PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.75
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.75
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
← All changes | includes/class-forms.php +8 -59 trunk → 1.2.75 View file →
@@ -219,16 +219,8 @@
219 219 if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 220 return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 221 }
222 222
223 - // Only allow cropping the image the current user just uploaded (normalized like $image_url).
224 - $pending_key = '_uwp_pending_' . $type . '_upload';
225 - $pending_url = get_user_meta( get_current_user_id(), $pending_key, true );
226 - $pending_url = $pending_url ? str_replace( array( 'https://', 'http://' ), '', $this->normalize_url( esc_url( $pending_url ) ) ) : '';
227 - if ( empty( $pending_url ) || $pending_url !== $_image_url ) {
228 - return new WP_Error( 'crop_session_expired', __( 'Your image upload could not be verified. Please upload the image again.', 'userswp' ) );
229 - }
230 -
231 223 $filetype = wp_check_filetype( $image_url );
232 224
233 225 if ( empty( $filetype['ext'] ) ) {
234 226 return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
@@ -289,15 +281,8 @@
289 281 wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
290 282 }
291 283
292 284 $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
293 -
294 - // Resize returns a path even on failure; bail before touching meta or files so the crop can be retried.
295 - clearstatcache( true, $thumb_image_location );
296 - if ( ! is_file( $thumb_image_location ) ) {
297 - return new WP_Error( 'crop_failed', __( 'Could not crop the image. Please try again.', 'userswp' ) );
298 - }
299 -
300 285 $cropped = str_replace( $upload_path, $upload_url, $cropped );
301 286
302 287 // Remove previous avatar/banner
303 288 $unlink_img = '';
@@ -312,34 +297,13 @@
312 297 } else {
313 298 uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
314 299 }
315 300
316 - $original_key = '_uwp_' . $type . '_original';
317 - $prev_original = get_user_meta( $user_id, $original_key, true );
318 -
319 - delete_user_meta( get_current_user_id(), $pending_key );
320 - $relative_original = ltrim( wp_normalize_path( str_replace( wp_normalize_path( untrailingslashit( $upload_path ) ), '', wp_normalize_path( $image_path ) ) ), '/' );
321 - update_user_meta( $user_id, $original_key, $relative_original );
322 -
323 - // Enforce containment inside uploads before deleting, matching upload_file_remove().
324 - $real_upload_path = realpath( $upload_path );
325 - $real_unlink_img = $unlink_img ? realpath( $unlink_img ) : false;
326 -
327 - if ( $real_upload_path && $real_unlink_img && realpath( $thumb_image_location ) !== $real_unlink_img
328 - && false !== strpos( basename( $real_unlink_img ), $thumb_postfix . '.' )
329 - && 0 === strpos( $real_unlink_img, $real_upload_path . DIRECTORY_SEPARATOR )
330 - && is_file( $real_unlink_img ) ) {
331 - wp_delete_file( $real_unlink_img );
332 -
333 - // Delete the previous source only if it is the exact file this user cropped.
334 - $unlink_ori_img = str_replace( $thumb_postfix . '.', '.', $real_unlink_img );
335 - $real_unlink_ori_img = realpath( $unlink_ori_img );
336 - $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false;
337 - if ( $expected_original && $real_unlink_ori_img && $expected_original === $real_unlink_ori_img
338 - && realpath( $image_path ) !== $real_unlink_ori_img
339 - && 0 === strpos( $real_unlink_ori_img, $real_upload_path . DIRECTORY_SEPARATOR )
340 - && is_file( $real_unlink_ori_img ) ) {
341 - wp_delete_file( $real_unlink_ori_img );
301 + if ( $unlink_img && $unlink_img != $thumb_image_location && is_file( $unlink_img ) && file_exists( $unlink_img ) ) {
302 + @unlink( $unlink_img );
303 + $unlink_ori_img = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $unlink_img );
304 + if ( is_file( $unlink_ori_img ) && file_exists( $unlink_ori_img ) ) {
305 + @unlink( $unlink_ori_img );
342 306 }
343 307 }
344 308 }
345 309
@@ -426,13 +390,8 @@
426 390 } else {
427 391 // Do nothing
428 392 }
429 393
430 - if ( in_array( $type, array( 'avatar', 'banner' ), true ) ) {
431 - delete_user_meta( $user_id, '_uwp_' . $type . '_original' );
432 - delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' );
433 - }
434 -
435 394 if ( is_admin() ) {
436 395 if ( $user_id == get_current_user_id() ) {
437 396 $redirect_url = admin_url( 'profile.php' );
438 397 } else {
@@ -2678,29 +2637,19 @@
2678 2637 if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file )
2679 2638 && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2680 2639 wp_delete_file( $real_unlink_file );
2681 2640
2682 - // For avatar/banner, also remove the original (non-thumb) file, only if it is the exact file this user cropped.
2641 + // For avatar/banner, also remove the original (non-thumb) file.
2683 2642 if ( $type ) {
2684 - $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2643 + $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2685 2644 $real_unlink_ori_file = realpath( $unlink_ori_file );
2686 - $prev_original = get_user_meta( $user_id, '_uwp_' . $type . '_original', true );
2687 - $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false;
2688 2645
2689 - if ( $expected_original && $real_unlink_ori_file && $expected_original === $real_unlink_ori_file
2690 - && $real_unlink_ori_file !== $real_unlink_file
2691 - && is_file( $real_unlink_ori_file )
2646 + if ( $real_unlink_ori_file && is_file( $real_unlink_ori_file )
2692 2647 && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2693 2648 wp_delete_file( $real_unlink_ori_file );
2694 2649 }
2695 2650 }
2696 2651 }
2697 - }
2698 -
2699 - // Clear crop bookkeeping meta (pending upload is stored against the uploader).
2700 - if ( $type ) {
2701 - delete_user_meta( $user_id, '_uwp_' . $type . '_original' );
2702 - delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' );
2703 2652 }
2704 2653
2705 2654 wp_send_json_success();
2706 2655