PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.76
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.76
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
userswp / includes / class-forms.php

class-forms.php in UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 1.2.76, at includes/class-forms.php

5,379 lines 186.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * Form related functions
5 *
6 * This class defines all code necessary to handle UsersWP forms like login. register etc.
7 *
8 * @since 1.0.0
9 * @author GeoDirectory Team <[email protected]>
10 */
11 class UsersWP_Forms {
12
13 protected $generated_password;
14
15 /**
16 * Logs the error message.
17 *
18 * @param array|object|string $log Error message.
19 *
20 * @return void
21 * @since 1.0.0
22 * @package userswp
23 *
24 */
25 public static function uwp_error_log( $log ) {
26 uwp_error_log( $log );
27 }
28
29 /**
30 * Initialize UsersWP notices.
31 *
32 * @return void
33 * @package userswp
34 *
35 * @since 1.0.0
36 */
37 public function init_notices() {
38 global $uwp_notices;
39 $uwp_notices = array();
40 }
41
42 /**
43 * Handles all UsersWP forms.
44 *
45 * @return void
46 * @package userswp
47 *
48 * @since 1.0.0
49 */
50 public function handler() {
51 global $uwp_notices;
52
53 ob_start();
54
55 $errors = null;
56 $message = null;
57 $redirect = false;
58 $processed = false;
59 $type = null;
60
61 if ( isset( $_POST['uwp_avatar_submit'] ) ) {
62 $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' );
63 if ( ! is_wp_error( $errors ) ) {
64 $redirect = $errors;
65 }
66 $message = __( 'Avatar cropped successfully.', 'userswp' );
67 $processed = true;
68 } elseif ( isset( $_POST['uwp_banner_submit'] ) ) {
69 $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' );
70 if ( ! is_wp_error( $errors ) ) {
71 $redirect = $errors;
72 }
73 $message = __( 'Banner cropped successfully.', 'userswp' );
74 $processed = true;
75 } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) {
76 $errors = $this->process_image_crop( $_POST, 'avatar', true );
77 if ( ! is_wp_error( $errors ) ) {
78 $redirect = $errors;
79 }
80 $message = __( 'Avatar cropped successfully.', 'userswp' );
81 $processed = true;
82 } elseif ( isset( $_POST['uwp_banner_crop'] ) ) {
83 $errors = $this->process_image_crop( $_POST, 'banner', true );
84 if ( ! is_wp_error( $errors ) ) {
85 $redirect = $errors;
86 }
87 $message = __( 'Banner cropped successfully.', 'userswp' );
88 $processed = true;
89 } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) {
90 $errors = $this->process_image_reset( 'avatar' );
91 if ( ! is_wp_error( $errors ) ) {
92 $redirect = $errors;
93 }
94 $message = __( 'Avatar reset successfully.', 'userswp' );
95 $processed = true;
96 } elseif ( isset( $_POST['uwp_banner_reset'] ) ) {
97 $errors = $this->process_image_reset( 'banner' );
98 if ( ! is_wp_error( $errors ) ) {
99 $redirect = $errors;
100 }
101 $message = __( 'Banner reset successfully.', 'userswp' );
102 $processed = true;
103 }
104
105 if ( $processed ) {
106 if ( is_wp_error( $errors ) ) {
107 aui()->alert(
108 array(
109 'type' => 'error',
110 'content' => wp_kses_post( $errors->get_error_message() )
111 ),
112 true
113 );
114 } else if ( $redirect ) {
115 wp_safe_redirect( $redirect );
116 exit();
117 } else {
118 aui()->alert(
119 array(
120 'type' => 'success',
121 'content' => wp_kses_post( $message )
122 ),
123 true
124 );
125 }
126 }
127
128 if ( $type ) {
129 $uwp_notices[] = array( $type => ob_get_contents() );
130 } else {
131 $uwp_notices[] = ob_get_contents();
132 }
133
134 ob_end_clean();
135 }
136
137 /**
138 * Processes avatar and banner uploads form submission.
139 *
140 * @param array $data Submitted $_POST data
141 * @param array $files Submitted $_FILES data
142 *
143 * @return bool|WP_Error|string File url to crop.
144 * @package userswp
145 *
146 * @since 1.0.0
147 */
148 public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) {
149
150 $file_obj = new UsersWP_Files();
151
152 $current_user_id = get_current_user_id();
153 if ( ! $current_user_id ) {
154 return false;
155 }
156
157 if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) {
158 return false;
159 }
160
161 do_action( 'uwp_before_validate', $type );
162
163 $result = $file_obj->validate_uploads( $files, $type );
164
165 $result = apply_filters( 'uwp_validate_result', $result, $type, $data );
166
167 if ( is_wp_error( $result ) ) {
168 return $result;
169 }
170
171 $profile_url = uwp_build_profile_tab_url( $current_user_id );
172
173 $url = add_query_arg(
174 array(
175 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ],
176 'type' => $type,
177 ),
178 $profile_url
179 );
180
181 return $url;
182 }
183
184 /**
185 * Processes avatar and banner uploads image crop.
186 *
187 * @param array $data Submitted $_POST data
188 * @param string $type Image type. Default 'avatar'.
189 * @param bool $unlink_prev_img True to remove previous image. Default false;
190 *
191 * @return bool|WP_Error|string Profile url.
192 * @since 1.0.12 New param $unlink_prev_img introduced.
193 * @package userswp
194 *
195 * @since 1.0.0
196 */
197 public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) {
198 global $wpdb;
199
200 if ( ! is_user_logged_in() ) {
201 return false;
202 }
203
204 if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) {
205 return;
206 }
207
208 $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : '';
209
210 if ( empty( $image_url ) ) {
211 return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) );
212 }
213
214 // Ensure we have a valid URL with an allowed meme type.
215 $image_url = $this->normalize_url( $image_url );
216
217 $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) );
218 $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url );
219 if ( strpos( $_image_url, $content_url ) !== 0 ) {
220 return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) );
221 }
222
223 // Only allow cropping the image the current user just uploaded (normalized like $image_url).
224 $pending_key = '_uwp_pending_' . $type . '_upload';
225 $pending_url = get_user_meta( get_current_user_id(), $pending_key, true );
226 $pending_url = $pending_url ? str_replace( array( 'https://', 'http://' ), '', $this->normalize_url( esc_url( $pending_url ) ) ) : '';
227 if ( empty( $pending_url ) || $pending_url !== $_image_url ) {
228 return new WP_Error( 'crop_session_expired', __( 'Your image upload could not be verified. Please upload the image again.', 'userswp' ) );
229 }
230
231 $filetype = wp_check_filetype( $image_url );
232
233 if ( empty( $filetype['ext'] ) ) {
234 return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) );
235 }
236
237 // If is current user's profile (profile.php)
238 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
239 $user_id = get_current_user_id();
240 // If is another user's profile page
241 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
242 $user_id = absint( $_GET['user_id'] );
243 // Otherwise something is wrong.
244 } else {
245 $user_id = get_current_user_id();
246 }
247
248 // Retrieve current thumbnail.
249 $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb';
250 $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) );
251 $thumb_postfix = '_uwp_' . $type . '_thumb';
252
253 if ( $image_url ) {
254 if ( $type == 'avatar' ) {
255 $avatar_size = uwp_get_upload_image_size();
256 $full_width = $avatar_size['width'];
257 } else {
258 $banner_size = uwp_get_upload_image_size( 'banner' );
259 $full_width = $banner_size['width'];
260 }
261
262 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
263 $uploads = wp_upload_dir();
264 remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' );
265 $upload_url = $uploads['baseurl'];
266 $upload_path = $uploads['basedir'];
267 $image_path = str_replace( $upload_url, $upload_path, $image_url );
268 $ext = $filetype['ext']; // to get extension
269 $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension
270 $thumb_image_name = $name . $thumb_postfix . '.' . $ext;
271 $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path );
272
273 //Get the new coordinates to crop the image.
274 $x = $data['uwpx'];
275 $y = $data['uwpy'];
276 $w = $data['uwpw'];
277 $h = $data['uwph'];
278 //Scale the image based on cropped width setting
279 $scale = $full_width / $w;
280 //$scale = 1; // no scaling
281
282 // check we are not editing another user file
283 $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name;
284 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
285 $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
286
287 // if file already exists then we should not be cropping it.
288 if ( $file_exists ) {
289 wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 );
290 }
291
292 $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale );
293
294 // Resize returns a path even on failure; bail before touching meta or files so the crop can be retried.
295 clearstatcache( true, $thumb_image_location );
296 if ( ! is_file( $thumb_image_location ) ) {
297 return new WP_Error( 'crop_failed', __( 'Could not crop the image. Please try again.', 'userswp' ) );
298 }
299
300 $cropped = str_replace( $upload_path, $upload_url, $cropped );
301
302 // Remove previous avatar/banner
303 $unlink_img = '';
304 if ( $unlink_prev_img && $current_thumbnail ) {
305 $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' );
306 }
307
308 // remove the uploads path for easy migrations
309 $cropped = str_replace( $upload_url, '', $cropped );
310 if ( $type == 'avatar' ) {
311 uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped );
312 } else {
313 uwp_update_usermeta( $user_id, 'banner_thumb', $cropped );
314 }
315
316 $original_key = '_uwp_' . $type . '_original';
317 $prev_original = get_user_meta( $user_id, $original_key, true );
318
319 delete_user_meta( get_current_user_id(), $pending_key );
320 $relative_original = ltrim( wp_normalize_path( str_replace( wp_normalize_path( untrailingslashit( $upload_path ) ), '', wp_normalize_path( $image_path ) ) ), '/' );
321 update_user_meta( $user_id, $original_key, $relative_original );
322
323 // Enforce containment inside uploads before deleting, matching upload_file_remove().
324 $real_upload_path = realpath( $upload_path );
325 $real_unlink_img = $unlink_img ? realpath( $unlink_img ) : false;
326
327 if ( $real_upload_path && $real_unlink_img && realpath( $thumb_image_location ) !== $real_unlink_img
328 && false !== strpos( basename( $real_unlink_img ), $thumb_postfix . '.' )
329 && 0 === strpos( $real_unlink_img, $real_upload_path . DIRECTORY_SEPARATOR )
330 && is_file( $real_unlink_img ) ) {
331 wp_delete_file( $real_unlink_img );
332
333 // Delete the previous source only if it is the exact file this user cropped.
334 $unlink_ori_img = str_replace( $thumb_postfix . '.', '.', $real_unlink_img );
335 $real_unlink_ori_img = realpath( $unlink_ori_img );
336 $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false;
337 if ( $expected_original && $real_unlink_ori_img && $expected_original === $real_unlink_ori_img
338 && realpath( $image_path ) !== $real_unlink_ori_img
339 && 0 === strpos( $real_unlink_ori_img, $real_upload_path . DIRECTORY_SEPARATOR )
340 && is_file( $real_unlink_ori_img ) ) {
341 wp_delete_file( $real_unlink_ori_img );
342 }
343 }
344 }
345
346 if ( is_admin() ) {
347 if ( $user_id == get_current_user_id() ) {
348 $redirect_url = admin_url( 'profile.php' );
349 } else {
350 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
351 }
352 } elseif ( uwp_current_page_url() ) {
353 $redirect_url = uwp_current_page_url();
354 } else {
355 $redirect_url = uwp_build_profile_tab_url( $user_id );
356 }
357
358 return $redirect_url;
359 }
360
361 /**
362 * Normalizes a URL.
363 *
364 */
365 public function normalize_url( $url ) {
366
367 if ( empty( $url ) ) {
368 return '';
369 }
370 // Normalize.
371 $url = wp_normalize_path( $url );
372
373 // Remove query vars.
374 $url = strtok( $url, '?' );
375
376 // Split.
377 $url = explode( '/', $url );
378
379 // Clean.
380 $url = array_diff( $url, array( '..', '.' ) );
381
382 // Rejoin and return.
383 return implode( '/', $url );
384 }
385
386 /**
387 * Processes avatar and banner image reset.
388 *
389 * @param string $type Image type. Default 'avatar'.
390 *
391 * @return bool|WP_Error|string Profile url.
392 * @package userswp
393 *
394 */
395 public function process_image_reset( $type ) {
396 if ( ! is_user_logged_in() ) {
397 return false;
398 }
399
400 if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) {
401 $user_id = get_current_user_id();
402 } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) {
403 $user_id = absint( $_GET['user_id'] );
404 } else {
405 $user_id = get_current_user_id();
406 }
407
408 if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) {
409 return;
410 }
411
412 $errors = new WP_Error();
413 if ( empty( $user_id ) ) {
414 $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) );
415 }
416
417 $error_code = $errors->get_error_code();
418 if ( ! empty( $error_code ) ) {
419 return $errors;
420 }
421
422 if ( $type == 'avatar' ) {
423 uwp_update_usermeta( $user_id, 'avatar_thumb', '' );
424 } elseif ( $type == 'banner' ) {
425 uwp_update_usermeta( $user_id, 'banner_thumb', '' );
426 } else {
427 // Do nothing
428 }
429
430 if ( in_array( $type, array( 'avatar', 'banner' ), true ) ) {
431 delete_user_meta( $user_id, '_uwp_' . $type . '_original' );
432 delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' );
433 }
434
435 if ( is_admin() ) {
436 if ( $user_id == get_current_user_id() ) {
437 $redirect_url = admin_url( 'profile.php' );
438 } else {
439 $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id );
440 }
441 } elseif ( uwp_current_page_url() ) {
442 $redirect_url = uwp_current_page_url();
443 } else {
444 $redirect_url = uwp_build_profile_tab_url( $user_id );
445 }
446
447 return $redirect_url;
448 }
449
450 /**
451 * Displays links in a dropdown
452 *
453 * @param $options
454 *
455 * @package userswp
456 *
457 * @since 1.0.0
458 */
459 public function output_dashboard_links( $options ) {
460 if ( ! empty( $options ) ) {
461 $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2';
462 echo '<select class="' . esc_attr( $class ) . '" onchange="window.location = jQuery(this).val();">';
463 $this->output_options( $options );
464 echo '</select>';
465 }
466 }
467
468 /**
469 * Displays options for the dashboard links
470 *
471 * @param $options
472 *
473 * @package userswp
474 *
475 * @since 1.0.0
476 */
477 public function output_options( $options ) {
478 if ( ! empty( $options ) ) {
479 foreach ( $options as $key => $link ) {
480
481 if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) {
482 $this->output_options( $link );
483 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) {
484 echo "<optgroup label='" . esc_attr( $link['text'] ) . "'>";
485 } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'close' ) {
486 echo '</optgroup>';
487 } elseif ( ! empty( $link['text'] ) ) {
488 echo '<option value="' . ( ! empty( $link['url'] ) ? esc_url( $link['url'] ) : '' ) . '"' . selected( ! empty( $link['selected'] ), true, false ) . ( ! empty( $link['disabled'] ) ? ' disabled' : '' ) . '' . ( ! empty( $link['display_none'] ) ? ' style="display:none;"' : '' ) . '>';
489 echo esc_attr__( $link['text'], 'userswp' );
490 echo '</option>';
491 }
492 }
493 }
494 }
495
496 /**
497 * Displays UsersWP notices in forms.
498 *
499 * @param string $type Form type
500 *
501 * @return void
502 * @since 1.0.0
503 * @package userswp
504 *
505 */
506 public function display_notices( $type ) {
507 global $uwp_notices;
508
509 if ( is_array( $uwp_notices ) ) {
510 foreach ( $uwp_notices as $notice ) {
511
512 // If the notification is type specific then only output on that type
513 if ( is_array( $notice ) ) {
514 foreach ( $notice as $key => $val ) {
515 if ( $key == $type ) {
516 echo wp_kses_post( $val );
517 }
518 }
519 } elseif ( ! empty( $notice ) ) {
520 echo wp_kses_post( $notice );
521 }
522 }
523 }
524
525 if ( $type == 'change' ) {
526 $user_id = get_current_user_id();
527 $password_nag = get_user_option( 'default_password_nag', $user_id );
528
529 if ( $password_nag ) {
530 $change_page = uwp_get_page_id( 'change_page', false );
531 $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) );
532
533 if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) {
534 delete_user_meta( $user_id, 'default_password_nag' );
535 $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, <a href="%s">click here</a>.', 'userswp' ), home_url( '/' ) );
536 echo aui()->alert(
537 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
538 'class' => 'text-center',
539 'type' => 'success',
540 'content' => wp_kses_post( $message ),
541 )
542 );
543 } else {
544 $message = sprintf( __( '<strong>Warning</strong>: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by <a href="%s">clicking here</a>.', 'userswp' ), $remove_nag_url );
545 echo aui()->alert(
546 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
547 'class' => 'text-center',
548 'type' => 'warning',
549 'content' => wp_kses_post( $message ),
550 )
551 );
552 }
553 }
554 }
555 }
556
557 /**
558 * Processes register form submission.
559 *
560 * @since 1.0.0
561 * @package userswp
562 *
563 */
564 public function process_register() {
565
566 $data = $_POST;
567
568 if ( ! isset( $data['uwp_register_nonce'] ) ) {
569 return;
570 }
571
572 global $uwp_notices;
573
574 if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) {
575 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
576 }
577
578 $form_id = 1;
579
580 if ( ! empty( $data['uwp_register_form_id'] ) ) {
581 $form_id = (int) $data['uwp_register_form_id'];
582 }
583
584 if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) {
585 $message = aui()->alert(
586 array(
587 'type' => 'error',
588 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
589 )
590 );
591 if ( wp_doing_ajax() ) {
592 wp_send_json_error( array( 'message' => $message ) );
593 } else {
594 $uwp_notices[] = array( 'register' => $message );
595
596 return;
597 }
598 }
599
600 $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 );
601 if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) {
602 $message = aui()->alert(
603 array(
604 'type' => 'error',
605 'content' => __( 'Security hash failed. Try again.', 'userswp' ),
606 )
607 );
608 if ( wp_doing_ajax() ) {
609 wp_send_json_error( array( 'message' => $message ) );
610 } else {
611 $uwp_notices[] = array( 'register' => $message );
612
613 return;
614 }
615 }
616
617 if ( ! get_option( 'users_can_register' ) ) {
618 $message = aui()->alert(
619 array(
620 'type' => 'error',
621 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ),
622 )
623 );
624 if ( wp_doing_ajax() ) {
625 wp_send_json_error( array( 'message' => $message ) );
626 } else {
627 $uwp_notices[] = array( 'register' => $message );
628
629 return;
630 }
631 }
632
633 $files = $_FILES;
634 $errors = new WP_Error();
635 $file_obj = new UsersWP_Files();
636
637 do_action( 'uwp_before_validate', 'register' );
638
639 $result = uwp_validate_fields( $data, 'register' );
640
641 $result = apply_filters( 'uwp_validate_result', $result, 'register', $data );
642
643 if ( is_wp_error( $result ) ) {
644 $message = aui()->alert(
645 array(
646 'type' => 'error',
647 'content' => $result->get_error_message(),
648 )
649 );
650 if ( wp_doing_ajax() ) {
651 wp_send_json_error( array( 'message' => $message ) );
652 } else {
653 $uwp_notices[] = array( 'register' => $message );
654
655 return;
656 }
657 }
658
659 $uploads_result = $file_obj->validate_uploads( $files, 'register' );
660
661 if ( is_wp_error( $uploads_result ) ) {
662 $message = aui()->alert(
663 array(
664 'type' => 'error',
665 'content' => $uploads_result->get_error_message(),
666 )
667 );
668 if ( wp_doing_ajax() ) {
669 wp_send_json_error( array( 'message' => $message ) );
670 } else {
671 $uwp_notices[] = array( 'register' => $message );
672
673 return;
674 }
675 }
676
677 do_action( 'uwp_after_validate', $result, 'register', $data );
678
679 $result = array_merge( $result, $uploads_result );
680
681 if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) {
682 $password = $result['password'];
683 $generated_password = false;
684 } else {
685 $password = wp_generate_password();
686 $this->generated_password = $password;
687 $generated_password = true;
688 }
689
690 $first_name = '';
691 if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) {
692 $first_name = $result['first_name'];
693 }
694
695 $last_name = '';
696 if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) {
697 $last_name = $result['last_name'];
698 }
699
700 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
701 $display_name = $result['display_name'];
702 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
703 $display_name = $first_name . ' ' . $last_name;
704 } else {
705 $display_name = ! empty( $result['username'] ) ? $result['username'] : '';
706 }
707
708 $user_url = '';
709 if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) {
710 $user_url = esc_url_raw( $result['user_url'] );
711 }
712
713 $user_login = ! empty( $result['username'] ) ? $result['username'] : '';
714 $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : '';
715
716 if ( empty( $user_login ) ) {
717 $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true );
718 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
719 $new_user_login = strstr( $email, '@', true );
720 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
721 $user_login = sanitize_user( $new_user_login, true );
722 }
723 if ( validate_username( $user_login ) && username_exists( $user_login ) ) {
724 $user_append_text = rand( 10, 1000 );
725 $user_login = sanitize_user( $new_user_login . $user_append_text, true );
726 }
727
728 if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) {
729 $user_login = $email;
730 }
731 }
732 } elseif ( ! validate_username( $user_login ) ) {
733 $message = aui()->alert(
734 array(
735 'type' => 'error',
736 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ),
737 )
738 );
739 if ( wp_doing_ajax() ) {
740 wp_send_json_error( array( 'message' => $message ) );
741 } else {
742 $uwp_notices[] = array( 'register' => $message );
743
744 return;
745 }
746 }
747
748 $args = array(
749 'user_login' => sanitize_user( $user_login ),
750 'user_email' => sanitize_email( $email ),
751 'user_pass' => $password,
752 'display_name' => sanitize_text_field( $display_name ),
753 'first_name' => esc_attr( $first_name ),
754 'last_name' => esc_attr( $last_name ),
755 'user_url' => esc_url_raw( $user_url ),
756 );
757
758 // Set user role by form.
759 $user_role = uwp_get_register_form_by( $form_id, 'user_role' );
760
761 if ( ! empty( $user_role ) ) {
762 $user_roles = uwp_get_user_roles();
763 $chosen_role = strtolower( $user_role );
764
765 if ( ! empty( $user_roles ) ) {
766 $wp_roles = wp_roles();
767
768 if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) {
769 $args['role'] = $chosen_role;
770 }
771 }
772 }
773
774 $user_id = wp_insert_user( $args );
775
776 if ( is_wp_error( $user_id ) ) {
777 $message = aui()->alert(
778 array(
779 'type' => 'error',
780 'content' => $user_id->get_error_message(),
781 )
782 );
783 if ( wp_doing_ajax() ) {
784 wp_send_json_error( array( 'message' => $message ) );
785 } else {
786 $uwp_notices[] = array( 'register' => $message );
787
788 return;
789 }
790 }
791
792 $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id );
793
794 // Save user form id.
795 if ( ! empty( $data['uwp_register_form_id'] ) ) {
796 update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] );
797 }
798
799 $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' );
800
801 $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id );
802
803 if ( is_wp_error( $save_result ) ) {
804 $message = aui()->alert(
805 array(
806 'type' => 'error',
807 'content' => $save_result->get_error_message(),
808 )
809 );
810 if ( wp_doing_ajax() ) {
811 wp_send_json_error( array( 'message' => $message ) );
812 } else {
813 $uwp_notices[] = array( 'register' => $message );
814
815 return;
816 }
817 }
818
819 if ( ! $save_result ) {
820 $message = aui()->alert(
821 array(
822 'type' => 'error',
823 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
824 )
825 );
826 if ( wp_doing_ajax() ) {
827 wp_send_json_error( array( 'message' => $message ) );
828 } else {
829 $uwp_notices[] = array( 'register' => $message );
830
831 return;
832 }
833 }
834
835 //updating bio field after saving extra fields to reflect the points in mycred add on.
836 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
837 $args = array(
838 'ID' => $user_id,
839 'description' => $result['bio'],
840 );
841 wp_update_user( $args );
842 }
843
844 do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id );
845
846 // Unset post data to empty the form on submit
847 $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) );
848 foreach ( $data as $key => $value ) {
849 if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) {
850 unset( $_POST[ $key ] );
851 }
852 }
853
854 $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' );
855 if ( ! $reg_action ) {
856 $reg_action = uwp_get_option( 'uwp_registration_action', false );
857 }
858
859 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id );
860
861 if ( $reg_action == 'require_email_activation' && ! $generated_password ) {
862
863 $user_data = get_userdata( $user_id );
864 $activation_link = uwp_get_activation_link( $user_id );
865
866 $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n";
867
868 $message .= "<a href='" . esc_url_raw( $activation_link ) . "' target='_blank'>" . esc_url_raw( $activation_link ) . '</a>' . "\r\n";
869
870 $activate_message = '<p><b>' . __( 'Please activate your account :', 'userswp' ) . '</b></p><p>' . $message . '</p>';
871
872 $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id );
873
874 $email_vars = array(
875 'user_id' => $user_id,
876 'login_details' => $activate_message,
877 'activation_link' => $activation_link,
878 );
879
880 UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars );
881
882 } elseif ( $reg_action != 'require_admin_review' ) {
883
884 $user_data = get_userdata( $user_id );
885
886 if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) {
887 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
888 update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag.
889 }
890 $message_pass = $this->generated_password;
891 $this->generated_password = false;
892 } else {
893 $message_pass = __( 'Password you entered during registration.', 'userswp' );
894 }
895
896 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>
897 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
898 <p>' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '</p>';
899
900 $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password );
901
902 $email_vars = array(
903 'user_id' => $user_id,
904 'login_details' => $message,
905 'form_fields' => $form_fields,
906 );
907
908 UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars );
909 }
910
911 $error_code = $errors->get_error_code();
912 if ( ! empty( $error_code ) ) {
913 $message = aui()->alert(
914 array(
915 'type' => 'error',
916 'content' => $result->get_error_message(),
917 )
918 );
919 if ( wp_doing_ajax() ) {
920 wp_send_json_error( array( 'message' => $message ) );
921 } else {
922 $uwp_notices[] = array( 'register' => $message );
923 return;
924 }
925 }
926
927 if ( $reg_action != 'require_admin_review' ) {
928
929 $user_data = get_userdata( $user_id );
930 $extras = '<p><b>' . __( 'User Information :', 'userswp' ) . '</b></p>
931 <p>' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '</p>
932 <p>' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '</p>
933 <p>' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '</p>
934 <p>' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '</p>';
935
936 $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id );
937
938 $email_vars = array(
939 'user_id' => $user_id,
940 'extras' => $extras,
941 'form_fields' => $form_fields,
942 );
943
944 UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true );
945
946 }
947
948 if ( $reg_action == 'auto_approve_login' ) {
949 $res = wp_signon(
950 array(
951 'user_login' => $user_login,
952 'user_password' => $password,
953 'remember' => false,
954 )
955 );
956
957 if ( is_wp_error( $res ) ) {
958 $message = aui()->alert(
959 array(
960 'type' => 'error',
961 'content' => $res->get_error_message(),
962 )
963 );
964
965 if ( wp_doing_ajax() ) {
966 wp_send_json_error( array( 'message' => $message ) );
967 } else {
968 $uwp_notices[] = array( 'register' => $message );
969 }
970 } else {
971 $redirect_to = $this->get_register_redirect_url( $data, $user_id );
972 do_action( 'uwp_after_process_register', $result, $user_id );
973
974 if ( wp_doing_ajax() ) {
975 $message = aui()->alert(
976 array(
977 'type' => 'success',
978 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ),
979 )
980 );
981 $response = array(
982 'message' => $message,
983 'redirect' => $redirect_to,
984 );
985 wp_send_json_success( $response );
986 } else {
987 wp_safe_redirect( $redirect_to );
988 }
989 exit();
990 }
991 } else {
992 if ( $reg_action == 'require_email_activation' ) {
993 $resend_link = uwp_get_register_page_url();
994 $resend_link = add_query_arg(
995 array(
996 'user_id' => $user_id,
997 'action' => 'uwp_resend',
998 '_nonce' => wp_create_nonce( 'uwp_resend' ),
999 ),
1000 $resend_link
1001 );
1002
1003 $message = aui()->alert(
1004 array(
1005 'type' => 'success',
1006 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. <a href="%s">Resend</a>.', 'userswp' ), $resend_link ),
1007 )
1008 );
1009
1010 } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) {
1011
1012 update_user_meta( $user_id, 'uwp_mod', '1' );
1013
1014 do_action( 'uwp_require_admin_review', $user_id, $result );
1015
1016 $message = aui()->alert(
1017 array(
1018 'type' => 'success',
1019 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ),
1020 )
1021 );
1022 } else {
1023
1024 $login_page_url = wp_login_url();
1025
1026 if ( $generated_password ) {
1027 $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
1028 } else {
1029 $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '<a href="' . $login_page_url . '">', '</a>' );
1030 }
1031
1032 $message = aui()->alert(
1033 array(
1034 'type' => 'success',
1035 'content' => $msg,
1036 )
1037 );
1038 }
1039
1040 do_action( 'uwp_after_process_register', $result, $user_id );
1041
1042 if ( wp_doing_ajax() ) {
1043 wp_send_json_success( array( 'message' => $message ) );
1044 } else {
1045 $uwp_notices[] = array( 'register' => $message );
1046 }
1047 }
1048
1049 if ( wp_doing_ajax() ) {
1050 wp_send_json_error();
1051 } // if we got this far there is a problem
1052 }
1053
1054 /**
1055 * Saves UsersWP related user custom fields.
1056 *
1057 * @param int $user_id User ID.
1058 * @param array $data Result array.
1059 * @param string $type Form type.
1060 *
1061 * @return bool True when success. False when failure.
1062 * @since 1.0.0
1063 * @package userswp
1064 *
1065 */
1066 public function save_user_extra_fields( $user_id, $data, $type ) {
1067
1068 if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) {
1069 return false;
1070 }
1071
1072 // custom user fields not applicable for login and forgot
1073 if ( $type == 'login' || $type == 'forgot' ) {
1074 return true;
1075 }
1076
1077 if ( $type == 'account' || $type == 'register' ) {
1078 if ( isset( $data['password'] ) ) {
1079 unset( $data['password'] );
1080 }
1081 }
1082
1083 if ( $type == 'register' ) {
1084 if ( isset( $data['username'] ) ) {
1085 unset( $data['username'] );
1086 }
1087 if ( isset( $data['email'] ) ) {
1088 unset( $data['email'] );
1089 }
1090 }
1091
1092 if ( empty( $data ) ) {
1093 // no extra fields. so just return
1094 return true;
1095 } else {
1096 foreach ( $data as $key => $value ) {
1097 if ( 'uwp_language' == $key ) {
1098 update_user_meta( $user_id, 'locale', $value );
1099 }
1100 uwp_update_usermeta( $user_id, $key, $value );
1101 }
1102
1103 return true;
1104 }
1105 }
1106
1107 public function get_register_redirect_url( $data, $user ) {
1108 if ( is_int( $user ) ) {
1109 $user = get_userdata( $user );
1110 }
1111
1112 $redirect_page_id = $custom_url = '';
1113 if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) {
1114 $form_id = (int) $data['uwp_register_form_id'];
1115 $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' );
1116 $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' );
1117 }
1118
1119 if ( ! $redirect_page_id ) {
1120 $redirect_page_id = uwp_get_option( 'register_redirect_to', '' );
1121 $custom_url = uwp_get_option( 'register_redirect_custom_url' );
1122 }
1123
1124 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1125 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1126 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1127 $redirect_to = esc_url_raw( $data['redirect_to'] );
1128 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1129 if ( uwp_is_wpml() ) {
1130 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1131 if ( ! empty( $wpml_page_id ) ) {
1132 $redirect_page_id = $wpml_page_id;
1133 }
1134 }
1135 $redirect_to = get_permalink( $redirect_page_id );
1136 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1137 $redirect_to = esc_url( wp_get_referer() );
1138 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) {
1139 $redirect_to = $custom_url;
1140 } else {
1141 if ( $user && $user->has_cap( 'manage_options' ) ) {
1142 $redirect_to = admin_url();
1143 } else {
1144 $redirect_to = home_url( '/' );
1145 }
1146
1147 $redirect_to = apply_filters( 'registration_redirect', $redirect_to );
1148 }
1149
1150 return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data );
1151 }
1152
1153 /**
1154 * Processes login form submission.
1155 *
1156 * @since 1.0.0
1157 * @package userswp
1158 *
1159 */
1160 public function process_login() {
1161
1162 $data = $_POST;
1163
1164 if ( ! isset( $data['uwp_login_nonce'] ) ) {
1165 return;
1166 }
1167
1168 if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) {
1169 $message = aui()->alert(
1170 array(
1171 'type' => 'error',
1172 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1173 )
1174 );
1175 if ( wp_doing_ajax() ) {
1176 wp_send_json_error( array( 'message' => $message ) );
1177 } else {
1178 return;
1179 }
1180 }
1181
1182 global $uwp_notices;
1183
1184 do_action( 'uwp_before_validate', 'login' );
1185
1186 $result = uwp_validate_fields( $data, 'login' );
1187
1188 $result = apply_filters( 'uwp_validate_result', $result, 'login', $data );
1189
1190 if ( is_wp_error( $result ) ) {
1191 $message = aui()->alert(
1192 array(
1193 'type' => 'error',
1194 'content' => $result->get_error_message(),
1195 )
1196 );
1197 if ( wp_doing_ajax() ) {
1198 wp_send_json_error( array( 'message' => $message ) );
1199 } else {
1200 $uwp_notices[] = array( 'login' => $message );
1201
1202 return;
1203 }
1204 }
1205
1206 do_action( 'uwp_after_validate', $result, 'login', $data );
1207
1208 if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) {
1209 $remember_me = true;
1210 } else {
1211 $remember_me = false;
1212 }
1213
1214 remove_action( 'authenticate', 'gglcptch_login_check', 21 );
1215
1216 global $wp2fa;
1217 if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) {
1218 remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 );
1219 }
1220 if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1221 remove_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20 );
1222 }
1223
1224 $user = wp_signon(
1225 array(
1226 'user_login' => $result['username'],
1227 'user_password' => $result['password'],
1228 'remember' => $remember_me,
1229 )
1230 );
1231
1232 add_action( 'authenticate', 'gglcptch_login_check', 21, 1 );
1233 if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) {
1234 add_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20, 2 );
1235 }
1236
1237 $wp2fa_available = ( isset( $wp2fa ) && ! empty( $wp2fa ) ) || class_exists( '\WP2FA\Authenticator\Login' );
1238 if ( wp_doing_ajax() && ! is_wp_error( $user ) && $wp2fa_available ) {
1239
1240 $two_fa = $this->check_2fa( $user );
1241 if ( isset( $two_fa ) && ! empty( $two_fa ) ) {
1242 if ( is_wp_error( $two_fa ) ) {
1243 $message = aui()->alert(
1244 array(
1245 'type' => 'error',
1246 'content' => $two_fa->get_error_message(),
1247 )
1248 );
1249 wp_send_json_error( array( 'message' => $message ) );
1250 } else {
1251 wp_send_json_success(
1252 array(
1253 'html' => $two_fa,
1254 'is_2fa' => true,
1255 )
1256 );
1257 }
1258 }
1259 }
1260
1261 if ( wp_doing_ajax() && is_wp_error( $user ) && $this->wordfence_2fa_available() ) {
1262 $wfls_2fa = $this->check_wordfence_2fa( $user, $result );
1263 if ( ! empty( $wfls_2fa ) ) {
1264 wp_send_json_success(
1265 array(
1266 'html' => $wfls_2fa,
1267 'is_2fa' => true,
1268 )
1269 );
1270 }
1271 }
1272
1273 if ( is_wp_error( $user ) ) {
1274 $message = aui()->alert(
1275 array(
1276 'type' => 'error',
1277 'content' => $user->get_error_message(),
1278 )
1279 );
1280 if ( wp_doing_ajax() ) {
1281 wp_send_json_error( array( 'message' => $message ) );
1282 } else {
1283 $uwp_notices[] = array( 'login' => $message );
1284
1285 return;
1286 }
1287 } else {
1288 do_action( 'uwp_after_process_login', $data );
1289 $message = aui()->alert(
1290 array(
1291 'type' => 'success',
1292 'content' => __( 'Login successful. Redirecting...', 'userswp' ),
1293 )
1294 );
1295 if ( wp_doing_ajax() ) {
1296 $redirect_to = '';
1297 if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) {
1298 $redirect_to = $this->get_login_redirect_url( $data, $user );
1299 }
1300 wp_send_json_success(
1301 array(
1302 'message' => $message,
1303 'redirect' => $redirect_to,
1304 )
1305 );
1306 } else {
1307 $redirect_to = $this->get_login_redirect_url( $data, $user );
1308 wp_safe_redirect( $redirect_to );
1309 exit();
1310 }
1311 }
1312 }
1313
1314 public function check_2fa( $user ) {
1315 if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) {
1316 return;
1317 }
1318
1319 if ( ! $user ) {
1320 $user = wp_get_current_user();
1321 }
1322
1323 global $wp2fa;
1324 $errors = new WP_Error();
1325
1326 if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) {
1327 return;
1328 }
1329 // Invalidate the current login session to prevent from being re-used.
1330 \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user );
1331
1332 // Also clear the cookies which are no longer valid.
1333 wp_clear_auth_cookie();
1334
1335 $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID );
1336 if ( ! $login_nonce ) {
1337 $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) );
1338
1339 return $errors;
1340 }
1341
1342 $provider = $this->get_wp2fa_provider_for_user( $user );
1343 if ( empty( $provider ) ) {
1344 return;
1345 }
1346
1347 ob_start();
1348 ?>
1349
1350 <div class="uwp-2fa-methods-wrap">
1351 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1352 autocomplete="off">
1353 <input type="hidden" name="provider" id="provider" value="<?php echo esc_attr( $provider ); ?>"/>
1354 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1355 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1356 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1357 <?php
1358
1359 // Check to see what provider is set and give the relevant authentication page.
1360 if ( 'totp' === $provider ) {
1361 ?>
1362 <p><?php esc_html_e( 'Please enter the authentication code from your 2FA authentication app below to login:', 'userswp' ); ?></p>
1363 <?php
1364
1365 echo aui()->input(
1366 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1367 'type' => 'tel',
1368 'id' => 'authcode',
1369 'name' => 'authcode',
1370 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1371 'value' => '',
1372 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1373 )
1374 );
1375
1376 echo aui()->button(
1377 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1378 'type' => 'submit',
1379 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1380 'name' => 'submit',
1381 'icon' => '',
1382 'content' => esc_html__( 'Log In', 'userswp' ),
1383 )
1384 );
1385
1386 } elseif ( 'email' === $provider ) {
1387 $has_token = \WP2FA\Authenticator\Authentication::user_has_token( $user->ID );
1388 if ( empty( $has_token ) || ! $has_token ) {
1389 \WP2FA\Admin\Setup_Wizard::send_authentication_setup_email( $user->ID );
1390 }
1391 ?>
1392 <p><?php esc_html_e( 'Please enter the 2FA verification code sent to your email address to login:', 'userswp' ); ?></p>
1393 <?php
1394 echo aui()->input(
1395 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1396 'type' => 'tel',
1397 'id' => 'authcode',
1398 'name' => 'authcode',
1399 'placeholder' => esc_attr__( 'Verification Code', 'userswp' ),
1400 'value' => '',
1401 'label' => esc_html__( 'Verification Code', 'userswp' ),
1402 'extra_attributes' => array(
1403 'size' => 20,
1404 'pattern' => '[0-9]*',
1405 ),
1406 )
1407 );
1408
1409 echo aui()->button(
1410 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1411 'type' => 'submit',
1412 'class' => 'btn btn-primary text-uppercase uwp-2fa-submit',
1413 'name' => 'submit',
1414 'icon' => '',
1415 'content' => esc_html__( 'Log In', 'userswp' ),
1416 )
1417 );
1418
1419 echo aui()->button(
1420 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1421 'type' => 'button',
1422 'class' => 'btn btn-secondary text-uppercase uwp-2fa-email-resend',
1423 'name' => 'wp-2fa-email-code-resend',
1424 'icon' => '',
1425 'content' => esc_html__( 'Resend Code', 'userswp' ),
1426 )
1427 );
1428
1429 }
1430 ?>
1431 </form>
1432 </div>
1433
1434 <?php
1435 $codes_remaining = $this->get_wp2fa_backup_codes_remaining( $user );
1436 if ( isset( $codes_remaining ) && $codes_remaining > 0 ) {
1437 ?>
1438 <div class="uwp-2fa-methods-wrap" style="display:none;">
1439 <form name="validate_2fa_backup_codes_form" id="validate_2fa_backup_codes_form"
1440 class="validate_2fa_backup_codes_form" action="" method="post" autocomplete="off">
1441 <input type="hidden" name="provider" id="provider" value="backup_codes"/>
1442 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id"
1443 value="<?php echo esc_attr( $user->ID ); ?>"/>
1444 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1445 value="<?php echo esc_attr( $login_nonce['key'] ); ?>"/>
1446 <div class="uwp-backup-fields">
1447 <?php
1448 echo aui()->input(
1449 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1450 'type' => 'tel',
1451 'id' => 'authcode',
1452 'name' => 'wp-2fa-backup-code',
1453 'placeholder' => esc_attr__( 'Enter backup code', 'userswp' ),
1454 'value' => '',
1455 'label' => esc_html__( 'Backup Code', 'userswp' ),
1456 'extra_attributes' => array(
1457 'size' => 20,
1458 'pattern' => '[0-9]*',
1459 ),
1460 )
1461 );
1462
1463 echo aui()->button(
1464 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1465 'type' => 'submit',
1466 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1467 'name' => 'submit',
1468 'icon' => '',
1469 'content' => esc_html__( 'Log In', 'userswp' ),
1470 )
1471 );
1472 ?>
1473 </div>
1474 </form>
1475 </div>
1476 <a href="#" class="uwp-switch-2fa-methods text-center d-block"><?php esc_html_e( 'Or, use a backup code.', 'userswp' ); ?></a>
1477 <script type="text/javascript">
1478 jQuery('.uwp-switch-2fa-methods').on('click',
1479 function (e) {
1480 e.preventDefault();
1481 jQuery('.uwp-auth-modal .modal-content .modal-error').html('');
1482 jQuery('.uwp-2fa-methods-wrap').toggle();
1483 return false;
1484 }
1485 );
1486 </script>
1487 <?php
1488 }
1489
1490 return ob_get_clean();
1491 }
1492
1493 /**
1494 * Checks if the Wordfence Login Security module (2FA) is available.
1495 *
1496 * @since 1.2.5
1497 * @package userswp
1498 *
1499 * @return bool
1500 */
1501 public function wordfence_2fa_available() {
1502 return class_exists( '\WordfenceLS\Controller_Users' ) && class_exists( '\WordfenceLS\Controller_TOTP' );
1503 }
1504
1505 /**
1506 * Checks whether Wordfence's 2FA requires a verification code for the
1507 * failed login attempt and, if so, returns the markup for the code entry form.
1508 *
1509 * @since 1.2.5
1510 * @package userswp
1511 *
1512 * @param WP_Error $error The error returned by wp_signon().
1513 * @param array $result The validated login fields (username/password).
1514 *
1515 * @return string|void The 2FA form markup, or nothing if not applicable.
1516 */
1517 public function check_wordfence_2fa( $error, $result ) {
1518 if ( 1 == uwp_get_option( 'disable_wordfence_2fa' ) ) {
1519 return;
1520 }
1521
1522 if ( ! $this->wordfence_2fa_available() ) {
1523 return;
1524 }
1525
1526 if ( ! is_wp_error( $error ) || 'wfls_twofactor_required' !== $error->get_error_code() ) {
1527 return;
1528 }
1529
1530 $username = ! empty( $result['username'] ) ? $result['username'] : '';
1531 if ( empty( $username ) ) {
1532 return;
1533 }
1534
1535 $user = is_email( $username ) ? get_user_by( 'email', $username ) : get_user_by( 'login', $username );
1536 if ( ! $user ) {
1537 return;
1538 }
1539
1540 if ( ! \WordfenceLS\Controller_Users::shared()->has_2fa_active( $user ) ) {
1541 return;
1542 }
1543
1544 if ( \WordfenceLS\Controller_Users::shared()->has_remembered_2fa( $user ) ) {
1545 return;
1546 }
1547
1548 $login_nonce = wp_create_nonce( 'uwp-wfls-2fa-' . $user->ID );
1549
1550 ob_start();
1551 ?>
1552
1553 <div class="uwp-2fa-methods-wrap">
1554 <form name="validate_2fa_form" id="validate_2fa_form" class="validate_2fa_form" action="" method="post"
1555 autocomplete="off">
1556 <input type="hidden" name="provider" id="provider" value="wordfence"/>
1557 <input type="hidden" name="uwp-auth-id" id="uwp-auth-id" value="<?php echo esc_attr( $user->ID ); ?>"/>
1558 <input type="hidden" name="wp-auth-nonce" id="wp-auth-nonce"
1559 value="<?php echo esc_attr( $login_nonce ); ?>"/>
1560
1561 <p><?php esc_html_e( 'Please enter the authentication code from your two-factor authentication app, or a recovery code, to login:', 'userswp' ); ?></p>
1562
1563 <?php
1564 echo aui()->input(
1565 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1566 'type' => 'text',
1567 'id' => 'authcode',
1568 'name' => 'authcode',
1569 'placeholder' => esc_attr__( 'Authentication Code', 'userswp' ),
1570 'value' => '',
1571 'label' => esc_html__( 'Authentication Code', 'userswp' ),
1572 'extra_attributes' => array(
1573 'autocomplete' => 'one-time-code',
1574 ),
1575 )
1576 );
1577
1578 echo aui()->button(
1579 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
1580 'type' => 'submit',
1581 'class' => 'btn btn-primary btn-block text-uppercase uwp-2fa-submit',
1582 'name' => 'submit',
1583 'icon' => '',
1584 'content' => esc_html__( 'Log In', 'userswp' ),
1585 )
1586 );
1587 ?>
1588 </form>
1589 </div>
1590
1591 <?php
1592 return ob_get_clean();
1593 }
1594
1595 public function get_wp2fa_provider_for_user( $user ) {
1596 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'get_available_providers_for_user' ) ) {
1597 $provider = \WP2FA\Authenticator\Login::get_available_providers_for_user( $user );
1598 if ( is_array( $provider ) ) {
1599 $provider = key( $provider );
1600 }
1601
1602 return $provider;
1603 }
1604
1605 if ( class_exists( '\WP2FA\Admin\Helpers\User_Helper' ) && method_exists( '\WP2FA\Admin\Helpers\User_Helper', 'get_enabled_method_for_user' ) ) {
1606 return \WP2FA\Admin\Helpers\User_Helper::get_enabled_method_for_user( $user );
1607 }
1608
1609 return '';
1610 }
1611
1612 public function get_wp2fa_backup_codes_remaining( $user ) {
1613 if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'codes_remaining_for_user' ) ) {
1614 return \WP2FA\Methods\Backup_Codes::codes_remaining_for_user( $user );
1615 }
1616
1617 if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'codes_remaining_for_user' ) ) {
1618 return \WP2FA\Authenticator\Backup_Codes::codes_remaining_for_user( $user );
1619 }
1620
1621 return 0;
1622 }
1623
1624 public function validate_wp2fa_totp_authentication( $user ) {
1625 if ( class_exists( '\WP2FA\Methods\TOTP' ) && method_exists( '\WP2FA\Methods\TOTP', 'validate_totp_authentication' ) ) {
1626 return \WP2FA\Methods\TOTP::validate_totp_authentication( $user );
1627 }
1628
1629 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_totp_authentication' ) ) {
1630 return \WP2FA\Authenticator\Login::validate_totp_authentication( $user );
1631 }
1632
1633 return false;
1634 }
1635
1636 public function validate_wp2fa_email_authentication( $user ) {
1637 if ( class_exists( '\WP2FA\Authenticator\Login' ) && method_exists( '\WP2FA\Authenticator\Login', 'validate_email_authentication' ) ) {
1638 return \WP2FA\Authenticator\Login::validate_email_authentication( $user );
1639 }
1640
1641 if ( class_exists( '\WP2FA\Authenticator\Authentication' ) && method_exists( '\WP2FA\Authenticator\Authentication', 'validate_token' ) && isset( $_REQUEST['authcode'] ) ) {
1642 return \WP2FA\Authenticator\Authentication::validate_token( $user, sanitize_text_field( wp_unslash( $_REQUEST['authcode'] ) ) );
1643 }
1644
1645 return false;
1646 }
1647
1648 public function validate_wp2fa_backup_codes( $user ) {
1649 if ( class_exists( '\WP2FA\Methods\Backup_Codes' ) && method_exists( '\WP2FA\Methods\Backup_Codes', 'validate_backup_codes' ) ) {
1650 return \WP2FA\Methods\Backup_Codes::validate_backup_codes( $user );
1651 }
1652
1653 if ( class_exists( '\WP2FA\Authenticator\Backup_Codes' ) && method_exists( '\WP2FA\Authenticator\Backup_Codes', 'validate_backup_codes' ) ) {
1654 return \WP2FA\Authenticator\Backup_Codes::validate_backup_codes( $user );
1655 }
1656
1657 return false;
1658 }
1659
1660 /**
1661 * Validates the Wordfence 2FA code submitted from the uwp-2fa form and,
1662 * if valid, completes the login by setting the auth cookie.
1663 *
1664 * @since 1.2.5
1665 * @package userswp
1666 *
1667 * @param WP_User $user The user attempting to complete 2FA login.
1668 *
1669 * @return void
1670 */
1671 public function process_login_wordfence_2fa( $user ) {
1672 if ( ! $this->wordfence_2fa_available() ) {
1673 $message = aui()->alert(
1674 array(
1675 'type' => 'error',
1676 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1677 )
1678 );
1679
1680 wp_send_json_error( array( 'message' => $message ) );
1681 }
1682
1683 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1684
1685 if ( ! wp_verify_nonce( $nonce, 'uwp-wfls-2fa-' . $user->ID ) ) {
1686 $message = aui()->alert(
1687 array(
1688 'type' => 'error',
1689 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1690 )
1691 );
1692
1693 wp_send_json_error( array( 'message' => $message ) );
1694 }
1695
1696 $code = isset( $_POST['authcode'] ) ? sanitize_text_field( wp_unslash( $_POST['authcode'] ) ) : '';
1697
1698 if ( empty( $code ) || true !== \WordfenceLS\Controller_TOTP::shared()->validate_2fa( $user, $code ) ) {
1699 do_action( 'wp_login_failed', $user->user_login );
1700
1701 $message = aui()->alert(
1702 array(
1703 'type' => 'error',
1704 'content' => __( 'Invalid verification code.', 'userswp' ),
1705 )
1706 );
1707
1708 wp_send_json_error( array( 'message' => $message ) );
1709 }
1710
1711 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : false;
1712
1713 // Complete the login the same way wp_signon() would have, now that 2FA has been verified.
1714 wp_set_auth_cookie( $user->ID, $remember );
1715 wp_set_current_user( $user->ID );
1716
1717 do_action( 'wp_login', $user->user_login, $user );
1718
1719 $message = aui()->alert(
1720 array(
1721 'type' => 'success',
1722 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1723 )
1724 );
1725
1726 wp_send_json_success( array( 'message' => $message ) );
1727 }
1728
1729 public function process_login_2fa() {
1730 global $wp2fa;
1731
1732 if ( ! isset( $_POST['uwp-auth-id'], $_POST['wp-auth-nonce'] ) ) {
1733 return;
1734 }
1735
1736 $auth_id = (int) $_POST['uwp-auth-id'];
1737 $user = get_userdata( $auth_id );
1738
1739 if ( ! $user ) {
1740 $message = aui()->alert(
1741 array(
1742 'type' => 'error',
1743 'content' => __( 'Invalid user data. Please try again.', 'userswp' ),
1744 )
1745 );
1746
1747 wp_send_json_error( array( 'message' => $message ) );
1748 }
1749
1750 if ( isset( $_POST['provider'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1751 $provider = sanitize_textarea_field( wp_unslash( $_POST['provider'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing
1752 } else {
1753 $provider = '';
1754 }
1755
1756 if ( 'wordfence' === $provider ) {
1757 $this->process_login_wordfence_2fa( $user );
1758
1759 return;
1760 }
1761
1762 $nonce = ( isset( $_POST['wp-auth-nonce'] ) ) ? sanitize_textarea_field( wp_unslash( $_POST['wp-auth-nonce'] ) ) : '';
1763
1764 if ( true !== \WP2FA\Authenticator\Login::verify_login_nonce( $user->ID, $nonce ) ) {
1765 $message = aui()->alert(
1766 array(
1767 'type' => 'error',
1768 'content' => __( 'Invalid request! Please try again.', 'userswp' ),
1769 )
1770 );
1771
1772 wp_send_json_error( array( 'message' => $message ) );
1773 }
1774
1775 $error = '';
1776
1777 try {
1778 $is_enabled = \WP2FA\Admin\Controllers\Settings::is_provider_enabled_for_role( \WP2FA\Admin\Helpers\User_Helper::get_user_role( $user ), $provider );
1779
1780 if ( ! $is_enabled ) {
1781 $error = __( 'Invalid 2FA provider for user.', 'userswp' );
1782 }
1783 } catch ( \Exception $e ) {
1784 $error = $e->getMessage();
1785 }
1786
1787 if ( $error ) {
1788 do_action( 'wp_login_failed', $user->user_login );
1789
1790 $message = aui()->alert(
1791 array(
1792 'type' => 'error',
1793 'content' => $error
1794 )
1795 );
1796
1797 wp_send_json_error( array( 'message' => $message ) );
1798 }
1799
1800 // If this is an email login, or if the user failed validation previously, lets send the code to the user.
1801 if ( 'email' === $provider && true !== \WP2FA\Authenticator\Login::pre_process_email_authentication( $user ) ) {
1802
1803 }
1804
1805 // Validate TOTP.
1806 if ( 'totp' === $provider && true !== $this->validate_wp2fa_totp_authentication( $user ) ) {
1807 do_action( 'wp_login_failed', $user->user_login );
1808
1809 $message = aui()->alert(
1810 array(
1811 'type' => 'error',
1812 'content' => __( 'Invalid verification code.', 'userswp' ),
1813 )
1814 );
1815
1816 wp_send_json_error( array( 'message' => $message ) );
1817 }
1818
1819 // Validate Email.
1820 if ( 'email' === $provider && true !== $this->validate_wp2fa_email_authentication( $user ) ) {
1821 do_action( 'wp_login_failed', $user->user_login );
1822
1823 if ( isset( $_REQUEST['wp-2fa-email-code-resend'] ) && 1 == $_REQUEST['wp-2fa-email-code-resend'] ) {
1824 $message = aui()->alert(
1825 array(
1826 'type' => 'info',
1827 'content' => __( 'A new code has been sent.', 'userswp' ),
1828 )
1829 );
1830
1831 wp_send_json_error( array( 'message' => $message ) );
1832 } else {
1833 $message = aui()->alert(
1834 array(
1835 'type' => 'error',
1836 'content' => __( 'Invalid verification code.', 'userswp' ),
1837 )
1838 );
1839
1840 wp_send_json_error( array( 'message' => $message ) );
1841 }
1842 }
1843
1844 // Backup Codes.
1845 if ( 'backup_codes' === $provider && true !== $this->validate_wp2fa_backup_codes( $user ) ) {
1846 do_action( 'wp_login_failed', $user->user_login );
1847
1848 $message = aui()->alert(
1849 array(
1850 'type' => 'error',
1851 'content' => __( 'Invalid backup code.', 'userswp' ),
1852 )
1853 );
1854
1855 wp_send_json_error( array( 'message' => $message ) );
1856 }
1857
1858 \WP2FA\Authenticator\Login::delete_login_nonce( $user->ID );
1859
1860 $rememberme = false;
1861 $remember = ( isset( $_REQUEST['rememberme'] ) ) ? filter_var( $_REQUEST['rememberme'], FILTER_VALIDATE_BOOLEAN ) : '';
1862
1863 if ( ! empty( $remember ) ) {
1864 $rememberme = true;
1865 }
1866
1867 wp_set_auth_cookie( $user->ID, $rememberme );
1868
1869 do_action( 'two_factor_user_authenticated', $user );
1870
1871 if ( defined( 'WP_2FA_PREFIX' ) ) {
1872 do_action( WP_2FA_PREFIX . 'user_authenticated', $user );
1873 }
1874
1875 $message = aui()->alert(
1876 array(
1877 'type' => 'success',
1878 'content' => __( 'Validation successful. Redirecting...', 'userswp' ),
1879 )
1880 );
1881
1882 wp_send_json_success( array( 'message' => $message ) );
1883 }
1884
1885 public function get_login_redirect_url( $data, $user ) {
1886 if ( is_int( $user ) ) {
1887 $user = get_userdata( $user );
1888 }
1889
1890 $redirect_page_id = uwp_get_option( 'login_redirect_to', - 1 );
1891 $custom_url = uwp_get_option( 'login_redirect_custom_url' );
1892
1893 if ( $user && isset( $user->roles[0] ) ) {
1894 $user_role = $user->roles[0];
1895 $redirect_page_id = uwp_get_option( 'login_redirect_to_' . $user_role, $redirect_page_id );
1896 $custom_url = uwp_get_option( 'login_redirect_custom_url_' . $user_role );
1897 }
1898
1899 if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) {
1900 $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] );
1901 } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) {
1902 $redirect_to = esc_url_raw( $data['redirect_to'] );
1903 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) {
1904 if ( uwp_is_wpml() ) {
1905 $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE );
1906 if ( ! empty( $wpml_page_id ) ) {
1907 $redirect_page_id = $wpml_page_id;
1908 }
1909 }
1910 $redirect_to = get_permalink( $redirect_page_id );
1911 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) {
1912 $redirect_to = esc_url( wp_get_referer() );
1913 } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && ! empty( $custom_url ) ) {
1914 $redirect_to = $custom_url;
1915 } else {
1916 $redirect_to = home_url( '/' );
1917 $redirect_to = apply_filters( 'login_redirect', $redirect_to, '', $user );
1918 }
1919
1920 return apply_filters( 'uwp_login_redirect', $redirect_to, $redirect_page_id, $data, $user );
1921 }
1922
1923 /**
1924 * Processes forgot password form submission.
1925 *
1926 * @since 1.0.0
1927 * @package userswp
1928 *
1929 */
1930 public function process_forgot() {
1931
1932 $data = $_POST;
1933
1934 if ( ! isset( $data['uwp_forgot_nonce'] ) ) {
1935 return;
1936 }
1937
1938 if ( ! isset( $data['uwp_forgot_nonce'] ) || ! wp_verify_nonce( $data['uwp_forgot_nonce'], 'uwp-forgot-nonce' ) ) {
1939 $message = aui()->alert(
1940 array(
1941 'type' => 'error',
1942 'content' => __( 'Security verification failed. Try again.', 'userswp' ),
1943 )
1944 );
1945 if ( wp_doing_ajax() ) {
1946 wp_send_json_error( $message );
1947 } else {
1948 return;
1949 }
1950 }
1951
1952 global $uwp_notices;
1953
1954 do_action( 'uwp_before_validate', 'forgot' );
1955
1956 $result = uwp_validate_fields( $data, 'forgot' );
1957
1958 $result = apply_filters( 'uwp_validate_result', $result, 'forgot', $data );
1959
1960 if ( is_wp_error( $result ) ) {
1961 $message = aui()->alert(
1962 array(
1963 'type' => 'error',
1964 'content' => $result->get_error_message(),
1965 )
1966 );
1967 if ( wp_doing_ajax() ) {
1968 wp_send_json_error( $message );
1969 } else {
1970 $uwp_notices[] = array( 'forgot' => $message );
1971
1972 return;
1973 }
1974 }
1975
1976 do_action( 'uwp_after_validate', $result, 'forgot', $data );
1977
1978 $login_or_email = trim( $data['email'] );
1979 $user_data = is_email( $login_or_email )
1980 ? get_user_by( 'email', $login_or_email )
1981 : get_user_by( 'login', $login_or_email );
1982
1983 // if no user we fake it and bail
1984 if ( ! $user_data ) {
1985 $args = apply_filters(
1986 'uwp_forgot_error_message',
1987 array(
1988 'type' => 'error',
1989 'content' => __( 'Invalid username/email or user doesn\'t exist.', 'userswp' ),
1990 )
1991 );
1992
1993 $message = aui()->alert( $args );
1994 if ( wp_doing_ajax() ) {
1995 wp_send_json_success( $message );
1996 } else {
1997 $uwp_notices[] = array( 'forgot' => $message );
1998
1999 return;
2000 }
2001 }
2002
2003 // make sure user account is active before account reset
2004 $mod_value = get_user_meta( $user_data->ID, 'uwp_mod', true );
2005 if ( $mod_value == 'email_unconfirmed' ) {
2006 $resend_link = uwp_get_forgot_page_url();
2007 $resend_link = add_query_arg(
2008 array(
2009 'user_id' => $user_data->ID,
2010 'action' => 'uwp_resend',
2011 '_nonce' => wp_create_nonce('uwp_resend'),
2012 ),
2013 $resend_link
2014 );
2015 $message = aui()->alert(
2016 array(
2017 'type' => 'error',
2018 'content' => sprintf(__('Your account is not activated yet. Please activate your account first. <a href="%s">Resend</a>.', 'userswp'), $resend_link),
2019 )
2020 );
2021 if ( wp_doing_ajax() ) {
2022 wp_send_json_error( $message );
2023 } else {
2024 $uwp_notices[] = array( 'forgot' => $message );
2025 return;
2026 }
2027 }
2028
2029 $user_data = get_userdata( $user_data->ID );
2030
2031 $allow = apply_filters( 'allow_password_reset', true, $user_data->ID );
2032
2033 if ( ! $allow ) {
2034 return false;
2035 } elseif ( is_wp_error( $allow ) ) {
2036 return false;
2037 }
2038
2039 $as_password = apply_filters( 'uwp_forgot_message_as_password', false );
2040
2041 $reset_link = '';
2042
2043 if ( $as_password ) {
2044 $new_pass = wp_generate_password( 12, false );
2045 wp_set_password( $new_pass, $user_data->ID );
2046 if ( ! uwp_get_option( 'change_disable_password_nag' ) ) {
2047 update_user_meta( $user_data->ID, 'default_password_nag', true ); //Set up the Password change nag.
2048 }
2049 $message = '<p><b>' . __( 'Your login Information :', 'userswp' ) . '</b></p>';
2050 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2051 $message .= '<p>' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '</p>';
2052
2053 } else {
2054 // Use WordPress core to generate, hash (wp_fast_hash in WP 6.8+), and store the reset key.
2055 // This ensures compatibility with check_password_reset_key() on all WP versions.
2056 $key = get_password_reset_key( $user_data );
2057
2058 if ( is_wp_error( $key ) ) {
2059 if ( wp_doing_ajax() ) {
2060 wp_send_json_error( $key->get_error_message() );
2061 } else {
2062 $uwp_notices[] = array( 'forgot' => aui()->alert( array( 'type' => 'error', 'content' => $key->get_error_message() ) ) );
2063 return;
2064 }
2065 }
2066
2067 $message = '<p>' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '</p>';
2068 $message .= home_url( '/' ) . '</p>';
2069 $message .= '<p>' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '</p>';
2070 $message .= '<p>' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '</p>';
2071 $message .= '<p>' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '</p>';
2072 $reset_page = uwp_get_page_id( 'reset_page', false );
2073 if ( $reset_page ) {
2074 $reset_link = add_query_arg(
2075 array(
2076 'key' => $key,
2077 'login' => rawurlencode( $user_data->user_login ),
2078 ),
2079 get_permalink( $reset_page )
2080 );
2081 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
2082 } else {
2083 $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' );
2084 $message .= "<a href='" . $reset_link . "' target='_blank'>" . $reset_link . '</a>' . "\r\n";
2085 }
2086 $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link );
2087 }
2088
2089 $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID );
2090
2091 $email_vars = array(
2092 'user_id' => $user_data->ID,
2093 'login_details' => $message,
2094 'reset_link' => $reset_link,
2095 );
2096
2097 UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars );
2098
2099 do_action( 'uwp_after_process_forgot', $data );
2100
2101 $message = aui()->alert(
2102 array(
2103 'type' => 'success',
2104 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ),
2105 )
2106 );
2107 if ( wp_doing_ajax() ) {
2108 wp_send_json_success( $message );
2109 } else {
2110 $uwp_notices[] = array( 'forgot' => $message );
2111 }
2112 }
2113
2114 /**
2115 * Processes change password form submission.
2116 *
2117 * @since 1.0.0
2118 * @package userswp
2119 *
2120 */
2121 public function process_change() {
2122
2123 $data = $_POST;
2124
2125 if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) {
2126 return;
2127 }
2128
2129 global $uwp_notices;
2130
2131 if ( is_uwp_account_page() ) {
2132 $notice_type = 'account';
2133 } else {
2134 $notice_type = 'change';
2135 }
2136
2137 do_action( 'uwp_before_validate', 'change' );
2138
2139 $result = uwp_validate_fields( $data, 'change' );
2140
2141 $result = apply_filters( 'uwp_validate_result', $result, 'change', $data );
2142
2143 if ( is_wp_error( $result ) ) {
2144 $message = aui()->alert(
2145 array(
2146 'type' => 'error',
2147 'content' => $result->get_error_message(),
2148 )
2149 );
2150 $uwp_notices[] = array( $notice_type => $message );
2151
2152 return;
2153 }
2154
2155 do_action( 'uwp_after_validate', $result, 'change', $data );
2156
2157 $user_data = get_user_by( 'id', get_current_user_id() );
2158
2159 if ( ! $user_data ) {
2160 $message = aui()->alert(
2161 array(
2162 'type' => 'error',
2163 'content' => $user_data->get_error_message(),
2164 )
2165 );
2166 $uwp_notices[] = array( $notice_type => $message );
2167
2168 return;
2169 }
2170
2171 $email_vars = array(
2172 'user_id' => $user_data->ID,
2173 );
2174
2175 UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars );
2176
2177 wp_set_password( $result['password'], $user_data->ID );
2178
2179 $password_nag = get_user_option( 'default_password_nag', $user_data->ID );
2180 if ( $password_nag ) {
2181 delete_user_meta( $user_data->ID, 'default_password_nag' );
2182 }
2183
2184 delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' );
2185
2186 $message = aui()->alert(
2187 array(
2188 'type' => 'success',
2189 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ),
2190 )
2191 );
2192
2193 $uwp_notices[] = array( $notice_type => $message );
2194
2195 do_action( 'uwp_after_process_change', $data );
2196
2197 wp_logout();
2198 exit();
2199 }
2200
2201 /**
2202 * Processes reset password form submission.
2203 *
2204 * @since 1.0.0
2205 * @package userswp
2206 *
2207 */
2208 public function process_reset() {
2209
2210 $data = $_POST;
2211
2212 if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) {
2213 wp_die( esc_html__( 'No spam please!', 'userswp' ) );
2214 }
2215
2216 if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) {
2217 return;
2218 }
2219
2220 global $uwp_notices;
2221
2222 do_action( 'uwp_before_validate', 'reset' );
2223
2224 $result = uwp_validate_fields( $data, 'reset' );
2225
2226 $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data );
2227
2228 if ( is_wp_error( $result ) ) {
2229 $message = aui()->alert(
2230 array(
2231 'type' => 'error',
2232 'content' => $result->get_error_message(),
2233 )
2234 );
2235 $uwp_notices[] = array( 'reset' => $message );
2236
2237 return;
2238 }
2239
2240 do_action( 'uwp_after_validate', $result, 'reset', $data );
2241
2242 $login = sanitize_text_field( $data['uwp_reset_username'] );
2243 $key = sanitize_text_field( $data['uwp_reset_key'] );
2244
2245 $user = get_user_by( 'login', $login );
2246 if ( ! $user ) {
2247 $message = aui()->alert(
2248 array(
2249 'type' => 'error',
2250 'content' => __( 'Invalid username.', 'userswp' ),
2251 )
2252 );
2253 $uwp_notices[] = array( 'reset' => $message );
2254
2255 return;
2256 }
2257
2258 clean_user_cache( $user );
2259
2260 $user_data = check_password_reset_key( $key, $login );
2261
2262 if ( is_wp_error( $user_data ) ) {
2263 $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data );
2264 $message = aui()->alert(
2265 array(
2266 'type' => 'error',
2267 'content' => $error,
2268 )
2269 );
2270 $uwp_notices[] = array( 'reset' => $message );
2271
2272 return;
2273 }
2274
2275 $email_vars = array(
2276 'user_id' => $user_data->ID,
2277 );
2278
2279 UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars );
2280
2281 wp_set_password( $data['password'], $user_data->ID );
2282
2283 $login_page_url = uwp_get_login_page_url();
2284 $message = sprintf( __( 'Password updated successfully. Please <a href="%s">login</a> with your new password.', 'userswp' ), $login_page_url );
2285 $message = apply_filters( 'uwp_reset_password_success_message', $message, $data );
2286 $message = aui()->alert(
2287 array(
2288 'type' => 'success',
2289 'content' => $message,
2290 )
2291 );
2292 $uwp_notices[] = array( 'reset' => $message );
2293
2294 do_action( 'uwp_after_process_reset', $data );
2295 }
2296
2297 /**
2298 * Processes account form submission.
2299 *
2300 * @since 1.0.0
2301 * @package userswp
2302 *
2303 */
2304 public function process_account() {
2305
2306 $data = wp_unslash( $_POST );
2307 $files = $_FILES;
2308
2309 if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) {
2310 return;
2311 }
2312
2313 if ( ! is_user_logged_in() ) {
2314 return;
2315 }
2316
2317 global $uwp_notices;
2318 $file_obj = new UsersWP_Files();
2319
2320 do_action( 'uwp_before_validate', 'account' );
2321
2322 $result = uwp_validate_fields( $data, 'account' );
2323
2324 $result = apply_filters( 'uwp_validate_result', $result, 'account', $data );
2325
2326 if ( is_wp_error( $result ) ) {
2327 $message = aui()->alert(
2328 array(
2329 'type' => 'error',
2330 'content' => $result->get_error_message(),
2331 )
2332 );
2333 $uwp_notices[] = array( 'account' => $message );
2334
2335 return;
2336 }
2337
2338 $uploads_result = $file_obj->validate_uploads( $files, 'account' );
2339
2340 if ( is_wp_error( $uploads_result ) ) {
2341 $message = aui()->alert(
2342 array(
2343 'type' => 'error',
2344 'content' => $uploads_result->get_error_message(),
2345 )
2346 );
2347 $uwp_notices[] = array( 'account' => $message );
2348
2349 return;
2350 }
2351
2352 do_action( 'uwp_after_validate', $result, 'account', $data );
2353
2354 //unset if value is empty for files
2355 foreach ( $uploads_result as $upload_file_key => $upload_file_value ) {
2356 if ( empty( $upload_file_value ) ) {
2357 unset( $uploads_result[ $upload_file_key ] );
2358 }
2359 }
2360
2361 global $wpdb;
2362 $file_field_names = $wpdb->get_col(
2363 $wpdb->prepare(
2364 "SELECT htmlvar_name FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE form_type = %s AND field_type IN ('file','image')",
2365 'account'
2366 )
2367 );
2368 foreach ( $file_field_names as $file_field_name ) {
2369 if ( isset( $result[ $file_field_name ] ) && ! isset( $uploads_result[ $file_field_name ] ) ) {
2370 unset( $result[ $file_field_name ] );
2371 }
2372 }
2373
2374 $result = array_merge( $result, $uploads_result );
2375
2376 $args = array(
2377 'ID' => get_current_user_id(),
2378 );
2379
2380 if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) {
2381 $args['display_name'] = $result['first_name'] . ' ' . $result['last_name'];
2382 }
2383
2384 if ( isset( $result['first_name'] ) ) {
2385 $args['first_name'] = $result['first_name'];
2386 }
2387
2388 if ( isset( $result['last_name'] ) ) {
2389 $args['last_name'] = $result['last_name'];
2390 }
2391
2392 if ( isset( $result['user_url'] ) ) {
2393 $args['user_url'] = $result['user_url'];
2394 }
2395
2396 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
2397 $args['display_name'] = $result['display_name'];
2398 }
2399
2400 if ( isset( $result['password'] ) ) {
2401 $args['user_pass'] = $result['password'];
2402 }
2403
2404 $user_id = wp_update_user( $args );
2405
2406 if ( is_wp_error( $user_id ) ) {
2407 $message = aui()->alert(
2408 array(
2409 'type' => 'error',
2410 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ),
2411 )
2412 );
2413 $uwp_notices[] = array( 'account' => $message );
2414
2415 return;
2416 }
2417
2418 $res = $this->save_user_extra_fields( $user_id, $result, 'account' );
2419
2420 if ( ! $res ) {
2421 $message = aui()->alert(
2422 array(
2423 'type' => 'error',
2424 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ),
2425 )
2426 );
2427 $uwp_notices[] = array( 'account' => $message );
2428
2429 return;
2430 }
2431
2432 //updating bio field after saving extra fields to reflect the points in mycred add on.
2433 if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) {
2434 $args = array(
2435 'ID' => $user_id,
2436 'description' => $result['bio'],
2437 );
2438 wp_update_user( $args );
2439 }
2440
2441 $user_data = get_userdata( $user_id );
2442
2443 $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id );
2444
2445 if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) {
2446
2447 if ( email_exists( trim( $result['email'] ) ) ) {
2448 $message = aui()->alert(
2449 array(
2450 'type' => 'error',
2451 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ),
2452 )
2453 );
2454
2455 $uwp_notices[] = array( 'account' => $message );
2456 return;
2457
2458 }
2459
2460 $hash = md5( $result['email'] . time() . wp_rand() );
2461 $new_admin_email = array(
2462 'hash' => $hash,
2463 'newemail' => $result['email'],
2464 );
2465
2466 update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email );
2467
2468 $new_email_link = add_query_arg(
2469 array(
2470 'uwp_new_email' => 'yes',
2471 'key' => $hash,
2472 'login' => $user_data->user_login,
2473 ),
2474 uwp_get_account_page_url()
2475 );
2476
2477 $email_vars = array(
2478 'user_id' => $user_id,
2479 'new_email' => $result['email'],
2480 'new_email_link' => esc_url( $new_email_link ),
2481 );
2482
2483 UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars );
2484
2485 $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data );
2486 $message = aui()->alert(
2487 array(
2488 'type' => 'success',
2489 'content' => $message,
2490 )
2491 );
2492
2493 $uwp_notices[] = array( 'account' => $message );
2494
2495 } else {
2496 $email_vars = array(
2497 'user_id' => $user_id,
2498 'form_fields' => $form_fields,
2499 );
2500
2501 UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars );
2502
2503 $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data );
2504 $message = aui()->alert(
2505 array(
2506 'type' => 'success',
2507 'content' => $message,
2508 )
2509 );
2510
2511 $uwp_notices[] = array( 'account' => $message );
2512 }
2513
2514 do_action( 'uwp_after_process_account', $data, $user_id );
2515 }
2516
2517 /**
2518 * Modifies the forms field in email based on the form type.
2519 *
2520 * @param string $form_fields Form fields.
2521 * @param string $type Form type.
2522 * @param int $user_id User ID.
2523 *
2524 * @return string Modified mail field.
2525 * @package userswp
2526 * @subpackage userswp/includes
2527 *
2528 */
2529 public function init_mail_form_fields( $form_fields, $type, $user_id ) {
2530 switch ( $type ) {
2531 case 'register':
2532 $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true );
2533 $fields = get_register_form_fields( $form_id );
2534 $user_data = get_userdata( $user_id );
2535 if ( ! empty( $fields ) && is_array( $fields ) ) {
2536 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2537 $excluded = uwp_get_excluded_fields();
2538 foreach ( $fields as $key => $field ) {
2539 if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) {
2540 continue;
2541 }
2542 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2543 $field_value = $user_data->user_email;
2544 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2545 $field_value = $user_data->user_login;
2546 } elseif ( $field->htmlvar_name == 'bio' ) {
2547 $field_value = get_user_meta( $user_id, 'description', true );
2548 } else {
2549 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2550 }
2551
2552 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2553 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2554 }
2555
2556 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2557 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2558 }
2559 }
2560 }
2561 break;
2562 case 'account':
2563 $fields = get_account_form_fields();
2564 $user_data = get_userdata( $user_id );
2565 if ( ! empty( $fields ) && is_array( $fields ) ) {
2566 $form_fields = '<p><b>' . __( 'User Information:', 'userswp' ) . '</b></p>';
2567 foreach ( $fields as $key => $field ) {
2568 if ( $field->is_active != '1' ) {
2569 continue;
2570 }
2571 if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) {
2572 $field_value = $user_data->user_email;
2573 } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) {
2574 $field_value = $user_data->user_login;
2575 } elseif ( $field->htmlvar_name == 'bio' ) {
2576 $field_value = get_user_meta( $user_id, 'description', true );
2577 } else {
2578 $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name );
2579 }
2580
2581 if ( is_array( $field_value ) && count( $field_value ) > 0 ) {
2582 $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value );
2583 }
2584
2585 if ( isset( $field->site_title ) && ! empty( $field_value ) ) {
2586 $form_fields .= '<p><b>' . __( wp_unslash( $field->site_title ), 'userswp' ) . '</b>:&nbsp;' . $field_value . '</p>';
2587 }
2588 }
2589 }
2590 break;
2591 }
2592
2593 return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id );
2594 }
2595
2596 /**
2597 *
2598 *
2599 * @return void
2600 * @since 1.0.12 Unlink file.
2601 * @package userswp
2602 * @since 1.0.0
2603 */
2604 public function upload_file_remove() {
2605 global $wpdb;
2606
2607 check_ajax_referer( 'uwp_basic_nonce', 'security' );
2608
2609 // Check user logged in.
2610 if ( ! is_user_logged_in() ) {
2611 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) );
2612 wp_send_json_error( array( 'message' => $message ) );
2613 }
2614
2615 $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0;
2616 $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : '';
2617
2618 if ( empty( $user_id ) || empty( $htmlvar ) ) {
2619 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) );
2620 wp_send_json_error( array( 'message' => $message ) );
2621 }
2622
2623 // Validate the user / admin.
2624 if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) {
2625 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) );
2626 wp_send_json_error( array( 'message' => $message ) );
2627 }
2628
2629 if ( $htmlvar == 'banner_thumb' ) {
2630 $field_key = 'banner';
2631 $type = 'banner';
2632 } else if ( $htmlvar == 'avatar_thumb' ) {
2633 $field_key = 'avatar';
2634 $type = 'avatar';
2635 } else {
2636 $field_key = $htmlvar;
2637 $type = '';
2638 }
2639
2640 $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) );
2641
2642 // Check field exists.
2643 if ( empty( $field ) ) {
2644 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) );
2645 wp_send_json_error( array( 'message' => $message ) );
2646 }
2647
2648 // Validate field access.
2649 if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) {
2650 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) );
2651 wp_send_json_error( array( 'message' => $message ) );
2652 }
2653
2654 if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) {
2655 $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) );
2656 wp_send_json_error( array( 'message' => $message ) );
2657 }
2658
2659 $value = uwp_get_usermeta( $user_id, $htmlvar );
2660
2661 uwp_update_usermeta( $user_id, $htmlvar, '' );
2662
2663 if ( $value && validate_file( $value ) === 0 ) {
2664 $uploads = wp_upload_dir();
2665 $upload_path = $uploads['basedir'];
2666
2667 if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) {
2668 // Get the relative url.
2669 $value = uwp_get_file_relative_url( $value );
2670 }
2671
2672 $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' );
2673
2674 // Canonicalize and enforce containment inside the uploads directory before deleting.
2675 $real_upload_path = realpath( $upload_path );
2676 $real_unlink_file = realpath( $unlink_file );
2677
2678 if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file )
2679 && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2680 wp_delete_file( $real_unlink_file );
2681
2682 // For avatar/banner, also remove the original (non-thumb) file, only if it is the exact file this user cropped.
2683 if ( $type ) {
2684 $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file );
2685 $real_unlink_ori_file = realpath( $unlink_ori_file );
2686 $prev_original = get_user_meta( $user_id, '_uwp_' . $type . '_original', true );
2687 $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false;
2688
2689 if ( $expected_original && $real_unlink_ori_file && $expected_original === $real_unlink_ori_file
2690 && $real_unlink_ori_file !== $real_unlink_file
2691 && is_file( $real_unlink_ori_file )
2692 && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) {
2693 wp_delete_file( $real_unlink_ori_file );
2694 }
2695 }
2696 }
2697 }
2698
2699 // Clear crop bookkeeping meta (pending upload is stored against the uploader).
2700 if ( $type ) {
2701 delete_user_meta( $user_id, '_uwp_' . $type . '_original' );
2702 delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' );
2703 }
2704
2705 wp_send_json_success();
2706
2707 wp_die();
2708 }
2709
2710 /**
2711 * Form field template for datepicker field type.
2712 *
2713 * @param string $html Form field html
2714 * @param object $field Field info.
2715 * @param string $value Form field default value.
2716 * @param string $form_type Form type
2717 *
2718 * @return string Modified form field html.
2719 * @package userswp
2720 *
2721 * @since 1.0.0
2722 */
2723 public function form_input_datepicker( $html, $field, $value, $form_type ) {
2724
2725 // Check if there is a field specific filter.
2726 if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) {
2727 $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2728 }
2729
2730 // If no html then we run the standard output.
2731 if ( empty( $html ) ) {
2732
2733 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2734 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2735 $bs_sr_only = $design_style ? 'sr-only' : '';
2736 $bs_form_control = $design_style ? 'form-control' : '';
2737 $extra_attributes = array();
2738 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2739 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2740
2741 ob_start(); // Start buffering;
2742
2743 $extra_fields = unserialize( $field->extra_fields );
2744
2745 if ( $extra_fields['date_format'] == '' ) {
2746 $extra_fields['date_format'] = 'yy-mm-dd';
2747 }
2748
2749 $date_format = $extra_fields['date_format'];
2750 $jquery_date_format = $date_format;
2751
2752 // check if we need to change the format or not
2753 $date_format_len = strlen( str_replace( ' ', '', $date_format ) );
2754 if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format.
2755
2756 $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format
2757 $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format
2758
2759 $date_format = str_replace( $search, $replace, $date_format );
2760 } else {
2761 $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format );
2762 }
2763
2764 if ( ! empty( $value ) && ! is_string( $value ) ) {
2765 $value = date( 'Y-m-d', $value );
2766 }
2767
2768 if ( $value == '0000-00-00' ) {
2769 $value = '';
2770 }//if date not set, then mark it empty
2771 $value = uwp_date( $value, 'Y-m-d', $date_format );
2772 $site_title = uwp_get_form_label( $field );
2773
2774 // bootstrap
2775 if ( $design_style ) {
2776 // flatpickr attributes
2777 $extra_attributes['data-alt-input'] = 'true';
2778 $extra_attributes['data-alt-format'] = $date_format;
2779 $extra_attributes['data-date-format'] = 'Y-m-d';
2780
2781 if ( 'dob' == $field->htmlvar_name ) {
2782 $extra_attributes['data-max-date'] = 'today';
2783 }
2784
2785 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2786
2787 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2788 array(
2789 'id' => esc_attr( $field->htmlvar_name ),
2790 'name' => esc_attr( $field->htmlvar_name ),
2791 'required' => ! empty( $field->is_required ) ? true : false,
2792 'label' => wp_kses_post( $site_title . $required ),
2793 'label_show' => true,
2794 'label_type' => 'hidden',
2795 'type' => 'datepicker',
2796 'title' => esc_html( $site_title ),
2797 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2798 'class' => '',
2799 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2800 'value' => esc_attr( $value ),
2801 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2802 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2803 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2804 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2805 )
2806 );
2807 } else {
2808 ?>
2809 <script type="text/javascript">
2810
2811 jQuery(function () {
2812 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker({
2813 changeMonth: true, changeYear: true
2814 <?php
2815 if ( $field->htmlvar_name == 'dob' ) {
2816 echo ", yearRange: '1900:+0'";
2817 } else {
2818 echo ", yearRange: '1900:2050'";
2819 }
2820 ?>
2821 <?php echo apply_filters( "uwp_datepicker_extra_{$field->htmlvar_name}", '' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>});
2822
2823 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("option", "dateFormat", '<?php echo esc_attr( $jquery_date_format ); ?>');
2824
2825 <?php if ( ! empty( $value ) ) { ?>
2826 var parsedDate = jQuery.datepicker.parseDate('yy-mm-dd', '<?php echo esc_attr( $value ); ?>');
2827 jQuery("#<?php echo esc_attr( $field->htmlvar_name ); ?>").datepicker("setDate", parsedDate);
2828 <?php } ?>
2829
2830 });
2831
2832 </script>
2833 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2834 class="
2835 <?php
2836 if ( $field->is_required ) {
2837 echo 'required_field';
2838 }
2839 ?>
2840 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2841
2842 <?php
2843
2844 if ( ! is_admin() ) {
2845 ?>
2846 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2847 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2848 <?php
2849 if ( $field->is_required ) {
2850 echo '<span>*</span>';
2851 }
2852 ?>
2853 </label>
2854 <?php } ?>
2855
2856 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2857 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2858 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2859 title="<?php echo esc_attr( $site_title ); ?>"
2860 type="text"
2861 <?php
2862 if ( $field->is_required == 1 ) {
2863 echo 'required="required"';
2864 }
2865 ?>
2866 value="<?php echo esc_attr( $value ); ?>"
2867 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2868
2869 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2870 <?php if ( $field->is_required ) { ?>
2871 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2872 <?php } ?>
2873 </div>
2874
2875 <?php
2876 }
2877
2878 $html = ob_get_clean();
2879 }
2880
2881 return $html;
2882 }
2883
2884 /**
2885 * Form field template for time field type.
2886 *
2887 * @param string $html Form field html
2888 * @param object $field Field info.
2889 * @param string $value Form field default value.
2890 * @param string $form_type Form type
2891 *
2892 * @return string Modified form field html.
2893 * @package userswp
2894 *
2895 * @since 1.0.0
2896 */
2897 public function form_input_time( $html, $field, $value, $form_type ) {
2898
2899 if ( has_filter( "uwp_form_input_html_time_{$field->htmlvar_name}" ) ) {
2900
2901 $html = apply_filters( "uwp_form_input_html_time_{$field->htmlvar_name}", $html, $field, $value, $form_type );
2902 }
2903
2904 // If no html then we run the standard output.
2905 if ( empty( $html ) ) {
2906
2907 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
2908 $bs_form_group = $design_style ? 'form-group mb-3' : '';
2909 $bs_sr_only = $design_style ? 'sr-only' : '';
2910 $bs_form_control = $design_style ? 'form-control bg-white' : '';
2911 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
2912 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
2913
2914 ob_start(); // Start buffering;
2915
2916 if ( $value != '' ) {
2917 $value = date( 'H:i', strtotime( $value ) );
2918 }
2919
2920 // flatpickr attributes
2921 $extra_attributes['data-enable-time'] = 'true';
2922 $extra_attributes['data-no-calendar'] = 'true';
2923 $extra_attributes['data-date-format'] = 'H:i';
2924 $site_title = uwp_get_form_label( $field );
2925 $label_type = is_admin() ? '' : 'top';
2926
2927 if ( $design_style ) {
2928 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
2929
2930 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2931 array(
2932 'id' => esc_attr( $field->htmlvar_name ),
2933 'name' => esc_attr( $field->htmlvar_name ),
2934 'required' => ! empty( $field->is_required ) ? true : false,
2935 'label' => wp_kses_post( $site_title . $required ),
2936 'label_show' => true,
2937 'label_type' => esc_attr( $label_type ),
2938 'type' => 'timepicker',
2939 'title' => esc_html( $site_title ),
2940 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
2941 'class' => '',
2942 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
2943 'value' => esc_attr( $value ),
2944 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
2945 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
2946 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
2947 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
2948 'input_group_right' => '<div class="input-group-text px-2 bg-transparent border-0x" onclick="jQuery(this).parent().parent().find(\'input\').val(\'\');"><i class="fas fa-times uwp-search-input-label-clear text-muted c-pointer" title="' . esc_attr__( 'Clear field', 'userswp' ) . '" ></i></div>',
2949 )
2950 );
2951 } else {
2952 ?>
2953 <script type="text/javascript">
2954 jQuery(document).ready(function () {
2955 jQuery('#<?php echo esc_attr( $field->htmlvar_name ); ?>').timepicker({
2956 showPeriod: true,
2957 showLeadingZero: true
2958 });
2959 });
2960 </script>
2961 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
2962 class="
2963 <?php
2964 if ( $field->is_required ) {
2965 echo 'required_field';
2966 }
2967 ?>
2968 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
2969
2970 <?php
2971 $site_title = uwp_get_form_label( $field );
2972 if ( ! is_admin() ) {
2973 ?>
2974 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
2975 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
2976 <?php
2977 if ( $field->is_required ) {
2978 echo '<span>*</span>';
2979 }
2980 ?>
2981 </label>
2982 <?php } ?>
2983
2984 <input readonly="readonly" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2985 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
2986 value="<?php echo esc_attr( $value ); ?>"
2987 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
2988 type="text"
2989 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"/>
2990
2991 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
2992 <?php if ( $field->is_required ) { ?>
2993 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
2994 <?php } ?>
2995 </div>
2996 <?php
2997 }
2998 $html = ob_get_clean();
2999 }
3000
3001 return $html;
3002 }
3003
3004 /**
3005 * Form field template for select field type.
3006 *
3007 * @param string $html Form field html
3008 * @param object $field Field info.
3009 * @param string $value Form field default value.
3010 * @param string $form_type Form type
3011 *
3012 * @return string Modified form field html.
3013 * @package userswp
3014 *
3015 * @since 1.0.0
3016 */
3017 public function form_input_select( $html, $field, $value, $form_type ) {
3018
3019 // Check if there is a field specific filter.
3020 if ( has_filter( "uwp_form_input_html_select_{$field->htmlvar_name}" ) ) {
3021 $html = apply_filters( "uwp_form_input_html_select_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3022 }
3023
3024 // Check if there is a field type specific filter.
3025 if ( has_filter( "uwp_form_input_html_select_{$field->field_type_key}" ) ) {
3026 $html = apply_filters( "uwp_form_input_html_select_{$field->field_type_key}", $html, $field, $value, $form_type );
3027 }
3028
3029 // If no html then we run the standard output.
3030 if ( empty( $html ) ) {
3031
3032 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3033 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3034 $bs_sr_only = $design_style ? 'sr-only' : '';
3035 $bs_form_control = $design_style ? 'form-control' : '';
3036 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3037 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3038
3039 ob_start(); // Start buffering;
3040 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
3041 $site_title = uwp_get_form_label( $field );
3042
3043 // bootstrap
3044 if ( $design_style ) {
3045
3046 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3047
3048 echo aui()->select(
3049 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3050 'id' => esc_attr( $field->htmlvar_name ),
3051 'name' => esc_attr( $field->htmlvar_name ),
3052 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3053 'title' => esc_html( $site_title ),
3054 'value' => esc_attr( $value ),
3055 'required' => (bool) $field->is_required,
3056 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3057 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3058 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3059 'label' => wp_kses_post( $site_title . $required ),
3060 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3061 'select2' => true,
3062 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3063 )
3064 );
3065 } else {
3066 ?>
3067 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3068 class="
3069 <?php
3070 if ( $field->is_required ) {
3071 echo 'required_field';
3072 }
3073 ?>
3074 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3075
3076 <?php
3077 if ( ! is_admin() ) {
3078 ?>
3079 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3080 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3081 <?php
3082 if ( $field->is_required ) {
3083 echo '<span>*</span>';
3084 }
3085 ?>
3086 </label>
3087 <?php } ?>
3088
3089 <?php
3090
3091 $select_options = '';
3092 if ( ! empty( $option_values_arr ) ) {
3093 foreach ( $option_values_arr as $option_row ) {
3094 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
3095 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3096
3097 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
3098 } else {
3099 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3100 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
3101 $selected = $option_value == $value ? 'selected="selected"' : '';
3102
3103 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
3104 }
3105 }
3106 }
3107 ?>
3108 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3109 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
3110 title="<?php echo esc_attr( $site_title ); ?>"
3111 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3112 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
3113 </select>
3114 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3115 <?php if ( $field->is_required ) { ?>
3116 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3117 <?php } ?>
3118 </div>
3119
3120 <?php
3121 }
3122 $html = ob_get_clean();
3123 }
3124
3125 return $html;
3126 }
3127
3128 /**
3129 * Form field template for multiselect field type.
3130 *
3131 * @param string $html Form field html
3132 * @param object $field Field info.
3133 * @param string $value Form field default value.
3134 * @param string $form_type Form type
3135 *
3136 * @return string Modified form field html.
3137 * @package userswp
3138 *
3139 * @since 1.0.0
3140 */
3141 public function form_input_multiselect( $html, $field, $value, $form_type ) {
3142
3143 // Check if there is a field specific filter.
3144 if ( has_filter( "uwp_form_input_html_multiselect_{$field->htmlvar_name}" ) ) {
3145 $html = apply_filters( "uwp_form_input_html_multiselect_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3146 }
3147
3148 if ( empty( $html ) ) {
3149
3150 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3151 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3152 $bs_sr_only = $design_style ? 'sr-only' : '';
3153 $bs_form_control = $design_style ? 'form-control' : '';
3154 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3155 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3156
3157 ob_start(); // Start buffering;
3158
3159 $multi_display = 'select';
3160 if ( ! empty( $field->extra_fields ) ) {
3161 $multi_display = unserialize( $field->extra_fields );
3162 }
3163
3164 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
3165 $site_title = uwp_get_form_label( $field );
3166 $value = is_array( $value ) ? $value : esc_attr( $value );
3167
3168 // bootstrap
3169 if ( $design_style ) {
3170
3171 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3172
3173 echo aui()->select(
3174 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3175 'id' => esc_attr( $field->htmlvar_name ),
3176 'name' => esc_attr( $field->htmlvar_name ),
3177 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3178 'title' => esc_html( $site_title ),
3179 'value' => $value,
3180 'required' => (bool) $field->is_required,
3181 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3182 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3183 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3184 'label' => wp_kses_post( $site_title . $required ),
3185 'options' => $option_values_arr, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3186 'select2' => true,
3187 'multiple' => true,
3188 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3189 )
3190 );
3191 } else {
3192 ?>
3193 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3194 class="
3195 <?php
3196 if ( $field->is_required ) {
3197 echo 'required_field';
3198 }
3199 ?>
3200 uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3201
3202 <?php
3203 if ( ! is_admin() ) {
3204 ?>
3205 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3206 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3207 <?php
3208 if ( $field->is_required ) {
3209 echo '<span>*</span>';
3210 }
3211 ?>
3212 </label>
3213 <?php } ?>
3214
3215 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value=""/>
3216 <?php if ( $multi_display == 'select' ) { ?>
3217 <div class="uwp_multiselect_list">
3218 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>[]"
3219 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3220 title="<?php echo esc_attr( $site_title ); ?>"
3221 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3222 class="aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
3223 >
3224 <?php
3225 } else {
3226 ?>
3227 <ul class="uwp_multi_choice">
3228 <?php
3229 }
3230
3231 $option_values_arr = uwp_string_values_to_options( $field->option_values, true );
3232 $select_options = '';
3233 if ( ! empty( $option_values_arr ) ) {
3234 foreach ( $option_values_arr as $option_row ) {
3235 if ( isset( $option_row['optgroup'] ) && ( $option_row['optgroup'] == 'start' || $option_row['optgroup'] == 'end' ) ) {
3236 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3237
3238 if ( $multi_display == 'select' ) {
3239 $select_options .= $option_row['optgroup'] == 'start' ? '<optgroup label="' . esc_attr( $option_label ) . '">' : '</optgroup>';
3240 } else {
3241 $select_options .= $option_row['optgroup'] == 'start' ? '<li>' . $option_label . '</li>' : '';
3242 }
3243 } else {
3244 $option_label = isset( $option_row['label'] ) ? $option_row['label'] : '';
3245 $option_value = isset( $option_row['value'] ) ? $option_row['value'] : '';
3246 $selected = $option_value == $value ? 'selected="selected"' : '';
3247 $checked = '';
3248
3249 if ( ( ! is_array( $value ) && trim( $value ) != '' ) || ( is_array( $value ) && ! empty( $value ) ) ) {
3250 if ( ! is_array( $value ) ) {
3251 $value_array = explode( ',', $value );
3252 } else {
3253 $value_array = $value;
3254 }
3255
3256 if ( is_array( $value_array ) ) {
3257 if ( in_array( $option_value, $value_array ) ) {
3258 $selected = 'selected="selected"';
3259 $checked = 'checked="checked"';
3260 }
3261 }
3262 }
3263
3264 if ( $multi_display == 'select' ) {
3265 $select_options .= '<option value="' . esc_attr( $option_value ) . '" ' . $selected . '>' . $option_label . '</option>';
3266 } else {
3267 $select_options .= '<li><input name="' . $field->name . '[]" ' . $checked . ' value="' . esc_attr( $option_value ) . '" class="uwp-' . $multi_display . '" type="' . $multi_display . '" />&nbsp;' . $option_label . ' </li>';
3268 }
3269 }
3270 }
3271 }
3272 echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3273
3274 if ( $multi_display == 'select' ) {
3275
3276 ?>
3277 </select></div>
3278 <?php } else { ?>
3279 </ul>
3280 <?php } ?>
3281 <?php if ( $field->is_required ) { ?>
3282 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3283 <?php } ?>
3284 </div>
3285 <?php
3286 }
3287 $html = ob_get_clean();
3288 }
3289
3290 return $html;
3291 }
3292
3293 /**
3294 * Form field template for file field type.
3295 *
3296 * @param string $html Form field html
3297 * @param object $field Field info.
3298 * @param string $value Form field default value.
3299 * @param string $form_type Form type
3300 *
3301 * @return string Modified form field html.
3302 * @package userswp
3303 *
3304 * @since 1.0.0
3305 */
3306 public function form_input_file( $html, $field, $value, $form_type ) {
3307
3308 $file_obj = new UsersWP_Files();
3309
3310 // Check if there is a field specific filter.
3311 if ( has_filter( "uwp_form_input_html_file_{$field->htmlvar_name}" ) ) {
3312 $html = apply_filters( "uwp_form_input_html_file_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3313 }
3314
3315 // If no html then we run the standard output.
3316 if ( empty( $html ) ) {
3317
3318 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3319 $wrap_class = isset( $field->css_class ) ? $field->css_class : '';
3320 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3321 $bs_sr_only = $design_style ? 'sr-only' : '';
3322 $bs_form_control = $design_style ? 'form-control' : '';
3323
3324 ob_start(); // Start buffering;
3325
3326 ?>
3327 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3328 class="
3329 <?php
3330 if ( $field->is_required ) {
3331 echo 'required_field';
3332 }
3333 ?>
3334 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group . $wrap_class ); ?>">
3335
3336 <?php
3337 $site_title = uwp_get_form_label( $field );
3338 if ( ! is_admin() && ! wp_doing_ajax() ) {
3339 ?>
3340 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3341 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3342 <?php
3343 if ( $field->is_required ) {
3344 echo ' <span class="text-danger">*</span>';
3345 }
3346 ?>
3347 </label>
3348 <?php } ?>
3349
3350 <?php echo $file_obj->file_upload_preview( $field, $value ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
3351 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3352 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3353 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3354 title="<?php echo esc_attr( $site_title ); ?>"
3355 <?php
3356 if ( $field->is_required == 1 ) {
3357 echo 'data-is-required="1"';
3358 }
3359 if ( $field->is_required == 1 && ! $value ) {
3360 echo 'required="required"';
3361 }
3362 ?>
3363 type="<?php echo esc_attr( $field->field_type ); ?>">
3364 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3365 <?php if ( $field->is_required ) { ?>
3366 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3367 <?php } ?>
3368 </div>
3369
3370 <?php
3371 $html = ob_get_clean();
3372 }
3373
3374 return $html;
3375 }
3376
3377 /**
3378 * Form field template for checkbox field type.
3379 *
3380 * @param string $html Form field html
3381 * @param object $field Field info.
3382 * @param string $value Form field default value.
3383 * @param string $form_type Form type
3384 *
3385 * @return string Modified form field html.
3386 * @package userswp
3387 *
3388 * @since 1.0.0
3389 */
3390 public function form_input_checkbox( $html, $field, $value, $form_type ) {
3391
3392 // Check if there is a field specific filter.
3393 if ( has_filter( "uwp_form_input_html_checkbox_{$field->htmlvar_name}" ) ) {
3394 $html = apply_filters( "uwp_form_input_html_checkbox_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3395 }
3396
3397 // If no html then we run the standard output.
3398 if ( empty( $html ) ) {
3399
3400 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3401 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
3402 $bs_sr_only = $design_style ? 'form-check-label' : '';
3403 $bs_form_control = $design_style ? 'form-check-input' : '';
3404
3405 ob_start(); // Start buffering;
3406 $site_title = uwp_get_form_label( $field );
3407
3408 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3409 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
3410
3411 $checked = $value == '1' ? true : false;
3412
3413 // bootstrap
3414 if ( $design_style ) {
3415 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3416
3417 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
3418
3419 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3420 array(
3421 'id' => esc_attr( $id ),
3422 'name' => esc_attr( $field->htmlvar_name ),
3423 'type' => 'checkbox',
3424 'value' => '1',
3425 'title' => esc_html( $site_title ),
3426 'label' => wp_kses_post( $site_title . $required ),
3427 'label_show' => true,
3428 'required' => ! empty( $field->is_required ) ? true : false,
3429 'checked' => (bool) $checked,
3430 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3431 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3432 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3433 )
3434 );
3435
3436 } else {
3437 ?>
3438 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3439 class="
3440 <?php
3441 if ( $field->is_required ) {
3442 echo 'required_field';
3443 }
3444 ?>
3445 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3446 <?php if ( ! empty( $design_style ) ) { ?>
3447 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3448 <?php } ?>
3449 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
3450 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3451 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3452 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3453 title="<?php echo esc_attr( $site_title ); ?>"
3454 <?php
3455 if ( $field->is_required == 1 ) {
3456 echo 'required="required"';
3457 }
3458 ?>
3459 <?php
3460 if ( $value == '1' ) {
3461 echo 'checked="checked"';
3462 }
3463 ?>
3464 type="<?php echo esc_attr( $field->field_type ); ?>"
3465 value="1">
3466 <?php
3467 echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;';
3468 ?>
3469 <?php if ( ! empty( $design_style ) ) { ?>
3470 </label>
3471 <?php } ?>
3472 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3473 <?php if ( $field->is_required ) { ?>
3474 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3475 <?php } ?>
3476 </div>
3477
3478 <?php
3479
3480 }
3481
3482 $html = ob_get_clean();
3483
3484 }
3485
3486 return $html;
3487 }
3488
3489 /**
3490 * Form field template for radio field type.
3491 *
3492 * @param string $html Form field html
3493 * @param object $field Field info.
3494 * @param string $value Form field default value.
3495 * @param string $form_type Form type
3496 *
3497 * @return string Modified form field html.
3498 * @package userswp
3499 *
3500 * @since 1.0.0
3501 */
3502 public function form_input_radio( $html, $field, $value, $form_type ) {
3503
3504 // Check if there is a field specific filter.
3505 if ( has_filter( "uwp_form_input_html_radio_{$field->htmlvar_name}" ) ) {
3506 $html = apply_filters( "uwp_form_input_html_radio_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3507 }
3508
3509 // If no html then we run the standard output.
3510 if ( empty( $html ) ) {
3511
3512 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3513 $bs_form_group = $design_style ? 'form-group mb-3 form-check-inline' : '';
3514 $bs_sr_only = $design_style ? 'sr-only' : '';
3515 $bs_label_class = $design_style ? 'form-check-label' : '';
3516 $bs_form_control = $design_style ? 'form-check-input' : '';
3517
3518 ob_start(); // Start buffering;
3519
3520 if ( $design_style ) {
3521
3522 $option_values_deep = uwp_string_values_to_options( $field->option_values, true );
3523 $option_values = array();
3524 if ( ! empty( $option_values_deep ) ) {
3525 foreach ( $option_values_deep as $option ) {
3526 $option_values[ $option['value'] ] = $option['label'];
3527 }
3528 }
3529
3530 $site_title = uwp_get_form_label( $field );
3531
3532 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3533
3534 echo aui()->radio( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3535 array(
3536 'id' => esc_attr( $field->htmlvar_name ),
3537 'name' => esc_attr( $field->htmlvar_name ),
3538 'type' => 'radio',
3539 'title' => esc_html( $site_title ),
3540 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3541 'label_type' => 'top',
3542 'class' => '',
3543 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3544 'value' => esc_attr( $value ),
3545 'options' => $option_values, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3546 )
3547 );
3548
3549 } else {
3550
3551 ?>
3552 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3553 class="
3554 <?php
3555 if ( $field->is_required ) {
3556 echo 'required_field';
3557 }
3558 ?>
3559 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3560
3561 <?php
3562 $site_title = uwp_get_form_label( $field );
3563 if ( ! is_admin() ) {
3564 ?>
3565 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3566 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3567 <?php
3568 if ( $field->is_required ) {
3569 echo '<span>*</span>';
3570 }
3571 ?>
3572 </label>
3573 <?php } ?>
3574
3575 <?php
3576 if ( $field->option_values ) {
3577 $option_values = uwp_string_values_to_options( $field->option_values, true );
3578
3579 if ( ! empty( $option_values ) ) {
3580 $count = 0;
3581 foreach ( $option_values as $option_value ) {
3582 if ( empty( $option_value['optgroup'] ) ) {
3583 ++$count;
3584 if ( $count == 1 ) {
3585 $class = 'uwp-radio-first';
3586 } else {
3587 $class = '';
3588 }
3589 ?>
3590 <?php if ( ! empty( $design_style ) ) { ?>
3591 <label class="<?php echo esc_attr( $bs_label_class ); ?>">
3592 <?php } else { ?>
3593 <span class="uwp-radios <?php echo esc_attr( $class ); ?>">
3594 <?php } ?>
3595 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3596 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3597 title="<?php echo esc_attr( $option_value['label'] ); ?>"
3598 <?php checked( $value, $option_value['value'] ); ?>
3599 <?php
3600 if ( $field->is_required == 1 ) {
3601 echo 'required="required"';
3602 }
3603 ?>
3604 value="<?php echo esc_attr( $option_value['value'] ); ?>"
3605 class="uwp-radio <?php echo esc_attr( $bs_form_control ); ?>" type="radio"/>
3606 <?php echo esc_html( $option_value['label'] ); ?>
3607 <?php if ( ! empty( $design_style ) ) { ?>
3608 </label>
3609 <?php } else { ?>
3610 </span>
3611 <?php
3612 }
3613 }
3614 }
3615 }
3616 }
3617 ?>
3618 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3619 <?php if ( $field->is_required ) { ?>
3620 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3621 <?php } ?>
3622 </div>
3623 <?php
3624 }
3625
3626 $html = ob_get_clean();
3627 }
3628
3629 return $html;
3630 }
3631
3632 /**
3633 * Form field template for text field type.
3634 *
3635 * @param string $html Form field html
3636 * @param object $field Field info.
3637 * @param string $value Form field default value.
3638 * @param string $form_type Form type
3639 *
3640 * @return string Modified form field html.
3641 * @package userswp
3642 *
3643 * @since 1.0.0
3644 */
3645 public function form_input_text( $html, $field, $value, $form_type ) {
3646
3647 // Check if there is a custom field specific filter.
3648 if ( has_filter( "uwp_form_input_text_{$field->htmlvar_name}" ) ) {
3649 $html = apply_filters( "uwp_form_input_text_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3650 }
3651
3652 // If no html then we run the standard output.
3653 if ( empty( $html ) ) {
3654
3655 ob_start(); // Start buffering;
3656
3657 $type = 'text';
3658 $step = false;
3659 //number and float validation $validation_pattern
3660 if ( isset( $field->data_type ) && $field->data_type == 'INT' ) {
3661 $type = 'number';
3662 } elseif ( isset( $field->data_type ) && $field->data_type == 'FLOAT' ) {
3663 $dp = $field->decimal_point;
3664 switch ( $dp ) {
3665 case '1':
3666 $step = '0.1';
3667 break;
3668 case '2':
3669 $step = '0.01';
3670 break;
3671 case '3':
3672 $step = '0.001';
3673 break;
3674 case '4':
3675 $step = '0.0001';
3676 break;
3677 case '5':
3678 $step = '0.00001';
3679 break;
3680 case '6':
3681 $step = '0.000001';
3682 break;
3683 case '7':
3684 $step = '0.0000001';
3685 break;
3686 case '8':
3687 $step = '0.00000001';
3688 break;
3689 case '9':
3690 $step = '0.000000001';
3691 break;
3692 case '10':
3693 $step = '0.0000000001';
3694 break;
3695 default:
3696 $step = '0.01';
3697 break;
3698 }
3699 $type = 'number';
3700 }
3701
3702 $site_title = uwp_get_form_label( $field );
3703 $placeholder = uwp_get_field_placeholder( $field );
3704 $manual_label = apply_filters( 'uwp_login_username_label_manual', true );
3705 if ( $manual_label
3706 && isset( $field->form_type )
3707 && $field->form_type == 'login'
3708 && $field->htmlvar_name == 'username' ) {
3709 $site_title = __( 'Username or Email', 'userswp' );
3710 $required = ! empty( $field->is_required ) ? ' *' : '';
3711 $placeholder = $site_title . $required;
3712 $placeholder = apply_filters( 'uwp_get_field_placeholder', stripslashes( $placeholder ), $field );
3713 }
3714
3715 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3716 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3717 $bs_sr_only = $design_style ? 'sr-only' : '';
3718 $bs_form_control = $design_style ? 'form-control' : '';
3719
3720 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3721 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3722
3723 // bootstrap
3724 if ( $design_style ) {
3725 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3726
3727 echo aui()->input(
3728 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3729 'type' => esc_attr( $type ),
3730 'id' => esc_attr( $field->htmlvar_name ),
3731 'name' => esc_attr( $field->htmlvar_name ),
3732 'placeholder' => esc_attr( $placeholder ),
3733 'title' => esc_html( $site_title ),
3734 'value' => esc_attr( wp_unslash( $value ) ),
3735 'required' => (bool) $field->is_required,
3736 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3737 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3738 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3739 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3740 'step' => esc_attr( $step ),
3741 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3742 )
3743 );
3744 } else {
3745 ?>
3746 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
3747 <?php
3748 if ( $field->is_required ) {
3749 echo 'required_field';
3750 }
3751 ?>
3752 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3753 <?php
3754
3755 if ( ! is_admin() ) {
3756 ?>
3757 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3758 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3759 <?php
3760 if ( $field->is_required ) {
3761 echo '<span>*</span>';
3762 }
3763 ?>
3764 </label>
3765 <?php
3766 }
3767 ?>
3768
3769 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3770 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
3771 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3772 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3773 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
3774 title="<?php echo esc_attr( $site_title ); ?>"
3775 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3776 oninput="setCustomValidity('')"
3777 <?php
3778 if ( $field->is_required == 1 ) {
3779 echo 'required="required"';
3780 }
3781 ?>
3782 <?php
3783 if ( $field->for_admin_use == 1 ) {
3784 echo 'readonly="readonly"';
3785 }
3786 ?>
3787 type="<?php echo esc_attr( $type ); ?>"
3788 <?php
3789 if ( $step ) {
3790 echo 'step="' . esc_attr( $step ) . '"';
3791 }
3792 ?>
3793 />
3794 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3795 <?php if ( $field->is_required ) { ?>
3796 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3797 <?php } ?>
3798 </div>
3799
3800
3801 <?php
3802 }
3803 $html = ob_get_clean();
3804 }
3805
3806 return $html;
3807 }
3808
3809 /**
3810 * Form field template for textarea field type.
3811 *
3812 * @param string $html Form field html
3813 * @param object $field Field info.
3814 * @param string $value Form field default value.
3815 * @param string $form_type Form type
3816 *
3817 * @return string Modified form field html.
3818 * @package userswp
3819 *
3820 * @since 1.0.0
3821 */
3822 public function form_input_textarea( $html, $field, $value, $form_type ) {
3823
3824 // Check if there is a field specific filter.
3825 if ( has_filter( "uwp_form_input_textarea_{$field->htmlvar_name}" ) ) {
3826 $html = apply_filters( "uwp_form_input_textarea_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3827 }
3828
3829 // If no html then we run the standard output.
3830 if ( empty( $html ) ) {
3831
3832 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3833 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3834 $bs_sr_only = $design_style ? 'sr-only' : '';
3835 $bs_form_control = $design_style ? 'form-control' : '';
3836 $site_title = uwp_get_form_label( $field );
3837
3838 ob_start(); // Start buffering;
3839
3840 // bootstrap
3841 if ( $design_style ) {
3842 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3843
3844 echo aui()->textarea(
3845 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3846 'id' => esc_attr( $field->htmlvar_name ),
3847 'name' => esc_attr( $field->htmlvar_name ),
3848 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3849 'title' => esc_html( $site_title ),
3850 'value' => wp_kses_post( stripslashes( $value ) ),
3851 'required' => (bool) $field->is_required,
3852 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
3853 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3854 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3855 'rows' => '4',
3856 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3857 )
3858 );
3859 } else {
3860 ?>
3861
3862 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3863 class="
3864 <?php
3865 if ( $field->is_required ) {
3866 echo 'required_field';
3867 }
3868 ?>
3869 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3870
3871 <?php
3872
3873 if ( ! is_admin() ) {
3874 ?>
3875 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3876 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3877 <?php
3878 if ( $field->is_required ) {
3879 echo '<span>*</span>';
3880 }
3881 ?>
3882 </label>
3883 <?php } ?>
3884
3885 <textarea name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
3886 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
3887 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
3888 title="<?php echo esc_attr( $site_title ); ?>"
3889 oninvalid="this.setCustomValidity('<?php esc_attr_e( stripslashes( $field->required_msg ), 'userswp' ); ?>')"
3890 oninput="setCustomValidity('')"
3891 <?php
3892 if ( $field->is_required == 1 ) {
3893 echo 'required="required"';
3894 }
3895 ?>
3896 type="<?php echo esc_attr( $field->field_type ); ?>"
3897 rows="4"><?php echo wp_kses_post( stripslashes( $value ) ); ?></textarea>
3898 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3899 <?php if ( $field->is_required ) { ?>
3900 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3901 <?php } ?>
3902 </div>
3903
3904 <?php
3905 }
3906 $html = ob_get_clean();
3907 }
3908
3909 return $html;
3910 }
3911
3912 public function form_input_editor( $html, $field, $value, $form_type ) {
3913
3914 // Check if there is a field specific filter.
3915 if ( has_filter( "uwp_form_input_editor_{$field->htmlvar_name}" ) ) {
3916 $html = apply_filters( "uwp_form_input_editor_{$field->htmlvar_name}", $html, $field, $value, $form_type );
3917 }
3918
3919 if ( empty( $html ) ) {
3920
3921 ob_start();
3922
3923 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
3924 $bs_form_group = $design_style ? 'form-group mb-3' : '';
3925 $bs_sr_only = $design_style ? 'sr-only' : '';
3926 $site_title = uwp_get_form_label( $field );
3927
3928 $content = stripslashes( $value );
3929 $editor_id = $field->htmlvar_name;
3930 $args = array(
3931 'textarea_rows' => 5,
3932 'media_buttons' => false,
3933 'quicktags' => false,
3934 );
3935
3936 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
3937 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
3938
3939 // bootstrap
3940 if ( $design_style ) {
3941 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
3942
3943 echo aui()->textarea(
3944 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
3945 'id' => esc_attr( $field->htmlvar_name ),
3946 'name' => esc_attr( $field->htmlvar_name ),
3947 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
3948 'title' => esc_html( $site_title ),
3949 'value' => wp_kses_post( stripslashes( $value ) ),
3950 'required' => (bool) $field->is_required,
3951 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
3952 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
3953 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
3954 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
3955 'rows' => 5,
3956 'wysiwyg' => true,
3957 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
3958 )
3959 );
3960 } else {
3961 ?>
3962 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
3963 class="
3964 <?php
3965 if ( $field->is_required ) {
3966 echo 'required_field';
3967 }
3968 ?>
3969 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
3970
3971 <?php
3972
3973 if ( ! is_admin() ) {
3974 ?>
3975 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
3976 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
3977 <?php
3978 if ( $field->is_required ) {
3979 echo '<span>*</span>';
3980 }
3981 ?>
3982 </label>
3983 <?php } ?>
3984
3985 <?php wp_editor( $content, $editor_id, $args ); ?>
3986
3987 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
3988 <?php if ( $field->is_required ) { ?>
3989 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
3990 <?php } ?>
3991 </div>
3992 <?php
3993 }
3994 $html = ob_get_clean();
3995 }
3996
3997 return $html;
3998 }
3999
4000 /**
4001 * Form field template for fieldset field type.
4002 *
4003 * @param string $html Form field html
4004 * @param object $field Field info.
4005 * @param string $value Form field default value.
4006 * @param string $form_type Form type
4007 *
4008 * @return string Modified form field html.
4009 * @package userswp
4010 *
4011 * @since 1.0.0
4012 */
4013 public function form_input_fieldset( $html, $field, $value, $form_type ) {
4014 // Check if there is a custom field specific filter.
4015 if ( has_filter( "uwp_form_input_fieldset_{$field->htmlvar_name}" ) ) {
4016 $html = apply_filters( "uwp_form_input_fieldset_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4017 }
4018
4019 // If no html then we run the standard output.
4020 if ( empty( $html ) ) {
4021
4022 ob_start(); // Start buffering;
4023 $site_title = uwp_get_form_label( $field );
4024 ?>
4025 <h3 class="uwp_input_fieldset <?php echo esc_attr( $field->css_class ); ?>">
4026 <?php echo esc_html( $site_title ); ?>
4027 <?php
4028 if ( $field->help_text != '' ) {
4029 echo '<small>( ' . wp_kses_post( $field->help_text ) . ' )</small>';
4030 }
4031 ?>
4032 </h3>
4033 <?php
4034 $html = ob_get_clean();
4035 }
4036
4037 return $html;
4038 }
4039
4040 /**
4041 * Form field template for url field type.
4042 *
4043 * @param string $html Form field html
4044 * @param object $field Field info.
4045 * @param string $value Form field default value.
4046 * @param string $form_type Form type
4047 *
4048 * @return string Modified form field html.
4049 * @package userswp
4050 *
4051 * @since 1.0.0
4052 */
4053 public function form_input_url( $html, $field, $value, $form_type ) {
4054
4055 // Check if there is a custom field specific filter.
4056 if ( has_filter( "uwp_form_input_url_{$field->htmlvar_name}" ) ) {
4057 $html = apply_filters( "uwp_form_input_url_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4058 }
4059
4060 // If no html then we run the standard output.
4061 if ( empty( $html ) ) {
4062
4063 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4064 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4065 $bs_sr_only = $design_style ? 'sr-only' : '';
4066 $bs_form_control = $design_style ? 'form-control' : '';
4067
4068 ob_start(); // Start buffering;
4069 $site_title = uwp_get_form_label( $field );
4070 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : __( 'Please enter a valid URL including https://', 'userswp' );
4071 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4072
4073 // bootstrap
4074 if ( $design_style ) {
4075 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4076
4077 echo aui()->input(
4078 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4079 'type' => 'url',
4080 'id' => esc_attr( $field->htmlvar_name ),
4081 'name' => esc_attr( $field->htmlvar_name ),
4082 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4083 'title' => esc_html( $site_title ),
4084 'value' => esc_attr( $value ),
4085 'required' => (bool) $field->is_required,
4086 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4087 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4088 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4089 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4090 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4091 )
4092 );
4093 } else {
4094 ?>
4095 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4096 class="
4097 <?php
4098 if ( $field->is_required ) {
4099 echo 'required_field';
4100 }
4101 ?>
4102 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4103
4104 <?php
4105 if ( ! is_admin() ) {
4106 ?>
4107 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4108 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4109 <?php
4110 if ( $field->is_required ) {
4111 echo '<span>*</span>';
4112 }
4113 ?>
4114 </label>
4115 <?php } ?>
4116
4117 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4118 class="
4119 <?php
4120 //echo $field->css_class;
4121 ?>
4122 uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4123 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4124 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4125 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4126 title="<?php echo esc_attr( $site_title ); ?>"
4127 <?php
4128 if ( $field->is_required == 1 ) {
4129 echo 'required="required"';
4130 }
4131 ?>
4132 type="url"
4133 oninvalid="setCustomValidity('<?php esc_attr_e( 'Please enter a valid URL including http://', 'userswp' ); ?>')"
4134 onchange="try{setCustomValidity('')}catch(e){}"
4135 />
4136 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4137 <?php if ( $field->is_required ) { ?>
4138 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4139 <?php } ?>
4140 </div>
4141
4142 <?php
4143 }
4144
4145 $html = ob_get_clean();
4146 }
4147
4148 return $html;
4149 }
4150
4151 /**
4152 * Form field template for email field type.
4153 *
4154 * @param string $html Form field html
4155 * @param object $field Field info.
4156 * @param string $value Form field default value.
4157 * @param string $form_type Form type
4158 *
4159 * @return string Modified form field html.
4160 * @package userswp
4161 *
4162 * @since 1.0.0
4163 */
4164 public function form_input_email( $html, $field, $value, $form_type ) {
4165
4166 // Check if there is a custom field specific filter.
4167 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}" ) ) {
4168 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4169 }
4170
4171 // If no html then we run the standard output.
4172 if ( empty( $html ) ) {
4173
4174 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4175 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4176 $bs_sr_only = $design_style ? 'sr-only' : '';
4177 $bs_form_control = $design_style ? 'form-control' : '';
4178
4179 ob_start(); // Start buffering;
4180 $site_title = uwp_get_form_label( $field );
4181 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4182 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4183
4184 $is_forgot_email = ( $form_type === 'forgot' && $field->htmlvar_name === 'email' );
4185 $input_type = $is_forgot_email ? 'text' : 'email';
4186 if ( $is_forgot_email ) {
4187 $site_title = __( 'Username or Email', 'userswp' );
4188 $placeholder = $site_title . ( ! empty( $field->is_required ) ? ' *' : '' );
4189 } else {
4190 $placeholder = uwp_get_field_placeholder( $field );
4191 }
4192
4193 if ( $design_style ) {
4194 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4195
4196 echo aui()->input(
4197 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4198 'type' => $input_type,
4199 'id' => esc_attr( $field->htmlvar_name ),
4200 'name' => esc_attr( $field->htmlvar_name ),
4201 'placeholder' => esc_attr( $placeholder ),
4202 'title' => esc_html( $site_title ),
4203 'value' => esc_attr( wp_unslash( $value ) ),
4204 'required' => (bool) $field->is_required,
4205 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4206 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4207 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4208 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4209 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4210 )
4211 );
4212 } else {
4213 ?>
4214 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4215 class="
4216 <?php
4217 if ( $field->is_required ) {
4218 echo 'required_field';
4219 }
4220 ?>
4221 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4222
4223 <?php
4224 if ( ! is_admin() ) {
4225 ?>
4226 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4227 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4228 <?php
4229 if ( $field->is_required ) {
4230 echo '<span>*</span>';
4231 }
4232 ?>
4233 </label>
4234 <?php } ?>
4235
4236 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4237 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4238 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4239 placeholder="<?php echo esc_attr( $placeholder ); ?>"
4240 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4241 title="<?php echo esc_attr( $site_title ); ?>"
4242 <?php
4243 if ( $field->is_required == 1 ) {
4244 echo 'required="required"';
4245 }
4246 ?>
4247 type="<?php echo esc_attr( $input_type ); ?>"
4248 />
4249 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4250 <?php if ( $field->is_required ) { ?>
4251 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4252 <?php } ?>
4253 </div>
4254
4255
4256 <?php
4257 }
4258 $html = ob_get_clean();
4259
4260 }
4261
4262 if ( has_filter( "uwp_form_input_email_{$field->htmlvar_name}_after" ) ) {
4263 $html = apply_filters( "uwp_form_input_email_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
4264 }
4265
4266 return $html;
4267 }
4268
4269 /**
4270 * Form field template for password field type.
4271 *
4272 * @param string $html Form field html
4273 * @param object $field Field info.
4274 * @param string $value Form field default value.
4275 * @param string $form_type Form type
4276 *
4277 * @return string Modified form field html.
4278 * @package userswp
4279 *
4280 * @since 1.0.0
4281 */
4282 public function form_input_password( $html, $field, $value, $form_type ) {
4283
4284 // Check if there is a custom field specific filter.
4285 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}" ) ) {
4286 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}", $html, $field, $value, $form_type );
4287 }
4288
4289 // If no html then we run the standard output.
4290 if ( empty( $html ) ) {
4291
4292 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4293 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4294 $bs_sr_only = $design_style ? 'sr-only' : '';
4295 $bs_form_control = $design_style ? 'form-control' : '';
4296
4297 ob_start(); // Start buffering;
4298 $site_title = uwp_get_form_label( $field );
4299
4300 if ( $design_style ) {
4301 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4302 $required_msg = ( ! empty( $field->required_msg ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4303 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4304 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4305
4306 echo aui()->input(
4307 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4308 'type' => 'password',
4309 'id' => esc_attr( $field->htmlvar_name ),
4310 'name' => esc_attr( $field->htmlvar_name ),
4311 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4312 'title' => esc_html( $site_title ),
4313 'value' => esc_attr( $value ),
4314 'required' => (bool) $field->is_required,
4315 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4316 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4317 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4318 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4319 'wrap_class' => esc_attr( $wrap_class ),
4320 )
4321 );
4322 } else {
4323 ?>
4324 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="
4325 <?php
4326 if ( $field->is_required ) {
4327 echo 'required_field';
4328 }
4329 ?>
4330 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4331 <?php
4332 if ( ! is_admin() ) {
4333 ?>
4334 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4335 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4336 <?php
4337 if ( $field->is_required ) {
4338 echo '<span>*</span>';
4339 }
4340 ?>
4341 </label>
4342 <?php } ?>
4343
4344 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4345 class="<?php echo esc_attr( $field->css_class ); ?> uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
4346 id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4347 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4348 value="<?php echo esc_attr( stripslashes( $value ) ); ?>"
4349 title="<?php echo esc_attr( $site_title ); ?>"
4350 <?php
4351 if ( $field->is_required == 1 ) {
4352 echo 'required="required"';
4353 }
4354 ?>
4355 type="password"
4356 />
4357 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4358 <?php if ( $field->is_required ) { ?>
4359 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4360 <?php } ?>
4361 </div>
4362
4363
4364 <?php
4365 }
4366
4367 $html = ob_get_clean();
4368 }
4369
4370 if ( has_filter( "uwp_form_input_password_{$field->htmlvar_name}_after" ) ) {
4371 $html = apply_filters( "uwp_form_input_password_{$field->htmlvar_name}_after", $html, $field, $value, $form_type );
4372 }
4373
4374 return $html;
4375 }
4376
4377 /**
4378 * Form field template for Phone field.
4379 *
4380 * @param string $html Form field html
4381 * @param object $field Field info.
4382 * @param string $value Form field default value.
4383 * @param string $form_type Form type
4384 *
4385 * @return string $html Modified form field html.
4386 * @since 1.0.0
4387 *
4388 */
4389 public function form_input_phone( $html, $field, $value, $form_type ) {
4390 if ( empty( $html ) ) {
4391 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4392 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4393 $bs_sr_only = $design_style ? 'sr-only' : '';
4394 $bs_form_control = $design_style ? 'form-control' : '';
4395 ob_start(); // Start buffering;
4396 $site_title = uwp_get_form_label( $field );
4397 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4398 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4399
4400 if ( $design_style ) {
4401 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4402
4403 echo aui()->input(
4404 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4405 'type' => 'tel',
4406 'id' => esc_attr( $field->htmlvar_name ),
4407 'name' => esc_attr( $field->htmlvar_name ),
4408 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4409 'title' => esc_html( $site_title ),
4410 'value' => esc_attr( $value ),
4411 'required' => (bool) $field->is_required,
4412 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4413 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4414 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4415 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4416 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4417 )
4418 );
4419 } else {
4420 ?>
4421 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4422 class="
4423 <?php
4424 if ( $field->is_required ) {
4425 echo 'required_field';
4426 }
4427 ?>
4428 clearfix uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4429 <?php
4430 if ( ! is_admin() ) {
4431 ?>
4432 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4433 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4434 <?php
4435 if ( $field->is_required ) {
4436 echo '<span>*</span>';
4437 }
4438 ?>
4439 </label>
4440 <?php } ?>
4441 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4442 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4443 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4444 title="<?php echo esc_attr( $site_title ); ?>"
4445 <?php
4446 if ( $field->for_admin_use == 1 ) {
4447 echo 'readonly="readonly"';
4448 }
4449 ?>
4450 <?php
4451 if ( $field->is_required == 1 ) {
4452 echo 'required="required"';
4453 }
4454 ?>
4455 type="tel"
4456 value="<?php echo esc_html( $value ); ?>">
4457 </div>
4458 <?php
4459 }
4460 $html = ob_get_clean();
4461 }
4462
4463 return $html;
4464 }
4465
4466 public function form_input_register_gdpr( $html, $field, $value, $form_type ) {
4467
4468 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4469 $reg_gdpr = uwp_get_register_form_by( $form_id, 'gdpr_page' );
4470 if ( empty( $reg_gdpr ) ) {
4471 $reg_gdpr = uwp_get_option( 'register_gdpr_page', false );
4472 }
4473
4474 if ( ! empty( $reg_gdpr ) ) {
4475
4476 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4477 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4478 $bs_form_control = $design_style ? 'form-check-input' : '';
4479 $site_title = uwp_get_form_label( $field );
4480 $field->htmlvar_name = 'register_gdpr';
4481 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4482
4483 $gdpr_page = get_permalink( $reg_gdpr );
4484 $link_start = '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">';
4485 $link_end = '</a>';
4486 $field_desc = uwp_get_field_description( $field, '' );
4487 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4488 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4489 $content = $field_desc ? $field_desc : sprintf( __( 'By using this form I agree to the storage and handling of my data by this website. View our %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $gdpr_page ) . '" target="_blank">', $site_title, '</a>' );
4490 $checked = $value == '1' ? true : false;
4491
4492 ob_start(); // Start buffering;
4493
4494 // bootstrap
4495 if ( $design_style ) {
4496 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4497 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4498
4499 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4500 array(
4501 'id' => esc_attr( $id ),
4502 'name' => esc_attr( $field->htmlvar_name ),
4503 'type' => 'checkbox',
4504 'value' => '1',
4505 'title' => esc_html( $site_title ),
4506 'label' => wp_kses_post( $content . $required ),
4507 'label_show' => true,
4508 'required' => ! empty( $field->is_required ) ? true : false,
4509 'checked' => (bool) $checked,
4510 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4511 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4512 )
4513 );
4514
4515 } else {
4516 ?>
4517 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4518 class="
4519 <?php
4520 if ( $field->is_required ) {
4521 echo 'required_field';
4522 }
4523 ?>
4524 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4525 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4526 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4527 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4528 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4529 title="<?php echo esc_attr( $site_title ); ?>"
4530 <?php
4531 if ( $value == '1' ) {
4532 echo 'checked="checked"';
4533 }
4534 ?>
4535 type="<?php echo esc_attr( $field->field_type ); ?>"
4536 value="1">
4537 <?php
4538 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4539 ?>
4540 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4541 <?php if ( $field->is_required ) { ?>
4542 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4543 <?php } ?>
4544 </div>
4545
4546 <?php
4547 }
4548
4549 $html = ob_get_clean();
4550
4551 } else {
4552 $html = '<input type="hidden" name="register_gdpr" value="-1"/>';
4553 }
4554
4555 return $html;
4556 }
4557
4558 public function form_input_register_tos( $html, $field, $value, $form_type ) {
4559
4560 $form_id = isset( $field->form_id ) ? (int) $field->form_id : 1;
4561 $reg_tos = uwp_get_register_form_by( $form_id, 'tos_page' );
4562 if ( empty( $reg_tos ) ) {
4563 $reg_tos = uwp_get_option( 'register_terms_page', false );
4564 }
4565
4566 if ( ! empty( $reg_tos ) ) {
4567
4568 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4569 $bs_form_group = $design_style ? 'form-group mb-3 form-check' : '';
4570 $bs_form_control = $design_style ? 'form-check-input' : '';
4571
4572 $site_title = uwp_get_form_label( $field );
4573 $terms_page = get_permalink( $reg_tos );
4574 $link_start = '<a href="' . esc_url( $terms_page ) . '" target="_blank">';
4575 $link_end = '</a>';
4576 $field_desc = uwp_get_field_description( $field, '' );
4577 $field_desc = str_replace( '%%link_start%%', $link_start, $field_desc );
4578 $field_desc = str_replace( '%%link_end%%', $link_end, $field_desc );
4579 $field->htmlvar_name = 'register_tos';
4580 $id = wp_doing_ajax() ? $field->htmlvar_name . '_ajax' : $field->htmlvar_name;
4581
4582 $content = $field_desc ? $field_desc : sprintf( __( 'I accept the %1$s %2$s %3$s.', 'userswp' ), '<a href="' . esc_url( $terms_page ) . '" target="_blank">', $site_title, '</a>' );
4583 $checked = $value == '1' ? true : false;
4584
4585 ob_start();
4586
4587 if ( $design_style ) {
4588 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4589 echo '<input type="hidden" name="' . esc_attr( $field->htmlvar_name ) . '" id="checkbox_' . esc_attr( $id ) . '" value="0"/>';
4590
4591 echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4592 array(
4593 'id' => esc_attr( $id ),
4594 'name' => esc_attr( $field->htmlvar_name ),
4595 'type' => 'checkbox',
4596 'value' => '1',
4597 'title' => esc_html( $site_title ),
4598 'label' => wp_kses_post( $content . $required ),
4599 'label_show' => true,
4600 'required' => ! empty( $field->is_required ) ? true : false,
4601 'checked' => (bool) $checked,
4602 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4603 'validation_text' => ! empty( $field->is_required ) ? esc_attr__( stripslashes( $field->required_msg ), 'userswp' ) : '',
4604 )
4605 );
4606
4607 } else {
4608 ?>
4609 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4610 class="
4611 <?php
4612 if ( $field->is_required ) {
4613 echo 'required_field';
4614 }
4615 ?>
4616 uwp_form_<?php echo esc_attr( $field->field_type ); ?>_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4617 <input type="hidden" name="<?php echo esc_attr( $field->htmlvar_name ); ?>" value="0"/>
4618 <input name="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4619 class="<?php echo esc_attr( $field->css_class ); ?> <?php echo esc_attr( $bs_form_control ); ?>"
4620 placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4621 title="<?php echo esc_attr( $site_title ); ?>"
4622 <?php
4623 if ( $value == '1' ) {
4624 echo 'checked="checked"';
4625 }
4626 ?>
4627 type="<?php echo esc_attr( $field->field_type ); ?>"
4628 value="1">
4629 <?php
4630 echo ( trim( $content ) ) ? wp_kses_post( $content ) : '&nbsp;';
4631 ?>
4632 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4633 <?php if ( $field->is_required ) { ?>
4634 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4635 <?php } ?>
4636 </div>
4637
4638 <?php
4639
4640 }
4641
4642 $html = ob_get_clean();
4643
4644 } else {
4645 $html = '<input type="hidden" name="register_tos" value="-1"/>';
4646 }
4647
4648 return $html;
4649 }
4650
4651 /**
4652 * Adds enctype tag in form for file fields.
4653 *
4654 * @return void
4655 * @package userswp
4656 *
4657 * @since 1.0.0
4658 */
4659 function add_multipart_to_admin_edit_form() {
4660 global $wpdb;
4661 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4662 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4663 if ( $fields ) {
4664 echo 'enctype="multipart/form-data"';
4665 }
4666 }
4667
4668 /**
4669 * Handles UsersWP custom field requests from admin.
4670 *
4671 * @param int $user_id User ID.
4672 *
4673 * @return void
4674 * @since 1.0.0
4675 * @package userswp
4676 *
4677 */
4678 public function update_profile_extra_admin_edit( $user_id ) {
4679 global $wpdb;
4680 $file_obj = new UsersWP_Files();
4681 $table_name = uwp_get_table_prefix() . 'uwp_form_fields';
4682 //Normal fields
4683 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type != 'file' AND field_type != 'fieldset' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4684 if ( $fields ) {
4685 if ( isset( $_POST['locale'] ) ) {
4686 $_POST['uwp_language'] = sanitize_text_field( $_POST['locale'] );
4687 }
4688 $result = uwp_validate_fields( $_POST, 'account', $fields );
4689 if ( is_wp_error( $result ) ) {
4690 die( wp_kses_post( $result->get_error_message() ) );
4691 }
4692 if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) {
4693 $display_name = $result['display_name'];
4694 } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) {
4695 $display_name = $result['first_name'] . ' ' . $result['last_name'];
4696 } else {
4697 $user_info = get_userdata( $user_id );
4698 $display_name = $user_info->user_login;
4699 }
4700 $result['display_name'] = $display_name;
4701 if ( ! is_wp_error( $result ) ) {
4702 foreach ( $fields as $field ) {
4703 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4704 if ( $value == '0' || ! empty( $value ) ) {
4705 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4706 }
4707 }
4708 }
4709 }
4710
4711 //File fields
4712 $fields = $wpdb->get_results( 'SELECT * FROM ' . $table_name . " WHERE form_type = 'account' AND field_type = 'file' AND is_default = '0' ORDER BY sort_order ASC" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
4713 if ( $fields ) {
4714 $result = $file_obj->validate_uploads( $_FILES, 'account', true, $fields );
4715 if ( ! is_wp_error( $result ) ) {
4716 foreach ( $fields as $field ) {
4717 $value = isset( $result[ $field->htmlvar_name ] ) ? $result[ $field->htmlvar_name ] : '';
4718 if ( $value == '0' || ! empty( $value ) ) {
4719 uwp_update_usermeta( $user_id, $field->htmlvar_name, $value );
4720 }
4721 }
4722 }
4723 }
4724 }
4725
4726 /**
4727 * Form field template for country field.
4728 *
4729 * @param string $html Form field html
4730 * @param object $field Field info.
4731 * @param string $value Form field default value.
4732 * @param string $form_type Form type
4733 *
4734 * @return string Modified form field html.
4735 * @package userswp
4736 *
4737 * @since 1.0.0
4738 */
4739 public function form_input_select_country( $html, $field, $value, $form_type ) {
4740
4741 // If no html then we run the standard output.
4742 if ( empty( $html ) ) {
4743
4744 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4745 $bs_form_group = $design_style ? 'form-group m-0' : ''; // country wrapper div added by JS adds margin so we remove ours
4746 $bs_sr_only = $design_style ? 'sr-only' : '';
4747 $bs_form_control = $design_style ? 'form-control' : '';
4748
4749 ob_start(); // Start buffering;
4750 ?>
4751 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row" class="<?php echo ( $field->is_required ? 'required_field' : '' ); ?> uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4752
4753 <?php
4754 $site_title = uwp_get_form_label( $field );
4755
4756 if ( ! is_admin() && ! wp_doing_ajax() ) {
4757 ?>
4758 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4759 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4760 <?php
4761 if ( $field->is_required ) {
4762 echo '<span class="text-danger">*</span>';
4763 }
4764 ?>
4765 </label>
4766 <?php
4767 }
4768 // if value empty set the default
4769 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4770 $value = $field->default_value;
4771 }
4772 if ( $value === false ) {
4773 $value = '';
4774 }
4775 $select_country_options = wp_json_encode( array( 'defaultCountry' => wp_unslash( $value ) ) );
4776 $select_country_options = apply_filters( 'uwp_form_input_select_country', $select_country_options, $field, $value, $form_type );
4777
4778 $htmlvar_name = $field->htmlvar_name;
4779 if ( wp_doing_ajax() ) {
4780 $htmlvar_name .= '_ajax';
4781 }
4782 ?>
4783 <input type="text" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" title="<?php echo esc_attr( $site_title ); ?>" id="<?php echo esc_attr( $htmlvar_name ); ?>"/>
4784 <input type="hidden" id="<?php echo esc_attr( $htmlvar_name ); ?>_code" name="<?php echo esc_attr( $field->htmlvar_name ); ?>"/>
4785 <script>jQuery(function(){jQuery("#<?php echo esc_js( $htmlvar_name ); ?>").countrySelect(<?php echo wp_json_encode( json_decode( $select_country_options ) ); ?>);});</script>
4786 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4787 <?php if ( $field->is_required ) { ?>
4788 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4789 <?php } ?>
4790 </div>
4791 <?php
4792 $html = ob_get_clean();
4793 }
4794
4795 return $html;
4796 }
4797
4798 /**
4799 * Form field template for language field.
4800 *
4801 * @param string $html Form field html
4802 * @param object $field Field info.
4803 * @param string $value Form field default value.
4804 * @param string $form_type Form type
4805 *
4806 * @return string Modified form field html.
4807 * @package userswp
4808 *
4809 * @since 1.0.0
4810 */
4811 public function form_input_uwp_language( $html, $field, $value, $form_type ) {
4812
4813 // If no html then we run the standard output.
4814 if ( empty( $html ) ) {
4815
4816 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4817 $bs_form_group = $design_style ? 'form-group m-0' : '';
4818 $bs_sr_only = $design_style ? 'sr-only' : '';
4819 $bs_form_control = $design_style ? 'form-control' : '';
4820 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4821 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4822
4823 ob_start(); // Start buffering;
4824
4825 ?>
4826 <div id="<?php echo esc_attr( $field->htmlvar_name ); ?>_row"
4827 class="
4828 <?php
4829 if ( $field->is_required ) {
4830 echo 'required_field';
4831 }
4832 ?>
4833 uwp_clear <?php echo esc_attr( $bs_form_group . ' ' . $field->css_class ); ?>">
4834
4835 <?php
4836 $site_title = uwp_get_form_label( $field );
4837 if ( ! is_admin() && ! wp_doing_ajax() ) {
4838 ?>
4839 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4840 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4841 <?php
4842 if ( $field->is_required ) {
4843 echo '<span class="text-danger">*</span>';
4844 }
4845 ?>
4846 </label>
4847 <?php } ?>
4848
4849 <?php
4850 if ( empty( $field->default_value ) ) {
4851 $field->default_value = 'site-default';
4852 }
4853
4854 // if value empty set the default
4855 if ( $value == '' && isset( $field->default_value ) && $field->default_value ) {
4856 $value = $field->default_value;
4857 }
4858
4859 require_once ABSPATH . 'wp-admin/includes/translation-install.php';
4860 $translations = wp_get_available_translations();
4861 $available_languages = get_available_languages();
4862 $languages = array( 'site-default' => __( 'Site Default', 'userswp' ) );
4863
4864 foreach ( $available_languages as $locale ) {
4865 if ( isset( $translations[ $locale ] ) ) {
4866 $translation = $translations[ $locale ];
4867 $languages[ $translation['language'] ] = $translation['native_name'];
4868
4869 // Remove installed language from available translations.
4870 unset( $translations[ $locale ] );
4871 } else {
4872 $languages[ $locale ] = $translation[ $locale ];
4873 }
4874 }
4875
4876 if ( $design_style ) {
4877
4878 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
4879
4880 echo aui()->select(
4881 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4882 'id' => esc_attr( $field->htmlvar_name ),
4883 'name' => esc_attr( $field->htmlvar_name ),
4884 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ),
4885 'title' => esc_attr( $site_title ),
4886 'value' => esc_attr( $value ),
4887 'required' => (bool) $field->is_required,
4888 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4889 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4890 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4891 'label' => wp_kses_post( $site_title . $required ),
4892 'options' => $languages, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4893 'select2' => true,
4894 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '',
4895 )
4896 );
4897 } else {
4898 ?>
4899 <select name="<?php echo esc_attr( $field->htmlvar_name ); ?>" id="<?php echo esc_attr( $field->htmlvar_name ); ?>"
4900 class="uwp_textfield aui-select2 <?php echo esc_attr( $bs_form_control ); ?>"
4901 title="<?php echo esc_attr( $site_title ); ?>"
4902 data-placeholder="<?php echo esc_attr( uwp_get_field_placeholder( $field ) ); ?>"
4903 ><?php echo $select_options; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>
4904 </select>
4905 <span class="uwp_message_note"><?php echo wp_kses_post( uwp_get_field_description( $field ) ); ?></span>
4906 <?php if ( $field->is_required ) { ?>
4907 <span class="uwp_message_error invalid-feedback"><?php echo esc_html__( stripslashes( $field->required_msg ), 'userswp' ); ?></span>
4908 <?php
4909 }
4910 }
4911
4912 $html = ob_get_clean();
4913 }
4914
4915 return $html;
4916 }
4917
4918 /**
4919 * Adds confirm password field in forms.
4920 *
4921 * @param string $html Form field html
4922 * @param object $field Field info.
4923 * @param string $value Form field default value.
4924 * @param string $form_type Form type
4925 *
4926 * @return string Modified form field html.
4927 * @package userswp
4928 *
4929 * @since 1.0.0
4930 */
4931 public function register_confirm_password_field( $html, $field, $value, $form_type ) {
4932 if ( $form_type == 'register' ) {
4933 //confirm password field
4934 $extra = array();
4935 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
4936 $extra = unserialize( $field->extra_fields );
4937 }
4938
4939 $enable_confirm_password_field = isset( $extra['confirm_password'] ) ? $extra['confirm_password'] : '0';
4940 if ( $enable_confirm_password_field == '1' ) {
4941
4942 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
4943 $bs_form_group = $design_style ? 'form-group mb-3' : '';
4944 $bs_sr_only = $design_style ? 'sr-only' : '';
4945 $bs_form_control = $design_style ? 'form-control' : '';
4946 $site_title = $placeholder = __( 'Confirm Password', 'userswp' );
4947 $required = '';
4948 if ( isset( $field->is_required ) && ! empty( $field->is_required ) ) {
4949 $placeholder .= ' *';
4950 $required = ' <span class="text-danger">*</span>';
4951 }
4952 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
4953 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
4954 $wrap_class = isset( $field->css_class ) ? $field->css_class . ' uwp-password-wrap' : 'uwp-password-wrap';
4955
4956 ob_start(); // Start buffering;
4957
4958 if ( $design_style ) {
4959
4960 echo aui()->input(
4961 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
4962 'type' => 'password',
4963 'id' => 'confirm_password',
4964 'name' => 'confirm_password',
4965 'placeholder' => esc_attr( $placeholder ),
4966 'title' => esc_attr( $site_title ),
4967 'value' => esc_attr( $value ),
4968 'required' => (bool) $field->is_required,
4969 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
4970 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
4971 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
4972 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
4973 'wrap_class' => esc_attr( $wrap_class ),
4974 )
4975 );
4976 } else {
4977 ?>
4978 <div id="uwp_account_confirm_password_row"
4979 class="<?php echo 'required_field'; ?> uwp_form_password_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
4980
4981 <?php
4982
4983 if ( ! is_admin() ) {
4984 ?>
4985 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
4986 <?php echo ( trim( $site_title ) ) ? esc_html( $site_title ) : '&nbsp;'; ?>
4987 <?php
4988 if ( $field->is_required ) {
4989 echo '<span>*</span>';
4990 }
4991 ?>
4992 </label>
4993 <?php } ?>
4994 <input name="confirm_password" class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>" id="uwp_account_confirm_password" placeholder="<?php echo esc_attr( $placeholder ); ?>" value="" title="<?php echo esc_attr( $site_title ); ?>" <?php echo 'required="required"'; ?> type="password"/>
4995 </div>
4996
4997 <?php
4998 }
4999 $confirm_html = ob_get_clean();
5000 $html = $html . $confirm_html;
5001 }
5002 }
5003
5004 return $html;
5005 }
5006
5007 /**
5008 * Adds confirm email field in forms.
5009 *
5010 * @param string $html Form field html
5011 * @param object $field Field info.
5012 * @param string $value Form field default value.
5013 * @param string $form_type Form type
5014 *
5015 * @return string Modified form field html.
5016 * @package userswp
5017 *
5018 * @since 1.0.0
5019 */
5020 public function register_confirm_email_field( $html, $field, $value, $form_type ) {
5021 if ( $form_type == 'register' ) {
5022 //confirm email field
5023 $extra = array();
5024 if ( isset( $field->extra_fields ) && $field->extra_fields != '' ) {
5025 $extra = unserialize( $field->extra_fields );
5026 }
5027 $enable_confirm_email_field = isset( $extra['confirm_email'] ) ? $extra['confirm_email'] : '0';
5028 if ( $enable_confirm_email_field == '1' ) {
5029
5030 $design_style = uwp_get_option( 'design_style', 'bootstrap' );
5031 $bs_form_group = $design_style ? 'form-group mb-3' : '';
5032 $bs_sr_only = $design_style ? 'sr-only' : '';
5033 $bs_form_control = $design_style ? 'form-control' : '';
5034 $site_title = __( 'Confirm Email', 'userswp' );
5035 $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : '';
5036 $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : '';
5037
5038 ob_start();
5039
5040 if ( $design_style ) {
5041 $required = ! empty( $field->is_required ) ? ' <span class="text-danger">*</span>' : '';
5042
5043 echo aui()->input(
5044 array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
5045 'type' => 'email',
5046 'id' => esc_attr( $field->htmlvar_name ),
5047 'name' => 'confirm_email',
5048 'placeholder' => esc_attr( $site_title ),
5049 'title' => esc_attr( $site_title ),
5050 'value' => esc_attr( $value ),
5051 'required' => (bool) $field->is_required,
5052 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ),
5053 'label' => is_admin() && ! wp_doing_ajax() ? '' : wp_kses_post( $site_title . $required ),
5054 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ),
5055 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '',
5056 )
5057 );
5058 } else {
5059 ?>
5060 <div id="uwp_account_confirm_email_row"
5061 class="<?php echo 'required_field'; ?> uwp_form_email_row uwp_clear <?php echo esc_attr( $bs_form_group ); ?>">
5062
5063 <?php
5064
5065 if ( ! is_admin() ) {
5066 ?>
5067 <label class="<?php echo esc_attr( $bs_sr_only ); ?>">
5068 <?php echo ( trim( $site_title ) ) ? esc_attr( $site_title ) : '&nbsp;'; ?>
5069 <?php
5070 if ( $field->is_required ) {
5071 echo '<span>*</span>';
5072 }
5073 ?>
5074 </label>
5075 <?php } ?>
5076
5077 <input name="confirm_email"
5078 class="uwp_textfield <?php echo esc_attr( $bs_form_control ); ?>"
5079 id="uwp_account_confirm_email"
5080 placeholder="<?php echo esc_attr( $site_title ); ?>"
5081 value=""
5082 title="<?php echo esc_attr( $site_title ); ?>"
5083 <?php echo 'required="required"'; ?>
5084 type="email"
5085 />
5086 </div>
5087 <?php
5088 }
5089 $confirm_html = ob_get_clean();
5090 $html = $html . $confirm_html;
5091 }
5092 }
5093
5094 return $html;
5095 }
5096
5097 /**
5098 * Handles the privacy form submission.
5099 *
5100 * @return void
5101 * @package userswp
5102 *
5103 * @since 1.0.0
5104 */
5105 public function privacy_submit_handler() {
5106 if ( isset( $_POST['uwp_privacy_submit'] ) ) {
5107 if ( ! isset( $_POST['uwp_privacy_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_privacy_nonce'], 'uwp-privacy-nonce' ) ) {
5108 return;
5109 }
5110
5111 global $wpdb, $uwp_notices;
5112
5113 // Save fields privacy settings
5114 $extra_where = "AND is_public='2'";
5115 $fields = get_account_form_fields( $extra_where );
5116 $fields = apply_filters( 'uwp_account_privacy_fields', $fields );
5117 $user_id = get_current_user_id();
5118 $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta';
5119
5120 $user_meta_info = $wpdb->get_row( $wpdb->prepare( "SELECT user_privacy, tabs_privacy FROM $meta_table WHERE user_id = %d", $user_id ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
5121 if ( ! empty( $user_meta_info->user_privacy ) ) {
5122 $public_fields = explode( ',', $user_meta_info->user_privacy );
5123 } else {
5124 $public_fields = array();
5125 }
5126
5127 if ( $fields ) {
5128
5129 foreach ( $fields as $field ) {
5130 $field_name = $field->htmlvar_name . '_privacy';
5131 $field_value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
5132
5133 if ( $field_value == 'no' ) {
5134 if ( ! in_array( $field_name, $public_fields ) ) {
5135 $public_fields[] = $field_name;
5136 }
5137 } elseif ( ( $field_name = array_search( $field_name, $public_fields ) ) !== false ) {
5138 unset( $public_fields[ $field_name ] );
5139 }
5140 }
5141
5142 $value = implode( ',', $public_fields );
5143 uwp_update_usermeta( $user_id, 'user_privacy', $value );
5144 }
5145
5146 // Save tabs privacy settings
5147 $tabs_table_name = uwp_get_table_prefix() . 'uwp_profile_tabs';
5148 $tabs = $wpdb->get_results( $wpdb->prepare( 'SELECT * FROM ' . $tabs_table_name . ' WHERE form_type=%s AND user_decided = 1 ORDER BY sort_order ASC', 'profile-tabs' ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
5149
5150 if ( $tabs ) {
5151 $public_fields = maybe_unserialize( $user_meta_info->tabs_privacy );
5152 $do_tabs_update = false;
5153 foreach ( $tabs as $tab ) {
5154 $field_name = $tab->tab_key . '_tab_privacy';
5155
5156 if ( isset( $_POST[ $field_name ] ) ) {
5157 $do_tabs_update = true;
5158 $field_value = $_POST[ $field_name ] == '' ? '' : absint( $_POST[ $field_name ] );
5159
5160 if ( $field_value === '' && isset( $public_fields[ $field_name ] ) ) {
5161 unset( $public_fields[ $field_name ] );
5162 } else {
5163 $public_fields[ $field_name ] = $field_value;
5164 }
5165 }
5166 }
5167
5168 if ( $do_tabs_update ) {
5169 uwp_update_usermeta( $user_id, 'tabs_privacy', maybe_serialize( $public_fields ) );
5170 }
5171 }
5172
5173 if ( isset( $_POST['uwp_hide_from_listing'] ) && 1 == $_POST['uwp_hide_from_listing'] ) {
5174 update_user_meta( $user_id, 'uwp_hide_from_listing', 1 );
5175 } else {
5176 update_user_meta( $user_id, 'uwp_hide_from_listing', 0 );
5177 }
5178
5179 $make_profile_private = uwp_can_make_profile_private();
5180 if ( $make_profile_private ) {
5181 $field_name = 'uwp_make_profile_private';
5182 if ( isset( $_POST[ $field_name ] ) ) {
5183 $value = strip_tags( esc_sql( $_POST[ $field_name ] ) );
5184 $user_id = get_current_user_id();
5185 update_user_meta( $user_id, $field_name, $value );
5186 }
5187 }
5188
5189 $message = apply_filters( 'uwp_privacy_update_success_message', __( 'Privacy settings updated successfully.', 'userswp' ) );
5190 $message = aui()->alert(
5191 array(
5192 'type' => 'success',
5193 'content' => $message,
5194 )
5195 );
5196 $uwp_notices[] = array( 'account' => $message );
5197
5198 }
5199 }
5200
5201 /**
5202 * Get the ajax login form.
5203 *
5204 * @since 1.2.0
5205 */
5206 public function ajax_login_form() {
5207
5208 // add the modal error container
5209 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5210
5211 $args = array(
5212 'form_title' => __( 'Login', 'userswp' ),
5213 );
5214
5215 // get the form
5216 ob_start();
5217 uwp_get_template( 'bootstrap/login.php', $args );
5218 $form = ob_get_clean();
5219
5220 // bs5
5221 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5222 $form = aui_bs_convert_sd_output( $form );
5223 }
5224 // send ajax response
5225 wp_send_json_success( $form );
5226 }
5227
5228 /**
5229 * Get the ajax register form.
5230 *
5231 * @since 1.2.0
5232 */
5233 public function ajax_register_form() {
5234
5235 // add the modal error container
5236 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5237
5238 global $wp_scripts;
5239 if ( empty( $wp_scripts ) ) {
5240 $wp_scripts = wp_scripts();
5241 }
5242
5243 // do we need country code script in ajax?
5244 $country_field = false;
5245 $lightbox_forms = uwp_get_option( 'register_modal_form', 1 );
5246
5247 if ( isset( $_POST['form_id'] ) && ! empty( $_POST['form_id'] ) ) {
5248 $form_id = (int)$_POST['form_id'];
5249 } elseif ( is_array( $lightbox_forms ) && count( $lightbox_forms ) > 0 ) {
5250 $form_id = reset( $lightbox_forms );
5251 } else {
5252 $form_id = 1;
5253 }
5254
5255 $fields = get_register_form_fields( $form_id );
5256 if ( ! empty( $fields ) ) {
5257 foreach ( $fields as $field ) {
5258 if ( $field->field_type_key == 'country' || $field->field_type_key == 'uwp_country' ) {
5259 $country_field = true;
5260 }
5261 }
5262 }
5263
5264 ob_start();
5265
5266 // maybe add country code JS
5267 if ( $country_field ) {
5268 $country_data = uwp_get_country_data();
5269 echo '<script>var uwp_country_data = ' . json_encode( $country_data ) . '</script>';
5270 echo "<script type='text/javascript' src='" . esc_url( USERSWP_PLUGIN_URL ) . 'assets/js/countrySelect.min.js' . "' ></script>";
5271 }
5272
5273 $args = array( 'form_title' => '' );
5274 if ( $form_id > 0 ) {
5275 $args['id'] = $form_id;
5276 }
5277
5278 $args['limit'] = $lightbox_forms;
5279
5280 // get template
5281 uwp_get_template( 'bootstrap/register.php', $args );
5282
5283 // only show the JS if NOT doing a block render
5284 if ( isset( $_REQUEST['action'] ) && $_REQUEST['action'] != 'super_duper_output_shortcode' ) {
5285 // load scripts
5286 $wp_scripts->do_item( 'zxcvbn-async' );
5287 $wp_scripts->do_item( 'wp-hooks' );
5288 $wp_scripts->do_item( 'wp-i18n' );
5289 $wp_scripts->do_item( 'password-strength-meter' );
5290 ?>
5291 <script>
5292 // Password strength indicator script
5293 jQuery(function ($) {
5294
5295 // Load the settings like WP does.
5296 var first, s;
5297 s = document.createElement('script');
5298 s.src = _zxcvbnSettings.src;
5299 s.type = 'text/javascript';
5300 s.async = true;
5301 first = document.getElementsByTagName('script')[0];
5302 first.parentNode.insertBefore(s, first);
5303
5304 // Enable any pass inputs.
5305 $('body').on('keyup', 'input[name=password], input[name=confirm_password]',
5306 function (event) {
5307 var $form = $(this).closest('form');
5308 if( ! $form.hasClass('uwp-login-form') ) {
5309 uwp_checkPasswordStrength(
5310 $form.find('input[name=password]'),
5311 $form.find('input[name=confirm_password]'),
5312 $form.find('#uwp-password-strength'),
5313 $form.find('button[type="submit"], input[type="submit"]'),
5314 ['black', 'listed', 'word']
5315 );
5316 }
5317 }
5318 );
5319 });
5320 </script>
5321 <?php
5322 }
5323 $form = ob_get_clean();
5324
5325 // bs5
5326 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5327 $form = aui_bs_convert_sd_output( $form );
5328 }
5329
5330 // send ajax response
5331 wp_send_json_success( $form );
5332 }
5333
5334 /**
5335 * Get the ajax forgot password form.
5336 *
5337 * @since 1.2.0
5338 */
5339 public function ajax_forgot_password_form() {
5340
5341 // add the modal error container
5342 add_action( 'uwp_template_display_notices', array( $this, 'modal_error_container' ) );
5343 $args = array(
5344 'form_title' => '',
5345 'css_class' => ''
5346 );
5347 // get the form
5348 ob_start();
5349 uwp_get_template( 'bootstrap/forgot.php', $args );
5350 $form = ob_get_clean();
5351
5352 // bs5
5353 if ( function_exists( 'aui_bs_convert_sd_output' ) ) {
5354 $form = aui_bs_convert_sd_output( $form );
5355 }
5356
5357 // send ajax response
5358 wp_send_json_success( $form );
5359 }
5360
5361 /**
5362 * Output the modal error container.
5363 *
5364 * @param string $type
5365 *
5366 * @since 1.2.0
5367 */
5368 public function modal_error_container( $type = '' ) {
5369 echo '<div class="form-group mb-3"><div class="modal-error"></div></div>';
5370 }
5371
5372 public function form_custom_html( $html, $field, $value, $form_type ) {
5373
5374 $html = ! empty( $field->default_value ) ? $field->default_value : ' ';
5375
5376 return $html;
5377 }
5378 }
5379