PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.76
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.76
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
userswp / includes / class-files.php

class-files.php in UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 1.2.76, at includes/class-files.php

630 lines 23.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Files related functions
4 *
5 * This class defines all code necessary to upload files.
6 *
7 * @since 1.0.0
8 * @author GeoDirectory Team <[email protected]>
9 */
10 class UsersWP_Files {
11
12 /**
13 * Handles file upload request.
14 *
15 * @since 1.0.0
16 * @package userswp
17 * @param object $field Field info object.
18 * @param array $files $_FILES array.
19 * @return bool|array Uploaded file url info array.
20 */
21 public function handle_file_upload($field, $files ) {
22
23 if ( isset( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ]['name'] ) ) {
24
25 $extra_fields = unserialize($field->extra_fields);
26
27 $allowed_mime_types = array();
28 if (isset($extra_fields['uwp_file_types']) && !in_array("*", $extra_fields['uwp_file_types'])) {
29 $allowed_mime_types = $extra_fields['uwp_file_types'];
30 }
31
32 $allowed_mime_types = apply_filters('uwp_fields_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name);
33
34 $file_urls = array();
35 $files_to_upload = $this->prepare_files( $files[ $field->htmlvar_name ] );
36
37 $max_upload_size = $this->uwp_get_max_upload_size($field->form_type, $field->htmlvar_name);
38
39 if ( ! $max_upload_size ) {
40 $max_upload_size = 0;
41 }
42
43 foreach ( $files_to_upload as $file_key => $file_to_upload ) {
44
45 if (!empty($allowed_mime_types)) {
46 $ext = $this->get_file_type($file_to_upload['type']);
47
48 $allowed_error_text = implode(', ', $allowed_mime_types);
49 if ( !in_array( $ext , $allowed_mime_types ) )
50 return new WP_Error( 'validation-error', sprintf( __( 'Allowed files types are: %s', 'userswp' ), $allowed_error_text) );
51 }
52
53
54 if ( $file_to_upload['size'] > $max_upload_size) {
55 return new WP_Error( 'file-too-big', __( 'The uploaded file is too big. Maximum size allowed:'. $this->uwp_formatSizeUnits($max_upload_size), 'userswp' ) );
56 }
57
58
59 $error_result = apply_filters('uwp_handle_file_upload_error_checks', true, $field, $file_key, $file_to_upload);
60 if (is_wp_error($error_result)) {
61 return $error_result;
62 }
63
64 remove_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
65 if(in_array($field->htmlvar_name, array('avatar', 'banner'))){
66 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
67 }
68 $uploaded_file = $this->upload_file( $file_to_upload, array( 'file_key' => $file_key ) );
69 add_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
70
71 if ( is_wp_error( $uploaded_file ) ) {
72
73 return new WP_Error( 'validation-error', $uploaded_file->get_error_message() );
74
75 } else {
76
77 // Record this upload so the crop handler only accepts the user's own file.
78 if ( in_array( $field->htmlvar_name, array( 'avatar', 'banner' ), true ) && get_current_user_id() ) {
79 update_user_meta( get_current_user_id(), '_uwp_pending_' . $field->htmlvar_name . '_upload', $uploaded_file->url );
80 }
81
82 $file_urls[] = array(
83 'url' => $uploaded_file->url,
84 'path' => $uploaded_file->path,
85 'size' => $uploaded_file->size,
86 'name' => $uploaded_file->name,
87 'type' => $uploaded_file->type,
88 );
89
90 }
91
92 }
93
94 return current( $file_urls );
95
96 }
97 return true;
98
99 }
100
101 /**
102 * Formats the file size into human readable form.
103 *
104 * @since 1.0.0
105 * @package userswp
106 * @param int $bytes Size in Bytes.
107 * @return string Size in human readable form.
108 */
109 public function uwp_formatSizeUnits($bytes)
110 {
111 if ($bytes >= 1073741824)
112 {
113 $bytes = number_format($bytes / 1073741824, 2) . ' GB';
114 }
115 elseif ($bytes >= 1048576)
116 {
117 $bytes = number_format($bytes / 1048576, 2) . ' MB';
118 }
119 elseif ($bytes >= 1024)
120 {
121 $bytes = number_format($bytes / 1024, 2) . ' kB';
122 }
123 elseif ($bytes > 1)
124 {
125 $bytes = $bytes . ' bytes';
126 }
127 elseif ($bytes == 1)
128 {
129 $bytes = $bytes . ' byte';
130 }
131 else
132 {
133 $bytes = '0 bytes';
134 }
135
136 return $bytes;
137 }
138
139 /**
140 * Formats the file size in KB.
141 *
142 * @since 1.0.0
143 * @package userswp
144 * @param int $bytes Size in Bytes.
145 * @return int Size in KB.
146 */
147 public function uwp_formatSizeinKb($bytes)
148 {
149 $kb = $bytes / 1024;
150 return $kb;
151 }
152
153 /**
154 * Gets the size is bytes for given value.
155 *
156 * @since 1.0.0
157 * @package userswp
158 * @param string $val Size in human readable form.
159 * @return int Value in bytes.
160 */
161 public function uwp_get_size_in_bytes($val) {
162 $val = trim($val);
163 $last = strtolower($val[strlen($val)-1]);
164 $val = substr($val, 0, -1);
165 switch($last) {
166 // The 'G' modifier is available since PHP 5.1.0
167 case 'g':
168 $val *= (1024 * 1024 * 1024); //1073741824
169 break;
170 case 'm':
171 $val *= (1024 * 1024); //1048576
172 break;
173 case 'k':
174 $val *= 1024;
175 break;
176 }
177
178 return $val;
179 }
180
181 /**
182 * Processes the file upload.
183 *
184 * @since 1.0.0
185 * @package userswp
186 * @param array $file File info to upload.
187 * @param array $args File upload helper args.
188 * @return object Uploaded file info
189 */
190 public function upload_file( $file, $args = array() ) {
191
192 include_once ABSPATH . 'wp-admin/includes/file.php';
193 include_once ABSPATH . 'wp-admin/includes/media.php';
194 include_once ABSPATH . 'wp-admin/includes/image.php';
195
196 $args = wp_parse_args( $args, array(
197 'file_key' => '',
198 'file_label' => '',
199 'allowed_mime_types' => get_allowed_mime_types()
200 ) );
201
202 $uploaded_file = new stdClass();
203
204 if ( ! in_array( $file['type'], $args['allowed_mime_types'] ) ) {
205 if ( $args['file_label'] ) {
206 return new WP_Error( 'upload', sprintf( __( '"%s" (filetype %s) needs to be one of the following file types: %s', 'userswp' ), $args['file_label'], $file['type'], implode( ', ', array_keys( $args['allowed_mime_types'] ) ) ) );
207 } else {
208 return new WP_Error( 'upload', sprintf( __( 'Uploaded files need to be one of the following file types: %s', 'userswp' ), implode( ', ', array_keys( $args['allowed_mime_types'] ) ) ) );
209 }
210 } else {
211 $upload = wp_handle_upload( $file, apply_filters( 'uwp_handle_upload_overrides', array( 'test_form' => false ) ) );
212
213 if ( ! empty( $upload['error'] ) ) {
214 return new WP_Error( 'upload', $upload['error'] );
215 } else {
216 if ( ! empty( $upload['type'] ) && $upload['type'] != 'image/png' && strpos( $upload['type'], 'image/' ) === 0 ) {
217 // Fetch additional metadata from EXIF/IPTC.
218 $exif_meta = wp_read_image_metadata( $upload['file'] );
219
220 if ( ! empty( $exif_meta ) && is_array( $exif_meta ) && ! empty( $exif_meta['orientation'] ) && 1 !== (int) $exif_meta['orientation'] ) {
221 $editor = wp_get_image_editor( $upload['file'] );
222
223 if ( ! empty( $editor ) && ! is_wp_error( $editor ) ) {
224 // Rotate the whole original image if there is EXIF data and "orientation" is not 1.
225 $rotated = $editor->maybe_exif_rotate();
226 $rotated = $rotated === true ? $editor->save( $editor->generate_filename( 'rotated' ) ) : false;
227
228 if ( ! empty( $rotated ) && ! is_wp_error( $rotated ) && ! empty( $rotated['path'] ) ) {
229 $upload['url'] = str_replace( basename( $upload['url'] ), basename( $rotated['path'] ), $upload['url'] );
230 $upload['file'] = $rotated['path'];
231 }
232 }
233 }
234 }
235
236 $uploaded_file->url = $upload['url'];
237 $uploaded_file->name = basename( $upload['file'] );
238 $uploaded_file->path = $upload['file'];
239 $uploaded_file->type = $upload['type'];
240 $uploaded_file->size = $file['size'];
241 $uploaded_file->extension = substr( strrchr( $uploaded_file->name, '.' ), 1 );
242 }
243 }
244
245 return $uploaded_file;
246 }
247
248 /**
249 * Prepares the files for upload
250 *
251 * @since 1.0.0
252 * @package userswp
253 * @param array $file_data Files to upload
254 * @return array Prepared files.
255 */
256 public function prepare_files( $file_data ) {
257 $files_to_upload = array();
258
259 if ( is_array( $file_data['name'] ) ) {
260 foreach ( $file_data['name'] as $file_data_key => $file_data_value ) {
261
262 if ( $file_data['name'][ $file_data_key ] ) {
263 $files_to_upload[] = array(
264 'name' => $file_data['name'][ $file_data_key ],
265 'type' => $file_data['type'][ $file_data_key ],
266 'tmp_name' => $file_data['tmp_name'][ $file_data_key ],
267 'error' => $file_data['error'][ $file_data_key ],
268 'size' => $file_data['size'][ $file_data_key ]
269 );
270 }
271 }
272 } else {
273 $files_to_upload[] = $file_data;
274 }
275
276 return $files_to_upload;
277 }
278
279 /**
280 * Validates the file uploads.
281 *
282 * @since 1.0.0
283 * @package userswp
284 * @param array $files $_FILES array
285 * @param string $type Form type.
286 * @param bool $url_only Return only the url or whole file info?
287 * @param array|bool $fields Form fields.
288 * @return array Validated data.
289 */
290 public function validate_uploads($files, $type, $url_only = true, $fields = false) {
291
292 $validated_data = array();
293
294 if (empty($files)) {
295 return $validated_data;
296 }
297
298 if (!$fields) {
299 global $wpdb;
300 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
301
302 if ($type == 'register') {
303 $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' AND is_register_field = '1' ORDER BY sort_order ASC", array('account')));
304 } elseif ($type == 'account') {
305 $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' AND is_register_only_field = '0' ORDER BY sort_order ASC", array('account')));
306 } else {
307 $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' ORDER BY sort_order ASC", array($type)));
308 }
309 }
310
311 if ( ! empty( $fields ) ) {
312 foreach ( $fields as $field ) {
313 if ( isset( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ]['name'] ) ) {
314 $file_urls = $this->handle_file_upload( $field, $files );
315
316 if ( is_wp_error( $file_urls ) ) {
317 return $file_urls;
318 }
319
320 if ( $url_only ) {
321 $validated_data[$field->htmlvar_name] = $file_urls['url'];
322 } else {
323 $validated_data[$field->htmlvar_name] = $file_urls;
324 }
325 }
326 }
327 }
328
329 return $validated_data;
330 }
331
332 /**
333 * Displays the preview for images and links for other types above the field for existing uploads.
334 *
335 * @since 1.0.0
336 * @package userswp
337 * @param object $field Form field info.
338 * @param string $value Value of the field.
339 * @param bool $removable Is this value removable by user?
340 * @return string HTML output.
341 */
342 public function file_upload_preview($field, $value, $removable = true) {
343 $output = '';
344
345 $value = esc_html($value);
346
347 if ($field->htmlvar_name == "banner") {
348 $htmlvar = "banner_thumb";
349 } elseif ($field->htmlvar_name == "avatar") {
350 $htmlvar = "avatar_thumb";
351 } else {
352 $htmlvar = $field->htmlvar_name;
353 }
354
355 // If is current user's profile (profile.php)
356 if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
357 $user_id = get_current_user_id();
358 // If is another user's profile page
359 } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
360 $user_id = absint( $_GET['user_id'] );
361 // Otherwise something is wrong.
362 } else {
363 $user_id = get_current_user_id();
364 }
365
366 if ($value) {
367
368 $upload_dir = wp_upload_dir();
369 if (substr( $value, 0, 4 ) !== "http") {
370 $value = $upload_dir['baseurl'].$value;
371 }
372
373 $file = basename( $value );
374 $filetype = wp_check_filetype($file);
375 $image_types = array('png', 'jpg', 'jpeg', 'gif');
376 if (in_array($filetype['ext'], $image_types)) {
377 $output .= '<div class="uwp_file_preview_wrap">';
378 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview"><img style="max-width:100px;" src="'.$value.'" /></a>';
379 if ($removable) {
380 $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>';
381 }
382 $output .= '</div>';
383 ?>
384 <?php
385 } else {
386 $output .= '<div class="uwp_file_preview_wrap">';
387 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview">'.$file.'</a>';
388 if ($removable) {
389 $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>';
390 }
391 $output .= '</div>';
392 ?>
393 <?php
394 }
395 }
396 return $output;
397 }
398
399 /**
400 * restrict files to certain types
401 *
402 * @since 1.0.0
403 * @package userswp
404 * @param array $file File info.
405 * @return array Modified file info.
406 */
407 public function wp_media_restrict_file_types($file) {
408 // This bit is for the flash uploader
409 if ($file['type']=='application/octet-stream' && isset($file['tmp_name'])) {
410 $file_size = getimagesize($file['tmp_name']);
411 if (isset($file_size['error']) && $file_size['error']!=0) {
412 $file['error'] = "Unexpected Error: {$file_size['error']}";
413 return $file;
414 } else {
415 $file['type'] = $file_size['mime'];
416 }
417 }
418 list($category,$type) = explode('/',$file['type']);
419 if ('image'!=$category || !in_array($type,array('jpg','jpeg','gif','png'))) {
420 $file['error'] = "Sorry, you can only upload a .GIF, a .JPG, or a .PNG image file.";
421 } else if ($post_id = (isset($_REQUEST['post_id']) ? absint($_REQUEST['post_id']) : false)) {
422 if (count(get_posts("post_type=attachment&post_parent={$post_id}"))>0)
423 $file['error'] = "Sorry, you cannot upload more than one (1) image.";
424 }
425 return $file;
426 }
427
428 /**
429 * Check whether the uploads is from the profile page.
430 *
431 * @since 1.0.0
432 * @package userswp
433 * @return bool
434 */
435 public function doing_upload(){
436 return isset($_POST['uwp_profile_upload']) ? true : false;
437 }
438
439 /**
440 * Gets the maximum file upload size.
441 *
442 * @since 1.0.0
443 * @package userswp
444 * @param string|bool $form_type Form type.
445 * @param string|bool $field_htmlvar_name htmlvar_name key.
446 * @return int Allowed upload size.
447 */
448 public function uwp_get_max_upload_size($form_type = false, $field_htmlvar_name = false) {
449 if (is_multisite()) {
450 $network_setting_size = esc_attr( get_option( 'fileupload_maxk', 300 ) );
451 $max_upload_size = $this->uwp_get_size_in_bytes($network_setting_size.'k');
452 if ($max_upload_size > wp_max_upload_size()) {
453 $max_upload_size = wp_max_upload_size();
454 }
455 } else {
456 $max_upload_size = wp_max_upload_size();
457 }
458 $max_upload_size = apply_filters('uwp_get_max_upload_size', $max_upload_size, $form_type, $field_htmlvar_name);
459
460 return $max_upload_size;
461 }
462
463
464 /**
465 * Modifies the maximum file upload size based on the setting.
466 *
467 * @since 1.0.0
468 * @package userswp
469 *
470 * @param int $bytes Size in bytes.
471 * @param string $type File upload type.
472 *
473 * @return int Size in bytes.
474 */
475 public function uwp_modify_get_max_upload_size($bytes, $type) {
476
477 if ($type == 'avatar') {
478 $kb = uwp_get_option('profile_avatar_size', false);
479 if ($kb) {
480 $bytes = intval($kb) * 1024;
481 }
482 }
483
484 if ($type == 'banner') {
485 $kb = uwp_get_option('profile_banner_size', false);
486 if ($kb) {
487 $bytes = intval($kb) * 1024;
488 }
489 }
490
491 return $bytes;
492
493 }
494
495 /**
496 * Gets the file type using the extension.
497 * Ex: 'jpg' => 'image/jpeg'
498 *
499 * @since 1.0.0
500 * @package userswp
501 *
502 * @param string $ext Extension string. Ex: png, jpg
503 *
504 * @return string File type.
505 */
506 public function get_file_type($ext) {
507 $allowed_file_types = $this->allowed_mime_types();
508 $file_types = array();
509 foreach ( $allowed_file_types as $format => $types ) {
510 $file_types = array_merge($file_types, $types);
511 }
512 $file_types = array_flip($file_types);
513 return $file_types[$ext];
514 }
515
516 /**
517 * Returns allowed mime types in uploads
518 *
519 * @since 1.0.0
520 * @package userswp
521 *
522 * @return array Allowed mime types.
523 */
524 public function allowed_mime_types() {
525 return apply_filters( 'uwp_allowed_mime_types', array(
526 'Image' => array( // Image formats.
527 'jpg' => 'image/jpeg',
528 'jpe' => 'image/jpeg',
529 'jpeg' => 'image/jpeg',
530 'gif' => 'image/gif',
531 'png' => 'image/png',
532 'bmp' => 'image/bmp',
533 'ico' => 'image/x-icon',
534 ),
535 'Video' => array( // Video formats.
536 'asf' => 'video/x-ms-asf',
537 'avi' => 'video/avi',
538 'flv' => 'video/x-flv',
539 'mkv' => 'video/x-matroska',
540 'mp4' => 'video/mp4',
541 'mpeg' => 'video/mpeg',
542 'mpg' => 'video/mpeg',
543 'wmv' => 'video/x-ms-wmv',
544 '3gp' => 'video/3gpp',
545 ),
546 'Audio' => array( // Audio formats.
547 'ogg' => 'audio/ogg',
548 'mp3' => 'audio/mpeg',
549 'wav' => 'audio/wav',
550 'wma' => 'audio/x-ms-wma',
551 ),
552 'Text' => array( // Text formats.
553 'css' => 'text/css',
554 'csv' => 'text/csv',
555 'htm' => 'text/html',
556 'html' => 'text/html',
557 'txt' => 'text/plain',
558 'rtx' => 'text/richtext',
559 'vtt' => 'text/vtt',
560 ),
561 'Application' => array( // Application formats.
562 'doc' => 'application/msword',
563 'docx' => 'application/vnd.openxmlformats-officedocument.wordprocessingml.document',
564 'exe' => 'application/x-msdownload',
565 'js' => 'application/javascript',
566 'odt' => 'application/vnd.oasis.opendocument.text',
567 'pdf' => 'application/pdf',
568 'pot' => 'application/vnd.ms-powerpoint',
569 'ppt' => 'application/vnd.ms-powerpoint',
570 'pptx' => 'application/vnd.ms-powerpoint',
571 'psd' => 'application/octet-stream',
572 'rar' => 'application/rar',
573 'rtf' => 'application/rtf',
574 'swf' => 'application/x-shockwave-flash',
575 'tar' => 'application/x-tar',
576 'xls' => 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
577 'xlsx' => 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
578 'zip' => 'application/zip',
579 )
580 )
581 );
582 }
583
584 /**
585 * Initiate the WordPress file system and provide fallback if needed.
586 *
587 * @since 1.2.2
588 * @package userswp
589 * @return bool|string Returns the file system class on success. False on failure.
590 */
591 public static function uwp_init_filesystem() {
592
593 if ( ! function_exists( 'get_filesystem_method' ) ) {
594 require_once( ABSPATH . "/wp-admin/includes/file.php" );
595 }
596 $access_type = get_filesystem_method();
597 if ( $access_type === 'direct' ) {
598 /* you can safely run request_filesystem_credentials() without any issues and don't need to worry about passing in a URL */
599 $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
600
601 /* initialize the API */
602 if ( ! WP_Filesystem( $creds ) ) {
603 /* any problems and we exit */
604 return false;
605 }
606
607 global $wp_filesystem;
608
609 return $wp_filesystem;
610 /* do our file manipulations below */
611 } elseif ( defined( 'FTP_USER' ) ) {
612 $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
613
614 /* initialize the API */
615 if ( ! WP_Filesystem( $creds ) ) {
616 /* any problems and we exit */
617 return false;
618 }
619
620 global $wp_filesystem;
621
622 return $wp_filesystem;
623
624 } else {
625 return false;
626 }
627
628 }
629
630 }