| [ Index ] |
PHP Cross Reference of WordPress Trunk (Updated Daily) |
[Summary view] [Print] [Text view]
1 <?php 2 /** 3 * Edit user administration panel. 4 * 5 * @package WordPress 6 * @subpackage Administration 7 */ 8 9 /** WordPress Administration Bootstrap */ 10 require_once __DIR__ . '/admin.php'; 11 12 /** WordPress Translation Installation API */ 13 require_once ABSPATH . 'wp-admin/includes/translation-install.php'; 14 15 $action = ! empty( $_REQUEST['action'] ) ? sanitize_text_field( $_REQUEST['action'] ) : ''; 16 $user_id = ! empty( $_REQUEST['user_id'] ) ? absint( $_REQUEST['user_id'] ) : 0; 17 $wp_http_referer = ! empty( $_REQUEST['wp_http_referer'] ) ? sanitize_url( $_REQUEST['wp_http_referer'] ) : ''; 18 19 $current_user = wp_get_current_user(); 20 21 if ( ! defined( 'IS_PROFILE_PAGE' ) ) { 22 define( 'IS_PROFILE_PAGE', ( $user_id === $current_user->ID ) ); 23 } 24 25 if ( ! $user_id && IS_PROFILE_PAGE ) { 26 $user_id = $current_user->ID; 27 } elseif ( ! $user_id && ! IS_PROFILE_PAGE ) { 28 wp_die( __( 'Invalid user ID.' ) ); 29 } elseif ( ! get_userdata( $user_id ) ) { 30 wp_die( __( 'Invalid user ID.' ) ); 31 } 32 33 wp_enqueue_script( 'user-profile' ); 34 35 if ( wp_is_application_passwords_available_for_user( $user_id ) ) { 36 wp_enqueue_script( 'application-passwords' ); 37 } 38 39 if ( IS_PROFILE_PAGE ) { 40 // Used in the HTML title tag. 41 $title = __( 'Profile' ); 42 } else { 43 // Used in the HTML title tag. 44 /* translators: %s: User's display name. */ 45 $title = __( 'Edit User %s' ); 46 } 47 48 if ( current_user_can( 'edit_users' ) && ! IS_PROFILE_PAGE ) { 49 $submenu_file = 'users.php'; 50 } else { 51 $submenu_file = 'profile.php'; 52 } 53 54 if ( current_user_can( 'edit_users' ) && ! is_user_admin() ) { 55 $parent_file = 'users.php'; 56 } else { 57 $parent_file = 'profile.php'; 58 } 59 60 $profile_help = '<p>' . __( 'Your profile contains information about you (your “account”) as well as some personal options related to using WordPress.' ) . '</p>' . 61 '<p>' . __( 'You can change your password, turn on keyboard shortcuts, change the color scheme of your WordPress administration screens, and turn off the WYSIWYG (Visual) editor, among other things. You can hide the Toolbar (formerly called the Admin Bar) from the front end of your site, however it cannot be disabled on the admin screens.' ) . '</p>' . 62 '<p>' . __( 'You can select the language you wish to use while using the WordPress administration screen without affecting the language site visitors see.' ) . '</p>' . 63 '<p>' . __( 'Your username cannot be changed, but you can use other fields to enter your real name or a nickname, and change which name to display on your posts.' ) . '</p>' . 64 '<p>' . __( 'You can log out of other devices, such as your phone or a public computer, by clicking the Log Out Everywhere Else button.' ) . '</p>' . 65 '<p>' . __( 'Required fields are indicated; the rest are optional. Profile information will only be displayed if your theme is set up to do so.' ) . '</p>' . 66 '<p>' . __( 'Remember to click the Update Profile button when you are finished.' ) . '</p>'; 67 68 get_current_screen()->add_help_tab( 69 array( 70 'id' => 'overview', 71 'title' => __( 'Overview' ), 72 'content' => $profile_help, 73 ) 74 ); 75 76 get_current_screen()->set_help_sidebar( 77 '<p><strong>' . __( 'For more information:' ) . '</strong></p>' . 78 '<p>' . __( '<a href="https://wordpress.org/documentation/article/users-your-profile-screen/">Documentation on User Profiles</a>' ) . '</p>' . 79 '<p>' . __( '<a href="https://wordpress.org/support/forums/">Support forums</a>' ) . '</p>' 80 ); 81 82 $wp_http_referer = remove_query_arg( array( 'update', 'delete_count', 'user_id' ), $wp_http_referer ); 83 84 $user_can_edit = current_user_can( 'edit_posts' ) || current_user_can( 'edit_pages' ); 85 86 /** 87 * Filters whether to allow administrators on Multisite to edit every user. 88 * 89 * Enabling the user editing form via this filter also hinges on the user holding 90 * the 'manage_network_users' cap, and the logged-in user not matching the user 91 * profile open for editing. 92 * 93 * The filter was introduced to replace the EDIT_ANY_USER constant. 94 * 95 * @since 3.0.0 96 * 97 * @param bool $allow Whether to allow editing of any user. Default true. 98 */ 99 if ( is_multisite() 100 && ! current_user_can( 'manage_network_users' ) 101 && $user_id !== $current_user->ID 102 && ! apply_filters( 'enable_edit_any_user_configuration', true ) 103 ) { 104 wp_die( __( 'Sorry, you are not allowed to edit this user.' ) ); 105 } 106 107 /** 108 * @global wpdb $wpdb WordPress database abstraction object. 109 */ 110 global $wpdb; 111 112 // Execute confirmed email change. See send_confirmation_on_profile_email(). 113 if ( IS_PROFILE_PAGE && isset( $_GET['newuseremail'] ) && $current_user->ID ) { 114 $new_email = get_user_meta( $current_user->ID, '_new_email', true ); 115 if ( $new_email && hash_equals( $new_email['hash'], $_GET['newuseremail'] ) ) { 116 $user = new stdClass(); 117 $user->ID = $current_user->ID; 118 $user->user_email = esc_html( trim( $new_email['newemail'] ) ); 119 if ( is_multisite() && $wpdb->get_var( $wpdb->prepare( "SELECT user_login FROM {$wpdb->signups} WHERE user_login = %s", $current_user->user_login ) ) ) { 120 $wpdb->query( $wpdb->prepare( "UPDATE {$wpdb->signups} SET user_email = %s WHERE user_login = %s", $user->user_email, $current_user->user_login ) ); 121 } 122 wp_update_user( $user ); 123 delete_user_meta( $current_user->ID, '_new_email' ); 124 wp_redirect( add_query_arg( array( 'updated' => 'true' ), self_admin_url( 'profile.php' ) ) ); 125 die(); 126 } else { 127 wp_redirect( add_query_arg( array( 'error' => 'new-email' ), self_admin_url( 'profile.php' ) ) ); 128 } 129 } elseif ( IS_PROFILE_PAGE && ! empty( $_GET['dismiss'] ) && $current_user->ID . '_new_email' === $_GET['dismiss'] ) { 130 check_admin_referer( 'dismiss-' . $current_user->ID . '_new_email' ); 131 delete_user_meta( $current_user->ID, '_new_email' ); 132 wp_redirect( add_query_arg( array( 'updated' => 'true' ), self_admin_url( 'profile.php' ) ) ); 133 die(); 134 } 135 136 switch ( $action ) { 137 case 'update': 138 check_admin_referer( 'update-user_' . $user_id ); 139 140 if ( ! current_user_can( 'edit_user', $user_id ) ) { 141 wp_die( __( 'Sorry, you are not allowed to edit this user.' ) ); 142 } 143 144 if ( IS_PROFILE_PAGE ) { 145 /** 146 * Fires before the page loads on the 'Profile' editing screen. 147 * 148 * The action only fires if the current user is editing their own profile. 149 * 150 * @since 2.0.0 151 * 152 * @param int $user_id The user ID. 153 */ 154 do_action( 'personal_options_update', $user_id ); 155 } else { 156 /** 157 * Fires before the page loads on the 'Edit User' screen. 158 * 159 * @since 2.7.0 160 * 161 * @param int $user_id The user ID. 162 */ 163 do_action( 'edit_user_profile_update', $user_id ); 164 } 165 166 // Update the email address in signups, if present. 167 if ( is_multisite() ) { 168 $user = get_userdata( $user_id ); 169 170 if ( $user->user_login && isset( $_POST['email'] ) && is_email( $_POST['email'] ) && $wpdb->get_var( $wpdb->prepare( "SELECT user_login FROM {$wpdb->signups} WHERE user_login = %s", $user->user_login ) ) ) { 171 $wpdb->query( $wpdb->prepare( "UPDATE {$wpdb->signups} SET user_email = %s WHERE user_login = %s", $_POST['email'], $user_login ) ); 172 } 173 } 174 175 // Update the user. 176 $errors = edit_user( $user_id ); 177 178 // Grant or revoke super admin status if requested. 179 if ( is_multisite() && is_network_admin() 180 && ! IS_PROFILE_PAGE && current_user_can( 'manage_network_options' ) 181 && ! isset( $super_admins ) && empty( $_POST['super_admin'] ) === is_super_admin( $user_id ) 182 ) { 183 empty( $_POST['super_admin'] ) ? revoke_super_admin( $user_id ) : grant_super_admin( $user_id ); 184 } 185 186 if ( ! is_wp_error( $errors ) ) { 187 $redirect = add_query_arg( 'updated', true, get_edit_user_link( $user_id ) ); 188 if ( $wp_http_referer ) { 189 $redirect = add_query_arg( 'wp_http_referer', urlencode( $wp_http_referer ), $redirect ); 190 } 191 wp_redirect( $redirect ); 192 exit; 193 } 194 195 // Intentional fall-through to display $errors. 196 default: 197 $profile_user = get_user_to_edit( $user_id ); 198 199 if ( ! current_user_can( 'edit_user', $user_id ) ) { 200 wp_die( __( 'Sorry, you are not allowed to edit this user.' ) ); 201 } 202 203 $title = sprintf( $title, $profile_user->display_name ); 204 $sessions = WP_Session_Tokens::get_instance( $profile_user->ID ); 205 206 require_once ABSPATH . 'wp-admin/admin-header.php'; 207 ?> 208 209 <?php 210 if ( ! IS_PROFILE_PAGE && is_super_admin( $profile_user->ID ) && current_user_can( 'manage_network_options' ) ) : 211 $message = '<strong>' . __( 'Important:' ) . '</strong> ' . __( 'This user has super admin privileges.' ); 212 wp_admin_notice( 213 $message, 214 array( 215 'type' => 'info', 216 ) 217 ); 218 endif; 219 220 if ( isset( $_GET['updated'] ) ) : 221 if ( IS_PROFILE_PAGE ) : 222 $message = '<p><strong>' . __( 'Profile updated.' ) . '</strong></p>'; 223 else : 224 $message = '<p><strong>' . __( 'User updated.' ) . '</strong></p>'; 225 endif; 226 if ( $wp_http_referer && ! str_contains( $wp_http_referer, 'user-new.php' ) && ! IS_PROFILE_PAGE ) : 227 $message .= sprintf( 228 '<p><a href="%1$s">%2$s</a></p>', 229 esc_url( wp_validate_redirect( sanitize_url( $wp_http_referer ), self_admin_url( 'users.php' ) ) ), 230 __( '← Go to Users' ) 231 ); 232 endif; 233 wp_admin_notice( 234 $message, 235 array( 236 'id' => 'message', 237 'dismissible' => true, 238 'additional_classes' => array( 'updated' ), 239 'paragraph_wrap' => false, 240 ) 241 ); 242 endif; 243 244 if ( isset( $_GET['error'] ) ) : 245 $message = ''; 246 if ( 'new-email' === $_GET['error'] ) : 247 $message = __( 'Error while saving the new email address. Please try again.' ); 248 endif; 249 wp_admin_notice( 250 $message, 251 array( 252 'type' => 'error', 253 ) 254 ); 255 endif; 256 257 if ( isset( $errors ) && is_wp_error( $errors ) ) { 258 wp_admin_notice( 259 implode( "</p>\n<p>", $errors->get_error_messages() ), 260 array( 261 'additional_classes' => array( 'error' ), 262 ) 263 ); 264 } 265 ?> 266 267 <div class="wrap" id="profile-page"> 268 <h1 class="wp-heading-inline"> 269 <?php echo esc_html( $title ); ?> 270 </h1> 271 272 <?php if ( ! IS_PROFILE_PAGE ) : ?> 273 <?php if ( current_user_can( 'create_users' ) ) : ?> 274 <a href="user-new.php" class="page-title-action"><?php echo esc_html__( 'Add User' ); ?></a> 275 <?php elseif ( is_multisite() && current_user_can( 'promote_users' ) ) : ?> 276 <a href="user-new.php" class="page-title-action"><?php echo esc_html__( 'Add Existing User' ); ?></a> 277 <?php endif; ?> 278 <?php endif; ?> 279 280 <hr class="wp-header-end"> 281 282 <form id="your-profile" action="<?php echo esc_url( self_admin_url( IS_PROFILE_PAGE ? 'profile.php' : 'user-edit.php' ) ); ?>" method="post" novalidate="novalidate" 283 <?php 284 /** 285 * Fires inside the your-profile form tag on the user editing screen. 286 * 287 * @since 3.0.0 288 */ 289 do_action( 'user_edit_form_tag' ); 290 ?> 291 > 292 <?php wp_nonce_field( 'update-user_' . $user_id ); ?> 293 <?php if ( $wp_http_referer ) : ?> 294 <input type="hidden" name="wp_http_referer" value="<?php echo esc_url( $wp_http_referer ); ?>" /> 295 <?php endif; ?> 296 <p> 297 <input type="hidden" name="from" value="profile" /> 298 <input type="hidden" name="checkuser_id" value="<?php echo get_current_user_id(); ?>" /> 299 </p> 300 301 <h2><?php _e( 'Personal Options' ); ?></h2> 302 303 <table class="form-table" role="presentation"> 304 <?php if ( ! ( IS_PROFILE_PAGE && ! $user_can_edit ) && 'false' === $profile_user->rich_editing ) : ?> 305 <tr class="user-rich-editing-wrap"> 306 <th scope="row"><?php _e( 'Visual Editor' ); ?></th> 307 <td> 308 <label for="rich_editing"><input name="rich_editing" type="checkbox" id="rich_editing" value="false" <?php checked( 'false', $profile_user->rich_editing ); ?> /> 309 <?php _e( 'Disable the visual editor when writing' ); ?> 310 </label> 311 </td> 312 </tr> 313 <?php endif; ?> 314 315 <?php 316 $show_syntax_highlighting_preference = ( 317 // For Custom HTML widget and Additional CSS in Customizer. 318 user_can( $profile_user, 'edit_theme_options' ) 319 || 320 // Edit plugins. 321 user_can( $profile_user, 'edit_plugins' ) 322 || 323 // Edit themes. 324 user_can( $profile_user, 'edit_themes' ) 325 ); 326 ?> 327 328 <?php if ( $show_syntax_highlighting_preference ) : ?> 329 <tr class="user-syntax-highlighting-wrap"> 330 <th scope="row"><?php _e( 'Syntax Highlighting' ); ?></th> 331 <td> 332 <label for="syntax_highlighting"><input name="syntax_highlighting" type="checkbox" id="syntax_highlighting" value="false" <?php checked( 'false', $profile_user->syntax_highlighting ); ?> /> 333 <?php _e( 'Disable syntax highlighting when editing code' ); ?> 334 </label> 335 </td> 336 </tr> 337 <?php endif; ?> 338 339 <?php if ( count( $_wp_admin_css_colors ) > 1 && has_action( 'admin_color_scheme_picker' ) ) : ?> 340 <tr class="user-admin-color-wrap"> 341 <th scope="row"><?php _e( 'Administration Color Scheme' ); ?></th> 342 <td> 343 <?php 344 /** 345 * Fires in the 'Administration Color Scheme' section of the user editing screen. 346 * 347 * The section is only enabled if a callback is hooked to the action, 348 * and if there is more than one defined color scheme for the admin. 349 * 350 * @since 3.0.0 351 * @since 3.8.1 Added `$user_id` parameter. 352 * 353 * @param int $user_id The user ID. 354 */ 355 do_action( 'admin_color_scheme_picker', $user_id ); 356 ?> 357 </td> 358 </tr> 359 <?php endif; // End if count ( $_wp_admin_css_colors ) > 1 ?> 360 361 <?php if ( ! ( IS_PROFILE_PAGE && ! $user_can_edit ) ) : ?> 362 <tr class="user-comment-shortcuts-wrap"> 363 <th scope="row"><?php _e( 'Keyboard Shortcuts' ); ?></th> 364 <td> 365 <label for="comment_shortcuts"> 366 <input type="checkbox" name="comment_shortcuts" id="comment_shortcuts" value="true" <?php checked( 'true', $profile_user->comment_shortcuts ); ?> /> 367 <?php _e( 'Enable keyboard shortcuts for comment moderation.' ); ?> 368 </label> 369 <?php _e( '<a href="https://wordpress.org/documentation/article/keyboard-shortcuts-classic-editor/#keyboard-shortcuts-for-comments">Documentation on Keyboard Shortcuts</a>' ); ?> 370 </td> 371 </tr> 372 <?php endif; ?> 373 374 <tr class="show-admin-bar user-admin-bar-front-wrap"> 375 <th scope="row"><?php _e( 'Toolbar' ); ?></th> 376 <td> 377 <label for="admin_bar_front"> 378 <input name="admin_bar_front" type="checkbox" id="admin_bar_front" value="1"<?php checked( _get_admin_bar_pref( 'front', $profile_user->ID ) ); ?> /> 379 <?php _e( 'Show Toolbar when viewing site' ); ?> 380 </label><br /> 381 </td> 382 </tr> 383 384 <?php if ( user_can( $profile_user, 'upload_files' ) ) : ?> 385 <tr class="user-infinite-scrolling-wrap"> 386 <th scope="row"><?php _e( 'Infinite Scrolling' ); ?></th> 387 <td> 388 <label for="infinite_scrolling"><input name="infinite_scrolling" type="checkbox" id="infinite_scrolling" value="false" <?php checked( 'false', $profile_user->infinite_scrolling ); ?> /> 389 <?php _e( 'Disable infinite scrolling in the Media Library grid view' ); ?> 390 </label> 391 </td> 392 </tr> 393 <?php endif; ?> 394 395 <?php 396 $languages = get_available_languages(); 397 $can_install_translations = current_user_can( 'install_languages' ) && wp_can_install_language_pack(); 398 ?> 399 <?php if ( $languages || $can_install_translations ) : ?> 400 <tr class="user-language-wrap"> 401 <th scope="row"> 402 <?php /* translators: The user language selection field label. */ ?> 403 <label for="locale"><?php _e( 'Language' ); ?><span class="dashicons dashicons-translation" aria-hidden="true"></span></label> 404 </th> 405 <td> 406 <?php 407 $user_locale = $profile_user->locale; 408 409 if ( 'en_US' === $user_locale ) { 410 $user_locale = ''; 411 } elseif ( '' === $user_locale || ! in_array( $user_locale, $languages, true ) ) { 412 $user_locale = 'site-default'; 413 } 414 415 wp_dropdown_languages( 416 array( 417 'name' => 'locale', 418 'id' => 'locale', 419 'selected' => $user_locale, 420 'languages' => $languages, 421 'show_available_translations' => $can_install_translations, 422 'show_option_site_default' => true, 423 ) 424 ); 425 ?> 426 </td> 427 </tr> 428 <?php endif; ?> 429 430 <?php 431 /** 432 * Fires at the end of the 'Personal Options' settings table on the user editing screen. 433 * 434 * @since 2.7.0 435 * 436 * @param WP_User $profile_user The current WP_User object. 437 */ 438 do_action( 'personal_options', $profile_user ); 439 ?> 440 441 </table> 442 <?php 443 if ( IS_PROFILE_PAGE ) { 444 /** 445 * Fires after the 'Personal Options' settings table on the 'Profile' editing screen. 446 * 447 * The action only fires if the current user is editing their own profile. 448 * 449 * @since 2.0.0 450 * 451 * @param WP_User $profile_user The current WP_User object. 452 */ 453 do_action( 'profile_personal_options', $profile_user ); 454 } 455 ?> 456 457 <h2><?php _e( 'Name' ); ?></h2> 458 459 <table class="form-table" role="presentation"> 460 <tr class="user-user-login-wrap"> 461 <th><label for="user_login"><?php _e( 'Username' ); ?></label></th> 462 <td><input type="text" name="user_login" id="user_login" value="<?php echo esc_attr( $profile_user->user_login ); ?>" readonly="readonly" class="regular-text ltr" /> <span class="description"><?php _e( 'Usernames cannot be changed.' ); ?></span></td> 463 </tr> 464 465 <?php if ( ! IS_PROFILE_PAGE && ! is_network_admin() && current_user_can( 'promote_user', $profile_user->ID ) ) : ?> 466 <tr class="user-role-wrap"> 467 <th><label for="role"><?php _e( 'Role' ); ?></label></th> 468 <td> 469 <select name="role" id="role"> 470 <?php 471 // Compare user role against currently editable roles. 472 $user_roles = array_intersect( array_values( $profile_user->roles ), array_keys( get_editable_roles() ) ); 473 $user_role = reset( $user_roles ); 474 475 // Print the full list of roles with the primary one selected. 476 wp_dropdown_roles( $user_role ); 477 478 // Print the 'no role' option. Make it selected if the user has no role yet. 479 if ( $user_role ) { 480 echo '<option value="">' . __( '— No role for this site —' ) . '</option>'; 481 } else { 482 echo '<option value="" selected="selected">' . __( '— No role for this site —' ) . '</option>'; 483 } 484 ?> 485 </select> 486 </td> 487 </tr> 488 <?php endif; // End if ! IS_PROFILE_PAGE. ?> 489 490 <?php if ( is_multisite() && is_network_admin() && ! IS_PROFILE_PAGE && ! isset( $super_admins ) ) : ?> 491 <tr class="user-super-admin-wrap"> 492 <th><?php _e( 'Super Admin' ); ?></th> 493 <td> 494 <p><label><input type="checkbox" id="super_admin" name="super_admin"<?php checked( is_super_admin( $profile_user->ID ) ); ?> /> <?php _e( 'Grant this user super admin privileges for the Network.' ); ?></label></p> 495 </td> 496 </tr> 497 <?php endif; ?> 498 499 <tr class="user-first-name-wrap"> 500 <th><label for="first_name"><?php _e( 'First Name' ); ?></label></th> 501 <td> 502 <?php if ( IS_PROFILE_PAGE ) : ?> 503 <input type="text" name="first_name" id="first_name" value="<?php echo esc_attr( $profile_user->first_name ); ?>" autocomplete="given-name" class="regular-text" /> 504 <?php else : ?> 505 <input type="text" name="first_name" id="first_name" value="<?php echo esc_attr( $profile_user->first_name ); ?>" class="regular-text" /> 506 <?php endif; ?> 507 </td> 508 </tr> 509 510 <tr class="user-last-name-wrap"> 511 <th><label for="last_name"><?php _e( 'Last Name' ); ?></label></th> 512 <td> 513 <?php if ( IS_PROFILE_PAGE ) : ?> 514 <input type="text" name="last_name" id="last_name" value="<?php echo esc_attr( $profile_user->last_name ); ?>" autocomplete="family-name" class="regular-text" /> 515 <?php else : ?> 516 <input type="text" name="last_name" id="last_name" value="<?php echo esc_attr( $profile_user->last_name ); ?>" class="regular-text" /> 517 <?php endif; ?> 518 </td> 519 </tr> 520 521 <tr class="user-nickname-wrap"> 522 <th><label for="nickname"><?php _e( 'Nickname' ); ?> <span class="description"><?php _e( '(required)' ); ?></span></label></th> 523 <td> 524 <?php if ( IS_PROFILE_PAGE ) : ?> 525 <input type="text" name="nickname" id="nickname" value="<?php echo esc_attr( $profile_user->nickname ); ?>" autocomplete="nickname" class="regular-text" /> 526 <?php else : ?> 527 <input type="text" name="nickname" id="nickname" value="<?php echo esc_attr( $profile_user->nickname ); ?>" class="regular-text" /> 528 <?php endif; ?> 529 </td> 530 </tr> 531 532 <tr class="user-display-name-wrap"> 533 <th> 534 <label for="display_name"><?php _e( 'Display name publicly as' ); ?></label> 535 </th> 536 <td> 537 <select name="display_name" id="display_name"> 538 <?php 539 $public_display = array(); 540 $public_display['display_nickname'] = $profile_user->nickname; 541 $public_display['display_username'] = $profile_user->user_login; 542 543 if ( ! empty( $profile_user->first_name ) ) { 544 $public_display['display_firstname'] = $profile_user->first_name; 545 } 546 547 if ( ! empty( $profile_user->last_name ) ) { 548 $public_display['display_lastname'] = $profile_user->last_name; 549 } 550 551 if ( ! empty( $profile_user->first_name ) && ! empty( $profile_user->last_name ) ) { 552 $public_display['display_firstlast'] = $profile_user->first_name . ' ' . $profile_user->last_name; 553 $public_display['display_lastfirst'] = $profile_user->last_name . ' ' . $profile_user->first_name; 554 } 555 556 if ( ! in_array( $profile_user->display_name, $public_display, true ) ) { // Only add this if it isn't duplicated elsewhere. 557 $public_display = array( 'display_displayname' => $profile_user->display_name ) + $public_display; 558 } 559 560 $public_display = array_map( 'trim', $public_display ); 561 $public_display = array_unique( $public_display ); 562 563 ?> 564 <?php foreach ( $public_display as $id => $item ) : ?> 565 <option <?php selected( $profile_user->display_name, $item ); ?>><?php echo $item; ?></option> 566 <?php endforeach; ?> 567 </select> 568 </td> 569 </tr> 570 </table> 571 572 <h2><?php _e( 'Contact Info' ); ?></h2> 573 574 <table class="form-table" role="presentation"> 575 <tr class="user-email-wrap"> 576 <th><label for="email"><?php _e( 'Email' ); ?> <span class="description"><?php _e( '(required)' ); ?></span></label></th> 577 <td> 578 <?php if ( $profile_user->ID === $current_user->ID ) : ?> 579 <input type="email" name="email" id="email" aria-describedby="email-description" value="<?php echo esc_attr( $profile_user->user_email ); ?>" autocomplete="email" class="regular-text ltr" /> 580 <p class="description" id="email-description"> 581 <?php _e( 'If you change this, an email will be sent at your new address to confirm it. <strong>The new address will not become active until confirmed.</strong>' ); ?> 582 </p> 583 <?php else : ?> 584 <input type="email" name="email" id="email" value="<?php echo esc_attr( $profile_user->user_email ); ?>" class="regular-text ltr" /> 585 <?php endif; ?> 586 587 <?php 588 $new_email = get_user_meta( $current_user->ID, '_new_email', true ); 589 if ( $new_email && $new_email['newemail'] !== $current_user->user_email && $profile_user->ID === $current_user->ID ) : 590 591 $pending_change_message = sprintf( 592 /* translators: %s: New email. */ 593 __( 'There is a pending change of your email to %s.' ), 594 '<code>' . esc_html( $new_email['newemail'] ) . '</code>' 595 ); 596 $pending_change_message .= sprintf( 597 ' <a href="%1$s">%2$s</a>', 598 esc_url( wp_nonce_url( self_admin_url( 'profile.php?dismiss=' . $current_user->ID . '_new_email' ), 'dismiss-' . $current_user->ID . '_new_email' ) ), 599 __( 'Cancel' ) 600 ); 601 wp_admin_notice( 602 $pending_change_message, 603 array( 604 'additional_classes' => array( 'updated', 'inline' ), 605 ) 606 ); 607 endif; 608 ?> 609 </td> 610 </tr> 611 612 <tr class="user-url-wrap"> 613 <th><label for="url"><?php _e( 'Website' ); ?></label></th> 614 <td><input type="url" name="url" id="url" value="<?php echo esc_attr( $profile_user->user_url ); ?>" class="regular-text code" /></td> 615 </tr> 616 617 <?php foreach ( wp_get_user_contact_methods( $profile_user ) as $name => $desc ) : ?> 618 <tr class="user-<?php echo $name; ?>-wrap"> 619 <th> 620 <label for="<?php echo $name; ?>"> 621 <?php 622 /** 623 * Filters a user contactmethod label. 624 * 625 * The dynamic portion of the hook name, `$name`, refers to 626 * each of the keys in the contact methods array. 627 * 628 * @since 2.9.0 629 * 630 * @param string $desc The translatable label for the contact method. 631 */ 632 echo apply_filters( "user_{$name}_label", $desc ); 633 ?> 634 </label> 635 </th> 636 <td> 637 <input type="text" name="<?php echo $name; ?>" id="<?php echo $name; ?>" value="<?php echo esc_attr( $profile_user->$name ); ?>" class="regular-text" /> 638 </td> 639 </tr> 640 <?php endforeach; ?> 641 </table> 642 643 <h2><?php IS_PROFILE_PAGE ? _e( 'About Yourself' ) : _e( 'About the user' ); ?></h2> 644 645 <table class="form-table" role="presentation"> 646 <tr class="user-description-wrap"> 647 <th><label for="description"><?php _e( 'Biographical Info' ); ?></label></th> 648 <td><textarea name="description" id="description" rows="5" cols="30"><?php echo $profile_user->description; // textarea_escaped ?></textarea> 649 <p class="description"><?php _e( 'Share a little biographical information to fill out your profile. This may be shown publicly.' ); ?></p></td> 650 </tr> 651 652 <?php if ( get_option( 'show_avatars' ) ) : ?> 653 <tr class="user-profile-picture"> 654 <th><?php _e( 'Profile Picture' ); ?></th> 655 <td> 656 <?php echo get_avatar( $user_id ); ?> 657 <p class="description"> 658 <?php 659 if ( IS_PROFILE_PAGE ) { 660 $description = sprintf( 661 /* translators: %s: Gravatar URL. */ 662 __( '<a href="%s">You can change your profile picture on Gravatar</a>.' ), 663 /* translators: The localized Gravatar URL. */ 664 __( 'https://gravatar.com/' ) 665 ); 666 } else { 667 $description = ''; 668 } 669 670 /** 671 * Filters the user profile picture description displayed under the Gravatar. 672 * 673 * @since 4.4.0 674 * @since 4.7.0 Added the `$profile_user` parameter. 675 * 676 * @param string $description The description that will be printed. 677 * @param WP_User $profile_user The current WP_User object. 678 */ 679 echo apply_filters( 'user_profile_picture_description', $description, $profile_user ); 680 ?> 681 </p> 682 </td> 683 </tr> 684 <?php endif; ?> 685 <?php 686 /** 687 * Filters the display of the password fields. 688 * 689 * @since 1.5.1 690 * @since 2.8.0 Added the `$profile_user` parameter. 691 * @since 4.4.0 Now evaluated only in user-edit.php. 692 * 693 * @param bool $show Whether to show the password fields. Default true. 694 * @param WP_User $profile_user User object for the current user to edit. 695 */ 696 $show_password_fields = apply_filters( 'show_password_fields', true, $profile_user ); 697 ?> 698 <?php if ( $show_password_fields ) : ?> 699 </table> 700 701 <h2><?php _e( 'Account Management' ); ?></h2> 702 703 <table class="form-table" role="presentation"> 704 <tr id="password" class="user-pass1-wrap"> 705 <th><label for="pass1"><?php _e( 'New Password' ); ?></label></th> 706 <td> 707 <input type="hidden" value=" " /><!-- #24364 workaround --> 708 <button type="button" class="button wp-generate-pw hide-if-no-js" aria-expanded="false"><?php _e( 'Set New Password' ); ?></button> 709 <div class="wp-pwd hide-if-js"> 710 <div class="password-input-wrapper"> 711 <input type="password" name="pass1" id="pass1" class="regular-text ltr" value="" autocomplete="new-password" spellcheck="false" data-pw="<?php echo esc_attr( wp_generate_password( 24 ) ); ?>" aria-describedby="pass-strength-result" /> 712 <div style="display:none" id="pass-strength-result" aria-live="polite"></div> 713 </div> 714 <button type="button" class="button wp-hide-pw user-new-password-toggle hide-if-no-js" data-toggle="0" aria-label="<?php esc_attr_e( 'Hide password' ); ?>"> 715 <span class="dashicons dashicons-hidden" aria-hidden="true"></span> 716 <span class="text"><?php _e( 'Hide' ); ?></span> 717 </button> 718 <button type="button" class="button wp-cancel-pw hide-if-no-js" data-toggle="0" aria-label="<?php esc_attr_e( 'Cancel password change' ); ?>"> 719 <span class="dashicons dashicons-no" aria-hidden="true"></span> 720 <span class="text"><?php _e( 'Cancel' ); ?></span> 721 </button> 722 </div> 723 </td> 724 </tr> 725 <tr class="user-pass2-wrap hide-if-js"> 726 <th scope="row"><label for="pass2"><?php _e( 'Repeat New Password' ); ?></label></th> 727 <td> 728 <input type="password" name="pass2" id="pass2" class="regular-text" value="" autocomplete="new-password" spellcheck="false" aria-describedby="pass2-desc" /> 729 <?php if ( IS_PROFILE_PAGE ) : ?> 730 <p class="description" id="pass2-desc"><?php _e( 'Type your new password again.' ); ?></p> 731 <?php else : ?> 732 <p class="description" id="pass2-desc"><?php _e( 'Type the new password again.' ); ?></p> 733 <?php endif; ?> 734 </td> 735 </tr> 736 <tr class="pw-weak"> 737 <th><?php _e( 'Confirm Password' ); ?></th> 738 <td> 739 <label> 740 <input type="checkbox" name="pw_weak" class="pw-checkbox" /> 741 <span id="pw-weak-text-label"><?php _e( 'Confirm use of weak password' ); ?></span> 742 </label> 743 </td> 744 </tr> 745 <?php endif; // End Show Password Fields. ?> 746 747 <?php // Allow admins to send reset password link. ?> 748 <?php if ( ! IS_PROFILE_PAGE && true === wp_is_password_reset_allowed_for_user( $profile_user ) ) : ?> 749 <tr class="user-generate-reset-link-wrap hide-if-no-js"> 750 <th><?php _e( 'Password Reset' ); ?></th> 751 <td> 752 <div class="generate-reset-link"> 753 <button type="button" class="button button-secondary" id="generate-reset-link"> 754 <?php _e( 'Send Reset Link' ); ?> 755 </button> 756 </div> 757 <p class="description"> 758 <?php 759 printf( 760 /* translators: %s: User's display name. */ 761 __( 'Send %s a link to reset their password. This will not change their password, nor will it force a change.' ), 762 esc_html( $profile_user->display_name ) 763 ); 764 ?> 765 </p> 766 </td> 767 </tr> 768 <?php endif; ?> 769 770 <?php if ( IS_PROFILE_PAGE && count( $sessions->get_all() ) === 1 ) : ?> 771 <tr class="user-sessions-wrap hide-if-no-js"> 772 <th><?php _e( 'Sessions' ); ?></th> 773 <td aria-live="assertive"> 774 <div class="destroy-sessions"><button type="button" disabled class="button"><?php _e( 'Log Out Everywhere Else' ); ?></button></div> 775 <p class="description"> 776 <?php _e( 'You are only logged in at this location.' ); ?> 777 </p> 778 </td> 779 </tr> 780 <?php elseif ( IS_PROFILE_PAGE && count( $sessions->get_all() ) > 1 ) : ?> 781 <tr class="user-sessions-wrap hide-if-no-js"> 782 <th><?php _e( 'Sessions' ); ?></th> 783 <td aria-live="assertive"> 784 <div class="destroy-sessions"><button type="button" class="button" id="destroy-sessions"><?php _e( 'Log Out Everywhere Else' ); ?></button></div> 785 <p class="description"> 786 <?php _e( 'Did you lose your phone or leave your account logged in at a public computer? You can log out everywhere else, and stay logged in here.' ); ?> 787 </p> 788 </td> 789 </tr> 790 <?php elseif ( ! IS_PROFILE_PAGE && $sessions->get_all() ) : ?> 791 <tr class="user-sessions-wrap hide-if-no-js"> 792 <th><?php _e( 'Sessions' ); ?></th> 793 <td> 794 <p><button type="button" class="button" id="destroy-sessions"><?php _e( 'Log Out Everywhere' ); ?></button></p> 795 <p class="description"> 796 <?php 797 /* translators: %s: User's display name. */ 798 printf( __( 'Log %s out of all locations.' ), $profile_user->display_name ); 799 ?> 800 </p> 801 </td> 802 </tr> 803 <?php endif; ?> 804 </table> 805 806 <?php if ( wp_is_application_passwords_available_for_user( $user_id ) || ! wp_is_application_passwords_supported() ) : ?> 807 <div class="application-passwords hide-if-no-js" id="application-passwords-section"> 808 <h2><?php _e( 'Application Passwords' ); ?></h2> 809 <p><?php _e( 'Application passwords allow authentication via non-interactive systems, such as XML-RPC or the REST API, without providing your actual password. Application passwords can be easily revoked. They cannot be used for traditional logins to your website.' ); ?></p> 810 <?php if ( wp_is_application_passwords_available_for_user( $user_id ) ) : ?> 811 <?php 812 if ( is_multisite() ) : 813 $blogs = get_blogs_of_user( $user_id, true ); 814 $blogs_count = count( $blogs ); 815 816 if ( $blogs_count > 1 ) : 817 ?> 818 <p> 819 <?php 820 /* translators: 1: URL to my-sites.php, 2: Number of sites the user has. */ 821 $message = _n( 822 'Application passwords grant access to <a href="%1$s">the %2$s site in this installation that you have permissions on</a>.', 823 'Application passwords grant access to <a href="%1$s">all %2$s sites in this installation that you have permissions on</a>.', 824 $blogs_count 825 ); 826 827 if ( is_super_admin( $user_id ) ) { 828 /* translators: 1: URL to my-sites.php, 2: Number of sites the user has. */ 829 $message = _n( 830 'Application passwords grant access to <a href="%1$s">the %2$s site on the network as you have Super Admin rights</a>.', 831 'Application passwords grant access to <a href="%1$s">all %2$s sites on the network as you have Super Admin rights</a>.', 832 $blogs_count 833 ); 834 } 835 836 printf( 837 $message, 838 admin_url( 'my-sites.php' ), 839 number_format_i18n( $blogs_count ) 840 ); 841 ?> 842 </p> 843 <?php 844 endif; 845 endif; 846 ?> 847 848 <?php if ( ! wp_is_site_protected_by_basic_auth( 'front' ) ) : ?> 849 <div class="create-application-password form-wrap"> 850 <div class="form-field"> 851 <label for="new_application_password_name"><?php _e( 'New Application Password Name' ); ?></label> 852 <input type="text" size="30" id="new_application_password_name" name="new_application_password_name" class="input ltr" aria-required="true" aria-describedby="new_application_password_name_desc" spellcheck="false" /> 853 <p class="description" id="new_application_password_name_desc"><?php _e( 'Required to create an Application Password, but not to update the user.' ); ?></p> 854 </div> 855 856 <?php 857 /** 858 * Fires in the create Application Passwords form. 859 * 860 * @since 5.6.0 861 * 862 * @param WP_User $profile_user The current WP_User object. 863 */ 864 do_action( 'wp_create_application_password_form', $profile_user ); 865 ?> 866 867 <button type="button" name="do_new_application_password" id="do_new_application_password" class="button button-secondary"><?php _e( 'Add Application Password' ); ?></button> 868 </div> 869 <?php 870 else : 871 wp_admin_notice( 872 __( 'Your website appears to use Basic Authentication, which is not currently compatible with Application Passwords.' ), 873 array( 874 'type' => 'error', 875 'additional_classes' => array( 'inline' ), 876 ) 877 ); 878 endif; 879 ?> 880 881 <div class="application-passwords-list-table-wrapper"> 882 <?php 883 $application_passwords_list_table = _get_list_table( 'WP_Application_Passwords_List_Table', array( 'screen' => 'application-passwords-user' ) ); 884 $application_passwords_list_table->prepare_items(); 885 $application_passwords_list_table->display(); 886 ?> 887 </div> 888 <?php elseif ( ! wp_is_application_passwords_supported() ) : ?> 889 <p><?php _e( 'The application password feature requires HTTPS, which is not enabled on this site.' ); ?></p> 890 <p> 891 <?php 892 printf( 893 /* translators: %s: Documentation URL. */ 894 __( 'If this is a development website, you can <a href="%s">set the environment type accordingly</a> to enable application passwords.' ), 895 __( 'https://developer.wordpress.org/apis/wp-config-php/#wp-environment-type' ) 896 ); 897 ?> 898 </p> 899 <?php endif; ?> 900 </div> 901 <?php endif; // End Application Passwords. ?> 902 903 <?php 904 if ( IS_PROFILE_PAGE ) { 905 /** 906 * Fires after the 'Application Passwords' section is loaded on the 'Profile' editing screen. 907 * 908 * The action only fires if the current user is editing their own profile. 909 * 910 * @since 2.0.0 911 * 912 * @param WP_User $profile_user The current WP_User object. 913 */ 914 do_action( 'show_user_profile', $profile_user ); 915 } else { 916 /** 917 * Fires after the 'Application Passwords' section is loaded on 'Edit User' screen. 918 * 919 * The action only fires if the current user is editing another user's profile. 920 * 921 * @since 2.0.0 922 * 923 * @param WP_User $profile_user The current WP_User object. 924 */ 925 do_action( 'edit_user_profile', $profile_user ); 926 } 927 ?> 928 929 <?php 930 /** 931 * Filters whether to display additional capabilities for the user. 932 * 933 * The 'Additional Capabilities' section will only be enabled if 934 * the number of the user's capabilities exceeds their number of 935 * roles. 936 * 937 * @since 2.8.0 938 * 939 * @param bool $enable Whether to display the capabilities. Default true. 940 * @param WP_User $profile_user The current WP_User object. 941 */ 942 $display_additional_caps = apply_filters( 'additional_capabilities_display', true, $profile_user ); 943 ?> 944 945 <?php if ( count( $profile_user->caps ) > count( $profile_user->roles ) && ( true === $display_additional_caps ) ) : ?> 946 <h2><?php _e( 'Additional Capabilities' ); ?></h2> 947 948 <table class="form-table" role="presentation"> 949 <tr class="user-capabilities-wrap"> 950 <th scope="row"><?php _e( 'Capabilities' ); ?></th> 951 <td> 952 <?php 953 $output = ''; 954 foreach ( $profile_user->caps as $cap => $value ) { 955 if ( ! $wp_roles->is_role( $cap ) ) { 956 if ( '' !== $output ) { 957 $output .= ', '; 958 } 959 960 if ( $value ) { 961 $output .= $cap; 962 } else { 963 /* translators: %s: Capability name. */ 964 $output .= sprintf( __( 'Denied: %s' ), $cap ); 965 } 966 } 967 } 968 echo $output; 969 ?> 970 </td> 971 </tr> 972 </table> 973 <?php endif; // End Display Additional Capabilities. ?> 974 975 <input type="hidden" name="action" value="update" /> 976 <input type="hidden" name="user_id" id="user_id" value="<?php echo esc_attr( $user_id ); ?>" /> 977 978 <?php submit_button( IS_PROFILE_PAGE ? __( 'Update Profile' ) : __( 'Update User' ) ); ?> 979 980 </form> 981 </div> 982 <?php 983 break; 984 } 985 ?> 986 <script> 987 if (window.location.hash == '#password') { 988 document.getElementById('pass1').focus(); 989 } 990 </script> 991 992 <script> 993 jQuery( function( $ ) { 994 var languageSelect = $( '#locale' ); 995 $( 'form' ).on( 'submit', function() { 996 /* 997 * Don't show a spinner for English and installed languages, 998 * as there is nothing to download. 999 */ 1000 if ( ! languageSelect.find( 'option:selected' ).data( 'installed' ) ) { 1001 $( '#submit', this ).after( '<span class="spinner language-install-spinner is-active" />' ); 1002 } 1003 }); 1004 } ); 1005 </script> 1006 1007 <?php if ( isset( $application_passwords_list_table ) ) : ?> 1008 <script type="text/html" id="tmpl-new-application-password"> 1009 <div class="notice notice-success is-dismissible new-application-password-notice" role="alert"> 1010 <p class="application-password-display"> 1011 <label for="new-application-password-value"> 1012 <?php 1013 printf( 1014 /* translators: %s: Application name. */ 1015 __( 'Your new password for %s is:' ), 1016 '<strong>{{ data.name }}</strong>' 1017 ); 1018 ?> 1019 </label> 1020 <input id="new-application-password-value" type="text" class="code" readonly="readonly" value="{{ data.password }}" /> 1021 <button type="button" class="button copy-button" data-clipboard-text="{{ data.password }}"><?php _e( 'Copy' ); ?></button> 1022 <span class="success hidden" aria-hidden="true"><?php _e( 'Copied!' ); ?></span> 1023 </p> 1024 <p><?php _e( 'Be sure to save this in a safe location. You will not be able to retrieve it.' ); ?></p> 1025 <button type="button" class="notice-dismiss"> 1026 <span class="screen-reader-text"> 1027 <?php 1028 /* translators: Hidden accessibility text. */ 1029 _e( 'Dismiss this notice.' ); 1030 ?> 1031 </span> 1032 </button> 1033 </div> 1034 </script> 1035 1036 <script type="text/html" id="tmpl-application-password-row"> 1037 <?php $application_passwords_list_table->print_js_template_row(); ?> 1038 </script> 1039 <?php endif; ?> 1040 <?php 1041 require_once ABSPATH . 'wp-admin/admin-footer.php';
title
Description
Body
title
Description
Body
title
Description
Body
title
Body
| Generated : Sun Oct 4 08:20:33 2026 | Cross-referenced by PHPXref |