvar_name ),
2755 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2756 'title' => esc_html( $site_title ),
2757 'value' => $value,
2758 'required' => (bool) $field->is_required,
2759 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2760 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2761 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2762 'label' => wp_kses_post( $site_title . $required ),
2763 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2764 'select2' => true,
2765 'multiple' => true,
2766 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2767 )
2768 );
2769 } else {
2770 ?>
2771 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2772 class="
2773 <?php
2774 if ( $field->is_required ) {
2775 echo 'required_field';
2776 }
2777 ?>
2778 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2779
2780 <?php
2781 if ( ! is_admin() ) {
2782 ?>
2783 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2784 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2785 <?php
2786 if ( $field->is_required ) {
2787 echo '<span>*</span>';
2788 }
2789 ?>
2790 </label>
2791 <?php } ?>
2792
2793 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
2794 <?php if ( $multi_display == 'select' ) { ?>
2795 <div class="uwp_multiselect_list">
2796 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
2797 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2798 title="<?php echo esc_attr( $site_title ); ?>"
2799 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2800 class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
2801 >
2802 <?php
2803 } else {
2804 ?>
2805 <ul class="uwp_multi_choice">
2806 <?php
2807 }
2808
2809 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2810 $select_options = '';
2811 if ( ! empty( $option_values_arr ) ) {
2812 foreach ( $option_values_arr as $option_row ) {
2813 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
2814 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2815
2816 if ( $multi_display == 'select' ) {
2817 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
2818 } else {
2819 $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
2820 }
2821 } else {
2822 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
2823 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
2824 $selected = $option_value == $value ? 'selected="selected"' : '';
2825 $checked = '';
2826
2827 if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
2828 if ( ! is_array( $value ) ) {
2829 $value_array = explode( ',', $value );
2830 } else {
2831 $value_array = $value;
2832 }
2833
2834 if ( is_array( $value_array ) ) {
2835 if ( in_array( $option_value, $value_array ) ) {
2836 $selected = 'selected="selected"';
2837 $checked = 'checked="checked"';
2838 }
2839 }
2840 }
2841
2842 if ( $multi_display == 'select' ) {
2843 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
2844 } else {
2845 $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
2846 }
2847 }
2848 }
2849 }
2850 echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2851
2852 if ( $multi_display == 'select' ) {
2853
2854 ?>
2855 </select></div>
2856 <?php } else { ?>
2857 </ul>
2858 <?php } ?>
2859 <?php if ( $field->is_required ) { ?>
2860 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2861 <?php } ?>
2862 </div>
2863 <?php
2864 }
2865 $html = ob_get_clean();
2866 }
2867
2868 return $html;
2869 }
2870
2871 /**
2872 * Form field template for file field type.
2873 *
2874 * @param string $html Form field html
2875 * @param object $field Field info.
2876 * @param string $value Form field default value.
2877 * @param string $form_type Form type
2878 *
2879 * @return string Modified form field html.
2880 * @package userswp
2881 *
2882 * @since 1.0.0
2883 */
2884 public function form_input_file( $html, $field, $value, $form_type ) {
2885
2886 $file_obj = new UsersWP_Files();
2887
2888 // Check if there is a field specific filter.
2889 if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
2890 $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2891 }
2892
2893 // If no html then we run the standard output.
2894 if ( empty( $html ) ) {
2895
2896 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2897 $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
2898 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2899 $bs_sr_only = $design_style ? 'sr-only' : '';
2900 $bs_form_control = $design_style ? 'form-control' : '';
2901
2902 ob_start(); // Start buffering;
2903
2904 ?>
2905 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2906 class="
2907 <?php
2908 if ( $field->is_required ) {
2909 echo 'required_field';
2910 }
2911 ?>
2912 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
2913
2914 <?php
2915 $site_title = uwp_get_form_label( $field );
2916 if ( ! is_admin() && ! wp_doing_ajax() ) {
2917 ?>
2918 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2919 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2920 <?php
2921 if ( $field->is_required ) {
2922 echo ' <span class="text-danger">*</span>';
2923 }
2924 ?>
2925 </label>
2926 <?php } ?>
2927
2928 <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
2929 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2930 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
2931 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2932 title="<?php echo esc_attr( $site_title ); ?>"
2933 <?php
2934 if ( $field->is_required == 1 ) {
2935 echo 'data-is-required="1"';
2936 }
2937 if ( $field->is_required == 1 && ! $value ) {
2938 echo 'required="required"';
2939 }
2940 ?>
2941 type="<?php echo esc_attr( $field->field_type ); ?>">
2942 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2943 <?php if ( $field->is_required ) { ?>
2944 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2945 <?php } ?>
2946 </div>
2947
2948 <?php
2949 $html = ob_get_clean();
2950 }
2951
2952 return $html;
2953 }
2954
2955 /**
2956 * Form field template for checkbox field type.
2957 *
2958 * @param string $html Form field html
2959 * @param object $field Field info.
2960 * @param string $value Form field default value.
2961 * @param string $form_type Form type
2962 *
2963 * @return string Modified form field html.
2964 * @package userswp
2965 *
2966 * @since 1.0.0
2967 */
2968 public function form_input_checkbox( $html, $field, $value, $form_type ) {
2969
2970 // Check if there is a field specific filter.
2971 if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
2972 $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2973 }
2974
2975 // If no html then we run the standard output.
2976 if ( empty( $html ) ) {
2977
2978 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2979 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
2980 $bs_sr_only = $design_style ? 'form-check-label' : '';
2981 $bs_form_control = $design_style ? 'form-check-input' : '';
2982
2983 ob_start(); // Start buffering;
2984 $site_title = uwp_get_form_label( $field );
2985
2986 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2987 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
2988
2989 $checked = $value == '1' ? true : false;
2990
2991 // bootstrap
2992 if ( $design_style ) {
2993 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2994
2995 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
2996
2997 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2998 array(
2999 'id' => esc_attr( $id ),
3000 'name' => esc_attr( $field->htmlvar_name ),
3001 'type' => 'checkbox',
3002 'value' => '1',
3003 'title' => esc_html( $site_title ),
3004 'label' => wp_kses_post( $site_title . $required ),
3005 'label_show' => true,
3006 'required' => ! empty( $field->is_required ) ? true : false,
3007 'checked' => (bool) $checked,
3008 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3009 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3010 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3011 )
3012 );
3013
3014 } else {
3015 ?>
3016 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3017 class="
3018 <?php
3019 if ( $field->is_required ) {
3020 echo 'required_field';
3021 }
3022 ?>
3023 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3024 <?php if ( ! empty( $design_style ) ) { ?>
3025 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3026 <?php } ?>
3027 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3028 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3029 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3030 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3031 title="<?php echo esc_attr( $site_title ); ?>"
3032 <?php
3033 if ( $field->is_required == 1 ) {
3034 echo 'required="required"';
3035 }
3036 ?>
3037 <?php
3038 if ( $value == '1' ) {
3039 echo 'checked="checked"';
3040 }
3041 ?>
3042 type="<?php echo esc_attr( $field->field_type ); ?>"
3043 value="1">
3044 <?php
3045 echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3046 ?>
3047 <?php if ( ! empty( $design_style ) ) { ?>
3048 </label>
3049 <?php } ?>
3050 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3051 <?php if ( $field->is_required ) { ?>
3052 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3053 <?php } ?>
3054 </div>
3055
3056 <?php
3057
3058 }
3059
3060 $html = ob_get_clean();
3061
3062 }
3063
3064 return $html;
3065 }
3066
3067 /**
3068 * Form field template for radio field type.
3069 *
3070 * @param string $html Form field html
3071 * @param object $field Field info.
3072 * @param string $value Form field default value.
3073 * @param string $form_type Form type
3074 *
3075 * @return string Modified form field html.
3076 * @package userswp
3077 *
3078 * @since 1.0.0
3079 */
3080 public function form_input_radio( $html, $field, $value, $form_type ) {
3081
3082 // Check if there is a field specific filter.
3083 if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3084 $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3085 }
3086
3087 // If no html then we run the standard output.
3088 if ( empty( $html ) ) {
3089
3090 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3091 $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3092 $bs_sr_only = $design_style ? 'sr-only' : '';
3093 $bs_label_class = $design_style ? 'form-check-label' : '';
3094 $bs_form_control = $design_style ? 'form-check-input' : '';
3095
3096 ob_start(); // Start buffering;
3097
3098 if ( $design_style ) {
3099
3100 $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3101 $option_values = array();
3102 if ( ! empty( $option_values_deep ) ) {
3103 foreach ( $option_values_deep as $option ) {
3104 $option_values[ $option['value'] ] = $option['label'];
3105 }
3106 }
3107
3108 $site_title = uwp_get_form_label( $field );
3109
3110 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3111
3112 echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3113 array(
3114 'id' => esc_attr( $field->htmlvar_name ),
3115 'name' => esc_attr( $field->htmlvar_name ),
3116 'type' => 'radio',
3117 'title' => esc_html( $site_title ),
3118 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3119 'label_type' => 'top',
3120 'class' => '',
3121 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3122 'value' => esc_attr( $value ),
3123 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3124 )
3125 );
3126
3127 } else {
3128
3129 ?>
3130 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3131 class="
3132 <?php
3133 if ( $field->is_required ) {
3134 echo 'required_field';
3135 }
3136 ?>
3137 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3138
3139 <?php
3140 $site_title = uwp_get_form_label( $field );
3141 if ( ! is_admin() ) {
3142 ?>
3143 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3144 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3145 <?php
3146 if ( $field->is_required ) {
3147 echo '<span>*</span>';
3148 }
3149 ?>
3150 </label>
3151 <?php } ?>
3152
3153 <?php
3154 if ( $field->option_values ) {
3155 $option_values = uwp_string_values_to_options( $field->option_values, true );
3156
3157 if ( ! empty( $option_values ) ) {
3158 $count = 0;
3159 foreach ( $option_values as $option_value ) {
3160 if ( empty( $option_value['optgroup'] ) ) {
3161 ++$count;
3162 if ( $count == 1 ) {
3163 $class = 'uwp-radio-first';
3164 } else {
3165 $class = '';
3166 }
3167 ?>
3168 <?php if ( ! empty( $design_style ) ) { ?>
3169 <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3170 <?php } else { ?>
3171 <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3172 <?php } ?>
3173 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3174 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3175 title="<?php echo esc_attr( $option_value['label'] ); ?>"
3176 <?php checked( $value, $option_value['value'] ); ?>
3177 <?php
3178 if ( $field->is_required == 1 ) {
3179 echo 'required="required"';
3180 }
3181 ?>
3182 value="<?php echo esc_attr( $option_value['value'] ); ?>"
3183 class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3184 <?php echo esc_html( $option_value['label'] ); ?>
3185 <?php if ( ! empty( $design_style ) ) { ?>
3186 </label>
3187 <?php } else { ?>
3188 </span>
3189 <?php
3190 }
3191 }
3192 }
3193 }
3194 }
3195 ?>
3196 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3197 <?php if ( $field->is_required ) { ?>
3198 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3199 <?php } ?>
3200 </div>
3201 <?php
3202 }
3203
3204 $html = ob_get_clean();
3205 }
3206
3207 return $html;
3208 }
3209
3210 /**
3211 * Form field template for text field type.
3212 *
3213 * @param string $html Form field html
3214 * @param object $field Field info.
3215 * @param string $value Form field default value.
3216 * @param string $form_type Form type
3217 *
3218 * @return string Modified form field html.
3219 * @package userswp
3220 *
3221 * @since 1.0.0
3222 */
3223 public function form_input_text( $html, $field, $value, $form_type ) {
3224
3225 // Check if there is a custom field specific filter.
3226 if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3227 $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3228 }
3229
3230 // If no html then we run the standard output.
3231 if ( empty( $html ) ) {
3232
3233 ob_start(); // Start buffering;
3234
3235 $type = 'text';
3236 $step = false;
3237 //number and float validation $validation_pattern
3238 if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3239 $type = 'number';
3240 } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3241 $dp = $field->decimal_point;
3242 switch ( $dp ) {
3243 case '1':
3244 $step = '0.1';
3245 break;
3246 case '2':
3247 $step = '0.01';
3248 break;
3249 case '3':
3250 $step = '0.001';
3251 break;
3252 case '4':
3253 $step = '0.0001';
3254 break;
3255 case '5':
3256 $step = '0.00001';
3257 break;
3258 case '6':
3259 $step = '0.000001';
3260 break;
3261 case '7':
3262 $step = '0.0000001';
3263 break;
3264 case '8':
3265 $step = '0.00000001';
3266 break;
3267 case '9':
3268 $step = '0.000000001';
3269 break;
3270 case '10':
3271 $step = '0.0000000001';
3272 break;
3273 default:
3274 $step = '0.01';
3275 break;
3276 }
3277 $type = 'number';
3278 }
3279
3280 $site_title = uwp_get_form_label( $field );
3281 $placeholder = uwp_get_field_placeholder( $field );
3282 $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3283 if ( $manual_label
3284 && isset( $field->form_type )
3285 && $field->form_type == 'login'
3286 && $field->htmlvar_name == 'username' ) {
3287 $site_title = __( 'Username or Email', 'userswp' );
3288 $required = ! empty( $field->is_required ) ? ' *' : '';
3289 $placeholder = $site_title . $required;
3290 $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3291 }
3292
3293 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3294 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3295 $bs_sr_only = $design_style ? 'sr-only' : '';
3296 $bs_form_control = $design_style ? 'form-control' : '';
3297
3298 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3299 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3300
3301 // bootstrap
3302 if ( $design_style ) {
3303 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3304
3305 echo aui()->input(
3306 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3307 'type' => esc_attr( $type ),
3308 'id' => esc_attr( $field->htmlvar_name ),
3309 'name' => esc_attr( $field->htmlvar_name ),
3310 'placeholder' => esc_attr( $placeholder ),
3311 'title' => esc_html( $site_title ),
3312 'value' => esc_attr( wp_unslash( $value ) ),
3313 'required' => (bool) $field->is_required,
3314 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3315 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3316 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3317 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3318 'step' => esc_attr( $step ),
3319 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3320 )
3321 );
3322 } else {
3323 ?>
3324 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3325 <?php
3326 if ( $field->is_required ) {
3327 echo 'required_field';
3328 }
3329 ?>
3330 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3331 <?php
3332
3333 if ( ! is_admin() ) {
3334 ?>
3335 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3336 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3337 <?php
3338 if ( $field->is_required ) {
3339 echo '<span>*</span>';
3340 }
3341 ?>
3342 </label>
3343 <?php
3344 }
3345 ?>
3346
3347 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3348 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3349 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3350 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3351 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3352 title="<?php echo esc_attr( $site_title ); ?>"
3353 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3354 oninput="setCustomValidity('')"
3355 <?php
3356 if ( $field->is_required == 1 ) {
3357 echo 'required="required"';
3358 }
3359 ?>
3360 <?php
3361 if ( $field->for_admin_use == 1 ) {
3362 echo 'readonly="readonly"';
3363 }
3364 ?>
3365 type="<?php echo esc_attr( $type ); ?>"
3366 <?php
3367 if ( $step ) {
3368 echo 'step="' . esc_attr( $step ) . '"';
3369 }
3370 ?>
3371 />
3372 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3373 <?php if ( $field->is_required ) { ?>
3374 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3375 <?php } ?>
3376 </div>
3377
3378
3379 <?php
3380 }
3381 $html = ob_get_clean();
3382 }
3383
3384 return $html;
3385 }
3386
3387 /**
3388 * Form field template for textarea field type.
3389 *
3390 * @param string $html Form field html
3391 * @param object $field Field info.
3392 * @param string $value Form field default value.
3393 * @param string $form_type Form type
3394 *
3395 * @return string Modified form field html.
3396 * @package userswp
3397 *
3398 * @since 1.0.0
3399 */
3400 public function form_input_textarea( $html, $field, $value, $form_type ) {
3401
3402 // Check if there is a field specific filter.
3403 if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3404 $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3405 }
3406
3407 // If no html then we run the standard output.
3408 if ( empty( $html ) ) {
3409
3410 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3411 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3412 $bs_sr_only = $design_style ? 'sr-only' : '';
3413 $bs_form_control = $design_style ? 'form-control' : '';
3414 $site_title = uwp_get_form_label( $field );
3415
3416 ob_start(); // Start buffering;
3417
3418 // bootstrap
3419 if ( $design_style ) {
3420 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3421
3422 echo aui()->textarea(
3423 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3424 'id' => esc_attr( $field->htmlvar_name ),
3425 'name' => esc_attr( $field->htmlvar_name ),
3426 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3427 'title' => esc_html( $site_title ),
3428 'value' => wp_kses_post( stripslashes( $value ) ),
3429 'required' => (bool) $field->is_required,
3430 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3431 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3432 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3433 'rows' => '4',
3434 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3435 )
3436 );
3437 } else {
3438 ?>
3439
3440 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3441 class="
3442 <?php
3443 if ( $field->is_required ) {
3444 echo 'required_field';
3445 }
3446 ?>
3447 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3448
3449 <?php
3450
3451 if ( ! is_admin() ) {
3452 ?>
3453 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3454 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3455 <?php
3456 if ( $field->is_required ) {
3457 echo '<span>*</span>';
3458 }
3459 ?>
3460 </label>
3461 <?php } ?>
3462
3463 <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3464 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3465 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3466 title="<?php echo esc_attr( $site_title ); ?>"
3467 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3468 oninput="setCustomValidity('')"
3469 <?php
3470 if ( $field->is_required == 1 ) {
3471 echo 'required="required"';
3472 }
3473 ?>
3474 type="<?php echo esc_attr( $field->field_type ); ?>"
3475 rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3476 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3477 <?php if ( $field->is_required ) { ?>
3478 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3479 <?php } ?>
3480 </div>
3481
3482 <?php
3483 }
3484 $html = ob_get_clean();
3485 }
3486
3487 return $html;
3488 }
3489
3490 public function form_input_editor( $html, $field, $value, $form_type ) {
3491
3492 // Check if there is a field specific filter.
3493 if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3494 $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3495 }
3496
3497 if ( empty( $html ) ) {
3498
3499 ob_start();
3500
3501 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3502 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3503 $bs_sr_only = $design_style ? 'sr-only' : '';
3504 $site_title = uwp_get_form_label( $field );
3505
3506 $content = stripslashes( $value );
3507 $editor_id = $field->htmlvar_name;
3508 $args = array(
3509 'textarea_rows' => 5,
3510 'media_buttons' => false,
3511 'quicktags' => false,
3512 );
3513
3514 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3515 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3516
3517 // bootstrap
3518 if ( $design_style ) {
3519 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3520
3521 echo aui()->textarea(
3522 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3523 'id' => esc_attr( $field->htmlvar_name ),
3524 'name' => esc_attr( $field->htmlvar_name ),
3525 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3526 'title' => esc_html( $site_title ),
3527 'value' => wp_kses_post( stripslashes( $value ) ),
3528 'required' => (bool) $field->is_required,
3529 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3530 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3531 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3532 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3533 'rows' => 5,
3534 'wysiwyg' => true,
3535 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3536 )
3537 );
3538 } else {
3539 ?>
3540 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3541 class="
3542 <?php
3543 if ( $field->is_required ) {
3544 echo 'required_field';
3545 }
3546 ?>
3547 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3548
3549 <?php
3550
3551 if ( ! is_admin() ) {
3552 ?>
3553 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3554 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3555 <?php
3556 if ( $field->is_required ) {
3557 echo '<span>*</span>';
3558 }
3559 ?>
3560 </label>
3561 <?php } ?>
3562
3563 <?php wp_editor( $content, $editor_id, $args ); ?>
3564
3565 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3566 <?php if ( $field->is_required ) { ?>
3567 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3568 <?php } ?>
3569 </div>
3570 <?php
3571 }
3572 $html = ob_get_clean();
3573 }
3574
3575 return $html;
3576 }
3577
3578 /**
3579 * Form field template for fieldset field type.
3580 *
3581 * @param string $html Form field html
3582 * @param object $field Field info.
3583 * @param string $value Form field default value.
3584 * @param string $form_type Form type
3585 *
3586 * @return string Modified form field html.
3587 * @package userswp
3588 *
3589 * @since 1.0.0
3590 */
3591 public function form_input_fieldset( $html, $field, $value, $form_type ) {
3592 // Check if there is a custom field specific filter.
3593 if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3594 $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3595 }
3596
3597 // If no html then we run the standard output.
3598 if ( empty( $html ) ) {
3599
3600 ob_start(); // Start buffering;
3601 $site_title = uwp_get_form_label( $field );
3602 ?>
3603 <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3604 <?php echo esc_html( $site_title ); ?>
3605 <?php
3606 if ( $field->help_text != '' ) {
3607 echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3608 }
3609 ?>
3610 </h3>
3611 <?php
3612 $html = ob_get_clean();
3613 }
3614
3615 return $html;
3616 }
3617
3618 /**
3619 * Form field template for url field type.
3620 *
3621 * @param string $html Form field html
3622 * @param object $field Field info.
3623 * @param string $value Form field default value.
3624 * @param string $form_type Form type
3625 *
3626 * @return string Modified form field html.
3627 * @package userswp
3628 *
3629 * @since 1.0.0
3630 */
3631 public function form_input_url( $html, $field, $value, $form_type ) {
3632
3633 // Check if there is a custom field specific filter.
3634 if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
3635 $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3636 }
3637
3638 // If no html then we run the standard output.
3639 if ( empty( $html ) ) {
3640
3641 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3642 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3643 $bs_sr_only = $design_style ? 'sr-only' : '';
3644 $bs_form_control = $design_style ? 'form-control' : '';
3645
3646 ob_start(); // Start buffering;
3647 $site_title = uwp_get_form_label( $field );
3648 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
3649 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3650
3651 // bootstrap
3652 if ( $design_style ) {
3653 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3654
3655 echo aui()->input(
3656 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3657 'type' => 'url',
3658 'id' => esc_attr( $field->htmlvar_name ),
3659 'name' => esc_attr( $field->htmlvar_name ),
3660 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3661 'title' => esc_html( $site_title ),
3662 'value' => esc_attr( $value ),
3663 'required' => (bool) $field->is_required,
3664 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3665 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3666 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3667 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3668 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3669 )
3670 );
3671 } else {
3672 ?>
3673 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3674 class="
3675 <?php
3676 if ( $field->is_required ) {
3677 echo 'required_field';
3678 }
3679 ?>
3680 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3681
3682 <?php
3683 if ( ! is_admin() ) {
3684 ?>
3685 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3686 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3687 <?php
3688 if ( $field->is_required ) {
3689 echo '<span>*</span>';
3690 }
3691 ?>
3692 </label>
3693 <?php } ?>
3694
3695 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3696 class="
3697 <?php
3698 //echo $field->css_class;
3699 ?>
3700 uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3701 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3702 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3703 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3704 title="<?php echo esc_attr( $site_title ); ?>"
3705 <?php
3706 if ( $field->is_required == 1 ) {
3707 echo 'required="required"';
3708 }
3709 ?>
3710 type="url"
3711 oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
3712 onchange="try{setCustomValidity('')}catch(e){}"
3713 />
3714 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3715 <?php if ( $field->is_required ) { ?>
3716 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3717 <?php } ?>
3718 </div>
3719
3720 <?php
3721 }
3722
3723 $html = ob_get_clean();
3724 }
3725
3726 return $html;
3727 }
3728
3729 /**
3730 * Form field template for email field type.
3731 *
3732 * @param string $html Form field html
3733 * @param object $field Field info.
3734 * @param string $value Form field default value.
3735 * @param string $form_type Form type
3736 *
3737 * @return string Modified form field html.
3738 * @package userswp
3739 *
3740 * @since 1.0.0
3741 */
3742 public function form_input_email( $html, $field, $value, $form_type ) {
3743
3744 // Check if there is a custom field specific filter.
3745 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
3746 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3747 }
3748
3749 // If no html then we run the standard output.
3750 if ( empty( $html ) ) {
3751
3752 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3753 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3754 $bs_sr_only = $design_style ? 'sr-only' : '';
3755 $bs_form_control = $design_style ? 'form-control' : '';
3756
3757 ob_start(); // Start buffering;
3758 $site_title = uwp_get_form_label( $field );
3759 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3760 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3761
3762 if ( $design_style ) {
3763 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3764
3765 echo aui()->input(
3766 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3767 'type' => 'email',
3768 'id' => esc_attr( $field->htmlvar_name ),
3769 'name' => esc_attr( $field->htmlvar_name ),
3770 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3771 'title' => esc_html( $site_title ),
3772 'value' => esc_attr( wp_unslash( $value ) ),
3773 'required' => (bool) $field->is_required,
3774 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3775 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3776 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3777 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3778 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3779 )
3780 );
3781 } else {
3782 ?>
3783 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3784 class="
3785 <?php
3786 if ( $field->is_required ) {
3787 echo 'required_field';
3788 }
3789 ?>
3790 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3791
3792 <?php
3793 if ( ! is_admin() ) {
3794 ?>
3795 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3796 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3797 <?php
3798 if ( $field->is_required ) {
3799 echo '<span>*</span>';
3800 }
3801 ?>
3802 </label>
3803 <?php } ?>
3804
3805 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3806 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3807 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3808 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3809 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3810 title="<?php echo esc_attr( $site_title ); ?>"
3811 <?php
3812 if ( $field->is_required == 1 ) {
3813 echo 'required="required"';
3814 }
3815 ?>
3816 type="email"
3817 />
3818 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3819 <?php if ( $field->is_required ) { ?>
3820 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3821 <?php } ?>
3822 </div>
3823
3824
3825 <?php
3826 }
3827 $html = ob_get_clean();
3828
3829 }
3830
3831 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
3832 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3833 }
3834
3835 return $html;
3836 }
3837
3838 /**
3839 * Form field template for password field type.
3840 *
3841 * @param string $html Form field html
3842 * @param object $field Field info.
3843 * @param string $value Form field default value.
3844 * @param string $form_type Form type
3845 *
3846 * @return string Modified form field html.
3847 * @package userswp
3848 *
3849 * @since 1.0.0
3850 */
3851 public function form_input_password( $html, $field, $value, $form_type ) {
3852
3853 // Check if there is a custom field specific filter.
3854 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
3855 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3856 }
3857
3858 // If no html then we run the standard output.
3859 if ( empty( $html ) ) {
3860
3861 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3862 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3863 $bs_sr_only = $design_style ? 'sr-only' : '';
3864 $bs_form_control = $design_style ? 'form-control' : '';
3865
3866 ob_start(); // Start buffering;
3867 $site_title = uwp_get_form_label( $field );
3868
3869 if ( $design_style ) {
3870 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3871 $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3872 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3873 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
3874
3875 echo aui()->input(
3876 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3877 'type' => 'password',
3878 'id' => esc_attr( $field->htmlvar_name ),
3879 'name' => esc_attr( $field->htmlvar_name ),
3880 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3881 'title' => esc_html( $site_title ),
3882 'value' => esc_attr( $value ),
3883 'required' => (bool) $field->is_required,
3884 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3885 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3886 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3887 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3888 'wrap_class' => esc_attr( $wrap_class ),
3889 )
3890 );
3891 } else {
3892 ?>
3893 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3894 <?php
3895 if ( $field->is_required ) {
3896 echo 'required_field';
3897 }
3898 ?>
3899 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3900 <?php
3901 if ( ! is_admin() ) {
3902 ?>
3903 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3904 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3905 <?php
3906 if ( $field->is_required ) {
3907 echo '<span>*</span>';
3908 }
3909 ?>
3910 </label>
3911 <?php } ?>
3912
3913 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3914 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3915 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3916 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3917 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3918 title="<?php echo esc_attr( $site_title ); ?>"
3919 <?php
3920 if ( $field->is_required == 1 ) {
3921 echo 'required="required"';
3922 }
3923 ?>
3924 type="password"
3925 />
3926 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3927 <?php if ( $field->is_required ) { ?>
3928 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3929 <?php } ?>
3930 </div>
3931
3932
3933 <?php
3934 }
3935
3936 $html = ob_get_clean();
3937 }
3938
3939 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
3940 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
3941 }
3942
3943 return $html;
3944 }
3945
3946 /**
3947 * Form field template for Phone field.
3948 *
3949 * @param string $html Form field html
3950 * @param object $field Field info.
3951 * @param string $value Form field default value.
3952 * @param string $form_type Form type
3953 *
3954 * @return string $html Modified form field html.
3955 * @since 1.0.0
3956 *
3957 */
3958 public function form_input_phone( $html, $field, $value, $form_type ) {
3959 if ( empty( $html ) ) {
3960 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3961 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3962 $bs_sr_only = $design_style ? 'sr-only' : '';
3963 $bs_form_control = $design_style ? 'form-control' : '';
3964 ob_start(); // Start buffering;
3965 $site_title = uwp_get_form_label( $field );
3966 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3967 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3968
3969 if ( $design_style ) {
3970 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3971
3972 echo aui()->input(
3973 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3974 'type' => 'tel',
3975 'id' => esc_attr( $field->htmlvar_name ),
3976 'name' => esc_attr( $field->htmlvar_name ),
3977 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3978 'title' => esc_html( $site_title ),
3979 'value' => esc_attr( $value ),
3980 'required' => (bool) $field->is_required,
3981 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3982 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3983 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3984 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3985 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3986 )
3987 );
3988 } else {
3989 ?>
3990 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3991 class="
3992 <?php
3993 if ( $field->is_required ) {
3994 echo 'required_field';
3995 }
3996 ?>
3997 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3998 <?php
3999 if ( ! is_admin() ) {
4000 ?>
4001 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4002 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4003 <?php
4004 if ( $field->is_required ) {
4005 echo '<span>*</span>';
4006 }
4007 ?>
4008 </label>
4009 <?php } ?>
4010 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4011 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4012 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4013 title="<?php echo esc_attr( $site_title ); ?>"
4014 <?php
4015 if ( $field->for_admin_use == 1 ) {
4016 echo 'readonly="readonly"';
4017 }
4018 ?>
4019 <?php
4020 if ( $field->is_required == 1 ) {
4021 echo 'required="required"';
4022 }
4023 ?>
4024 type="tel"
4025 value="<?php echo esc_html( $value ); ?>">
4026 </div>
4027 <?php
4028 }
4029 $html = ob_get_clean();
4030 }
4031
4032 return $html;
4033 }
4034
4035 public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
4036
4037 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4038 $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4039 if ( empty( $reg_gdpr ) ) {
4040 $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4041 }
4042
4043 if ( ! empty( $reg_gdpr ) ) {
4044
4045 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4046 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4047 $bs_form_control = $design_style ? 'form-check-input' : '';
4048 $site_title = uwp_get_form_label( $field );
4049 $field->htmlvar_name = 'register_gdpr';
4050 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4051
4052 $gdpr_page = get_permalink( $reg_gdpr );
4053 $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4054 $link_end = '</a>';
4055 $field_desc = uwp_get_field_description( $field, '' );
4056 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4057 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4058 $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4059 $checked = $value == '1' ? true : false;
4060
4061 ob_start(); // Start buffering;
4062
4063 // bootstrap
4064 if ( $design_style ) {
4065 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4066 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4067
4068 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4069 array(
4070 'id' => esc_attr( $id ),
4071 'name' => esc_attr( $field->htmlvar_name ),
4072 'type' => 'checkbox',
4073 'value' => '1',
4074 'title' => esc_html( $site_title ),
4075 'label' => wp_kses_post( $content . $required ),
4076 'label_show' => true,
4077 'required' => ! empty( $field->is_required ) ? true : false,
4078 'checked' => (bool) $checked,
4079 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4080 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4081 )
4082 );
4083
4084 } else {
4085 ?>
4086 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4087 class="
4088 <?php
4089 if ( $field->is_required ) {
4090 echo 'required_field';
4091 }
4092 ?>
4093 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4094 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4095 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4096 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4097 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4098 title="<?php echo esc_attr( $site_title ); ?>"
4099 <?php
4100 if ( $value == '1' ) {
4101 echo 'checked="checked"';
4102 }
4103 ?>
4104 type="<?php echo esc_attr( $field->field_type ); ?>"
4105 value="1">
4106 <?php
4107 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4108 ?>
4109 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4110 <?php if ( $field->is_required ) { ?>
4111 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4112 <?php } ?>
4113 </div>
4114
4115 <?php
4116 }
4117
4118 $html = ob_get_clean();
4119
4120 } else {
4121 $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4122 }
4123
4124 return $html;
4125 }
4126
4127 public function form_input_register_tos( $html, $field, $value, $form_type ) {
4128
4129 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4130 $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4131 if ( empty( $reg_tos ) ) {
4132 $reg_tos = uwp_get_option( 'register_terms_page', false );
4133 }
4134
4135 if ( ! empty( $reg_tos ) ) {
4136
4137 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4138 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4139 $bs_form_control = $design_style ? 'form-check-input' : '';
4140
4141 $site_title = uwp_get_form_label( $field );
4142 $terms_page = get_permalink( $reg_tos );
4143 $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4144 $link_end = '</a>';
4145 $field_desc = uwp_get_field_description( $field, '' );
4146 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4147 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4148 $field->htmlvar_name = 'register_tos';
4149 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4150
4151 $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4152 $checked = $value == '1' ? true : false;
4153
4154 ob_start();
4155
4156 if ( $design_style ) {
4157 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4158 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4159
4160 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4161 array(
4162 'id' => esc_attr( $id ),
4163 'name' => esc_attr( $field->htmlvar_name ),
4164 'type' => 'checkbox',
4165 'value' => '1',
4166 'title' => esc_html( $site_title ),
4167 'label' => wp_kses_post( $content . $required ),
4168 'label_show' => true,
4169 'required' => ! empty( $field->is_required ) ? true : false,
4170 'checked' => (bool) $checked,
4171 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4172 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4173 )
4174 );
4175
4176 } else {
4177 ?>
4178 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4179 class="
4180 <?php
4181 if ( $field->is_required ) {
4182 echo 'required_field';
4183 }
4184 ?>
4185 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4186 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4187 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4188 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4189 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4190 title="<?php echo esc_attr( $site_title ); ?>"
4191 <?php
4192 if ( $value == '1' ) {
4193 echo 'checked="checked"';
4194 }
4195 ?>
4196 type="<?php echo esc_attr( $field->field_type ); ?>"
4197 value="1">
4198 <?php
4199 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4200 ?>
4201 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4202 <?php if ( $field->is_required ) { ?>
4203 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4204 <?php } ?>
4205 </div>
4206
4207 <?php
4208
4209 }
4210
4211 $html = ob_get_clean();
4212
4213 } else {
4214 $html = '<input type="hidden" name="register_tos" value="-1"/>';
4215 }
4216
4217 return $html;
4218 }
4219
4220 /**
4221 * Adds enctype tag in form for file fields.
4222 *
4223 * @return void
4224 * @package userswp
4225 *
4226 * @since 1.0.0
4227 */
4228 function add_multipart_to_admin_edit_form() {
4229 global $wpdb;
4230 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4231 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4232 if ( $fields ) {
4233 echo 'enctype="multipart/form-data"';
4234 }
4235 }
4236
4237 /**
4238 * Handles UsersWP custom field requests from admin.
4239 *
4240 * @param int $user_id User ID.
4241 *
4242 * @return void
4243 * @since 1.0.0
4244 * @package userswp
4245 *
4246 */
4247 public function update_profile_extra_admin_edit( $user_id ) {
4248 global $wpdb;
4249 $file_obj = new UsersWP_Files();
4250 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4251 //Normal fields
4252 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4253 if ( $fields ) {
4254 if ( isset( $_POST['locale'] ) ) {
4255 $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4256 }
4257 $result = uwp_validate_fields( $_POST, 'account', $fields );
4258 if ( is_wp_error( $result ) ) {
4259 die( wp_kses_post( $result->get_error_message() ) );
4260 }
4261 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4262 $display_name = $result['display_name'];
4263 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4264 $display_name = $result['first_name'] . ' ' . $result['last_name'];
4265 } else {
4266 $user_info = get_userdata( $user_id );
4267 $display_name = $user_info->user_login;
4268 }
4269 $result['display_name'] = $display_name;
4270 if ( ! is_wp_error( $result ) ) {
4271 foreach ( $fields as $field ) {
4272 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4273 if ( $value == '0' || ! empty( $value ) ) {
4274 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4275 }
4276 }
4277 }
4278 }
4279
4280 //File fields
4281 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4282 if ( $fields ) {
4283 $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4284 if ( ! is_wp_error( $result ) ) {
4285 foreach ( $fields as $field ) {
4286 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4287 if ( $value == '0' || ! empty( $value ) ) {
4288 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4289 }
4290 }
4291 }
4292 }
4293 }
4294
4295 /**
4296 * Form field template for country field.
4297 *
4298 * @param string $html Form field html
4299 * @param object $field Field info.
4300 * @param string $value Form field default value.
4301 * @param string $form_type Form type
4302 *
4303 * @return string Modified form field html.
4304 * @package userswp
4305 *
4306 * @since 1.0.0
4307 */
4308 public function form_input_select_country( $html, $field, $value, $form_type ) {
4309
4310 // If no html then we run the standard output.
4311 if ( empty( $html ) ) {
4312
4313 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4314 $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds marginso we remove ours
4315 $bs_sr_only = $design_style ? 'sr-only' : '';
4316 $bs_form_control = $design_style ? 'form-control' : '';
4317
4318 ob_start(); // Start buffering;
4319 ?>
4320 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4321
4322 <?php
4323 $site_title = uwp_get_form_label( $field );
4324
4325 if ( ! is_admin() && ! wp_doing_ajax() ) {
4326 ?>
4327 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4328 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4329 <?php
4330 if ( $field->is_required ) {
4331 echo '<span class="text-danger">*</span>';
4332 }
4333 ?>
4334 </label>
4335 <?php
4336 }
4337 // if value empty set the default
4338 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4339 $value = $field->default_value;
4340 }
4341 if ( $value === false ) {
4342 $value = '';
4343 }
4344 $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4345 $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4346
4347 $htmlvar_name = $field->htmlvar_name;
4348 if ( wp_doing_ajax() ) {
4349 $htmlvar_name .= '_ajax';
4350 }
4351 ?>
4352 <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4353 <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4354 <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4355 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4356 <?php if ( $field->is_required ) { ?>
4357 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4358 <?php } ?>
4359 </div>
4360 <?php
4361 $html = ob_get_clean();
4362 }
4363
4364 return $html;
4365 }
4366
4367 /**
4368 * Form field template for language field.
4369 *
4370 * @param string $html Form field html
4371 * @param object $field Field info.
4372 * @param string $value Form field default value.
4373 * @param string $form_type Form type
4374 *
4375 * @return string Modified form field html.
4376 * @package userswp
4377 *
4378 * @since 1.0.0
4379 */
4380 public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4381
4382 // If no html then we run the standard output.
4383 if ( empty( $html ) ) {
4384
4385 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4386 $bs_form_group = $design_style ? 'form-group m-0' : '';
4387 $bs_sr_only = $design_style ? 'sr-only' : '';
4388 $bs_form_control = $design_style ? 'form-control' : '';
4389 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4390 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4391
4392 ob_start(); // Start buffering;
4393
4394 ?>
4395 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4396 class="
4397 <?php
4398 if ( $field->is_required ) {
4399 echo 'required_field';
4400 }
4401 ?>
4402 uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4403
4404 <?php
4405 $site_title = uwp_get_form_label( $field );
4406 if ( ! is_admin() && ! wp_doing_ajax() ) {
4407 ?>
4408 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4409 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4410 <?php
4411 if ( $field->is_required ) {
4412 echo '<span class="text-danger">*</span>';
4413 }
4414 ?>
4415 </label>
4416 <?php } ?>
4417
4418 <?php
4419 if ( empty( $field->default_value ) ) {
4420 $field->default_value = 'site-default';
4421 }
4422
4423 // if value empty set the default
4424 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4425 $value = $field->default_value;
4426 }
4427
4428 require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4429 $translations = wp_get_available_translations();
4430 $available_languages = get_available_languages();
4431 $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
4432
4433 foreach ( $available_languages as $locale ) {
4434 if ( isset( $translations[ $locale ] ) ) {
4435 $translation = $translations[ $locale ];
4436 $languages[ $translation['language'] ] = $translation['native_name'];
4437
4438 // Remove installed language from available translations.
4439 unset( $translations[ $locale ] );
4440 } else {
4441 $languages[ $locale ] = $translation[ $locale ];
4442 }
4443 }
4444
4445 if ( $design_style ) {
4446
4447 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4448
4449 echo aui()->select(
4450 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4451 'id' => esc_attr( $field->htmlvar_name ),
4452 'name' => esc_attr( $field->htmlvar_name ),
4453 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4454 'title' => esc_attr( $site_title ),
4455 'value' => esc_attr( $value ),
4456 'required' => (bool) $field->is_required,
4457 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4458 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4459 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4460 'label' => wp_kses_post( $site_title . $required ),
4461 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4462 'select2' => true,
4463 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4464 )
4465 );
4466 } else {
4467 ?>
4468 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4469 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4470 title="<?php echo esc_attr( $site_title ); ?>"
4471 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4472 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4473 </select>
4474 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4475 <?php if ( $field->is_required ) { ?>
4476 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4477 <?php
4478 }
4479 }
4480
4481 $html = ob_get_clean();
4482 }
4483
4484 return $html;
4485 }
4486
4487 /**
4488 * Adds confirm password field in forms.
4489 *
4490 * @param string $html Form field html
4491 * @param object $field Field info.
4492 * @param string $value Form field default value.
4493 * @param string $form_type Form type
4494 *
4495 * @return string Modified form field html.
4496 * @package userswp
4497 *
4498 * @since 1.0.0
4499 */
4500 public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4501 if ( $form_type == 'register' ) {
4502 //confirm password field
4503 $extra = array();
4504 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4505 $extra = unserialize( $field->extra_fields );
4506 }
4507
4508 $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4509 if ( $enable_confirm_password_field == '1' ) {
4510
4511 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4512 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4513 $bs_sr_only = $design_style ? 'sr-only' : '';
4514 $bs_form_control = $design_style ? 'form-control' : '';
4515 $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4516 $required = '';
4517 if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4518 $placeholder .= ' *';
4519 $required = ' <span class="text-danger">*</span>';
4520 }
4521 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4522 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4523 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4524
4525 ob_start(); // Start buffering;
4526
4527 if ( $design_style ) {
4528
4529 echo aui()->input(
4530 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4531 'type' => 'password',
4532 'id' => 'confirm_password',
4533 'name' => 'confirm_password',
4534 'placeholder' => esc_attr( $placeholder ),
4535 'title' => esc_attr( $site_title ),
4536 'value' => esc_attr( $value ),
4537 'required' => (bool) $field->is_required,
4538 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4539 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4540 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4541 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4542 'wrap_class' => esc_attr( $wrap_class ),
4543 )
4544 );
4545 } else {
4546 ?>
4547 <div id="uwp_account_confirm_password_row"
4548 class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4549
4550 <?php
4551
4552 if ( ! is_admin() ) {
4553 ?>
4554 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4555 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4556 <?php
4557 if ( $field->is_required ) {
4558 echo '<span>*</span>';
4559 }
4560 ?>
4561 </label>
4562 <?php } ?>
4563 <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4564 </div>
4565
4566 <?php
4567 }
4568 $confirm_html = ob_get_clean();
4569 $html = $html . $confirm_html;
4570 }
4571 }
4572
4573 return $html;
4574 }
4575
4576 /**
4577 * Adds confirm email field in forms.
4578 *
4579 * @param string $html Form field html
4580 * @param object $field Field info.
4581 * @param string $value Form field default value.
4582 * @param string $form_type Form type
4583 *
4584 * @return string Modified form field html.
4585 * @package userswp
4586 *
4587 * @since 1.0.0
4588 */
4589 public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4590 if ( $form_type == 'register' ) {
4591 //confirm email field
4592 $extra = array();
4593 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4594 $extra = unserialize( $field->extra_fields );
4595 }
4596 $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4597 if ( $enable_confirm_email_field == '1' ) {
4598
4599 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4600 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4601 $bs_sr_only = $design_style ? 'sr-only' : '';
4602 $bs_form_control = $design_style ? 'form-control' : '';
4603 $site_title = __( 'Confirm Email', 'userswp' );
4604 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4605 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4606
4607 ob_start();
4608
4609 if ( $design_style ) {
4610 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4611
4612 echo aui()->input(
4613 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4614 'type' => 'email',
4615 'id' => esc_attr( $field->htmlvar_name ),
4616 'name' => 'confirm_email',
4617 'placeholder' => esc_attr( $site_title ),
4618 'title' => esc_attr( $site_title ),
4619 'value' => esc_attr( $value ),
4620 'required' => (bool) $field->is_required,
4621 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4622 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4623 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4624 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4625 )
4626 );
4627 } else {
4628 ?>
4629 <div id="uwp_account_confirm_email_row"
4630 class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4631
4632 <?php
4633
4634 if ( ! is_admin() ) {
4635 ?>
4636 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4637 <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
4638 <?php
4639 if ( $field->is_required ) {
4640 echo '<span>*</span>';
4641 }
4642 ?>
4643 </label>
4644 <?php } ?>
4645
4646 <input name="confirm_email"
4647 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4648 id="uwp_account_confirm_email"
4649 placeholder="<?php echo esc_attr( $site_title ); ?>"
4650 value=""
4651 title="<?php echo esc_attr( $site_title ); ?>"
4652 <?php echo 'required="required"'; ?>
4653 type="email"
4654 />
4655 </div>
4656 <?php
4657 }
4658 $confirm_html = ob_get_clean();
4659 $html = $html . $confirm_html;
4660 }
4661 }
4662
4663 return $html;
4664 }
4665
4666 /**
4667 * Handles the privacy form submission.
4668 *
4669 * @return void
4670 * @package userswp
4671 *
4672 * @since 1.0.0
4673 */
4674 public function privacy_submit_handler() {
4675 if ( isset( $_POST['uwp_privacy_submit'] ) ) {
4676 if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
4677 return;
4678 }
4679
4680 global $wpdb, $uwp_notices;
4681
4682 // Save fields privacy settings
4683 $extra_where = "AND is_public='2'";
4684 $fields = get_account_form_fields( $extra_where );
4685 $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
4686 $user_id = get_current_user_id();
4687 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
4688
4689 $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4690 if ( ! empty( $user_meta_info->user_privacy ) ) {
4691 $public_fields = explode( ',', $user_meta_info->user_privacy );
4692 } else {
4693 $public_fields = array();
4694 }
4695
4696 if ( $fields ) {
4697
4698 foreach ( $fields as $field ) {
4699 $field_name = $field->htmlvar_name . '_privacy';
4700 $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4701
4702 if ( $field_value == 'no' ) {
4703 if ( ! in_array( $field_name, $public_fields ) ) {
4704 $public_fields[] = $field_name;
4705 }
4706 } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
4707 unset( $public_fields[ $field_name ] );
4708 }
4709 }
4710
4711 $value = implode( ',', $public_fields );
4712 uwp_update_usermeta( $user_id, 'user_privacy', $value );
4713 }
4714
4715 // Save tabs privacy settings
4716 $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
4717 $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4718
4719 if ( $tabs ) {
4720 $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
4721 $do_tabs_update = false;
4722 foreach ( $tabs as $tab ) {
4723 $field_name = $tab->tab_key . '_tab_privacy';
4724
4725 if ( isset( $_POST[ $field_name ] ) ) {
4726 $do_tabs_update = true;
4727 $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
4728
4729 if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
4730 unset( $public_fields[ $field_name ] );
4731 } else {
4732 $public_fields[ $field_name ] = $field_value;
4733 }
4734 }
4735 }
4736
4737 if ( $do_tabs_update ) {
4738 uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
4739 }
4740 }
4741
4742 if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
4743 update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
4744 } else {
4745 update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
4746 }
4747
4748 $make_profile_private = uwp_can_make_profile_private();
4749 if ( $make_profile_private ) {
4750 $field_name = 'uwp_make_profile_private';
4751 if ( isset( $_POST[ $field_name ] ) ) {
4752 $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
4753 $user_id = get_current_user_id();
4754 update_user_meta( $user_id, $field_name, $value );
4755 }
4756 }
4757
4758 $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
4759 $message = aui()->alert(
4760 array(
4761 'type' => 'success',
4762 'content' => $message,
4763 )
4764 );
4765 $uwp_notices[] = array( 'account' => $message );
4766
4767 }
4768 }
4769
4770 /**
4771 * Get the ajax login form.
4772 *
4773 * @since 1.2.0
4774 */
4775 public function ajax_login_form() {
4776
4777 // add the modal error container
4778 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4779
4780 $args = array(
4781 'form_title' => __( 'Login', 'userswp' ),
4782 );
4783
4784 // get the form
4785 ob_start();
4786 uwp_get_template( 'bootstrap/login.php', $args );
4787 $form = ob_get_clean();
4788
4789 // bs5
4790 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4791 $form = aui_bs_convert_sd_output( $form );
4792 }
4793 // send ajax response
4794 wp_send_json_success( $form );
4795 }
4796
4797 /**
4798 * Get the ajax register form.
4799 *
4800 * @since 1.2.0
4801 */
4802 public function ajax_register_form() {
4803
4804 // add the modal error container
4805 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4806
4807 global $wp_scripts;
4808 if ( empty( $wp_scripts ) ) {
4809 $wp_scripts = wp_scripts();
4810 }
4811
4812 // do we need country code script in ajax?
4813 $country_field = false;
4814 $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
4815
4816 if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
4817 $form_id = (int)$_POST['form_id'];
4818 } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
4819 $form_id = reset( $lightbox_forms );
4820 } else {
4821 $form_id = 1;
4822 }
4823
4824 $fields = get_register_form_fields( $form_id );
4825 if ( ! empty( $fields ) ) {
4826 foreach ( $fields as $field ) {
4827 if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
4828 $country_field = true;
4829 }
4830 }
4831 }
4832
4833 ob_start();
4834
4835 // maybe add country code JS
4836 if ( $country_field ) {
4837 $country_data = uwp_get_country_data();
4838 echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
4839 echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
4840 }
4841
4842 $args = array( 'form_title' => '' );
4843 if ( $form_id > 0 ) {
4844 $args['id'] = $form_id;
4845 }
4846
4847 $args['limit'] = $lightbox_forms;
4848
4849 // get template
4850 uwp_get_template( 'bootstrap/register.php', $args );
4851
4852 // only show the JS if NOT doing a block render
4853 if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
4854 // load scripts
4855 $wp_scripts->do_item( 'zxcvbn-async' );
4856 $wp_scripts->do_item( 'wp-hooks' );
4857 $wp_scripts->do_item( 'wp-i18n' );
4858 $wp_scripts->do_item( 'password-strength-meter' );
4859 ?>
4860 <script>
4861 // Password strength indicator script
4862 jQuery(function ($) {
4863
4864 // Load the settings like WP does.
4865 var first, s;
4866 s = document.createElement('script');
4867 s.src = _zxcvbnSettings.src;
4868 s.type = 'text/javascript';
4869 s.async = true;
4870 first = document.getElementsByTagName('script')[0];
4871 first.parentNode.insertBefore(s, first);
4872
4873 // Enable any pass inputs.
4874 $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
4875 function (event) {
4876 var $form = $(this).closest('form');
4877 if( ! $form.hasClass('uwp-login-form') ) {
4878 uwp_checkPasswordStrength(
4879 $('input[name=password]', $form), // First password field
4880 $('input[name=confirm_password]', $form), // Second password field
4881 $('#uwp-password-strength', $form), // Strength meter
4882 $('input[type=submit]', $form), // Submit button
4883 ['black', 'listed', 'word'] // Blacklisted words
4884 );
4885 }
4886 }
4887 );
4888 });
4889 </script>
4890 <?php
4891 }
4892 $form = ob_get_clean();
4893
4894 // bs5
4895 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4896 $form = aui_bs_convert_sd_output( $form );
4897 }
4898
4899 // send ajax response
4900 wp_send_json_success( $form );
4901 }
4902
4903 /**
4904 * Get the ajax forgot password form.
4905 *
4906 * @since 1.2.0
4907 */
4908 public function ajax_forgot_password_form() {
4909
4910 // add the modal error container
4911 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
4912
4913 // get the form
4914 ob_start();
4915 uwp_get_template( 'bootstrap/forgot.php' );
4916 $form = ob_get_clean();
4917
4918 // bs5
4919 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
4920 $form = aui_bs_convert_sd_output( $form );
4921 }
4922
4923 // send ajax response
4924 wp_send_json_success( $form );
4925 }
4926
4927 /**
4928 * Output the modal error container.
4929 *
4930 * @param string $type
4931 *
4932 * @since 1.2.0
4933 */
4934 public function modal_error_container( $type = '' ) {
4935 echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
4936 }
4937
4938 public function form_custom_html( $html, $field, $value, $form_type ) {
4939
4940 $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
4941
4942 return $html;
4943 }
4944 }
4945