CI / Tests (PHP 8.2) (pull_request) Successful in 58s
CI / Tests (PHP 8.1) (pull_request) Successful in 58s
CI / No Debug Code (pull_request) Successful in 3s
CI / Coding Standards (pull_request) Successful in 2m53s
CI / PHPStan (pull_request) Successful in 3m0s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m42s
CI / Build Plugin Zip (pull_request) Skipped
Every account-signup question was asked of everybody who registered, on the same terms: "school and grade" had to be put to an adult signing themselves up, and a question a studio needed answered for each student could only be made required by demanding it of everyone. A question now carries an audience — everyone, or only the students someone registers on behalf of — and its own required flag for each side, so optional for you and required for every student you enrol is expressible. Both settings are account-scope only: an offering asks its questions once, about the student being booked, so there is no second audience to differ from, and an offering question mirrors its single "required" into both columns. Every caller reads askedOfSelf()/isRequiredForSelf()/isRequiredForChild() rather than the raw flags, so a students-only question can neither block the account holder nor have an answer filed against them by a crafted post. The family screen, which only ever adds a student, is held to the students' rule. is_required_child arrives from dbDelta defaulting to 0, which would quietly stop every existing required question being required of the students a guardian registers — the case it most likely existed for. A one-time backfill copies is_required across, guarded by its own option so a question later made optional for students stays that way. Closes #163 Co-Authored-By: Claude Opus 5 <[email protected]>
203 lines
13 KiB
PHP
203 lines
13 KiB
PHP
<?php
|
|
declare(strict_types=1);
|
|
|
|
use Unsupervised\Schedular\Auth\PasswordPolicy;
|
|
use Unsupervised\Schedular\Auth\RegistrationPage;
|
|
use Unsupervised\Schedular\Registration\Question;
|
|
use Unsupervised\Schedular\Registration\QuestionField;
|
|
|
|
if (! defined('ABSPATH')) {
|
|
exit;
|
|
}
|
|
|
|
/**
|
|
* @var \Unsupervised\Schedular\Auth\Invite|null $invite
|
|
* @var bool $inviteValid Whether $invite can still be redeemed — only then is the email fixed.
|
|
* @var string $token Raw invite token from the request (only its hash is stored).
|
|
* @var bool $canRegister
|
|
* @var string $inviteOnlyMessage Text shown when registration is closed and no valid invite is present.
|
|
* @var bool $open Whether open (self-approval) registration is enabled.
|
|
* @var string $successType '' | 'confirm' (check email) | 'confirm_group' (check email; auto-approved on confirm). The invited-student success is rendered by RegistrationPage::render() itself, which returns before this template for logged-in visitors.
|
|
* @var string $confirmResult '' | '1' (email confirmed, awaiting approval) | 'ready' (confirmed + auto-approved) | 'expired'.
|
|
* @var string $loginUrl Where the post-confirmation sign-in link points.
|
|
* @var string $error
|
|
* @var list<array{policy: \Unsupervised\Schedular\Policy\Policy, version: \Unsupervised\Schedular\Policy\PolicyVersion}> $policyForms
|
|
* @var list<Question> $accountQuestions Studio-wide questions, asked of every student being registered — the account holder included when they are one, unless the question is for students only.
|
|
*/
|
|
|
|
?>
|
|
<div class="us-register-form">
|
|
<?php if ($successType === 'confirm') : ?>
|
|
<p class="us-success"><?php esc_html_e('Your account has been created. Check your email for a link to confirm your address — once you do, a studio admin will review and approve your account.', 'unsupervised-schedular'); ?></p>
|
|
<?php elseif ($successType === 'confirm_group') : ?>
|
|
<p class="us-success"><?php esc_html_e('Your account has been created. Check your email for a link to confirm your address — once you do, your account is ready to use.', 'unsupervised-schedular'); ?></p>
|
|
<?php elseif ($confirmResult === 'ready') : ?>
|
|
<p class="us-success"><?php esc_html_e('Thanks — your email is confirmed and your account is ready to use.', 'unsupervised-schedular'); ?></p>
|
|
<p><a href="<?php echo esc_url($loginUrl); ?>"><?php esc_html_e('Sign in to your account', 'unsupervised-schedular'); ?></a></p>
|
|
<?php elseif ($confirmResult === '1') : ?>
|
|
<p class="us-success"><?php esc_html_e('Thanks — your email is confirmed. Your account is now awaiting studio approval; we will email you when it is ready.', 'unsupervised-schedular'); ?></p>
|
|
<p><a href="<?php echo esc_url($loginUrl); ?>"><?php esc_html_e('Sign in to your account', 'unsupervised-schedular'); ?></a></p>
|
|
<?php else : ?>
|
|
<?php if ($confirmResult === 'expired') : ?>
|
|
<p class="us-error" role="alert"><?php esc_html_e('That confirmation link is invalid or has expired. Please contact the studio.', 'unsupervised-schedular'); ?></p>
|
|
<?php endif; ?>
|
|
|
|
<?php if (! $canRegister) : ?>
|
|
<p><?php echo esc_html($inviteOnlyMessage); ?></p>
|
|
<?php else : ?>
|
|
<?php if ($error !== '') : ?>
|
|
<p class="us-error" role="alert"><?php echo esc_html($error); ?></p>
|
|
<?php endif; ?>
|
|
|
|
<form method="post" action="">
|
|
<?php wp_nonce_field('us_student_register'); ?>
|
|
<input type="hidden" name="us_invite" value="<?php echo esc_attr($token); ?>">
|
|
|
|
<p>
|
|
<label for="us-reg-email"><?php esc_html_e('Email', 'unsupervised-schedular'); ?></label>
|
|
<?php if ($inviteValid && $invite !== null && ! $invite->isGroup()) : ?>
|
|
<input type="email" id="us-reg-email" value="<?php echo esc_attr($invite->email); ?>" readonly>
|
|
<?php else : ?>
|
|
<input type="email" name="email" id="us-reg-email" autocomplete="email" required>
|
|
<?php endif; ?>
|
|
</p>
|
|
<p>
|
|
<label for="us-reg-name"><?php esc_html_e('Your name', 'unsupervised-schedular'); ?></label>
|
|
<input type="text" name="display_name" id="us-reg-name" autocomplete="name" required>
|
|
</p>
|
|
<p>
|
|
<label for="us-reg-pass"><?php esc_html_e('Password', 'unsupervised-schedular'); ?></label>
|
|
<input type="password" name="password" id="us-reg-pass" autocomplete="new-password" minlength="<?php echo esc_attr((string) PasswordPolicy::MIN_LENGTH); ?>" required aria-describedby="us-reg-pass-strength">
|
|
<?php
|
|
/*
|
|
* Filled in by register.js. `aria-live` announces the verdict as
|
|
* it changes, and it starts empty so nothing is announced — or
|
|
* takes up space — before anything has been typed.
|
|
*/
|
|
?>
|
|
<span class="us-password-strength" id="us-reg-pass-strength" role="status" aria-live="polite"></span>
|
|
</p>
|
|
|
|
<fieldset class="us-reg-group">
|
|
<legend><?php esc_html_e('Who are you registering?', 'unsupervised-schedular'); ?></legend>
|
|
<?php
|
|
/*
|
|
* Radios, not checkboxes: the three answers are mutually
|
|
* exclusive, and "both" only means anything as a third
|
|
* choice alongside the other two. "Just myself" is
|
|
* pre-selected because it is the commonest signup and the
|
|
* one that collects the least.
|
|
*/
|
|
$registeringForChoices = [
|
|
RegistrationPage::FOR_SELF => __('Just myself', 'unsupervised-schedular'),
|
|
RegistrationPage::FOR_STUDENTS => __('On behalf of one or more students', 'unsupervised-schedular'),
|
|
RegistrationPage::FOR_BOTH => __('Both — myself and one or more students', 'unsupervised-schedular'),
|
|
];
|
|
?>
|
|
<?php foreach ($registeringForChoices as $value => $label) : ?>
|
|
<p>
|
|
<label>
|
|
<input type="radio" name="us_registering_for" value="<?php echo esc_attr($value); ?>" class="us-registering-for"<?php checked($value, RegistrationPage::FOR_SELF); ?>>
|
|
<?php echo esc_html($label); ?>
|
|
</label>
|
|
</p>
|
|
<?php endforeach; ?>
|
|
</fieldset>
|
|
|
|
<?php
|
|
/*
|
|
* The account holder's own student details, asked on the same page
|
|
* as everything else rather than behind a "Next": what the studio
|
|
* needs to know about them is part of registering, not a sequel to
|
|
* it. Taken out of play by register.js when they say they are
|
|
* registering *only* on behalf of other people — the questions
|
|
* describe a student, and in that case they are not one.
|
|
*/
|
|
?>
|
|
<fieldset class="us-reg-group us-reg-self" id="us-reg-self">
|
|
<legend><?php esc_html_e('About you', 'unsupervised-schedular'); ?></legend>
|
|
<p>
|
|
<label for="us-reg-birth-year"><?php esc_html_e('Birth year', 'unsupervised-schedular'); ?> <span class="us-required" aria-hidden="true">*</span></label>
|
|
<input type="number" name="birth_year" id="us-reg-birth-year" aria-required="true" required min="1900" max="<?php echo esc_attr(current_time('Y')); ?>" step="1" inputmode="numeric" autocomplete="bday-year" placeholder="<?php esc_attr_e('YYYY', 'unsupervised-schedular'); ?>">
|
|
</p>
|
|
<?php foreach ($accountQuestions as $question) : ?>
|
|
<?php
|
|
// A "students only" question describes a child being registered,
|
|
// so it is never put to the account holder about themselves.
|
|
if (! $question->askedOfSelf()) {
|
|
continue;
|
|
}
|
|
?>
|
|
<?php
|
|
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- QuestionField::render() escapes every interpolated value.
|
|
echo QuestionField::render(
|
|
$question,
|
|
'us_answers[' . (int) $question->id . ']',
|
|
'us-reg-q-' . (int) $question->id,
|
|
isRequired: $question->isRequiredForSelf()
|
|
);
|
|
?>
|
|
<?php endforeach; ?>
|
|
</fieldset>
|
|
|
|
<?php /* Revealed by the two student-bearing choices; without JS it is simply always visible. */ ?>
|
|
<fieldset class="us-reg-group us-children" id="us-children">
|
|
<legend><?php esc_html_e('Students', 'unsupervised-schedular'); ?></legend>
|
|
<p class="us-children-intro"><?php esc_html_e('Add each student you will be booking lessons for. They do not need their own login — you book and pay for them from this account.', 'unsupervised-schedular'); ?></p>
|
|
|
|
<?php /* The first block is the template the "Add another student" button clones. */ ?>
|
|
<div class="us-child" data-child-index="0">
|
|
<p>
|
|
<label for="us-child-0-name"><?php esc_html_e("Student's name", 'unsupervised-schedular'); ?> <span class="us-required" aria-hidden="true">*</span></label>
|
|
<input type="text" name="children[0][name]" id="us-child-0-name" aria-required="true" data-us-child-required>
|
|
</p>
|
|
<p>
|
|
<label for="us-child-0-birth-year"><?php esc_html_e('Birth year', 'unsupervised-schedular'); ?> <span class="us-required" aria-hidden="true">*</span></label>
|
|
<input type="number" name="children[0][birth_year]" id="us-child-0-birth-year" aria-required="true" data-us-child-required min="1900" max="<?php echo esc_attr(current_time('Y')); ?>" step="1" inputmode="numeric" placeholder="<?php esc_attr_e('YYYY', 'unsupervised-schedular'); ?>">
|
|
</p>
|
|
<?php foreach ($accountQuestions as $question) : ?>
|
|
<?php
|
|
// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- QuestionField::render() escapes every interpolated value.
|
|
echo QuestionField::render(
|
|
$question,
|
|
'children[0][answers][' . (int) $question->id . ']',
|
|
'us-child-0-q-' . (int) $question->id,
|
|
enforceRequired: false,
|
|
isRequired: $question->isRequiredForChild()
|
|
);
|
|
?>
|
|
<?php endforeach; ?>
|
|
</div>
|
|
|
|
<p>
|
|
<button type="button" class="us-add-child"><?php esc_html_e('Add another student', 'unsupervised-schedular'); ?></button>
|
|
</p>
|
|
</fieldset>
|
|
|
|
<?php if (! empty($policyForms)) : ?>
|
|
<fieldset class="us-policies">
|
|
<legend><?php esc_html_e('Policies', 'unsupervised-schedular'); ?></legend>
|
|
<?php foreach ($policyForms as $form) : ?>
|
|
<div class="us-policy">
|
|
<h4><?php echo esc_html($form['policy']->title); ?></h4>
|
|
<div class="us-policy-body"><?php echo wp_kses_post($form['version']->bodyHtml()); ?></div>
|
|
<label>
|
|
<input type="checkbox" name="accept[]" value="<?php echo esc_attr((string) $form['version']->id); ?>" required>
|
|
<?php
|
|
/* translators: %s: policy title */
|
|
echo esc_html(sprintf(__('I have read and agree to the %s.', 'unsupervised-schedular'), $form['policy']->title));
|
|
?>
|
|
</label>
|
|
</div>
|
|
<?php endforeach; ?>
|
|
</fieldset>
|
|
<?php endif; ?>
|
|
|
|
<p>
|
|
<input type="submit" name="us_register" value="<?php esc_attr_e('Create Account', 'unsupervised-schedular'); ?>">
|
|
</p>
|
|
</form>
|
|
<?php endif; ?>
|
|
<?php endif; ?>
|
|
</div>
|