'<p>' . __('<a href="https://wordpress.org/support/" target="_blank">Support Forums</a>') . '</p>'
);
-$wp_http_referer = remove_query_arg(array('update', 'delete_count'), $wp_http_referer );
+$wp_http_referer = remove_query_arg( array( 'update', 'delete_count', 'user_id' ), $wp_http_referer );
$user_can_edit = current_user_can( 'edit_posts' ) || current_user_can( 'edit_pages' );
-/**
- * Optional SSL preference that can be turned on by hooking to the 'personal_options' action.
- *
- * @since 2.7.0
- *
- * @param object $user User data object
- */
-function use_ssl_preference($user) {
-?>
- <tr class="user-use-ssl-wrap">
- <th scope="row"><?php _e('Use https')?></th>
- <td><label for="use_ssl"><input name="use_ssl" type="checkbox" id="use_ssl" value="1" <?php checked('1', $user->use_ssl); ?> /> <?php _e('Always use https when visiting the admin'); ?></label></td>
- </tr>
-<?php
-}
-
/**
* Filter whether to allow administrators on Multisite to edit every user.
*
// Execute confirmed email change. See send_confirmation_on_profile_email().
if ( is_multisite() && IS_PROFILE_PAGE && isset( $_GET[ 'newuseremail' ] ) && $current_user->ID ) {
- $new_email = get_option( $current_user->ID . '_new_email' );
- if ( $new_email[ 'hash' ] == $_GET[ 'newuseremail' ] ) {
+ $new_email = get_user_meta( $current_user->ID, '_new_email', true );
+ if ( $new_email && hash_equals( $new_email[ 'hash' ], $_GET[ 'newuseremail' ] ) ) {
$user = new stdClass;
$user->ID = $current_user->ID;
$user->user_email = esc_html( trim( $new_email[ 'newemail' ] ) );
- if ( $wpdb->get_var( $wpdb->prepare( "SELECT user_login FROM {$wpdb->signups} WHERE user_login = %s", $current_user->user_login ) ) )
+ if ( $wpdb->get_var( $wpdb->prepare( "SELECT user_login FROM {$wpdb->signups} WHERE user_login = %s", $current_user->user_login ) ) ) {
$wpdb->query( $wpdb->prepare( "UPDATE {$wpdb->signups} SET user_email = %s WHERE user_login = %s", $user->user_email, $current_user->user_login ) );
+ }
wp_update_user( $user );
- delete_option( $current_user->ID . '_new_email' );
- wp_redirect( add_query_arg( array('updated' => 'true'), self_admin_url( 'profile.php' ) ) );
+ delete_user_meta( $current_user->ID, '_new_email' );
+ wp_redirect( add_query_arg( array( 'updated' => 'true' ), self_admin_url( 'profile.php' ) ) );
die();
+ } else {
+ wp_redirect( add_query_arg( array( 'error' => 'new-email' ), self_admin_url( 'profile.php' ) ) );
}
-} elseif ( is_multisite() && IS_PROFILE_PAGE && !empty( $_GET['dismiss'] ) && $current_user->ID . '_new_email' == $_GET['dismiss'] ) {
- delete_option( $current_user->ID . '_new_email' );
+} elseif ( is_multisite() && IS_PROFILE_PAGE && !empty( $_GET['dismiss'] ) && $current_user->ID . '_new_email' === $_GET['dismiss'] ) {
+ check_admin_referer( 'dismiss-' . $current_user->ID . '_new_email' );
+ delete_user_meta( $current_user->ID, '_new_email' );
wp_redirect( add_query_arg( array('updated' => 'true'), self_admin_url( 'profile.php' ) ) );
die();
}
<?php else: ?>
<p><strong><?php _e('User updated.') ?></strong></p>
<?php endif; ?>
- <?php if ( $wp_http_referer && !IS_PROFILE_PAGE ) : ?>
+ <?php if ( $wp_http_referer && false === strpos( $wp_http_referer, 'user-new.php' ) && ! IS_PROFILE_PAGE ) : ?>
<p><a href="<?php echo esc_url( $wp_http_referer ); ?>"><?php _e('← Back to Users'); ?></a></p>
<?php endif; ?>
</div>
<?php endif; ?>
+<?php if ( isset( $_GET['error'] ) ) : ?>
+<div class="notice notice-error">
+ <?php if ( 'new-email' == $_GET['error'] ) : ?>
+ <p><?php _e( 'Error while saving the new email address. Please try again.' ); ?></p>
+ <?php endif; ?>
+</div>
+<?php endif; ?>
<?php if ( isset( $errors ) && is_wp_error( $errors ) ) : ?>
<div class="error"><p><?php echo implode( "</p>\n<p>", $errors->get_error_messages() ); ?></p></div>
<?php endif; ?>
<input type="hidden" name="checkuser_id" value="<?php echo get_current_user_id(); ?>" />
</p>
-<h3><?php _e('Personal Options'); ?></h3>
+<h2><?php _e( 'Personal Options' ); ?></h2>
<table class="form-table">
<?php if ( ! ( IS_PROFILE_PAGE && ! $user_can_edit ) ) : ?>
}
?>
-<h3><?php _e('Name') ?></h3>
+<h2><?php _e( 'Name' ); ?></h2>
<table class="form-table">
<tr class="user-user-login-wrap">
</tr>
</table>
-<h3><?php _e('Contact Info') ?></h3>
+<h2><?php _e( 'Contact Info' ); ?></h2>
<table class="form-table">
<tr class="user-email-wrap">
- <th><label for="email"><?php _e('E-mail'); ?> <span class="description"><?php _e('(required)'); ?></span></label></th>
+ <th><label for="email"><?php _e('Email'); ?> <span class="description"><?php _e('(required)'); ?></span></label></th>
<td><input type="email" name="email" id="email" value="<?php echo esc_attr( $profileuser->user_email ) ?>" class="regular-text ltr" />
<?php
- $new_email = get_option( $current_user->ID . '_new_email' );
+ $new_email = get_user_meta( $current_user->ID, '_new_email', true );
if ( $new_email && $new_email['newemail'] != $current_user->user_email && $profileuser->ID == $current_user->ID ) : ?>
<div class="updated inline">
<p><?php
printf(
- __( 'There is a pending change of your e-mail to %1$s. <a href="%2$s">Cancel</a>' ),
- '<code>' . $new_email['newemail'] . '</code>',
- esc_url( self_admin_url( 'profile.php?dismiss=' . $current_user->ID . '_new_email' ) )
- ); ?></p>
+ /* translators: %s: new email */
+ __( 'There is a pending change of your email to %s.' ),
+ '<code>' . esc_html( $new_email['newemail'] ) . '</code>'
+ );
+ printf(
+ ' <a href="%1$s">%2$s</a>',
+ esc_url( wp_nonce_url( self_admin_url( 'profile.php?dismiss=' . $current_user->ID . '_new_email' ), 'dismiss-' . $current_user->ID . '_new_email' ) ),
+ __( 'Cancel' )
+ );
+ ?></p>
</div>
<?php endif; ?>
</td>
?>
</table>
-<h3><?php IS_PROFILE_PAGE ? _e('About Yourself') : _e('About the user'); ?></h3>
+<h2><?php IS_PROFILE_PAGE ? _e( 'About Yourself' ) : _e( 'About the user' ); ?></h2>
<table class="form-table">
<tr class="user-description-wrap">
<p class="description"><?php _e('Share a little biographical information to fill out your profile. This may be shown publicly.'); ?></p></td>
</tr>
+<?php if ( get_option( 'show_avatars' ) ) : ?>
+<tr class="user-profile-picture">
+ <th><?php _e( 'Profile Picture' ); ?></th>
+ <td>
+ <?php echo get_avatar( $user_id ); ?>
+ <p class="description"><?php
+ if ( IS_PROFILE_PAGE ) {
+ /* translators: %s: Gravatar URL */
+ $description = sprintf( __( 'You can change your profile picture on <a href="%s">Gravatar</a>.' ),
+ __( 'https://en.gravatar.com/' )
+ );
+ } else {
+ $description = '';
+ }
+
+ /**
+ * Filter the user profile picture description displayed under the Gravatar.
+ *
+ * @since 4.4.0
+ *
+ * @param string $description The description that will be printed.
+ */
+ echo apply_filters( 'user_profile_picture_description', $description );
+ ?></p>
+ </td>
+</tr>
+<?php endif; ?>
+
<?php
-/** This filter is documented in wp-admin/user-new.php */
-$show_password_fields = apply_filters( 'show_password_fields', true, $profileuser );
-if ( $show_password_fields ) :
+/**
+ * Filter the display of the password fields.
+ *
+ * @since 1.5.1
+ * @since 2.8.0 Added the `$profileuser` parameter.
+ * @since 4.4.0 Now evaluated only in user-edit.php.
+ *
+ * @param bool $show Whether to show the password fields. Default true.
+ * @param WP_User $profileuser User object for the current user to edit.
+ */
+if ( $show_password_fields = apply_filters( 'show_password_fields', true, $profileuser ) ) :
?>
</table>
-<h3><?php _e('Account Management'); ?></h3>
+<h2><?php _e( 'Account Management' ); ?></h2>
<table class="form-table">
<tr id="password" class="user-pass1-wrap">
<th><label for="pass1"><?php _e( 'New Password' ); ?></label></th>
*
* The 'Additional Capabilities' section will only be enabled if
* the number of the user's capabilities exceeds their number of
- * of roles.
+ * roles.
*
* @since 2.8.0
*
if ( count( $profileuser->caps ) > count( $profileuser->roles )
&& apply_filters( 'additional_capabilities_display', true, $profileuser )
) : ?>
-<h3><?php _e( 'Additional Capabilities' ); ?></h3>
+<h2><?php _e( 'Additional Capabilities' ); ?></h2>
<table class="form-table">
<tr class="user-capabilities-wrap">
<th scope="row"><?php _e( 'Capabilities' ); ?></th>