Edit File by line
/home/barbar84/www/wp-admin/network
File: users.php
<?php
[0] Fix | Delete
/**
[1] Fix | Delete
* Multisite users administration panel.
[2] Fix | Delete
*
[3] Fix | Delete
* @package WordPress
[4] Fix | Delete
* @subpackage Multisite
[5] Fix | Delete
* @since 3.0.0
[6] Fix | Delete
*/
[7] Fix | Delete
[8] Fix | Delete
/** Load WordPress Administration Bootstrap */
[9] Fix | Delete
require_once __DIR__ . '/admin.php';
[10] Fix | Delete
[11] Fix | Delete
if ( ! current_user_can( 'manage_network_users' ) ) {
[12] Fix | Delete
wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
[13] Fix | Delete
}
[14] Fix | Delete
[15] Fix | Delete
if ( isset( $_GET['action'] ) ) {
[16] Fix | Delete
/** This action is documented in wp-admin/network/edit.php */
[17] Fix | Delete
do_action( 'wpmuadminedit' );
[18] Fix | Delete
[19] Fix | Delete
switch ( $_GET['action'] ) {
[20] Fix | Delete
case 'deleteuser':
[21] Fix | Delete
if ( ! current_user_can( 'manage_network_users' ) ) {
[22] Fix | Delete
wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
[23] Fix | Delete
}
[24] Fix | Delete
[25] Fix | Delete
check_admin_referer( 'deleteuser' );
[26] Fix | Delete
[27] Fix | Delete
$id = (int) $_GET['id'];
[28] Fix | Delete
if ( $id > 1 ) {
[29] Fix | Delete
$_POST['allusers'] = array( $id ); // confirm_delete_users() can only handle arrays.
[30] Fix | Delete
$title = __( 'Users' );
[31] Fix | Delete
$parent_file = 'users.php';
[32] Fix | Delete
require_once ABSPATH . 'wp-admin/admin-header.php';
[33] Fix | Delete
echo '<div class="wrap">';
[34] Fix | Delete
confirm_delete_users( $_POST['allusers'] );
[35] Fix | Delete
echo '</div>';
[36] Fix | Delete
require_once ABSPATH . 'wp-admin/admin-footer.php';
[37] Fix | Delete
} else {
[38] Fix | Delete
wp_redirect( network_admin_url( 'users.php' ) );
[39] Fix | Delete
}
[40] Fix | Delete
exit;
[41] Fix | Delete
[42] Fix | Delete
case 'allusers':
[43] Fix | Delete
if ( ! current_user_can( 'manage_network_users' ) ) {
[44] Fix | Delete
wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
[45] Fix | Delete
}
[46] Fix | Delete
[47] Fix | Delete
if ( isset( $_POST['action'] ) && isset( $_POST['allusers'] ) ) {
[48] Fix | Delete
check_admin_referer( 'bulk-users-network' );
[49] Fix | Delete
[50] Fix | Delete
$doaction = $_POST['action'];
[51] Fix | Delete
$userfunction = '';
[52] Fix | Delete
[53] Fix | Delete
foreach ( (array) $_POST['allusers'] as $user_id ) {
[54] Fix | Delete
if ( ! empty( $user_id ) ) {
[55] Fix | Delete
switch ( $doaction ) {
[56] Fix | Delete
case 'delete':
[57] Fix | Delete
if ( ! current_user_can( 'delete_users' ) ) {
[58] Fix | Delete
wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
[59] Fix | Delete
}
[60] Fix | Delete
$title = __( 'Users' );
[61] Fix | Delete
$parent_file = 'users.php';
[62] Fix | Delete
require_once ABSPATH . 'wp-admin/admin-header.php';
[63] Fix | Delete
echo '<div class="wrap">';
[64] Fix | Delete
confirm_delete_users( $_POST['allusers'] );
[65] Fix | Delete
echo '</div>';
[66] Fix | Delete
require_once ABSPATH . 'wp-admin/admin-footer.php';
[67] Fix | Delete
exit;
[68] Fix | Delete
[69] Fix | Delete
case 'spam':
[70] Fix | Delete
$user = get_userdata( $user_id );
[71] Fix | Delete
if ( is_super_admin( $user->ID ) ) {
[72] Fix | Delete
wp_die(
[73] Fix | Delete
sprintf(
[74] Fix | Delete
/* translators: %s: User login. */
[75] Fix | Delete
__( 'Warning! User cannot be modified. The user %s is a network administrator.' ),
[76] Fix | Delete
esc_html( $user->user_login )
[77] Fix | Delete
)
[78] Fix | Delete
);
[79] Fix | Delete
}
[80] Fix | Delete
[81] Fix | Delete
$userfunction = 'all_spam';
[82] Fix | Delete
$blogs = get_blogs_of_user( $user_id, true );
[83] Fix | Delete
[84] Fix | Delete
foreach ( (array) $blogs as $details ) {
[85] Fix | Delete
if ( get_network()->site_id != $details->userblog_id ) { // Main blog is not a spam!
[86] Fix | Delete
update_blog_status( $details->userblog_id, 'spam', '1' );
[87] Fix | Delete
}
[88] Fix | Delete
}
[89] Fix | Delete
[90] Fix | Delete
$user_data = $user->to_array();
[91] Fix | Delete
$user_data['spam'] = '1';
[92] Fix | Delete
[93] Fix | Delete
wp_update_user( $user_data );
[94] Fix | Delete
break;
[95] Fix | Delete
[96] Fix | Delete
case 'notspam':
[97] Fix | Delete
$user = get_userdata( $user_id );
[98] Fix | Delete
[99] Fix | Delete
$userfunction = 'all_notspam';
[100] Fix | Delete
$blogs = get_blogs_of_user( $user_id, true );
[101] Fix | Delete
[102] Fix | Delete
foreach ( (array) $blogs as $details ) {
[103] Fix | Delete
update_blog_status( $details->userblog_id, 'spam', '0' );
[104] Fix | Delete
}
[105] Fix | Delete
[106] Fix | Delete
$user_data = $user->to_array();
[107] Fix | Delete
$user_data['spam'] = '0';
[108] Fix | Delete
[109] Fix | Delete
wp_update_user( $user_data );
[110] Fix | Delete
break;
[111] Fix | Delete
}
[112] Fix | Delete
}
[113] Fix | Delete
}
[114] Fix | Delete
[115] Fix | Delete
if ( ! in_array( $doaction, array( 'delete', 'spam', 'notspam' ), true ) ) {
[116] Fix | Delete
$sendback = wp_get_referer();
[117] Fix | Delete
$user_ids = (array) $_POST['allusers'];
[118] Fix | Delete
[119] Fix | Delete
/** This action is documented in wp-admin/network/site-themes.php */
[120] Fix | Delete
$sendback = apply_filters( 'handle_network_bulk_actions-' . get_current_screen()->id, $sendback, $doaction, $user_ids ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores
[121] Fix | Delete
[122] Fix | Delete
wp_safe_redirect( $sendback );
[123] Fix | Delete
exit;
[124] Fix | Delete
}
[125] Fix | Delete
[126] Fix | Delete
wp_safe_redirect(
[127] Fix | Delete
add_query_arg(
[128] Fix | Delete
array(
[129] Fix | Delete
'updated' => 'true',
[130] Fix | Delete
'action' => $userfunction,
[131] Fix | Delete
),
[132] Fix | Delete
wp_get_referer()
[133] Fix | Delete
)
[134] Fix | Delete
);
[135] Fix | Delete
} else {
[136] Fix | Delete
$location = network_admin_url( 'users.php' );
[137] Fix | Delete
[138] Fix | Delete
if ( ! empty( $_REQUEST['paged'] ) ) {
[139] Fix | Delete
$location = add_query_arg( 'paged', (int) $_REQUEST['paged'], $location );
[140] Fix | Delete
}
[141] Fix | Delete
wp_redirect( $location );
[142] Fix | Delete
}
[143] Fix | Delete
exit;
[144] Fix | Delete
[145] Fix | Delete
case 'dodelete':
[146] Fix | Delete
check_admin_referer( 'ms-users-delete' );
[147] Fix | Delete
if ( ! ( current_user_can( 'manage_network_users' ) && current_user_can( 'delete_users' ) ) ) {
[148] Fix | Delete
wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
[149] Fix | Delete
}
[150] Fix | Delete
[151] Fix | Delete
if ( ! empty( $_POST['blog'] ) && is_array( $_POST['blog'] ) ) {
[152] Fix | Delete
foreach ( $_POST['blog'] as $id => $users ) {
[153] Fix | Delete
foreach ( $users as $blogid => $user_id ) {
[154] Fix | Delete
if ( ! current_user_can( 'delete_user', $id ) ) {
[155] Fix | Delete
continue;
[156] Fix | Delete
}
[157] Fix | Delete
[158] Fix | Delete
if ( ! empty( $_POST['delete'] ) && 'reassign' === $_POST['delete'][ $blogid ][ $id ] ) {
[159] Fix | Delete
remove_user_from_blog( $id, $blogid, (int) $user_id );
[160] Fix | Delete
} else {
[161] Fix | Delete
remove_user_from_blog( $id, $blogid );
[162] Fix | Delete
}
[163] Fix | Delete
}
[164] Fix | Delete
}
[165] Fix | Delete
}
[166] Fix | Delete
[167] Fix | Delete
$i = 0;
[168] Fix | Delete
[169] Fix | Delete
if ( is_array( $_POST['user'] ) && ! empty( $_POST['user'] ) ) {
[170] Fix | Delete
foreach ( $_POST['user'] as $id ) {
[171] Fix | Delete
if ( ! current_user_can( 'delete_user', $id ) ) {
[172] Fix | Delete
continue;
[173] Fix | Delete
}
[174] Fix | Delete
wpmu_delete_user( $id );
[175] Fix | Delete
$i++;
[176] Fix | Delete
}
[177] Fix | Delete
}
[178] Fix | Delete
[179] Fix | Delete
if ( 1 === $i ) {
[180] Fix | Delete
$deletefunction = 'delete';
[181] Fix | Delete
} else {
[182] Fix | Delete
$deletefunction = 'all_delete';
[183] Fix | Delete
}
[184] Fix | Delete
[185] Fix | Delete
wp_redirect(
[186] Fix | Delete
add_query_arg(
[187] Fix | Delete
array(
[188] Fix | Delete
'updated' => 'true',
[189] Fix | Delete
'action' => $deletefunction,
[190] Fix | Delete
),
[191] Fix | Delete
network_admin_url( 'users.php' )
[192] Fix | Delete
)
[193] Fix | Delete
);
[194] Fix | Delete
exit;
[195] Fix | Delete
}
[196] Fix | Delete
}
[197] Fix | Delete
[198] Fix | Delete
$wp_list_table = _get_list_table( 'WP_MS_Users_List_Table' );
[199] Fix | Delete
$pagenum = $wp_list_table->get_pagenum();
[200] Fix | Delete
$wp_list_table->prepare_items();
[201] Fix | Delete
$total_pages = $wp_list_table->get_pagination_arg( 'total_pages' );
[202] Fix | Delete
[203] Fix | Delete
if ( $pagenum > $total_pages && $total_pages > 0 ) {
[204] Fix | Delete
wp_redirect( add_query_arg( 'paged', $total_pages ) );
[205] Fix | Delete
exit;
[206] Fix | Delete
}
[207] Fix | Delete
$title = __( 'Users' );
[208] Fix | Delete
$parent_file = 'users.php';
[209] Fix | Delete
[210] Fix | Delete
add_screen_option( 'per_page' );
[211] Fix | Delete
[212] Fix | Delete
get_current_screen()->add_help_tab(
[213] Fix | Delete
array(
[214] Fix | Delete
'id' => 'overview',
[215] Fix | Delete
'title' => __( 'Overview' ),
[216] Fix | Delete
'content' =>
[217] Fix | Delete
'<p>' . __( 'This table shows all users across the network and the sites to which they are assigned.' ) . '</p>' .
[218] Fix | Delete
'<p>' . __( 'Hover over any user on the list to make the edit links appear. The Edit link on the left will take you to their Edit User profile page; the Edit link on the right by any site name goes to an Edit Site screen for that site.' ) . '</p>' .
[219] Fix | Delete
'<p>' . __( 'You can also go to the user&#8217;s profile page by clicking on the individual username.' ) . '</p>' .
[220] Fix | Delete
'<p>' . __( 'You can sort the table by clicking on any of the table headings and switch between list and excerpt views by using the icons above the users list.' ) . '</p>' .
[221] Fix | Delete
'<p>' . __( 'The bulk action will permanently delete selected users, or mark/unmark those selected as spam. Spam users will have posts removed and will be unable to sign up again with the same email addresses.' ) . '</p>' .
[222] Fix | Delete
'<p>' . __( 'You can make an existing user an additional super admin by going to the Edit User profile page and checking the box to grant that privilege.' ) . '</p>',
[223] Fix | Delete
)
[224] Fix | Delete
);
[225] Fix | Delete
[226] Fix | Delete
get_current_screen()->set_help_sidebar(
[227] Fix | Delete
'<p><strong>' . __( 'For more information:' ) . '</strong></p>' .
[228] Fix | Delete
'<p>' . __( '<a href="https://codex.wordpress.org/Network_Admin_Users_Screen">Documentation on Network Users</a>' ) . '</p>' .
[229] Fix | Delete
'<p>' . __( '<a href="https://wordpress.org/support/forum/multisite/">Support Forums</a>' ) . '</p>'
[230] Fix | Delete
);
[231] Fix | Delete
[232] Fix | Delete
get_current_screen()->set_screen_reader_content(
[233] Fix | Delete
array(
[234] Fix | Delete
'heading_views' => __( 'Filter users list' ),
[235] Fix | Delete
'heading_pagination' => __( 'Users list navigation' ),
[236] Fix | Delete
'heading_list' => __( 'Users list' ),
[237] Fix | Delete
)
[238] Fix | Delete
);
[239] Fix | Delete
[240] Fix | Delete
require_once ABSPATH . 'wp-admin/admin-header.php';
[241] Fix | Delete
[242] Fix | Delete
if ( isset( $_REQUEST['updated'] ) && 'true' == $_REQUEST['updated'] && ! empty( $_REQUEST['action'] ) ) {
[243] Fix | Delete
?>
[244] Fix | Delete
<div id="message" class="updated notice is-dismissible"><p>
[245] Fix | Delete
<?php
[246] Fix | Delete
switch ( $_REQUEST['action'] ) {
[247] Fix | Delete
case 'delete':
[248] Fix | Delete
_e( 'User deleted.' );
[249] Fix | Delete
break;
[250] Fix | Delete
case 'all_spam':
[251] Fix | Delete
_e( 'Users marked as spam.' );
[252] Fix | Delete
break;
[253] Fix | Delete
case 'all_notspam':
[254] Fix | Delete
_e( 'Users removed from spam.' );
[255] Fix | Delete
break;
[256] Fix | Delete
case 'all_delete':
[257] Fix | Delete
_e( 'Users deleted.' );
[258] Fix | Delete
break;
[259] Fix | Delete
case 'add':
[260] Fix | Delete
_e( 'User added.' );
[261] Fix | Delete
break;
[262] Fix | Delete
}
[263] Fix | Delete
?>
[264] Fix | Delete
</p></div>
[265] Fix | Delete
<?php
[266] Fix | Delete
}
[267] Fix | Delete
?>
[268] Fix | Delete
<div class="wrap">
[269] Fix | Delete
<h1 class="wp-heading-inline"><?php esc_html_e( 'Users' ); ?></h1>
[270] Fix | Delete
[271] Fix | Delete
<?php
[272] Fix | Delete
if ( current_user_can( 'create_users' ) ) :
[273] Fix | Delete
?>
[274] Fix | Delete
<a href="<?php echo network_admin_url( 'user-new.php' ); ?>" class="page-title-action"><?php echo esc_html_x( 'Add New', 'user' ); ?></a>
[275] Fix | Delete
<?php
[276] Fix | Delete
endif;
[277] Fix | Delete
[278] Fix | Delete
if ( strlen( $usersearch ) ) {
[279] Fix | Delete
echo '<span class="subtitle">';
[280] Fix | Delete
printf(
[281] Fix | Delete
/* translators: %s: Search query. */
[282] Fix | Delete
__( 'Search results for: %s' ),
[283] Fix | Delete
'<strong>' . esc_html( $usersearch ) . '</strong>'
[284] Fix | Delete
);
[285] Fix | Delete
echo '</span>';
[286] Fix | Delete
}
[287] Fix | Delete
?>
[288] Fix | Delete
[289] Fix | Delete
<hr class="wp-header-end">
[290] Fix | Delete
[291] Fix | Delete
<?php $wp_list_table->views(); ?>
[292] Fix | Delete
[293] Fix | Delete
<form method="get" class="search-form">
[294] Fix | Delete
<?php $wp_list_table->search_box( __( 'Search Users' ), 'all-user' ); ?>
[295] Fix | Delete
</form>
[296] Fix | Delete
[297] Fix | Delete
<form id="form-user-list" action="users.php?action=allusers" method="post">
[298] Fix | Delete
<?php $wp_list_table->display(); ?>
[299] Fix | Delete
</form>
[300] Fix | Delete
</div>
[301] Fix | Delete
[302] Fix | Delete
<?php require_once ABSPATH . 'wp-admin/admin-footer.php'; ?>
[303] Fix | Delete
[304] Fix | Delete
It is recommended that you Edit text format, this type of Fix handles quite a lot in one request
Function