PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.76
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.76
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
← All changes | includes/class-files.php +102 -33 1.0.17 → 1.2.76 View file →
@@ -28,12 +28,12 @@
28 28 if (isset($extra_fields['uwp_file_types']) && !in_array("*", $extra_fields['uwp_file_types'])) {
29 29 $allowed_mime_types = $extra_fields['uwp_file_types'];
30 30 }
31 31
32 - $allowed_mime_types = apply_filters('uwp_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name);
32 + $allowed_mime_types = apply_filters('uwp_fields_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name);
33 33
34 34 $file_urls = array();
35 - $files_to_upload = $this->uwp_prepare_files( $files[ $field->htmlvar_name ] );
35 + $files_to_upload = $this->prepare_files( $files[ $field->htmlvar_name ] );
36 36
37 37 $max_upload_size = $this->uwp_get_max_upload_size($field->form_type, $field->htmlvar_name);
38 38
39 39 if ( ! $max_upload_size ) {
@@ -42,9 +42,9 @@
42 42
43 43 foreach ( $files_to_upload as $file_key => $file_to_upload ) {
44 44
45 45 if (!empty($allowed_mime_types)) {
46 - $ext = $this->uwp_get_file_type($file_to_upload['type']);
46 + $ext = $this->get_file_type($file_to_upload['type']);
47 47
48 48 $allowed_error_text = implode(', ', $allowed_mime_types);
49 49 if ( !in_array( $ext , $allowed_mime_types ) )
50 50 return new WP_Error( 'validation-error', sprintf( __( 'Allowed files types are: %s', 'userswp' ), $allowed_error_text) );
@@ -60,14 +60,14 @@
60 60 if (is_wp_error($error_result)) {
61 61 return $error_result;
62 62 }
63 63
64 - remove_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') );
65 - if(in_array($field->htmlvar_name, array('uwp_banner_file','uwp_avatar_file'))){
64 + remove_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
65 + if(in_array($field->htmlvar_name, array('avatar', 'banner'))){
66 66 add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 );
67 67 }
68 - $uploaded_file = $this->uwp_upload_file( $file_to_upload, array( 'file_key' => $file_key ) );
69 - add_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') );
68 + $uploaded_file = $this->upload_file( $file_to_upload, array( 'file_key' => $file_key ) );
69 + add_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') );
70 70
71 71 if ( is_wp_error( $uploaded_file ) ) {
72 72
73 73 return new WP_Error( 'validation-error', $uploaded_file->get_error_message() );
@@ -73,8 +73,13 @@
73 73 return new WP_Error( 'validation-error', $uploaded_file->get_error_message() );
74 74
75 75 } else {
76 76
77 + // Record this upload so the crop handler only accepts the user's own file.
78 + if ( in_array( $field->htmlvar_name, array( 'avatar', 'banner' ), true ) && get_current_user_id() ) {
79 + update_user_meta( get_current_user_id(), '_uwp_pending_' . $field->htmlvar_name . '_upload', $uploaded_file->url );
80 + }
81 +
77 82 $file_urls[] = array(
78 83 'url' => $uploaded_file->url,
79 84 'path' => $uploaded_file->path,
80 85 'size' => $uploaded_file->size,
@@ -155,8 +160,9 @@
155 160 */
156 161 public function uwp_get_size_in_bytes($val) {
157 162 $val = trim($val);
158 163 $last = strtolower($val[strlen($val)-1]);
164 + $val = substr($val, 0, -1);
159 165 switch($last) {
160 166 // The 'G' modifier is available since PHP 5.1.0
161 167 case 'g':
162 168 $val *= (1024 * 1024 * 1024); //1073741824
@@ -180,12 +186,13 @@
180 186 * @param array $file File info to upload.
181 187 * @param array $args File upload helper args.
182 188 * @return object Uploaded file info
183 189 */
184 - public function uwp_upload_file( $file, $args = array() ) {
190 + public function upload_file( $file, $args = array() ) {
185 191
186 192 include_once ABSPATH . 'wp-admin/includes/file.php';
187 193 include_once ABSPATH . 'wp-admin/includes/media.php';
194 + include_once ABSPATH . 'wp-admin/includes/image.php';
188 195
189 196 $args = wp_parse_args( $args, array(
190 197 'file_key' => '',
191 198 'file_label' => '',
@@ -201,11 +208,32 @@
201 208 return new WP_Error( 'upload', sprintf( __( 'Uploaded files need to be one of the following file types: %s', 'userswp' ), implode( ', ', array_keys( $args['allowed_mime_types'] ) ) ) );
202 209 }
203 210 } else {
204 211 $upload = wp_handle_upload( $file, apply_filters( 'uwp_handle_upload_overrides', array( 'test_form' => false ) ) );
212 +
205 213 if ( ! empty( $upload['error'] ) ) {
206 214 return new WP_Error( 'upload', $upload['error'] );
207 215 } else {
216 + if ( ! empty( $upload['type'] ) && $upload['type'] != 'image/png' && strpos( $upload['type'], 'image/' ) === 0 ) {
217 + // Fetch additional metadata from EXIF/IPTC.
218 + $exif_meta = wp_read_image_metadata( $upload['file'] );
219 +
220 + if ( ! empty( $exif_meta ) && is_array( $exif_meta ) && ! empty( $exif_meta['orientation'] ) && 1 !== (int) $exif_meta['orientation'] ) {
221 + $editor = wp_get_image_editor( $upload['file'] );
222 +
223 + if ( ! empty( $editor ) && ! is_wp_error( $editor ) ) {
224 + // Rotate the whole original image if there is EXIF data and "orientation" is not 1.
225 + $rotated = $editor->maybe_exif_rotate();
226 + $rotated = $rotated === true ? $editor->save( $editor->generate_filename( 'rotated' ) ) : false;
227 +
228 + if ( ! empty( $rotated ) && ! is_wp_error( $rotated ) && ! empty( $rotated['path'] ) ) {
229 + $upload['url'] = str_replace( basename( $upload['url'] ), basename( $rotated['path'] ), $upload['url'] );
230 + $upload['file'] = $rotated['path'];
231 + }
232 + }
233 + }
234 + }
235 +
208 236 $uploaded_file->url = $upload['url'];
209 237 $uploaded_file->name = basename( $upload['file'] );
210 238 $uploaded_file->path = $upload['file'];
211 239 $uploaded_file->type = $upload['type'];
@@ -213,9 +241,8 @@
213 241 $uploaded_file->extension = substr( strrchr( $uploaded_file->name, '.' ), 1 );
214 242 }
215 243 }
216 244
217 -
218 245 return $uploaded_file;
219 246 }
220 247
221 248 /**
@@ -225,9 +252,9 @@
225 252 * @package userswp
226 253 * @param array $file_data Files to upload
227 254 * @return array Prepared files.
228 255 */
229 - public function uwp_prepare_files( $file_data ) {
256 + public function prepare_files( $file_data ) {
230 257 $files_to_upload = array();
231 258
232 259 if ( is_array( $file_data['name'] ) ) {
233 260 foreach ( $file_data['name'] as $file_data_key => $file_data_value ) {
@@ -259,9 +286,9 @@
259 286 * @param bool $url_only Return only the url or whole file info?
260 287 * @param array|bool $fields Form fields.
261 288 * @return array Validated data.
262 289 */
263 - public function uwp_validate_uploads($files, $type, $url_only = true, $fields = false) {
290 + public function validate_uploads($files, $type, $url_only = true, $fields = false) {
264 291
265 292 $validated_data = array();
266 293
267 294 if (empty($files)) {
@@ -280,26 +307,23 @@
280 307 $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' ORDER BY sort_order ASC", array($type)));
281 308 }
282 309 }
283 310
311 + if ( ! empty( $fields ) ) {
312 + foreach ( $fields as $field ) {
313 + if ( isset( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ]['name'] ) ) {
314 + $file_urls = $this->handle_file_upload( $field, $files );
284 315
285 - if (!empty($fields)) {
286 - foreach ($fields as $field) {
287 - if(isset($files[$field->htmlvar_name])) {
288 -
289 - $file_urls = $this->handle_file_upload($field, $files);
290 -
291 - if (is_wp_error($file_urls)) {
316 + if ( is_wp_error( $file_urls ) ) {
292 317 return $file_urls;
293 318 }
294 319
295 - if ($url_only) {
320 + if ( $url_only ) {
296 321 $validated_data[$field->htmlvar_name] = $file_urls['url'];
297 322 } else {
298 323 $validated_data[$field->htmlvar_name] = $file_urls;
299 324 }
300 325 }
301 -
302 326 }
303 327 }
304 328
305 329 return $validated_data;
@@ -314,17 +338,17 @@
314 338 * @param string $value Value of the field.
315 339 * @param bool $removable Is this value removable by user?
316 340 * @return string HTML output.
317 341 */
318 - public function uwp_file_upload_preview($field, $value, $removable = true) {
342 + public function file_upload_preview($field, $value, $removable = true) {
319 343 $output = '';
320 344
321 345 $value = esc_html($value);
322 346
323 - if ($field->htmlvar_name == "uwp_banner_file") {
324 - $htmlvar = "uwp_account_banner_thumb";
325 - } elseif ($field->htmlvar_name == "uwp_avatar_file") {
326 - $htmlvar = "uwp_account_avatar_thumb";
347 + if ($field->htmlvar_name == "banner") {
348 + $htmlvar = "banner_thumb";
349 + } elseif ($field->htmlvar_name == "avatar") {
350 + $htmlvar = "avatar_thumb";
327 351 } else {
328 352 $htmlvar = $field->htmlvar_name;
329 353 }
330 354
@@ -332,10 +356,9 @@
332 356 if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) {
333 357 $user_id = get_current_user_id();
334 358 // If is another user's profile page
335 359 } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) {
336 - $user_id = $_GET['user_id'];
337 - $user_id = (int) sanitize_text_field($user_id);
360 + $user_id = absint( $_GET['user_id'] );
338 361 // Otherwise something is wrong.
339 362 } else {
340 363 $user_id = get_current_user_id();
341 364 }
@@ -353,9 +376,9 @@
353 376 if (in_array($filetype['ext'], $image_types)) {
354 377 $output .= '<div class="uwp_file_preview_wrap">';
355 378 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview"><img style="max-width:100px;" src="'.$value.'" /></a>';
356 379 if ($removable) {
357 - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>';
380 + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>';
358 381 }
359 382 $output .= '</div>';
360 383 ?>
361 384 <?php
@@ -362,9 +385,9 @@
362 385 } else {
363 386 $output .= '<div class="uwp_file_preview_wrap">';
364 387 $output .= '<a href="'.$value.'" class="uwp_upload_file_preview">'.$file.'</a>';
365 388 if ($removable) {
366 - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>';
389 + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>';
367 390 }
368 391 $output .= '</div>';
369 392 ?>
370 393 <?php
@@ -380,9 +403,9 @@
380 403 * @package userswp
381 404 * @param array $file File info.
382 405 * @return array Modified file info.
383 406 */
384 - public function uwp_wp_media_restrict_file_types($file) {
407 + public function wp_media_restrict_file_types($file) {
385 408 // This bit is for the flash uploader
386 409 if ($file['type']=='application/octet-stream' && isset($file['tmp_name'])) {
387 410 $file_size = getimagesize($file['tmp_name']);
388 411 if (isset($file_size['error']) && $file_size['error']!=0) {
@@ -394,9 +417,9 @@
394 417 }
395 418 list($category,$type) = explode('/',$file['type']);
396 419 if ('image'!=$category || !in_array($type,array('jpg','jpeg','gif','png'))) {
397 420 $file['error'] = "Sorry, you can only upload a .GIF, a .JPG, or a .PNG image file.";
398 - } else if ($post_id = (isset($_REQUEST['post_id']) ? $_REQUEST['post_id'] : false)) {
421 + } else if ($post_id = (isset($_REQUEST['post_id']) ? absint($_REQUEST['post_id']) : false)) {
399 422 if (count(get_posts("post_type=attachment&post_parent={$post_id}"))>0)
400 423 $file['error'] = "Sorry, you cannot upload more than one (1) image.";
401 424 }
402 425 return $file;
@@ -408,9 +431,9 @@
408 431 * @since 1.0.0
409 432 * @package userswp
410 433 * @return bool
411 434 */
412 - public function uwp_doing_upload(){
435 + public function doing_upload(){
413 436 return isset($_POST['uwp_profile_upload']) ? true : false;
414 437 }
415 438
416 439 /**
@@ -479,9 +502,9 @@
479 502 * @param string $ext Extension string. Ex: png, jpg
480 503 *
481 504 * @return string File type.
482 505 */
483 - public function uwp_get_file_type($ext) {
506 + public function get_file_type($ext) {
484 507 $allowed_file_types = $this->allowed_mime_types();
485 508 $file_types = array();
486 509 foreach ( $allowed_file_types as $format => $types ) {
487 510 $file_types = array_merge($file_types, $types);
@@ -556,6 +579,52 @@
556 579 )
557 580 )
558 581 );
559 582 }
583 +
584 + /**
585 + * Initiate the WordPress file system and provide fallback if needed.
586 + *
587 + * @since 1.2.2
588 + * @package userswp
589 + * @return bool|string Returns the file system class on success. False on failure.
590 + */
591 + public static function uwp_init_filesystem() {
592 +
593 + if ( ! function_exists( 'get_filesystem_method' ) ) {
594 + require_once( ABSPATH . "/wp-admin/includes/file.php" );
595 + }
596 + $access_type = get_filesystem_method();
597 + if ( $access_type === 'direct' ) {
598 + /* you can safely run request_filesystem_credentials() without any issues and don't need to worry about passing in a URL */
599 + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
600 +
601 + /* initialize the API */
602 + if ( ! WP_Filesystem( $creds ) ) {
603 + /* any problems and we exit */
604 + return false;
605 + }
606 +
607 + global $wp_filesystem;
608 +
609 + return $wp_filesystem;
610 + /* do our file manipulations below */
611 + } elseif ( defined( 'FTP_USER' ) ) {
612 + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() );
613 +
614 + /* initialize the API */
615 + if ( ! WP_Filesystem( $creds ) ) {
616 + /* any problems and we exit */
617 + return false;
618 + }
619 +
620 + global $wp_filesystem;
621 +
622 + return $wp_filesystem;
623 +
624 + } else {
625 + return false;
626 + }
627 +
628 + }
560 629
561 630 }