' . __('You can customize the display of this screen in a number of ways:') . '
' .
'
' .
'
' . __('You can hide/display columns based on your needs and decide how many users to list per screen using the Screen Options tab.') . '
' .
- '
' . __('You can filter the list of users by User Role using the text links in the upper left to show All, Administrator, Editor, Author, Contributor, or Subscriber. The default view is to show all users. Unused User Roles are not listed.') . '
' .
+ '
' . __('You can filter the list of users by User Role using the text links in the upper left to show All, Administrator, Editor, Author, Contributor, or Subscriber. The default view is to show all users. Unused User Roles are not listed.') . '
' .
'
' . __('You can view all posts made by a user by clicking on the number under the Posts column.') . '
' .
'
'
) );
@@ -64,9 +64,9 @@ get_current_screen()->set_help_sidebar(
);
if ( empty($_REQUEST) ) {
- $referer = '';
+ $referer = '';
} elseif ( isset($_REQUEST['wp_http_referer']) ) {
- $redirect = remove_query_arg(array('wp_http_referer', 'updated', 'delete_count'), stripslashes($_REQUEST['wp_http_referer']));
+ $redirect = remove_query_arg(array('wp_http_referer', 'updated', 'delete_count'), wp_unslash( $_REQUEST['wp_http_referer'] ) );
$referer = '';
} else {
$redirect = 'users.php';
@@ -75,6 +75,25 @@ if ( empty($_REQUEST) ) {
$update = '';
+/**
+ * @since 3.5.0
+ * @access private
+ */
+function delete_users_add_js() { ?>
+
+current_action() ) {
/* Bulk Dropdown menu Role changes */
@@ -100,17 +119,18 @@ case 'promote':
if ( ! current_user_can('promote_user', $id) )
wp_die(__('You can’t edit that user.'));
- // The new role of the current user must also have the promote_users cap or be a super admin
- if ( $id == $current_user->ID && ! is_super_admin() && ! $wp_roles->role_objects[ $_REQUEST['new_role'] ]->has_cap('promote_users') ) {
- $update = 'err_admin_role';
- continue;
+ // The new role of the current user must also have the promote_users cap or be a multisite super admin
+ if ( $id == $current_user->ID && ! $wp_roles->role_objects[ $_REQUEST['new_role'] ]->has_cap('promote_users')
+ && ! ( is_multisite() && is_super_admin() ) ) {
+ $update = 'err_admin_role';
+ continue;
}
// If the user doesn't already belong to the blog, bail.
if ( is_multisite() && !is_user_member_of_blog( $id ) )
wp_die(__('Cheatin’ uh?'));
- $user = new WP_User($id);
+ $user = get_userdata( $id );
$user->set_role($_REQUEST['new_role']);
}
@@ -130,16 +150,22 @@ case 'dodelete':
exit();
}
+ $userids = array_map( 'intval', (array) $_REQUEST['users'] );
+
+ if ( empty( $_REQUEST['delete_option'] ) ) {
+ $url = self_admin_url( 'users.php?action=delete&users[]=' . implode( '&users[]=', $userids ) . '&error=true' );
+ $url = str_replace( '&', '&', wp_nonce_url( $url, 'bulk-users' ) );
+ wp_redirect( $url );
+ exit;
+ }
+
if ( ! current_user_can( 'delete_users' ) )
wp_die(__('You can’t delete users.'));
- $userids = $_REQUEST['users'];
$update = 'del';
$delete_count = 0;
- foreach ( (array) $userids as $id) {
- $id = (int) $id;
-
+ foreach ( $userids as $id ) {
if ( ! current_user_can( 'delete_user', $id ) )
wp_die(__( 'You can’t delete that user.' ) );
@@ -149,12 +175,10 @@ case 'dodelete':
}
switch ( $_REQUEST['delete_option'] ) {
case 'delete':
- if ( current_user_can('delete_user', $id) )
- wp_delete_user($id);
+ wp_delete_user( $id );
break;
case 'reassign':
- if ( current_user_can('delete_user', $id) )
- wp_delete_user($id, $_REQUEST['reassign_user']);
+ wp_delete_user( $id, $_REQUEST['reassign_user'] );
break;
}
++$delete_count;
@@ -181,11 +205,13 @@ case 'delete':
$errors = new WP_Error( 'edit_users', __( 'You can’t delete users.' ) );
if ( empty($_REQUEST['users']) )
- $userids = array(intval($_REQUEST['user']));
+ $userids = array( intval( $_REQUEST['user'] ) );
else
- $userids = (array) $_REQUEST['users'];
+ $userids = array_map( 'intval', (array) $_REQUEST['users'] );
- include ('admin-header.php');
+ add_action( 'admin_head', 'delete_users_add_js' );
+
+ include( ABSPATH . 'wp-admin/admin-header.php' );
?>