/wp-includes/user.php

https://github.com/socialplanning/opencore-wordpress-mu · PHP · 182 lines · 135 code · 33 blank · 14 comment · 32 complexity · 13bb5a6cfe98488e5458194b4471d0dc MD5 · raw file

  1. <?php
  2. function get_profile($field, $user = false) {
  3. global $wpdb;
  4. if ( !$user )
  5. $user = $wpdb->escape($_COOKIE[USER_COOKIE]);
  6. return $wpdb->get_var("SELECT $field FROM $wpdb->users WHERE user_login = '$user'");
  7. }
  8. function get_usernumposts($userid) {
  9. global $wpdb;
  10. $userid = (int) $userid;
  11. return $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE post_author = '$userid' AND post_type = 'post' AND " . get_private_posts_cap_sql('post'));
  12. }
  13. // TODO: xmlrpc only. Maybe move to xmlrpc.php.
  14. function user_pass_ok($user_login,$user_pass) {
  15. global $cache_userdata;
  16. if ( empty($cache_userdata[$user_login]) ) {
  17. $userdata = get_userdatabylogin($user_login);
  18. } else {
  19. $userdata = $cache_userdata[$user_login];
  20. }
  21. return (md5($user_pass) == $userdata->user_pass);
  22. }
  23. //
  24. // User option functions
  25. //
  26. function get_user_option( $option, $user = 0 ) {
  27. global $wpdb;
  28. if ( empty($user) )
  29. $user = wp_get_current_user();
  30. else
  31. $user = get_userdata($user);
  32. if ( isset( $user->{$wpdb->prefix . $option} ) ) // Blog specific
  33. return $user->{$wpdb->prefix . $option};
  34. elseif ( isset( $user->{$option} ) ) // User specific and cross-blog
  35. return $user->{$option};
  36. else // Blog global
  37. return get_option( $option );
  38. }
  39. function update_user_option( $user_id, $option_name, $newvalue, $global = false ) {
  40. global $wpdb;
  41. if ( !$global )
  42. $option_name = $wpdb->prefix . $option_name;
  43. return update_usermeta( $user_id, $option_name, $newvalue );
  44. }
  45. // Get users with capabilities for the current blog.
  46. // For setups that use the multi-blog feature.
  47. function get_users_of_blog( $id = '' ) {
  48. global $wpdb, $wpmuBaseTablePrefix;
  49. if ( empty($id) )
  50. $id = (int) $wpdb->blogid;
  51. $users = $wpdb->get_results( "SELECT user_id, user_login, display_name, user_email, meta_value FROM $wpdb->users, $wpdb->usermeta WHERE " . $wpdb->users . ".ID = " . $wpdb->usermeta . ".user_id AND meta_key = '" . $wpmuBaseTablePrefix . $id . "_capabilities' ORDER BY {$wpdb->usermeta}.user_id" );
  52. return $users;
  53. }
  54. //
  55. // User meta functions
  56. //
  57. function delete_usermeta( $user_id, $meta_key, $meta_value = '' ) {
  58. global $wpdb;
  59. if ( !is_numeric( $user_id ) )
  60. return false;
  61. $meta_key = preg_replace('|[^a-z0-9_]|i', '', $meta_key);
  62. if ( is_array($meta_value) || is_object($meta_value) )
  63. $meta_value = serialize($meta_value);
  64. $meta_value = trim( $meta_value );
  65. if ( ! empty($meta_value) )
  66. $wpdb->query("DELETE FROM $wpdb->usermeta WHERE user_id = '$user_id' AND meta_key = '$meta_key' AND meta_value = '$meta_value'");
  67. else
  68. $wpdb->query("DELETE FROM $wpdb->usermeta WHERE user_id = '$user_id' AND meta_key = '$meta_key'");
  69. $user = get_userdata($user_id);
  70. wp_cache_delete($user_id, 'users');
  71. wp_cache_delete($user->user_login, 'userlogins');
  72. return true;
  73. }
  74. function get_usermeta( $user_id, $meta_key = '') {
  75. global $wpdb;
  76. $user_id = (int) $user_id;
  77. if ( !empty($meta_key) ) {
  78. $meta_key = preg_replace('|[^a-z0-9_]|i', '', $meta_key);
  79. $metas = $wpdb->get_results("SELECT meta_key, meta_value FROM $wpdb->usermeta WHERE user_id = '$user_id' AND meta_key = '$meta_key'");
  80. } else {
  81. $metas = $wpdb->get_results("SELECT meta_key, meta_value FROM $wpdb->usermeta WHERE user_id = '$user_id'");
  82. }
  83. if ( empty($metas) ) {
  84. if ( empty($meta_key) )
  85. return array();
  86. else
  87. return '';
  88. }
  89. foreach ($metas as $index => $meta) {
  90. @ $value = unserialize($meta->meta_value);
  91. if ( $value === FALSE )
  92. $value = $meta->meta_value;
  93. $values[] = $value;
  94. }
  95. if ( count($values) == 1 )
  96. return $values[0];
  97. else
  98. return $values;
  99. }
  100. function update_usermeta( $user_id, $meta_key, $meta_value ) {
  101. global $wpdb;
  102. if ( !is_numeric( $user_id ) )
  103. return false;
  104. $meta_key = preg_replace('|[^a-z0-9_]|i', '', $meta_key);
  105. // FIXME: usermeta data is assumed to be already escaped
  106. if ( is_string($meta_value) )
  107. $meta_value = stripslashes($meta_value);
  108. $meta_value = maybe_serialize($meta_value);
  109. $meta_value = $wpdb->escape($meta_value);
  110. if (empty($meta_value)) {
  111. return delete_usermeta($user_id, $meta_key);
  112. }
  113. $cur = $wpdb->get_row("SELECT * FROM $wpdb->usermeta WHERE user_id = '$user_id' AND meta_key = '$meta_key'");
  114. if ( !$cur ) {
  115. $wpdb->query("INSERT INTO $wpdb->usermeta ( user_id, meta_key, meta_value )
  116. VALUES
  117. ( '$user_id', '$meta_key', '$meta_value' )");
  118. } else if ( $cur->meta_value != $meta_value ) {
  119. $wpdb->query("UPDATE $wpdb->usermeta SET meta_value = '$meta_value' WHERE user_id = '$user_id' AND meta_key = '$meta_key'");
  120. } else {
  121. return false;
  122. }
  123. $user = get_userdata($user_id);
  124. wp_cache_delete($user_id, 'users');
  125. wp_cache_delete($user->user_login, 'userlogins');
  126. return true;
  127. }
  128. //
  129. // Private helper functions
  130. //
  131. // Setup global user vars. Used by set_current_user() for back compat.
  132. function setup_userdata($user_id = '') {
  133. global $user_login, $userdata, $user_level, $user_ID, $user_email, $user_url, $user_pass_md5, $user_identity;
  134. if ( '' == $user_id )
  135. $user = wp_get_current_user();
  136. else
  137. $user = new WP_User($user_id);
  138. if ( 0 == $user->ID )
  139. return;
  140. $userdata = $user->data;
  141. $user_login = $user->user_login;
  142. $user_level = (int) $user->user_level;
  143. $user_ID = (int) $user->ID;
  144. $user_email = $user->user_email;
  145. $user_url = $user->user_url;
  146. $user_pass_md5 = md5($user->user_pass);
  147. $user_identity = $user->display_name;
  148. }
  149. ?>