2006-06-08 04:22:16 +02:00
< ? php
2008-09-12 06:29:09 +02:00
/**
* WordPress User API
*
* @ package WordPress
*/
/**
* Authenticate user with remember capability .
*
* The credentials is an array that has 'user_login' , 'user_password' , and
* 'remember' indices . If the credentials is not given , then the log in form
* will be assumed and used if set .
*
* The various authentication cookies will be set by this function and will be
* set for a longer period depending on if the 'remember' credential is set to
* true .
*
* @ since 2.5 . 0
*
* @ param array $credentials Optional . User info in order to sign on .
* @ param bool $secure_cookie Optional . Whether to use secure cookie .
* @ return object Either WP_Error on failure , or WP_User on success .
*/
2008-06-11 19:25:55 +02:00
function wp_signon ( $credentials = '' , $secure_cookie = '' ) {
2008-01-22 20:35:19 +01:00
if ( empty ( $credentials ) ) {
if ( ! empty ( $_POST [ 'log' ]) )
$credentials [ 'user_login' ] = $_POST [ 'log' ];
if ( ! empty ( $_POST [ 'pwd' ]) )
$credentials [ 'user_password' ] = $_POST [ 'pwd' ];
if ( ! empty ( $_POST [ 'rememberme' ]) )
$credentials [ 'remember' ] = $_POST [ 'rememberme' ];
}
if ( ! empty ( $credentials [ 'remember' ]) )
$credentials [ 'remember' ] = true ;
else
$credentials [ 'remember' ] = false ;
2009-01-24 23:38:19 +01:00
// TODO do we deprecate the wp_authentication action?
2008-04-16 06:49:19 +02:00
do_action_ref_array ( 'wp_authenticate' , array ( & $credentials [ 'user_login' ], & $credentials [ 'user_password' ]));
2008-06-11 19:25:55 +02:00
if ( '' === $secure_cookie )
2010-03-19 22:15:00 +01:00
$secure_cookie = is_ssl ();
2008-08-09 07:36:14 +02:00
2011-01-06 05:08:23 +01:00
$secure_cookie = apply_filters ( 'secure_signon_cookie' , $secure_cookie , $credentials );
2009-01-24 23:38:19 +01:00
global $auth_secure_cookie ; // XXX ugly hack to pass this to wp_authenticate_cookie
$auth_secure_cookie = $secure_cookie ;
2008-01-22 20:35:19 +01:00
2009-01-24 23:38:19 +01:00
add_filter ( 'authenticate' , 'wp_authenticate_cookie' , 30 , 3 );
2008-06-11 19:25:55 +02:00
2009-01-24 23:38:19 +01:00
$user = wp_authenticate ( $credentials [ 'user_login' ], $credentials [ 'user_password' ]);
2008-01-22 20:35:19 +01:00
2009-01-29 22:30:16 +01:00
if ( is_wp_error ( $user ) ) {
if ( $user -> get_error_codes () == array ( 'empty_username' , 'empty_password' ) ) {
$user = new WP_Error ( '' , '' );
}
2009-01-24 23:38:19 +01:00
return $user ;
2009-01-29 22:30:16 +01:00
}
2009-01-24 23:38:19 +01:00
wp_set_auth_cookie ( $user -> ID , $credentials [ 'remember' ], $secure_cookie );
do_action ( 'wp_login' , $credentials [ 'user_login' ]);
return $user ;
}
/**
* Authenticate the user using the username and password .
*/
add_filter ( 'authenticate' , 'wp_authenticate_username_password' , 20 , 3 );
function wp_authenticate_username_password ( $user , $username , $password ) {
if ( is_a ( $user , 'WP_User' ) ) { return $user ; }
if ( empty ( $username ) || empty ( $password ) ) {
2008-01-22 20:35:19 +01:00
$error = new WP_Error ();
2009-01-24 23:38:19 +01:00
if ( empty ( $username ) )
2008-01-22 20:35:19 +01:00
$error -> add ( 'empty_username' , __ ( '<strong>ERROR</strong>: The username field is empty.' ));
2009-01-24 23:38:19 +01:00
if ( empty ( $password ) )
2008-01-22 20:35:19 +01:00
$error -> add ( 'empty_password' , __ ( '<strong>ERROR</strong>: The password field is empty.' ));
2009-01-24 23:38:19 +01:00
2008-01-22 20:35:19 +01:00
return $error ;
}
2010-01-26 21:25:34 +01:00
$userdata = get_user_by ( 'login' , $username );
2009-01-24 23:38:19 +01:00
2010-01-26 21:25:34 +01:00
if ( ! $userdata )
2009-04-17 00:07:25 +02:00
return new WP_Error ( 'invalid_username' , sprintf ( __ ( '<strong>ERROR</strong>: Invalid username. <a href="%s" title="Password Lost and Found">Lost your password</a>?' ), site_url ( 'wp-login.php?action=lostpassword' , 'login' )));
2010-01-26 21:25:34 +01:00
2010-01-27 19:11:17 +01:00
if ( is_multisite () ) {
// Is user marked as spam?
if ( 1 == $userdata -> spam )
return new WP_Error ( 'invalid_username' , __ ( '<strong>ERROR</strong>: Your account has been marked as a spammer.' ));
// Is a user's blog marked as spam?
if ( ! is_super_admin ( $userdata -> ID ) && isset ( $userdata -> primary_blog ) ) {
$details = get_blog_details ( $userdata -> primary_blog );
if ( is_object ( $details ) && $details -> spam == 1 )
2010-04-30 05:17:49 +02:00
return new WP_Error ( 'blog_suspended' , __ ( 'Site Suspended.' ));
2010-01-27 19:11:17 +01:00
}
}
2009-01-24 23:38:19 +01:00
2009-03-02 23:25:55 +01:00
$userdata = apply_filters ( 'wp_authenticate_user' , $userdata , $password );
2010-01-26 21:25:34 +01:00
if ( is_wp_error ( $userdata ) )
2009-03-02 23:25:55 +01:00
return $userdata ;
2009-01-24 23:38:19 +01:00
2010-01-26 21:25:34 +01:00
if ( ! wp_check_password ( $password , $userdata -> user_pass , $userdata -> ID ) )
2010-12-08 22:25:52 +01:00
return new WP_Error ( 'incorrect_password' , sprintf ( __ ( '<strong>ERROR</strong>: The password you entered for the username <strong>%1$s</strong> is incorrect. <a href="%2$s" title="Password Lost and Found">Lost your password</a>?' ),
$username , site_url ( 'wp-login.php?action=lostpassword' , 'login' ) ) );
2009-01-24 23:38:19 +01:00
$user = new WP_User ( $userdata -> ID );
return $user ;
}
/**
* Authenticate the user using the WordPress auth cookie .
*/
function wp_authenticate_cookie ( $user , $username , $password ) {
if ( is_a ( $user , 'WP_User' ) ) { return $user ; }
if ( empty ( $username ) && empty ( $password ) ) {
$user_id = wp_validate_auth_cookie ();
if ( $user_id )
return new WP_User ( $user_id );
global $auth_secure_cookie ;
if ( $auth_secure_cookie )
$auth_cookie = SECURE_AUTH_COOKIE ;
else
$auth_cookie = AUTH_COOKIE ;
if ( ! empty ( $_COOKIE [ $auth_cookie ]) )
return new WP_Error ( 'expired_session' , __ ( 'Please log in again.' ));
// If the cookie is not set, be silent.
}
2008-01-22 20:35:19 +01:00
return $user ;
}
2008-09-12 06:29:09 +02:00
/**
* Number of posts user has written .
*
2010-03-19 02:11:21 +01:00
* @ since 3.0 . 0
2008-09-12 06:29:09 +02:00
* @ uses $wpdb WordPress database object for queries .
*
* @ param int $userid User ID .
* @ return int Amount of posts user has written .
*/
2010-03-03 20:08:30 +01:00
function count_user_posts ( $userid ) {
2006-06-08 04:22:16 +02:00
global $wpdb ;
2010-03-03 20:08:30 +01:00
$where = get_posts_by_author_sql ( 'post' , TRUE , $userid );
$count = $wpdb -> get_var ( " SELECT COUNT(*) FROM $wpdb->posts $where " );
2008-09-27 23:26:57 +02:00
return apply_filters ( 'get_usernumposts' , $count , $userid );
2006-06-08 04:22:16 +02:00
}
2010-03-03 20:08:30 +01:00
/**
* Number of posts written by a list of users .
*
* @ since 3.0 . 0
2011-04-28 13:27:39 +02:00
* @ param array $user_ids Array of user IDs .
* @ param string | array $post_type Optional . Post type to check . Defaults to post .
2010-03-03 20:08:30 +01:00
* @ return array Amount of posts each user has written .
*/
2011-04-28 13:27:39 +02:00
function count_many_users_posts ( $users , $post_type = 'post' ) {
2010-03-03 20:08:30 +01:00
global $wpdb ;
2010-03-08 15:30:17 +01:00
$count = array ();
2011-04-28 13:27:39 +02:00
if ( empty ( $users ) || ! is_array ( $users ) )
2010-03-08 15:30:17 +01:00
return $count ;
2011-04-28 13:27:39 +02:00
$userlist = implode ( ',' , array_map ( 'absint' , $users ) );
$where = get_posts_by_author_sql ( $post_type );
2010-03-03 20:08:30 +01:00
$result = $wpdb -> get_results ( " SELECT post_author, COUNT(*) FROM $wpdb->posts $where AND post_author IN ( $userlist ) GROUP BY post_author " , ARRAY_N );
2010-03-08 15:30:17 +01:00
foreach ( $result as $row ) {
$count [ $row [ 0 ] ] = $row [ 1 ];
2010-03-03 20:08:30 +01:00
}
2010-03-08 15:30:17 +01:00
foreach ( $users as $id ) {
if ( ! isset ( $count [ $id ] ) )
$count [ $id ] = 0 ;
2010-03-03 20:08:30 +01:00
}
return $count ;
}
2008-09-12 06:29:09 +02:00
/**
* Check that the user login name and password is correct .
*
* @ since 0.71
* @ todo xmlrpc only . Maybe move to xmlrpc . php .
*
* @ param string $user_login User name .
* @ param string $user_pass User password .
* @ return bool False if does not authenticate , true if username and password authenticates .
*/
function user_pass_ok ( $user_login , $user_pass ) {
2008-01-22 20:35:19 +01:00
$user = wp_authenticate ( $user_login , $user_pass );
if ( is_wp_error ( $user ) )
return false ;
return true ;
2006-06-08 04:22:16 +02:00
}
//
// User option functions
//
2010-06-08 17:12:15 +02:00
/**
* Get the current user ' s ID
2010-06-11 22:19:35 +02:00
*
2010-06-08 17:12:15 +02:00
* @ since MU
2010-06-11 22:19:35 +02:00
*
2010-06-08 17:12:15 +02:00
* @ uses wp_get_current_user
*
* @ return int The current user ' s ID
*/
function get_current_user_id () {
$user = wp_get_current_user ();
return ( isset ( $user -> ID ) ? ( int ) $user -> ID : 0 );
}
2008-09-12 06:29:09 +02:00
/**
2010-02-19 11:49:07 +01:00
* Retrieve user option that can be either per Site or per Network .
2008-09-12 06:29:09 +02:00
*
* If the user ID is not given , then the current user will be used instead . If
* the user ID is given , then the user data will be retrieved . The filter for
* the result , will also pass the original option name and finally the user data
* object as the third parameter .
*
2010-02-19 11:49:07 +01:00
* The option will first check for the per site name and then the per Network name .
2008-09-12 06:29:09 +02:00
*
* @ since 2.0 . 0
* @ uses $wpdb WordPress database object for queries .
* @ uses apply_filters () Calls 'get_user_option_$option' hook with result ,
* option parameter , and user data object .
*
* @ param string $option User option name .
* @ param int $user Optional . User ID .
2010-01-07 01:01:52 +01:00
* @ param bool $deprecated Use get_option () to check for an option in the options table .
2008-09-12 06:29:09 +02:00
* @ return mixed
*/
2010-01-07 01:01:52 +01:00
function get_user_option ( $option , $user = 0 , $deprecated = '' ) {
2006-06-08 04:22:16 +02:00
global $wpdb ;
2010-01-07 01:01:52 +01:00
if ( ! empty ( $deprecated ) )
_deprecated_argument ( __FUNCTION__ , '3.0' );
2010-04-29 21:19:21 +02:00
if ( empty ( $user ) ) {
2006-06-08 04:22:16 +02:00
$user = wp_get_current_user ();
2010-04-29 22:55:39 +02:00
$user = $user -> ID ;
2010-04-29 21:19:21 +02:00
}
2006-06-08 04:22:16 +02:00
2010-04-29 22:55:39 +02:00
$user = get_userdata ( $user );
2010-04-29 22:19:47 +02:00
// Keys used as object vars cannot have dashes.
2010-04-30 19:57:30 +02:00
$key = str_replace ( '-' , '' , $option );
2010-04-29 22:19:47 +02:00
2010-04-29 21:19:21 +02:00
if ( isset ( $user -> { $wpdb -> prefix . $key } ) ) // Blog specific
$result = $user -> { $wpdb -> prefix . $key };
elseif ( isset ( $user -> { $key } ) ) // User specific and cross-blog
$result = $user -> { $key };
2008-11-25 19:33:04 +01:00
else
$result = false ;
2008-08-09 07:36:14 +02:00
2008-03-11 22:37:23 +01:00
return apply_filters ( " get_user_option_ { $option } " , $result , $option , $user );
2006-06-08 04:22:16 +02:00
}
2008-09-12 06:29:09 +02:00
/**
* Update user option with global blog capability .
*
* User options are just like user metadata except that they have support for
2009-04-08 20:24:49 +02:00
* global blog options . If the 'global' parameter is false , which it is by default
2008-09-12 06:29:09 +02:00
* it will prepend the WordPress table prefix to the option name .
*
2010-04-23 16:25:05 +02:00
* Deletes the user option if $newvalue is empty .
*
2008-09-12 06:29:09 +02:00
* @ since 2.0 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param int $user_id User ID
* @ param string $option_name User option name .
* @ param mixed $newvalue User option value .
2010-03-11 19:28:31 +01:00
* @ param bool $global Optional . Whether option name is global or blog specific . Default false ( blog specific ) .
2008-09-12 06:29:09 +02:00
* @ return unknown
*/
2006-06-08 04:22:16 +02:00
function update_user_option ( $user_id , $option_name , $newvalue , $global = false ) {
global $wpdb ;
2010-03-02 19:06:14 +01:00
2006-06-08 04:22:16 +02:00
if ( ! $global )
$option_name = $wpdb -> prefix . $option_name ;
2010-04-23 16:25:05 +02:00
2010-04-23 17:32:31 +02:00
// For backward compatibility. See differences between update_user_meta() and deprecated update_usermeta().
2010-04-23 16:25:05 +02:00
// http://core.trac.wordpress.org/ticket/13088
if ( is_null ( $newvalue ) || is_scalar ( $newvalue ) && empty ( $newvalue ) )
return delete_user_meta ( $user_id , $option_name );
2010-02-22 22:25:32 +01:00
return update_user_meta ( $user_id , $option_name , $newvalue );
2006-06-08 04:22:16 +02:00
}
2010-03-11 19:28:31 +01:00
/**
* Delete user option with global blog capability .
*
* User options are just like user metadata except that they have support for
* global blog options . If the 'global' parameter is false , which it is by default
* it will prepend the WordPress table prefix to the option name .
*
* @ since 3.0 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param int $user_id User ID
* @ param string $option_name User option name .
* @ param bool $global Optional . Whether option name is global or blog specific . Default false ( blog specific ) .
* @ return unknown
*/
function delete_user_option ( $user_id , $option_name , $global = false ) {
global $wpdb ;
if ( ! $global )
$option_name = $wpdb -> prefix . $option_name ;
return delete_user_meta ( $user_id , $option_name );
}
2010-08-11 23:54:51 +02:00
/**
* WordPress User Query class .
*
* @ since 3.1 . 0
*/
2010-11-13 19:32:43 +01:00
class WP_User_Query {
2010-08-11 23:54:51 +02:00
/**
2010-08-27 17:41:32 +02:00
* List of found user ids
2010-08-11 23:54:51 +02:00
*
* @ since 3.1 . 0
* @ access private
* @ var array
*/
var $results ;
/**
2010-08-27 17:41:32 +02:00
* Total number of found users for the current query
2010-08-11 23:54:51 +02:00
*
* @ since 3.1 . 0
* @ access private
* @ var int
*/
var $total_users = 0 ;
2010-12-16 00:56:53 +01:00
// SQL clauses
var $query_fields ;
2010-08-11 23:54:51 +02:00
var $query_from ;
var $query_where ;
var $query_orderby ;
var $query_limit ;
2010-08-27 17:41:32 +02:00
/**
* PHP5 constructor
2010-08-11 23:54:51 +02:00
*
* @ since 3.1 . 0
*
* @ param string | array $args The query variables
* @ return WP_User_Query
*/
2010-08-27 17:41:32 +02:00
function __construct ( $query = null ) {
if ( ! empty ( $query ) ) {
$this -> query_vars = wp_parse_args ( $query , array (
2010-10-27 20:16:52 +02:00
'blog_id' => $GLOBALS [ 'blog_id' ],
'role' => '' ,
2010-10-28 17:46:11 +02:00
'meta_key' => '' ,
2010-10-27 20:16:52 +02:00
'meta_value' => '' ,
'meta_compare' => '' ,
'include' => array (),
'exclude' => array (),
2010-09-05 16:35:55 +02:00
'search' => '' ,
2010-10-27 20:16:52 +02:00
'orderby' => 'login' ,
'order' => 'ASC' ,
2011-06-07 17:55:05 +02:00
'offset' => '' ,
'number' => '' ,
2010-10-27 20:16:52 +02:00
'count_total' => true ,
2010-09-05 15:31:33 +02:00
'fields' => 'all' ,
2010-12-20 20:02:44 +01:00
'who' => ''
2010-08-27 17:41:32 +02:00
) );
$this -> prepare_query ();
$this -> query ();
}
2010-08-11 23:54:51 +02:00
}
/**
* Prepare the query variables
*
* @ since 3.1 . 0
* @ access private
*/
function prepare_query () {
global $wpdb ;
$qv = & $this -> query_vars ;
2010-12-16 00:56:53 +01:00
if ( is_array ( $qv [ 'fields' ] ) ) {
$qv [ 'fields' ] = array_unique ( $qv [ 'fields' ] );
$this -> query_fields = array ();
foreach ( $qv [ 'fields' ] as $field )
$this -> query_fields [] = $wpdb -> users . '.' . esc_sql ( $field );
$this -> query_fields = implode ( ',' , $this -> query_fields );
2010-12-17 01:38:15 +01:00
} elseif ( 'all' == $qv [ 'fields' ] ) {
$this -> query_fields = " $wpdb->users .* " ;
2010-12-16 00:56:53 +01:00
} else {
$this -> query_fields = " $wpdb->users .ID " ;
}
2011-06-07 17:55:05 +02:00
if ( $this -> query_vars [ 'count_total' ] )
$this -> query_fields = 'SQL_CALC_FOUND_ROWS ' . $this -> query_fields ;
2010-12-16 00:56:53 +01:00
$this -> query_from = " FROM $wpdb->users " ;
$this -> query_where = " WHERE 1=1 " ;
2010-08-11 23:54:51 +02:00
// sorting
2010-12-15 18:18:04 +01:00
if ( in_array ( $qv [ 'orderby' ], array ( 'nicename' , 'email' , 'url' , 'registered' ) ) ) {
2010-08-11 23:54:51 +02:00
$orderby = 'user_' . $qv [ 'orderby' ];
2010-12-15 18:18:04 +01:00
} elseif ( in_array ( $qv [ 'orderby' ], array ( 'user_nicename' , 'user_email' , 'user_url' , 'user_registered' ) ) ) {
2010-12-15 17:51:38 +01:00
$orderby = $qv [ 'orderby' ];
2010-12-14 17:19:08 +01:00
} elseif ( 'name' == $qv [ 'orderby' ] || 'display_name' == $qv [ 'orderby' ] ) {
2010-08-11 23:54:51 +02:00
$orderby = 'display_name' ;
2010-11-03 14:34:04 +01:00
} elseif ( 'post_count' == $qv [ 'orderby' ] ) {
2010-12-17 11:25:27 +01:00
// todo: avoid the JOIN
2010-08-11 23:54:51 +02:00
$where = get_posts_by_author_sql ( 'post' );
$this -> query_from .= " LEFT OUTER JOIN (
SELECT post_author , COUNT ( * ) as post_count
2011-04-13 19:02:08 +02:00
FROM $wpdb -> posts
2010-08-11 23:54:51 +02:00
$where
GROUP BY post_author
2010-10-04 11:43:02 +02:00
) p ON ({ $wpdb -> users } . ID = p . post_author )
2010-08-11 23:54:51 +02:00
" ;
$orderby = 'post_count' ;
2010-12-15 18:18:04 +01:00
} elseif ( 'ID' == $qv [ 'orderby' ] || 'id' == $qv [ 'orderby' ] ) {
2010-11-03 14:34:04 +01:00
$orderby = 'ID' ;
} else {
2010-08-11 23:54:51 +02:00
$orderby = 'user_login' ;
}
$qv [ 'order' ] = strtoupper ( $qv [ 'order' ] );
if ( 'ASC' == $qv [ 'order' ] )
$order = 'ASC' ;
else
$order = 'DESC' ;
2010-12-16 00:56:53 +01:00
$this -> query_orderby = " ORDER BY $orderby $order " ;
2010-08-11 23:54:51 +02:00
// limit
if ( $qv [ 'number' ] ) {
if ( $qv [ 'offset' ] )
2010-12-16 00:56:53 +01:00
$this -> query_limit = $wpdb -> prepare ( " LIMIT %d, %d " , $qv [ 'offset' ], $qv [ 'number' ]);
2010-08-11 23:54:51 +02:00
else
2010-12-16 00:56:53 +01:00
$this -> query_limit = $wpdb -> prepare ( " LIMIT %d " , $qv [ 'number' ]);
2010-08-11 23:54:51 +02:00
}
$search = trim ( $qv [ 'search' ] );
if ( $search ) {
2010-12-31 00:38:21 +01:00
$leading_wild = ( ltrim ( $search , '*' ) != $search );
$trailing_wild = ( rtrim ( $search , '*' ) != $search );
if ( $leading_wild && $trailing_wild )
$wild = 'both' ;
elseif ( $leading_wild )
$wild = 'leading' ;
elseif ( $trailing_wild )
$wild = 'trailing' ;
else
$wild = false ;
if ( $wild )
2010-11-03 20:31:11 +01:00
$search = trim ( $search , '*' );
2010-12-31 00:38:21 +01:00
2010-11-03 20:02:42 +01:00
if ( false !== strpos ( $search , '@' ) )
2010-11-20 00:58:29 +01:00
$search_columns = array ( 'user_email' );
2010-11-03 20:02:42 +01:00
elseif ( is_numeric ( $search ) )
$search_columns = array ( 'user_login' , 'ID' );
elseif ( preg_match ( '|^https?://|' , $search ) )
$search_columns = array ( 'user_url' );
else
2010-11-09 21:01:56 +01:00
$search_columns = array ( 'user_login' , 'user_nicename' );
2010-11-03 20:02:42 +01:00
2010-11-03 20:31:11 +01:00
$this -> query_where .= $this -> get_search_sql ( $search , $search_columns , $wild );
2010-08-11 23:54:51 +02:00
}
2010-12-20 18:25:39 +01:00
$blog_id = absint ( $qv [ 'blog_id' ] );
if ( 'authors' == $qv [ 'who' ] && $blog_id ) {
$qv [ 'meta_key' ] = $wpdb -> get_blog_prefix ( $blog_id ) . 'user_level' ;
2011-04-21 20:13:03 +02:00
$qv [ 'meta_value' ] = 0 ;
2010-12-20 18:25:39 +01:00
$qv [ 'meta_compare' ] = '!=' ;
$qv [ 'blog_id' ] = $blog_id = 0 ; // Prevent extra meta query
}
2010-08-11 23:54:51 +02:00
$role = trim ( $qv [ 'role' ] );
2010-08-27 02:18:57 +02:00
2010-12-13 12:44:53 +01:00
if ( $blog_id && ( $role || is_multisite () ) ) {
2010-09-05 16:35:55 +02:00
$cap_meta_query = array ();
2010-10-04 20:26:26 +02:00
$cap_meta_query [ 'key' ] = $wpdb -> get_blog_prefix ( $blog_id ) . 'capabilities' ;
2010-09-05 15:31:33 +02:00
2010-09-05 16:35:55 +02:00
if ( $role ) {
2010-10-28 15:26:16 +02:00
$cap_meta_query [ 'value' ] = '"' . $role . '"' ;
2010-10-04 20:26:26 +02:00
$cap_meta_query [ 'compare' ] = 'like' ;
2010-09-05 16:35:55 +02:00
}
2010-08-27 02:18:57 +02:00
2010-10-09 12:48:13 +02:00
$qv [ 'meta_query' ][] = $cap_meta_query ;
2010-10-04 20:26:26 +02:00
}
2010-09-05 15:31:33 +02:00
2011-04-25 19:27:35 +02:00
$meta_query = new WP_Meta_Query ();
$meta_query -> parse_query_vars ( $qv );
if ( ! empty ( $meta_query -> queries ) ) {
$clauses = $meta_query -> get_sql ( 'user' , $wpdb -> users , 'ID' , $this );
2010-10-28 19:02:37 +02:00
$this -> query_from .= $clauses [ 'join' ];
$this -> query_where .= $clauses [ 'where' ];
2011-06-07 17:55:05 +02:00
if ( 'OR' == $meta_query -> relation )
$this -> query_fields = 'DISTINCT ' . $this -> query_fields ;
2010-10-09 14:18:52 +02:00
}
2010-08-11 23:54:51 +02:00
2010-10-09 14:18:52 +02:00
if ( ! empty ( $qv [ 'include' ] ) ) {
2010-08-11 23:54:51 +02:00
$ids = implode ( ',' , wp_parse_id_list ( $qv [ 'include' ] ) );
$this -> query_where .= " AND $wpdb->users .ID IN ( $ids ) " ;
2010-12-17 22:48:30 +01:00
} elseif ( ! empty ( $qv [ 'exclude' ]) ) {
2010-08-11 23:54:51 +02:00
$ids = implode ( ',' , wp_parse_id_list ( $qv [ 'exclude' ] ) );
$this -> query_where .= " AND $wpdb->users .ID NOT IN ( $ids ) " ;
}
do_action_ref_array ( 'pre_user_query' , array ( & $this ) );
}
/**
* Execute the query , with the current variables
*
* @ since 3.1 . 0
* @ access private
*/
function query () {
global $wpdb ;
2011-02-09 18:35:36 +01:00
2010-12-17 01:38:15 +01:00
if ( is_array ( $this -> query_vars [ 'fields' ] ) || 'all' == $this -> query_vars [ 'fields' ] ) {
2010-12-16 00:56:53 +01:00
$this -> results = $wpdb -> get_results ( " SELECT $this->query_fields $this->query_from $this->query_where $this->query_orderby $this->query_limit " );
} else {
$this -> results = $wpdb -> get_col ( " SELECT $this->query_fields $this->query_from $this->query_where $this->query_orderby $this->query_limit " );
}
2011-02-09 18:35:36 +01:00
2011-01-25 20:20:20 +01:00
if ( $this -> query_vars [ 'count_total' ] )
2011-06-07 17:55:05 +02:00
$this -> total_users = $wpdb -> get_var ( apply_filters ( 'found_users_query' , 'SELECT FOUND_ROWS()' ) );
2010-08-11 23:54:51 +02:00
if ( ! $this -> results )
return ;
2010-12-17 01:38:15 +01:00
if ( 'all_with_meta' == $this -> query_vars [ 'fields' ] ) {
cache_users ( $this -> results );
2010-08-11 23:54:51 +02:00
$r = array ();
foreach ( $this -> results as $userid )
2010-09-05 16:35:55 +02:00
$r [ $userid ] = new WP_User ( $userid , '' , $this -> query_vars [ 'blog_id' ] );
2010-08-11 23:54:51 +02:00
$this -> results = $r ;
}
}
2010-11-13 19:18:45 +01:00
/*
* Used internally to generate an SQL string for searching across multiple columns
*
* @ access protected
* @ since 3.1 . 0
*
* @ param string $string
* @ param array $cols
2010-12-31 00:38:21 +01:00
* @ param bool $wild Whether to allow wildcard searches . Default is false for Network Admin , true for
* single site . Single site allows leading and trailing wildcards , Network Admin only trailing .
2010-11-13 19:18:45 +01:00
* @ return string
*/
function get_search_sql ( $string , $cols , $wild = false ) {
$string = esc_sql ( $string );
$searches = array ();
2010-12-31 00:38:21 +01:00
$leading_wild = ( 'leading' == $wild || 'both' == $wild ) ? '%' : '' ;
$trailing_wild = ( 'trailing' == $wild || 'both' == $wild ) ? '%' : '' ;
2010-11-13 19:18:45 +01:00
foreach ( $cols as $col ) {
if ( 'ID' == $col )
$searches [] = " $col = ' $string ' " ;
else
2010-12-31 00:38:21 +01:00
$searches [] = " $col LIKE ' $leading_wild " . like_escape ( $string ) . " $trailing_wild ' " ;
2010-11-13 19:18:45 +01:00
}
return ' AND (' . implode ( ' OR ' , $searches ) . ')' ;
}
2010-08-11 23:54:51 +02:00
/**
* Return the list of users
*
* @ since 3.1 . 0
* @ access public
*
* @ return array
*/
function get_results () {
return $this -> results ;
}
/**
* Return the total number of users for the current query
*
* @ since 3.1 . 0
* @ access public
*
* @ return array
*/
function get_total () {
return $this -> total_users ;
}
}
/**
* Retrieve list of users matching criteria .
*
* @ since 3.1 . 0
* @ uses $wpdb
* @ uses WP_User_Query See for default arguments and information .
*
2010-10-20 19:21:06 +02:00
* @ param array $args Optional .
2010-08-11 23:54:51 +02:00
* @ return array List of users .
*/
2010-10-20 19:21:06 +02:00
function get_users ( $args = array () ) {
2010-08-11 23:54:51 +02:00
$args = wp_parse_args ( $args );
$args [ 'count_total' ] = false ;
$user_search = new WP_User_Query ( $args );
return ( array ) $user_search -> get_results ();
}
2010-09-27 22:26:36 +02:00
/**
2010-10-18 19:11:00 +02:00
* Get the blogs a user belongs to .
2010-09-27 22:26:36 +02:00
*
2010-10-18 19:11:00 +02:00
* @ since 3.0 . 0
2010-09-27 22:26:36 +02:00
*
* @ param int $id User Id
2010-10-18 19:11:00 +02:00
* @ param bool $all Whether to retrieve all blogs or only blogs that are not marked as deleted , archived , or spam .
* @ return array A list of the user ' s blogs . False if the user was not found or an empty array if the user has no blogs .
2010-09-27 22:26:36 +02:00
*/
function get_blogs_of_user ( $id , $all = false ) {
global $wpdb ;
if ( ! is_multisite () ) {
2010-10-28 17:46:11 +02:00
$blog_id = get_current_blog_id ();
2010-09-27 22:26:36 +02:00
$blogs = array ();
$blogs [ $blog_id ] -> userblog_id = $blog_id ;
$blogs [ $blog_id ] -> blogname = get_option ( 'blogname' );
$blogs [ $blog_id ] -> domain = '' ;
$blogs [ $blog_id ] -> path = '' ;
$blogs [ $blog_id ] -> site_id = 1 ;
$blogs [ $blog_id ] -> siteurl = get_option ( 'siteurl' );
return $blogs ;
}
2010-10-18 19:11:00 +02:00
$blogs = wp_cache_get ( 'blogs_of_user-' . $id , 'users' );
2010-11-06 19:45:20 +01:00
// Try priming the new cache from the old cache
if ( false === $blogs ) {
$cache_suffix = $all ? '_all' : '_short' ;
$blogs = wp_cache_get ( 'blogs_of_user_' . $id . $cache_suffix , 'users' );
if ( is_array ( $blogs ) ) {
$blogs = array_keys ( $blogs );
if ( $all )
wp_cache_set ( 'blogs_of_user-' . $id , $blogs , 'users' );
}
}
2010-10-18 19:11:00 +02:00
if ( false === $blogs ) {
$user = get_userdata ( ( int ) $id );
if ( ! $user )
return false ;
$blogs = $match = array ();
$prefix_length = strlen ( $wpdb -> base_prefix );
foreach ( ( array ) $user as $key => $value ) {
if ( $prefix_length && substr ( $key , 0 , $prefix_length ) != $wpdb -> base_prefix )
continue ;
if ( substr ( $key , - 12 , 12 ) != 'capabilities' )
continue ;
if ( preg_match ( '/^' . $wpdb -> base_prefix . '((\d+)_)?capabilities$/' , $key , $match ) ) {
if ( count ( $match ) > 2 )
$blogs [] = ( int ) $match [ 2 ];
else
$blogs [] = 1 ;
2010-09-27 22:26:36 +02:00
}
}
2010-10-18 19:11:00 +02:00
wp_cache_set ( 'blogs_of_user-' . $id , $blogs , 'users' );
}
$blog_deets = array ();
foreach ( ( array ) $blogs as $blog_id ) {
$blog = get_blog_details ( $blog_id );
if ( $blog && isset ( $blog -> domain ) && ( $all == true || $all == false && ( $blog -> archived == 0 && $blog -> spam == 0 && $blog -> deleted == 0 ) ) ) {
$blog_deets [ $blog_id ] -> userblog_id = $blog_id ;
$blog_deets [ $blog_id ] -> blogname = $blog -> blogname ;
$blog_deets [ $blog_id ] -> domain = $blog -> domain ;
$blog_deets [ $blog_id ] -> path = $blog -> path ;
$blog_deets [ $blog_id ] -> site_id = $blog -> site_id ;
$blog_deets [ $blog_id ] -> siteurl = $blog -> siteurl ;
}
2010-09-27 22:26:36 +02:00
}
2010-10-18 19:11:00 +02:00
return apply_filters ( 'get_blogs_of_user' , $blog_deets , $id , $all );
2010-09-27 22:26:36 +02:00
}
/**
* Checks if the current user belong to a given blog .
*
* @ since 3.0 . 0
*
* @ param int $blog_id Blog ID
* @ return bool True if the current users belong to $blog_id , false if not .
*/
function is_blog_user ( $blog_id = 0 ) {
global $wpdb ;
2010-10-19 09:48:22 +02:00
2010-09-27 22:26:36 +02:00
$current_user = wp_get_current_user ();
if ( ! $blog_id )
$blog_id = $wpdb -> blogid ;
$cap_key = $wpdb -> base_prefix . $blog_id . '_capabilities' ;
if ( is_array ( $current_user -> $cap_key ) && in_array ( 1 , $current_user -> $cap_key ) )
return true ;
return false ;
}
2008-09-12 06:29:09 +02:00
/**
2010-02-22 19:35:35 +01:00
* Add meta data field to a user .
2008-09-12 06:29:09 +02:00
*
2011-04-28 17:24:49 +02:00
* Post meta data is called " Custom Fields " on the Administration Screens .
2010-02-22 19:35:35 +01:00
*
* @ since 3.0 . 0
* @ uses add_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / add_user_meta
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* @ param int $user_id Post ID .
2010-09-07 13:21:11 +02:00
* @ param string $meta_key Metadata name .
* @ param mixed $meta_value Metadata value .
2010-02-22 19:35:35 +01:00
* @ param bool $unique Optional , default is false . Whether the same key should not be added .
* @ return bool False for failure . True for success .
2008-09-12 06:29:09 +02:00
*/
2010-02-22 19:35:35 +01:00
function add_user_meta ( $user_id , $meta_key , $meta_value , $unique = false ) {
return add_metadata ( 'user' , $user_id , $meta_key , $meta_value , $unique );
2006-06-08 04:22:16 +02:00
}
2008-09-12 06:29:09 +02:00
/**
2010-02-22 19:35:35 +01:00
* Remove metadata matching criteria from a user .
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* You can match based on the key , or key and value . Removing based on key and
* value , will keep from removing duplicate metadata with the same key . It also
* allows removing all metadata matching key , if needed .
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* @ since 3.0 . 0
* @ uses delete_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / delete_user_meta
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* @ param int $user_id user ID
* @ param string $meta_key Metadata name .
* @ param mixed $meta_value Optional . Metadata value .
* @ return bool False for failure . True for success .
2008-09-12 06:29:09 +02:00
*/
2010-02-22 19:35:35 +01:00
function delete_user_meta ( $user_id , $meta_key , $meta_value = '' ) {
return delete_metadata ( 'user' , $user_id , $meta_key , $meta_value );
}
2006-06-08 04:22:16 +02:00
2010-02-22 19:35:35 +01:00
/**
* Retrieve user meta field for a user .
*
* @ since 3.0 . 0
* @ uses get_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / get_user_meta
*
* @ param int $user_id Post ID .
* @ param string $key The meta key to retrieve .
* @ param bool $single Whether to return a single value .
* @ return mixed Will be an array if $single is false . Will be value of meta data field if $single
* is true .
*/
function get_user_meta ( $user_id , $key , $single = false ) {
return get_metadata ( 'user' , $user_id , $key , $single );
2006-06-08 04:22:16 +02:00
}
2008-09-12 06:29:09 +02:00
/**
2010-02-22 19:35:35 +01:00
* Update user meta field based on user ID .
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* Use the $prev_value parameter to differentiate between meta fields with the
* same key and user ID .
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* If the meta field for the user does not exist , it will be added .
2008-09-12 06:29:09 +02:00
*
2010-03-26 20:13:36 +01:00
* @ since 3.0 . 0
2010-02-22 19:35:35 +01:00
* @ uses update_metadata
* @ link http :// codex . wordpress . org / Function_Reference / update_user_meta
2008-09-12 06:29:09 +02:00
*
2010-02-22 19:35:35 +01:00
* @ param int $user_id Post ID .
2010-09-07 13:21:11 +02:00
* @ param string $meta_key Metadata key .
* @ param mixed $meta_value Metadata value .
2010-02-22 19:35:35 +01:00
* @ param mixed $prev_value Optional . Previous value to check before removing .
* @ return bool False on failure , true if success .
2008-09-12 06:29:09 +02:00
*/
2010-02-22 19:35:35 +01:00
function update_user_meta ( $user_id , $meta_key , $meta_value , $prev_value = '' ) {
return update_metadata ( 'user' , $user_id , $meta_key , $meta_value , $prev_value );
2006-06-08 04:22:16 +02:00
}
2010-03-03 20:08:30 +01:00
/**
* Count number of users who have each of the user roles .
*
* Assumes there are neither duplicated nor orphaned capabilities meta_values .
2010-08-11 23:54:51 +02:00
* Assumes role names are unique phrases . Same assumption made by WP_User_Query :: prepare_query ()
2010-03-03 20:08:30 +01:00
* Using $strategy = 'time' this is CPU - intensive and should handle around 10 ^ 7 users .
* Using $strategy = 'memory' this is memory - intensive and should handle around 10 ^ 5 users , but see WP Bug #12257.
*
* @ since 3.0 . 0
* @ param string $strategy 'time' or 'memory'
* @ return array Includes a grand total and an array of counts indexed by role strings .
*/
function count_users ( $strategy = 'time' ) {
2010-10-28 17:46:11 +02:00
global $wpdb , $wp_roles ;
2010-03-03 20:08:30 +01:00
// Initialize
2010-10-28 17:46:11 +02:00
$id = get_current_blog_id ();
2010-03-03 20:08:30 +01:00
$blog_prefix = $wpdb -> get_blog_prefix ( $id );
$result = array ();
2010-04-15 23:24:52 +02:00
if ( 'time' == $strategy ) {
global $wp_roles ;
if ( ! isset ( $wp_roles ) )
$wp_roles = new WP_Roles ();
2010-03-03 20:08:30 +01:00
$avail_roles = $wp_roles -> get_names ();
// Build a CPU-intensive query that will return concise information.
$select_count = array ();
foreach ( $avail_roles as $this_role => $name ) {
$select_count [] = " COUNT(NULLIF(`meta_value` LIKE '% " . like_escape ( $this_role ) . " %', FALSE)) " ;
}
$select_count = implode ( ', ' , $select_count );
// Add the meta_value index to the selection list, then run the query.
$row = $wpdb -> get_row ( " SELECT $select_count , COUNT(*) FROM $wpdb->usermeta WHERE meta_key = ' { $blog_prefix } capabilities' " , ARRAY_N );
// Run the previous loop again to associate results with role names.
$col = 0 ;
$role_counts = array ();
foreach ( $avail_roles as $this_role => $name ) {
$count = ( int ) $row [ $col ++ ];
if ( $count > 0 ) {
$role_counts [ $this_role ] = $count ;
}
}
// Get the meta_value index from the end of the result set.
$total_users = ( int ) $row [ $col ];
$result [ 'total_users' ] = $total_users ;
$result [ 'avail_roles' ] =& $role_counts ;
} else {
$avail_roles = array ();
$users_of_blog = $wpdb -> get_col ( " SELECT meta_value FROM $wpdb->usermeta WHERE meta_key = ' { $blog_prefix } capabilities' " );
foreach ( $users_of_blog as $caps_meta ) {
$b_roles = unserialize ( $caps_meta );
if ( is_array ( $b_roles ) ) {
foreach ( $b_roles as $b_role => $val ) {
if ( isset ( $avail_roles [ $b_role ]) ) {
$avail_roles [ $b_role ] ++ ;
} else {
$avail_roles [ $b_role ] = 1 ;
}
}
}
}
$result [ 'total_users' ] = count ( $users_of_blog );
$result [ 'avail_roles' ] =& $avail_roles ;
}
return $result ;
}
2006-06-08 04:22:16 +02:00
//
// Private helper functions
//
2008-09-12 06:29:09 +02:00
/**
2010-03-17 05:39:50 +01:00
* Set up global user vars .
2008-09-12 06:29:09 +02:00
*
2010-04-15 00:06:03 +02:00
* Used by wp_set_current_user () for back compat . Might be deprecated in the future .
2008-09-12 06:29:09 +02:00
*
* @ since 2.0 . 4
* @ global string $userdata User description .
* @ global string $user_login The user username for logging in
* @ global int $user_level The level of the user
* @ global int $user_ID The ID of the user
* @ global string $user_email The email address of the user
* @ global string $user_url The url in the user ' s profile
* @ global string $user_pass_md5 MD5 of the user ' s password
* @ global string $user_identity The display name of the user
*
2010-03-17 05:39:50 +01:00
* @ param int $for_user_id Optional . User ID to set up global data .
2008-09-12 06:29:09 +02:00
*/
2009-11-27 19:17:44 +01:00
function setup_userdata ( $for_user_id = '' ) {
2009-12-01 03:06:02 +01:00
global $user_login , $userdata , $user_level , $user_ID , $user_email , $user_url , $user_pass_md5 , $user_identity ;
2006-06-08 04:22:16 +02:00
2009-11-27 19:17:44 +01:00
if ( '' == $for_user_id )
2006-06-08 04:22:16 +02:00
$user = wp_get_current_user ();
2006-11-19 08:56:05 +01:00
else
2009-11-27 19:17:44 +01:00
$user = new WP_User ( $for_user_id );
2006-06-08 04:22:16 +02:00
2010-05-12 01:02:40 +02:00
$userdata = $user -> data ;
$user_ID = ( int ) $user -> ID ;
$user_level = ( int ) isset ( $user -> user_level ) ? $user -> user_level : 0 ;
if ( 0 == $user -> ID ) {
$user_login = $user_email = $user_url = $user_pass_md5 = $user_identity = '' ;
2006-06-08 04:22:16 +02:00
return ;
2010-05-12 01:02:40 +02:00
}
2006-06-08 04:22:16 +02:00
$user_login = $user -> user_login ;
$user_email = $user -> user_email ;
$user_url = $user -> user_url ;
$user_pass_md5 = md5 ( $user -> user_pass );
$user_identity = $user -> display_name ;
}
2008-09-12 06:29:09 +02:00
/**
* Create dropdown HTML content of users .
*
* The content can either be displayed , which it is by default or retrieved by
* setting the 'echo' argument . The 'include' and 'exclude' arguments do not
* need to be used ; all users will be displayed in that case . Only one can be
* used , either 'include' or 'exclude' , but not both .
*
* The available arguments are as follows :
* < ol >
* < li > show_option_all - Text to show all and whether HTML option exists .</ li >
2010-12-14 17:19:08 +01:00
* < li > show_option_none - Text for show none and whether HTML option exists .</ li >
2010-12-20 18:25:39 +01:00
* < li > hide_if_only_one_author - Don ' t create the dropdown if there is only one user .</ li >
2010-12-14 17:19:08 +01:00
* < li > orderby - SQL order by clause for what order the users appear . Default is 'display_name' .</ li >
2008-09-12 06:29:09 +02:00
* < li > order - Default is 'ASC' . Can also be 'DESC' .</ li >
* < li > include - User IDs to include .</ li >
* < li > exclude - User IDs to exclude .</ li >
2010-03-02 19:36:49 +01:00
* < li > multi - Default is 'false' . Whether to skip the ID attribute on the 'select' element . A 'true' value is overridden when id argument is set .</ li >
2010-12-14 17:19:08 +01:00
* < li > show - Default is 'display_name' . User table column to display . If the selected item is empty then the user_login will be displayed in parentheses </ li >
2008-09-12 06:29:09 +02:00
* < li > echo - Default is '1' . Whether to display or retrieve content .</ li >
* < li > selected - Which User ID is selected .</ li >
2011-01-01 02:52:03 +01:00
* < li > include_selected - Always include the selected user ID in the dropdown . Default is false .</ li >
2008-09-12 06:29:09 +02:00
* < li > name - Default is 'user' . Name attribute of select element .</ li >
2010-03-02 19:36:49 +01:00
* < li > id - Default is the value of the 'name' parameter . ID attribute of select element .</ li >
2008-09-12 06:29:09 +02:00
* < li > class - Class attribute of select element .</ li >
2010-02-13 21:17:15 +01:00
* < li > blog_id - ID of blog ( Multisite only ) . Defaults to ID of current blog .</ li >
2010-12-20 18:25:39 +01:00
* < li > who - Which users to query . Currently only 'authors' is supported . Default is all users .</ li >
2008-09-12 06:29:09 +02:00
* </ ol >
*
* @ since 2.3 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param string | array $args Optional . Override defaults .
* @ return string | null Null on display . String of HTML content on retrieve .
*/
2007-05-29 06:28:10 +02:00
function wp_dropdown_users ( $args = '' ) {
$defaults = array (
2010-12-20 18:25:39 +01:00
'show_option_all' => '' , 'show_option_none' => '' , 'hide_if_only_one_author' => '' ,
2007-05-29 06:28:10 +02:00
'orderby' => 'display_name' , 'order' => 'ASC' ,
2008-09-30 12:30:56 +02:00
'include' => '' , 'exclude' => '' , 'multi' => 0 ,
2007-05-29 06:28:10 +02:00
'show' => 'display_name' , 'echo' => 1 ,
2010-12-20 18:25:39 +01:00
'selected' => 0 , 'name' => 'user' , 'class' => '' , 'id' => '' ,
2011-01-01 02:52:03 +01:00
'blog_id' => $GLOBALS [ 'blog_id' ], 'who' => '' , 'include_selected' => false
2007-05-29 06:28:10 +02:00
);
2007-06-14 04:25:30 +02:00
2007-05-29 06:28:10 +02:00
$defaults [ 'selected' ] = is_author () ? get_query_var ( 'author' ) : 0 ;
2007-06-14 04:25:30 +02:00
2007-05-29 06:28:10 +02:00
$r = wp_parse_args ( $args , $defaults );
2007-06-15 00:45:40 +02:00
extract ( $r , EXTR_SKIP );
2007-05-29 06:28:10 +02:00
2010-12-20 18:25:39 +01:00
$query_args = wp_array_slice_assoc ( $r , array ( 'blog_id' , 'include' , 'exclude' , 'orderby' , 'order' , 'who' ) );
2010-12-16 00:56:53 +01:00
$query_args [ 'fields' ] = array ( 'ID' , $show );
$users = get_users ( $query_args );
2007-05-29 06:28:10 +02:00
$output = '' ;
2010-12-20 18:25:39 +01:00
if ( ! empty ( $users ) && ( empty ( $hide_if_only_one_author ) || count ( $users ) > 1 ) ) {
2010-03-02 19:36:49 +01:00
$name = esc_attr ( $name );
if ( $multi && ! $id )
$id = '' ;
else
2010-05-26 06:01:14 +02:00
$id = $id ? " id=' " . esc_attr ( $id ) . " ' " : " id=' $name ' " ;
2008-09-30 12:30:56 +02:00
2010-03-02 19:36:49 +01:00
$output = " <select name=' { $name } ' { $id } class=' $class '> \n " ;
2007-05-29 06:28:10 +02:00
if ( $show_option_all )
$output .= " \t <option value='0'> $show_option_all </option> \n " ;
2010-05-21 16:35:39 +02:00
if ( $show_option_none ) {
$_selected = selected ( - 1 , $selected , false );
$output .= " \t <option value='-1' $_selected > $show_option_none </option> \n " ;
}
2007-05-29 06:28:10 +02:00
2011-01-01 02:52:03 +01:00
$found_selected = false ;
2008-08-06 22:31:54 +02:00
foreach ( ( array ) $users as $user ) {
2007-05-29 06:28:10 +02:00
$user -> ID = ( int ) $user -> ID ;
2010-05-21 16:35:39 +02:00
$_selected = selected ( $user -> ID , $selected , false );
2011-01-01 02:52:03 +01:00
if ( $_selected )
$found_selected = true ;
$display = ! empty ( $user -> $show ) ? $user -> $show : '(' . $user -> user_login . ')' ;
$output .= " \t <option value=' $user->ID ' $_selected > " . esc_html ( $display ) . " </option> \n " ;
}
if ( $include_selected && ! $found_selected && ( $selected > 0 ) ) {
$user = get_userdata ( $selected );
$_selected = selected ( $user -> ID , $selected , false );
2008-10-25 22:40:58 +02:00
$display = ! empty ( $user -> $show ) ? $user -> $show : '(' . $user -> user_login . ')' ;
2009-05-18 17:11:07 +02:00
$output .= " \t <option value=' $user->ID ' $_selected > " . esc_html ( $display ) . " </option> \n " ;
2007-05-29 06:28:10 +02:00
}
$output .= " </select> " ;
}
$output = apply_filters ( 'wp_dropdown_users' , $output );
if ( $echo )
echo $output ;
return $output ;
}
2008-09-12 06:29:09 +02:00
/**
* Add user meta data as properties to given user object .
*
* The finished user data is cached , but the cache is not used to fill in the
* user data for the given object . Once the function has been used , the cache
2010-03-03 20:08:30 +01:00
* should be used to retrieve user data . The intention is if the current data
* had been cached already , there would be no need to call this function .
2008-09-12 06:29:09 +02:00
*
* @ access private
* @ since 2.5 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param object $user The user data object .
*/
2007-11-27 23:14:53 +01:00
function _fill_user ( & $user ) {
2010-03-03 20:08:30 +01:00
$metavalues = get_user_metavalues ( array ( $user -> ID ));
_fill_single_user ( $user , $metavalues [ $user -> ID ]);
}
/**
* Perform the query to get the $metavalues array ( s ) needed by _fill_user and _fill_many_users
*
* @ since 3.0 . 0
* @ param array $ids User ID numbers list .
* @ return array of arrays . The array is indexed by user_id , containing $metavalues object arrays .
*/
function get_user_metavalues ( $ids ) {
2010-10-04 09:38:32 +02:00
$objects = array ();
$ids = array_map ( 'intval' , $ids );
foreach ( $ids as $id )
$objects [ $id ] = array ();
2010-11-26 22:35:26 +01:00
$metas = update_meta_cache ( 'user' , $ids );
2010-10-04 11:59:53 +02:00
2010-11-26 22:35:26 +01:00
foreach ( $metas as $id => $meta ) {
2010-10-04 11:59:53 +02:00
foreach ( $meta as $key => $metavalues ) {
foreach ( $metavalues as $value ) {
2010-10-04 09:38:32 +02:00
$objects [ $id ][] = ( object ) array ( 'user_id' => $id , 'meta_key' => $key , 'meta_value' => $value );
2010-10-04 11:59:53 +02:00
}
}
2010-10-04 09:38:32 +02:00
}
2010-03-03 20:08:30 +01:00
return $objects ;
}
/**
* Unserialize user metadata , fill $user object , then cache everything .
*
* @ since 3.0 . 0
* @ param object $user The User object .
* @ param array $metavalues An array of objects provided by get_user_metavalues ()
*/
function _fill_single_user ( & $user , & $metavalues ) {
global $wpdb ;
foreach ( $metavalues as $meta ) {
2010-10-04 13:00:36 +02:00
$value = maybe_unserialize ( $meta -> meta_value );
2010-04-29 21:19:21 +02:00
// Keys used as object vars cannot have dashes.
2010-04-30 19:57:30 +02:00
$key = str_replace ( '-' , '' , $meta -> meta_key );
2010-10-04 13:00:36 +02:00
$user -> { $key } = $value ;
2007-11-27 23:14:53 +01:00
}
$level = $wpdb -> prefix . 'user_level' ;
if ( isset ( $user -> { $level } ) )
$user -> user_level = $user -> { $level };
// For backwards compat.
if ( isset ( $user -> first_name ) )
$user -> user_firstname = $user -> first_name ;
if ( isset ( $user -> last_name ) )
$user -> user_lastname = $user -> last_name ;
if ( isset ( $user -> description ) )
$user -> user_description = $user -> description ;
2010-03-03 20:08:30 +01:00
update_user_caches ( $user );
}
/**
* Take an array of user objects , fill them with metas , and cache them .
*
* @ since 3.0 . 0
* @ param array $users User objects
*/
function _fill_many_users ( & $users ) {
$ids = array ();
2010-10-04 09:38:32 +02:00
foreach ( $users as $user_object ) {
2010-03-03 20:08:30 +01:00
$ids [] = $user_object -> ID ;
}
2010-06-30 02:05:18 +02:00
$metas = get_user_metavalues ( $ids );
2010-03-03 20:08:30 +01:00
2010-10-04 09:38:32 +02:00
foreach ( $users as $user_object ) {
if ( isset ( $metas [ $user_object -> ID ]) ) {
2010-06-30 02:05:18 +02:00
_fill_single_user ( $user_object , $metas [ $user_object -> ID ]);
2010-03-03 20:08:30 +01:00
}
}
2007-11-27 23:14:53 +01:00
}
2009-09-14 15:57:48 +02:00
/**
* Sanitize every user field .
*
* If the context is 'raw' , then the user object or array will get minimal santization of the int fields .
*
* @ since 2.3 . 0
* @ uses sanitize_user_field () Used to sanitize the fields .
*
* @ param object | array $user The User Object or Array
* @ param string $context Optional , default is 'display' . How to sanitize user fields .
* @ return object | array The now sanitized User Object or Array ( will be the same type as $user )
*/
function sanitize_user_object ( $user , $context = 'display' ) {
if ( is_object ( $user ) ) {
if ( ! isset ( $user -> ID ) )
$user -> ID = 0 ;
if ( isset ( $user -> data ) )
$vars = get_object_vars ( $user -> data );
else
$vars = get_object_vars ( $user );
foreach ( array_keys ( $vars ) as $field ) {
2010-01-15 23:11:12 +01:00
if ( is_string ( $user -> $field ) || is_numeric ( $user -> $field ) )
2009-12-23 16:02:06 +01:00
$user -> $field = sanitize_user_field ( $field , $user -> $field , $user -> ID , $context );
2009-09-14 15:57:48 +02:00
}
$user -> filter = $context ;
} else {
if ( ! isset ( $user [ 'ID' ]) )
$user [ 'ID' ] = 0 ;
foreach ( array_keys ( $user ) as $field )
$user [ $field ] = sanitize_user_field ( $field , $user [ $field ], $user [ 'ID' ], $context );
$user [ 'filter' ] = $context ;
}
return $user ;
}
/**
* Sanitize user field based on context .
*
* Possible context values are : 'raw' , 'edit' , 'db' , 'display' , 'attribute' and 'js' . The
* 'display' context is used by default . 'attribute' and 'js' contexts are treated like 'display'
* when calling filters .
*
* @ since 2.3 . 0
2010-11-14 16:50:02 +01:00
* @ uses apply_filters () Calls 'edit_$field' and '{$field_no_prefix}_edit_pre' passing $value and
2009-09-14 15:57:48 +02:00
* $user_id if $context == 'edit' and field name prefix == 'user_' .
*
* @ uses apply_filters () Calls 'edit_user_$field' passing $value and $user_id if $context == 'db' .
* @ uses apply_filters () Calls 'pre_$field' passing $value if $context == 'db' and field name prefix == 'user_' .
2010-11-14 16:50:02 +01:00
* @ uses apply_filters () Calls '{$field}_pre' passing $value if $context == 'db' and field name prefix != 'user_' .
2009-09-14 15:57:48 +02:00
*
* @ uses apply_filters () Calls '$field' passing $value , $user_id and $context if $context == anything
* other than 'raw' , 'edit' and 'db' and field name prefix == 'user_' .
* @ uses apply_filters () Calls 'user_$field' passing $value if $context == anything other than 'raw' ,
* 'edit' and 'db' and field name prefix != 'user_' .
*
* @ param string $field The user Object field name .
* @ param mixed $value The user Object value .
* @ param int $user_id user ID .
* @ param string $context How to sanitize user fields . Looks for 'raw' , 'edit' , 'db' , 'display' ,
* 'attribute' and 'js' .
* @ return mixed Sanitized value .
*/
function sanitize_user_field ( $field , $value , $user_id , $context ) {
$int_fields = array ( 'ID' );
if ( in_array ( $field , $int_fields ) )
$value = ( int ) $value ;
if ( 'raw' == $context )
return $value ;
2009-12-23 16:02:06 +01:00
if ( ! is_string ( $value ) && ! is_numeric ( $value ) )
2009-09-14 15:57:48 +02:00
return $value ;
$prefixed = false ;
if ( false !== strpos ( $field , 'user_' ) ) {
$prefixed = true ;
$field_no_prefix = str_replace ( 'user_' , '' , $field );
}
if ( 'edit' == $context ) {
if ( $prefixed ) {
2010-11-14 16:50:02 +01:00
$value = apply_filters ( " edit_ { $field } " , $value , $user_id );
2009-09-14 15:57:48 +02:00
} else {
2010-11-14 16:50:02 +01:00
$value = apply_filters ( " edit_user_ { $field } " , $value , $user_id );
2009-09-14 15:57:48 +02:00
}
if ( 'description' == $field )
2010-12-25 19:10:59 +01:00
$value = esc_html ( $value ); // textarea_escaped?
2009-09-14 15:57:48 +02:00
else
$value = esc_attr ( $value );
} else if ( 'db' == $context ) {
if ( $prefixed ) {
2010-11-14 16:50:02 +01:00
$value = apply_filters ( " pre_ { $field } " , $value );
2009-09-14 15:57:48 +02:00
} else {
2010-11-14 16:50:02 +01:00
$value = apply_filters ( " pre_user_ { $field } " , $value );
2009-09-14 15:57:48 +02:00
}
} else {
// Use display filters by default.
if ( $prefixed )
$value = apply_filters ( $field , $value , $user_id , $context );
else
2010-11-14 16:50:02 +01:00
$value = apply_filters ( " user_ { $field } " , $value , $user_id , $context );
2009-09-14 15:57:48 +02:00
}
if ( 'user_url' == $field )
$value = esc_url ( $value );
if ( 'attribute' == $context )
$value = esc_attr ( $value );
else if ( 'js' == $context )
$value = esc_js ( $value );
return $value ;
}
2010-03-03 20:08:30 +01:00
/**
* Update all user caches
*
* @ since 3.0 . 0
*
* @ param object $user User object to be cached
*/
function update_user_caches ( & $user ) {
wp_cache_add ( $user -> ID , $user , 'users' );
wp_cache_add ( $user -> user_login , $user -> ID , 'userlogins' );
wp_cache_add ( $user -> user_email , $user -> ID , 'useremail' );
wp_cache_add ( $user -> user_nicename , $user -> ID , 'userslugs' );
}
2010-01-19 20:23:11 +01:00
/**
* Clean all user caches
*
2010-03-03 20:08:30 +01:00
* @ since 3.0 . 0
2010-01-19 20:23:11 +01:00
*
* @ param int $id User ID
*/
function clean_user_cache ( $id ) {
$user = new WP_User ( $id );
wp_cache_delete ( $id , 'users' );
wp_cache_delete ( $user -> user_login , 'userlogins' );
wp_cache_delete ( $user -> user_email , 'useremail' );
wp_cache_delete ( $user -> user_nicename , 'userslugs' );
2010-10-18 19:11:00 +02:00
wp_cache_delete ( 'blogs_of_user-' . $id , 'users' );
2010-01-19 20:23:11 +01:00
}
2010-10-27 12:46:24 +02:00
/**
* Checks whether the given username exists .
*
* @ since 2.0 . 0
*
* @ param string $username Username .
* @ return null | int The user ' s ID on success , and null on failure .
*/
function username_exists ( $username ) {
if ( $user = get_userdatabylogin ( $username ) ) {
return $user -> ID ;
} else {
return null ;
}
}
/**
* Checks whether the given email exists .
*
* @ since 2.1 . 0
* @ uses $wpdb
*
* @ param string $email Email .
* @ return bool | int The user ' s ID on success , and false on failure .
*/
function email_exists ( $email ) {
if ( $user = get_user_by_email ( $email ) )
return $user -> ID ;
return false ;
}
/**
* Checks whether an username is valid .
*
* @ since 2.0 . 1
* @ uses apply_filters () Calls 'validate_username' hook on $valid check and $username as parameters
*
* @ param string $username Username .
* @ return bool Whether username given is valid
*/
function validate_username ( $username ) {
$sanitized = sanitize_user ( $username , true );
$valid = ( $sanitized == $username );
return apply_filters ( 'validate_username' , $valid , $username );
}
/**
* Insert an user into the database .
*
* Can update a current user or insert a new user based on whether the user ' s ID
* is present .
*
* Can be used to update the user 's info (see below), set the user' s role , and
* set the user ' s preference on whether they want the rich editor on .
*
* Most of the $userdata array fields have filters associated with the values .
* The exceptions are 'rich_editing' , 'role' , 'jabber' , 'aim' , 'yim' ,
* 'user_registered' , and 'ID' . The filters have the prefix 'pre_user_' followed
* by the field name . An example using 'description' would have the filter
* called , 'pre_user_description' that can be hooked into .
*
* The $userdata array can contain the following fields :
* 'ID' - An integer that will be used for updating an existing user .
* 'user_pass' - A string that contains the plain text password for the user .
* 'user_login' - A string that contains the user ' s username for logging in .
* 'user_nicename' - A string that contains a nicer looking name for the user .
* The default is the user ' s username .
* 'user_url' - A string containing the user 's URL for the user' s web site .
* 'user_email' - A string containing the user ' s email address .
* 'display_name' - A string that will be shown on the site . Defaults to user ' s
2011-05-29 02:56:50 +02:00
* username . It is likely that you will want to change this , for appearance .
2010-10-27 12:46:24 +02:00
* 'nickname' - The user 's nickname, defaults to the user' s username .
* 'first_name' - The user ' s first name .
* 'last_name' - The user ' s last name .
* 'description' - A string containing content about the user .
* 'rich_editing' - A string for whether to enable the rich editor . False
* if not empty .
* 'user_registered' - The date the user registered . Format is 'Y-m-d H:i:s' .
* 'role' - A string used to set the user ' s role .
* 'jabber' - User ' s Jabber account .
* 'aim' - User ' s AOL IM account .
* 'yim' - User ' s Yahoo IM account .
*
* @ since 2.0 . 0
* @ uses $wpdb WordPress database layer .
* @ uses apply_filters () Calls filters for most of the $userdata fields with the prefix 'pre_user' . See note above .
* @ uses do_action () Calls 'profile_update' hook when updating giving the user ' s ID
* @ uses do_action () Calls 'user_register' hook when creating a new user giving the user ' s ID
*
* @ param array $userdata An array of user data .
* @ return int | WP_Error The newly created user ' s ID or a WP_Error object if the user could not be created .
*/
function wp_insert_user ( $userdata ) {
global $wpdb ;
extract ( $userdata , EXTR_SKIP );
// Are we updating or creating?
if ( ! empty ( $ID ) ) {
$ID = ( int ) $ID ;
$update = true ;
$old_user_data = get_userdata ( $ID );
} else {
$update = false ;
// Hash the password
$user_pass = wp_hash_password ( $user_pass );
}
$user_login = sanitize_user ( $user_login , true );
$user_login = apply_filters ( 'pre_user_login' , $user_login );
//Remove any non-printable chars from the login string to see if we have ended up with an empty username
$user_login = trim ( $user_login );
if ( empty ( $user_login ) )
return new WP_Error ( 'empty_user_login' , __ ( 'Cannot create a user with an empty login name.' ) );
if ( ! $update && username_exists ( $user_login ) )
return new WP_Error ( 'existing_user_login' , __ ( 'This username is already registered.' ) );
if ( empty ( $user_nicename ) )
$user_nicename = sanitize_title ( $user_login );
$user_nicename = apply_filters ( 'pre_user_nicename' , $user_nicename );
if ( empty ( $user_url ) )
$user_url = '' ;
$user_url = apply_filters ( 'pre_user_url' , $user_url );
if ( empty ( $user_email ) )
$user_email = '' ;
$user_email = apply_filters ( 'pre_user_email' , $user_email );
if ( ! $update && ! defined ( 'WP_IMPORTING' ) && email_exists ( $user_email ) )
return new WP_Error ( 'existing_user_email' , __ ( 'This email address is already registered.' ) );
if ( empty ( $display_name ) )
$display_name = $user_login ;
$display_name = apply_filters ( 'pre_user_display_name' , $display_name );
if ( empty ( $nickname ) )
$nickname = $user_login ;
$nickname = apply_filters ( 'pre_user_nickname' , $nickname );
if ( empty ( $first_name ) )
$first_name = '' ;
$first_name = apply_filters ( 'pre_user_first_name' , $first_name );
if ( empty ( $last_name ) )
$last_name = '' ;
$last_name = apply_filters ( 'pre_user_last_name' , $last_name );
if ( empty ( $description ) )
$description = '' ;
$description = apply_filters ( 'pre_user_description' , $description );
if ( empty ( $rich_editing ) )
$rich_editing = 'true' ;
if ( empty ( $comment_shortcuts ) )
$comment_shortcuts = 'false' ;
if ( empty ( $admin_color ) )
$admin_color = 'fresh' ;
$admin_color = preg_replace ( '|[^a-z0-9 _.\-@]|i' , '' , $admin_color );
if ( empty ( $use_ssl ) )
$use_ssl = 0 ;
if ( empty ( $user_registered ) )
$user_registered = gmdate ( 'Y-m-d H:i:s' );
2011-01-06 05:11:14 +01:00
2010-12-17 22:48:30 +01:00
if ( empty ( $show_admin_bar_front ) )
$show_admin_bar_front = 'true' ;
2011-01-06 05:11:14 +01:00
2010-12-17 22:48:30 +01:00
if ( empty ( $show_admin_bar_admin ) )
$show_admin_bar_admin = is_multisite () ? 'true' : 'false' ;
2010-10-27 12:46:24 +02:00
$user_nicename_check = $wpdb -> get_var ( $wpdb -> prepare ( " SELECT ID FROM $wpdb->users WHERE user_nicename = %s AND user_login != %s LIMIT 1 " , $user_nicename , $user_login ));
if ( $user_nicename_check ) {
$suffix = 2 ;
while ( $user_nicename_check ) {
$alt_user_nicename = $user_nicename . " - $suffix " ;
$user_nicename_check = $wpdb -> get_var ( $wpdb -> prepare ( " SELECT ID FROM $wpdb->users WHERE user_nicename = %s AND user_login != %s LIMIT 1 " , $alt_user_nicename , $user_login ));
$suffix ++ ;
}
$user_nicename = $alt_user_nicename ;
}
$data = compact ( 'user_pass' , 'user_email' , 'user_url' , 'user_nicename' , 'display_name' , 'user_registered' );
$data = stripslashes_deep ( $data );
if ( $update ) {
$wpdb -> update ( $wpdb -> users , $data , compact ( 'ID' ) );
$user_id = ( int ) $ID ;
} else {
$wpdb -> insert ( $wpdb -> users , $data + compact ( 'user_login' ) );
$user_id = ( int ) $wpdb -> insert_id ;
}
2010-12-17 22:48:30 +01:00
update_user_meta ( $user_id , 'first_name' , $first_name );
update_user_meta ( $user_id , 'last_name' , $last_name );
2010-10-27 12:46:24 +02:00
update_user_meta ( $user_id , 'nickname' , $nickname );
update_user_meta ( $user_id , 'description' , $description );
2010-12-17 22:48:30 +01:00
update_user_meta ( $user_id , 'rich_editing' , $rich_editing );
update_user_meta ( $user_id , 'comment_shortcuts' , $comment_shortcuts );
update_user_meta ( $user_id , 'admin_color' , $admin_color );
update_user_meta ( $user_id , 'use_ssl' , $use_ssl );
update_user_meta ( $user_id , 'show_admin_bar_front' , $show_admin_bar_front );
update_user_meta ( $user_id , 'show_admin_bar_admin' , $show_admin_bar_admin );
2010-10-27 12:46:24 +02:00
$user = new WP_User ( $user_id );
foreach ( _wp_get_user_contactmethods ( $user ) as $method => $name ) {
if ( empty ( $$method ) )
$$method = '' ;
update_user_meta ( $user_id , $method , $$method );
}
if ( isset ( $role ) )
$user -> set_role ( $role );
elseif ( ! $update )
$user -> set_role ( get_option ( 'default_role' ));
wp_cache_delete ( $user_id , 'users' );
wp_cache_delete ( $user_login , 'userlogins' );
if ( $update )
do_action ( 'profile_update' , $user_id , $old_user_data );
else
do_action ( 'user_register' , $user_id );
return $user_id ;
}
/**
* Update an user in the database .
*
* It is possible to update a user 's password by specifying the ' user_pass '
* value in the $userdata parameter array .
*
* If $userdata does not contain an 'ID' key , then a new user will be created
* and the new user ' s ID will be returned .
*
* If current user ' s password is being updated , then the cookies will be
* cleared .
*
* @ since 2.0 . 0
* @ see wp_insert_user () For what fields can be set in $userdata
* @ uses wp_insert_user () Used to update existing user or add new one if user doesn ' t exist already
*
* @ param array $userdata An array of user data .
* @ return int The updated user ' s ID .
*/
function wp_update_user ( $userdata ) {
$ID = ( int ) $userdata [ 'ID' ];
// First, get all of the original fields
$user = get_userdata ( $ID );
// Escape data pulled from DB.
$user = add_magic_quotes ( get_object_vars ( $user ));
// If password is changing, hash it now.
if ( ! empty ( $userdata [ 'user_pass' ]) ) {
$plaintext_pass = $userdata [ 'user_pass' ];
$userdata [ 'user_pass' ] = wp_hash_password ( $userdata [ 'user_pass' ]);
}
wp_cache_delete ( $user [ 'user_email' ], 'useremail' );
// Merge old and new fields with new fields overwriting old ones.
$userdata = array_merge ( $user , $userdata );
$user_id = wp_insert_user ( $userdata );
// Update the cookies if the password changed.
$current_user = wp_get_current_user ();
if ( $current_user -> id == $ID ) {
if ( isset ( $plaintext_pass ) ) {
wp_clear_auth_cookie ();
wp_set_auth_cookie ( $ID );
}
}
return $user_id ;
}
/**
* A simpler way of inserting an user into the database .
*
* Creates a new user with just the username , password , and email . For a more
* detail creation of a user , use wp_insert_user () to specify more infomation .
*
* @ since 2.0 . 0
* @ see wp_insert_user () More complete way to create a new user
*
* @ param string $username The user ' s username .
* @ param string $password The user ' s password .
* @ param string $email The user ' s email ( optional ) .
* @ return int The new user ' s ID .
*/
function wp_create_user ( $username , $password , $email = '' ) {
$user_login = esc_sql ( $username );
$user_email = esc_sql ( $email );
$user_pass = $password ;
$userdata = compact ( 'user_login' , 'user_email' , 'user_pass' );
return wp_insert_user ( $userdata );
}
/**
* Set up the default contact methods
*
* @ access private
* @ since
*
* @ param object $user User data object ( optional )
* @ return array $user_contactmethods Array of contact methods and their labels .
*/
function _wp_get_user_contactmethods ( $user = null ) {
$user_contactmethods = array (
'aim' => __ ( 'AIM' ),
'yim' => __ ( 'Yahoo IM' ),
'jabber' => __ ( 'Jabber / Google Talk' )
);
return apply_filters ( 'user_contactmethods' , $user_contactmethods , $user );
}
2010-10-27 20:16:52 +02:00
?>