PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.73
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.73
1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.20 1.0.21 1.0.22 All 173 releases
userswp / includes / class-forms.php

class-forms.php in UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 1.2.73, at includes/class-forms.php

5,328 lines 183.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * Form related functions
5 *
6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
7 *
8 * @since 1.0.0
9 * @author GeoDirectory Team <info@wpgeodirectory.com>
10 */
11 class UsersWP_Forms {
12
13 protected $generated_password;
14
15 /**
16 * Logs the error message.
17 *
18 * @param array|object|string $log Error message.
19 *
20 * @return void
21 * @since 1.0.0
22 * @package userswp
23 *
24 */
25 public static function uwp_error_log( $log ) {
26 uwp_error_log( $log );
27 }
28
29 /**
30 * Initialize UsersWP notices.
31 *
32 * @return void
33 * @package userswp
34 *
35 * @since 1.0.0
36 */
37 public function init_notices() {
38 global $uwp_notices;
39 $uwp_notices = array();
40 }
41
42 /**
43 * Handles all UsersWP forms.
44 *
45 * @return void
46 * @package userswp
47 *
48 * @since 1.0.0
49 */
50 public function handler() {
51 global $uwp_notices;
52
53 ob_start();
54
55 $errors = null;
56 $message = null;
57 $redirect = false;
58 $processed = false;
59 $type = null;
60
61 if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 if ( ! is_wp_error( $errors ) ) {
64 $redirect = $errors;
65 }
66 $message = __( 'Avatar cropped successfully.', 'userswp' );
67 $processed = true;
68 } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 if ( ! is_wp_error( $errors ) ) {
71 $redirect = $errors;
72 }
73 $message = __( 'Banner cropped successfully.', 'userswp' );
74 $processed = true;
75 } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 if ( ! is_wp_error( $errors ) ) {
78 $redirect = $errors;
79 }
80 $message = __( 'Avatar cropped successfully.', 'userswp' );
81 $processed = true;
82 } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 $errors = $this->process_image_crop( $_POST, 'banner', true );
84 if ( ! is_wp_error( $errors ) ) {
85 $redirect = $errors;
86 }
87 $message = __( 'Banner cropped successfully.', 'userswp' );
88 $processed = true;
89 } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 $errors = $this->process_image_reset( 'avatar' );
91 if ( ! is_wp_error( $errors ) ) {
92 $redirect = $errors;
93 }
94 $message = __( 'Avatar reset successfully.', 'userswp' );
95 $processed = true;
96 } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 $errors = $this->process_image_reset( 'banner' );
98 if ( ! is_wp_error( $errors ) ) {
99 $redirect = $errors;
100 }
101 $message = __( 'Banner reset successfully.', 'userswp' );
102 $processed = true;
103 }
104
105 if ( $processed ) {
106 if ( is_wp_error( $errors ) ) {
107 aui()->alert(
108 array(
109 'type' => 'error',
110 'content' => wp_kses_post( $errors->get_error_message() )
111 ),
112 true
113 );
114 } else if ( $redirect ) {
115 wp_safe_redirect( $redirect );
116 exit();
117 } else {
118 aui()->alert(
119 array(
120 'type' => 'success',
121 'content' => wp_kses_post( $message )
122 ),
123 true
124 );
125 }
126 }
127
128 if ( $type ) {
129 $uwp_notices[] = array( $type => ob_get_contents() );
130 } else {
131 $uwp_notices[] = ob_get_contents();
132 }
133
134 ob_end_clean();
135 }
136
137 /**
138 * Processes avatar and banner uploads form submission.
139 *
140 * @param array $data Submitted $_POST data
141 * @param array $files Submitted $_FILES data
142 *
143 * @return bool|WP_Error|string File url to crop.
144 * @package userswp
145 *
146 * @since 1.0.0
147 */
148 public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
149
150 $file_obj = new UsersWP_Files();
151
152 $current_user_id = get_current_user_id();
153 if ( ! $current_user_id ) {
154 return false;
155 }
156
157 if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
158 return false;
159 }
160
161 do_action( 'uwp_before_validate', $type );
162
163 $result = $file_obj->validate_uploads( $files, $type );
164
165 $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
166
167 if ( is_wp_error( $result ) ) {
168 return $result;
169 }
170
171 $profile_url = uwp_build_profile_tab_url( $current_user_id );
172
173 $url = add_query_arg(
174 array(
175 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
176 'type' => $type,
177 ),
178 $profile_url
179 );
180
181 return $url;
182 }
183
184 /**
185 * Processes avatar and banner uploads image crop.
186 *
187 * @param array $data Submitted $_POST data
188 * @param string $type Image type. Default 'avatar'.
189 * @param bool $unlink_prev_img True to remove previous image. Default false;
190 *
191 * @return bool|WP_Error|string Profile url.
192 * @since 1.0.12 New param $unlink_prev_img introduced.
193 * @package userswp
194 *
195 * @since 1.0.0
196 */
197 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 global $wpdb;
199
200 if ( ! is_user_logged_in() ) {
201 return false;
202 }
203
204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 return;
206 }
207
208 $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209
210 if ( empty( $image_url ) ) {
211 return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 }
213
214 // Ensure we have a valid URL with an allowed meme type.
215 $image_url = $this->normalize_url( $image_url );
216
217 $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 }
222
223 $filetype = wp_check_filetype( $image_url );
224
225 if ( empty( $filetype['ext'] ) ) {
226 return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
227 }
228
229 // If is current user's profile (profile.php)
230 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
231 $user_id = get_current_user_id();
232 // If is another user's profile page
233 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
234 $user_id = absint( $_GET['user_id'] );
235 // Otherwise something is wrong.
236 } else {
237 $user_id = get_current_user_id();
238 }
239
240 // Retrieve current thumbnail.
241 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
242 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
243 $thumb_postfix = '_uwp_' . $type . '_thumb';
244
245 if ( $image_url ) {
246 if ( $type == 'avatar' ) {
247 $avatar_size = uwp_get_upload_image_size();
248 $full_width = $avatar_size['width'];
249 } else {
250 $banner_size = uwp_get_upload_image_size( 'banner' );
251 $full_width = $banner_size['width'];
252 }
253
254 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
255 $uploads = wp_upload_dir();
256 remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
257 $upload_url = $uploads['baseurl'];
258 $upload_path = $uploads['basedir'];
259 $image_path = str_replace( $upload_url, $upload_path, $image_url );
260 $ext = $filetype['ext']; // to get extension
261 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
262 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
263 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
264
265 //Get the new coordinates to crop the image.
266 $x = $data['uwpx'];
267 $y = $data['uwpy'];
268 $w = $data['uwpw'];
269 $h = $data['uwph'];
270 //Scale the image based on cropped width setting
271 $scale = $full_width / $w;
272 //$scale = 1; // no scaling
273
274 // check we are not editing another user file
275 $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
276 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
277 $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
278
279 // if file already exists then we should not be cropping it.
280 if ( $file_exists ) {
281 wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
282 }
283
284 $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
285 $cropped = str_replace( $upload_path, $upload_url, $cropped );
286
287 // Remove previous avatar/banner
288 $unlink_img = '';
289 if ( $unlink_prev_img && $current_thumbnail ) {
290 $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
291 }
292
293 // remove the uploads path for easy migrations
294 $cropped = str_replace( $upload_url, '', $cropped );
295 if ( $type == 'avatar' ) {
296 uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
297 } else {
298 uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
299 }
300
301 if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
302 @unlink( $unlink_img );
303 $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
304 if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
305 @unlink( $unlink_ori_img );
306 }
307 }
308 }
309
310 if ( is_admin() ) {
311 if ( $user_id == get_current_user_id() ) {
312 $redirect_url = admin_url( 'profile.php' );
313 } else {
314 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
315 }
316 } elseif ( uwp_current_page_url() ) {
317 $redirect_url = uwp_current_page_url();
318 } else {
319 $redirect_url = uwp_build_profile_tab_url( $user_id );
320 }
321
322 return $redirect_url;
323 }
324
325 /**
326 * Normalizes a URL.
327 *
328 */
329 public function normalize_url( $url ) {
330
331 if ( empty( $url ) ) {
332 return '';
333 }
334 // Normalize.
335 $url = wp_normalize_path( $url );
336
337 // Remove query vars.
338 $url = strtok( $url, '?' );
339
340 // Split.
341 $url = explode( '/', $url );
342
343 // Clean.
344 $url = array_diff( $url, array( '..', '.' ) );
345
346 // Rejoin and return.
347 return implode( '/', $url );
348 }
349
350 /**
351 * Processes avatar and banner image reset.
352 *
353 * @param string $type Image type. Default 'avatar'.
354 *
355 * @return bool|WP_Error|string Profile url.
356 * @package userswp
357 *
358 */
359 public function process_image_reset( $type ) {
360 if ( ! is_user_logged_in() ) {
361 return false;
362 }
363
364 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
365 $user_id = get_current_user_id();
366 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
367 $user_id = absint( $_GET['user_id'] );
368 } else {
369 $user_id = get_current_user_id();
370 }
371
372 if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) {
373 return;
374 }
375
376 $errors = new WP_Error();
377 if ( empty( $user_id ) ) {
378 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
379 }
380
381 $error_code = $errors->get_error_code();
382 if ( ! empty( $error_code ) ) {
383 return $errors;
384 }
385
386 if ( $type == 'avatar' ) {
387 uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
388 } elseif ( $type == 'banner' ) {
389 uwp_update_usermeta( $user_id, 'banner_thumb', '' );
390 } else {
391 // Do nothing
392 }
393
394 if ( is_admin() ) {
395 if ( $user_id == get_current_user_id() ) {
396 $redirect_url = admin_url( 'profile.php' );
397 } else {
398 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
399 }
400 } elseif ( uwp_current_page_url() ) {
401 $redirect_url = uwp_current_page_url();
402 } else {
403 $redirect_url = uwp_build_profile_tab_url( $user_id );
404 }
405
406 return $redirect_url;
407 }
408
409 /**
410 * Displays links in a dropdown
411 *
412 * @param $options
413 *
414 * @package userswp
415 *
416 * @since 1.0.0
417 */
418 public function output_dashboard_links( $options ) {
419 if ( ! empty( $options ) ) {
420 $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
421 echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
422 $this->output_options( $options );
423 echo '</select>';
424 }
425 }
426
427 /**
428 * Displays options for the dashboard links
429 *
430 * @param $options
431 *
432 * @package userswp
433 *
434 * @since 1.0.0
435 */
436 public function output_options( $options ) {
437 if ( ! empty( $options ) ) {
438 foreach ( $options as $key => $link ) {
439
440 if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
441 $this->output_options( $link );
442 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
443 echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
444 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
445 echo '</optgroup>';
446 } elseif ( ! empty( $link['text'] ) ) {
447 echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
448 echo esc_attr__( $link['text'], 'userswp' );
449 echo '</option>';
450 }
451 }
452 }
453 }
454
455 /**
456 * Displays UsersWP notices in forms.
457 *
458 * @param string $type Form type
459 *
460 * @return void
461 * @since 1.0.0
462 * @package userswp
463 *
464 */
465 public function display_notices( $type ) {
466 global $uwp_notices;
467
468 if ( is_array( $uwp_notices ) ) {
469 foreach ( $uwp_notices as $notice ) {
470
471 // If the notification is type specific then only output on that type
472 if ( is_array( $notice ) ) {
473 foreach ( $notice as $key => $val ) {
474 if ( $key == $type ) {
475 echo wp_kses_post( $val );
476 }
477 }
478 } elseif ( ! empty( $notice ) ) {
479 echo wp_kses_post( $notice );
480 }
481 }
482 }
483
484 if ( $type == 'change' ) {
485 $user_id = get_current_user_id();
486 $password_nag = get_user_option( 'default_password_nag', $user_id );
487
488 if ( $password_nag ) {
489 $change_page = uwp_get_page_id( 'change_page', false );
490 $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
491
492 if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
493 delete_user_meta( $user_id, 'default_password_nag' );
494 $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
495 echo aui()->alert(
496 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
497 'class' => 'text-center',
498 'type' => 'success',
499 'content' => wp_kses_post( $message ),
500 )
501 );
502 } else {
503 $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
504 echo aui()->alert(
505 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
506 'class' => 'text-center',
507 'type' => 'warning',
508 'content' => wp_kses_post( $message ),
509 )
510 );
511 }
512 }
513 }
514 }
515
516 /**
517 * Processes register form submission.
518 *
519 * @since 1.0.0
520 * @package userswp
521 *
522 */
523 public function process_register() {
524
525 $data = $_POST;
526
527 if ( ! isset( $data['uwp_register_nonce'] ) ) {
528 return;
529 }
530
531 global $uwp_notices;
532
533 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
534 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
535 }
536
537 $form_id = 1;
538
539 if ( ! empty( $data['uwp_register_form_id'] ) ) {
540 $form_id = (int) $data['uwp_register_form_id'];
541 }
542
543 if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
544 $message = aui()->alert(
545 array(
546 'type' => 'error',
547 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
548 )
549 );
550 if ( wp_doing_ajax() ) {
551 wp_send_json_error( array( 'message' => $message ) );
552 } else {
553 $uwp_notices[] = array( 'register' => $message );
554
555 return;
556 }
557 }
558
559 $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
560 if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
561 $message = aui()->alert(
562 array(
563 'type' => 'error',
564 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
565 )
566 );
567 if ( wp_doing_ajax() ) {
568 wp_send_json_error( array( 'message' => $message ) );
569 } else {
570 $uwp_notices[] = array( 'register' => $message );
571
572 return;
573 }
574 }
575
576 if ( ! get_option( 'users_can_register' ) ) {
577 $message = aui()->alert(
578 array(
579 'type' => 'error',
580 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
581 )
582 );
583 if ( wp_doing_ajax() ) {
584 wp_send_json_error( array( 'message' => $message ) );
585 } else {
586 $uwp_notices[] = array( 'register' => $message );
587
588 return;
589 }
590 }
591
592 $files = $_FILES;
593 $errors = new WP_Error();
594 $file_obj = new UsersWP_Files();
595
596 do_action( 'uwp_before_validate', 'register' );
597
598 $result = uwp_validate_fields( $data, 'register' );
599
600 $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
601
602 if ( is_wp_error( $result ) ) {
603 $message = aui()->alert(
604 array(
605 'type' => 'error',
606 'content' => $result->get_error_message(),
607 )
608 );
609 if ( wp_doing_ajax() ) {
610 wp_send_json_error( array( 'message' => $message ) );
611 } else {
612 $uwp_notices[] = array( 'register' => $message );
613
614 return;
615 }
616 }
617
618 $uploads_result = $file_obj->validate_uploads( $files, 'register' );
619
620 if ( is_wp_error( $uploads_result ) ) {
621 $message = aui()->alert(
622 array(
623 'type' => 'error',
624 'content' => $uploads_result->get_error_message(),
625 )
626 );
627 if ( wp_doing_ajax() ) {
628 wp_send_json_error( array( 'message' => $message ) );
629 } else {
630 $uwp_notices[] = array( 'register' => $message );
631
632 return;
633 }
634 }
635
636 do_action( 'uwp_after_validate', $result, 'register', $data );
637
638 $result = array_merge( $result, $uploads_result );
639
640 if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
641 $password = $result['password'];
642 $generated_password = false;
643 } else {
644 $password = wp_generate_password();
645 $this->generated_password = $password;
646 $generated_password = true;
647 }
648
649 $first_name = '';
650 if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
651 $first_name = $result['first_name'];
652 }
653
654 $last_name = '';
655 if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
656 $last_name = $result['last_name'];
657 }
658
659 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
660 $display_name = $result['display_name'];
661 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
662 $display_name = $first_name . ' ' . $last_name;
663 } else {
664 $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
665 }
666
667 $user_url = '';
668 if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
669 $user_url = esc_url_raw( $result['user_url'] );
670 }
671
672 $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
673 $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
674
675 if ( empty( $user_login ) ) {
676 $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
677 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
678 $new_user_login = strstr( $email, '@', true );
679 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
680 $user_login = sanitize_user( $new_user_login, true );
681 }
682 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
683 $user_append_text = rand( 10, 1000 );
684 $user_login = sanitize_user( $new_user_login . $user_append_text, true );
685 }
686
687 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
688 $user_login = $email;
689 }
690 }
691 } elseif ( ! validate_username( $user_login ) ) {
692 $message = aui()->alert(
693 array(
694 'type' => 'error',
695 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
696 )
697 );
698 if ( wp_doing_ajax() ) {
699 wp_send_json_error( array( 'message' => $message ) );
700 } else {
701 $uwp_notices[] = array( 'register' => $message );
702
703 return;
704 }
705 }
706
707 $args = array(
708 'user_login' => sanitize_user( $user_login ),
709 'user_email' => sanitize_email( $email ),
710 'user_pass' => $password,
711 'display_name' => sanitize_text_field( $display_name ),
712 'first_name' => esc_attr( $first_name ),
713 'last_name' => esc_attr( $last_name ),
714 'user_url' => esc_url_raw( $user_url ),
715 );
716
717 // Set user role by form.
718 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
719
720 if ( ! empty( $user_role ) ) {
721 $user_roles = uwp_get_user_roles();
722 $chosen_role = strtolower( $user_role );
723
724 if ( ! empty( $user_roles ) ) {
725 $wp_roles = wp_roles();
726
727 if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
728 $args['role'] = $chosen_role;
729 }
730 }
731 }
732
733 $user_id = wp_insert_user( $args );
734
735 if ( is_wp_error( $user_id ) ) {
736 $message = aui()->alert(
737 array(
738 'type' => 'error',
739 'content' => $user_id->get_error_message(),
740 )
741 );
742 if ( wp_doing_ajax() ) {
743 wp_send_json_error( array( 'message' => $message ) );
744 } else {
745 $uwp_notices[] = array( 'register' => $message );
746
747 return;
748 }
749 }
750
751 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
752
753 // Save user form id.
754 if ( ! empty( $data['uwp_register_form_id'] ) ) {
755 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
756 }
757
758 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
759
760 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
761
762 if ( is_wp_error( $save_result ) ) {
763 $message = aui()->alert(
764 array(
765 'type' => 'error',
766 'content' => $save_result->get_error_message(),
767 )
768 );
769 if ( wp_doing_ajax() ) {
770 wp_send_json_error( array( 'message' => $message ) );
771 } else {
772 $uwp_notices[] = array( 'register' => $message );
773
774 return;
775 }
776 }
777
778 if ( ! $save_result ) {
779 $message = aui()->alert(
780 array(
781 'type' => 'error',
782 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
783 )
784 );
785 if ( wp_doing_ajax() ) {
786 wp_send_json_error( array( 'message' => $message ) );
787 } else {
788 $uwp_notices[] = array( 'register' => $message );
789
790 return;
791 }
792 }
793
794 //updating bio field after saving extra fields to reflect the points in mycred add on.
795 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
796 $args = array(
797 'ID' => $user_id,
798 'description' => $result['bio'],
799 );
800 wp_update_user( $args );
801 }
802
803 do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
804
805 // Unset post data to empty the form on submit
806 $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
807 foreach ( $data as $key => $value ) {
808 if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
809 unset( $_POST[ $key ] );
810 }
811 }
812
813 $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
814 if ( ! $reg_action ) {
815 $reg_action = uwp_get_option( 'uwp_registration_action', false );
816 }
817
818 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
819
820 if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
821
822 $user_data = get_userdata( $user_id );
823 $activation_link = uwp_get_activation_link( $user_id );
824
825 $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
826
827 $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
828
829 $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
830
831 $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
832
833 $email_vars = array(
834 'user_id' => $user_id,
835 'login_details' => $activate_message,
836 'activation_link' => $activation_link,
837 );
838
839 UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
840
841 } elseif ( $reg_action != 'require_admin_review' ) {
842
843 $user_data = get_userdata( $user_id );
844
845 if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
846 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
847 update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
848 }
849 $message_pass = $this->generated_password;
850 $this->generated_password = false;
851 } else {
852 $message_pass = __( 'Password you entered during registration.', 'userswp' );
853 }
854
855 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
856 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
857 <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
858
859 $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
860
861 $email_vars = array(
862 'user_id' => $user_id,
863 'login_details' => $message,
864 'form_fields' => $form_fields,
865 );
866
867 UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
868 }
869
870 $error_code = $errors->get_error_code();
871 if ( ! empty( $error_code ) ) {
872 $message = aui()->alert(
873 array(
874 'type' => 'error',
875 'content' => $result->get_error_message(),
876 )
877 );
878 if ( wp_doing_ajax() ) {
879 wp_send_json_error( array( 'message' => $message ) );
880 } else {
881 $uwp_notices[] = array( 'register' => $message );
882 return;
883 }
884 }
885
886 if ( $reg_action != 'require_admin_review' ) {
887
888 $user_data = get_userdata( $user_id );
889 $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
890 <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
891 <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
892 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
893 <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
894
895 $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
896
897 $email_vars = array(
898 'user_id' => $user_id,
899 'extras' => $extras,
900 'form_fields' => $form_fields,
901 );
902
903 UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
904
905 }
906
907 if ( $reg_action == 'auto_approve_login' ) {
908 $res = wp_signon(
909 array(
910 'user_login' => $user_login,
911 'user_password' => $password,
912 'remember' => false,
913 )
914 );
915
916 if ( is_wp_error( $res ) ) {
917 $message = aui()->alert(
918 array(
919 'type' => 'error',
920 'content' => $res->get_error_message(),
921 )
922 );
923
924 if ( wp_doing_ajax() ) {
925 wp_send_json_error( array( 'message' => $message ) );
926 } else {
927 $uwp_notices[] = array( 'register' => $message );
928 }
929 } else {
930 $redirect_to = $this->get_register_redirect_url( $data, $user_id );
931 do_action( 'uwp_after_process_register', $result, $user_id );
932
933 if ( wp_doing_ajax() ) {
934 $message = aui()->alert(
935 array(
936 'type' => 'success',
937 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
938 )
939 );
940 $response = array(
941 'message' => $message,
942 'redirect' => $redirect_to,
943 );
944 wp_send_json_success( $response );
945 } else {
946 wp_safe_redirect( $redirect_to );
947 }
948 exit();
949 }
950 } else {
951 if ( $reg_action == 'require_email_activation' ) {
952 $resend_link = uwp_get_register_page_url();
953 $resend_link = add_query_arg(
954 array(
955 'user_id' => $user_id,
956 'action' => 'uwp_resend',
957 '_nonce' => wp_create_nonce( 'uwp_resend' ),
958 ),
959 $resend_link
960 );
961
962 $message = aui()->alert(
963 array(
964 'type' => 'success',
965 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
966 )
967 );
968
969 } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
970
971 update_user_meta( $user_id, 'uwp_mod', '1' );
972
973 do_action( 'uwp_require_admin_review', $user_id, $result );
974
975 $message = aui()->alert(
976 array(
977 'type' => 'success',
978 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
979 )
980 );
981 } else {
982
983 $login_page_url = wp_login_url();
984
985 if ( $generated_password ) {
986 $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
987 } else {
988 $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
989 }
990
991 $message = aui()->alert(
992 array(
993 'type' => 'success',
994 'content' => $msg,
995 )
996 );
997 }
998
999 do_action( 'uwp_after_process_register', $result, $user_id );
1000
1001 if ( wp_doing_ajax() ) {
1002 wp_send_json_success( array( 'message' => $message ) );
1003 } else {
1004 $uwp_notices[] = array( 'register' => $message );
1005 }
1006 }
1007
1008 if ( wp_doing_ajax() ) {
1009 wp_send_json_error();
1010 } // if we got this far there is a problem
1011 }
1012
1013 /**
1014 * Saves UsersWP related user custom fields.
1015 *
1016 * @param int $user_id User ID.
1017 * @param array $data Result array.
1018 * @param string $type Form type.
1019 *
1020 * @return bool True when success. False when failure.
1021 * @since 1.0.0
1022 * @package userswp
1023 *
1024 */
1025 public function save_user_extra_fields( $user_id, $data, $type ) {
1026
1027 if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1028 return false;
1029 }
1030
1031 // custom user fields not applicable for login and forgot
1032 if ( $type == 'login' || $type == 'forgot' ) {
1033 return true;
1034 }
1035
1036 if ( $type == 'account' || $type == 'register' ) {
1037 if ( isset( $data['password'] ) ) {
1038 unset( $data['password'] );
1039 }
1040 }
1041
1042 if ( $type == 'register' ) {
1043 if ( isset( $data['username'] ) ) {
1044 unset( $data['username'] );
1045 }
1046 if ( isset( $data['email'] ) ) {
1047 unset( $data['email'] );
1048 }
1049 }
1050
1051 if ( empty( $data ) ) {
1052 // no extra fields. so just return
1053 return true;
1054 } else {
1055 foreach ( $data as $key => $value ) {
1056 if ( 'uwp_language' == $key ) {
1057 update_user_meta( $user_id, 'locale', $value );
1058 }
1059 uwp_update_usermeta( $user_id, $key, $value );
1060 }
1061
1062 return true;
1063 }
1064 }
1065
1066 public function get_register_redirect_url( $data, $user ) {
1067 if ( is_int( $user ) ) {
1068 $user = get_userdata( $user );
1069 }
1070
1071 $redirect_page_id = $custom_url = '';
1072 if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1073 $form_id = (int) $data['uwp_register_form_id'];
1074 $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1075 $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1076 }
1077
1078 if ( ! $redirect_page_id ) {
1079 $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1080 $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1081 }
1082
1083 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1084 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1085 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1086 $redirect_to = esc_url_raw( $data['redirect_to'] );
1087 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1088 if ( uwp_is_wpml() ) {
1089 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1090 if ( ! empty( $wpml_page_id ) ) {
1091 $redirect_page_id = $wpml_page_id;
1092 }
1093 }
1094 $redirect_to = get_permalink( $redirect_page_id );
1095 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1096 $redirect_to = esc_url( wp_get_referer() );
1097 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1098 $redirect_to = $custom_url;
1099 } else {
1100 if ( $user && $user->has_cap( 'manage_options' ) ) {
1101 $redirect_to = admin_url();
1102 } else {
1103 $redirect_to = home_url( '/' );
1104 }
1105
1106 $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1107 }
1108
1109 return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1110 }
1111
1112 /**
1113 * Processes login form submission.
1114 *
1115 * @since 1.0.0
1116 * @package userswp
1117 *
1118 */
1119 public function process_login() {
1120
1121 $data = $_POST;
1122
1123 if ( ! isset( $data['uwp_login_nonce'] ) ) {
1124 return;
1125 }
1126
1127 if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1128 $message = aui()->alert(
1129 array(
1130 'type' => 'error',
1131 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1132 )
1133 );
1134 if ( wp_doing_ajax() ) {
1135 wp_send_json_error( array( 'message' => $message ) );
1136 } else {
1137 return;
1138 }
1139 }
1140
1141 global $uwp_notices;
1142
1143 do_action( 'uwp_before_validate', 'login' );
1144
1145 $result = uwp_validate_fields( $data, 'login' );
1146
1147 $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1148
1149 if ( is_wp_error( $result ) ) {
1150 $message = aui()->alert(
1151 array(
1152 'type' => 'error',
1153 'content' => $result->get_error_message(),
1154 )
1155 );
1156 if ( wp_doing_ajax() ) {
1157 wp_send_json_error( array( 'message' => $message ) );
1158 } else {
1159 $uwp_notices[] = array( 'login' => $message );
1160
1161 return;
1162 }
1163 }
1164
1165 do_action( 'uwp_after_validate', $result, 'login', $data );
1166
1167 if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1168 $remember_me = true;
1169 } else {
1170 $remember_me = false;
1171 }
1172
1173 remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1174
1175 global $wp2fa;
1176 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1177 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1178 }
1179 if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1180 remove_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20 );
1181 }
1182
1183 $user = wp_signon(
1184 array(
1185 'user_login' => $result['username'],
1186 'user_password' => $result['password'],
1187 'remember' => $remember_me,
1188 )
1189 );
1190
1191 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1192 if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1193 add_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20, 2 );
1194 }
1195
1196 $wp2fa_available = ( isset( $wp2fa ) && ! empty( $wp2fa ) ) || class_exists( '\WP2FA\Authenticator\Login' );
1197 if ( wp_doing_ajax() && ! is_wp_error( $user ) && $wp2fa_available ) {
1198
1199 $two_fa = $this->check_2fa( $user );
1200 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1201 if ( is_wp_error( $two_fa ) ) {
1202 $message = aui()->alert(
1203 array(
1204 'type' => 'error',
1205 'content' => $two_fa->get_error_message(),
1206 )
1207 );
1208 wp_send_json_error( array( 'message' => $message ) );
1209 } else {
1210 wp_send_json_success(
1211 array(
1212 'html' => $two_fa,
1213 'is_2fa' => true,
1214 )
1215 );
1216 }
1217 }
1218 }
1219
1220 if ( wp_doing_ajax() && is_wp_error( $user ) && $this->wordfence_2fa_available() ) {
1221 $wfls_2fa = $this->check_wordfence_2fa( $user, $result );
1222 if ( ! empty( $wfls_2fa ) ) {
1223 wp_send_json_success(
1224 array(
1225 'html' => $wfls_2fa,
1226 'is_2fa' => true,
1227 )
1228 );
1229 }
1230 }
1231
1232 if ( is_wp_error( $user ) ) {
1233 $message = aui()->alert(
1234 array(
1235 'type' => 'error',
1236 'content' => $user->get_error_message(),
1237 )
1238 );
1239 if ( wp_doing_ajax() ) {
1240 wp_send_json_error( array( 'message' => $message ) );
1241 } else {
1242 $uwp_notices[] = array( 'login' => $message );
1243
1244 return;
1245 }
1246 } else {
1247 do_action( 'uwp_after_process_login', $data );
1248 $message = aui()->alert(
1249 array(
1250 'type' => 'success',
1251 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1252 )
1253 );
1254 if ( wp_doing_ajax() ) {
1255 $redirect_to = '';
1256 if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1257 $redirect_to = $this->get_login_redirect_url( $data, $user );
1258 }
1259 wp_send_json_success(
1260 array(
1261 'message' => $message,
1262 'redirect' => $redirect_to,
1263 )
1264 );
1265 } else {
1266 $redirect_to = $this->get_login_redirect_url( $data, $user );
1267 wp_safe_redirect( $redirect_to );
1268 exit();
1269 }
1270 }
1271 }
1272
1273 public function check_2fa( $user ) {
1274 if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1275 return;
1276 }
1277
1278 if ( ! $user ) {
1279 $user = wp_get_current_user();
1280 }
1281
1282 global $wp2fa;
1283 $errors = new WP_Error();
1284
1285 if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1286 return;
1287 }
1288 // Invalidate the current login session to prevent from being re-used.
1289 \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1290
1291 // Also clear the cookies which are no longer valid.
1292 wp_clear_auth_cookie();
1293
1294 $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1295 if ( ! $login_nonce ) {
1296 $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1297
1298 return $errors;
1299 }
1300
1301 $provider = $this->get_wp2fa_provider_for_user( $user );
1302 if ( empty( $provider ) ) {
1303 return;
1304 }
1305
1306 ob_start();
1307 ?>
1308
1309 <div class="uwp-2fa-methods-wrap">
1310 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1311 autocomplete="off">
1312 <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1313 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1314 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1315 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1316 <?php
1317
1318 // Check to see what provider is set and give the relevant authentication page.
1319 if ( 'totp' === $provider ) {
1320 ?>
1321 <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1322 <?php
1323
1324 echo aui()->input(
1325 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1326 'type' => 'tel',
1327 'id' => 'authcode',
1328 'name' => 'authcode',
1329 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1330 'value' => '',
1331 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1332 )
1333 );
1334
1335 echo aui()->button(
1336 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1337 'type' => 'submit',
1338 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1339 'name' => 'submit',
1340 'icon' => '',
1341 'content' => esc_html__( 'Log In', 'userswp' ),
1342 )
1343 );
1344
1345 } elseif ( 'email' === $provider ) {
1346 $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1347 if ( empty( $has_token ) || ! $has_token ) {
1348 \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1349 }
1350 ?>
1351 <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1352 <?php
1353 echo aui()->input(
1354 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1355 'type' => 'tel',
1356 'id' => 'authcode',
1357 'name' => 'authcode',
1358 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1359 'value' => '',
1360 'label' => esc_html__( 'Verification Code', 'userswp' ),
1361 'extra_attributes' => array(
1362 'size' => 20,
1363 'pattern' => '[0-9]*',
1364 ),
1365 )
1366 );
1367
1368 echo aui()->button(
1369 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1370 'type' => 'submit',
1371 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1372 'name' => 'submit',
1373 'icon' => '',
1374 'content' => esc_html__( 'Log In', 'userswp' ),
1375 )
1376 );
1377
1378 echo aui()->button(
1379 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1380 'type' => 'button',
1381 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1382 'name' => 'wp-2fa-email-code-resend',
1383 'icon' => '',
1384 'content' => esc_html__( 'Resend Code', 'userswp' ),
1385 )
1386 );
1387
1388 }
1389 ?>
1390 </form>
1391 </div>
1392
1393 <?php
1394 $codes_remaining = $this->get_wp2fa_backup_codes_remaining( $user );
1395 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1396 ?>
1397 <div class="uwp-2fa-methods-wrap" style="display:none;">
1398 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1399 class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1400 <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1401 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1402 value="<?php echo esc_attr( $user->ID ); ?>"/>
1403 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1404 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1405 <div class="uwp-backup-fields">
1406 <?php
1407 echo aui()->input(
1408 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1409 'type' => 'tel',
1410 'id' => 'authcode',
1411 'name' => 'wp-2fa-backup-code',
1412 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1413 'value' => '',
1414 'label' => esc_html__( 'Backup Code', 'userswp' ),
1415 'extra_attributes' => array(
1416 'size' => 20,
1417 'pattern' => '[0-9]*',
1418 ),
1419 )
1420 );
1421
1422 echo aui()->button(
1423 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1424 'type' => 'submit',
1425 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1426 'name' => 'submit',
1427 'icon' => '',
1428 'content' => esc_html__( 'Log In', 'userswp' ),
1429 )
1430 );
1431 ?>
1432 </div>
1433 </form>
1434 </div>
1435 <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1436 <script type="text/javascript">
1437 jQuery('.uwp-switch-2fa-methods').on('click',
1438 function (e) {
1439 e.preventDefault();
1440 jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1441 jQuery('.uwp-2fa-methods-wrap').toggle();
1442 return false;
1443 }
1444 );
1445 </script>
1446 <?php
1447 }
1448
1449 return ob_get_clean();
1450 }
1451
1452 /**
1453 * Checks if the Wordfence Login Security module (2FA) is available.
1454 *
1455 * @since 1.2.5
1456 * @package userswp
1457 *
1458 * @return bool
1459 */
1460 public function wordfence_2fa_available() {
1461 return class_exists( '\WordfenceLS\Controller_Users' ) && class_exists( '\WordfenceLS\Controller_TOTP' );
1462 }
1463
1464 /**
1465 * Checks whether Wordfence's 2FA requires a verification code for the
1466 * failed login attempt and, if so, returns the markup for the code entry form.
1467 *
1468 * @since 1.2.5
1469 * @package userswp
1470 *
1471 * @param WP_Error $error The error returned by wp_signon().
1472 * @param array $result The validated login fields (username/password).
1473 *
1474 * @return string|void The 2FA form markup, or nothing if not applicable.
1475 */
1476 public function check_wordfence_2fa( $error, $result ) {
1477 if ( 1 == uwp_get_option( 'disable_wordfence_2fa' ) ) {
1478 return;
1479 }
1480
1481 if ( ! $this->wordfence_2fa_available() ) {
1482 return;
1483 }
1484
1485 if ( ! is_wp_error( $error ) || 'wfls_twofactor_required' !== $error->get_error_code() ) {
1486 return;
1487 }
1488
1489 $username = ! empty( $result['username'] ) ? $result['username'] : '';
1490 if ( empty( $username ) ) {
1491 return;
1492 }
1493
1494 $user = is_email( $username ) ? get_user_by( 'email', $username ) : get_user_by( 'login', $username );
1495 if ( ! $user ) {
1496 return;
1497 }
1498
1499 if ( ! \WordfenceLS\Controller_Users::shared()->has_2fa_active( $user ) ) {
1500 return;
1501 }
1502
1503 if ( \WordfenceLS\Controller_Users::shared()->has_remembered_2fa( $user ) ) {
1504 return;
1505 }
1506
1507 $login_nonce = wp_create_nonce( 'uwp-wfls-2fa-' . $user->ID );
1508
1509 ob_start();
1510 ?>
1511
1512 <div class="uwp-2fa-methods-wrap">
1513 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1514 autocomplete="off">
1515 <input type="hidden" name="provider" id="provider" value="wordfence"/>
1516 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1517 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1518 value="<?php echo esc_attr( $login_nonce ); ?>"/>
1519
1520 <p><?php esc_html_e( 'Please enter the authentication code from your two-factor authentication app, or a recovery code, to login:', 'userswp' ); ?></p>
1521
1522 <?php
1523 echo aui()->input(
1524 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1525 'type' => 'text',
1526 'id' => 'authcode',
1527 'name' => 'authcode',
1528 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1529 'value' => '',
1530 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1531 'extra_attributes' => array(
1532 'autocomplete' => 'one-time-code',
1533 ),
1534 )
1535 );
1536
1537 echo aui()->button(
1538 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1539 'type' => 'submit',
1540 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1541 'name' => 'submit',
1542 'icon' => '',
1543 'content' => esc_html__( 'Log In', 'userswp' ),
1544 )
1545 );
1546 ?>
1547 </form>
1548 </div>
1549
1550 <?php
1551 return ob_get_clean();
1552 }
1553
1554 public function get_wp2fa_provider_for_user( $user ) {
1555 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'get_available_providers_for_user' ) ) {
1556 $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1557 if ( is_array( $provider ) ) {
1558 $provider = key( $provider );
1559 }
1560
1561 return $provider;
1562 }
1563
1564 if ( class_exists( '\WP2FA\Admin\Helpers\User_Helper' ) && method_exists( '\WP2FA\Admin\Helpers\User_Helper', 'get_enabled_method_for_user' ) ) {
1565 return \WP2FA\Admin\Helpers\User_Helper::get_enabled_method_for_user( $user );
1566 }
1567
1568 return '';
1569 }
1570
1571 public function get_wp2fa_backup_codes_remaining( $user ) {
1572 if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'codes_remaining_for_user' ) ) {
1573 return \WP2FA\Methods\Backup_Codes::codes_remaining_for_user( $user );
1574 }
1575
1576 if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'codes_remaining_for_user' ) ) {
1577 return \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1578 }
1579
1580 return 0;
1581 }
1582
1583 public function validate_wp2fa_totp_authentication( $user ) {
1584 if ( class_exists( '\WP2FA\Methods\TOTP' ) && method_exists( '\WP2FA\Methods\TOTP', 'validate_totp_authentication' ) ) {
1585 return \WP2FA\Methods\TOTP::validate_totp_authentication( $user );
1586 }
1587
1588 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_totp_authentication' ) ) {
1589 return \WP2FA\Authenticator\Login::validate_totp_authentication( $user );
1590 }
1591
1592 return false;
1593 }
1594
1595 public function validate_wp2fa_email_authentication( $user ) {
1596 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_email_authentication' ) ) {
1597 return \WP2FA\Authenticator\Login::validate_email_authentication( $user );
1598 }
1599
1600 if ( class_exists( '\WP2FA\Authenticator\Authentication' ) && method_exists( '\WP2FA\Authenticator\Authentication', 'validate_token' ) && isset( $_REQUEST['authcode'] ) ) {
1601 return \WP2FA\Authenticator\Authentication::validate_token( $user, sanitize_text_field( wp_unslash( $_REQUEST['authcode'] ) ) );
1602 }
1603
1604 return false;
1605 }
1606
1607 public function validate_wp2fa_backup_codes( $user ) {
1608 if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'validate_backup_codes' ) ) {
1609 return \WP2FA\Methods\Backup_Codes::validate_backup_codes( $user );
1610 }
1611
1612 if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'validate_backup_codes' ) ) {
1613 return \WP2FA\Authenticator\Backup_Codes::validate_backup_codes( $user );
1614 }
1615
1616 return false;
1617 }
1618
1619 /**
1620 * Validates the Wordfence 2FA code submitted from the uwp-2fa form and,
1621 * if valid, completes the login by setting the auth cookie.
1622 *
1623 * @since 1.2.5
1624 * @package userswp
1625 *
1626 * @param WP_User $user The user attempting to complete 2FA login.
1627 *
1628 * @return void
1629 */
1630 public function process_login_wordfence_2fa( $user ) {
1631 if ( ! $this->wordfence_2fa_available() ) {
1632 $message = aui()->alert(
1633 array(
1634 'type' => 'error',
1635 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1636 )
1637 );
1638
1639 wp_send_json_error( array( 'message' => $message ) );
1640 }
1641
1642 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1643
1644 if ( ! wp_verify_nonce( $nonce, 'uwp-wfls-2fa-' . $user->ID ) ) {
1645 $message = aui()->alert(
1646 array(
1647 'type' => 'error',
1648 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1649 )
1650 );
1651
1652 wp_send_json_error( array( 'message' => $message ) );
1653 }
1654
1655 $code = isset( $_POST['authcode'] ) ? sanitize_text_field( wp_unslash( $_POST['authcode'] ) ) : '';
1656
1657 if ( empty( $code ) || true !== \WordfenceLS\Controller_TOTP::shared()->validate_2fa( $user, $code ) ) {
1658 do_action( 'wp_login_failed', $user->user_login );
1659
1660 $message = aui()->alert(
1661 array(
1662 'type' => 'error',
1663 'content' => __( 'Invalid verification code.', 'userswp' ),
1664 )
1665 );
1666
1667 wp_send_json_error( array( 'message' => $message ) );
1668 }
1669
1670 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : false;
1671
1672 // Complete the login the same way wp_signon() would have, now that 2FA has been verified.
1673 wp_set_auth_cookie( $user->ID, $remember );
1674 wp_set_current_user( $user->ID );
1675
1676 do_action( 'wp_login', $user->user_login, $user );
1677
1678 $message = aui()->alert(
1679 array(
1680 'type' => 'success',
1681 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1682 )
1683 );
1684
1685 wp_send_json_success( array( 'message' => $message ) );
1686 }
1687
1688 public function process_login_2fa() {
1689 global $wp2fa;
1690
1691 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1692 return;
1693 }
1694
1695 $auth_id = (int) $_POST['uwp-auth-id'];
1696 $user = get_userdata( $auth_id );
1697
1698 if ( ! $user ) {
1699 $message = aui()->alert(
1700 array(
1701 'type' => 'error',
1702 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1703 )
1704 );
1705
1706 wp_send_json_error( array( 'message' => $message ) );
1707 }
1708
1709 if ( isset( $_POST['provider'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1710 $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
1711 } else {
1712 $provider = '';
1713 }
1714
1715 if ( 'wordfence' === $provider ) {
1716 $this->process_login_wordfence_2fa( $user );
1717
1718 return;
1719 }
1720
1721 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1722
1723 if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1724 $message = aui()->alert(
1725 array(
1726 'type' => 'error',
1727 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1728 )
1729 );
1730
1731 wp_send_json_error( array( 'message' => $message ) );
1732 }
1733
1734 $error = '';
1735
1736 try {
1737 $is_enabled = \WP2FA\Admin\Controllers\Settings::is_provider_enabled_for_role( \WP2FA\Admin\Helpers\User_Helper::get_user_role( $user ), $provider );
1738
1739 if ( ! $is_enabled ) {
1740 $error = __( 'Invalid 2FA provider for user.', 'userswp' );
1741 }
1742 } catch ( \Exception $e ) {
1743 $error = $e->getMessage();
1744 }
1745
1746 if ( $error ) {
1747 do_action( 'wp_login_failed', $user->user_login );
1748
1749 $message = aui()->alert(
1750 array(
1751 'type' => 'error',
1752 'content' => $error
1753 )
1754 );
1755
1756 wp_send_json_error( array( 'message' => $message ) );
1757 }
1758
1759 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1760 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1761
1762 }
1763
1764 // Validate TOTP.
1765 if ( 'totp' === $provider && true !== $this->validate_wp2fa_totp_authentication( $user ) ) {
1766 do_action( 'wp_login_failed', $user->user_login );
1767
1768 $message = aui()->alert(
1769 array(
1770 'type' => 'error',
1771 'content' => __( 'Invalid verification code.', 'userswp' ),
1772 )
1773 );
1774
1775 wp_send_json_error( array( 'message' => $message ) );
1776 }
1777
1778 // Validate Email.
1779 if ( 'email' === $provider && true !== $this->validate_wp2fa_email_authentication( $user ) ) {
1780 do_action( 'wp_login_failed', $user->user_login );
1781
1782 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1783 $message = aui()->alert(
1784 array(
1785 'type' => 'info',
1786 'content' => __( 'A new code has been sent.', 'userswp' ),
1787 )
1788 );
1789
1790 wp_send_json_error( array( 'message' => $message ) );
1791 } else {
1792 $message = aui()->alert(
1793 array(
1794 'type' => 'error',
1795 'content' => __( 'Invalid verification code.', 'userswp' ),
1796 )
1797 );
1798
1799 wp_send_json_error( array( 'message' => $message ) );
1800 }
1801 }
1802
1803 // Backup Codes.
1804 if ( 'backup_codes' === $provider && true !== $this->validate_wp2fa_backup_codes( $user ) ) {
1805 do_action( 'wp_login_failed', $user->user_login );
1806
1807 $message = aui()->alert(
1808 array(
1809 'type' => 'error',
1810 'content' => __( 'Invalid backup code.', 'userswp' ),
1811 )
1812 );
1813
1814 wp_send_json_error( array( 'message' => $message ) );
1815 }
1816
1817 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1818
1819 $rememberme = false;
1820 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1821
1822 if ( ! empty( $remember ) ) {
1823 $rememberme = true;
1824 }
1825
1826 wp_set_auth_cookie( $user->ID, $rememberme );
1827
1828 do_action( 'two_factor_user_authenticated', $user );
1829
1830 if ( defined( 'WP_2FA_PREFIX' ) ) {
1831 do_action( WP_2FA_PREFIX . 'user_authenticated', $user );
1832 }
1833
1834 $message = aui()->alert(
1835 array(
1836 'type' => 'success',
1837 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1838 )
1839 );
1840
1841 wp_send_json_success( array( 'message' => $message ) );
1842 }
1843
1844 public function get_login_redirect_url( $data, $user ) {
1845 if ( is_int( $user ) ) {
1846 $user = get_userdata( $user );
1847 }
1848
1849 $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1850 $custom_url = uwp_get_option( 'login_redirect_custom_url' );
1851
1852 if ( $user && isset( $user->roles[0] ) ) {
1853 $user_role = $user->roles[0];
1854 $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1855 $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1856 }
1857
1858 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1859 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1860 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1861 $redirect_to = esc_url_raw( $data['redirect_to'] );
1862 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1863 if ( uwp_is_wpml() ) {
1864 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1865 if ( ! empty( $wpml_page_id ) ) {
1866 $redirect_page_id = $wpml_page_id;
1867 }
1868 }
1869 $redirect_to = get_permalink( $redirect_page_id );
1870 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1871 $redirect_to = esc_url( wp_get_referer() );
1872 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1873 $redirect_to = $custom_url;
1874 } else {
1875 $redirect_to = home_url( '/' );
1876 $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1877 }
1878
1879 return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1880 }
1881
1882 /**
1883 * Processes forgot password form submission.
1884 *
1885 * @since 1.0.0
1886 * @package userswp
1887 *
1888 */
1889 public function process_forgot() {
1890
1891 $data = $_POST;
1892
1893 if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1894 return;
1895 }
1896
1897 if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1898 $message = aui()->alert(
1899 array(
1900 'type' => 'error',
1901 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1902 )
1903 );
1904 if ( wp_doing_ajax() ) {
1905 wp_send_json_error( $message );
1906 } else {
1907 return;
1908 }
1909 }
1910
1911 global $uwp_notices;
1912
1913 do_action( 'uwp_before_validate', 'forgot' );
1914
1915 $result = uwp_validate_fields( $data, 'forgot' );
1916
1917 $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
1918
1919 if ( is_wp_error( $result ) ) {
1920 $message = aui()->alert(
1921 array(
1922 'type' => 'error',
1923 'content' => $result->get_error_message(),
1924 )
1925 );
1926 if ( wp_doing_ajax() ) {
1927 wp_send_json_error( $message );
1928 } else {
1929 $uwp_notices[] = array( 'forgot' => $message );
1930
1931 return;
1932 }
1933 }
1934
1935 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1936
1937 $login_or_email = trim( $data['email'] );
1938 $user_data = is_email( $login_or_email )
1939 ? get_user_by( 'email', $login_or_email )
1940 : get_user_by( 'login', $login_or_email );
1941
1942 // if no user we fake it and bail
1943 if ( ! $user_data ) {
1944 $args = apply_filters(
1945 'uwp_forgot_error_message',
1946 array(
1947 'type' => 'error',
1948 'content' => __( 'Invalid username/email or user doesn\'t exist.', 'userswp' ),
1949 )
1950 );
1951
1952 $message = aui()->alert( $args );
1953 if ( wp_doing_ajax() ) {
1954 wp_send_json_success( $message );
1955 } else {
1956 $uwp_notices[] = array( 'forgot' => $message );
1957
1958 return;
1959 }
1960 }
1961
1962 // make sure user account is active before account reset
1963 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
1964 if ( $mod_value == 'email_unconfirmed' ) {
1965 $resend_link = uwp_get_forgot_page_url();
1966 $resend_link = add_query_arg(
1967 array(
1968 'user_id' => $user_data->ID,
1969 'action' => 'uwp_resend',
1970 '_nonce' => wp_create_nonce('uwp_resend'),
1971 ),
1972 $resend_link
1973 );
1974 $message = aui()->alert(
1975 array(
1976 'type' => 'error',
1977 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
1978 )
1979 );
1980 if ( wp_doing_ajax() ) {
1981 wp_send_json_error( $message );
1982 } else {
1983 $uwp_notices[] = array( 'forgot' => $message );
1984 return;
1985 }
1986 }
1987
1988 $user_data = get_userdata( $user_data->ID );
1989
1990 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
1991
1992 if ( ! $allow ) {
1993 return false;
1994 } elseif ( is_wp_error( $allow ) ) {
1995 return false;
1996 }
1997
1998 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
1999
2000 $reset_link = '';
2001
2002 if ( $as_password ) {
2003 $new_pass = wp_generate_password( 12, false );
2004 wp_set_password( $new_pass, $user_data->ID );
2005 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
2006 update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
2007 }
2008 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
2009 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2010 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
2011
2012 } else {
2013 // Use WordPress core to generate, hash (wp_fast_hash in WP 6.8+), and store the reset key.
2014 // This ensures compatibility with check_password_reset_key() on all WP versions.
2015 $key = get_password_reset_key( $user_data );
2016
2017 if ( is_wp_error( $key ) ) {
2018 if ( wp_doing_ajax() ) {
2019 wp_send_json_error( $key->get_error_message() );
2020 } else {
2021 $uwp_notices[] = array( 'forgot' => aui()->alert( array( 'type' => 'error', 'content' => $key->get_error_message() ) ) );
2022 return;
2023 }
2024 }
2025
2026 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
2027 $message .= home_url( '/' ) . '</p>';
2028 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2029 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
2030 $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
2031 $reset_page = uwp_get_page_id( 'reset_page', false );
2032 if ( $reset_page ) {
2033 $reset_link = add_query_arg(
2034 array(
2035 'key' => $key,
2036 'login' => rawurlencode( $user_data->user_login ),
2037 ),
2038 get_permalink( $reset_page )
2039 );
2040 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
2041 } else {
2042 $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
2043 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
2044 }
2045 $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
2046 }
2047
2048 $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
2049
2050 $email_vars = array(
2051 'user_id' => $user_data->ID,
2052 'login_details' => $message,
2053 'reset_link' => $reset_link,
2054 );
2055
2056 UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
2057
2058 do_action( 'uwp_after_process_forgot', $data );
2059
2060 $message = aui()->alert(
2061 array(
2062 'type' => 'success',
2063 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
2064 )
2065 );
2066 if ( wp_doing_ajax() ) {
2067 wp_send_json_success( $message );
2068 } else {
2069 $uwp_notices[] = array( 'forgot' => $message );
2070 }
2071 }
2072
2073 /**
2074 * Processes change password form submission.
2075 *
2076 * @since 1.0.0
2077 * @package userswp
2078 *
2079 */
2080 public function process_change() {
2081
2082 $data = $_POST;
2083
2084 if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
2085 return;
2086 }
2087
2088 global $uwp_notices;
2089
2090 if ( is_uwp_account_page() ) {
2091 $notice_type = 'account';
2092 } else {
2093 $notice_type = 'change';
2094 }
2095
2096 do_action( 'uwp_before_validate', 'change' );
2097
2098 $result = uwp_validate_fields( $data, 'change' );
2099
2100 $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
2101
2102 if ( is_wp_error( $result ) ) {
2103 $message = aui()->alert(
2104 array(
2105 'type' => 'error',
2106 'content' => $result->get_error_message(),
2107 )
2108 );
2109 $uwp_notices[] = array( $notice_type => $message );
2110
2111 return;
2112 }
2113
2114 do_action( 'uwp_after_validate', $result, 'change', $data );
2115
2116 $user_data = get_user_by( 'id', get_current_user_id() );
2117
2118 if ( ! $user_data ) {
2119 $message = aui()->alert(
2120 array(
2121 'type' => 'error',
2122 'content' => $user_data->get_error_message(),
2123 )
2124 );
2125 $uwp_notices[] = array( $notice_type => $message );
2126
2127 return;
2128 }
2129
2130 $email_vars = array(
2131 'user_id' => $user_data->ID,
2132 );
2133
2134 UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
2135
2136 wp_set_password( $result['password'], $user_data->ID );
2137
2138 $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
2139 if ( $password_nag ) {
2140 delete_user_meta( $user_data->ID, 'default_password_nag' );
2141 }
2142
2143 delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
2144
2145 $message = aui()->alert(
2146 array(
2147 'type' => 'success',
2148 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
2149 )
2150 );
2151
2152 $uwp_notices[] = array( $notice_type => $message );
2153
2154 do_action( 'uwp_after_process_change', $data );
2155
2156 wp_logout();
2157 exit();
2158 }
2159
2160 /**
2161 * Processes reset password form submission.
2162 *
2163 * @since 1.0.0
2164 * @package userswp
2165 *
2166 */
2167 public function process_reset() {
2168
2169 $data = $_POST;
2170
2171 if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
2172 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
2173 }
2174
2175 if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
2176 return;
2177 }
2178
2179 global $uwp_notices;
2180
2181 do_action( 'uwp_before_validate', 'reset' );
2182
2183 $result = uwp_validate_fields( $data, 'reset' );
2184
2185 $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
2186
2187 if ( is_wp_error( $result ) ) {
2188 $message = aui()->alert(
2189 array(
2190 'type' => 'error',
2191 'content' => $result->get_error_message(),
2192 )
2193 );
2194 $uwp_notices[] = array( 'reset' => $message );
2195
2196 return;
2197 }
2198
2199 do_action( 'uwp_after_validate', $result, 'reset', $data );
2200
2201 $login = sanitize_text_field( $data['uwp_reset_username'] );
2202 $key = sanitize_text_field( $data['uwp_reset_key'] );
2203
2204 $user = get_user_by( 'login', $login );
2205 if ( ! $user ) {
2206 $message = aui()->alert(
2207 array(
2208 'type' => 'error',
2209 'content' => __( 'Invalid username.', 'userswp' ),
2210 )
2211 );
2212 $uwp_notices[] = array( 'reset' => $message );
2213
2214 return;
2215 }
2216
2217 clean_user_cache( $user );
2218
2219 $user_data = check_password_reset_key( $key, $login );
2220
2221 if ( is_wp_error( $user_data ) ) {
2222 $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
2223 $message = aui()->alert(
2224 array(
2225 'type' => 'error',
2226 'content' => $error,
2227 )
2228 );
2229 $uwp_notices[] = array( 'reset' => $message );
2230
2231 return;
2232 }
2233
2234 $email_vars = array(
2235 'user_id' => $user_data->ID,
2236 );
2237
2238 UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
2239
2240 wp_set_password( $data['password'], $user_data->ID );
2241
2242 $login_page_url = uwp_get_login_page_url();
2243 $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
2244 $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
2245 $message = aui()->alert(
2246 array(
2247 'type' => 'success',
2248 'content' => $message,
2249 )
2250 );
2251 $uwp_notices[] = array( 'reset' => $message );
2252
2253 do_action( 'uwp_after_process_reset', $data );
2254 }
2255
2256 /**
2257 * Processes account form submission.
2258 *
2259 * @since 1.0.0
2260 * @package userswp
2261 *
2262 */
2263 public function process_account() {
2264
2265 $data = wp_unslash( $_POST );
2266 $files = $_FILES;
2267
2268 if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
2269 return;
2270 }
2271
2272 if ( ! is_user_logged_in() ) {
2273 return;
2274 }
2275
2276 global $uwp_notices;
2277 $file_obj = new UsersWP_Files();
2278
2279 do_action( 'uwp_before_validate', 'account' );
2280
2281 $result = uwp_validate_fields( $data, 'account' );
2282
2283 $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
2284
2285 if ( is_wp_error( $result ) ) {
2286 $message = aui()->alert(
2287 array(
2288 'type' => 'error',
2289 'content' => $result->get_error_message(),
2290 )
2291 );
2292 $uwp_notices[] = array( 'account' => $message );
2293
2294 return;
2295 }
2296
2297 $uploads_result = $file_obj->validate_uploads( $files, 'account' );
2298
2299 if ( is_wp_error( $uploads_result ) ) {
2300 $message = aui()->alert(
2301 array(
2302 'type' => 'error',
2303 'content' => $uploads_result->get_error_message(),
2304 )
2305 );
2306 $uwp_notices[] = array( 'account' => $message );
2307
2308 return;
2309 }
2310
2311 do_action( 'uwp_after_validate', $result, 'account', $data );
2312
2313 //unset if value is empty for files
2314 foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2315 if ( empty( $upload_file_value ) ) {
2316 unset( $uploads_result[ $upload_file_key ] );
2317 }
2318 }
2319
2320 global $wpdb;
2321 $file_field_names = $wpdb->get_col(
2322 $wpdb->prepare(
2323 "SELECT htmlvar_name FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE form_type = %s AND field_type IN ('file','image')",
2324 'account'
2325 )
2326 );
2327 foreach ( $file_field_names as $file_field_name ) {
2328 if ( isset( $result[ $file_field_name ] ) && ! isset( $uploads_result[ $file_field_name ] ) ) {
2329 unset( $result[ $file_field_name ] );
2330 }
2331 }
2332
2333 $result = array_merge( $result, $uploads_result );
2334
2335 $args = array(
2336 'ID' => get_current_user_id(),
2337 );
2338
2339 if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2340 $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2341 }
2342
2343 if ( isset( $result['first_name'] ) ) {
2344 $args['first_name'] = $result['first_name'];
2345 }
2346
2347 if ( isset( $result['last_name'] ) ) {
2348 $args['last_name'] = $result['last_name'];
2349 }
2350
2351 if ( isset( $result['user_url'] ) ) {
2352 $args['user_url'] = $result['user_url'];
2353 }
2354
2355 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2356 $args['display_name'] = $result['display_name'];
2357 }
2358
2359 if ( isset( $result['password'] ) ) {
2360 $args['user_pass'] = $result['password'];
2361 }
2362
2363 $user_id = wp_update_user( $args );
2364
2365 if ( is_wp_error( $user_id ) ) {
2366 $message = aui()->alert(
2367 array(
2368 'type' => 'error',
2369 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2370 )
2371 );
2372 $uwp_notices[] = array( 'account' => $message );
2373
2374 return;
2375 }
2376
2377 $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
2378
2379 if ( ! $res ) {
2380 $message = aui()->alert(
2381 array(
2382 'type' => 'error',
2383 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2384 )
2385 );
2386 $uwp_notices[] = array( 'account' => $message );
2387
2388 return;
2389 }
2390
2391 //updating bio field after saving extra fields to reflect the points in mycred add on.
2392 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2393 $args = array(
2394 'ID' => $user_id,
2395 'description' => $result['bio'],
2396 );
2397 wp_update_user( $args );
2398 }
2399
2400 $user_data = get_userdata( $user_id );
2401
2402 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
2403
2404 if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
2405
2406 if ( email_exists( trim( $result['email'] ) ) ) {
2407 $message = aui()->alert(
2408 array(
2409 'type' => 'error',
2410 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2411 )
2412 );
2413
2414 $uwp_notices[] = array( 'account' => $message );
2415 return;
2416
2417 }
2418
2419 $hash = md5( $result['email'] . time() . wp_rand() );
2420 $new_admin_email = array(
2421 'hash' => $hash,
2422 'newemail' => $result['email'],
2423 );
2424
2425 update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2426
2427 $new_email_link = add_query_arg(
2428 array(
2429 'uwp_new_email' => 'yes',
2430 'key' => $hash,
2431 'login' => $user_data->user_login,
2432 ),
2433 uwp_get_account_page_url()
2434 );
2435
2436 $email_vars = array(
2437 'user_id' => $user_id,
2438 'new_email' => $result['email'],
2439 'new_email_link' => esc_url( $new_email_link ),
2440 );
2441
2442 UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2443
2444 $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2445 $message = aui()->alert(
2446 array(
2447 'type' => 'success',
2448 'content' => $message,
2449 )
2450 );
2451
2452 $uwp_notices[] = array( 'account' => $message );
2453
2454 } else {
2455 $email_vars = array(
2456 'user_id' => $user_id,
2457 'form_fields' => $form_fields,
2458 );
2459
2460 UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2461
2462 $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2463 $message = aui()->alert(
2464 array(
2465 'type' => 'success',
2466 'content' => $message,
2467 )
2468 );
2469
2470 $uwp_notices[] = array( 'account' => $message );
2471 }
2472
2473 do_action( 'uwp_after_process_account', $data, $user_id );
2474 }
2475
2476 /**
2477 * Modifies the forms field in email based on the form type.
2478 *
2479 * @param string $form_fields Form fields.
2480 * @param string $type Form type.
2481 * @param int $user_id User ID.
2482 *
2483 * @return string Modified mail field.
2484 * @package userswp
2485 * @subpackage userswp/includes
2486 *
2487 */
2488 public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2489 switch ( $type ) {
2490 case 'register':
2491 $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2492 $fields = get_register_form_fields( $form_id );
2493 $user_data = get_userdata( $user_id );
2494 if ( ! empty( $fields ) && is_array( $fields ) ) {
2495 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2496 $excluded = uwp_get_excluded_fields();
2497 foreach ( $fields as $key => $field ) {
2498 if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2499 continue;
2500 }
2501 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2502 $field_value = $user_data->user_email;
2503 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2504 $field_value = $user_data->user_login;
2505 } elseif ( $field->htmlvar_name == 'bio' ) {
2506 $field_value = get_user_meta( $user_id, 'description', true );
2507 } else {
2508 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2509 }
2510
2511 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2512 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2513 }
2514
2515 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2516 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2517 }
2518 }
2519 }
2520 break;
2521 case 'account':
2522 $fields = get_account_form_fields();
2523 $user_data = get_userdata( $user_id );
2524 if ( ! empty( $fields ) && is_array( $fields ) ) {
2525 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2526 foreach ( $fields as $key => $field ) {
2527 if ( $field->is_active != '1' ) {
2528 continue;
2529 }
2530 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2531 $field_value = $user_data->user_email;
2532 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2533 $field_value = $user_data->user_login;
2534 } elseif ( $field->htmlvar_name == 'bio' ) {
2535 $field_value = get_user_meta( $user_id, 'description', true );
2536 } else {
2537 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2538 }
2539
2540 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2541 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2542 }
2543
2544 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2545 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2546 }
2547 }
2548 }
2549 break;
2550 }
2551
2552 return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2553 }
2554
2555 /**
2556 *
2557 *
2558 * @return void
2559 * @since 1.0.12 Unlink file.
2560 * @package userswp
2561 * @since 1.0.0
2562 */
2563 public function upload_file_remove() {
2564 global $wpdb;
2565
2566 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2567
2568 // Check user logged in.
2569 if ( ! is_user_logged_in() ) {
2570 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2571 wp_send_json_error( array( 'message' => $message ) );
2572 }
2573
2574 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2575 $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2576
2577 if ( empty( $user_id ) || empty( $htmlvar ) ) {
2578 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2579 wp_send_json_error( array( 'message' => $message ) );
2580 }
2581
2582 // Validate the user / admin.
2583 if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2584 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2585 wp_send_json_error( array( 'message' => $message ) );
2586 }
2587
2588 if ( $htmlvar == 'banner_thumb' ) {
2589 $field_key = 'banner';
2590 $type = 'banner';
2591 } else if ( $htmlvar == 'avatar_thumb' ) {
2592 $field_key = 'avatar';
2593 $type = 'avatar';
2594 } else {
2595 $field_key = $htmlvar;
2596 $type = '';
2597 }
2598
2599 $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2600
2601 // Check field exists.
2602 if ( empty( $field ) ) {
2603 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2604 wp_send_json_error( array( 'message' => $message ) );
2605 }
2606
2607 // Validate field access.
2608 if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2609 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2610 wp_send_json_error( array( 'message' => $message ) );
2611 }
2612
2613 if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2614 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2615 wp_send_json_error( array( 'message' => $message ) );
2616 }
2617
2618 $value = uwp_get_usermeta( $user_id, $htmlvar );
2619
2620 uwp_update_usermeta( $user_id, $htmlvar, '' );
2621
2622 if ( $value && validate_file( $value ) === 0 ) {
2623 $uploads = wp_upload_dir();
2624 $upload_path = $uploads['basedir'];
2625
2626 if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) {
2627 // Get the relative url.
2628 $value = uwp_get_file_relative_url( $value );
2629 }
2630
2631 $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' );
2632
2633 // Canonicalize and enforce containment inside the uploads directory before deleting.
2634 $real_upload_path = realpath( $upload_path );
2635 $real_unlink_file = realpath( $unlink_file );
2636
2637 if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file )
2638 && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2639 wp_delete_file( $real_unlink_file );
2640
2641 // For avatar/banner, also remove the original (non-thumb) file.
2642 if ( $type ) {
2643 $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2644 $real_unlink_ori_file = realpath( $unlink_ori_file );
2645
2646 if ( $real_unlink_ori_file && is_file( $real_unlink_ori_file )
2647 && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2648 wp_delete_file( $real_unlink_ori_file );
2649 }
2650 }
2651 }
2652 }
2653
2654 wp_send_json_success();
2655
2656 wp_die();
2657 }
2658
2659 /**
2660 * Form field template for datepicker field type.
2661 *
2662 * @param string $html Form field html
2663 * @param object $field Field info.
2664 * @param string $value Form field default value.
2665 * @param string $form_type Form type
2666 *
2667 * @return string Modified form field html.
2668 * @package userswp
2669 *
2670 * @since 1.0.0
2671 */
2672 public function form_input_datepicker( $html, $field, $value, $form_type ) {
2673
2674 // Check if there is a field specific filter.
2675 if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2676 $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2677 }
2678
2679 // If no html then we run the standard output.
2680 if ( empty( $html ) ) {
2681
2682 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2683 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2684 $bs_sr_only = $design_style ? 'sr-only' : '';
2685 $bs_form_control = $design_style ? 'form-control' : '';
2686 $extra_attributes = array();
2687 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2688 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2689
2690 ob_start(); // Start buffering;
2691
2692 $extra_fields = unserialize( $field->extra_fields );
2693
2694 if ( $extra_fields['date_format'] == '' ) {
2695 $extra_fields['date_format'] = 'yy-mm-dd';
2696 }
2697
2698 $date_format = $extra_fields['date_format'];
2699 $jquery_date_format = $date_format;
2700
2701 // check if we need to change the format or not
2702 $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2703 if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2704
2705 $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2706 $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2707
2708 $date_format = str_replace( $search, $replace, $date_format );
2709 } else {
2710 $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2711 }
2712
2713 if ( ! empty( $value ) && ! is_string( $value ) ) {
2714 $value = date( 'Y-m-d', $value );
2715 }
2716
2717 if ( $value == '0000-00-00' ) {
2718 $value = '';
2719 }//if date not set, then mark it empty
2720 $value = uwp_date( $value, 'Y-m-d', $date_format );
2721 $site_title = uwp_get_form_label( $field );
2722
2723 // bootstrap
2724 if ( $design_style ) {
2725 // flatpickr attributes
2726 $extra_attributes['data-alt-input'] = 'true';
2727 $extra_attributes['data-alt-format'] = $date_format;
2728 $extra_attributes['data-date-format'] = 'Y-m-d';
2729
2730 if ( 'dob' == $field->htmlvar_name ) {
2731 $extra_attributes['data-max-date'] = 'today';
2732 }
2733
2734 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2735
2736 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2737 array(
2738 'id' => esc_attr( $field->htmlvar_name ),
2739 'name' => esc_attr( $field->htmlvar_name ),
2740 'required' => ! empty( $field->is_required ) ? true : false,
2741 'label' => wp_kses_post( $site_title . $required ),
2742 'label_show' => true,
2743 'label_type' => 'hidden',
2744 'type' => 'datepicker',
2745 'title' => esc_html( $site_title ),
2746 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2747 'class' => '',
2748 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2749 'value' => esc_attr( $value ),
2750 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2751 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2752 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2753 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2754 )
2755 );
2756 } else {
2757 ?>
2758 <script type="text/javascript">
2759
2760 jQuery(function () {
2761 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2762 changeMonth: true, changeYear: true
2763 <?php
2764 if ( $field->htmlvar_name == 'dob' ) {
2765 echo ", yearRange: '1900:+0'";
2766 } else {
2767 echo ", yearRange: '1900:2050'";
2768 }
2769 ?>
2770 <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2771
2772 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2773
2774 <?php if ( ! empty( $value ) ) { ?>
2775 var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2776 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2777 <?php } ?>
2778
2779 });
2780
2781 </script>
2782 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2783 class="
2784 <?php
2785 if ( $field->is_required ) {
2786 echo 'required_field';
2787 }
2788 ?>
2789 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2790
2791 <?php
2792
2793 if ( ! is_admin() ) {
2794 ?>
2795 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2796 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2797 <?php
2798 if ( $field->is_required ) {
2799 echo '<span>*</span>';
2800 }
2801 ?>
2802 </label>
2803 <?php } ?>
2804
2805 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2806 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2807 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2808 title="<?php echo esc_attr( $site_title ); ?>"
2809 type="text"
2810 <?php
2811 if ( $field->is_required == 1 ) {
2812 echo 'required="required"';
2813 }
2814 ?>
2815 value="<?php echo esc_attr( $value ); ?>"
2816 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2817
2818 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2819 <?php if ( $field->is_required ) { ?>
2820 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2821 <?php } ?>
2822 </div>
2823
2824 <?php
2825 }
2826
2827 $html = ob_get_clean();
2828 }
2829
2830 return $html;
2831 }
2832
2833 /**
2834 * Form field template for time field type.
2835 *
2836 * @param string $html Form field html
2837 * @param object $field Field info.
2838 * @param string $value Form field default value.
2839 * @param string $form_type Form type
2840 *
2841 * @return string Modified form field html.
2842 * @package userswp
2843 *
2844 * @since 1.0.0
2845 */
2846 public function form_input_time( $html, $field, $value, $form_type ) {
2847
2848 if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
2849
2850 $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2851 }
2852
2853 // If no html then we run the standard output.
2854 if ( empty( $html ) ) {
2855
2856 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2857 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2858 $bs_sr_only = $design_style ? 'sr-only' : '';
2859 $bs_form_control = $design_style ? 'form-control bg-white' : '';
2860 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2861 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2862
2863 ob_start(); // Start buffering;
2864
2865 if ( $value != '' ) {
2866 $value = date( 'H:i', strtotime( $value ) );
2867 }
2868
2869 // flatpickr attributes
2870 $extra_attributes['data-enable-time'] = 'true';
2871 $extra_attributes['data-no-calendar'] = 'true';
2872 $extra_attributes['data-date-format'] = 'H:i';
2873 $site_title = uwp_get_form_label( $field );
2874 $label_type = is_admin() ? '' : 'top';
2875
2876 if ( $design_style ) {
2877 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2878
2879 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2880 array(
2881 'id' => esc_attr( $field->htmlvar_name ),
2882 'name' => esc_attr( $field->htmlvar_name ),
2883 'required' => ! empty( $field->is_required ) ? true : false,
2884 'label' => wp_kses_post( $site_title . $required ),
2885 'label_show' => true,
2886 'label_type' => esc_attr( $label_type ),
2887 'type' => 'timepicker',
2888 'title' => esc_html( $site_title ),
2889 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2890 'class' => '',
2891 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2892 'value' => esc_attr( $value ),
2893 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2894 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2895 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2896 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2897 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2898 )
2899 );
2900 } else {
2901 ?>
2902 <script type="text/javascript">
2903 jQuery(document).ready(function () {
2904 jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2905 showPeriod: true,
2906 showLeadingZero: true
2907 });
2908 });
2909 </script>
2910 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2911 class="
2912 <?php
2913 if ( $field->is_required ) {
2914 echo 'required_field';
2915 }
2916 ?>
2917 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2918
2919 <?php
2920 $site_title = uwp_get_form_label( $field );
2921 if ( ! is_admin() ) {
2922 ?>
2923 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2924 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2925 <?php
2926 if ( $field->is_required ) {
2927 echo '<span>*</span>';
2928 }
2929 ?>
2930 </label>
2931 <?php } ?>
2932
2933 <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2934 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2935 value="<?php echo esc_attr( $value ); ?>"
2936 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2937 type="text"
2938 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2939
2940 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2941 <?php if ( $field->is_required ) { ?>
2942 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2943 <?php } ?>
2944 </div>
2945 <?php
2946 }
2947 $html = ob_get_clean();
2948 }
2949
2950 return $html;
2951 }
2952
2953 /**
2954 * Form field template for select field type.
2955 *
2956 * @param string $html Form field html
2957 * @param object $field Field info.
2958 * @param string $value Form field default value.
2959 * @param string $form_type Form type
2960 *
2961 * @return string Modified form field html.
2962 * @package userswp
2963 *
2964 * @since 1.0.0
2965 */
2966 public function form_input_select( $html, $field, $value, $form_type ) {
2967
2968 // Check if there is a field specific filter.
2969 if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
2970 $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2971 }
2972
2973 // Check if there is a field type specific filter.
2974 if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
2975 $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
2976 }
2977
2978 // If no html then we run the standard output.
2979 if ( empty( $html ) ) {
2980
2981 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2982 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2983 $bs_sr_only = $design_style ? 'sr-only' : '';
2984 $bs_form_control = $design_style ? 'form-control' : '';
2985 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2986 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2987
2988 ob_start(); // Start buffering;
2989 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
2990 $site_title = uwp_get_form_label( $field );
2991
2992 // bootstrap
2993 if ( $design_style ) {
2994
2995 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2996
2997 echo aui()->select(
2998 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2999 'id' => esc_attr( $field->htmlvar_name ),
3000 'name' => esc_attr( $field->htmlvar_name ),
3001 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3002 'title' => esc_html( $site_title ),
3003 'value' => esc_attr( $value ),
3004 'required' => (bool) $field->is_required,
3005 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3006 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3007 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3008 'label' => wp_kses_post( $site_title . $required ),
3009 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3010 'select2' => true,
3011 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3012 )
3013 );
3014 } else {
3015 ?>
3016 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3017 class="
3018 <?php
3019 if ( $field->is_required ) {
3020 echo 'required_field';
3021 }
3022 ?>
3023 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3024
3025 <?php
3026 if ( ! is_admin() ) {
3027 ?>
3028 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3029 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3030 <?php
3031 if ( $field->is_required ) {
3032 echo '<span>*</span>';
3033 }
3034 ?>
3035 </label>
3036 <?php } ?>
3037
3038 <?php
3039
3040 $select_options = '';
3041 if ( ! empty( $option_values_arr ) ) {
3042 foreach ( $option_values_arr as $option_row ) {
3043 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
3044 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3045
3046 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
3047 } else {
3048 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3049 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
3050 $selected = $option_value == $value ? 'selected="selected"' : '';
3051
3052 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
3053 }
3054 }
3055 }
3056 ?>
3057 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3058 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
3059 title="<?php echo esc_attr( $site_title ); ?>"
3060 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3061 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
3062 </select>
3063 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3064 <?php if ( $field->is_required ) { ?>
3065 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3066 <?php } ?>
3067 </div>
3068
3069 <?php
3070 }
3071 $html = ob_get_clean();
3072 }
3073
3074 return $html;
3075 }
3076
3077 /**
3078 * Form field template for multiselect field type.
3079 *
3080 * @param string $html Form field html
3081 * @param object $field Field info.
3082 * @param string $value Form field default value.
3083 * @param string $form_type Form type
3084 *
3085 * @return string Modified form field html.
3086 * @package userswp
3087 *
3088 * @since 1.0.0
3089 */
3090 public function form_input_multiselect( $html, $field, $value, $form_type ) {
3091
3092 // Check if there is a field specific filter.
3093 if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
3094 $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3095 }
3096
3097 if ( empty( $html ) ) {
3098
3099 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3100 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3101 $bs_sr_only = $design_style ? 'sr-only' : '';
3102 $bs_form_control = $design_style ? 'form-control' : '';
3103 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3104 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3105
3106 ob_start(); // Start buffering;
3107
3108 $multi_display = 'select';
3109 if ( ! empty( $field->extra_fields ) ) {
3110 $multi_display = unserialize( $field->extra_fields );
3111 }
3112
3113 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
3114 $site_title = uwp_get_form_label( $field );
3115 $value = is_array( $value ) ? $value : esc_attr( $value );
3116
3117 // bootstrap
3118 if ( $design_style ) {
3119
3120 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3121
3122 echo aui()->select(
3123 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3124 'id' => esc_attr( $field->htmlvar_name ),
3125 'name' => esc_attr( $field->htmlvar_name ),
3126 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3127 'title' => esc_html( $site_title ),
3128 'value' => $value,
3129 'required' => (bool) $field->is_required,
3130 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3131 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3132 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3133 'label' => wp_kses_post( $site_title . $required ),
3134 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3135 'select2' => true,
3136 'multiple' => true,
3137 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3138 )
3139 );
3140 } else {
3141 ?>
3142 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3143 class="
3144 <?php
3145 if ( $field->is_required ) {
3146 echo 'required_field';
3147 }
3148 ?>
3149 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3150
3151 <?php
3152 if ( ! is_admin() ) {
3153 ?>
3154 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3155 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3156 <?php
3157 if ( $field->is_required ) {
3158 echo '<span>*</span>';
3159 }
3160 ?>
3161 </label>
3162 <?php } ?>
3163
3164 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
3165 <?php if ( $multi_display == 'select' ) { ?>
3166 <div class="uwp_multiselect_list">
3167 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
3168 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3169 title="<?php echo esc_attr( $site_title ); ?>"
3170 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3171 class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
3172 >
3173 <?php
3174 } else {
3175 ?>
3176 <ul class="uwp_multi_choice">
3177 <?php
3178 }
3179
3180 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
3181 $select_options = '';
3182 if ( ! empty( $option_values_arr ) ) {
3183 foreach ( $option_values_arr as $option_row ) {
3184 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
3185 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3186
3187 if ( $multi_display == 'select' ) {
3188 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
3189 } else {
3190 $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
3191 }
3192 } else {
3193 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3194 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
3195 $selected = $option_value == $value ? 'selected="selected"' : '';
3196 $checked = '';
3197
3198 if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
3199 if ( ! is_array( $value ) ) {
3200 $value_array = explode( ',', $value );
3201 } else {
3202 $value_array = $value;
3203 }
3204
3205 if ( is_array( $value_array ) ) {
3206 if ( in_array( $option_value, $value_array ) ) {
3207 $selected = 'selected="selected"';
3208 $checked = 'checked="checked"';
3209 }
3210 }
3211 }
3212
3213 if ( $multi_display == 'select' ) {
3214 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
3215 } else {
3216 $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
3217 }
3218 }
3219 }
3220 }
3221 echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3222
3223 if ( $multi_display == 'select' ) {
3224
3225 ?>
3226 </select></div>
3227 <?php } else { ?>
3228 </ul>
3229 <?php } ?>
3230 <?php if ( $field->is_required ) { ?>
3231 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3232 <?php } ?>
3233 </div>
3234 <?php
3235 }
3236 $html = ob_get_clean();
3237 }
3238
3239 return $html;
3240 }
3241
3242 /**
3243 * Form field template for file field type.
3244 *
3245 * @param string $html Form field html
3246 * @param object $field Field info.
3247 * @param string $value Form field default value.
3248 * @param string $form_type Form type
3249 *
3250 * @return string Modified form field html.
3251 * @package userswp
3252 *
3253 * @since 1.0.0
3254 */
3255 public function form_input_file( $html, $field, $value, $form_type ) {
3256
3257 $file_obj = new UsersWP_Files();
3258
3259 // Check if there is a field specific filter.
3260 if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
3261 $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3262 }
3263
3264 // If no html then we run the standard output.
3265 if ( empty( $html ) ) {
3266
3267 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3268 $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
3269 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3270 $bs_sr_only = $design_style ? 'sr-only' : '';
3271 $bs_form_control = $design_style ? 'form-control' : '';
3272
3273 ob_start(); // Start buffering;
3274
3275 ?>
3276 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3277 class="
3278 <?php
3279 if ( $field->is_required ) {
3280 echo 'required_field';
3281 }
3282 ?>
3283 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
3284
3285 <?php
3286 $site_title = uwp_get_form_label( $field );
3287 if ( ! is_admin() && ! wp_doing_ajax() ) {
3288 ?>
3289 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3290 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3291 <?php
3292 if ( $field->is_required ) {
3293 echo ' <span class="text-danger">*</span>';
3294 }
3295 ?>
3296 </label>
3297 <?php } ?>
3298
3299 <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
3300 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3301 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3302 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3303 title="<?php echo esc_attr( $site_title ); ?>"
3304 <?php
3305 if ( $field->is_required == 1 ) {
3306 echo 'data-is-required="1"';
3307 }
3308 if ( $field->is_required == 1 && ! $value ) {
3309 echo 'required="required"';
3310 }
3311 ?>
3312 type="<?php echo esc_attr( $field->field_type ); ?>">
3313 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3314 <?php if ( $field->is_required ) { ?>
3315 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3316 <?php } ?>
3317 </div>
3318
3319 <?php
3320 $html = ob_get_clean();
3321 }
3322
3323 return $html;
3324 }
3325
3326 /**
3327 * Form field template for checkbox field type.
3328 *
3329 * @param string $html Form field html
3330 * @param object $field Field info.
3331 * @param string $value Form field default value.
3332 * @param string $form_type Form type
3333 *
3334 * @return string Modified form field html.
3335 * @package userswp
3336 *
3337 * @since 1.0.0
3338 */
3339 public function form_input_checkbox( $html, $field, $value, $form_type ) {
3340
3341 // Check if there is a field specific filter.
3342 if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
3343 $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3344 }
3345
3346 // If no html then we run the standard output.
3347 if ( empty( $html ) ) {
3348
3349 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3350 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
3351 $bs_sr_only = $design_style ? 'form-check-label' : '';
3352 $bs_form_control = $design_style ? 'form-check-input' : '';
3353
3354 ob_start(); // Start buffering;
3355 $site_title = uwp_get_form_label( $field );
3356
3357 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3358 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
3359
3360 $checked = $value == '1' ? true : false;
3361
3362 // bootstrap
3363 if ( $design_style ) {
3364 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3365
3366 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
3367
3368 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3369 array(
3370 'id' => esc_attr( $id ),
3371 'name' => esc_attr( $field->htmlvar_name ),
3372 'type' => 'checkbox',
3373 'value' => '1',
3374 'title' => esc_html( $site_title ),
3375 'label' => wp_kses_post( $site_title . $required ),
3376 'label_show' => true,
3377 'required' => ! empty( $field->is_required ) ? true : false,
3378 'checked' => (bool) $checked,
3379 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3380 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3381 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3382 )
3383 );
3384
3385 } else {
3386 ?>
3387 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3388 class="
3389 <?php
3390 if ( $field->is_required ) {
3391 echo 'required_field';
3392 }
3393 ?>
3394 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3395 <?php if ( ! empty( $design_style ) ) { ?>
3396 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3397 <?php } ?>
3398 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3399 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3400 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3401 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3402 title="<?php echo esc_attr( $site_title ); ?>"
3403 <?php
3404 if ( $field->is_required == 1 ) {
3405 echo 'required="required"';
3406 }
3407 ?>
3408 <?php
3409 if ( $value == '1' ) {
3410 echo 'checked="checked"';
3411 }
3412 ?>
3413 type="<?php echo esc_attr( $field->field_type ); ?>"
3414 value="1">
3415 <?php
3416 echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3417 ?>
3418 <?php if ( ! empty( $design_style ) ) { ?>
3419 </label>
3420 <?php } ?>
3421 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3422 <?php if ( $field->is_required ) { ?>
3423 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3424 <?php } ?>
3425 </div>
3426
3427 <?php
3428
3429 }
3430
3431 $html = ob_get_clean();
3432
3433 }
3434
3435 return $html;
3436 }
3437
3438 /**
3439 * Form field template for radio field type.
3440 *
3441 * @param string $html Form field html
3442 * @param object $field Field info.
3443 * @param string $value Form field default value.
3444 * @param string $form_type Form type
3445 *
3446 * @return string Modified form field html.
3447 * @package userswp
3448 *
3449 * @since 1.0.0
3450 */
3451 public function form_input_radio( $html, $field, $value, $form_type ) {
3452
3453 // Check if there is a field specific filter.
3454 if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3455 $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3456 }
3457
3458 // If no html then we run the standard output.
3459 if ( empty( $html ) ) {
3460
3461 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3462 $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3463 $bs_sr_only = $design_style ? 'sr-only' : '';
3464 $bs_label_class = $design_style ? 'form-check-label' : '';
3465 $bs_form_control = $design_style ? 'form-check-input' : '';
3466
3467 ob_start(); // Start buffering;
3468
3469 if ( $design_style ) {
3470
3471 $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3472 $option_values = array();
3473 if ( ! empty( $option_values_deep ) ) {
3474 foreach ( $option_values_deep as $option ) {
3475 $option_values[ $option['value'] ] = $option['label'];
3476 }
3477 }
3478
3479 $site_title = uwp_get_form_label( $field );
3480
3481 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3482
3483 echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3484 array(
3485 'id' => esc_attr( $field->htmlvar_name ),
3486 'name' => esc_attr( $field->htmlvar_name ),
3487 'type' => 'radio',
3488 'title' => esc_html( $site_title ),
3489 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3490 'label_type' => 'top',
3491 'class' => '',
3492 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3493 'value' => esc_attr( $value ),
3494 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3495 )
3496 );
3497
3498 } else {
3499
3500 ?>
3501 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3502 class="
3503 <?php
3504 if ( $field->is_required ) {
3505 echo 'required_field';
3506 }
3507 ?>
3508 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3509
3510 <?php
3511 $site_title = uwp_get_form_label( $field );
3512 if ( ! is_admin() ) {
3513 ?>
3514 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3515 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3516 <?php
3517 if ( $field->is_required ) {
3518 echo '<span>*</span>';
3519 }
3520 ?>
3521 </label>
3522 <?php } ?>
3523
3524 <?php
3525 if ( $field->option_values ) {
3526 $option_values = uwp_string_values_to_options( $field->option_values, true );
3527
3528 if ( ! empty( $option_values ) ) {
3529 $count = 0;
3530 foreach ( $option_values as $option_value ) {
3531 if ( empty( $option_value['optgroup'] ) ) {
3532 ++$count;
3533 if ( $count == 1 ) {
3534 $class = 'uwp-radio-first';
3535 } else {
3536 $class = '';
3537 }
3538 ?>
3539 <?php if ( ! empty( $design_style ) ) { ?>
3540 <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3541 <?php } else { ?>
3542 <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3543 <?php } ?>
3544 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3545 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3546 title="<?php echo esc_attr( $option_value['label'] ); ?>"
3547 <?php checked( $value, $option_value['value'] ); ?>
3548 <?php
3549 if ( $field->is_required == 1 ) {
3550 echo 'required="required"';
3551 }
3552 ?>
3553 value="<?php echo esc_attr( $option_value['value'] ); ?>"
3554 class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3555 <?php echo esc_html( $option_value['label'] ); ?>
3556 <?php if ( ! empty( $design_style ) ) { ?>
3557 </label>
3558 <?php } else { ?>
3559 </span>
3560 <?php
3561 }
3562 }
3563 }
3564 }
3565 }
3566 ?>
3567 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3568 <?php if ( $field->is_required ) { ?>
3569 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3570 <?php } ?>
3571 </div>
3572 <?php
3573 }
3574
3575 $html = ob_get_clean();
3576 }
3577
3578 return $html;
3579 }
3580
3581 /**
3582 * Form field template for text field type.
3583 *
3584 * @param string $html Form field html
3585 * @param object $field Field info.
3586 * @param string $value Form field default value.
3587 * @param string $form_type Form type
3588 *
3589 * @return string Modified form field html.
3590 * @package userswp
3591 *
3592 * @since 1.0.0
3593 */
3594 public function form_input_text( $html, $field, $value, $form_type ) {
3595
3596 // Check if there is a custom field specific filter.
3597 if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3598 $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3599 }
3600
3601 // If no html then we run the standard output.
3602 if ( empty( $html ) ) {
3603
3604 ob_start(); // Start buffering;
3605
3606 $type = 'text';
3607 $step = false;
3608 //number and float validation $validation_pattern
3609 if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3610 $type = 'number';
3611 } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3612 $dp = $field->decimal_point;
3613 switch ( $dp ) {
3614 case '1':
3615 $step = '0.1';
3616 break;
3617 case '2':
3618 $step = '0.01';
3619 break;
3620 case '3':
3621 $step = '0.001';
3622 break;
3623 case '4':
3624 $step = '0.0001';
3625 break;
3626 case '5':
3627 $step = '0.00001';
3628 break;
3629 case '6':
3630 $step = '0.000001';
3631 break;
3632 case '7':
3633 $step = '0.0000001';
3634 break;
3635 case '8':
3636 $step = '0.00000001';
3637 break;
3638 case '9':
3639 $step = '0.000000001';
3640 break;
3641 case '10':
3642 $step = '0.0000000001';
3643 break;
3644 default:
3645 $step = '0.01';
3646 break;
3647 }
3648 $type = 'number';
3649 }
3650
3651 $site_title = uwp_get_form_label( $field );
3652 $placeholder = uwp_get_field_placeholder( $field );
3653 $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3654 if ( $manual_label
3655 && isset( $field->form_type )
3656 && $field->form_type == 'login'
3657 && $field->htmlvar_name == 'username' ) {
3658 $site_title = __( 'Username or Email', 'userswp' );
3659 $required = ! empty( $field->is_required ) ? ' *' : '';
3660 $placeholder = $site_title . $required;
3661 $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3662 }
3663
3664 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3665 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3666 $bs_sr_only = $design_style ? 'sr-only' : '';
3667 $bs_form_control = $design_style ? 'form-control' : '';
3668
3669 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3670 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3671
3672 // bootstrap
3673 if ( $design_style ) {
3674 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3675
3676 echo aui()->input(
3677 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3678 'type' => esc_attr( $type ),
3679 'id' => esc_attr( $field->htmlvar_name ),
3680 'name' => esc_attr( $field->htmlvar_name ),
3681 'placeholder' => esc_attr( $placeholder ),
3682 'title' => esc_html( $site_title ),
3683 'value' => esc_attr( wp_unslash( $value ) ),
3684 'required' => (bool) $field->is_required,
3685 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3686 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3687 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3688 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3689 'step' => esc_attr( $step ),
3690 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3691 )
3692 );
3693 } else {
3694 ?>
3695 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3696 <?php
3697 if ( $field->is_required ) {
3698 echo 'required_field';
3699 }
3700 ?>
3701 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3702 <?php
3703
3704 if ( ! is_admin() ) {
3705 ?>
3706 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3707 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3708 <?php
3709 if ( $field->is_required ) {
3710 echo '<span>*</span>';
3711 }
3712 ?>
3713 </label>
3714 <?php
3715 }
3716 ?>
3717
3718 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3719 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3720 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3721 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3722 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3723 title="<?php echo esc_attr( $site_title ); ?>"
3724 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3725 oninput="setCustomValidity('')"
3726 <?php
3727 if ( $field->is_required == 1 ) {
3728 echo 'required="required"';
3729 }
3730 ?>
3731 <?php
3732 if ( $field->for_admin_use == 1 ) {
3733 echo 'readonly="readonly"';
3734 }
3735 ?>
3736 type="<?php echo esc_attr( $type ); ?>"
3737 <?php
3738 if ( $step ) {
3739 echo 'step="' . esc_attr( $step ) . '"';
3740 }
3741 ?>
3742 />
3743 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3744 <?php if ( $field->is_required ) { ?>
3745 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3746 <?php } ?>
3747 </div>
3748
3749
3750 <?php
3751 }
3752 $html = ob_get_clean();
3753 }
3754
3755 return $html;
3756 }
3757
3758 /**
3759 * Form field template for textarea field type.
3760 *
3761 * @param string $html Form field html
3762 * @param object $field Field info.
3763 * @param string $value Form field default value.
3764 * @param string $form_type Form type
3765 *
3766 * @return string Modified form field html.
3767 * @package userswp
3768 *
3769 * @since 1.0.0
3770 */
3771 public function form_input_textarea( $html, $field, $value, $form_type ) {
3772
3773 // Check if there is a field specific filter.
3774 if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3775 $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3776 }
3777
3778 // If no html then we run the standard output.
3779 if ( empty( $html ) ) {
3780
3781 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3782 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3783 $bs_sr_only = $design_style ? 'sr-only' : '';
3784 $bs_form_control = $design_style ? 'form-control' : '';
3785 $site_title = uwp_get_form_label( $field );
3786
3787 ob_start(); // Start buffering;
3788
3789 // bootstrap
3790 if ( $design_style ) {
3791 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3792
3793 echo aui()->textarea(
3794 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3795 'id' => esc_attr( $field->htmlvar_name ),
3796 'name' => esc_attr( $field->htmlvar_name ),
3797 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3798 'title' => esc_html( $site_title ),
3799 'value' => wp_kses_post( stripslashes( $value ) ),
3800 'required' => (bool) $field->is_required,
3801 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3802 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3803 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3804 'rows' => '4',
3805 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3806 )
3807 );
3808 } else {
3809 ?>
3810
3811 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3812 class="
3813 <?php
3814 if ( $field->is_required ) {
3815 echo 'required_field';
3816 }
3817 ?>
3818 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3819
3820 <?php
3821
3822 if ( ! is_admin() ) {
3823 ?>
3824 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3825 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3826 <?php
3827 if ( $field->is_required ) {
3828 echo '<span>*</span>';
3829 }
3830 ?>
3831 </label>
3832 <?php } ?>
3833
3834 <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3835 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3836 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3837 title="<?php echo esc_attr( $site_title ); ?>"
3838 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3839 oninput="setCustomValidity('')"
3840 <?php
3841 if ( $field->is_required == 1 ) {
3842 echo 'required="required"';
3843 }
3844 ?>
3845 type="<?php echo esc_attr( $field->field_type ); ?>"
3846 rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3847 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3848 <?php if ( $field->is_required ) { ?>
3849 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3850 <?php } ?>
3851 </div>
3852
3853 <?php
3854 }
3855 $html = ob_get_clean();
3856 }
3857
3858 return $html;
3859 }
3860
3861 public function form_input_editor( $html, $field, $value, $form_type ) {
3862
3863 // Check if there is a field specific filter.
3864 if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3865 $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3866 }
3867
3868 if ( empty( $html ) ) {
3869
3870 ob_start();
3871
3872 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3873 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3874 $bs_sr_only = $design_style ? 'sr-only' : '';
3875 $site_title = uwp_get_form_label( $field );
3876
3877 $content = stripslashes( $value );
3878 $editor_id = $field->htmlvar_name;
3879 $args = array(
3880 'textarea_rows' => 5,
3881 'media_buttons' => false,
3882 'quicktags' => false,
3883 );
3884
3885 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3886 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3887
3888 // bootstrap
3889 if ( $design_style ) {
3890 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3891
3892 echo aui()->textarea(
3893 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3894 'id' => esc_attr( $field->htmlvar_name ),
3895 'name' => esc_attr( $field->htmlvar_name ),
3896 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3897 'title' => esc_html( $site_title ),
3898 'value' => wp_kses_post( stripslashes( $value ) ),
3899 'required' => (bool) $field->is_required,
3900 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3901 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3902 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3903 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3904 'rows' => 5,
3905 'wysiwyg' => true,
3906 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3907 )
3908 );
3909 } else {
3910 ?>
3911 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3912 class="
3913 <?php
3914 if ( $field->is_required ) {
3915 echo 'required_field';
3916 }
3917 ?>
3918 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3919
3920 <?php
3921
3922 if ( ! is_admin() ) {
3923 ?>
3924 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3925 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3926 <?php
3927 if ( $field->is_required ) {
3928 echo '<span>*</span>';
3929 }
3930 ?>
3931 </label>
3932 <?php } ?>
3933
3934 <?php wp_editor( $content, $editor_id, $args ); ?>
3935
3936 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3937 <?php if ( $field->is_required ) { ?>
3938 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3939 <?php } ?>
3940 </div>
3941 <?php
3942 }
3943 $html = ob_get_clean();
3944 }
3945
3946 return $html;
3947 }
3948
3949 /**
3950 * Form field template for fieldset field type.
3951 *
3952 * @param string $html Form field html
3953 * @param object $field Field info.
3954 * @param string $value Form field default value.
3955 * @param string $form_type Form type
3956 *
3957 * @return string Modified form field html.
3958 * @package userswp
3959 *
3960 * @since 1.0.0
3961 */
3962 public function form_input_fieldset( $html, $field, $value, $form_type ) {
3963 // Check if there is a custom field specific filter.
3964 if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
3965 $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3966 }
3967
3968 // If no html then we run the standard output.
3969 if ( empty( $html ) ) {
3970
3971 ob_start(); // Start buffering;
3972 $site_title = uwp_get_form_label( $field );
3973 ?>
3974 <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
3975 <?php echo esc_html( $site_title ); ?>
3976 <?php
3977 if ( $field->help_text != '' ) {
3978 echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
3979 }
3980 ?>
3981 </h3>
3982 <?php
3983 $html = ob_get_clean();
3984 }
3985
3986 return $html;
3987 }
3988
3989 /**
3990 * Form field template for url field type.
3991 *
3992 * @param string $html Form field html
3993 * @param object $field Field info.
3994 * @param string $value Form field default value.
3995 * @param string $form_type Form type
3996 *
3997 * @return string Modified form field html.
3998 * @package userswp
3999 *
4000 * @since 1.0.0
4001 */
4002 public function form_input_url( $html, $field, $value, $form_type ) {
4003
4004 // Check if there is a custom field specific filter.
4005 if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
4006 $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4007 }
4008
4009 // If no html then we run the standard output.
4010 if ( empty( $html ) ) {
4011
4012 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4013 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4014 $bs_sr_only = $design_style ? 'sr-only' : '';
4015 $bs_form_control = $design_style ? 'form-control' : '';
4016
4017 ob_start(); // Start buffering;
4018 $site_title = uwp_get_form_label( $field );
4019 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
4020 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4021
4022 // bootstrap
4023 if ( $design_style ) {
4024 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4025
4026 echo aui()->input(
4027 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4028 'type' => 'url',
4029 'id' => esc_attr( $field->htmlvar_name ),
4030 'name' => esc_attr( $field->htmlvar_name ),
4031 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4032 'title' => esc_html( $site_title ),
4033 'value' => esc_attr( $value ),
4034 'required' => (bool) $field->is_required,
4035 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4036 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4037 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4038 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4039 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4040 )
4041 );
4042 } else {
4043 ?>
4044 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4045 class="
4046 <?php
4047 if ( $field->is_required ) {
4048 echo 'required_field';
4049 }
4050 ?>
4051 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4052
4053 <?php
4054 if ( ! is_admin() ) {
4055 ?>
4056 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4057 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4058 <?php
4059 if ( $field->is_required ) {
4060 echo '<span>*</span>';
4061 }
4062 ?>
4063 </label>
4064 <?php } ?>
4065
4066 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4067 class="
4068 <?php
4069 //echo $field->css_class;
4070 ?>
4071 uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4072 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4073 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4074 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4075 title="<?php echo esc_attr( $site_title ); ?>"
4076 <?php
4077 if ( $field->is_required == 1 ) {
4078 echo 'required="required"';
4079 }
4080 ?>
4081 type="url"
4082 oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
4083 onchange="try{setCustomValidity('')}catch(e){}"
4084 />
4085 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4086 <?php if ( $field->is_required ) { ?>
4087 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4088 <?php } ?>
4089 </div>
4090
4091 <?php
4092 }
4093
4094 $html = ob_get_clean();
4095 }
4096
4097 return $html;
4098 }
4099
4100 /**
4101 * Form field template for email field type.
4102 *
4103 * @param string $html Form field html
4104 * @param object $field Field info.
4105 * @param string $value Form field default value.
4106 * @param string $form_type Form type
4107 *
4108 * @return string Modified form field html.
4109 * @package userswp
4110 *
4111 * @since 1.0.0
4112 */
4113 public function form_input_email( $html, $field, $value, $form_type ) {
4114
4115 // Check if there is a custom field specific filter.
4116 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
4117 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4118 }
4119
4120 // If no html then we run the standard output.
4121 if ( empty( $html ) ) {
4122
4123 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4124 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4125 $bs_sr_only = $design_style ? 'sr-only' : '';
4126 $bs_form_control = $design_style ? 'form-control' : '';
4127
4128 ob_start(); // Start buffering;
4129 $site_title = uwp_get_form_label( $field );
4130 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4131 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4132
4133 $is_forgot_email = ( $form_type === 'forgot' && $field->htmlvar_name === 'email' );
4134 $input_type = $is_forgot_email ? 'text' : 'email';
4135 if ( $is_forgot_email ) {
4136 $site_title = __( 'Username or Email', 'userswp' );
4137 $placeholder = $site_title . ( ! empty( $field->is_required ) ? ' *' : '' );
4138 } else {
4139 $placeholder = uwp_get_field_placeholder( $field );
4140 }
4141
4142 if ( $design_style ) {
4143 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4144
4145 echo aui()->input(
4146 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4147 'type' => $input_type,
4148 'id' => esc_attr( $field->htmlvar_name ),
4149 'name' => esc_attr( $field->htmlvar_name ),
4150 'placeholder' => esc_attr( $placeholder ),
4151 'title' => esc_html( $site_title ),
4152 'value' => esc_attr( wp_unslash( $value ) ),
4153 'required' => (bool) $field->is_required,
4154 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4155 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4156 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4157 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4158 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4159 )
4160 );
4161 } else {
4162 ?>
4163 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4164 class="
4165 <?php
4166 if ( $field->is_required ) {
4167 echo 'required_field';
4168 }
4169 ?>
4170 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4171
4172 <?php
4173 if ( ! is_admin() ) {
4174 ?>
4175 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4176 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4177 <?php
4178 if ( $field->is_required ) {
4179 echo '<span>*</span>';
4180 }
4181 ?>
4182 </label>
4183 <?php } ?>
4184
4185 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4186 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4187 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4188 placeholder="<?php echo esc_attr( $placeholder ); ?>"
4189 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4190 title="<?php echo esc_attr( $site_title ); ?>"
4191 <?php
4192 if ( $field->is_required == 1 ) {
4193 echo 'required="required"';
4194 }
4195 ?>
4196 type="<?php echo esc_attr( $input_type ); ?>"
4197 />
4198 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4199 <?php if ( $field->is_required ) { ?>
4200 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4201 <?php } ?>
4202 </div>
4203
4204
4205 <?php
4206 }
4207 $html = ob_get_clean();
4208
4209 }
4210
4211 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
4212 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
4213 }
4214
4215 return $html;
4216 }
4217
4218 /**
4219 * Form field template for password field type.
4220 *
4221 * @param string $html Form field html
4222 * @param object $field Field info.
4223 * @param string $value Form field default value.
4224 * @param string $form_type Form type
4225 *
4226 * @return string Modified form field html.
4227 * @package userswp
4228 *
4229 * @since 1.0.0
4230 */
4231 public function form_input_password( $html, $field, $value, $form_type ) {
4232
4233 // Check if there is a custom field specific filter.
4234 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
4235 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4236 }
4237
4238 // If no html then we run the standard output.
4239 if ( empty( $html ) ) {
4240
4241 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4242 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4243 $bs_sr_only = $design_style ? 'sr-only' : '';
4244 $bs_form_control = $design_style ? 'form-control' : '';
4245
4246 ob_start(); // Start buffering;
4247 $site_title = uwp_get_form_label( $field );
4248
4249 if ( $design_style ) {
4250 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4251 $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4252 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4253 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4254
4255 echo aui()->input(
4256 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4257 'type' => 'password',
4258 'id' => esc_attr( $field->htmlvar_name ),
4259 'name' => esc_attr( $field->htmlvar_name ),
4260 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4261 'title' => esc_html( $site_title ),
4262 'value' => esc_attr( $value ),
4263 'required' => (bool) $field->is_required,
4264 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4265 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4266 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4267 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4268 'wrap_class' => esc_attr( $wrap_class ),
4269 )
4270 );
4271 } else {
4272 ?>
4273 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
4274 <?php
4275 if ( $field->is_required ) {
4276 echo 'required_field';
4277 }
4278 ?>
4279 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4280 <?php
4281 if ( ! is_admin() ) {
4282 ?>
4283 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4284 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4285 <?php
4286 if ( $field->is_required ) {
4287 echo '<span>*</span>';
4288 }
4289 ?>
4290 </label>
4291 <?php } ?>
4292
4293 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4294 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4295 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4296 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4297 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4298 title="<?php echo esc_attr( $site_title ); ?>"
4299 <?php
4300 if ( $field->is_required == 1 ) {
4301 echo 'required="required"';
4302 }
4303 ?>
4304 type="password"
4305 />
4306 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4307 <?php if ( $field->is_required ) { ?>
4308 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4309 <?php } ?>
4310 </div>
4311
4312
4313 <?php
4314 }
4315
4316 $html = ob_get_clean();
4317 }
4318
4319 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
4320 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
4321 }
4322
4323 return $html;
4324 }
4325
4326 /**
4327 * Form field template for Phone field.
4328 *
4329 * @param string $html Form field html
4330 * @param object $field Field info.
4331 * @param string $value Form field default value.
4332 * @param string $form_type Form type
4333 *
4334 * @return string $html Modified form field html.
4335 * @since 1.0.0
4336 *
4337 */
4338 public function form_input_phone( $html, $field, $value, $form_type ) {
4339 if ( empty( $html ) ) {
4340 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4341 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4342 $bs_sr_only = $design_style ? 'sr-only' : '';
4343 $bs_form_control = $design_style ? 'form-control' : '';
4344 ob_start(); // Start buffering;
4345 $site_title = uwp_get_form_label( $field );
4346 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4347 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4348
4349 if ( $design_style ) {
4350 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4351
4352 echo aui()->input(
4353 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4354 'type' => 'tel',
4355 'id' => esc_attr( $field->htmlvar_name ),
4356 'name' => esc_attr( $field->htmlvar_name ),
4357 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4358 'title' => esc_html( $site_title ),
4359 'value' => esc_attr( $value ),
4360 'required' => (bool) $field->is_required,
4361 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4362 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4363 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4364 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4365 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4366 )
4367 );
4368 } else {
4369 ?>
4370 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4371 class="
4372 <?php
4373 if ( $field->is_required ) {
4374 echo 'required_field';
4375 }
4376 ?>
4377 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4378 <?php
4379 if ( ! is_admin() ) {
4380 ?>
4381 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4382 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4383 <?php
4384 if ( $field->is_required ) {
4385 echo '<span>*</span>';
4386 }
4387 ?>
4388 </label>
4389 <?php } ?>
4390 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4391 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4392 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4393 title="<?php echo esc_attr( $site_title ); ?>"
4394 <?php
4395 if ( $field->for_admin_use == 1 ) {
4396 echo 'readonly="readonly"';
4397 }
4398 ?>
4399 <?php
4400 if ( $field->is_required == 1 ) {
4401 echo 'required="required"';
4402 }
4403 ?>
4404 type="tel"
4405 value="<?php echo esc_html( $value ); ?>">
4406 </div>
4407 <?php
4408 }
4409 $html = ob_get_clean();
4410 }
4411
4412 return $html;
4413 }
4414
4415 public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
4416
4417 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4418 $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4419 if ( empty( $reg_gdpr ) ) {
4420 $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4421 }
4422
4423 if ( ! empty( $reg_gdpr ) ) {
4424
4425 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4426 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4427 $bs_form_control = $design_style ? 'form-check-input' : '';
4428 $site_title = uwp_get_form_label( $field );
4429 $field->htmlvar_name = 'register_gdpr';
4430 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4431
4432 $gdpr_page = get_permalink( $reg_gdpr );
4433 $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4434 $link_end = '</a>';
4435 $field_desc = uwp_get_field_description( $field, '' );
4436 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4437 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4438 $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4439 $checked = $value == '1' ? true : false;
4440
4441 ob_start(); // Start buffering;
4442
4443 // bootstrap
4444 if ( $design_style ) {
4445 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4446 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4447
4448 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4449 array(
4450 'id' => esc_attr( $id ),
4451 'name' => esc_attr( $field->htmlvar_name ),
4452 'type' => 'checkbox',
4453 'value' => '1',
4454 'title' => esc_html( $site_title ),
4455 'label' => wp_kses_post( $content . $required ),
4456 'label_show' => true,
4457 'required' => ! empty( $field->is_required ) ? true : false,
4458 'checked' => (bool) $checked,
4459 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4460 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4461 )
4462 );
4463
4464 } else {
4465 ?>
4466 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4467 class="
4468 <?php
4469 if ( $field->is_required ) {
4470 echo 'required_field';
4471 }
4472 ?>
4473 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4474 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4475 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4476 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4477 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4478 title="<?php echo esc_attr( $site_title ); ?>"
4479 <?php
4480 if ( $value == '1' ) {
4481 echo 'checked="checked"';
4482 }
4483 ?>
4484 type="<?php echo esc_attr( $field->field_type ); ?>"
4485 value="1">
4486 <?php
4487 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4488 ?>
4489 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4490 <?php if ( $field->is_required ) { ?>
4491 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4492 <?php } ?>
4493 </div>
4494
4495 <?php
4496 }
4497
4498 $html = ob_get_clean();
4499
4500 } else {
4501 $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4502 }
4503
4504 return $html;
4505 }
4506
4507 public function form_input_register_tos( $html, $field, $value, $form_type ) {
4508
4509 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4510 $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4511 if ( empty( $reg_tos ) ) {
4512 $reg_tos = uwp_get_option( 'register_terms_page', false );
4513 }
4514
4515 if ( ! empty( $reg_tos ) ) {
4516
4517 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4518 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4519 $bs_form_control = $design_style ? 'form-check-input' : '';
4520
4521 $site_title = uwp_get_form_label( $field );
4522 $terms_page = get_permalink( $reg_tos );
4523 $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4524 $link_end = '</a>';
4525 $field_desc = uwp_get_field_description( $field, '' );
4526 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4527 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4528 $field->htmlvar_name = 'register_tos';
4529 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4530
4531 $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4532 $checked = $value == '1' ? true : false;
4533
4534 ob_start();
4535
4536 if ( $design_style ) {
4537 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4538 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4539
4540 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4541 array(
4542 'id' => esc_attr( $id ),
4543 'name' => esc_attr( $field->htmlvar_name ),
4544 'type' => 'checkbox',
4545 'value' => '1',
4546 'title' => esc_html( $site_title ),
4547 'label' => wp_kses_post( $content . $required ),
4548 'label_show' => true,
4549 'required' => ! empty( $field->is_required ) ? true : false,
4550 'checked' => (bool) $checked,
4551 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4552 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4553 )
4554 );
4555
4556 } else {
4557 ?>
4558 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4559 class="
4560 <?php
4561 if ( $field->is_required ) {
4562 echo 'required_field';
4563 }
4564 ?>
4565 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4566 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4567 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4568 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4569 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4570 title="<?php echo esc_attr( $site_title ); ?>"
4571 <?php
4572 if ( $value == '1' ) {
4573 echo 'checked="checked"';
4574 }
4575 ?>
4576 type="<?php echo esc_attr( $field->field_type ); ?>"
4577 value="1">
4578 <?php
4579 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4580 ?>
4581 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4582 <?php if ( $field->is_required ) { ?>
4583 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4584 <?php } ?>
4585 </div>
4586
4587 <?php
4588
4589 }
4590
4591 $html = ob_get_clean();
4592
4593 } else {
4594 $html = '<input type="hidden" name="register_tos" value="-1"/>';
4595 }
4596
4597 return $html;
4598 }
4599
4600 /**
4601 * Adds enctype tag in form for file fields.
4602 *
4603 * @return void
4604 * @package userswp
4605 *
4606 * @since 1.0.0
4607 */
4608 function add_multipart_to_admin_edit_form() {
4609 global $wpdb;
4610 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4611 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4612 if ( $fields ) {
4613 echo 'enctype="multipart/form-data"';
4614 }
4615 }
4616
4617 /**
4618 * Handles UsersWP custom field requests from admin.
4619 *
4620 * @param int $user_id User ID.
4621 *
4622 * @return void
4623 * @since 1.0.0
4624 * @package userswp
4625 *
4626 */
4627 public function update_profile_extra_admin_edit( $user_id ) {
4628 global $wpdb;
4629 $file_obj = new UsersWP_Files();
4630 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4631 //Normal fields
4632 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4633 if ( $fields ) {
4634 if ( isset( $_POST['locale'] ) ) {
4635 $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4636 }
4637 $result = uwp_validate_fields( $_POST, 'account', $fields );
4638 if ( is_wp_error( $result ) ) {
4639 die( wp_kses_post( $result->get_error_message() ) );
4640 }
4641 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4642 $display_name = $result['display_name'];
4643 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4644 $display_name = $result['first_name'] . ' ' . $result['last_name'];
4645 } else {
4646 $user_info = get_userdata( $user_id );
4647 $display_name = $user_info->user_login;
4648 }
4649 $result['display_name'] = $display_name;
4650 if ( ! is_wp_error( $result ) ) {
4651 foreach ( $fields as $field ) {
4652 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4653 if ( $value == '0' || ! empty( $value ) ) {
4654 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4655 }
4656 }
4657 }
4658 }
4659
4660 //File fields
4661 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4662 if ( $fields ) {
4663 $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4664 if ( ! is_wp_error( $result ) ) {
4665 foreach ( $fields as $field ) {
4666 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4667 if ( $value == '0' || ! empty( $value ) ) {
4668 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4669 }
4670 }
4671 }
4672 }
4673 }
4674
4675 /**
4676 * Form field template for country field.
4677 *
4678 * @param string $html Form field html
4679 * @param object $field Field info.
4680 * @param string $value Form field default value.
4681 * @param string $form_type Form type
4682 *
4683 * @return string Modified form field html.
4684 * @package userswp
4685 *
4686 * @since 1.0.0
4687 */
4688 public function form_input_select_country( $html, $field, $value, $form_type ) {
4689
4690 // If no html then we run the standard output.
4691 if ( empty( $html ) ) {
4692
4693 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4694 $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4695 $bs_sr_only = $design_style ? 'sr-only' : '';
4696 $bs_form_control = $design_style ? 'form-control' : '';
4697
4698 ob_start(); // Start buffering;
4699 ?>
4700 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4701
4702 <?php
4703 $site_title = uwp_get_form_label( $field );
4704
4705 if ( ! is_admin() && ! wp_doing_ajax() ) {
4706 ?>
4707 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4708 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4709 <?php
4710 if ( $field->is_required ) {
4711 echo '<span class="text-danger">*</span>';
4712 }
4713 ?>
4714 </label>
4715 <?php
4716 }
4717 // if value empty set the default
4718 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4719 $value = $field->default_value;
4720 }
4721 if ( $value === false ) {
4722 $value = '';
4723 }
4724 $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4725 $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4726
4727 $htmlvar_name = $field->htmlvar_name;
4728 if ( wp_doing_ajax() ) {
4729 $htmlvar_name .= '_ajax';
4730 }
4731 ?>
4732 <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4733 <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4734 <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4735 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4736 <?php if ( $field->is_required ) { ?>
4737 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4738 <?php } ?>
4739 </div>
4740 <?php
4741 $html = ob_get_clean();
4742 }
4743
4744 return $html;
4745 }
4746
4747 /**
4748 * Form field template for language field.
4749 *
4750 * @param string $html Form field html
4751 * @param object $field Field info.
4752 * @param string $value Form field default value.
4753 * @param string $form_type Form type
4754 *
4755 * @return string Modified form field html.
4756 * @package userswp
4757 *
4758 * @since 1.0.0
4759 */
4760 public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4761
4762 // If no html then we run the standard output.
4763 if ( empty( $html ) ) {
4764
4765 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4766 $bs_form_group = $design_style ? 'form-group m-0' : '';
4767 $bs_sr_only = $design_style ? 'sr-only' : '';
4768 $bs_form_control = $design_style ? 'form-control' : '';
4769 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4770 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4771
4772 ob_start(); // Start buffering;
4773
4774 ?>
4775 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4776 class="
4777 <?php
4778 if ( $field->is_required ) {
4779 echo 'required_field';
4780 }
4781 ?>
4782 uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4783
4784 <?php
4785 $site_title = uwp_get_form_label( $field );
4786 if ( ! is_admin() && ! wp_doing_ajax() ) {
4787 ?>
4788 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4789 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4790 <?php
4791 if ( $field->is_required ) {
4792 echo '<span class="text-danger">*</span>';
4793 }
4794 ?>
4795 </label>
4796 <?php } ?>
4797
4798 <?php
4799 if ( empty( $field->default_value ) ) {
4800 $field->default_value = 'site-default';
4801 }
4802
4803 // if value empty set the default
4804 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4805 $value = $field->default_value;
4806 }
4807
4808 require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4809 $translations = wp_get_available_translations();
4810 $available_languages = get_available_languages();
4811 $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
4812
4813 foreach ( $available_languages as $locale ) {
4814 if ( isset( $translations[ $locale ] ) ) {
4815 $translation = $translations[ $locale ];
4816 $languages[ $translation['language'] ] = $translation['native_name'];
4817
4818 // Remove installed language from available translations.
4819 unset( $translations[ $locale ] );
4820 } else {
4821 $languages[ $locale ] = $translation[ $locale ];
4822 }
4823 }
4824
4825 if ( $design_style ) {
4826
4827 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4828
4829 echo aui()->select(
4830 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4831 'id' => esc_attr( $field->htmlvar_name ),
4832 'name' => esc_attr( $field->htmlvar_name ),
4833 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4834 'title' => esc_attr( $site_title ),
4835 'value' => esc_attr( $value ),
4836 'required' => (bool) $field->is_required,
4837 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4838 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4839 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4840 'label' => wp_kses_post( $site_title . $required ),
4841 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4842 'select2' => true,
4843 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4844 )
4845 );
4846 } else {
4847 ?>
4848 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4849 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4850 title="<?php echo esc_attr( $site_title ); ?>"
4851 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4852 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4853 </select>
4854 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4855 <?php if ( $field->is_required ) { ?>
4856 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4857 <?php
4858 }
4859 }
4860
4861 $html = ob_get_clean();
4862 }
4863
4864 return $html;
4865 }
4866
4867 /**
4868 * Adds confirm password field in forms.
4869 *
4870 * @param string $html Form field html
4871 * @param object $field Field info.
4872 * @param string $value Form field default value.
4873 * @param string $form_type Form type
4874 *
4875 * @return string Modified form field html.
4876 * @package userswp
4877 *
4878 * @since 1.0.0
4879 */
4880 public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4881 if ( $form_type == 'register' ) {
4882 //confirm password field
4883 $extra = array();
4884 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4885 $extra = unserialize( $field->extra_fields );
4886 }
4887
4888 $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4889 if ( $enable_confirm_password_field == '1' ) {
4890
4891 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4892 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4893 $bs_sr_only = $design_style ? 'sr-only' : '';
4894 $bs_form_control = $design_style ? 'form-control' : '';
4895 $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4896 $required = '';
4897 if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4898 $placeholder .= ' *';
4899 $required = ' <span class="text-danger">*</span>';
4900 }
4901 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4902 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4903 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4904
4905 ob_start(); // Start buffering;
4906
4907 if ( $design_style ) {
4908
4909 echo aui()->input(
4910 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4911 'type' => 'password',
4912 'id' => 'confirm_password',
4913 'name' => 'confirm_password',
4914 'placeholder' => esc_attr( $placeholder ),
4915 'title' => esc_attr( $site_title ),
4916 'value' => esc_attr( $value ),
4917 'required' => (bool) $field->is_required,
4918 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4919 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4920 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4921 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4922 'wrap_class' => esc_attr( $wrap_class ),
4923 )
4924 );
4925 } else {
4926 ?>
4927 <div id="uwp_account_confirm_password_row"
4928 class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4929
4930 <?php
4931
4932 if ( ! is_admin() ) {
4933 ?>
4934 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4935 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4936 <?php
4937 if ( $field->is_required ) {
4938 echo '<span>*</span>';
4939 }
4940 ?>
4941 </label>
4942 <?php } ?>
4943 <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4944 </div>
4945
4946 <?php
4947 }
4948 $confirm_html = ob_get_clean();
4949 $html = $html . $confirm_html;
4950 }
4951 }
4952
4953 return $html;
4954 }
4955
4956 /**
4957 * Adds confirm email field in forms.
4958 *
4959 * @param string $html Form field html
4960 * @param object $field Field info.
4961 * @param string $value Form field default value.
4962 * @param string $form_type Form type
4963 *
4964 * @return string Modified form field html.
4965 * @package userswp
4966 *
4967 * @since 1.0.0
4968 */
4969 public function register_confirm_email_field( $html, $field, $value, $form_type ) {
4970 if ( $form_type == 'register' ) {
4971 //confirm email field
4972 $extra = array();
4973 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4974 $extra = unserialize( $field->extra_fields );
4975 }
4976 $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
4977 if ( $enable_confirm_email_field == '1' ) {
4978
4979 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4980 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4981 $bs_sr_only = $design_style ? 'sr-only' : '';
4982 $bs_form_control = $design_style ? 'form-control' : '';
4983 $site_title = __( 'Confirm Email', 'userswp' );
4984 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4985 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4986
4987 ob_start();
4988
4989 if ( $design_style ) {
4990 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4991
4992 echo aui()->input(
4993 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4994 'type' => 'email',
4995 'id' => esc_attr( $field->htmlvar_name ),
4996 'name' => 'confirm_email',
4997 'placeholder' => esc_attr( $site_title ),
4998 'title' => esc_attr( $site_title ),
4999 'value' => esc_attr( $value ),
5000 'required' => (bool) $field->is_required,
5001 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
5002 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
5003 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
5004 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
5005 )
5006 );
5007 } else {
5008 ?>
5009 <div id="uwp_account_confirm_email_row"
5010 class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
5011
5012 <?php
5013
5014 if ( ! is_admin() ) {
5015 ?>
5016 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
5017 <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
5018 <?php
5019 if ( $field->is_required ) {
5020 echo '<span>*</span>';
5021 }
5022 ?>
5023 </label>
5024 <?php } ?>
5025
5026 <input name="confirm_email"
5027 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
5028 id="uwp_account_confirm_email"
5029 placeholder="<?php echo esc_attr( $site_title ); ?>"
5030 value=""
5031 title="<?php echo esc_attr( $site_title ); ?>"
5032 <?php echo 'required="required"'; ?>
5033 type="email"
5034 />
5035 </div>
5036 <?php
5037 }
5038 $confirm_html = ob_get_clean();
5039 $html = $html . $confirm_html;
5040 }
5041 }
5042
5043 return $html;
5044 }
5045
5046 /**
5047 * Handles the privacy form submission.
5048 *
5049 * @return void
5050 * @package userswp
5051 *
5052 * @since 1.0.0
5053 */
5054 public function privacy_submit_handler() {
5055 if ( isset( $_POST['uwp_privacy_submit'] ) ) {
5056 if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
5057 return;
5058 }
5059
5060 global $wpdb, $uwp_notices;
5061
5062 // Save fields privacy settings
5063 $extra_where = "AND is_public='2'";
5064 $fields = get_account_form_fields( $extra_where );
5065 $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
5066 $user_id = get_current_user_id();
5067 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
5068
5069 $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
5070 if ( ! empty( $user_meta_info->user_privacy ) ) {
5071 $public_fields = explode( ',', $user_meta_info->user_privacy );
5072 } else {
5073 $public_fields = array();
5074 }
5075
5076 if ( $fields ) {
5077
5078 foreach ( $fields as $field ) {
5079 $field_name = $field->htmlvar_name . '_privacy';
5080 $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
5081
5082 if ( $field_value == 'no' ) {
5083 if ( ! in_array( $field_name, $public_fields ) ) {
5084 $public_fields[] = $field_name;
5085 }
5086 } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
5087 unset( $public_fields[ $field_name ] );
5088 }
5089 }
5090
5091 $value = implode( ',', $public_fields );
5092 uwp_update_usermeta( $user_id, 'user_privacy', $value );
5093 }
5094
5095 // Save tabs privacy settings
5096 $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
5097 $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
5098
5099 if ( $tabs ) {
5100 $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
5101 $do_tabs_update = false;
5102 foreach ( $tabs as $tab ) {
5103 $field_name = $tab->tab_key . '_tab_privacy';
5104
5105 if ( isset( $_POST[ $field_name ] ) ) {
5106 $do_tabs_update = true;
5107 $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
5108
5109 if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
5110 unset( $public_fields[ $field_name ] );
5111 } else {
5112 $public_fields[ $field_name ] = $field_value;
5113 }
5114 }
5115 }
5116
5117 if ( $do_tabs_update ) {
5118 uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
5119 }
5120 }
5121
5122 if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
5123 update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
5124 } else {
5125 update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
5126 }
5127
5128 $make_profile_private = uwp_can_make_profile_private();
5129 if ( $make_profile_private ) {
5130 $field_name = 'uwp_make_profile_private';
5131 if ( isset( $_POST[ $field_name ] ) ) {
5132 $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
5133 $user_id = get_current_user_id();
5134 update_user_meta( $user_id, $field_name, $value );
5135 }
5136 }
5137
5138 $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
5139 $message = aui()->alert(
5140 array(
5141 'type' => 'success',
5142 'content' => $message,
5143 )
5144 );
5145 $uwp_notices[] = array( 'account' => $message );
5146
5147 }
5148 }
5149
5150 /**
5151 * Get the ajax login form.
5152 *
5153 * @since 1.2.0
5154 */
5155 public function ajax_login_form() {
5156
5157 // add the modal error container
5158 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5159
5160 $args = array(
5161 'form_title' => __( 'Login', 'userswp' ),
5162 );
5163
5164 // get the form
5165 ob_start();
5166 uwp_get_template( 'bootstrap/login.php', $args );
5167 $form = ob_get_clean();
5168
5169 // bs5
5170 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5171 $form = aui_bs_convert_sd_output( $form );
5172 }
5173 // send ajax response
5174 wp_send_json_success( $form );
5175 }
5176
5177 /**
5178 * Get the ajax register form.
5179 *
5180 * @since 1.2.0
5181 */
5182 public function ajax_register_form() {
5183
5184 // add the modal error container
5185 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5186
5187 global $wp_scripts;
5188 if ( empty( $wp_scripts ) ) {
5189 $wp_scripts = wp_scripts();
5190 }
5191
5192 // do we need country code script in ajax?
5193 $country_field = false;
5194 $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
5195
5196 if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
5197 $form_id = (int)$_POST['form_id'];
5198 } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
5199 $form_id = reset( $lightbox_forms );
5200 } else {
5201 $form_id = 1;
5202 }
5203
5204 $fields = get_register_form_fields( $form_id );
5205 if ( ! empty( $fields ) ) {
5206 foreach ( $fields as $field ) {
5207 if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
5208 $country_field = true;
5209 }
5210 }
5211 }
5212
5213 ob_start();
5214
5215 // maybe add country code JS
5216 if ( $country_field ) {
5217 $country_data = uwp_get_country_data();
5218 echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
5219 echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
5220 }
5221
5222 $args = array( 'form_title' => '' );
5223 if ( $form_id > 0 ) {
5224 $args['id'] = $form_id;
5225 }
5226
5227 $args['limit'] = $lightbox_forms;
5228
5229 // get template
5230 uwp_get_template( 'bootstrap/register.php', $args );
5231
5232 // only show the JS if NOT doing a block render
5233 if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
5234 // load scripts
5235 $wp_scripts->do_item( 'zxcvbn-async' );
5236 $wp_scripts->do_item( 'wp-hooks' );
5237 $wp_scripts->do_item( 'wp-i18n' );
5238 $wp_scripts->do_item( 'password-strength-meter' );
5239 ?>
5240 <script>
5241 // Password strength indicator script
5242 jQuery(function ($) {
5243
5244 // Load the settings like WP does.
5245 var first, s;
5246 s = document.createElement('script');
5247 s.src = _zxcvbnSettings.src;
5248 s.type = 'text/javascript';
5249 s.async = true;
5250 first = document.getElementsByTagName('script')[0];
5251 first.parentNode.insertBefore(s, first);
5252
5253 // Enable any pass inputs.
5254 $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
5255 function (event) {
5256 var $form = $(this).closest('form');
5257 if( ! $form.hasClass('uwp-login-form') ) {
5258 uwp_checkPasswordStrength(
5259 $form.find('input[name=password]'),
5260 $form.find('input[name=confirm_password]'),
5261 $form.find('#uwp-password-strength'),
5262 $form.find('button[type="submit"], input[type="submit"]'),
5263 ['black', 'listed', 'word']
5264 );
5265 }
5266 }
5267 );
5268 });
5269 </script>
5270 <?php
5271 }
5272 $form = ob_get_clean();
5273
5274 // bs5
5275 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5276 $form = aui_bs_convert_sd_output( $form );
5277 }
5278
5279 // send ajax response
5280 wp_send_json_success( $form );
5281 }
5282
5283 /**
5284 * Get the ajax forgot password form.
5285 *
5286 * @since 1.2.0
5287 */
5288 public function ajax_forgot_password_form() {
5289
5290 // add the modal error container
5291 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5292 $args = array(
5293 'form_title' => '',
5294 'css_class' => ''
5295 );
5296 // get the form
5297 ob_start();
5298 uwp_get_template( 'bootstrap/forgot.php', $args );
5299 $form = ob_get_clean();
5300
5301 // bs5
5302 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5303 $form = aui_bs_convert_sd_output( $form );
5304 }
5305
5306 // send ajax response
5307 wp_send_json_success( $form );
5308 }
5309
5310 /**
5311 * Output the modal error container.
5312 *
5313 * @param string $type
5314 *
5315 * @since 1.2.0
5316 */
5317 public function modal_error_container( $type = '' ) {
5318 echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
5319 }
5320
5321 public function form_custom_html( $html, $field, $value, $form_type ) {
5322
5323 $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
5324
5325 return $html;
5326 }
5327 }
5328