PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.76
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.76
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
← All changes | includes/class-files.php +104 -32 1.0.11 → 1.2.76 View file →
@@ -28,12 +28,12 @@
28 28 if (isset($extra_fields['uwp_file_types']) && !in_array("*", $extra_fields['uwp_file_types'])) {
29 29 $allowed_mime_types = $extra_fields['uwp_file_types'];
30 30 }
31 31
32 - $allowed_mime_types = apply_filters('uwp_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name);
32 + $allowed_mime_types = apply_filters('uwp_fields_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name);
33 33
34 34 $file_urls = array();
35 - $files_to_upload = $this->uwp_prepare_files( $files[ $field->htmlvar_name ] );
35 + $files_to_upload = $this->prepare_files( $files[ $field->htmlvar_name ] );
36 36
37 37 $max_upload_size = $this->uwp_get_max_upload_size($field->form_type, $field->htmlvar_name);
38 38
39 39 if ( ! $max_upload_size ) {
@@ -42,9 +42,9 @@
42 42
43 43 foreach ( $files_to_upload as $file_key => $file_to_upload ) {
44 44
45 45 if (!empty($allowed_mime_types)) {
46 - $ext = $this->uwp_get_file_type($file_to_upload['type']);
46 + $ext = $this->get_file_type($file_to_upload['type']);
47 47
48 48 $allowed_error_text = implode(', ', $allowed_mime_types);
49 49 if ( !in_array( $ext , $allowed_mime_types ) )
50 50 return new WP_Error( 'validation-error', sprintf( __( 'Allowed files types are: %s', 'userswp' ), $allowed_error_text) );
@@ -60,11 +60,14 @@
60 60 if (is_wp_error($error_result)) {
61 61 return $error_result;
62 62 }
63 63
64 - remove_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') );
65 - $uploaded_file = $this->uwp_upload_file( $file_to_upload, array( 'file_key' => $file_key ) );
66 - add_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') );
64 + remove_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
65 + if(in_array($field->htmlvar_name, array('avatar', 'banner'))){
66 + add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
67 + }
68 + $uploaded_file = $this->upload_file( $file_to_upload, array( 'file_key' => $file_key ) );
69 + add_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
67 70
68 71 if ( is_wp_error( $uploaded_file ) ) {
69 72
70 73 return new WP_Error( 'validation-error', $uploaded_file->get_error_message() );
@@ -70,8 +73,13 @@
70 73 return new WP_Error( 'validation-error', $uploaded_file->get_error_message() );
71 74
72 75 } else {
73 76
77 + // Record this upload so the crop handler only accepts the user's own file.
78 + if ( in_array( $field->htmlvar_name, array( 'avatar', 'banner' ), true ) && get_current_user_id() ) {
79 + update_user_meta( get_current_user_id(), '_uwp_pending_' . $field->htmlvar_name . '_upload', $uploaded_file->url );
80 + }
81 +
74 82 $file_urls[] = array(
75 83 'url' => $uploaded_file->url,
76 84 'path' => $uploaded_file->path,
77 85 'size' => $uploaded_file->size,
@@ -152,8 +160,9 @@
152 160 */
153 161 public function uwp_get_size_in_bytes($val) {
154 162 $val = trim($val);
155 163 $last = strtolower($val[strlen($val)-1]);
164 + $val = substr($val, 0, -1);
156 165 switch($last) {
157 166 // The 'G' modifier is available since PHP 5.1.0
158 167 case 'g':
159 168 $val *= (1024 * 1024 * 1024); //1073741824
@@ -177,12 +186,13 @@
177 186 * @param array $file File info to upload.
178 187 * @param array $args File upload helper args.
179 188 * @return object Uploaded file info
180 189 */
181 - public function uwp_upload_file( $file, $args = array() ) {
190 + public function upload_file( $file, $args = array() ) {
182 191
183 192 include_once ABSPATH . 'wp-admin/includes/file.php';
184 193 include_once ABSPATH . 'wp-admin/includes/media.php';
194 + include_once ABSPATH . 'wp-admin/includes/image.php';
185 195
186 196 $args = wp_parse_args( $args, array(
187 197 'file_key' => '',
188 198 'file_label' => '',
@@ -198,11 +208,32 @@
198 208 return new WP_Error( 'upload', sprintf( __( 'Uploaded files need to be one of the following file types: %s', 'userswp' ), implode( ', ', array_keys( $args['allowed_mime_types'] ) ) ) );
199 209 }
200 210 } else {
201 211 $upload = wp_handle_upload( $file, apply_filters( 'uwp_handle_upload_overrides', array( 'test_form' => false ) ) );
212 +
202 213 if ( ! empty( $upload['error'] ) ) {
203 214 return new WP_Error( 'upload', $upload['error'] );
204 215 } else {
216 + if ( ! empty( $upload['type'] ) && $upload['type'] != 'image/png' && strpos( $upload['type'], 'image/' ) === 0 ) {
217 + // Fetch additional metadata from EXIF/IPTC.
218 + $exif_meta = wp_read_image_metadata( $upload['file'] );
219 +
220 + if ( ! empty( $exif_meta ) && is_array( $exif_meta ) && ! empty( $exif_meta['orientation'] ) && 1 !== (int) $exif_meta['orientation'] ) {
221 + $editor = wp_get_image_editor( $upload['file'] );
222 +
223 + if ( ! empty( $editor ) && ! is_wp_error( $editor ) ) {
224 + // Rotate the whole original image if there is EXIF data and "orientation" is not 1.
225 + $rotated = $editor->maybe_exif_rotate();
226 + $rotated = $rotated === true ? $editor->save( $editor->generate_filename( 'rotated' ) ) : false;
227 +
228 + if ( ! empty( $rotated ) && ! is_wp_error( $rotated ) && ! empty( $rotated['path'] ) ) {
229 + $upload['url'] = str_replace( basename( $upload['url'] ), basename( $rotated['path'] ), $upload['url'] );
230 + $upload['file'] = $rotated['path'];
231 + }
232 + }
233 + }
234 + }
235 +
205 236 $uploaded_file->url = $upload['url'];
206 237 $uploaded_file->name = basename( $upload['file'] );
207 238 $uploaded_file->path = $upload['file'];
208 239 $uploaded_file->type = $upload['type'];
@@ -210,9 +241,8 @@
210 241 $uploaded_file->extension = substr( strrchr( $uploaded_file->name, '.' ), 1 );
211 242 }
212 243 }
213 244
214 -
215 245 return $uploaded_file;
216 246 }
217 247
218 248 /**
@@ -222,9 +252,9 @@
222 252 * @package userswp
223 253 * @param array $file_data Files to upload
224 254 * @return array Prepared files.
225 255 */
226 - public function uwp_prepare_files( $file_data ) {
256 + public function prepare_files( $file_data ) {
227 257 $files_to_upload = array();
228 258
229 259 if ( is_array( $file_data['name'] ) ) {
230 260 foreach ( $file_data['name'] as $file_data_key => $file_data_value ) {
@@ -256,9 +286,9 @@
256 286 * @param bool $url_only Return only the url or whole file info?
257 287 * @param array|bool $fields Form fields.
258 288 * @return array Validated data.
259 289 */
260 - public function uwp_validate_uploads($files, $type, $url_only = true, $fields = false) {
290 + public function validate_uploads($files, $type, $url_only = true, $fields = false) {
261 291
262 292 $validated_data = array();
263 293
264 294 if (empty($files)) {
@@ -277,26 +307,23 @@
277 307 $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' ORDER BY sort_order ASC", array($type)));
278 308 }
279 309 }
280 310
311 + if ( ! empty( $fields ) ) {
312 + foreach ( $fields as $field ) {
313 + if ( isset( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ]['name'] ) ) {
314 + $file_urls = $this->handle_file_upload( $field, $files );
281 315
282 - if (!empty($fields)) {
283 - foreach ($fields as $field) {
284 - if(isset($files[$field->htmlvar_name])) {
285 -
286 - $file_urls = $this->handle_file_upload($field, $files);
287 -
288 - if (is_wp_error($file_urls)) {
316 + if ( is_wp_error( $file_urls ) ) {
289 317 return $file_urls;
290 318 }
291 319
292 - if ($url_only) {
320 + if ( $url_only ) {
293 321 $validated_data[$field->htmlvar_name] = $file_urls['url'];
294 322 } else {
295 323 $validated_data[$field->htmlvar_name] = $file_urls;
296 324 }
297 325 }
298 -
299 326 }
300 327 }
301 328
302 329 return $validated_data;
@@ -311,17 +338,17 @@
311 338 * @param string $value Value of the field.
312 339 * @param bool $removable Is this value removable by user?
313 340 * @return string HTML output.
314 341 */
315 - public function uwp_file_upload_preview($field, $value, $removable = true) {
342 + public function file_upload_preview($field, $value, $removable = true) {
316 343 $output = '';
317 344
318 345 $value = esc_html($value);
319 346
320 - if ($field->htmlvar_name == "uwp_banner_file") {
321 - $htmlvar = "uwp_account_banner_thumb";
322 - } elseif ($field->htmlvar_name == "uwp_avatar_file") {
323 - $htmlvar = "uwp_account_avatar_thumb";
347 + if ($field->htmlvar_name == "banner") {
348 + $htmlvar = "banner_thumb";
349 + } elseif ($field->htmlvar_name == "avatar") {
350 + $htmlvar = "avatar_thumb";
324 351 } else {
325 352 $htmlvar = $field->htmlvar_name;
326 353 }
327 354
@@ -329,10 +356,9 @@
329 356 if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
330 357 $user_id = get_current_user_id();
331 358 // If is another user's profile page
332 359 } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
333 - $user_id = $_GET['user_id'];
334 - $user_id = (int) sanitize_text_field($user_id);
360 + $user_id = absint( $_GET['user_id'] );
335 361 // Otherwise something is wrong.
336 362 } else {
337 363 $user_id = get_current_user_id();
338 364 }
@@ -350,9 +376,9 @@
350 376 if (in_array($filetype['ext'], $image_types)) {
351 377 $output .= '<div class="uwp_file_preview_wrap">';
352 378 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview"><img style="max-width:100px;" src="'.$value.'" /></a>';
353 379 if ($removable) {
354 - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>';
380 + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>';
355 381 }
356 382 $output .= '</div>';
357 383 ?>
358 384 <?php
@@ -359,9 +385,9 @@
359 385 } else {
360 386 $output .= '<div class="uwp_file_preview_wrap">';
361 387 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview">'.$file.'</a>';
362 388 if ($removable) {
363 - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>';
389 + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>';
364 390 }
365 391 $output .= '</div>';
366 392 ?>
367 393 <?php
@@ -377,9 +403,9 @@
377 403 * @package userswp
378 404 * @param array $file File info.
379 405 * @return array Modified file info.
380 406 */
381 - public function uwp_wp_media_restrict_file_types($file) {
407 + public function wp_media_restrict_file_types($file) {
382 408 // This bit is for the flash uploader
383 409 if ($file['type']=='application/octet-stream' && isset($file['tmp_name'])) {
384 410 $file_size = getimagesize($file['tmp_name']);
385 411 if (isset($file_size['error']) && $file_size['error']!=0) {
@@ -391,9 +417,9 @@
391 417 }
392 418 list($category,$type) = explode('/',$file['type']);
393 419 if ('image'!=$category || !in_array($type,array('jpg','jpeg','gif','png'))) {
394 420 $file['error'] = "Sorry, you can only upload a .GIF, a .JPG, or a .PNG image file.";
395 - } else if ($post_id = (isset($_REQUEST['post_id']) ? $_REQUEST['post_id'] : false)) {
421 + } else if ($post_id = (isset($_REQUEST['post_id']) ? absint($_REQUEST['post_id']) : false)) {
396 422 if (count(get_posts("post_type=attachment&post_parent={$post_id}"))>0)
397 423 $file['error'] = "Sorry, you cannot upload more than one (1) image.";
398 424 }
399 425 return $file;
@@ -405,9 +431,9 @@
405 431 * @since 1.0.0
406 432 * @package userswp
407 433 * @return bool
408 434 */
409 - public function uwp_doing_upload(){
435 + public function doing_upload(){
410 436 return isset($_POST['uwp_profile_upload']) ? true : false;
411 437 }
412 438
413 439 /**
@@ -476,9 +502,9 @@
476 502 * @param string $ext Extension string. Ex: png, jpg
477 503 *
478 504 * @return string File type.
479 505 */
480 - public function uwp_get_file_type($ext) {
506 + public function get_file_type($ext) {
481 507 $allowed_file_types = $this->allowed_mime_types();
482 508 $file_types = array();
483 509 foreach ( $allowed_file_types as $format => $types ) {
484 510 $file_types = array_merge($file_types, $types);
@@ -553,6 +579,52 @@
553 579 )
554 580 )
555 581 );
556 582 }
583 +
584 + /**
585 + * Initiate the WordPress file system and provide fallback if needed.
586 + *
587 + * @since 1.2.2
588 + * @package userswp
589 + * @return bool|string Returns the file system class on success. False on failure.
590 + */
591 + public static function uwp_init_filesystem() {
592 +
593 + if ( ! function_exists( 'get_filesystem_method' ) ) {
594 + require_once( ABSPATH . "/wp-admin/includes/file.php" );
595 + }
596 + $access_type = get_filesystem_method();
597 + if ( $access_type === 'direct' ) {
598 + /* you can safely run request_filesystem_credentials() without any issues and don't need to worry about passing in a URL */
599 + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
600 +
601 + /* initialize the API */
602 + if ( ! WP_Filesystem( $creds ) ) {
603 + /* any problems and we exit */
604 + return false;
605 + }
606 +
607 + global $wp_filesystem;
608 +
609 + return $wp_filesystem;
610 + /* do our file manipulations below */
611 + } elseif ( defined( 'FTP_USER' ) ) {
612 + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
613 +
614 + /* initialize the API */
615 + if ( ! WP_Filesystem( $creds ) ) {
616 + /* any problems and we exit */
617 + return false;
618 + }
619 +
620 + global $wp_filesystem;
621 +
622 + return $wp_filesystem;
623 +
624 + } else {
625 + return false;
626 + }
627 +
628 + }
557 629
558 630 }