*/ class UsersWP_Forms { protected $generated_password; /** * Logs the error message. * * @param array|object|string $log Error message. * * @return void * @since 1.0.0 * @package userswp * */ public static function uwp_error_log( $log ) { uwp_error_log( $log ); } /** * Initialize UsersWP notices. * * @return void * @package userswp * * @since 1.0.0 */ public function init_notices() { global $uwp_notices; $uwp_notices = array(); } /** * Handles all UsersWP forms. * * @return void * @package userswp * * @since 1.0.0 */ public function handler() { global $uwp_notices; ob_start(); $errors = null; $message = null; $redirect = false; $processed = false; $type = null; if ( isset( $_POST['uwp_avatar_submit'] ) ) { $errors = $this->process_upload_submit( $_POST, $_FILES, 'avatar' ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Avatar cropped successfully.', 'userswp' ); $processed = true; } elseif ( isset( $_POST['uwp_banner_submit'] ) ) { $errors = $this->process_upload_submit( $_POST, $_FILES, 'banner' ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Banner cropped successfully.', 'userswp' ); $processed = true; } elseif ( isset( $_POST['uwp_avatar_crop'] ) ) { $errors = $this->process_image_crop( $_POST, 'avatar', true ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Avatar cropped successfully.', 'userswp' ); $processed = true; } elseif ( isset( $_POST['uwp_banner_crop'] ) ) { $errors = $this->process_image_crop( $_POST, 'banner', true ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Banner cropped successfully.', 'userswp' ); $processed = true; } elseif ( isset( $_POST['uwp_avatar_reset'] ) ) { $errors = $this->process_image_reset( 'avatar' ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Avatar reset successfully.', 'userswp' ); $processed = true; } elseif ( isset( $_POST['uwp_banner_reset'] ) ) { $errors = $this->process_image_reset( 'banner' ); if ( ! is_wp_error( $errors ) ) { $redirect = $errors; } $message = __( 'Banner reset successfully.', 'userswp' ); $processed = true; } if ( $processed ) { if ( is_wp_error( $errors ) ) { aui()->alert( array( 'type' => 'error', 'content' => wp_kses_post( $errors->get_error_message() ) ), true ); } else if ( $redirect ) { wp_safe_redirect( $redirect ); exit(); } else { aui()->alert( array( 'type' => 'success', 'content' => wp_kses_post( $message ) ), true ); } } if ( $type ) { $uwp_notices[] = array( $type => ob_get_contents() ); } else { $uwp_notices[] = ob_get_contents(); } ob_end_clean(); } /** * Processes avatar and banner uploads form submission. * * @param array $data Submitted $_POST data * @param array $files Submitted $_FILES data * * @return bool|WP_Error|string File url to crop. * @package userswp * * @since 1.0.0 */ public function process_upload_submit( $data = array(), $files = array(), $type = 'avatar' ) { $file_obj = new UsersWP_Files(); $current_user_id = get_current_user_id(); if ( ! $current_user_id ) { return false; } if ( ! isset( $data['uwp_upload_nonce'] ) || ! wp_verify_nonce( $data['uwp_upload_nonce'], 'uwp-upload-nonce' ) ) { return false; } do_action( 'uwp_before_validate', $type ); $result = $file_obj->validate_uploads( $files, $type ); $result = apply_filters( 'uwp_validate_result', $result, $type, $data ); if ( is_wp_error( $result ) ) { return $result; } $profile_url = uwp_build_profile_tab_url( $current_user_id ); $url = add_query_arg( array( 'uwp_crop' => $result[ 'uwp_' . $type . '_file' ], 'type' => $type, ), $profile_url ); return $url; } /** * Processes avatar and banner uploads image crop. * * @param array $data Submitted $_POST data * @param string $type Image type. Default 'avatar'. * @param bool $unlink_prev_img True to remove previous image. Default false; * * @return bool|WP_Error|string Profile url. * @since 1.0.12 New param $unlink_prev_img introduced. * @package userswp * * @since 1.0.0 */ public function process_image_crop( $data = array(), $type = 'avatar', $unlink_prev_img = false ) { global $wpdb; if ( ! is_user_logged_in() ) { return false; } if ( empty( $_POST['uwp_crop_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_crop_nonce'], 'uwp_crop_nonce_' . $type ) ) { return; } $image_url = ! empty( $data['uwp_crop'] ) ? esc_url( $data['uwp_crop'] ) : ''; if ( empty( $image_url ) ) { return new WP_Error( 'empty_image', __( 'Upload valid image.', 'userswp' ) ); } // Ensure we have a valid URL with an allowed meme type. $image_url = $this->normalize_url( $image_url ); $content_url = str_replace( array( 'https://', 'http://' ) , '', untrailingslashit( WP_CONTENT_URL ) ); $_image_url = str_replace( array( 'https://', 'http://' ), '', $image_url ); if ( strpos( $_image_url, $content_url ) !== 0 ) { return new WP_Error( 'invalid_image', __( 'Invalid image url.', 'userswp' ) ); } // Only allow cropping the image the current user just uploaded (normalized like $image_url). $pending_key = '_uwp_pending_' . $type . '_upload'; $pending_url = get_user_meta( get_current_user_id(), $pending_key, true ); $pending_url = $pending_url ? str_replace( array( 'https://', 'http://' ), '', $this->normalize_url( esc_url( $pending_url ) ) ) : ''; if ( empty( $pending_url ) || $pending_url !== $_image_url ) { return new WP_Error( 'crop_session_expired', __( 'Your image upload could not be verified. Please upload the image again.', 'userswp' ) ); } $filetype = wp_check_filetype( $image_url ); if ( empty( $filetype['ext'] ) ) { return new WP_Error( 'invalid_image', __( 'Invalid image type.', 'userswp' ) ); } // If is current user's profile (profile.php) if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) { $user_id = get_current_user_id(); // If is another user's profile page } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) { $user_id = absint( $_GET['user_id'] ); // Otherwise something is wrong. } else { $user_id = get_current_user_id(); } // Retrieve current thumbnail. $current_field = 'avatar' === $type ? 'avatar_thumb' : 'banner_thumb'; $current_thumbnail = $this->normalize_url( uwp_get_usermeta( $user_id, $current_field, '' ) ); $thumb_postfix = '_uwp_' . $type . '_thumb'; if ( $image_url ) { if ( $type == 'avatar' ) { $avatar_size = uwp_get_upload_image_size(); $full_width = $avatar_size['width']; } else { $banner_size = uwp_get_upload_image_size( 'banner' ); $full_width = $banner_size['width']; } add_filter( 'upload_dir', 'uwp_handle_multisite_profile_image', 10, 1 ); $uploads = wp_upload_dir(); remove_filter( 'upload_dir', 'uwp_handle_multisite_profile_image' ); $upload_url = $uploads['baseurl']; $upload_path = $uploads['basedir']; $image_path = str_replace( $upload_url, $upload_path, $image_url ); $ext = $filetype['ext']; // to get extension $name = sanitize_file_name( pathinfo( $image_path, PATHINFO_FILENAME ) ); //file name without extension $thumb_image_name = $name . $thumb_postfix . '.' . $ext; $thumb_image_location = str_replace( $name . '.' . $ext, $thumb_image_name, $image_path ); //Get the new coordinates to crop the image. $x = $data['uwpx']; $y = $data['uwpy']; $w = $data['uwpw']; $h = $data['uwph']; //Scale the image based on cropped width setting $scale = $full_width / $w; //$scale = 1; // no scaling // check we are not editing another user file $db_value = trailingslashit( $uploads['subdir'] ) . $thumb_image_name; $meta_table = get_usermeta_table_prefix() . 'uwp_usermeta'; $file_exists = $wpdb->get_var( $wpdb->prepare( "SELECT user_id FROM {$meta_table} WHERE ( `avatar_thumb` = %s OR `banner_thumb` = %s ) ", $db_value, $db_value ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching // if file already exists then we should not be cropping it. if ( $file_exists ) { wp_die( esc_html__( 'Something went wrong. Please contact site admin.', 'userswp' ), 403 ); } $cropped = uwp_resizeThumbnailImage( $thumb_image_location, $image_path, $x, $y, $w, $h, $scale ); // Resize returns a path even on failure; bail before touching meta or files so the crop can be retried. clearstatcache( true, $thumb_image_location ); if ( ! is_file( $thumb_image_location ) ) { return new WP_Error( 'crop_failed', __( 'Could not crop the image. Please try again.', 'userswp' ) ); } $cropped = str_replace( $upload_path, $upload_url, $cropped ); // Remove previous avatar/banner $unlink_img = ''; if ( $unlink_prev_img && $current_thumbnail ) { $unlink_img = untrailingslashit( $upload_path ) . '/' . ltrim( $current_thumbnail, '/' ); } // remove the uploads path for easy migrations $cropped = str_replace( $upload_url, '', $cropped ); if ( $type == 'avatar' ) { uwp_update_usermeta( $user_id, 'avatar_thumb', $cropped ); } else { uwp_update_usermeta( $user_id, 'banner_thumb', $cropped ); } $original_key = '_uwp_' . $type . '_original'; $prev_original = get_user_meta( $user_id, $original_key, true ); delete_user_meta( get_current_user_id(), $pending_key ); $relative_original = ltrim( wp_normalize_path( str_replace( wp_normalize_path( untrailingslashit( $upload_path ) ), '', wp_normalize_path( $image_path ) ) ), '/' ); update_user_meta( $user_id, $original_key, $relative_original ); // Enforce containment inside uploads before deleting, matching upload_file_remove(). $real_upload_path = realpath( $upload_path ); $real_unlink_img = $unlink_img ? realpath( $unlink_img ) : false; if ( $real_upload_path && $real_unlink_img && realpath( $thumb_image_location ) !== $real_unlink_img && false !== strpos( basename( $real_unlink_img ), $thumb_postfix . '.' ) && 0 === strpos( $real_unlink_img, $real_upload_path . DIRECTORY_SEPARATOR ) && is_file( $real_unlink_img ) ) { wp_delete_file( $real_unlink_img ); // Delete the previous source only if it is the exact file this user cropped. $unlink_ori_img = str_replace( $thumb_postfix . '.', '.', $real_unlink_img ); $real_unlink_ori_img = realpath( $unlink_ori_img ); $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false; if ( $expected_original && $real_unlink_ori_img && $expected_original === $real_unlink_ori_img && realpath( $image_path ) !== $real_unlink_ori_img && 0 === strpos( $real_unlink_ori_img, $real_upload_path . DIRECTORY_SEPARATOR ) && is_file( $real_unlink_ori_img ) ) { wp_delete_file( $real_unlink_ori_img ); } } } if ( is_admin() ) { if ( $user_id == get_current_user_id() ) { $redirect_url = admin_url( 'profile.php' ); } else { $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id ); } } elseif ( uwp_current_page_url() ) { $redirect_url = uwp_current_page_url(); } else { $redirect_url = uwp_build_profile_tab_url( $user_id ); } return $redirect_url; } /** * Normalizes a URL. * */ public function normalize_url( $url ) { if ( empty( $url ) ) { return ''; } // Normalize. $url = wp_normalize_path( $url ); // Remove query vars. $url = strtok( $url, '?' ); // Split. $url = explode( '/', $url ); // Clean. $url = array_diff( $url, array( '..', '.' ) ); // Rejoin and return. return implode( '/', $url ); } /** * Processes avatar and banner image reset. * * @param string $type Image type. Default 'avatar'. * * @return bool|WP_Error|string Profile url. * @package userswp * */ public function process_image_reset( $type ) { if ( ! is_user_logged_in() ) { return false; } if ( is_admin() && defined( 'IS_PROFILE_PAGE' ) && IS_PROFILE_PAGE ) { $user_id = get_current_user_id(); } elseif ( is_admin() && current_user_can( 'manage_options' ) && ! empty( $_GET['user_id'] ) && is_numeric( $_GET['user_id'] ) ) { $user_id = absint( $_GET['user_id'] ); } else { $user_id = get_current_user_id(); } if ( empty( $_POST['uwp_reset_nonce'] ) || ! wp_verify_nonce( $_POST['uwp_reset_nonce'], 'uwp_reset_nonce_' . $type . '_' . $user_id ) ) { return; } $errors = new WP_Error(); if ( empty( $user_id ) ) { $errors->add( 'something_wrong', __( 'Something went wrong. Please try again.', 'userswp' ) ); } $error_code = $errors->get_error_code(); if ( ! empty( $error_code ) ) { return $errors; } if ( $type == 'avatar' ) { uwp_update_usermeta( $user_id, 'avatar_thumb', '' ); } elseif ( $type == 'banner' ) { uwp_update_usermeta( $user_id, 'banner_thumb', '' ); } else { // Do nothing } if ( in_array( $type, array( 'avatar', 'banner' ), true ) ) { delete_user_meta( $user_id, '_uwp_' . $type . '_original' ); delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' ); } if ( is_admin() ) { if ( $user_id == get_current_user_id() ) { $redirect_url = admin_url( 'profile.php' ); } else { $redirect_url = admin_url( 'user-edit.php?user_id=' . $user_id ); } } elseif ( uwp_current_page_url() ) { $redirect_url = uwp_current_page_url(); } else { $redirect_url = uwp_build_profile_tab_url( $user_id ); } return $redirect_url; } /** * Displays links in a dropdown * * @param $options * * @package userswp * * @since 1.0.0 */ public function output_dashboard_links( $options ) { if ( ! empty( $options ) ) { $class = uwp_get_option( 'design_style', 'bootstrap' ) == 'bootstrap' ? 'form-control' : 'aui-select2'; echo ''; } } /** * Displays options for the dashboard links * * @param $options * * @package userswp * * @since 1.0.0 */ public function output_options( $options ) { if ( ! empty( $options ) ) { foreach ( $options as $key => $link ) { if ( ! isset( $link['text'] ) && isset( $link[0] ) && is_array( $link[0] ) ) { $this->output_options( $link ); } elseif ( ! empty( $link['optgroup'] ) && $link['optgroup'] == 'open' ) { echo "'; } elseif ( ! empty( $link['text'] ) ) { echo ''; } } } } /** * Displays UsersWP notices in forms. * * @param string $type Form type * * @return void * @since 1.0.0 * @package userswp * */ public function display_notices( $type ) { global $uwp_notices; if ( is_array( $uwp_notices ) ) { foreach ( $uwp_notices as $notice ) { // If the notification is type specific then only output on that type if ( is_array( $notice ) ) { foreach ( $notice as $key => $val ) { if ( $key == $type ) { echo wp_kses_post( $val ); } } } elseif ( ! empty( $notice ) ) { echo wp_kses_post( $notice ); } } } if ( $type == 'change' ) { $user_id = get_current_user_id(); $password_nag = get_user_option( 'default_password_nag', $user_id ); if ( $password_nag ) { $change_page = uwp_get_page_id( 'change_page', false ); $remove_nag_url = add_query_arg( 'uwp_remove_nag', 'yes', get_permalink( $change_page ) ); if ( isset( $_GET['uwp_remove_nag'] ) && $_GET['uwp_remove_nag'] == 'yes' ) { delete_user_meta( $user_id, 'default_password_nag' ); $message = sprintf( __( 'We have removed the system generated password warning for you. From this point forward you can continue to access our site as usual. To go to home page, click here.', 'userswp' ), home_url( '/' ) ); echo aui()->alert( array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 'class' => 'text-center', 'type' => 'success', 'content' => wp_kses_post( $message ), ) ); } else { $message = sprintf( __( 'Warning: It seems like you are using a system generated password. Please change the password in this page. If this is not a problem for you, you can remove this warning by clicking here.', 'userswp' ), $remove_nag_url ); echo aui()->alert( array( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 'class' => 'text-center', 'type' => 'warning', 'content' => wp_kses_post( $message ), ) ); } } } } /** * Processes register form submission. * * @since 1.0.0 * @package userswp * */ public function process_register() { $data = $_POST; if ( ! isset( $data['uwp_register_nonce'] ) ) { return; } global $uwp_notices; if ( isset( $data['uwp_register_hp'] ) && '' != $data['uwp_register_hp'] ) { wp_die( esc_html__( 'No spam please!', 'userswp' ) ); } $form_id = 1; if ( ! empty( $data['uwp_register_form_id'] ) ) { $form_id = (int) $data['uwp_register_form_id']; } if ( ! isset( $data['uwp_register_nonce'] ) || ! wp_verify_nonce( $data['uwp_register_nonce'], 'uwp-register-nonce-' . $form_id ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Security verification failed. Try again.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } $hash = substr( hash( 'SHA256', AUTH_KEY . site_url() ), 0, 25 ); if ( empty( $data['uwp_register_hash'] ) || $hash != $data['uwp_register_hash'] ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Security hash failed. Try again.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } if ( ! get_option( 'users_can_register' ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'User registration is currently not allowed. Please check settings of your site.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } $files = $_FILES; $errors = new WP_Error(); $file_obj = new UsersWP_Files(); do_action( 'uwp_before_validate', 'register' ); $result = uwp_validate_fields( $data, 'register' ); $result = apply_filters( 'uwp_validate_result', $result, 'register', $data ); if ( is_wp_error( $result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } $uploads_result = $file_obj->validate_uploads( $files, 'register' ); if ( is_wp_error( $uploads_result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $uploads_result->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } do_action( 'uwp_after_validate', $result, 'register', $data ); $result = array_merge( $result, $uploads_result ); if ( isset( $result['password'] ) && ! empty( $result['password'] ) ) { $password = $result['password']; $generated_password = false; } else { $password = wp_generate_password(); $this->generated_password = $password; $generated_password = true; } $first_name = ''; if ( isset( $result['first_name'] ) && ! empty( $result['first_name'] ) ) { $first_name = $result['first_name']; } $last_name = ''; if ( isset( $result['last_name'] ) && ! empty( $result['last_name'] ) ) { $last_name = $result['last_name']; } if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) { $display_name = $result['display_name']; } elseif ( ! empty( $first_name ) || ! empty( $last_name ) ) { $display_name = $first_name . ' ' . $last_name; } else { $display_name = ! empty( $result['username'] ) ? $result['username'] : ''; } $user_url = ''; if ( isset( $result['user_url'] ) && ! empty( $result['user_url'] ) ) { $user_url = esc_url_raw( $result['user_url'] ); } $user_login = ! empty( $result['username'] ) ? $result['username'] : ''; $email = ! empty( $result['email'] ) ? sanitize_email( $result['email'] ) : ''; if ( empty( $user_login ) ) { $user_login = sanitize_user( str_replace( ' ', '', $display_name ), true ); if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) { $new_user_login = strstr( $email, '@', true ); if ( validate_username( $user_login ) && username_exists( $user_login ) ) { $user_login = sanitize_user( $new_user_login, true ); } if ( validate_username( $user_login ) && username_exists( $user_login ) ) { $user_append_text = rand( 10, 1000 ); $user_login = sanitize_user( $new_user_login . $user_append_text, true ); } if ( ! ( validate_username( $user_login ) && ! username_exists( $user_login ) ) ) { $user_login = $email; } } } elseif ( ! validate_username( $user_login ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Sorry, that username is not allowed.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } $args = array( 'user_login' => sanitize_user( $user_login ), 'user_email' => sanitize_email( $email ), 'user_pass' => $password, 'display_name' => sanitize_text_field( $display_name ), 'first_name' => esc_attr( $first_name ), 'last_name' => esc_attr( $last_name ), 'user_url' => esc_url_raw( $user_url ), ); // Set user role by form. $user_role = uwp_get_register_form_by( $form_id, 'user_role' ); if ( ! empty( $user_role ) ) { $user_roles = uwp_get_user_roles(); $chosen_role = strtolower( $user_role ); if ( ! empty( $user_roles ) ) { $wp_roles = wp_roles(); if ( $wp_roles->is_role( $chosen_role ) && in_array( $chosen_role, array_keys( $user_roles ) ) ) { $args['role'] = $chosen_role; } } } $user_id = wp_insert_user( $args ); if ( is_wp_error( $user_id ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $user_id->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } $result = apply_filters( 'uwp_before_extra_fields_save', $result, 'register', $user_id ); // Save user form id. if ( ! empty( $data['uwp_register_form_id'] ) ) { update_user_meta( $user_id, '_uwp_register_form_id', (int) $data['uwp_register_form_id'] ); } $save_result = $this->save_user_extra_fields( $user_id, $result, 'register' ); $save_result = apply_filters( 'uwp_after_extra_fields_save', $save_result, $result, 'register', $user_id ); if ( is_wp_error( $save_result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $save_result->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } if ( ! $save_result ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } //updating bio field after saving extra fields to reflect the points in mycred add on. if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) { $args = array( 'ID' => $user_id, 'description' => $result['bio'], ); wp_update_user( $args ); } do_action( 'uwp_after_custom_fields_save', 'register', $data, $result, $user_id ); // Unset post data to empty the form on submit $excluded_post_data = apply_filters( 'uwp_register_excluded_post_reset_fields', array( 'uwp_register_nonce' ) ); foreach ( $data as $key => $value ) { if ( isset( $key ) && ! in_array( $key, $excluded_post_data ) ) { unset( $_POST[ $key ] ); } } $reg_action = uwp_get_register_form_by( $form_id, 'reg_action' ); if ( ! $reg_action ) { $reg_action = uwp_get_option( 'uwp_registration_action', false ); } $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'register', $user_id ); if ( $reg_action == 'require_email_activation' && ! $generated_password ) { $user_data = get_userdata( $user_id ); $activation_link = uwp_get_activation_link( $user_id ); $message = __( 'To activate your account, visit the following address:', 'userswp' ) . "\r\n\r\n"; $message .= "" . esc_url_raw( $activation_link ) . '' . "\r\n"; $activate_message = '
' . __( 'Please activate your account :', 'userswp' ) . '
' . $message . '
'; $activate_message = apply_filters( 'uwp_activation_mail_message', $activate_message, $user_id ); $email_vars = array( 'user_id' => $user_id, 'login_details' => $activate_message, 'activation_link' => $activation_link, ); UsersWP_Mails::send( $user_data->user_email, 'registration_activate', $email_vars ); } elseif ( $reg_action != 'require_admin_review' ) { $user_data = get_userdata( $user_id ); if ( isset( $this->generated_password ) && ! empty( $this->generated_password ) ) { if ( ! uwp_get_option( 'change_disable_password_nag' ) ) { update_user_meta( $user_id, 'default_password_nag', true ); //Set up the Password change nag. } $message_pass = $this->generated_password; $this->generated_password = false; } else { $message_pass = __( 'Password you entered during registration.', 'userswp' ); } $message = '' . __( 'Your login Information :', 'userswp' ) . '
' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '
' . __( 'Password:', 'userswp' ) . ' ' . $message_pass . '
'; $message = apply_filters( 'uwp_register_mail_message', $message, $user_id, $this->generated_password ); $email_vars = array( 'user_id' => $user_id, 'login_details' => $message, 'form_fields' => $form_fields, ); UsersWP_Mails::send( $user_data->user_email, 'registration_success', $email_vars ); } $error_code = $errors->get_error_code(); if ( ! empty( $error_code ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); return; } } if ( $reg_action != 'require_admin_review' ) { $user_data = get_userdata( $user_id ); $extras = '' . __( 'User Information :', 'userswp' ) . '
' . __( 'First Name:', 'userswp' ) . ' ' . $user_data->first_name . '
' . __( 'Last Name:', 'userswp' ) . ' ' . $user_data->last_name . '
' . __( 'Username:', 'userswp' ) . ' ' . $user_data->user_login . '
' . __( 'Email:', 'userswp' ) . ' ' . $user_data->user_email . '
'; $extras = apply_filters( 'uwp_admin_mail_extras', $extras, 'register_admin', $user_id ); $email_vars = array( 'user_id' => $user_id, 'extras' => $extras, 'form_fields' => $form_fields, ); UsersWP_Mails::send( get_option( 'admin_email' ), 'registration_success', $email_vars, true ); } if ( $reg_action == 'auto_approve_login' ) { $res = wp_signon( array( 'user_login' => $user_login, 'user_password' => $password, 'remember' => false, ) ); if ( is_wp_error( $res ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $res->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); } } else { $redirect_to = $this->get_register_redirect_url( $data, $user_id ); do_action( 'uwp_after_process_register', $result, $user_id ); if ( wp_doing_ajax() ) { $message = aui()->alert( array( 'type' => 'success', 'content' => __( 'Account registered successfully. Redirecting...', 'userswp' ), ) ); $response = array( 'message' => $message, 'redirect' => $redirect_to, ); wp_send_json_success( $response ); } else { wp_safe_redirect( $redirect_to ); } exit(); } } else { if ( $reg_action == 'require_email_activation' ) { $resend_link = uwp_get_register_page_url(); $resend_link = add_query_arg( array( 'user_id' => $user_id, 'action' => 'uwp_resend', '_nonce' => wp_create_nonce( 'uwp_resend' ), ), $resend_link ); $message = aui()->alert( array( 'type' => 'success', 'content' => sprintf( __( 'An email has been sent to your registered email address. Please click the activation link to proceed. Resend.', 'userswp' ), $resend_link ), ) ); } elseif ( $reg_action == 'require_admin_review' && defined( 'UWP_MOD_VERSION' ) ) { update_user_meta( $user_id, 'uwp_mod', '1' ); do_action( 'uwp_require_admin_review', $user_id, $result ); $message = aui()->alert( array( 'type' => 'success', 'content' => __( 'Your account is under moderation. We will email you once its approved.', 'userswp' ), ) ); } else { $login_page_url = wp_login_url(); if ( $generated_password ) { $msg = sprintf( __( 'Account registered successfully. A password has been generated and mailed to your registered Email ID. Please login %1$shere%2$s.', 'userswp' ), '', '' ); } else { $msg = sprintf( __( 'Account registered successfully. Please login %1$shere%2$s', 'userswp' ), '', '' ); } $message = aui()->alert( array( 'type' => 'success', 'content' => $msg, ) ); } do_action( 'uwp_after_process_register', $result, $user_id ); if ( wp_doing_ajax() ) { wp_send_json_success( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'register' => $message ); } } if ( wp_doing_ajax() ) { wp_send_json_error(); } // if we got this far there is a problem } /** * Saves UsersWP related user custom fields. * * @param int $user_id User ID. * @param array $data Result array. * @param string $type Form type. * * @return bool True when success. False when failure. * @since 1.0.0 * @package userswp * */ public function save_user_extra_fields( $user_id, $data, $type ) { if ( empty( $user_id ) || empty( $data ) || empty( $type ) ) { return false; } // custom user fields not applicable for login and forgot if ( $type == 'login' || $type == 'forgot' ) { return true; } if ( $type == 'account' || $type == 'register' ) { if ( isset( $data['password'] ) ) { unset( $data['password'] ); } } if ( $type == 'register' ) { if ( isset( $data['username'] ) ) { unset( $data['username'] ); } if ( isset( $data['email'] ) ) { unset( $data['email'] ); } } if ( empty( $data ) ) { // no extra fields. so just return return true; } else { foreach ( $data as $key => $value ) { if ( 'uwp_language' == $key ) { update_user_meta( $user_id, 'locale', $value ); } uwp_update_usermeta( $user_id, $key, $value ); } return true; } } public function get_register_redirect_url( $data, $user ) { if ( is_int( $user ) ) { $user = get_userdata( $user ); } $redirect_page_id = $custom_url = ''; if ( isset( $data['uwp_register_form_id'] ) && ! empty( $data['uwp_register_form_id'] ) ) { $form_id = (int) $data['uwp_register_form_id']; $redirect_page_id = uwp_get_register_form_by( $form_id, 'redirect_to' ); $custom_url = uwp_get_register_form_by( $form_id, 'custom_url' ); } if ( ! $redirect_page_id ) { $redirect_page_id = uwp_get_option( 'register_redirect_to', '' ); $custom_url = uwp_get_option( 'register_redirect_custom_url' ); } if ( isset( $_REQUEST['redirect_to'] ) && ! empty( $_REQUEST['redirect_to'] ) ) { $redirect_to = esc_url_raw( $_REQUEST['redirect_to'] ); } elseif ( isset( $data['redirect_to'] ) && ! empty( $data['redirect_to'] ) ) { $redirect_to = esc_url_raw( $data['redirect_to'] ); } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id > 0 ) { if ( uwp_is_wpml() ) { $wpml_page_id = uwp_wpml_object_id( $redirect_page_id, 'page', true, ICL_LANGUAGE_CODE ); if ( ! empty( $wpml_page_id ) ) { $redirect_page_id = $wpml_page_id; } } $redirect_to = get_permalink( $redirect_page_id ); } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 1 && wp_get_referer() ) { $redirect_to = esc_url( wp_get_referer() ); } elseif ( isset( $redirect_page_id ) && (int) $redirect_page_id == - 2 && $custom_url ) { $redirect_to = $custom_url; } else { if ( $user && $user->has_cap( 'manage_options' ) ) { $redirect_to = admin_url(); } else { $redirect_to = home_url( '/' ); } $redirect_to = apply_filters( 'registration_redirect', $redirect_to ); } return apply_filters( 'uwp_register_redirect', $redirect_to, $redirect_page_id, $data ); } /** * Processes login form submission. * * @since 1.0.0 * @package userswp * */ public function process_login() { $data = $_POST; if ( ! isset( $data['uwp_login_nonce'] ) ) { return; } if ( ! isset( $data['uwp_login_nonce'] ) || ! wp_verify_nonce( $data['uwp_login_nonce'], 'uwp-login-nonce' ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Security verification failed. Try again.', 'userswp' ), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { return; } } global $uwp_notices; do_action( 'uwp_before_validate', 'login' ); $result = uwp_validate_fields( $data, 'login' ); $result = apply_filters( 'uwp_validate_result', $result, 'login', $data ); if ( is_wp_error( $result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'login' => $message ); return; } } do_action( 'uwp_after_validate', $result, 'login', $data ); if ( isset( $data['remember_me'] ) && $data['remember_me'] == 'forever' ) { $remember_me = true; } else { $remember_me = false; } remove_action( 'authenticate', 'gglcptch_login_check', 21 ); global $wp2fa; if ( wp_doing_ajax() && isset( $wp2fa ) && ! empty( $wp2fa ) ) { remove_action( 'wp_login', array( $wp2fa->login, 'wp_login' ), 20 ); } if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) { remove_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20 ); } $user = wp_signon( array( 'user_login' => $result['username'], 'user_password' => $result['password'], 'remember' => $remember_me, ) ); add_action( 'authenticate', 'gglcptch_login_check', 21, 1 ); if ( wp_doing_ajax() && class_exists( '\WP2FA\Authenticator\Login' ) ) { add_action( 'wp_login', array( 'WP2FA\Authenticator\Login', 'wp_login' ), 20, 2 ); } $wp2fa_available = ( isset( $wp2fa ) && ! empty( $wp2fa ) ) || class_exists( '\WP2FA\Authenticator\Login' ); if ( wp_doing_ajax() && ! is_wp_error( $user ) && $wp2fa_available ) { $two_fa = $this->check_2fa( $user ); if ( isset( $two_fa ) && ! empty( $two_fa ) ) { if ( is_wp_error( $two_fa ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $two_fa->get_error_message(), ) ); wp_send_json_error( array( 'message' => $message ) ); } else { wp_send_json_success( array( 'html' => $two_fa, 'is_2fa' => true, ) ); } } } if ( wp_doing_ajax() && is_wp_error( $user ) && $this->wordfence_2fa_available() ) { $wfls_2fa = $this->check_wordfence_2fa( $user, $result ); if ( ! empty( $wfls_2fa ) ) { wp_send_json_success( array( 'html' => $wfls_2fa, 'is_2fa' => true, ) ); } } if ( is_wp_error( $user ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $user->get_error_message(), ) ); if ( wp_doing_ajax() ) { wp_send_json_error( array( 'message' => $message ) ); } else { $uwp_notices[] = array( 'login' => $message ); return; } } else { do_action( 'uwp_after_process_login', $data ); $message = aui()->alert( array( 'type' => 'success', 'content' => __( 'Login successful. Redirecting...', 'userswp' ), ) ); if ( wp_doing_ajax() ) { $redirect_to = ''; if ( 1 == uwp_get_option( 'login_modal_enable_redirect' ) ) { $redirect_to = $this->get_login_redirect_url( $data, $user ); } wp_send_json_success( array( 'message' => $message, 'redirect' => $redirect_to, ) ); } else { $redirect_to = $this->get_login_redirect_url( $data, $user ); wp_safe_redirect( $redirect_to ); exit(); } } } public function check_2fa( $user ) { if ( 1 == uwp_get_option( 'disable_wp_2fa' ) ) { return; } if ( ! $user ) { $user = wp_get_current_user(); } global $wp2fa; $errors = new WP_Error(); if ( ! \WP2FA\Admin\Helpers\User_Helper::is_user_using_two_factor( $user->ID ) ) { return; } // Invalidate the current login session to prevent from being re-used. \WP2FA\Authenticator\Login::destroy_current_session_for_user( $user ); // Also clear the cookies which are no longer valid. wp_clear_auth_cookie(); $login_nonce = \WP2FA\Authenticator\Login::create_login_nonce( $user->ID ); if ( ! $login_nonce ) { $errors->add( 'failed_login_nonce', __( 'Failed to create a login nonce.', 'userswp' ) ); return $errors; } $provider = $this->get_wp2fa_provider_for_user( $user ); if ( empty( $provider ) ) { return; } ob_start(); ?>' . __( 'Your login Information :', 'userswp' ) . '
'; $message .= '' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '
'; $message .= '' . sprintf( __( 'Password: %s', 'userswp' ), $new_pass ) . '
'; } else { // Use WordPress core to generate, hash (wp_fast_hash in WP 6.8+), and store the reset key. // This ensures compatibility with check_password_reset_key() on all WP versions. $key = get_password_reset_key( $user_data ); if ( is_wp_error( $key ) ) { if ( wp_doing_ajax() ) { wp_send_json_error( $key->get_error_message() ); } else { $uwp_notices[] = array( 'forgot' => aui()->alert( array( 'type' => 'error', 'content' => $key->get_error_message() ) ) ); return; } } $message = '' . __( 'You have requested to reset your password for the following account:', 'userswp' ) . '
'; $message .= home_url( '/' ) . ''; $message .= '' . sprintf( __( 'Username: %s', 'userswp' ), $user_data->user_login ) . '
'; $message .= '' . __( 'If this was by mistake, just ignore this email and nothing will happen.', 'userswp' ) . '
'; $message .= '' . __( 'To reset your password, click the following link and follow the instructions.', 'userswp' ) . '
'; $reset_page = uwp_get_page_id( 'reset_page', false ); if ( $reset_page ) { $reset_link = add_query_arg( array( 'key' => $key, 'login' => rawurlencode( $user_data->user_login ), ), get_permalink( $reset_page ) ); $message .= "" . $reset_link . '' . "\r\n"; } else { $reset_link = home_url( "reset?key=$key&login=" . rawurlencode( $user_data->user_login ), 'login' ); $message .= "" . $reset_link . '' . "\r\n"; } $message = apply_filters( 'uwp_forgot_password_message', $message, $user_data, $reset_link ); } $message = apply_filters( 'uwp_forgot_mail_message', $message, $user_data->ID ); $email_vars = array( 'user_id' => $user_data->ID, 'login_details' => $message, 'reset_link' => $reset_link, ); UsersWP_Mails::send( $user_data->user_email, 'forgot_password', $email_vars ); do_action( 'uwp_after_process_forgot', $data ); $message = aui()->alert( array( 'type' => 'success', 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Please check your email.', 'userswp' ), $data ), ) ); if ( wp_doing_ajax() ) { wp_send_json_success( $message ); } else { $uwp_notices[] = array( 'forgot' => $message ); } } /** * Processes change password form submission. * * @since 1.0.0 * @package userswp * */ public function process_change() { $data = $_POST; if ( ! isset( $data['uwp_change_nonce'] ) || ! wp_verify_nonce( $data['uwp_change_nonce'], 'uwp-change-nonce' ) ) { return; } global $uwp_notices; if ( is_uwp_account_page() ) { $notice_type = 'account'; } else { $notice_type = 'change'; } do_action( 'uwp_before_validate', 'change' ); $result = uwp_validate_fields( $data, 'change' ); $result = apply_filters( 'uwp_validate_result', $result, 'change', $data ); if ( is_wp_error( $result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); $uwp_notices[] = array( $notice_type => $message ); return; } do_action( 'uwp_after_validate', $result, 'change', $data ); $user_data = get_user_by( 'id', get_current_user_id() ); if ( ! $user_data ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $user_data->get_error_message(), ) ); $uwp_notices[] = array( $notice_type => $message ); return; } $email_vars = array( 'user_id' => $user_data->ID, ); UsersWP_Mails::send( $user_data->user_email, 'change_password', $email_vars ); wp_set_password( $result['password'], $user_data->ID ); $password_nag = get_user_option( 'default_password_nag', $user_data->ID ); if ( $password_nag ) { delete_user_meta( $user_data->ID, 'default_password_nag' ); } delete_user_meta( $user_data->ID, 'is_uwp_social_login_no_password' ); $message = aui()->alert( array( 'type' => 'success', 'content' => apply_filters( 'uwp_change_password_success_message', __( 'Password changed successfully.', 'userswp' ), $data ), ) ); $uwp_notices[] = array( $notice_type => $message ); do_action( 'uwp_after_process_change', $data ); wp_logout(); exit(); } /** * Processes reset password form submission. * * @since 1.0.0 * @package userswp * */ public function process_reset() { $data = $_POST; if ( isset( $data['uwp_reset_hp'] ) && '' != $data['uwp_reset_hp'] ) { wp_die( esc_html__( 'No spam please!', 'userswp' ) ); } if ( ! isset( $data['uwp_reset_nonce'] ) || ! wp_verify_nonce( $data['uwp_reset_nonce'], 'uwp-reset-nonce' ) ) { return; } global $uwp_notices; do_action( 'uwp_before_validate', 'reset' ); $result = uwp_validate_fields( $data, 'reset' ); $result = apply_filters( 'uwp_validate_result', $result, 'reset', $data ); if ( is_wp_error( $result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); $uwp_notices[] = array( 'reset' => $message ); return; } do_action( 'uwp_after_validate', $result, 'reset', $data ); $login = sanitize_text_field( $data['uwp_reset_username'] ); $key = sanitize_text_field( $data['uwp_reset_key'] ); $user = get_user_by( 'login', $login ); if ( ! $user ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid username.', 'userswp' ), ) ); $uwp_notices[] = array( 'reset' => $message ); return; } clean_user_cache( $user ); $user_data = check_password_reset_key( $key, $login ); if ( is_wp_error( $user_data ) ) { $error = apply_filters( 'uwp_reset_password_error_message', $user_data->get_error_message(), $user_data ); $message = aui()->alert( array( 'type' => 'error', 'content' => $error, ) ); $uwp_notices[] = array( 'reset' => $message ); return; } $email_vars = array( 'user_id' => $user_data->ID, ); UsersWP_Mails::send( $user_data->user_email, 'reset_password', $email_vars ); wp_set_password( $data['password'], $user_data->ID ); $login_page_url = uwp_get_login_page_url(); $message = sprintf( __( 'Password updated successfully. Please login with your new password.', 'userswp' ), $login_page_url ); $message = apply_filters( 'uwp_reset_password_success_message', $message, $data ); $message = aui()->alert( array( 'type' => 'success', 'content' => $message, ) ); $uwp_notices[] = array( 'reset' => $message ); do_action( 'uwp_after_process_reset', $data ); } /** * Processes account form submission. * * @since 1.0.0 * @package userswp * */ public function process_account() { $data = wp_unslash( $_POST ); $files = $_FILES; if ( ! isset( $data['uwp_account_nonce'] ) || ! wp_verify_nonce( $data['uwp_account_nonce'], 'uwp-account-nonce' ) ) { return; } if ( ! is_user_logged_in() ) { return; } global $uwp_notices; $file_obj = new UsersWP_Files(); do_action( 'uwp_before_validate', 'account' ); $result = uwp_validate_fields( $data, 'account' ); $result = apply_filters( 'uwp_validate_result', $result, 'account', $data ); if ( is_wp_error( $result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $result->get_error_message(), ) ); $uwp_notices[] = array( 'account' => $message ); return; } $uploads_result = $file_obj->validate_uploads( $files, 'account' ); if ( is_wp_error( $uploads_result ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => $uploads_result->get_error_message(), ) ); $uwp_notices[] = array( 'account' => $message ); return; } do_action( 'uwp_after_validate', $result, 'account', $data ); //unset if value is empty for files foreach ( $uploads_result as $upload_file_key => $upload_file_value ) { if ( empty( $upload_file_value ) ) { unset( $uploads_result[ $upload_file_key ] ); } } global $wpdb; $file_field_names = $wpdb->get_col( $wpdb->prepare( "SELECT htmlvar_name FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE form_type = %s AND field_type IN ('file','image')", 'account' ) ); foreach ( $file_field_names as $file_field_name ) { if ( isset( $result[ $file_field_name ] ) && ! isset( $uploads_result[ $file_field_name ] ) ) { unset( $result[ $file_field_name ] ); } } $result = array_merge( $result, $uploads_result ); $args = array( 'ID' => get_current_user_id(), ); if ( isset( $result['first_name'] ) && isset( $result['last_name'] ) ) { $args['display_name'] = $result['first_name'] . ' ' . $result['last_name']; } if ( isset( $result['first_name'] ) ) { $args['first_name'] = $result['first_name']; } if ( isset( $result['last_name'] ) ) { $args['last_name'] = $result['last_name']; } if ( isset( $result['user_url'] ) ) { $args['user_url'] = $result['user_url']; } if ( isset( $result['display_name'] ) && ! empty( $result['display_name'] ) ) { $args['display_name'] = $result['display_name']; } if ( isset( $result['password'] ) ) { $args['user_pass'] = $result['password']; } $user_id = wp_update_user( $args ); if ( is_wp_error( $user_id ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => sprintf( __( '%s', 'userswp' ), $user_id->get_error_message() ), ) ); $uwp_notices[] = array( 'account' => $message ); return; } $res = $this->save_user_extra_fields( $user_id, $result, 'account' ); if ( ! $res ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Something went wrong. Please contact site admin.', 'userswp' ), ) ); $uwp_notices[] = array( 'account' => $message ); return; } //updating bio field after saving extra fields to reflect the points in mycred add on. if ( isset( $result['bio'] ) && ! empty( $result['bio'] ) ) { $args = array( 'ID' => $user_id, 'description' => $result['bio'], ); wp_update_user( $args ); } $user_data = get_userdata( $user_id ); $form_fields = apply_filters( 'uwp_send_mail_form_fields', '', 'account', $user_id ); if ( isset( $result['email'] ) && $user_data->user_email !== trim( $result['email'] ) ) { if ( email_exists( trim( $result['email'] ) ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'This email is already registered, please choose another one.', 'userswp' ), ) ); $uwp_notices[] = array( 'account' => $message ); return; } $hash = md5( $result['email'] . time() . wp_rand() ); $new_admin_email = array( 'hash' => $hash, 'newemail' => $result['email'], ); update_user_meta( get_current_user_id(), 'uwp_update_email_hash', $new_admin_email ); $new_email_link = add_query_arg( array( 'uwp_new_email' => 'yes', 'key' => $hash, 'login' => $user_data->user_login, ), uwp_get_account_page_url() ); $email_vars = array( 'user_id' => $user_id, 'new_email' => $result['email'], 'new_email_link' => esc_url( $new_email_link ), ); UsersWP_Mails::send( $result['email'], 'account_new_email_activation', $email_vars ); $message = apply_filters( 'uwp_account_pending_new_email_activation_message', __( 'Account updated successfully. The new address will become active once you confirm via activation link sent to your new email.', 'userswp' ), $data ); $message = aui()->alert( array( 'type' => 'success', 'content' => $message, ) ); $uwp_notices[] = array( 'account' => $message ); } else { $email_vars = array( 'user_id' => $user_id, 'form_fields' => $form_fields, ); UsersWP_Mails::send( $user_data->user_email, 'account_update', $email_vars ); $message = apply_filters( 'uwp_account_update_success_message', __( 'Account updated successfully.', 'userswp' ), $data ); $message = aui()->alert( array( 'type' => 'success', 'content' => $message, ) ); $uwp_notices[] = array( 'account' => $message ); } do_action( 'uwp_after_process_account', $data, $user_id ); } /** * Modifies the forms field in email based on the form type. * * @param string $form_fields Form fields. * @param string $type Form type. * @param int $user_id User ID. * * @return string Modified mail field. * @package userswp * @subpackage userswp/includes * */ public function init_mail_form_fields( $form_fields, $type, $user_id ) { switch ( $type ) { case 'register': $form_id = get_user_meta( $user_id, '_uwp_register_form_id', true ); $fields = get_register_form_fields( $form_id ); $user_data = get_userdata( $user_id ); if ( ! empty( $fields ) && is_array( $fields ) ) { $form_fields = '' . __( 'User Information:', 'userswp' ) . '
'; $excluded = uwp_get_excluded_fields(); foreach ( $fields as $key => $field ) { if ( $field->is_active != '1' || in_array( $field->htmlvar_name, $excluded ) ) { continue; } if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) { $field_value = $user_data->user_email; } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) { $field_value = $user_data->user_login; } elseif ( $field->htmlvar_name == 'bio' ) { $field_value = get_user_meta( $user_id, 'description', true ); } else { $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name ); } if ( is_array( $field_value ) && count( $field_value ) > 0 ) { $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value ); } if ( isset( $field->site_title ) && ! empty( $field_value ) ) { $form_fields .= '' . __( wp_unslash( $field->site_title ), 'userswp' ) . ': ' . $field_value . '
'; } } } break; case 'account': $fields = get_account_form_fields(); $user_data = get_userdata( $user_id ); if ( ! empty( $fields ) && is_array( $fields ) ) { $form_fields = '' . __( 'User Information:', 'userswp' ) . '
'; foreach ( $fields as $key => $field ) { if ( $field->is_active != '1' ) { continue; } if ( $field->htmlvar_name == 'email' && isset( $user_data->user_email ) ) { $field_value = $user_data->user_email; } elseif ( $field->htmlvar_name == 'display_name' && isset( $user_data->user_login ) ) { $field_value = $user_data->user_login; } elseif ( $field->htmlvar_name == 'bio' ) { $field_value = get_user_meta( $user_id, 'description', true ); } else { $field_value = uwp_get_usermeta( $user_id, $field->htmlvar_name ); } if ( is_array( $field_value ) && count( $field_value ) > 0 ) { $field_value = uwp_maybe_serialize( $field->htmlvar_name, $field_value ); } if ( isset( $field->site_title ) && ! empty( $field_value ) ) { $form_fields .= '' . __( wp_unslash( $field->site_title ), 'userswp' ) . ': ' . $field_value . '
'; } } } break; } return apply_filters( 'uwp_mail_form_fields', $form_fields, $type, $user_id ); } /** * * * @return void * @since 1.0.12 Unlink file. * @package userswp * @since 1.0.0 */ public function upload_file_remove() { global $wpdb; check_ajax_referer( 'uwp_basic_nonce', 'security' ); // Check user logged in. if ( ! is_user_logged_in() ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Access denied!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } $user_id = ! empty( $_POST['uid'] ) ? absint( $_POST['uid'] ) : 0; $htmlvar = ! empty( $_POST['htmlvar'] ) ? sanitize_key( $_POST['htmlvar'] ) : ''; if ( empty( $user_id ) || empty( $htmlvar ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid data!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } // Validate the user / admin. if ( ! ( $user_id == (int) get_current_user_id() || current_user_can( 'manage_options' ) ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid access!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } if ( $htmlvar == 'banner_thumb' ) { $field_key = 'banner'; $type = 'banner'; } else if ( $htmlvar == 'avatar_thumb' ) { $field_key = 'avatar'; $type = 'avatar'; } else { $field_key = $htmlvar; $type = ''; } $field = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM " . uwp_get_table_prefix() . "uwp_form_fields WHERE htmlvar_name = %s LIMIT 1", $field_key ) ); // Check field exists. if ( empty( $field ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } // Validate field access. if ( ! empty( $field->for_admin_use ) && ! current_user_can( 'manage_options' ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'You are not allowed to perform this action!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } if ( ! in_array( $field->field_type, array( 'file', 'image' ) ) ) { $message = aui()->alert( array( 'type' => 'error', 'content' => __( 'Invalid field type!', 'userswp' ) ) ); wp_send_json_error( array( 'message' => $message ) ); } $value = uwp_get_usermeta( $user_id, $htmlvar ); uwp_update_usermeta( $user_id, $htmlvar, '' ); if ( $value && validate_file( $value ) === 0 ) { $uploads = wp_upload_dir(); $upload_path = $uploads['basedir']; if ( strpos( $value, 'http://' ) === 0 || strpos( $value, 'https://' ) === 0 ) { // Get the relative url. $value = uwp_get_file_relative_url( $value ); } $unlink_file = untrailingslashit( $upload_path ) . '/' . trim( $value, '/\\' ); // Canonicalize and enforce containment inside the uploads directory before deleting. $real_upload_path = realpath( $upload_path ); $real_unlink_file = realpath( $unlink_file ); if ( $real_upload_path && $real_unlink_file && is_file( $real_unlink_file ) && strpos( $real_unlink_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) { wp_delete_file( $real_unlink_file ); // For avatar/banner, also remove the original (non-thumb) file, only if it is the exact file this user cropped. if ( $type ) { $unlink_ori_file = str_replace( '_uwp_' . $type . '_thumb' . '.', '.', $real_unlink_file ); $real_unlink_ori_file = realpath( $unlink_ori_file ); $prev_original = get_user_meta( $user_id, '_uwp_' . $type . '_original', true ); $expected_original = $prev_original ? realpath( untrailingslashit( $upload_path ) . '/' . $prev_original ) : false; if ( $expected_original && $real_unlink_ori_file && $expected_original === $real_unlink_ori_file && $real_unlink_ori_file !== $real_unlink_file && is_file( $real_unlink_ori_file ) && strpos( $real_unlink_ori_file, $real_upload_path . DIRECTORY_SEPARATOR ) === 0 ) { wp_delete_file( $real_unlink_ori_file ); } } } } // Clear crop bookkeeping meta (pending upload is stored against the uploader). if ( $type ) { delete_user_meta( $user_id, '_uwp_' . $type . '_original' ); delete_user_meta( get_current_user_id(), '_uwp_pending_' . $type . '_upload' ); } wp_send_json_success(); wp_die(); } /** * Form field template for datepicker field type. * * @param string $html Form field html * @param object $field Field info. * @param string $value Form field default value. * @param string $form_type Form type * * @return string Modified form field html. * @package userswp * * @since 1.0.0 */ public function form_input_datepicker( $html, $field, $value, $form_type ) { // Check if there is a field specific filter. if ( has_filter( "uwp_form_input_html_datepicker_{$field->htmlvar_name}" ) ) { $html = apply_filters( "uwp_form_input_html_datepicker_{$field->htmlvar_name}", $html, $field, $value, $form_type ); } // If no html then we run the standard output. if ( empty( $html ) ) { $design_style = uwp_get_option( 'design_style', 'bootstrap' ); $bs_form_group = $design_style ? 'form-group mb-3' : ''; $bs_sr_only = $design_style ? 'sr-only' : ''; $bs_form_control = $design_style ? 'form-control' : ''; $extra_attributes = array(); $required_msg = ( ! empty( $field->is_required ) && $field->required_msg != '') ? __( stripslashes( $field->required_msg ), 'userswp' ) : ''; $validation_text = ! empty( $field->validation_msg ) ? __( stripslashes( $field->validation_msg ), 'userswp' ) : ''; ob_start(); // Start buffering; $extra_fields = unserialize( $field->extra_fields ); if ( $extra_fields['date_format'] == '' ) { $extra_fields['date_format'] = 'yy-mm-dd'; } $date_format = $extra_fields['date_format']; $jquery_date_format = $date_format; // check if we need to change the format or not $date_format_len = strlen( str_replace( ' ', '', $date_format ) ); if ( $date_format_len > 5 ) {// if greater then 5 then it's the old style format. $search = array( 'dd', 'd', 'DD', 'mm', 'm', 'MM', 'yy' ); //jQuery UI datepicker format $replace = array( 'd', 'j', 'l', 'm', 'n', 'F', 'Y' );//PHP date format $date_format = str_replace( $search, $replace, $date_format ); } else { $jquery_date_format = uwp_date_format_php_to_jqueryui( $jquery_date_format ); } if ( ! empty( $value ) && ! is_string( $value ) ) { $value = date( 'Y-m-d', $value ); } if ( $value == '0000-00-00' ) { $value = ''; }//if date not set, then mark it empty $value = uwp_date( $value, 'Y-m-d', $date_format ); $site_title = uwp_get_form_label( $field ); // bootstrap if ( $design_style ) { // flatpickr attributes $extra_attributes['data-alt-input'] = 'true'; $extra_attributes['data-alt-format'] = $date_format; $extra_attributes['data-date-format'] = 'Y-m-d'; if ( 'dob' == $field->htmlvar_name ) { $extra_attributes['data-max-date'] = 'today'; } $required = ! empty( $field->is_required ) ? ' *' : ''; echo aui()->input( // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped array( 'id' => esc_attr( $field->htmlvar_name ), 'name' => esc_attr( $field->htmlvar_name ), 'required' => ! empty( $field->is_required ) ? true : false, 'label' => wp_kses_post( $site_title . $required ), 'label_show' => true, 'label_type' => 'hidden', 'type' => 'datepicker', 'title' => esc_html( $site_title ), 'placeholder' => esc_attr( uwp_get_field_placeholder( $field ) ), 'class' => '', 'wrap_class' => isset( $field->css_class ) ? esc_attr( $field->css_class ) : '', 'value' => esc_attr( $value ), 'help_text' => wp_kses_post( uwp_get_field_description( $field ) ), 'validation_text' => $validation_text != '' ? esc_attr( $validation_text ) : esc_attr( $required_msg ), 'validation_pattern' => ! empty( $field->validation_pattern ) ? esc_attr( wp_unslash( $field->validation_pattern ) ) : '', 'extra_attributes' => $extra_attributes, // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ) ); } else { ?>