2006-06-07 22:22:16 -04:00
< ? php
2008-09-12 00:29:09 -04:00
/**
* WordPress User API
*
* @ package WordPress
*/
/**
* Authenticate user with remember capability .
*
* The credentials is an array that has 'user_login' , 'user_password' , and
* 'remember' indices . If the credentials is not given , then the log in form
* will be assumed and used if set .
*
* The various authentication cookies will be set by this function and will be
* set for a longer period depending on if the 'remember' credential is set to
* true .
*
* @ since 2.5 . 0
*
* @ param array $credentials Optional . User info in order to sign on .
* @ param bool $secure_cookie Optional . Whether to use secure cookie .
* @ return object Either WP_Error on failure , or WP_User on success .
*/
2008-06-11 13:25:55 -04:00
function wp_signon ( $credentials = '' , $secure_cookie = '' ) {
2008-01-22 14:35:19 -05:00
if ( empty ( $credentials ) ) {
if ( ! empty ( $_POST [ 'log' ]) )
$credentials [ 'user_login' ] = $_POST [ 'log' ];
if ( ! empty ( $_POST [ 'pwd' ]) )
$credentials [ 'user_password' ] = $_POST [ 'pwd' ];
if ( ! empty ( $_POST [ 'rememberme' ]) )
$credentials [ 'remember' ] = $_POST [ 'rememberme' ];
}
if ( ! empty ( $credentials [ 'remember' ]) )
$credentials [ 'remember' ] = true ;
else
$credentials [ 'remember' ] = false ;
2009-01-24 17:38:19 -05:00
// TODO do we deprecate the wp_authentication action?
2008-04-16 00:49:19 -04:00
do_action_ref_array ( 'wp_authenticate' , array ( & $credentials [ 'user_login' ], & $credentials [ 'user_password' ]));
2008-06-11 13:25:55 -04:00
if ( '' === $secure_cookie )
2010-03-19 17:15:00 -04:00
$secure_cookie = is_ssl ();
2008-08-09 01:36:14 -04:00
2011-01-05 23:08:23 -05:00
$secure_cookie = apply_filters ( 'secure_signon_cookie' , $secure_cookie , $credentials );
2009-01-24 17:38:19 -05:00
global $auth_secure_cookie ; // XXX ugly hack to pass this to wp_authenticate_cookie
$auth_secure_cookie = $secure_cookie ;
2008-01-22 14:35:19 -05:00
2009-01-24 17:38:19 -05:00
add_filter ( 'authenticate' , 'wp_authenticate_cookie' , 30 , 3 );
2008-06-11 13:25:55 -04:00
2009-01-24 17:38:19 -05:00
$user = wp_authenticate ( $credentials [ 'user_login' ], $credentials [ 'user_password' ]);
2008-01-22 14:35:19 -05:00
2009-01-29 16:30:16 -05:00
if ( is_wp_error ( $user ) ) {
if ( $user -> get_error_codes () == array ( 'empty_username' , 'empty_password' ) ) {
$user = new WP_Error ( '' , '' );
}
2009-01-24 17:38:19 -05:00
return $user ;
2009-01-29 16:30:16 -05:00
}
2009-01-24 17:38:19 -05:00
wp_set_auth_cookie ( $user -> ID , $credentials [ 'remember' ], $secure_cookie );
2011-09-21 16:26:39 -04:00
do_action ( 'wp_login' , $user -> user_login , $user );
2009-01-24 17:38:19 -05:00
return $user ;
}
/**
* Authenticate the user using the username and password .
*/
add_filter ( 'authenticate' , 'wp_authenticate_username_password' , 20 , 3 );
function wp_authenticate_username_password ( $user , $username , $password ) {
if ( is_a ( $user , 'WP_User' ) ) { return $user ; }
if ( empty ( $username ) || empty ( $password ) ) {
2008-01-22 14:35:19 -05:00
$error = new WP_Error ();
2009-01-24 17:38:19 -05:00
if ( empty ( $username ) )
2008-01-22 14:35:19 -05:00
$error -> add ( 'empty_username' , __ ( '<strong>ERROR</strong>: The username field is empty.' ));
2009-01-24 17:38:19 -05:00
if ( empty ( $password ) )
2008-01-22 14:35:19 -05:00
$error -> add ( 'empty_password' , __ ( '<strong>ERROR</strong>: The password field is empty.' ));
2009-01-24 17:38:19 -05:00
2008-01-22 14:35:19 -05:00
return $error ;
}
2010-01-26 15:25:34 -05:00
$userdata = get_user_by ( 'login' , $username );
2009-01-24 17:38:19 -05:00
2010-01-26 15:25:34 -05:00
if ( ! $userdata )
2011-10-20 10:40:11 -04:00
return new WP_Error ( 'invalid_username' , sprintf ( __ ( '<strong>ERROR</strong>: Invalid username. <a href="%s" title="Password Lost and Found">Lost your password</a>?' ), wp_lostpassword_url ()));
2010-01-26 15:25:34 -05:00
2010-01-27 13:11:17 -05:00
if ( is_multisite () ) {
// Is user marked as spam?
if ( 1 == $userdata -> spam )
return new WP_Error ( 'invalid_username' , __ ( '<strong>ERROR</strong>: Your account has been marked as a spammer.' ));
// Is a user's blog marked as spam?
if ( ! is_super_admin ( $userdata -> ID ) && isset ( $userdata -> primary_blog ) ) {
$details = get_blog_details ( $userdata -> primary_blog );
if ( is_object ( $details ) && $details -> spam == 1 )
2010-04-29 23:17:49 -04:00
return new WP_Error ( 'blog_suspended' , __ ( 'Site Suspended.' ));
2010-01-27 13:11:17 -05:00
}
}
2009-01-24 17:38:19 -05:00
2009-03-02 17:25:55 -05:00
$userdata = apply_filters ( 'wp_authenticate_user' , $userdata , $password );
2010-01-26 15:25:34 -05:00
if ( is_wp_error ( $userdata ) )
2009-03-02 17:25:55 -05:00
return $userdata ;
2009-01-24 17:38:19 -05:00
2010-01-26 15:25:34 -05:00
if ( ! wp_check_password ( $password , $userdata -> user_pass , $userdata -> ID ) )
2010-12-08 16:25:52 -05:00
return new WP_Error ( 'incorrect_password' , sprintf ( __ ( '<strong>ERROR</strong>: The password you entered for the username <strong>%1$s</strong> is incorrect. <a href="%2$s" title="Password Lost and Found">Lost your password</a>?' ),
2011-10-20 10:40:11 -04:00
$username , wp_lostpassword_url () ) );
2009-01-24 17:38:19 -05:00
$user = new WP_User ( $userdata -> ID );
return $user ;
}
/**
* Authenticate the user using the WordPress auth cookie .
*/
function wp_authenticate_cookie ( $user , $username , $password ) {
if ( is_a ( $user , 'WP_User' ) ) { return $user ; }
if ( empty ( $username ) && empty ( $password ) ) {
$user_id = wp_validate_auth_cookie ();
if ( $user_id )
return new WP_User ( $user_id );
global $auth_secure_cookie ;
if ( $auth_secure_cookie )
$auth_cookie = SECURE_AUTH_COOKIE ;
else
$auth_cookie = AUTH_COOKIE ;
if ( ! empty ( $_COOKIE [ $auth_cookie ]) )
return new WP_Error ( 'expired_session' , __ ( 'Please log in again.' ));
// If the cookie is not set, be silent.
}
2008-01-22 14:35:19 -05:00
return $user ;
}
2008-09-12 00:29:09 -04:00
/**
* Number of posts user has written .
*
2010-03-18 21:11:21 -04:00
* @ since 3.0 . 0
2008-09-12 00:29:09 -04:00
* @ uses $wpdb WordPress database object for queries .
*
* @ param int $userid User ID .
* @ return int Amount of posts user has written .
*/
2010-03-03 14:08:30 -05:00
function count_user_posts ( $userid ) {
2006-06-07 22:22:16 -04:00
global $wpdb ;
2010-03-03 14:08:30 -05:00
2012-01-05 15:50:54 -05:00
$where = get_posts_by_author_sql ( 'post' , true , $userid );
2010-03-03 14:08:30 -05:00
$count = $wpdb -> get_var ( " SELECT COUNT(*) FROM $wpdb->posts $where " );
2008-09-27 17:26:57 -04:00
return apply_filters ( 'get_usernumposts' , $count , $userid );
2006-06-07 22:22:16 -04:00
}
2010-03-03 14:08:30 -05:00
/**
* Number of posts written by a list of users .
*
* @ since 3.0 . 0
2012-01-06 13:31:43 -05:00
*
* @ param array $users Array of user IDs .
2011-04-28 07:27:39 -04:00
* @ param string | array $post_type Optional . Post type to check . Defaults to post .
2010-03-03 14:08:30 -05:00
* @ return array Amount of posts each user has written .
*/
2012-01-06 13:31:43 -05:00
function count_many_users_posts ( $users , $post_type = 'post' ) {
2010-03-03 14:08:30 -05:00
global $wpdb ;
2010-03-08 09:30:17 -05:00
$count = array ();
2011-04-28 07:27:39 -04:00
if ( empty ( $users ) || ! is_array ( $users ) )
2010-03-08 09:30:17 -05:00
return $count ;
2011-04-28 07:27:39 -04:00
$userlist = implode ( ',' , array_map ( 'absint' , $users ) );
$where = get_posts_by_author_sql ( $post_type );
2010-03-03 14:08:30 -05:00
$result = $wpdb -> get_results ( " SELECT post_author, COUNT(*) FROM $wpdb->posts $where AND post_author IN ( $userlist ) GROUP BY post_author " , ARRAY_N );
2010-03-08 09:30:17 -05:00
foreach ( $result as $row ) {
$count [ $row [ 0 ] ] = $row [ 1 ];
2010-03-03 14:08:30 -05:00
}
2010-03-08 09:30:17 -05:00
foreach ( $users as $id ) {
if ( ! isset ( $count [ $id ] ) )
$count [ $id ] = 0 ;
2010-03-03 14:08:30 -05:00
}
return $count ;
}
2008-09-12 00:29:09 -04:00
/**
* Check that the user login name and password is correct .
*
* @ since 0.71
* @ todo xmlrpc only . Maybe move to xmlrpc . php .
*
* @ param string $user_login User name .
* @ param string $user_pass User password .
* @ return bool False if does not authenticate , true if username and password authenticates .
*/
function user_pass_ok ( $user_login , $user_pass ) {
2008-01-22 14:35:19 -05:00
$user = wp_authenticate ( $user_login , $user_pass );
if ( is_wp_error ( $user ) )
return false ;
return true ;
2006-06-07 22:22:16 -04:00
}
//
// User option functions
//
2010-06-08 11:12:15 -04:00
/**
* Get the current user ' s ID
2010-06-11 16:19:35 -04:00
*
2010-06-08 11:12:15 -04:00
* @ since MU
2010-06-11 16:19:35 -04:00
*
2010-06-08 11:12:15 -04:00
* @ uses wp_get_current_user
*
* @ return int The current user ' s ID
*/
function get_current_user_id () {
$user = wp_get_current_user ();
return ( isset ( $user -> ID ) ? ( int ) $user -> ID : 0 );
}
2008-09-12 00:29:09 -04:00
/**
2010-02-19 05:49:07 -05:00
* Retrieve user option that can be either per Site or per Network .
2008-09-12 00:29:09 -04:00
*
* If the user ID is not given , then the current user will be used instead . If
* the user ID is given , then the user data will be retrieved . The filter for
* the result , will also pass the original option name and finally the user data
* object as the third parameter .
*
2010-02-19 05:49:07 -05:00
* The option will first check for the per site name and then the per Network name .
2008-09-12 00:29:09 -04:00
*
* @ since 2.0 . 0
* @ uses $wpdb WordPress database object for queries .
* @ uses apply_filters () Calls 'get_user_option_$option' hook with result ,
* option parameter , and user data object .
*
* @ param string $option User option name .
* @ param int $user Optional . User ID .
2010-01-06 19:01:52 -05:00
* @ param bool $deprecated Use get_option () to check for an option in the options table .
2008-09-12 00:29:09 -04:00
* @ return mixed
*/
2010-01-06 19:01:52 -05:00
function get_user_option ( $option , $user = 0 , $deprecated = '' ) {
2006-06-07 22:22:16 -04:00
global $wpdb ;
2010-01-06 19:01:52 -05:00
if ( ! empty ( $deprecated ) )
_deprecated_argument ( __FUNCTION__ , '3.0' );
2011-08-24 15:32:59 -04:00
if ( empty ( $user ) )
2006-06-07 22:22:16 -04:00
$user = wp_get_current_user ();
2011-08-24 15:32:59 -04:00
else
$user = new WP_User ( $user );
2010-04-29 16:55:39 -04:00
2011-08-24 15:32:59 -04:00
if ( ! isset ( $user -> ID ) )
return false ;
2010-04-29 16:19:47 -04:00
2011-08-24 15:32:59 -04:00
if ( $user -> has_prop ( $wpdb -> prefix . $option ) ) // Blog specific
$result = $user -> get ( $wpdb -> prefix . $option );
elseif ( $user -> has_prop ( $option ) ) // User specific and cross-blog
$result = $user -> get ( $option );
2008-11-25 13:33:04 -05:00
else
$result = false ;
2008-08-09 01:36:14 -04:00
2008-03-11 17:37:23 -04:00
return apply_filters ( " get_user_option_ { $option } " , $result , $option , $user );
2006-06-07 22:22:16 -04:00
}
2008-09-12 00:29:09 -04:00
/**
* Update user option with global blog capability .
*
* User options are just like user metadata except that they have support for
2009-04-08 14:24:49 -04:00
* global blog options . If the 'global' parameter is false , which it is by default
2008-09-12 00:29:09 -04:00
* it will prepend the WordPress table prefix to the option name .
*
2010-04-23 10:25:05 -04:00
* Deletes the user option if $newvalue is empty .
*
2008-09-12 00:29:09 -04:00
* @ since 2.0 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param int $user_id User ID
* @ param string $option_name User option name .
* @ param mixed $newvalue User option value .
2010-03-11 13:28:31 -05:00
* @ param bool $global Optional . Whether option name is global or blog specific . Default false ( blog specific ) .
2008-09-12 00:29:09 -04:00
* @ return unknown
*/
2006-06-07 22:22:16 -04:00
function update_user_option ( $user_id , $option_name , $newvalue , $global = false ) {
global $wpdb ;
2010-03-02 13:06:14 -05:00
2006-06-07 22:22:16 -04:00
if ( ! $global )
$option_name = $wpdb -> prefix . $option_name ;
2010-04-23 10:25:05 -04:00
2010-04-23 11:32:31 -04:00
// For backward compatibility. See differences between update_user_meta() and deprecated update_usermeta().
2010-04-23 10:25:05 -04:00
// http://core.trac.wordpress.org/ticket/13088
if ( is_null ( $newvalue ) || is_scalar ( $newvalue ) && empty ( $newvalue ) )
return delete_user_meta ( $user_id , $option_name );
2010-02-22 16:25:32 -05:00
return update_user_meta ( $user_id , $option_name , $newvalue );
2006-06-07 22:22:16 -04:00
}
2010-03-11 13:28:31 -05:00
/**
* Delete user option with global blog capability .
*
* User options are just like user metadata except that they have support for
* global blog options . If the 'global' parameter is false , which it is by default
* it will prepend the WordPress table prefix to the option name .
*
* @ since 3.0 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param int $user_id User ID
* @ param string $option_name User option name .
* @ param bool $global Optional . Whether option name is global or blog specific . Default false ( blog specific ) .
* @ return unknown
*/
function delete_user_option ( $user_id , $option_name , $global = false ) {
global $wpdb ;
if ( ! $global )
$option_name = $wpdb -> prefix . $option_name ;
return delete_user_meta ( $user_id , $option_name );
}
2010-08-11 17:54:51 -04:00
/**
* WordPress User Query class .
*
* @ since 3.1 . 0
*/
2010-11-13 13:32:43 -05:00
class WP_User_Query {
2010-08-11 17:54:51 -04:00
/**
2010-08-27 11:41:32 -04:00
* List of found user ids
2010-08-11 17:54:51 -04:00
*
* @ since 3.1 . 0
* @ access private
* @ var array
*/
var $results ;
/**
2010-08-27 11:41:32 -04:00
* Total number of found users for the current query
2010-08-11 17:54:51 -04:00
*
* @ since 3.1 . 0
* @ access private
* @ var int
*/
var $total_users = 0 ;
2010-12-15 18:56:53 -05:00
// SQL clauses
var $query_fields ;
2010-08-11 17:54:51 -04:00
var $query_from ;
var $query_where ;
var $query_orderby ;
var $query_limit ;
2010-08-27 11:41:32 -04:00
/**
* PHP5 constructor
2010-08-11 17:54:51 -04:00
*
* @ since 3.1 . 0
*
* @ param string | array $args The query variables
* @ return WP_User_Query
*/
2010-08-27 11:41:32 -04:00
function __construct ( $query = null ) {
if ( ! empty ( $query ) ) {
$this -> query_vars = wp_parse_args ( $query , array (
2010-10-27 14:16:52 -04:00
'blog_id' => $GLOBALS [ 'blog_id' ],
'role' => '' ,
2010-10-28 11:46:11 -04:00
'meta_key' => '' ,
2010-10-27 14:16:52 -04:00
'meta_value' => '' ,
'meta_compare' => '' ,
'include' => array (),
'exclude' => array (),
2010-09-05 10:35:55 -04:00
'search' => '' ,
2012-02-08 16:48:47 -05:00
'search_columns' => array (),
2010-10-27 14:16:52 -04:00
'orderby' => 'login' ,
'order' => 'ASC' ,
2011-06-07 11:55:05 -04:00
'offset' => '' ,
'number' => '' ,
2010-10-27 14:16:52 -04:00
'count_total' => true ,
2010-09-05 09:31:33 -04:00
'fields' => 'all' ,
2010-12-20 14:02:44 -05:00
'who' => ''
2010-08-27 11:41:32 -04:00
) );
$this -> prepare_query ();
$this -> query ();
}
2010-08-11 17:54:51 -04:00
}
/**
* Prepare the query variables
*
* @ since 3.1 . 0
* @ access private
*/
function prepare_query () {
global $wpdb ;
$qv = & $this -> query_vars ;
2010-12-15 18:56:53 -05:00
if ( is_array ( $qv [ 'fields' ] ) ) {
$qv [ 'fields' ] = array_unique ( $qv [ 'fields' ] );
$this -> query_fields = array ();
foreach ( $qv [ 'fields' ] as $field )
$this -> query_fields [] = $wpdb -> users . '.' . esc_sql ( $field );
$this -> query_fields = implode ( ',' , $this -> query_fields );
2010-12-16 19:38:15 -05:00
} elseif ( 'all' == $qv [ 'fields' ] ) {
$this -> query_fields = " $wpdb->users .* " ;
2010-12-15 18:56:53 -05:00
} else {
$this -> query_fields = " $wpdb->users .ID " ;
}
2011-06-07 11:55:05 -04:00
if ( $this -> query_vars [ 'count_total' ] )
$this -> query_fields = 'SQL_CALC_FOUND_ROWS ' . $this -> query_fields ;
2010-12-15 18:56:53 -05:00
$this -> query_from = " FROM $wpdb->users " ;
$this -> query_where = " WHERE 1=1 " ;
2010-08-11 17:54:51 -04:00
// sorting
2010-12-15 12:18:04 -05:00
if ( in_array ( $qv [ 'orderby' ], array ( 'nicename' , 'email' , 'url' , 'registered' ) ) ) {
2010-08-11 17:54:51 -04:00
$orderby = 'user_' . $qv [ 'orderby' ];
2010-12-15 12:18:04 -05:00
} elseif ( in_array ( $qv [ 'orderby' ], array ( 'user_nicename' , 'user_email' , 'user_url' , 'user_registered' ) ) ) {
2010-12-15 11:51:38 -05:00
$orderby = $qv [ 'orderby' ];
2010-12-14 11:19:08 -05:00
} elseif ( 'name' == $qv [ 'orderby' ] || 'display_name' == $qv [ 'orderby' ] ) {
2010-08-11 17:54:51 -04:00
$orderby = 'display_name' ;
2010-11-03 09:34:04 -04:00
} elseif ( 'post_count' == $qv [ 'orderby' ] ) {
2010-12-17 05:25:27 -05:00
// todo: avoid the JOIN
2010-08-11 17:54:51 -04:00
$where = get_posts_by_author_sql ( 'post' );
$this -> query_from .= " LEFT OUTER JOIN (
SELECT post_author , COUNT ( * ) as post_count
2011-04-13 13:02:08 -04:00
FROM $wpdb -> posts
2010-08-11 17:54:51 -04:00
$where
GROUP BY post_author
2010-10-04 05:43:02 -04:00
) p ON ({ $wpdb -> users } . ID = p . post_author )
2010-08-11 17:54:51 -04:00
" ;
$orderby = 'post_count' ;
2010-12-15 12:18:04 -05:00
} elseif ( 'ID' == $qv [ 'orderby' ] || 'id' == $qv [ 'orderby' ] ) {
2010-11-03 09:34:04 -04:00
$orderby = 'ID' ;
} else {
2010-08-11 17:54:51 -04:00
$orderby = 'user_login' ;
}
$qv [ 'order' ] = strtoupper ( $qv [ 'order' ] );
if ( 'ASC' == $qv [ 'order' ] )
$order = 'ASC' ;
else
$order = 'DESC' ;
2010-12-15 18:56:53 -05:00
$this -> query_orderby = " ORDER BY $orderby $order " ;
2010-08-11 17:54:51 -04:00
// limit
if ( $qv [ 'number' ] ) {
if ( $qv [ 'offset' ] )
2010-12-15 18:56:53 -05:00
$this -> query_limit = $wpdb -> prepare ( " LIMIT %d, %d " , $qv [ 'offset' ], $qv [ 'number' ]);
2010-08-11 17:54:51 -04:00
else
2010-12-15 18:56:53 -05:00
$this -> query_limit = $wpdb -> prepare ( " LIMIT %d " , $qv [ 'number' ]);
2010-08-11 17:54:51 -04:00
}
$search = trim ( $qv [ 'search' ] );
if ( $search ) {
2010-12-30 18:38:21 -05:00
$leading_wild = ( ltrim ( $search , '*' ) != $search );
$trailing_wild = ( rtrim ( $search , '*' ) != $search );
if ( $leading_wild && $trailing_wild )
$wild = 'both' ;
elseif ( $leading_wild )
$wild = 'leading' ;
elseif ( $trailing_wild )
$wild = 'trailing' ;
else
$wild = false ;
if ( $wild )
2010-11-03 15:31:11 -04:00
$search = trim ( $search , '*' );
2010-12-30 18:38:21 -05:00
2012-02-08 16:48:47 -05:00
$search_columns = array ();
if ( $qv [ 'search_columns' ] )
$search_columns = array_intersect ( $qv [ 'search_columns' ], array ( 'ID' , 'user_login' , 'user_email' , 'user_url' , 'user_nicename' ) );
if ( ! $search_columns ) {
if ( false !== strpos ( $search , '@' ) )
$search_columns = array ( 'user_email' );
elseif ( is_numeric ( $search ) )
$search_columns = array ( 'user_login' , 'ID' );
elseif ( preg_match ( '|^https?://|' , $search ) )
$search_columns = array ( 'user_url' );
else
$search_columns = array ( 'user_login' , 'user_nicename' );
}
2010-11-03 15:02:42 -04:00
2010-11-03 15:31:11 -04:00
$this -> query_where .= $this -> get_search_sql ( $search , $search_columns , $wild );
2010-08-11 17:54:51 -04:00
}
2010-12-20 12:25:39 -05:00
$blog_id = absint ( $qv [ 'blog_id' ] );
if ( 'authors' == $qv [ 'who' ] && $blog_id ) {
$qv [ 'meta_key' ] = $wpdb -> get_blog_prefix ( $blog_id ) . 'user_level' ;
2011-04-21 14:13:03 -04:00
$qv [ 'meta_value' ] = 0 ;
2010-12-20 12:25:39 -05:00
$qv [ 'meta_compare' ] = '!=' ;
$qv [ 'blog_id' ] = $blog_id = 0 ; // Prevent extra meta query
}
2010-08-11 17:54:51 -04:00
$role = trim ( $qv [ 'role' ] );
2010-08-26 20:18:57 -04:00
2010-12-13 06:44:53 -05:00
if ( $blog_id && ( $role || is_multisite () ) ) {
2010-09-05 10:35:55 -04:00
$cap_meta_query = array ();
2010-10-04 14:26:26 -04:00
$cap_meta_query [ 'key' ] = $wpdb -> get_blog_prefix ( $blog_id ) . 'capabilities' ;
2010-09-05 09:31:33 -04:00
2010-09-05 10:35:55 -04:00
if ( $role ) {
2010-10-28 09:26:16 -04:00
$cap_meta_query [ 'value' ] = '"' . $role . '"' ;
2010-10-04 14:26:26 -04:00
$cap_meta_query [ 'compare' ] = 'like' ;
2010-09-05 10:35:55 -04:00
}
2010-08-26 20:18:57 -04:00
2010-10-09 06:48:13 -04:00
$qv [ 'meta_query' ][] = $cap_meta_query ;
2010-10-04 14:26:26 -04:00
}
2010-09-05 09:31:33 -04:00
2011-04-25 13:27:35 -04:00
$meta_query = new WP_Meta_Query ();
$meta_query -> parse_query_vars ( $qv );
if ( ! empty ( $meta_query -> queries ) ) {
$clauses = $meta_query -> get_sql ( 'user' , $wpdb -> users , 'ID' , $this );
2010-10-28 13:02:37 -04:00
$this -> query_from .= $clauses [ 'join' ];
$this -> query_where .= $clauses [ 'where' ];
2011-06-07 11:55:05 -04:00
if ( 'OR' == $meta_query -> relation )
$this -> query_fields = 'DISTINCT ' . $this -> query_fields ;
2010-10-09 08:18:52 -04:00
}
2010-08-11 17:54:51 -04:00
2010-10-09 08:18:52 -04:00
if ( ! empty ( $qv [ 'include' ] ) ) {
2010-08-11 17:54:51 -04:00
$ids = implode ( ',' , wp_parse_id_list ( $qv [ 'include' ] ) );
$this -> query_where .= " AND $wpdb->users .ID IN ( $ids ) " ;
2010-12-17 16:48:30 -05:00
} elseif ( ! empty ( $qv [ 'exclude' ]) ) {
2010-08-11 17:54:51 -04:00
$ids = implode ( ',' , wp_parse_id_list ( $qv [ 'exclude' ] ) );
$this -> query_where .= " AND $wpdb->users .ID NOT IN ( $ids ) " ;
}
do_action_ref_array ( 'pre_user_query' , array ( & $this ) );
}
/**
* Execute the query , with the current variables
*
* @ since 3.1 . 0
* @ access private
*/
function query () {
global $wpdb ;
2011-02-09 12:35:36 -05:00
2010-12-16 19:38:15 -05:00
if ( is_array ( $this -> query_vars [ 'fields' ] ) || 'all' == $this -> query_vars [ 'fields' ] ) {
2010-12-15 18:56:53 -05:00
$this -> results = $wpdb -> get_results ( " SELECT $this->query_fields $this->query_from $this->query_where $this->query_orderby $this->query_limit " );
} else {
$this -> results = $wpdb -> get_col ( " SELECT $this->query_fields $this->query_from $this->query_where $this->query_orderby $this->query_limit " );
}
2011-02-09 12:35:36 -05:00
2011-01-25 14:20:20 -05:00
if ( $this -> query_vars [ 'count_total' ] )
2011-06-07 11:55:05 -04:00
$this -> total_users = $wpdb -> get_var ( apply_filters ( 'found_users_query' , 'SELECT FOUND_ROWS()' ) );
2010-08-11 17:54:51 -04:00
if ( ! $this -> results )
return ;
2010-12-16 19:38:15 -05:00
if ( 'all_with_meta' == $this -> query_vars [ 'fields' ] ) {
cache_users ( $this -> results );
2010-08-11 17:54:51 -04:00
$r = array ();
foreach ( $this -> results as $userid )
2010-09-05 10:35:55 -04:00
$r [ $userid ] = new WP_User ( $userid , '' , $this -> query_vars [ 'blog_id' ] );
2010-08-11 17:54:51 -04:00
$this -> results = $r ;
}
}
2010-11-13 13:18:45 -05:00
/*
* Used internally to generate an SQL string for searching across multiple columns
*
* @ access protected
* @ since 3.1 . 0
*
* @ param string $string
* @ param array $cols
2010-12-30 18:38:21 -05:00
* @ param bool $wild Whether to allow wildcard searches . Default is false for Network Admin , true for
* single site . Single site allows leading and trailing wildcards , Network Admin only trailing .
2010-11-13 13:18:45 -05:00
* @ return string
*/
function get_search_sql ( $string , $cols , $wild = false ) {
$string = esc_sql ( $string );
$searches = array ();
2010-12-30 18:38:21 -05:00
$leading_wild = ( 'leading' == $wild || 'both' == $wild ) ? '%' : '' ;
$trailing_wild = ( 'trailing' == $wild || 'both' == $wild ) ? '%' : '' ;
2010-11-13 13:18:45 -05:00
foreach ( $cols as $col ) {
if ( 'ID' == $col )
$searches [] = " $col = ' $string ' " ;
else
2010-12-30 18:38:21 -05:00
$searches [] = " $col LIKE ' $leading_wild " . like_escape ( $string ) . " $trailing_wild ' " ;
2010-11-13 13:18:45 -05:00
}
return ' AND (' . implode ( ' OR ' , $searches ) . ')' ;
}
2010-08-11 17:54:51 -04:00
/**
* Return the list of users
*
* @ since 3.1 . 0
* @ access public
*
* @ return array
*/
function get_results () {
return $this -> results ;
}
/**
* Return the total number of users for the current query
*
* @ since 3.1 . 0
* @ access public
*
* @ return array
*/
function get_total () {
return $this -> total_users ;
}
}
/**
* Retrieve list of users matching criteria .
*
* @ since 3.1 . 0
* @ uses $wpdb
* @ uses WP_User_Query See for default arguments and information .
*
2010-10-20 13:21:06 -04:00
* @ param array $args Optional .
2010-08-11 17:54:51 -04:00
* @ return array List of users .
*/
2010-10-20 13:21:06 -04:00
function get_users ( $args = array () ) {
2010-08-11 17:54:51 -04:00
$args = wp_parse_args ( $args );
$args [ 'count_total' ] = false ;
$user_search = new WP_User_Query ( $args );
return ( array ) $user_search -> get_results ();
}
2010-09-27 16:26:36 -04:00
/**
2010-10-18 13:11:00 -04:00
* Get the blogs a user belongs to .
2010-09-27 16:26:36 -04:00
*
2010-10-18 13:11:00 -04:00
* @ since 3.0 . 0
2010-09-27 16:26:36 -04:00
*
2011-10-10 15:50:08 -04:00
* @ param int $user_id User ID
* @ param bool $all Whether to retrieve all blogs , or only blogs that are not marked as deleted , archived , or spam .
2010-10-18 13:11:00 -04:00
* @ return array A list of the user ' s blogs . False if the user was not found or an empty array if the user has no blogs .
2010-09-27 16:26:36 -04:00
*/
2011-10-10 15:50:08 -04:00
function get_blogs_of_user ( $user_id , $all = false ) {
2010-09-27 16:26:36 -04:00
global $wpdb ;
2011-11-07 18:05:13 -05:00
$user_id = ( int ) $user_id ;
// Logged out users can't have blogs
if ( empty ( $user_id ) )
return false ;
$keys = get_user_meta ( $user_id );
if ( empty ( $keys ) )
return false ;
2011-10-10 15:50:08 -04:00
if ( ! is_multisite () ) {
2010-10-28 11:46:11 -04:00
$blog_id = get_current_blog_id ();
2011-08-17 13:49:57 -04:00
$blogs = array ( $blog_id => new stdClass );
2010-09-27 16:26:36 -04:00
$blogs [ $blog_id ] -> userblog_id = $blog_id ;
$blogs [ $blog_id ] -> blogname = get_option ( 'blogname' );
$blogs [ $blog_id ] -> domain = '' ;
$blogs [ $blog_id ] -> path = '' ;
$blogs [ $blog_id ] -> site_id = 1 ;
$blogs [ $blog_id ] -> siteurl = get_option ( 'siteurl' );
return $blogs ;
}
2011-10-10 15:50:08 -04:00
$blogs = array ();
if ( isset ( $keys [ $wpdb -> base_prefix . 'capabilities' ] ) && defined ( 'MULTISITE' ) ) {
$blog = get_blog_details ( 1 );
if ( $blog && isset ( $blog -> domain ) && ( $all || ( ! $blog -> archived && ! $blog -> spam && ! $blog -> deleted ) ) ) {
$blogs [ 1 ] = ( object ) array (
'userblog_id' => 1 ,
'blogname' => $blog -> blogname ,
'domain' => $blog -> domain ,
'path' => $blog -> path ,
'site_id' => $blog -> site_id ,
'siteurl' => $blog -> siteurl ,
);
2010-11-06 14:45:20 -04:00
}
2011-10-10 15:50:08 -04:00
unset ( $keys [ $wpdb -> base_prefix . 'capabilities' ] );
2010-11-06 14:45:20 -04:00
}
2011-10-10 15:50:08 -04:00
$keys = array_keys ( $keys );
foreach ( $keys as $key ) {
if ( 'capabilities' !== substr ( $key , - 12 ) )
continue ;
2011-12-30 18:22:09 -05:00
if ( $wpdb -> base_prefix && 0 !== strpos ( $key , $wpdb -> base_prefix ) )
2011-10-10 15:50:08 -04:00
continue ;
$blog_id = str_replace ( array ( $wpdb -> base_prefix , '_capabilities' ), '' , $key );
if ( ! is_numeric ( $blog_id ) )
continue ;
2010-10-18 13:11:00 -04:00
2011-10-10 15:50:08 -04:00
$blog_id = ( int ) $blog_id ;
2010-10-18 13:11:00 -04:00
$blog = get_blog_details ( $blog_id );
2011-10-10 15:50:08 -04:00
if ( $blog && isset ( $blog -> domain ) && ( $all || ( ! $blog -> archived && ! $blog -> spam && ! $blog -> deleted ) ) ) {
$blogs [ $blog_id ] = ( object ) array (
'userblog_id' => $blog_id ,
'blogname' => $blog -> blogname ,
'domain' => $blog -> domain ,
'path' => $blog -> path ,
'site_id' => $blog -> site_id ,
'siteurl' => $blog -> siteurl ,
);
2010-10-18 13:11:00 -04:00
}
2010-09-27 16:26:36 -04:00
}
2011-10-10 15:50:08 -04:00
return apply_filters ( 'get_blogs_of_user' , $blogs , $user_id , $all );
2010-09-27 16:26:36 -04:00
}
/**
2011-10-19 18:35:15 -04:00
* Find out whether a user is a member of a given blog .
2010-09-27 16:26:36 -04:00
*
2011-10-19 18:35:15 -04:00
* @ since MU 1.1
* @ uses get_blogs_of_user ()
2010-09-27 16:26:36 -04:00
*
2012-01-06 06:42:00 -05:00
* @ param int $user_id Optional . The unique ID of the user . Defaults to the current user .
* @ param int $blog_id Optional . ID of the blog to check . Defaults to the current site .
2011-10-19 18:35:15 -04:00
* @ return bool
2010-09-27 16:26:36 -04:00
*/
2011-10-19 18:35:15 -04:00
function is_user_member_of_blog ( $user_id = 0 , $blog_id = 0 ) {
$user_id = ( int ) $user_id ;
$blog_id = ( int ) $blog_id ;
2010-10-19 03:48:22 -04:00
2011-10-19 18:35:15 -04:00
if ( empty ( $user_id ) )
$user_id = get_current_user_id ();
2010-09-27 16:26:36 -04:00
2011-11-07 18:07:07 -05:00
if ( empty ( $blog_id ) )
$blog_id = get_current_blog_id ();
2010-09-27 16:26:36 -04:00
2011-10-19 18:35:15 -04:00
$blogs = get_blogs_of_user ( $user_id );
if ( is_array ( $blogs ) )
return array_key_exists ( $blog_id , $blogs );
else
return false ;
2010-09-27 16:26:36 -04:00
}
2008-09-12 00:29:09 -04:00
/**
2010-02-22 13:35:35 -05:00
* Add meta data field to a user .
2008-09-12 00:29:09 -04:00
*
2011-04-28 11:24:49 -04:00
* Post meta data is called " Custom Fields " on the Administration Screens .
2010-02-22 13:35:35 -05:00
*
* @ since 3.0 . 0
* @ uses add_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / add_user_meta
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* @ param int $user_id Post ID .
2010-09-07 07:21:11 -04:00
* @ param string $meta_key Metadata name .
* @ param mixed $meta_value Metadata value .
2010-02-22 13:35:35 -05:00
* @ param bool $unique Optional , default is false . Whether the same key should not be added .
* @ return bool False for failure . True for success .
2008-09-12 00:29:09 -04:00
*/
2010-02-22 13:35:35 -05:00
function add_user_meta ( $user_id , $meta_key , $meta_value , $unique = false ) {
return add_metadata ( 'user' , $user_id , $meta_key , $meta_value , $unique );
2006-06-07 22:22:16 -04:00
}
2008-09-12 00:29:09 -04:00
/**
2010-02-22 13:35:35 -05:00
* Remove metadata matching criteria from a user .
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* You can match based on the key , or key and value . Removing based on key and
* value , will keep from removing duplicate metadata with the same key . It also
* allows removing all metadata matching key , if needed .
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* @ since 3.0 . 0
* @ uses delete_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / delete_user_meta
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* @ param int $user_id user ID
* @ param string $meta_key Metadata name .
* @ param mixed $meta_value Optional . Metadata value .
* @ return bool False for failure . True for success .
2008-09-12 00:29:09 -04:00
*/
2010-02-22 13:35:35 -05:00
function delete_user_meta ( $user_id , $meta_key , $meta_value = '' ) {
return delete_metadata ( 'user' , $user_id , $meta_key , $meta_value );
}
2006-06-07 22:22:16 -04:00
2010-02-22 13:35:35 -05:00
/**
* Retrieve user meta field for a user .
*
* @ since 3.0 . 0
* @ uses get_metadata ()
* @ link http :// codex . wordpress . org / Function_Reference / get_user_meta
*
* @ param int $user_id Post ID .
* @ param string $key The meta key to retrieve .
* @ param bool $single Whether to return a single value .
* @ return mixed Will be an array if $single is false . Will be value of meta data field if $single
* is true .
*/
2011-08-24 15:32:59 -04:00
function get_user_meta ( $user_id , $key = '' , $single = false ) {
2010-02-22 13:35:35 -05:00
return get_metadata ( 'user' , $user_id , $key , $single );
2006-06-07 22:22:16 -04:00
}
2008-09-12 00:29:09 -04:00
/**
2010-02-22 13:35:35 -05:00
* Update user meta field based on user ID .
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* Use the $prev_value parameter to differentiate between meta fields with the
* same key and user ID .
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* If the meta field for the user does not exist , it will be added .
2008-09-12 00:29:09 -04:00
*
2010-03-26 15:13:36 -04:00
* @ since 3.0 . 0
2010-02-22 13:35:35 -05:00
* @ uses update_metadata
* @ link http :// codex . wordpress . org / Function_Reference / update_user_meta
2008-09-12 00:29:09 -04:00
*
2010-02-22 13:35:35 -05:00
* @ param int $user_id Post ID .
2010-09-07 07:21:11 -04:00
* @ param string $meta_key Metadata key .
* @ param mixed $meta_value Metadata value .
2010-02-22 13:35:35 -05:00
* @ param mixed $prev_value Optional . Previous value to check before removing .
* @ return bool False on failure , true if success .
2008-09-12 00:29:09 -04:00
*/
2010-02-22 13:35:35 -05:00
function update_user_meta ( $user_id , $meta_key , $meta_value , $prev_value = '' ) {
return update_metadata ( 'user' , $user_id , $meta_key , $meta_value , $prev_value );
2006-06-07 22:22:16 -04:00
}
2010-03-03 14:08:30 -05:00
/**
* Count number of users who have each of the user roles .
*
* Assumes there are neither duplicated nor orphaned capabilities meta_values .
2011-12-13 18:45:31 -05:00
* Assumes role names are unique phrases . Same assumption made by WP_User_Query :: prepare_query ()
2010-03-03 14:08:30 -05:00
* Using $strategy = 'time' this is CPU - intensive and should handle around 10 ^ 7 users .
* Using $strategy = 'memory' this is memory - intensive and should handle around 10 ^ 5 users , but see WP Bug #12257.
*
* @ since 3.0 . 0
* @ param string $strategy 'time' or 'memory'
* @ return array Includes a grand total and an array of counts indexed by role strings .
*/
function count_users ( $strategy = 'time' ) {
2010-10-28 11:46:11 -04:00
global $wpdb , $wp_roles ;
2010-03-03 14:08:30 -05:00
// Initialize
2010-10-28 11:46:11 -04:00
$id = get_current_blog_id ();
2010-03-03 14:08:30 -05:00
$blog_prefix = $wpdb -> get_blog_prefix ( $id );
$result = array ();
2010-04-15 17:24:52 -04:00
if ( 'time' == $strategy ) {
global $wp_roles ;
if ( ! isset ( $wp_roles ) )
$wp_roles = new WP_Roles ();
2010-03-03 14:08:30 -05:00
$avail_roles = $wp_roles -> get_names ();
// Build a CPU-intensive query that will return concise information.
$select_count = array ();
foreach ( $avail_roles as $this_role => $name ) {
2012-01-20 11:34:26 -05:00
$select_count [] = " COUNT(NULLIF(`meta_value` LIKE '% \" " . like_escape ( $this_role ) . " \" %', false)) " ;
2010-03-03 14:08:30 -05:00
}
$select_count = implode ( ', ' , $select_count );
// Add the meta_value index to the selection list, then run the query.
$row = $wpdb -> get_row ( " SELECT $select_count , COUNT(*) FROM $wpdb->usermeta WHERE meta_key = ' { $blog_prefix } capabilities' " , ARRAY_N );
// Run the previous loop again to associate results with role names.
$col = 0 ;
$role_counts = array ();
foreach ( $avail_roles as $this_role => $name ) {
$count = ( int ) $row [ $col ++ ];
if ( $count > 0 ) {
$role_counts [ $this_role ] = $count ;
}
}
// Get the meta_value index from the end of the result set.
$total_users = ( int ) $row [ $col ];
$result [ 'total_users' ] = $total_users ;
$result [ 'avail_roles' ] =& $role_counts ;
} else {
$avail_roles = array ();
$users_of_blog = $wpdb -> get_col ( " SELECT meta_value FROM $wpdb->usermeta WHERE meta_key = ' { $blog_prefix } capabilities' " );
foreach ( $users_of_blog as $caps_meta ) {
$b_roles = unserialize ( $caps_meta );
if ( is_array ( $b_roles ) ) {
foreach ( $b_roles as $b_role => $val ) {
if ( isset ( $avail_roles [ $b_role ]) ) {
$avail_roles [ $b_role ] ++ ;
} else {
$avail_roles [ $b_role ] = 1 ;
}
}
}
}
$result [ 'total_users' ] = count ( $users_of_blog );
$result [ 'avail_roles' ] =& $avail_roles ;
}
return $result ;
}
2006-06-07 22:22:16 -04:00
//
// Private helper functions
//
2008-09-12 00:29:09 -04:00
/**
2010-03-17 00:39:50 -04:00
* Set up global user vars .
2008-09-12 00:29:09 -04:00
*
2010-04-14 18:06:03 -04:00
* Used by wp_set_current_user () for back compat . Might be deprecated in the future .
2008-09-12 00:29:09 -04:00
*
* @ since 2.0 . 4
* @ global string $userdata User description .
* @ global string $user_login The user username for logging in
* @ global int $user_level The level of the user
* @ global int $user_ID The ID of the user
* @ global string $user_email The email address of the user
* @ global string $user_url The url in the user ' s profile
* @ global string $user_pass_md5 MD5 of the user ' s password
* @ global string $user_identity The display name of the user
*
2010-03-17 00:39:50 -04:00
* @ param int $for_user_id Optional . User ID to set up global data .
2008-09-12 00:29:09 -04:00
*/
2009-11-27 13:17:44 -05:00
function setup_userdata ( $for_user_id = '' ) {
2009-11-30 21:06:02 -05:00
global $user_login , $userdata , $user_level , $user_ID , $user_email , $user_url , $user_pass_md5 , $user_identity ;
2006-06-07 22:22:16 -04:00
2009-11-27 13:17:44 -05:00
if ( '' == $for_user_id )
2006-06-07 22:22:16 -04:00
$user = wp_get_current_user ();
2006-11-19 02:56:05 -05:00
else
2009-11-27 13:17:44 -05:00
$user = new WP_User ( $for_user_id );
2006-06-07 22:22:16 -04:00
2011-12-21 15:07:54 -05:00
$userdata = $user ;
2010-05-11 19:02:40 -04:00
$user_ID = ( int ) $user -> ID ;
$user_level = ( int ) isset ( $user -> user_level ) ? $user -> user_level : 0 ;
if ( 0 == $user -> ID ) {
$user_login = $user_email = $user_url = $user_pass_md5 = $user_identity = '' ;
2006-06-07 22:22:16 -04:00
return ;
2010-05-11 19:02:40 -04:00
}
2006-06-07 22:22:16 -04:00
$user_login = $user -> user_login ;
$user_email = $user -> user_email ;
$user_url = $user -> user_url ;
$user_pass_md5 = md5 ( $user -> user_pass );
$user_identity = $user -> display_name ;
}
2008-09-12 00:29:09 -04:00
/**
* Create dropdown HTML content of users .
*
* The content can either be displayed , which it is by default or retrieved by
* setting the 'echo' argument . The 'include' and 'exclude' arguments do not
* need to be used ; all users will be displayed in that case . Only one can be
* used , either 'include' or 'exclude' , but not both .
*
* The available arguments are as follows :
* < ol >
* < li > show_option_all - Text to show all and whether HTML option exists .</ li >
2010-12-14 11:19:08 -05:00
* < li > show_option_none - Text for show none and whether HTML option exists .</ li >
2010-12-20 12:25:39 -05:00
* < li > hide_if_only_one_author - Don ' t create the dropdown if there is only one user .</ li >
2010-12-14 11:19:08 -05:00
* < li > orderby - SQL order by clause for what order the users appear . Default is 'display_name' .</ li >
2008-09-12 00:29:09 -04:00
* < li > order - Default is 'ASC' . Can also be 'DESC' .</ li >
* < li > include - User IDs to include .</ li >
* < li > exclude - User IDs to exclude .</ li >
2010-03-02 13:36:49 -05:00
* < li > multi - Default is 'false' . Whether to skip the ID attribute on the 'select' element . A 'true' value is overridden when id argument is set .</ li >
2010-12-14 11:19:08 -05:00
* < li > show - Default is 'display_name' . User table column to display . If the selected item is empty then the user_login will be displayed in parentheses </ li >
2008-09-12 00:29:09 -04:00
* < li > echo - Default is '1' . Whether to display or retrieve content .</ li >
* < li > selected - Which User ID is selected .</ li >
2010-12-31 20:52:03 -05:00
* < li > include_selected - Always include the selected user ID in the dropdown . Default is false .</ li >
2008-09-12 00:29:09 -04:00
* < li > name - Default is 'user' . Name attribute of select element .</ li >
2010-03-02 13:36:49 -05:00
* < li > id - Default is the value of the 'name' parameter . ID attribute of select element .</ li >
2008-09-12 00:29:09 -04:00
* < li > class - Class attribute of select element .</ li >
2010-02-13 15:17:15 -05:00
* < li > blog_id - ID of blog ( Multisite only ) . Defaults to ID of current blog .</ li >
2011-12-13 18:45:31 -05:00
* < li > who - Which users to query . Currently only 'authors' is supported . Default is all users .</ li >
2008-09-12 00:29:09 -04:00
* </ ol >
*
* @ since 2.3 . 0
* @ uses $wpdb WordPress database object for queries
*
* @ param string | array $args Optional . Override defaults .
* @ return string | null Null on display . String of HTML content on retrieve .
*/
2007-05-29 00:28:10 -04:00
function wp_dropdown_users ( $args = '' ) {
$defaults = array (
2010-12-20 12:25:39 -05:00
'show_option_all' => '' , 'show_option_none' => '' , 'hide_if_only_one_author' => '' ,
2007-05-29 00:28:10 -04:00
'orderby' => 'display_name' , 'order' => 'ASC' ,
2008-09-30 06:30:56 -04:00
'include' => '' , 'exclude' => '' , 'multi' => 0 ,
2007-05-29 00:28:10 -04:00
'show' => 'display_name' , 'echo' => 1 ,
2010-12-20 12:25:39 -05:00
'selected' => 0 , 'name' => 'user' , 'class' => '' , 'id' => '' ,
2010-12-31 20:52:03 -05:00
'blog_id' => $GLOBALS [ 'blog_id' ], 'who' => '' , 'include_selected' => false
2007-05-29 00:28:10 -04:00
);
2007-06-13 22:25:30 -04:00
2007-05-29 00:28:10 -04:00
$defaults [ 'selected' ] = is_author () ? get_query_var ( 'author' ) : 0 ;
2007-06-13 22:25:30 -04:00
2007-05-29 00:28:10 -04:00
$r = wp_parse_args ( $args , $defaults );
2007-06-14 18:45:40 -04:00
extract ( $r , EXTR_SKIP );
2007-05-29 00:28:10 -04:00
2010-12-20 12:25:39 -05:00
$query_args = wp_array_slice_assoc ( $r , array ( 'blog_id' , 'include' , 'exclude' , 'orderby' , 'order' , 'who' ) );
2010-12-15 18:56:53 -05:00
$query_args [ 'fields' ] = array ( 'ID' , $show );
$users = get_users ( $query_args );
2007-05-29 00:28:10 -04:00
$output = '' ;
2010-12-20 12:25:39 -05:00
if ( ! empty ( $users ) && ( empty ( $hide_if_only_one_author ) || count ( $users ) > 1 ) ) {
2010-03-02 13:36:49 -05:00
$name = esc_attr ( $name );
if ( $multi && ! $id )
$id = '' ;
else
2010-05-26 00:01:14 -04:00
$id = $id ? " id=' " . esc_attr ( $id ) . " ' " : " id=' $name ' " ;
2008-09-30 06:30:56 -04:00
2010-03-02 13:36:49 -05:00
$output = " <select name=' { $name } ' { $id } class=' $class '> \n " ;
2007-05-29 00:28:10 -04:00
if ( $show_option_all )
$output .= " \t <option value='0'> $show_option_all </option> \n " ;
2010-05-21 10:35:39 -04:00
if ( $show_option_none ) {
$_selected = selected ( - 1 , $selected , false );
$output .= " \t <option value='-1' $_selected > $show_option_none </option> \n " ;
}
2007-05-29 00:28:10 -04:00
2010-12-31 20:52:03 -05:00
$found_selected = false ;
2008-08-06 16:31:54 -04:00
foreach ( ( array ) $users as $user ) {
2007-05-29 00:28:10 -04:00
$user -> ID = ( int ) $user -> ID ;
2010-05-21 10:35:39 -04:00
$_selected = selected ( $user -> ID , $selected , false );
2010-12-31 20:52:03 -05:00
if ( $_selected )
$found_selected = true ;
$display = ! empty ( $user -> $show ) ? $user -> $show : '(' . $user -> user_login . ')' ;
$output .= " \t <option value=' $user->ID ' $_selected > " . esc_html ( $display ) . " </option> \n " ;
}
if ( $include_selected && ! $found_selected && ( $selected > 0 ) ) {
$user = get_userdata ( $selected );
$_selected = selected ( $user -> ID , $selected , false );
2008-10-25 16:40:58 -04:00
$display = ! empty ( $user -> $show ) ? $user -> $show : '(' . $user -> user_login . ')' ;
2009-05-18 11:11:07 -04:00
$output .= " \t <option value=' $user->ID ' $_selected > " . esc_html ( $display ) . " </option> \n " ;
2007-05-29 00:28:10 -04:00
}
$output .= " </select> " ;
}
$output = apply_filters ( 'wp_dropdown_users' , $output );
if ( $echo )
echo $output ;
return $output ;
}
2009-09-14 09:57:48 -04:00
/**
* Sanitize user field based on context .
*
* Possible context values are : 'raw' , 'edit' , 'db' , 'display' , 'attribute' and 'js' . The
* 'display' context is used by default . 'attribute' and 'js' contexts are treated like 'display'
* when calling filters .
*
* @ since 2.3 . 0
2010-11-14 10:50:02 -05:00
* @ uses apply_filters () Calls 'edit_$field' and '{$field_no_prefix}_edit_pre' passing $value and
2009-09-14 09:57:48 -04:00
* $user_id if $context == 'edit' and field name prefix == 'user_' .
*
* @ uses apply_filters () Calls 'edit_user_$field' passing $value and $user_id if $context == 'db' .
* @ uses apply_filters () Calls 'pre_$field' passing $value if $context == 'db' and field name prefix == 'user_' .
2010-11-14 10:50:02 -05:00
* @ uses apply_filters () Calls '{$field}_pre' passing $value if $context == 'db' and field name prefix != 'user_' .
2009-09-14 09:57:48 -04:00
*
* @ uses apply_filters () Calls '$field' passing $value , $user_id and $context if $context == anything
* other than 'raw' , 'edit' and 'db' and field name prefix == 'user_' .
* @ uses apply_filters () Calls 'user_$field' passing $value if $context == anything other than 'raw' ,
* 'edit' and 'db' and field name prefix != 'user_' .
*
* @ param string $field The user Object field name .
* @ param mixed $value The user Object value .
* @ param int $user_id user ID .
* @ param string $context How to sanitize user fields . Looks for 'raw' , 'edit' , 'db' , 'display' ,
* 'attribute' and 'js' .
* @ return mixed Sanitized value .
*/
function sanitize_user_field ( $field , $value , $user_id , $context ) {
$int_fields = array ( 'ID' );
if ( in_array ( $field , $int_fields ) )
$value = ( int ) $value ;
if ( 'raw' == $context )
return $value ;
2009-12-23 10:02:06 -05:00
if ( ! is_string ( $value ) && ! is_numeric ( $value ) )
2009-09-14 09:57:48 -04:00
return $value ;
$prefixed = false ;
if ( false !== strpos ( $field , 'user_' ) ) {
$prefixed = true ;
$field_no_prefix = str_replace ( 'user_' , '' , $field );
}
if ( 'edit' == $context ) {
if ( $prefixed ) {
2010-11-14 10:50:02 -05:00
$value = apply_filters ( " edit_ { $field } " , $value , $user_id );
2009-09-14 09:57:48 -04:00
} else {
2010-11-14 10:50:02 -05:00
$value = apply_filters ( " edit_user_ { $field } " , $value , $user_id );
2009-09-14 09:57:48 -04:00
}
if ( 'description' == $field )
2010-12-25 13:10:59 -05:00
$value = esc_html ( $value ); // textarea_escaped?
2009-09-14 09:57:48 -04:00
else
$value = esc_attr ( $value );
} else if ( 'db' == $context ) {
if ( $prefixed ) {
2010-11-14 10:50:02 -05:00
$value = apply_filters ( " pre_ { $field } " , $value );
2009-09-14 09:57:48 -04:00
} else {
2010-11-14 10:50:02 -05:00
$value = apply_filters ( " pre_user_ { $field } " , $value );
2009-09-14 09:57:48 -04:00
}
} else {
// Use display filters by default.
if ( $prefixed )
$value = apply_filters ( $field , $value , $user_id , $context );
else
2010-11-14 10:50:02 -05:00
$value = apply_filters ( " user_ { $field } " , $value , $user_id , $context );
2009-09-14 09:57:48 -04:00
}
if ( 'user_url' == $field )
$value = esc_url ( $value );
if ( 'attribute' == $context )
$value = esc_attr ( $value );
else if ( 'js' == $context )
$value = esc_js ( $value );
return $value ;
}
2010-03-03 14:08:30 -05:00
/**
* Update all user caches
*
* @ since 3.0 . 0
*
* @ param object $user User object to be cached
*/
2011-08-24 15:32:59 -04:00
function update_user_caches ( $user ) {
2010-03-03 14:08:30 -05:00
wp_cache_add ( $user -> ID , $user , 'users' );
wp_cache_add ( $user -> user_login , $user -> ID , 'userlogins' );
wp_cache_add ( $user -> user_email , $user -> ID , 'useremail' );
wp_cache_add ( $user -> user_nicename , $user -> ID , 'userslugs' );
}
2010-01-19 14:23:11 -05:00
/**
* Clean all user caches
*
2010-03-03 14:08:30 -05:00
* @ since 3.0 . 0
2010-01-19 14:23:11 -05:00
*
* @ param int $id User ID
*/
function clean_user_cache ( $id ) {
2011-08-24 15:32:59 -04:00
$user = WP_User :: get_data_by ( 'id' , $id );
2010-01-19 14:23:11 -05:00
wp_cache_delete ( $id , 'users' );
wp_cache_delete ( $user -> user_login , 'userlogins' );
wp_cache_delete ( $user -> user_email , 'useremail' );
wp_cache_delete ( $user -> user_nicename , 'userslugs' );
}
2010-10-27 06:46:24 -04:00
/**
* Checks whether the given username exists .
*
* @ since 2.0 . 0
*
* @ param string $username Username .
* @ return null | int The user ' s ID on success , and null on failure .
*/
function username_exists ( $username ) {
2011-08-05 12:57:31 -04:00
if ( $user = get_user_by ( 'login' , $username ) ) {
2010-10-27 06:46:24 -04:00
return $user -> ID ;
} else {
return null ;
}
}
/**
* Checks whether the given email exists .
*
* @ since 2.1 . 0
* @ uses $wpdb
*
* @ param string $email Email .
* @ return bool | int The user ' s ID on success , and false on failure .
*/
function email_exists ( $email ) {
2011-08-05 12:57:31 -04:00
if ( $user = get_user_by ( 'email' , $email ) )
2010-10-27 06:46:24 -04:00
return $user -> ID ;
return false ;
}
/**
* Checks whether an username is valid .
*
* @ since 2.0 . 1
* @ uses apply_filters () Calls 'validate_username' hook on $valid check and $username as parameters
*
* @ param string $username Username .
* @ return bool Whether username given is valid
*/
function validate_username ( $username ) {
$sanitized = sanitize_user ( $username , true );
$valid = ( $sanitized == $username );
return apply_filters ( 'validate_username' , $valid , $username );
}
/**
* Insert an user into the database .
*
* Can update a current user or insert a new user based on whether the user ' s ID
* is present .
*
* Can be used to update the user 's info (see below), set the user' s role , and
* set the user ' s preference on whether they want the rich editor on .
*
* Most of the $userdata array fields have filters associated with the values .
* The exceptions are 'rich_editing' , 'role' , 'jabber' , 'aim' , 'yim' ,
* 'user_registered' , and 'ID' . The filters have the prefix 'pre_user_' followed
* by the field name . An example using 'description' would have the filter
* called , 'pre_user_description' that can be hooked into .
*
* The $userdata array can contain the following fields :
* 'ID' - An integer that will be used for updating an existing user .
* 'user_pass' - A string that contains the plain text password for the user .
* 'user_login' - A string that contains the user ' s username for logging in .
* 'user_nicename' - A string that contains a nicer looking name for the user .
* The default is the user ' s username .
* 'user_url' - A string containing the user 's URL for the user' s web site .
* 'user_email' - A string containing the user ' s email address .
* 'display_name' - A string that will be shown on the site . Defaults to user ' s
2011-05-28 20:56:50 -04:00
* username . It is likely that you will want to change this , for appearance .
2010-10-27 06:46:24 -04:00
* 'nickname' - The user 's nickname, defaults to the user' s username .
* 'first_name' - The user ' s first name .
* 'last_name' - The user ' s last name .
* 'description' - A string containing content about the user .
* 'rich_editing' - A string for whether to enable the rich editor . False
* if not empty .
* 'user_registered' - The date the user registered . Format is 'Y-m-d H:i:s' .
* 'role' - A string used to set the user ' s role .
* 'jabber' - User ' s Jabber account .
* 'aim' - User ' s AOL IM account .
* 'yim' - User ' s Yahoo IM account .
*
* @ since 2.0 . 0
* @ uses $wpdb WordPress database layer .
* @ uses apply_filters () Calls filters for most of the $userdata fields with the prefix 'pre_user' . See note above .
* @ uses do_action () Calls 'profile_update' hook when updating giving the user ' s ID
* @ uses do_action () Calls 'user_register' hook when creating a new user giving the user ' s ID
*
* @ param array $userdata An array of user data .
* @ return int | WP_Error The newly created user ' s ID or a WP_Error object if the user could not be created .
*/
function wp_insert_user ( $userdata ) {
global $wpdb ;
extract ( $userdata , EXTR_SKIP );
// Are we updating or creating?
if ( ! empty ( $ID ) ) {
$ID = ( int ) $ID ;
$update = true ;
2011-08-24 15:32:59 -04:00
$old_user_data = WP_User :: get_data_by ( 'id' , $ID );
2010-10-27 06:46:24 -04:00
} else {
$update = false ;
// Hash the password
$user_pass = wp_hash_password ( $user_pass );
}
$user_login = sanitize_user ( $user_login , true );
$user_login = apply_filters ( 'pre_user_login' , $user_login );
//Remove any non-printable chars from the login string to see if we have ended up with an empty username
$user_login = trim ( $user_login );
if ( empty ( $user_login ) )
return new WP_Error ( 'empty_user_login' , __ ( 'Cannot create a user with an empty login name.' ) );
if ( ! $update && username_exists ( $user_login ) )
return new WP_Error ( 'existing_user_login' , __ ( 'This username is already registered.' ) );
if ( empty ( $user_nicename ) )
$user_nicename = sanitize_title ( $user_login );
$user_nicename = apply_filters ( 'pre_user_nicename' , $user_nicename );
if ( empty ( $user_url ) )
$user_url = '' ;
$user_url = apply_filters ( 'pre_user_url' , $user_url );
if ( empty ( $user_email ) )
$user_email = '' ;
$user_email = apply_filters ( 'pre_user_email' , $user_email );
if ( ! $update && ! defined ( 'WP_IMPORTING' ) && email_exists ( $user_email ) )
return new WP_Error ( 'existing_user_email' , __ ( 'This email address is already registered.' ) );
if ( empty ( $display_name ) )
$display_name = $user_login ;
$display_name = apply_filters ( 'pre_user_display_name' , $display_name );
if ( empty ( $nickname ) )
$nickname = $user_login ;
$nickname = apply_filters ( 'pre_user_nickname' , $nickname );
if ( empty ( $first_name ) )
$first_name = '' ;
$first_name = apply_filters ( 'pre_user_first_name' , $first_name );
if ( empty ( $last_name ) )
$last_name = '' ;
$last_name = apply_filters ( 'pre_user_last_name' , $last_name );
if ( empty ( $description ) )
$description = '' ;
$description = apply_filters ( 'pre_user_description' , $description );
if ( empty ( $rich_editing ) )
$rich_editing = 'true' ;
if ( empty ( $comment_shortcuts ) )
$comment_shortcuts = 'false' ;
if ( empty ( $admin_color ) )
$admin_color = 'fresh' ;
$admin_color = preg_replace ( '|[^a-z0-9 _.\-@]|i' , '' , $admin_color );
if ( empty ( $use_ssl ) )
$use_ssl = 0 ;
if ( empty ( $user_registered ) )
$user_registered = gmdate ( 'Y-m-d H:i:s' );
2011-01-05 23:11:14 -05:00
2010-12-17 16:48:30 -05:00
if ( empty ( $show_admin_bar_front ) )
$show_admin_bar_front = 'true' ;
2011-01-05 23:11:14 -05:00
2010-10-27 06:46:24 -04:00
$user_nicename_check = $wpdb -> get_var ( $wpdb -> prepare ( " SELECT ID FROM $wpdb->users WHERE user_nicename = %s AND user_login != %s LIMIT 1 " , $user_nicename , $user_login ));
if ( $user_nicename_check ) {
$suffix = 2 ;
while ( $user_nicename_check ) {
$alt_user_nicename = $user_nicename . " - $suffix " ;
$user_nicename_check = $wpdb -> get_var ( $wpdb -> prepare ( " SELECT ID FROM $wpdb->users WHERE user_nicename = %s AND user_login != %s LIMIT 1 " , $alt_user_nicename , $user_login ));
$suffix ++ ;
}
$user_nicename = $alt_user_nicename ;
}
$data = compact ( 'user_pass' , 'user_email' , 'user_url' , 'user_nicename' , 'display_name' , 'user_registered' );
$data = stripslashes_deep ( $data );
if ( $update ) {
$wpdb -> update ( $wpdb -> users , $data , compact ( 'ID' ) );
$user_id = ( int ) $ID ;
} else {
$wpdb -> insert ( $wpdb -> users , $data + compact ( 'user_login' ) );
$user_id = ( int ) $wpdb -> insert_id ;
}
2011-10-06 22:34:41 -04:00
$user = new WP_User ( $user_id );
foreach ( _get_additional_user_keys ( $user ) as $key ) {
2011-10-10 19:14:38 -04:00
if ( isset ( $$key ) )
update_user_meta ( $user_id , $key , $$key );
2010-10-27 06:46:24 -04:00
}
if ( isset ( $role ) )
$user -> set_role ( $role );
elseif ( ! $update )
$user -> set_role ( get_option ( 'default_role' ));
wp_cache_delete ( $user_id , 'users' );
wp_cache_delete ( $user_login , 'userlogins' );
if ( $update )
do_action ( 'profile_update' , $user_id , $old_user_data );
else
do_action ( 'user_register' , $user_id );
return $user_id ;
}
/**
* Update an user in the database .
*
* It is possible to update a user 's password by specifying the ' user_pass '
* value in the $userdata parameter array .
*
* If $userdata does not contain an 'ID' key , then a new user will be created
* and the new user ' s ID will be returned .
*
* If current user ' s password is being updated , then the cookies will be
* cleared .
*
* @ since 2.0 . 0
* @ see wp_insert_user () For what fields can be set in $userdata
* @ uses wp_insert_user () Used to update existing user or add new one if user doesn ' t exist already
*
* @ param array $userdata An array of user data .
* @ return int The updated user ' s ID .
*/
function wp_update_user ( $userdata ) {
$ID = ( int ) $userdata [ 'ID' ];
// First, get all of the original fields
2011-10-06 22:34:41 -04:00
$user_obj = get_userdata ( $ID );
$user = get_object_vars ( $user_obj -> data );
// Add additional custom fields
foreach ( _get_additional_user_keys ( $user_obj ) as $key ) {
$user [ $key ] = get_user_meta ( $ID , $key , true );
}
2010-10-27 06:46:24 -04:00
// Escape data pulled from DB.
2011-10-06 22:34:41 -04:00
$user = add_magic_quotes ( $user );
2010-10-27 06:46:24 -04:00
// If password is changing, hash it now.
if ( ! empty ( $userdata [ 'user_pass' ]) ) {
$plaintext_pass = $userdata [ 'user_pass' ];
$userdata [ 'user_pass' ] = wp_hash_password ( $userdata [ 'user_pass' ]);
}
wp_cache_delete ( $user [ 'user_email' ], 'useremail' );
// Merge old and new fields with new fields overwriting old ones.
$userdata = array_merge ( $user , $userdata );
$user_id = wp_insert_user ( $userdata );
// Update the cookies if the password changed.
$current_user = wp_get_current_user ();
2011-08-03 23:09:27 -04:00
if ( $current_user -> ID == $ID ) {
2010-10-27 06:46:24 -04:00
if ( isset ( $plaintext_pass ) ) {
wp_clear_auth_cookie ();
wp_set_auth_cookie ( $ID );
}
}
return $user_id ;
}
/**
* A simpler way of inserting an user into the database .
*
2011-09-05 15:08:15 -04:00
* Creates a new user with just the username , password , and email . For more
* complex user creation use wp_insert_user () to specify more information .
2010-10-27 06:46:24 -04:00
*
* @ since 2.0 . 0
* @ see wp_insert_user () More complete way to create a new user
*
* @ param string $username The user ' s username .
* @ param string $password The user ' s password .
* @ param string $email The user ' s email ( optional ) .
* @ return int The new user ' s ID .
*/
function wp_create_user ( $username , $password , $email = '' ) {
$user_login = esc_sql ( $username );
$user_email = esc_sql ( $email );
$user_pass = $password ;
$userdata = compact ( 'user_login' , 'user_email' , 'user_pass' );
return wp_insert_user ( $userdata );
}
2011-10-06 22:34:41 -04:00
/**
* Return a list of meta keys that wp_insert_user () is supposed to set .
*
* @ access private
* @ since 3.3 . 0
*
* @ param object $user WP_User instance
* @ return array
*/
function _get_additional_user_keys ( $user ) {
$keys = array ( 'first_name' , 'last_name' , 'nickname' , 'description' , 'rich_editing' , 'comment_shortcuts' , 'admin_color' , 'use_ssl' , 'show_admin_bar_front' );
return array_merge ( $keys , array_keys ( _wp_get_user_contactmethods ( $user ) ) );
}
2010-10-27 06:46:24 -04:00
/**
* Set up the default contact methods
*
* @ access private
* @ since
*
* @ param object $user User data object ( optional )
* @ return array $user_contactmethods Array of contact methods and their labels .
*/
function _wp_get_user_contactmethods ( $user = null ) {
$user_contactmethods = array (
'aim' => __ ( 'AIM' ),
'yim' => __ ( 'Yahoo IM' ),
'jabber' => __ ( 'Jabber / Google Talk' )
);
return apply_filters ( 'user_contactmethods' , $user_contactmethods , $user );
}