| @@ -1262,41 +1262,59 @@ | ||
| 1262 | 1262 | |
| 1263 | 1263 | /** |
| 1264 | 1264 | * Redirects the user to login page when email not confirmed. |
| 1265 | 1265 | * |
| 1266 | + * @since 1.0.0 | |
| 1267 | + * @package userswp | |
| 1268 | + * | |
| 1266 | 1269 | * @param string $username Username. |
| 1267 | - * @param object $user User object. | |
| 1270 | + * @param object $user Logged in user object. | |
| 1268 | 1271 | * |
| 1269 | - * @return void | |
| 1270 | - * @package userswp | |
| 1271 | - * | |
| 1272 | - * @since 1.0.0 | |
| 1272 | + * @return void | |
| 1273 | 1273 | */ |
| 1274 | 1274 | public function unconfirmed_login_redirect( $username, $user ) { |
| 1275 | - if ( ! is_wp_error( $user ) ) { | |
| 1276 | - $mod_value = get_user_meta( $user->ID, 'uwp_mod', true ); | |
| 1277 | - if ( $mod_value == 'email_unconfirmed' ) { | |
| 1278 | - if ( ! in_array( 'administrator', $user->roles ) ) { | |
| 1279 | - $login_page = uwp_get_page_id( 'login_page', false ); | |
| 1280 | - if ( $login_page ) { | |
| 1281 | - $redirect_to = add_query_arg( array( | |
| 1282 | - 'uwp_err' => 'act_pending', | |
| 1283 | - 'user_id' => $user->ID | |
| 1284 | - ), get_permalink( $login_page ) ); | |
| 1285 | - wp_destroy_current_session(); | |
| 1286 | - wp_clear_auth_cookie(); | |
| 1287 | - if ( wp_doing_ajax() ) { | |
| 1288 | - global $userswp; | |
| 1289 | - $message = $userswp->notices->form_notice_by_key( 'act_pending', false, $user->ID ); | |
| 1290 | - wp_send_json_error( $message ); | |
| 1291 | - } else { | |
| 1292 | - wp_redirect( $redirect_to ); | |
| 1293 | - } | |
| 1294 | - exit(); | |
| 1295 | - } | |
| 1296 | - } | |
| 1297 | - } | |
| 1275 | + if ( ! $user instanceof WP_User ) { | |
| 1276 | + return; | |
| 1298 | 1277 | } |
| 1278 | + | |
| 1279 | + if ( 'email_unconfirmed' !== get_user_meta( $user->ID, 'uwp_mod', true ) ) { | |
| 1280 | + return; | |
| 1281 | + } | |
| 1282 | + | |
| 1283 | + if ( in_array( 'administrator', (array) $user->roles, true ) ) { | |
| 1284 | + return; | |
| 1285 | + } | |
| 1286 | + | |
| 1287 | + // wp_destroy_current_session() reads the token from $_COOKIE, which does not | |
| 1288 | + // yet contain the cookie issued during this request, so destroy by user instead. | |
| 1289 | + WP_Session_Tokens::get_instance( $user->ID )->destroy_all(); | |
| 1290 | + wp_clear_auth_cookie(); | |
| 1291 | + wp_set_current_user( 0 ); | |
| 1292 | + | |
| 1293 | + global $userswp; | |
| 1294 | + | |
| 1295 | + $message = $userswp->notices->form_notice_by_key( 'act_pending', false, $user->ID ); | |
| 1296 | + | |
| 1297 | + if ( wp_doing_ajax() ) { | |
| 1298 | + wp_send_json_error( array( 'message' => $message ) ); | |
| 1299 | + } | |
| 1300 | + | |
| 1301 | + $login_page = uwp_get_page_id( 'login_page', false ); | |
| 1302 | + | |
| 1303 | + if ( ! $login_page ) { | |
| 1304 | + return; | |
| 1305 | + } | |
| 1306 | + | |
| 1307 | + $redirect_to = add_query_arg( | |
| 1308 | + array( | |
| 1309 | + 'uwp_err' => 'act_pending', | |
| 1310 | + 'user_id' => $user->ID, | |
| 1311 | + ), | |
| 1312 | + get_permalink( $login_page ) | |
| 1313 | + ); | |
| 1314 | + | |
| 1315 | + wp_safe_redirect( $redirect_to ); | |
| 1316 | + exit; | |
| 1299 | 1317 | } |
| 1300 | 1318 | |
| 1301 | 1319 | /** |
| 1302 | 1320 | * Oxygen override theme template. |