| @@ -28,12 +28,12 @@ | ||
| 28 | 28 | if (isset($extra_fields['uwp_file_types']) && !in_array("*", $extra_fields['uwp_file_types'])) { |
| 29 | 29 | $allowed_mime_types = $extra_fields['uwp_file_types']; |
| 30 | 30 | } |
| 31 | 31 | |
| 32 | - $allowed_mime_types = apply_filters('uwp_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name); | |
| 32 | + $allowed_mime_types = apply_filters('uwp_fields_allowed_mime_types', $allowed_mime_types, $field->htmlvar_name); | |
| 33 | 33 | |
| 34 | 34 | $file_urls = array(); |
| 35 | - $files_to_upload = $this->uwp_prepare_files( $files[ $field->htmlvar_name ] ); | |
| 35 | + $files_to_upload = $this->prepare_files( $files[ $field->htmlvar_name ] ); | |
| 36 | 36 | |
| 37 | 37 | $max_upload_size = $this->uwp_get_max_upload_size($field->form_type, $field->htmlvar_name); |
| 38 | 38 | |
| 39 | 39 | if ( ! $max_upload_size ) { |
| @@ -42,9 +42,9 @@ | ||
| 42 | 42 | |
| 43 | 43 | foreach ( $files_to_upload as $file_key => $file_to_upload ) { |
| 44 | 44 | |
| 45 | 45 | if (!empty($allowed_mime_types)) { |
| 46 | - $ext = $this->uwp_get_file_type($file_to_upload['type']); | |
| 46 | + $ext = $this->get_file_type($file_to_upload['type']); | |
| 47 | 47 | |
| 48 | 48 | $allowed_error_text = implode(', ', $allowed_mime_types); |
| 49 | 49 | if ( !in_array( $ext , $allowed_mime_types ) ) |
| 50 | 50 | return new WP_Error( 'validation-error', sprintf( __( 'Allowed files types are: %s', 'userswp' ), $allowed_error_text) ); |
| @@ -60,14 +60,14 @@ | ||
| 60 | 60 | if (is_wp_error($error_result)) { |
| 61 | 61 | return $error_result; |
| 62 | 62 | } |
| 63 | 63 | |
| 64 | - remove_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') ); | |
| 65 | - if(in_array($field->htmlvar_name, array('uwp_banner_file','uwp_avatar_file'))){ | |
| 64 | + remove_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') ); | |
| 65 | + if(in_array($field->htmlvar_name, array('avatar', 'banner'))){ | |
| 66 | 66 | add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 ); |
| 67 | 67 | } |
| 68 | - $uploaded_file = $this->uwp_upload_file( $file_to_upload, array( 'file_key' => $file_key ) ); | |
| 69 | - add_filter( 'wp_handle_upload_prefilter', array($this, 'uwp_wp_media_restrict_file_types') ); | |
| 68 | + $uploaded_file = $this->upload_file( $file_to_upload, array( 'file_key' => $file_key ) ); | |
| 69 | + add_filter( 'wp_handle_upload_prefilter', array($this, 'wp_media_restrict_file_types') ); | |
| 70 | 70 | |
| 71 | 71 | if ( is_wp_error( $uploaded_file ) ) { |
| 72 | 72 | |
| 73 | 73 | return new WP_Error( 'validation-error', $uploaded_file->get_error_message() ); |
| @@ -73,8 +73,13 @@ | ||
| 73 | 73 | return new WP_Error( 'validation-error', $uploaded_file->get_error_message() ); |
| 74 | 74 | |
| 75 | 75 | } else { |
| 76 | 76 | |
| 77 | + // Record this upload so the crop handler only accepts the user's own file. | |
| 78 | + if ( in_array( $field->htmlvar_name, array( 'avatar', 'banner' ), true ) && get_current_user_id() ) { | |
| 79 | + update_user_meta( get_current_user_id(), '_uwp_pending_' . $field->htmlvar_name . '_upload', $uploaded_file->url ); | |
| 80 | + } | |
| 81 | + | |
| 77 | 82 | $file_urls[] = array( |
| 78 | 83 | 'url' => $uploaded_file->url, |
| 79 | 84 | 'path' => $uploaded_file->path, |
| 80 | 85 | 'size' => $uploaded_file->size, |
| @@ -155,8 +160,9 @@ | ||
| 155 | 160 | */ |
| 156 | 161 | public function uwp_get_size_in_bytes($val) { |
| 157 | 162 | $val = trim($val); |
| 158 | 163 | $last = strtolower($val[strlen($val)-1]); |
| 164 | + $val = substr($val, 0, -1); | |
| 159 | 165 | switch($last) { |
| 160 | 166 | // The 'G' modifier is available since PHP 5.1.0 |
| 161 | 167 | case 'g': |
| 162 | 168 | $val *= (1024 * 1024 * 1024); //1073741824 |
| @@ -180,12 +186,13 @@ | ||
| 180 | 186 | * @param array $file File info to upload. |
| 181 | 187 | * @param array $args File upload helper args. |
| 182 | 188 | * @return object Uploaded file info |
| 183 | 189 | */ |
| 184 | - public function uwp_upload_file( $file, $args = array() ) { | |
| 190 | + public function upload_file( $file, $args = array() ) { | |
| 185 | 191 | |
| 186 | 192 | include_once ABSPATH . 'wp-admin/includes/file.php'; |
| 187 | 193 | include_once ABSPATH . 'wp-admin/includes/media.php'; |
| 194 | + include_once ABSPATH . 'wp-admin/includes/image.php'; | |
| 188 | 195 | |
| 189 | 196 | $args = wp_parse_args( $args, array( |
| 190 | 197 | 'file_key' => '', |
| 191 | 198 | 'file_label' => '', |
| @@ -201,11 +208,32 @@ | ||
| 201 | 208 | return new WP_Error( 'upload', sprintf( __( 'Uploaded files need to be one of the following file types: %s', 'userswp' ), implode( ', ', array_keys( $args['allowed_mime_types'] ) ) ) ); |
| 202 | 209 | } |
| 203 | 210 | } else { |
| 204 | 211 | $upload = wp_handle_upload( $file, apply_filters( 'uwp_handle_upload_overrides', array( 'test_form' => false ) ) ); |
| 212 | + | |
| 205 | 213 | if ( ! empty( $upload['error'] ) ) { |
| 206 | 214 | return new WP_Error( 'upload', $upload['error'] ); |
| 207 | 215 | } else { |
| 216 | + if ( ! empty( $upload['type'] ) && $upload['type'] != 'image/png' && strpos( $upload['type'], 'image/' ) === 0 ) { | |
| 217 | + // Fetch additional metadata from EXIF/IPTC. | |
| 218 | + $exif_meta = wp_read_image_metadata( $upload['file'] ); | |
| 219 | + | |
| 220 | + if ( ! empty( $exif_meta ) && is_array( $exif_meta ) && ! empty( $exif_meta['orientation'] ) && 1 !== (int) $exif_meta['orientation'] ) { | |
| 221 | + $editor = wp_get_image_editor( $upload['file'] ); | |
| 222 | + | |
| 223 | + if ( ! empty( $editor ) && ! is_wp_error( $editor ) ) { | |
| 224 | + // Rotate the whole original image if there is EXIF data and "orientation" is not 1. | |
| 225 | + $rotated = $editor->maybe_exif_rotate(); | |
| 226 | + $rotated = $rotated === true ? $editor->save( $editor->generate_filename( 'rotated' ) ) : false; | |
| 227 | + | |
| 228 | + if ( ! empty( $rotated ) && ! is_wp_error( $rotated ) && ! empty( $rotated['path'] ) ) { | |
| 229 | + $upload['url'] = str_replace( basename( $upload['url'] ), basename( $rotated['path'] ), $upload['url'] ); | |
| 230 | + $upload['file'] = $rotated['path']; | |
| 231 | + } | |
| 232 | + } | |
| 233 | + } | |
| 234 | + } | |
| 235 | + | |
| 208 | 236 | $uploaded_file->url = $upload['url']; |
| 209 | 237 | $uploaded_file->name = basename( $upload['file'] ); |
| 210 | 238 | $uploaded_file->path = $upload['file']; |
| 211 | 239 | $uploaded_file->type = $upload['type']; |
| @@ -213,9 +241,8 @@ | ||
| 213 | 241 | $uploaded_file->extension = substr( strrchr( $uploaded_file->name, '.' ), 1 ); |
| 214 | 242 | } |
| 215 | 243 | } |
| 216 | 244 | |
| 217 | - | |
| 218 | 245 | return $uploaded_file; |
| 219 | 246 | } |
| 220 | 247 | |
| 221 | 248 | /** |
| @@ -225,9 +252,9 @@ | ||
| 225 | 252 | * @package userswp |
| 226 | 253 | * @param array $file_data Files to upload |
| 227 | 254 | * @return array Prepared files. |
| 228 | 255 | */ |
| 229 | - public function uwp_prepare_files( $file_data ) { | |
| 256 | + public function prepare_files( $file_data ) { | |
| 230 | 257 | $files_to_upload = array(); |
| 231 | 258 | |
| 232 | 259 | if ( is_array( $file_data['name'] ) ) { |
| 233 | 260 | foreach ( $file_data['name'] as $file_data_key => $file_data_value ) { |
| @@ -259,9 +286,9 @@ | ||
| 259 | 286 | * @param bool $url_only Return only the url or whole file info? |
| 260 | 287 | * @param array|bool $fields Form fields. |
| 261 | 288 | * @return array Validated data. |
| 262 | 289 | */ |
| 263 | - public function uwp_validate_uploads($files, $type, $url_only = true, $fields = false) { | |
| 290 | + public function validate_uploads($files, $type, $url_only = true, $fields = false) { | |
| 264 | 291 | |
| 265 | 292 | $validated_data = array(); |
| 266 | 293 | |
| 267 | 294 | if (empty($files)) { |
| @@ -280,26 +307,23 @@ | ||
| 280 | 307 | $fields = $wpdb->get_results($wpdb->prepare("SELECT * FROM " . $table_name . " WHERE form_type = %s AND field_type = 'file' AND is_active = '1' ORDER BY sort_order ASC", array($type))); |
| 281 | 308 | } |
| 282 | 309 | } |
| 283 | 310 | |
| 311 | + if ( ! empty( $fields ) ) { | |
| 312 | + foreach ( $fields as $field ) { | |
| 313 | + if ( isset( $files[ $field->htmlvar_name ] ) && ! empty( $files[ $field->htmlvar_name ]['name'] ) ) { | |
| 314 | + $file_urls = $this->handle_file_upload( $field, $files ); | |
| 284 | 315 | |
| 285 | - if (!empty($fields)) { | |
| 286 | - foreach ($fields as $field) { | |
| 287 | - if(isset($files[$field->htmlvar_name])) { | |
| 288 | - | |
| 289 | - $file_urls = $this->handle_file_upload($field, $files); | |
| 290 | - | |
| 291 | - if (is_wp_error($file_urls)) { | |
| 316 | + if ( is_wp_error( $file_urls ) ) { | |
| 292 | 317 | return $file_urls; |
| 293 | 318 | } |
| 294 | 319 | |
| 295 | - if ($url_only) { | |
| 320 | + if ( $url_only ) { | |
| 296 | 321 | $validated_data[$field->htmlvar_name] = $file_urls['url']; |
| 297 | 322 | } else { |
| 298 | 323 | $validated_data[$field->htmlvar_name] = $file_urls; |
| 299 | 324 | } |
| 300 | 325 | } |
| 301 | - | |
| 302 | 326 | } |
| 303 | 327 | } |
| 304 | 328 | |
| 305 | 329 | return $validated_data; |
| @@ -314,17 +338,17 @@ | ||
| 314 | 338 | * @param string $value Value of the field. |
| 315 | 339 | * @param bool $removable Is this value removable by user? |
| 316 | 340 | * @return string HTML output. |
| 317 | 341 | */ |
| 318 | - public function uwp_file_upload_preview($field, $value, $removable = true) { | |
| 342 | + public function file_upload_preview($field, $value, $removable = true) { | |
| 319 | 343 | $output = ''; |
| 320 | 344 | |
| 321 | 345 | $value = esc_html($value); |
| 322 | 346 | |
| 323 | - if ($field->htmlvar_name == "uwp_banner_file") { | |
| 324 | - $htmlvar = "uwp_account_banner_thumb"; | |
| 325 | - } elseif ($field->htmlvar_name == "uwp_avatar_file") { | |
| 326 | - $htmlvar = "uwp_account_avatar_thumb"; | |
| 347 | + if ($field->htmlvar_name == "banner") { | |
| 348 | + $htmlvar = "banner_thumb"; | |
| 349 | + } elseif ($field->htmlvar_name == "avatar") { | |
| 350 | + $htmlvar = "avatar_thumb"; | |
| 327 | 351 | } else { |
| 328 | 352 | $htmlvar = $field->htmlvar_name; |
| 329 | 353 | } |
| 330 | 354 | |
| @@ -332,10 +356,9 @@ | ||
| 332 | 356 | if ( is_admin() && defined('IS_PROFILE_PAGE') && IS_PROFILE_PAGE ) { |
| 333 | 357 | $user_id = get_current_user_id(); |
| 334 | 358 | // If is another user's profile page |
| 335 | 359 | } elseif (is_admin() && ! empty($_GET['user_id']) && is_numeric($_GET['user_id']) ) { |
| 336 | - $user_id = $_GET['user_id']; | |
| 337 | - $user_id = (int) sanitize_text_field($user_id); | |
| 360 | + $user_id = absint( $_GET['user_id'] ); | |
| 338 | 361 | // Otherwise something is wrong. |
| 339 | 362 | } else { |
| 340 | 363 | $user_id = get_current_user_id(); |
| 341 | 364 | } |
| @@ -353,9 +376,9 @@ | ||
| 353 | 376 | if (in_array($filetype['ext'], $image_types)) { |
| 354 | 377 | $output .= '<div class="uwp_file_preview_wrap">'; |
| 355 | 378 | $output .= '<a href="'.$value.'" class="uwp_upload_file_preview"><img style="max-width:100px;" src="'.$value.'" /></a>'; |
| 356 | 379 | if ($removable) { |
| 357 | - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>'; | |
| 380 | + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove Image' , 'userswp' ).'</a>'; | |
| 358 | 381 | } |
| 359 | 382 | $output .= '</div>'; |
| 360 | 383 | ?> |
| 361 | 384 | <?php |
| @@ -362,9 +385,9 @@ | ||
| 362 | 385 | } else { |
| 363 | 386 | $output .= '<div class="uwp_file_preview_wrap">'; |
| 364 | 387 | $output .= '<a href="'.$value.'" class="uwp_upload_file_preview">'.$file.'</a>'; |
| 365 | 388 | if ($removable) { |
| 366 | - $output .= '<a onclick="return confirm(\'are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>'; | |
| 389 | + $output .= '<a onclick="return confirm(\'Are you sure?\')" style="display: block;margin: 5px 0;" href="#" id="'.$htmlvar.'" data-htmlvar="'.$htmlvar.'" data-uid="'.$user_id.'" class="uwp_upload_file_remove">'. __( 'Remove File' , 'userswp' ).'</a>'; | |
| 367 | 390 | } |
| 368 | 391 | $output .= '</div>'; |
| 369 | 392 | ?> |
| 370 | 393 | <?php |
| @@ -380,9 +403,9 @@ | ||
| 380 | 403 | * @package userswp |
| 381 | 404 | * @param array $file File info. |
| 382 | 405 | * @return array Modified file info. |
| 383 | 406 | */ |
| 384 | - public function uwp_wp_media_restrict_file_types($file) { | |
| 407 | + public function wp_media_restrict_file_types($file) { | |
| 385 | 408 | // This bit is for the flash uploader |
| 386 | 409 | if ($file['type']=='application/octet-stream' && isset($file['tmp_name'])) { |
| 387 | 410 | $file_size = getimagesize($file['tmp_name']); |
| 388 | 411 | if (isset($file_size['error']) && $file_size['error']!=0) { |
| @@ -394,9 +417,9 @@ | ||
| 394 | 417 | } |
| 395 | 418 | list($category,$type) = explode('/',$file['type']); |
| 396 | 419 | if ('image'!=$category || !in_array($type,array('jpg','jpeg','gif','png'))) { |
| 397 | 420 | $file['error'] = "Sorry, you can only upload a .GIF, a .JPG, or a .PNG image file."; |
| 398 | - } else if ($post_id = (isset($_REQUEST['post_id']) ? $_REQUEST['post_id'] : false)) { | |
| 421 | + } else if ($post_id = (isset($_REQUEST['post_id']) ? absint($_REQUEST['post_id']) : false)) { | |
| 399 | 422 | if (count(get_posts("post_type=attachment&post_parent={$post_id}"))>0) |
| 400 | 423 | $file['error'] = "Sorry, you cannot upload more than one (1) image."; |
| 401 | 424 | } |
| 402 | 425 | return $file; |
| @@ -408,9 +431,9 @@ | ||
| 408 | 431 | * @since 1.0.0 |
| 409 | 432 | * @package userswp |
| 410 | 433 | * @return bool |
| 411 | 434 | */ |
| 412 | - public function uwp_doing_upload(){ | |
| 435 | + public function doing_upload(){ | |
| 413 | 436 | return isset($_POST['uwp_profile_upload']) ? true : false; |
| 414 | 437 | } |
| 415 | 438 | |
| 416 | 439 | /** |
| @@ -479,9 +502,9 @@ | ||
| 479 | 502 | * @param string $ext Extension string. Ex: png, jpg |
| 480 | 503 | * |
| 481 | 504 | * @return string File type. |
| 482 | 505 | */ |
| 483 | - public function uwp_get_file_type($ext) { | |
| 506 | + public function get_file_type($ext) { | |
| 484 | 507 | $allowed_file_types = $this->allowed_mime_types(); |
| 485 | 508 | $file_types = array(); |
| 486 | 509 | foreach ( $allowed_file_types as $format => $types ) { |
| 487 | 510 | $file_types = array_merge($file_types, $types); |
| @@ -556,6 +579,52 @@ | ||
| 556 | 579 | ) |
| 557 | 580 | ) |
| 558 | 581 | ); |
| 559 | 582 | } |
| 583 | + | |
| 584 | + /** | |
| 585 | + * Initiate the WordPress file system and provide fallback if needed. | |
| 586 | + * | |
| 587 | + * @since 1.2.2 | |
| 588 | + * @package userswp | |
| 589 | + * @return bool|string Returns the file system class on success. False on failure. | |
| 590 | + */ | |
| 591 | + public static function uwp_init_filesystem() { | |
| 592 | + | |
| 593 | + if ( ! function_exists( 'get_filesystem_method' ) ) { | |
| 594 | + require_once( ABSPATH . "/wp-admin/includes/file.php" ); | |
| 595 | + } | |
| 596 | + $access_type = get_filesystem_method(); | |
| 597 | + if ( $access_type === 'direct' ) { | |
| 598 | + /* you can safely run request_filesystem_credentials() without any issues and don't need to worry about passing in a URL */ | |
| 599 | + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() ); | |
| 600 | + | |
| 601 | + /* initialize the API */ | |
| 602 | + if ( ! WP_Filesystem( $creds ) ) { | |
| 603 | + /* any problems and we exit */ | |
| 604 | + return false; | |
| 605 | + } | |
| 606 | + | |
| 607 | + global $wp_filesystem; | |
| 608 | + | |
| 609 | + return $wp_filesystem; | |
| 610 | + /* do our file manipulations below */ | |
| 611 | + } elseif ( defined( 'FTP_USER' ) ) { | |
| 612 | + $creds = request_filesystem_credentials( trailingslashit( site_url() ) . 'wp-admin/', '', false, false, array() ); | |
| 613 | + | |
| 614 | + /* initialize the API */ | |
| 615 | + if ( ! WP_Filesystem( $creds ) ) { | |
| 616 | + /* any problems and we exit */ | |
| 617 | + return false; | |
| 618 | + } | |
| 619 | + | |
| 620 | + global $wp_filesystem; | |
| 621 | + | |
| 622 | + return $wp_filesystem; | |
| 623 | + | |
| 624 | + } else { | |
| 625 | + return false; | |
| 626 | + } | |
| 627 | + | |
| 628 | + } | |
| 560 | 629 | |
| 561 | 630 | } |