wp/wp-admin/network/site-users.php
changeset 7 cf61fcea0001
parent 5 5e2f62d02dcd
child 9 177826044cd9
equal deleted inserted replaced
6:490d5cc509ed 7:cf61fcea0001
     8  */
     8  */
     9 
     9 
    10 /** Load WordPress Administration Bootstrap */
    10 /** Load WordPress Administration Bootstrap */
    11 require_once( dirname( __FILE__ ) . '/admin.php' );
    11 require_once( dirname( __FILE__ ) . '/admin.php' );
    12 
    12 
    13 if ( ! is_multisite() )
       
    14 	wp_die( __( 'Multisite support is not enabled.' ) );
       
    15 
       
    16 if ( ! current_user_can('manage_sites') )
    13 if ( ! current_user_can('manage_sites') )
    17 	wp_die(__('You do not have sufficient permissions to edit this site.'));
    14 	wp_die( __( 'Sorry, you are not allowed to edit this site.' ), 403 );
    18 
    15 
    19 $wp_list_table = _get_list_table('WP_Users_List_Table');
    16 $wp_list_table = _get_list_table('WP_Users_List_Table');
    20 $wp_list_table->prepare_items();
    17 $wp_list_table->prepare_items();
    21 
    18 
    22 get_current_screen()->add_help_tab( array(
    19 get_current_screen()->add_help_tab( get_site_screen_help_tab_args() );
    23 	'id'      => 'overview',
    20 get_current_screen()->set_help_sidebar( get_site_screen_help_sidebar_content() );
    24 	'title'   => __('Overview'),
    21 
    25 	'content' =>
    22 get_current_screen()->set_screen_reader_content( array(
    26 		'<p>' . __('The menu is for editing information specific to individual sites, particularly if the admin area of a site is unavailable.') . '</p>' .
    23 	'heading_views'      => __( 'Filter site users list' ),
    27 		'<p>' . __('<strong>Info</strong> - The domain and path are rarely edited as this can cause the site to not work properly. The Registered date and Last Updated date are displayed. Network admins can mark a site as archived, spam, deleted and mature, to remove from public listings or disable.') . '</p>' .
    24 	'heading_pagination' => __( 'Site users list navigation' ),
    28 		'<p>' . __('<strong>Users</strong> - This displays the users associated with this site. You can also change their role, reset their password, or remove them from the site. Removing the user from the site does not remove the user from the network.') . '</p>' .
    25 	'heading_list'       => __( 'Site users list' ),
    29 		'<p>' . sprintf( __('<strong>Themes</strong> - This area shows themes that are not already enabled across the network. Enabling a theme in this menu makes it accessible to this site. It does not activate the theme, but allows it to show in the site&#8217;s Appearance menu. To enable a theme for the entire network, see the <a href="%s">Network Themes</a> screen.' ), network_admin_url( 'themes.php' ) ) . '</p>' .
       
    30 		'<p>' . __('<strong>Settings</strong> - This page shows a list of all settings associated with this site. Some are created by WordPress and others are created by plugins you activate. Note that some fields are grayed out and say Serialized Data. You cannot modify these values due to the way the setting is stored in the database.') . '</p>'
       
    31 ) );
    26 ) );
    32 
       
    33 get_current_screen()->set_help_sidebar(
       
    34 	'<p><strong>' . __('For more information:') . '</strong></p>' .
       
    35 	'<p>' . __('<a href="https://codex.wordpress.org/Network_Admin_Sites_Screen" target="_blank">Documentation on Site Management</a>') . '</p>' .
       
    36 	'<p>' . __('<a href="https://wordpress.org/support/forum/multisite/" target="_blank">Support Forums</a>') . '</p>'
       
    37 );
       
    38 
    27 
    39 $_SERVER['REQUEST_URI'] = remove_query_arg( 'update', $_SERVER['REQUEST_URI'] );
    28 $_SERVER['REQUEST_URI'] = remove_query_arg( 'update', $_SERVER['REQUEST_URI'] );
    40 $referer = remove_query_arg( 'update', wp_get_referer() );
    29 $referer = remove_query_arg( 'update', wp_get_referer() );
    41 
    30 
    42 if ( ! empty( $_REQUEST['paged'] ) ) {
    31 if ( ! empty( $_REQUEST['paged'] ) ) {
    46 $id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
    35 $id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
    47 
    36 
    48 if ( ! $id )
    37 if ( ! $id )
    49 	wp_die( __('Invalid site ID.') );
    38 	wp_die( __('Invalid site ID.') );
    50 
    39 
    51 $details = get_blog_details( $id );
    40 $details = get_site( $id );
       
    41 if ( ! $details ) {
       
    42 	wp_die( __( 'The requested site does not exist.' ) );
       
    43 }
       
    44 
    52 if ( ! can_edit_network( $details->site_id ) )
    45 if ( ! can_edit_network( $details->site_id ) )
    53 	wp_die( __( 'You do not have permission to access this page.' ), 403 );
    46 	wp_die( __( 'Sorry, you are not allowed to access this page.' ), 403 );
    54 
    47 
    55 $is_main_site = is_main_site( $id );
    48 $is_main_site = is_main_site( $id );
    56 
    49 
    57 switch_to_blog( $id );
    50 switch_to_blog( $id );
    58 
    51 
    68 				$update = 'err_new';
    61 				$update = 'err_new';
    69 			} else {
    62 			} else {
    70 				$password = wp_generate_password( 12, false);
    63 				$password = wp_generate_password( 12, false);
    71 				$user_id = wpmu_create_user( esc_html( strtolower( $user['username'] ) ), $password, esc_html( $user['email'] ) );
    64 				$user_id = wpmu_create_user( esc_html( strtolower( $user['username'] ) ), $password, esc_html( $user['email'] ) );
    72 
    65 
    73 				if ( false == $user_id ) {
    66 				if ( false === $user_id ) {
    74 		 			$update = 'err_new_dup';
    67 		 			$update = 'err_new_dup';
    75 				} else {
    68 				} else {
    76 					wp_new_user_notification( $user_id, $password );
    69 					$result = add_user_to_blog( $id, $user_id, $_POST['new_role'] );
    77 					add_user_to_blog( $id, $user_id, $_POST['new_role'] );
    70 
    78 					$update = 'newuser';
    71 					if ( is_wp_error( $result ) ) {
       
    72 						$update = 'err_add_fail';
       
    73 					} else {
       
    74 						$update = 'newuser';
       
    75 						/**
       
    76 						  * Fires after a user has been created via the network site-users.php page.
       
    77 						  *
       
    78 						  * @since 4.4.0
       
    79 						  *
       
    80 						  * @param int $user_id ID of the newly created user.
       
    81 						  */
       
    82 						do_action( 'network_site_users_created_user', $user_id );
       
    83 					}
    79 				}
    84 				}
    80 			}
    85 			}
    81 			break;
    86 			break;
    82 
    87 
    83 		case 'adduser':
    88 		case 'adduser':
    85 			if ( !empty( $_POST['newuser'] ) ) {
    90 			if ( !empty( $_POST['newuser'] ) ) {
    86 				$update = 'adduser';
    91 				$update = 'adduser';
    87 				$newuser = $_POST['newuser'];
    92 				$newuser = $_POST['newuser'];
    88 				$user = get_user_by( 'login', $newuser );
    93 				$user = get_user_by( 'login', $newuser );
    89 				if ( $user && $user->exists() ) {
    94 				if ( $user && $user->exists() ) {
    90 					if ( ! is_user_member_of_blog( $user->ID, $id ) )
    95 					if ( ! is_user_member_of_blog( $user->ID, $id ) ) {
    91 						add_user_to_blog( $id, $user->ID, $_POST['new_role'] );
    96 						$result = add_user_to_blog( $id, $user->ID, $_POST['new_role'] );
    92 					else
    97 
       
    98 						if ( is_wp_error( $result ) ) {
       
    99 							$update = 'err_add_fail';
       
   100 						}
       
   101 					} else {
    93 						$update = 'err_add_member';
   102 						$update = 'err_add_member';
       
   103 					}
    94 				} else {
   104 				} else {
    95 					$update = 'err_add_notfound';
   105 					$update = 'err_add_notfound';
    96 				}
   106 				}
    97 			} else {
   107 			} else {
    98 				$update = 'err_add_notfound';
   108 				$update = 'err_add_notfound';
    99 			}
   109 			}
   100 			break;
   110 			break;
   101 
   111 
   102 		case 'remove':
   112 		case 'remove':
   103 			if ( ! current_user_can( 'remove_users' )  )
   113 			if ( ! current_user_can( 'remove_users' ) ) {
   104 				die(__('You can&#8217;t remove users.'));
   114 				wp_die( __( 'Sorry, you are not allowed to remove users.' ), 403 );
       
   115 			}
       
   116 
   105 			check_admin_referer( 'bulk-users' );
   117 			check_admin_referer( 'bulk-users' );
   106 
   118 
   107 			$update = 'remove';
   119 			$update = 'remove';
   108 			if ( isset( $_REQUEST['users'] ) ) {
   120 			if ( isset( $_REQUEST['users'] ) ) {
   109 				$userids = $_REQUEST['users'];
   121 				$userids = $_REQUEST['users'];
   120 			break;
   132 			break;
   121 
   133 
   122 		case 'promote':
   134 		case 'promote':
   123 			check_admin_referer( 'bulk-users' );
   135 			check_admin_referer( 'bulk-users' );
   124 			$editable_roles = get_editable_roles();
   136 			$editable_roles = get_editable_roles();
   125 			if ( empty( $editable_roles[$_REQUEST['new_role']] ) )
   137 			$role = false;
   126 				wp_die(__('You can&#8217;t give users that role.'));
   138 			if ( ! empty( $_REQUEST['new_role2'] ) ) {
       
   139 				$role = $_REQUEST['new_role2'];
       
   140 			} elseif ( ! empty( $_REQUEST['new_role'] ) ) {
       
   141 				$role = $_REQUEST['new_role'];
       
   142 			}
       
   143 
       
   144 			if ( empty( $editable_roles[ $role ] ) ) {
       
   145 				wp_die( __( 'Sorry, you are not allowed to give users that role.' ), 403 );
       
   146 			}
   127 
   147 
   128 			if ( isset( $_REQUEST['users'] ) ) {
   148 			if ( isset( $_REQUEST['users'] ) ) {
   129 				$userids = $_REQUEST['users'];
   149 				$userids = $_REQUEST['users'];
   130 				$update = 'promote';
   150 				$update = 'promote';
   131 				foreach ( $userids as $user_id ) {
   151 				foreach ( $userids as $user_id ) {
   132 					$user_id = (int) $user_id;
   152 					$user_id = (int) $user_id;
   133 
   153 
   134 					// If the user doesn't already belong to the blog, bail.
   154 					// If the user doesn't already belong to the blog, bail.
   135 					if ( !is_user_member_of_blog( $user_id ) )
   155 					if ( ! is_user_member_of_blog( $user_id ) ) {
   136 						wp_die( __( 'Cheatin&#8217; uh?' ), 403 );
   156 						wp_die(
       
   157 							'<h1>' . __( 'Something went wrong.' ) . '</h1>' .
       
   158 							'<p>' . __( 'One of the selected users is not a member of this site.' ) . '</p>',
       
   159 							403
       
   160 						);
       
   161 					}
   137 
   162 
   138 					$user = get_userdata( $user_id );
   163 					$user = get_userdata( $user_id );
   139 					$user->set_role( $_REQUEST['new_role'] );
   164 					$user->set_role( $role );
   140 				}
   165 				}
   141 			} else {
   166 			} else {
   142 				$update = 'err_promote';
   167 				$update = 'err_promote';
   143 			}
   168 			}
       
   169 			break;
       
   170 		default:
       
   171 			if ( ! isset( $_REQUEST['users'] ) ) {
       
   172 				break;
       
   173 			}
       
   174 			check_admin_referer( 'bulk-users' );
       
   175 			$userids = $_REQUEST['users'];
       
   176 			/** This action is documented in wp-admin/network/site-themes.php */
       
   177 			$referer = apply_filters( 'handle_network_bulk_actions-' . get_current_screen()->id, $referer, $action, $userids, $id );
       
   178 			$update = $action;
   144 			break;
   179 			break;
   145 	}
   180 	}
   146 
   181 
   147 	wp_safe_redirect( add_query_arg( 'update', $update, $referer ) );
   182 	wp_safe_redirect( add_query_arg( 'update', $update, $referer ) );
   148 	exit();
   183 	exit();
   155 	exit();
   190 	exit();
   156 }
   191 }
   157 
   192 
   158 add_screen_option( 'per_page' );
   193 add_screen_option( 'per_page' );
   159 
   194 
   160 $site_url_no_http = preg_replace( '#^http(s)?://#', '', get_blogaddress_by_id( $id ) );
   195 /* translators: %s: site name */
   161 $title_site_url_linked = sprintf( __( 'Edit Site: %s' ), '<a href="' . get_blogaddress_by_id( $id ) . '">' . $site_url_no_http . '</a>' );
   196 $title = sprintf( __( 'Edit Site: %s' ), esc_html( $details->blogname ) );
   162 $title = sprintf( __( 'Edit Site: %s' ), $site_url_no_http );
       
   163 
   197 
   164 $parent_file = 'sites.php';
   198 $parent_file = 'sites.php';
   165 $submenu_file = 'sites.php';
   199 $submenu_file = 'sites.php';
   166 
   200 
   167 /**
   201 /**
   168  * Filter whether to show the Add Existing User form on the Multisite Users screen.
   202  * Filters whether to show the Add Existing User form on the Multisite Users screen.
   169  *
   203  *
   170  * @since 3.1.0
   204  * @since 3.1.0
   171  *
   205  *
   172  * @param bool $bool Whether to show the Add Existing User form. Default true.
   206  * @param bool $bool Whether to show the Add Existing User form. Default true.
   173  */
   207  */
   180 var current_site_id = <?php echo $id; ?>;
   214 var current_site_id = <?php echo $id; ?>;
   181 </script>
   215 </script>
   182 
   216 
   183 
   217 
   184 <div class="wrap">
   218 <div class="wrap">
   185 <h2 id="edit-site"><?php echo $title_site_url_linked ?></h2>
   219 <h1 id="edit-site"><?php echo $title; ?></h1>
   186 <h3 class="nav-tab-wrapper">
   220 <p class="edit-site-actions"><a href="<?php echo esc_url( get_home_url( $id, '/' ) ); ?>"><?php _e( 'Visit' ); ?></a> | <a href="<?php echo esc_url( get_admin_url( $id ) ); ?>"><?php _e( 'Dashboard' ); ?></a></p>
   187 <?php
   221 <?php
   188 $tabs = array(
   222 
   189 	'site-info'     => array( 'label' => __( 'Info' ),     'url' => 'site-info.php'     ),
   223 network_edit_site_nav( array(
   190 	'site-users'    => array( 'label' => __( 'Users' ),    'url' => 'site-users.php'    ),
   224 	'blog_id'  => $id,
   191 	'site-themes'   => array( 'label' => __( 'Themes' ),   'url' => 'site-themes.php'   ),
   225 	'selected' => 'site-users'
   192 	'site-settings' => array( 'label' => __( 'Settings' ), 'url' => 'site-settings.php' ),
   226 ) );
   193 );
       
   194 foreach ( $tabs as $tab_id => $tab ) {
       
   195 	$class = ( $tab['url'] == $pagenow ) ? ' nav-tab-active' : '';
       
   196 	echo '<a href="' . $tab['url'] . '?id=' . $id .'" class="nav-tab' . $class . '">' . esc_html( $tab['label'] ) . '</a>';
       
   197 }
       
   198 ?>
       
   199 </h3><?php
       
   200 
   227 
   201 if ( isset($_GET['update']) ) :
   228 if ( isset($_GET['update']) ) :
   202 	switch($_GET['update']) {
   229 	switch($_GET['update']) {
   203 	case 'adduser':
   230 	case 'adduser':
   204 		echo '<div id="message" class="updated notice is-dismissible"><p>' . __( 'User added.' ) . '</p></div>';
   231 		echo '<div id="message" class="updated notice is-dismissible"><p>' . __( 'User added.' ) . '</p></div>';
   205 		break;
   232 		break;
   206 	case 'err_add_member':
   233 	case 'err_add_member':
   207 		echo '<div id="message" class="error notice is-dismissible"><p>' . __( 'User is already a member of this site.' ) . '</p></div>';
   234 		echo '<div id="message" class="error notice is-dismissible"><p>' . __( 'User is already a member of this site.' ) . '</p></div>';
   208 		break;
   235 		break;
       
   236 	case 'err_add_fail':
       
   237 		echo '<div id="message" class="error notice is-dismissible"><p>' . __( 'User could not be added to this site.' ) . '</p></div>';
       
   238 		break;
   209 	case 'err_add_notfound':
   239 	case 'err_add_notfound':
   210 		echo '<div id="message" class="error notice is-dismissible"><p>' . __( 'Enter the username of an existing user.' ) . '</p></div>';
   240 		echo '<div id="message" class="error notice is-dismissible"><p>' . __( 'Enter the username of an existing user.' ) . '</p></div>';
   211 		break;
   241 		break;
   212 	case 'promote':
   242 	case 'promote':
   213 		echo '<div id="message" class="updated notice is-dismissible"><p>' . __( 'Changed roles.' ) . '</p></div>';
   243 		echo '<div id="message" class="updated notice is-dismissible"><p>' . __( 'Changed roles.' ) . '</p></div>';
   255  */
   285  */
   256 do_action( 'network_site_users_after_list_table' );
   286 do_action( 'network_site_users_after_list_table' );
   257 
   287 
   258 /** This filter is documented in wp-admin/network/site-users.php */
   288 /** This filter is documented in wp-admin/network/site-users.php */
   259 if ( current_user_can( 'promote_users' ) && apply_filters( 'show_network_site_users_add_existing_form', true ) ) : ?>
   289 if ( current_user_can( 'promote_users' ) && apply_filters( 'show_network_site_users_add_existing_form', true ) ) : ?>
   260 <h3 id="add-existing-user"><?php _e( 'Add Existing User' ); ?></h3>
   290 <h2 id="add-existing-user"><?php _e( 'Add Existing User' ); ?></h2>
   261 <form action="site-users.php?action=adduser" id="adduser" method="post">
   291 <form action="site-users.php?action=adduser" id="adduser" method="post">
   262 	<input type="hidden" name="id" value="<?php echo esc_attr( $id ) ?>" />
   292 	<input type="hidden" name="id" value="<?php echo esc_attr( $id ) ?>" />
   263 	<table class="form-table">
   293 	<table class="form-table">
   264 		<tr>
   294 		<tr>
   265 			<th scope="row"><label for="newuser"><?php _e( 'Username' ); ?></label></th>
   295 			<th scope="row"><label for="newuser"><?php _e( 'Username' ); ?></label></th>
   266 			<td><input type="text" class="regular-text wp-suggest-user" name="newuser" id="newuser" /></td>
   296 			<td><input type="text" class="regular-text wp-suggest-user" name="newuser" id="newuser" /></td>
   267 		</tr>
   297 		</tr>
   268 		<tr>
   298 		<tr>
   269 			<th scope="row"><label for="new_role_adduser"><?php _e( 'Role' ); ?></label></th>
   299 			<th scope="row"><label for="new_role_adduser"><?php _e( 'Role' ); ?></label></th>
   270 			<td><select name="new_role" id="new_role_adduser">
   300 			<td><select name="new_role" id="new_role_adduser">
   271 			<?php wp_dropdown_roles( get_option( 'default_role' ) ); ?>
   301 			<?php
       
   302 			switch_to_blog( $id );
       
   303 			wp_dropdown_roles( get_option( 'default_role' ) );
       
   304 			restore_current_blog();
       
   305 			?>
   272 			</select></td>
   306 			</select></td>
   273 		</tr>
   307 		</tr>
   274 	</table>
   308 	</table>
   275 	<?php wp_nonce_field( 'add-user', '_wpnonce_add-user' ) ?>
   309 	<?php wp_nonce_field( 'add-user', '_wpnonce_add-user' ) ?>
   276 	<?php submit_button( __( 'Add User' ), 'primary', 'add-user', true, array( 'id' => 'submit-add-existing-user' ) ); ?>
   310 	<?php submit_button( __( 'Add User' ), 'primary', 'add-user', true, array( 'id' => 'submit-add-existing-user' ) ); ?>
   277 </form>
   311 </form>
   278 <?php endif; ?>
   312 <?php endif; ?>
   279 
   313 
   280 <?php
   314 <?php
   281 /**
   315 /**
   282  * Filter whether to show the Add New User form on the Multisite Users screen.
   316  * Filters whether to show the Add New User form on the Multisite Users screen.
   283  *
   317  *
   284  * @since 3.1.0
   318  * @since 3.1.0
   285  *
   319  *
   286  * @param bool $bool Whether to show the Add New User form. Default true.
   320  * @param bool $bool Whether to show the Add New User form. Default true.
   287  */
   321  */
   288 if ( current_user_can( 'create_users' ) && apply_filters( 'show_network_site_users_add_new_form', true ) ) : ?>
   322 if ( current_user_can( 'create_users' ) && apply_filters( 'show_network_site_users_add_new_form', true ) ) : ?>
   289 <h3 id="add-new-user"><?php _e( 'Add New User' ); ?></h3>
   323 <h2 id="add-new-user"><?php _e( 'Add New User' ); ?></h2>
   290 <form action="<?php echo network_admin_url('site-users.php?action=newuser'); ?>" id="newuser" method="post">
   324 <form action="<?php echo network_admin_url('site-users.php?action=newuser'); ?>" id="newuser" method="post">
   291 	<input type="hidden" name="id" value="<?php echo esc_attr( $id ) ?>" />
   325 	<input type="hidden" name="id" value="<?php echo esc_attr( $id ) ?>" />
   292 	<table class="form-table">
   326 	<table class="form-table">
   293 		<tr>
   327 		<tr>
   294 			<th scope="row"><label for="user_username"><?php _e( 'Username' ) ?></label></th>
   328 			<th scope="row"><label for="user_username"><?php _e( 'Username' ) ?></label></th>
   299 			<td><input type="text" class="regular-text" name="user[email]" id="user_email" /></td>
   333 			<td><input type="text" class="regular-text" name="user[email]" id="user_email" /></td>
   300 		</tr>
   334 		</tr>
   301 		<tr>
   335 		<tr>
   302 			<th scope="row"><label for="new_role_newuser"><?php _e( 'Role' ); ?></label></th>
   336 			<th scope="row"><label for="new_role_newuser"><?php _e( 'Role' ); ?></label></th>
   303 			<td><select name="new_role" id="new_role_newuser">
   337 			<td><select name="new_role" id="new_role_newuser">
   304 			<?php wp_dropdown_roles( get_option( 'default_role' ) ); ?>
   338 			<?php
       
   339 			switch_to_blog( $id );
       
   340 			wp_dropdown_roles( get_option( 'default_role' ) );
       
   341 			restore_current_blog();
       
   342 			?>
   305 			</select></td>
   343 			</select></td>
   306 		</tr>
   344 		</tr>
   307 		<tr class="form-field">
   345 		<tr class="form-field">
   308 			<td colspan="2"><?php _e( 'Username and password will be mailed to the above email address.' ) ?></td>
   346 			<td colspan="2"><?php _e( 'A password reset link will be sent to the user via email.' ) ?></td>
   309 		</tr>
   347 		</tr>
   310 	</table>
   348 	</table>
   311 	<?php wp_nonce_field( 'add-user', '_wpnonce_add-new-user' ) ?>
   349 	<?php wp_nonce_field( 'add-user', '_wpnonce_add-new-user' ) ?>
   312 	<?php submit_button( __( 'Add New User' ), 'primary', 'add-user', true, array( 'id' => 'submit-add-user' ) ); ?>
   350 	<?php submit_button( __( 'Add New User' ), 'primary', 'add-user', true, array( 'id' => 'submit-add-user' ) ); ?>
   313 </form>
   351 </form>