xref: /webtrees/app/User.php (revision 76692c8b291f16d9251d67f27078779f6737fe7e)
1a25f0a04SGreg Roach<?php
2a25f0a04SGreg Roach/**
3a25f0a04SGreg Roach * webtrees: online genealogy
4a25f0a04SGreg Roach * Copyright (C) 2015 webtrees development team
5a25f0a04SGreg Roach * This program is free software: you can redistribute it and/or modify
6a25f0a04SGreg Roach * it under the terms of the GNU General Public License as published by
7a25f0a04SGreg Roach * the Free Software Foundation, either version 3 of the License, or
8a25f0a04SGreg Roach * (at your option) any later version.
9a25f0a04SGreg Roach * This program is distributed in the hope that it will be useful,
10a25f0a04SGreg Roach * but WITHOUT ANY WARRANTY; without even the implied warranty of
11a25f0a04SGreg Roach * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12a25f0a04SGreg Roach * GNU General Public License for more details.
13a25f0a04SGreg Roach * You should have received a copy of the GNU General Public License
14a25f0a04SGreg Roach * along with this program. If not, see <http://www.gnu.org/licenses/>.
15a25f0a04SGreg Roach */
16*76692c8bSGreg Roachnamespace Fisharebest\Webtrees;
17a25f0a04SGreg Roach
18a25f0a04SGreg Roach/**
19*76692c8bSGreg Roach * Provide an interface to the wt_user table.
20a25f0a04SGreg Roach */
21a25f0a04SGreg Roachclass User {
22a25f0a04SGreg Roach	/** @var  string The primary key of this user. */
23a25f0a04SGreg Roach	private $user_id;
24a25f0a04SGreg Roach
25a25f0a04SGreg Roach	/** @var  string The login name of this user. */
26a25f0a04SGreg Roach	private $user_name;
27a25f0a04SGreg Roach
28a25f0a04SGreg Roach	/** @var  string The real (display) name of this user. */
29a25f0a04SGreg Roach	private $real_name;
30a25f0a04SGreg Roach
31a25f0a04SGreg Roach	/** @var  string The email address of this user. */
32a25f0a04SGreg Roach	private $email;
33a25f0a04SGreg Roach
34a25f0a04SGreg Roach	/** @var array Cached copy of the wt_user_setting table. */
35a25f0a04SGreg Roach	private $preferences;
36a25f0a04SGreg Roach
37a25f0a04SGreg Roach	/** @var  User[] Only fetch users from the database once. */
38a25f0a04SGreg Roach	private static $cache = array();
39a25f0a04SGreg Roach
40a25f0a04SGreg Roach	/**
41a25f0a04SGreg Roach	 * Find the user with a specified user_id.
42a25f0a04SGreg Roach	 *
43cbc1590aSGreg Roach	 * @param int|null $user_id
44a25f0a04SGreg Roach	 *
45a25f0a04SGreg Roach	 * @return User|null
46a25f0a04SGreg Roach	 */
47a25f0a04SGreg Roach	public static function find($user_id) {
48a25f0a04SGreg Roach		if (!array_key_exists($user_id, self::$cache)) {
49a25f0a04SGreg Roach			$row = Database::prepare(
50a25f0a04SGreg Roach				"SELECT SQL_CACHE user_id, user_name, real_name, email FROM `##user` WHERE user_id = ?"
51a25f0a04SGreg Roach			)->execute(array($user_id))->fetchOneRow();
52a25f0a04SGreg Roach			if ($row) {
5306ef8e02SGreg Roach				self::$cache[$user_id] = new self($row);
54a25f0a04SGreg Roach			} else {
55a25f0a04SGreg Roach				self::$cache[$user_id] = null;
56a25f0a04SGreg Roach			}
57a25f0a04SGreg Roach		}
58a25f0a04SGreg Roach
59a25f0a04SGreg Roach		return self::$cache[$user_id];
60a25f0a04SGreg Roach	}
61a25f0a04SGreg Roach
62a25f0a04SGreg Roach	/**
63a25f0a04SGreg Roach	 * Find the user with a specified user_id.
64a25f0a04SGreg Roach	 *
65a25f0a04SGreg Roach	 * @param string $identifier
66a25f0a04SGreg Roach	 *
67a25f0a04SGreg Roach	 * @return User|null
68a25f0a04SGreg Roach	 */
69a25f0a04SGreg Roach	public static function findByIdentifier($identifier) {
70a25f0a04SGreg Roach		$user_id = Database::prepare(
71a25f0a04SGreg Roach			"SELECT SQL_CACHE user_id FROM `##user` WHERE ? IN (user_name, email)"
72a25f0a04SGreg Roach		)->execute(array($identifier))->fetchOne();
73a25f0a04SGreg Roach
74a25f0a04SGreg Roach		return self::find($user_id);
75a25f0a04SGreg Roach	}
76a25f0a04SGreg Roach
77a25f0a04SGreg Roach	/**
78a25f0a04SGreg Roach	 * Find the user with a specified genealogy record.
79a25f0a04SGreg Roach	 *
80a25f0a04SGreg Roach	 * @param Individual $individual
81a25f0a04SGreg Roach	 *
82a25f0a04SGreg Roach	 * @return User|null
83a25f0a04SGreg Roach	 */
84a5adda01SGreg Roach	public static function findByGenealogyRecord(Individual $individual) {
85a25f0a04SGreg Roach		$user_id = Database::prepare(
86a25f0a04SGreg Roach			"SELECT SQL_CACHE user_id" .
87a25f0a04SGreg Roach			" FROM `##user_gedcom_setting`" .
88a5adda01SGreg Roach			" WHERE gedcom_id = :tree_id AND setting_name = 'gedcomid' AND setting_value = :xref"
89a5adda01SGreg Roach		)->execute(array(
90a5adda01SGreg Roach			'tree_id' => $individual->getTree()->getTreeId(),
91cbc1590aSGreg Roach			'xref'    => $individual->getXref(),
92a5adda01SGreg Roach		))->fetchOne();
93a25f0a04SGreg Roach
94a25f0a04SGreg Roach		return self::find($user_id);
95a25f0a04SGreg Roach	}
96a25f0a04SGreg Roach
97a25f0a04SGreg Roach	/**
98a25f0a04SGreg Roach	 * Find the latest user to register.
99a25f0a04SGreg Roach	 *
100a25f0a04SGreg Roach	 * @return User|null
101a25f0a04SGreg Roach	 */
102a25f0a04SGreg Roach	public static function findLatestToRegister() {
103a25f0a04SGreg Roach		$user_id = Database::prepare(
104a25f0a04SGreg Roach			"SELECT SQL_CACHE u.user_id" .
105a25f0a04SGreg Roach			" FROM `##user` u" .
106a25f0a04SGreg Roach			" LEFT JOIN `##user_setting` us ON (u.user_id=us.user_id AND us.setting_name='reg_timestamp') " .
107a25f0a04SGreg Roach			" ORDER BY us.setting_value DESC LIMIT 1"
108a25f0a04SGreg Roach		)->execute()->fetchOne();
109a25f0a04SGreg Roach
110a25f0a04SGreg Roach		return self::find($user_id);
111a25f0a04SGreg Roach	}
112a25f0a04SGreg Roach
113a25f0a04SGreg Roach	/**
114a25f0a04SGreg Roach	 * Create a new user.
115a25f0a04SGreg Roach	 *
116a25f0a04SGreg Roach	 * The calling code needs to check for duplicates identifiers before calling
117a25f0a04SGreg Roach	 * this function.
118a25f0a04SGreg Roach	 *
119a25f0a04SGreg Roach	 * @param string $user_name
120a25f0a04SGreg Roach	 * @param string $real_name
121a25f0a04SGreg Roach	 * @param string $email
122a25f0a04SGreg Roach	 * @param string $password
123a25f0a04SGreg Roach	 *
124a25f0a04SGreg Roach	 * @return User
125a25f0a04SGreg Roach	 */
126a25f0a04SGreg Roach	public static function create($user_name, $real_name, $email, $password) {
127a25f0a04SGreg Roach		Database::prepare(
128a25f0a04SGreg Roach			"INSERT INTO `##user` (user_name, real_name, email, password) VALUES (:user_name, :real_name, :email, :password)"
129a25f0a04SGreg Roach		)->execute(array(
130a25f0a04SGreg Roach			'user_name' => $user_name,
131a25f0a04SGreg Roach			'real_name' => $real_name,
132a25f0a04SGreg Roach			'email'     => $email,
133a25f0a04SGreg Roach			'password'  => password_hash($password, PASSWORD_DEFAULT),
134a25f0a04SGreg Roach		));
135a25f0a04SGreg Roach
136a25f0a04SGreg Roach		// Set default blocks for this user
13706ef8e02SGreg Roach		$user = self::findByIdentifier($user_name);
138a25f0a04SGreg Roach		Database::prepare(
139a25f0a04SGreg Roach			"INSERT INTO `##block` (`user_id`, `location`, `block_order`, `module_name`)" .
140a25f0a04SGreg Roach			" SELECT :user_id , `location`, `block_order`, `module_name` FROM `##block` WHERE `user_id` = -1"
141a25f0a04SGreg Roach		)->execute(array('user_id' => $user->getUserId()));
142cbc1590aSGreg Roach
143a25f0a04SGreg Roach		return $user;
144a25f0a04SGreg Roach	}
145a25f0a04SGreg Roach
146a25f0a04SGreg Roach	/**
147a25f0a04SGreg Roach	 * Get a count of all users.
148a25f0a04SGreg Roach	 *
149cbc1590aSGreg Roach	 * @return int
150a25f0a04SGreg Roach	 */
151a25f0a04SGreg Roach	public static function count() {
152a25f0a04SGreg Roach		return (int) Database::prepare(
153a25f0a04SGreg Roach			"SELECT SQL_CACHE COUNT(*)" .
154a25f0a04SGreg Roach			" FROM `##user`" .
155a25f0a04SGreg Roach			" WHERE user_id > 0"
156a25f0a04SGreg Roach		)->fetchOne();
157a25f0a04SGreg Roach	}
158a25f0a04SGreg Roach
159a25f0a04SGreg Roach	/**
160a25f0a04SGreg Roach	 * Get a list of all users.
161a25f0a04SGreg Roach	 *
162a25f0a04SGreg Roach	 * @return User[]
163a25f0a04SGreg Roach	 */
164a25f0a04SGreg Roach	public static function all() {
165a25f0a04SGreg Roach		$users = array();
166a25f0a04SGreg Roach
167a25f0a04SGreg Roach		$rows = Database::prepare(
168a25f0a04SGreg Roach			"SELECT SQL_CACHE user_id, user_name, real_name, email" .
169a25f0a04SGreg Roach			" FROM `##user`" .
170a25f0a04SGreg Roach			" WHERE user_id > 0" .
171a25f0a04SGreg Roach			" ORDER BY user_name"
172a25f0a04SGreg Roach		)->fetchAll();
173a25f0a04SGreg Roach
174a25f0a04SGreg Roach		foreach ($rows as $row) {
17506ef8e02SGreg Roach			$users[] = new self($row);
176a25f0a04SGreg Roach		}
177a25f0a04SGreg Roach
178a25f0a04SGreg Roach		return $users;
179a25f0a04SGreg Roach	}
180a25f0a04SGreg Roach
181a25f0a04SGreg Roach	/**
182a25f0a04SGreg Roach	 * Get a list of all administrators.
183a25f0a04SGreg Roach	 *
184a25f0a04SGreg Roach	 * @return User[]
185a25f0a04SGreg Roach	 */
186a25f0a04SGreg Roach	public static function allAdmins() {
187a25f0a04SGreg Roach		$rows = Database::prepare(
188a25f0a04SGreg Roach			"SELECT SQL_CACHE user_id, user_name, real_name, email" .
189a25f0a04SGreg Roach			" FROM `##user`" .
190a25f0a04SGreg Roach			" JOIN `##user_setting` USING (user_id)" .
191a25f0a04SGreg Roach			" WHERE user_id > 0" .
192a25f0a04SGreg Roach			"   AND setting_name = 'canadmin'" .
193a25f0a04SGreg Roach			"   AND setting_value = '1'"
194a25f0a04SGreg Roach		)->fetchAll();
195a25f0a04SGreg Roach
196a25f0a04SGreg Roach		$users = array();
197a25f0a04SGreg Roach		foreach ($rows as $row) {
19806ef8e02SGreg Roach			$users[] = new self($row);
199a25f0a04SGreg Roach		}
200a25f0a04SGreg Roach
201a25f0a04SGreg Roach		return $users;
202a25f0a04SGreg Roach	}
203a25f0a04SGreg Roach
204a25f0a04SGreg Roach	/**
205a25f0a04SGreg Roach	 * Get a list of all verified uses.
206a25f0a04SGreg Roach	 *
207a25f0a04SGreg Roach	 * @return User[]
208a25f0a04SGreg Roach	 */
209a25f0a04SGreg Roach	public static function allVerified() {
210a25f0a04SGreg Roach		$rows = Database::prepare(
211a25f0a04SGreg Roach			"SELECT SQL_CACHE user_id, user_name, real_name, email" .
212a25f0a04SGreg Roach			" FROM `##user`" .
213a25f0a04SGreg Roach			" JOIN `##user_setting` USING (user_id)" .
214a25f0a04SGreg Roach			" WHERE user_id > 0" .
215a25f0a04SGreg Roach			"   AND setting_name = 'verified'" .
216a25f0a04SGreg Roach			"   AND setting_value = '1'"
217a25f0a04SGreg Roach		)->fetchAll();
218a25f0a04SGreg Roach
219a25f0a04SGreg Roach		$users = array();
220a25f0a04SGreg Roach		foreach ($rows as $row) {
22106ef8e02SGreg Roach			$users[] = new self($row);
222a25f0a04SGreg Roach		}
223a25f0a04SGreg Roach
224a25f0a04SGreg Roach		return $users;
225a25f0a04SGreg Roach	}
226a25f0a04SGreg Roach
227a25f0a04SGreg Roach	/**
228a25f0a04SGreg Roach	 * Get a list of all users who are currently logged in.
229a25f0a04SGreg Roach	 *
230a25f0a04SGreg Roach	 * @return User[]
231a25f0a04SGreg Roach	 */
232a25f0a04SGreg Roach	public static function allLoggedIn() {
233a25f0a04SGreg Roach		$rows = Database::prepare(
234a25f0a04SGreg Roach			"SELECT SQL_NO_CACHE DISTINCT user_id, user_name, real_name, email" .
235a25f0a04SGreg Roach			" FROM `##user`" .
236a25f0a04SGreg Roach			" JOIN `##session` USING (user_id)"
237a25f0a04SGreg Roach		)->fetchAll();
238a25f0a04SGreg Roach
239a25f0a04SGreg Roach		$users = array();
240a25f0a04SGreg Roach		foreach ($rows as $row) {
24106ef8e02SGreg Roach			$users[] = new self($row);
242a25f0a04SGreg Roach		}
243a25f0a04SGreg Roach
244a25f0a04SGreg Roach		return $users;
245a25f0a04SGreg Roach	}
246a25f0a04SGreg Roach
247a25f0a04SGreg Roach	/**
248a25f0a04SGreg Roach	 * Create a new user object from a row in the database.
249a25f0a04SGreg Roach	 *
250a25f0a04SGreg Roach	 * @param \stdclass $user A row from the wt_user table
251a25f0a04SGreg Roach	 */
252a25f0a04SGreg Roach	public function __construct(\stdClass $user) {
253a25f0a04SGreg Roach		$this->user_id   = $user->user_id;
254a25f0a04SGreg Roach		$this->user_name = $user->user_name;
255a25f0a04SGreg Roach		$this->real_name = $user->real_name;
256a25f0a04SGreg Roach		$this->email     = $user->email;
257a25f0a04SGreg Roach	}
258a25f0a04SGreg Roach
259a25f0a04SGreg Roach	/**
260a25f0a04SGreg Roach	 * Delete a user
261a25f0a04SGreg Roach	 */
262ffd703eaSGreg Roach	public function delete() {
263a25f0a04SGreg Roach		// Don't delete the logs.
264a25f0a04SGreg Roach		Database::prepare("UPDATE `##log` SET user_id=NULL WHERE user_id =?")->execute(array($this->user_id));
265a25f0a04SGreg Roach		// Take over the user’s pending changes. (What else could we do with them?)
266a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##change` WHERE user_id=? AND status='accepted'")->execute(array($this->user_id));
267a25f0a04SGreg Roach		Database::prepare("UPDATE `##change` SET user_id=? WHERE user_id=?")->execute(array($this->user_id, $this->user_id));
268a25f0a04SGreg Roach		Database::prepare("DELETE `##block_setting` FROM `##block_setting` JOIN `##block` USING (block_id) WHERE user_id=?")->execute(array($this->user_id));
269a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##block` WHERE user_id=?")->execute(array($this->user_id));
270a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##user_gedcom_setting` WHERE user_id=?")->execute(array($this->user_id));
271a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##gedcom_setting` WHERE setting_value=? AND setting_name in ('CONTACT_USER_ID', 'WEBMASTER_USER_ID')")->execute(array($this->user_id));
272a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##user_setting` WHERE user_id=?")->execute(array($this->user_id));
273a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##message` WHERE user_id=?")->execute(array($this->user_id));
274a25f0a04SGreg Roach		Database::prepare("DELETE FROM `##user` WHERE user_id=?")->execute(array($this->user_id));
275a25f0a04SGreg Roach	}
276a25f0a04SGreg Roach
277a25f0a04SGreg Roach	/** Validate a supplied password
278a25f0a04SGreg Roach	 * @param string $password
279a25f0a04SGreg Roach	 *
280cbc1590aSGreg Roach	 * @return bool
281a25f0a04SGreg Roach	 */
282a25f0a04SGreg Roach	public function checkPassword($password) {
283a25f0a04SGreg Roach		$password_hash = Database::prepare(
284a25f0a04SGreg Roach			"SELECT password FROM `##user` WHERE user_id = ?"
285a25f0a04SGreg Roach		)->execute(array($this->user_id))->fetchOne();
286a25f0a04SGreg Roach
287a25f0a04SGreg Roach		if (password_verify($password, $password_hash)) {
288a25f0a04SGreg Roach			if (password_needs_rehash($password_hash, PASSWORD_DEFAULT)) {
289a25f0a04SGreg Roach				$this->setPassword($password);
290a25f0a04SGreg Roach			}
291cbc1590aSGreg Roach
292a25f0a04SGreg Roach			return true;
293a25f0a04SGreg Roach		} else {
294a25f0a04SGreg Roach			return false;
295a25f0a04SGreg Roach		}
296a25f0a04SGreg Roach	}
297a25f0a04SGreg Roach
298a25f0a04SGreg Roach	/**
299a25f0a04SGreg Roach	 * Get the numeric ID for this user.
300a25f0a04SGreg Roach	 *
301a25f0a04SGreg Roach	 * @return string
302a25f0a04SGreg Roach	 */
303a25f0a04SGreg Roach	public function getUserId() {
304a25f0a04SGreg Roach		return $this->user_id;
305a25f0a04SGreg Roach	}
306a25f0a04SGreg Roach
307a25f0a04SGreg Roach	/**
308a25f0a04SGreg Roach	 * Get the login name for this user.
309a25f0a04SGreg Roach	 *
310a25f0a04SGreg Roach	 * @return string
311a25f0a04SGreg Roach	 */
312a25f0a04SGreg Roach	public function getUserName() {
313a25f0a04SGreg Roach		return $this->user_name;
314a25f0a04SGreg Roach	}
315a25f0a04SGreg Roach
316a25f0a04SGreg Roach	/**
317a25f0a04SGreg Roach	 * Set the login name for this user.
318a25f0a04SGreg Roach	 *
319a25f0a04SGreg Roach	 * @param string $user_name
320a25f0a04SGreg Roach	 *
321a25f0a04SGreg Roach	 * @return $this
322a25f0a04SGreg Roach	 */
323a25f0a04SGreg Roach	public function setUserName($user_name) {
324a25f0a04SGreg Roach		if ($this->user_name !== $user_name) {
325a25f0a04SGreg Roach			$this->user_name = $user_name;
326a25f0a04SGreg Roach			Database::prepare(
327a25f0a04SGreg Roach				"UPDATE `##user` SET user_name = ? WHERE user_id = ?"
328a25f0a04SGreg Roach			)->execute(array($user_name, $this->user_id));
329a25f0a04SGreg Roach		}
330a25f0a04SGreg Roach
331a25f0a04SGreg Roach		return $this;
332a25f0a04SGreg Roach	}
333a25f0a04SGreg Roach
334a25f0a04SGreg Roach	/**
335a25f0a04SGreg Roach	 * Get the real name of this user.
336a25f0a04SGreg Roach	 *
337a25f0a04SGreg Roach	 * @return string
338a25f0a04SGreg Roach	 */
339a25f0a04SGreg Roach	public function getRealName() {
340a25f0a04SGreg Roach		return $this->real_name;
341a25f0a04SGreg Roach	}
342a25f0a04SGreg Roach
343a25f0a04SGreg Roach	/**
344524c0fabSGreg Roach	 * Get the real name of this user, for display on screen.
345524c0fabSGreg Roach	 *
346524c0fabSGreg Roach	 * @return string
347524c0fabSGreg Roach	 */
348524c0fabSGreg Roach	public function getRealNameHtml() {
349524c0fabSGreg Roach		return '<span dir="auto">' . Filter::escapeHtml($this->real_name) . '</span>';
350524c0fabSGreg Roach	}
351524c0fabSGreg Roach
352524c0fabSGreg Roach	/**
353a25f0a04SGreg Roach	 * Set the real name of this user.
354a25f0a04SGreg Roach	 *
355a25f0a04SGreg Roach	 * @param string $real_name
356a25f0a04SGreg Roach	 *
357a25f0a04SGreg Roach	 * @return User
358a25f0a04SGreg Roach	 */
359a25f0a04SGreg Roach	public function setRealName($real_name) {
360a25f0a04SGreg Roach		if ($this->real_name !== $real_name) {
361a25f0a04SGreg Roach			$this->real_name = $real_name;
362a25f0a04SGreg Roach			Database::prepare(
363a25f0a04SGreg Roach				"UPDATE `##user` SET real_name = ? WHERE user_id = ?"
364a25f0a04SGreg Roach			)->execute(array($real_name, $this->user_id));
365a25f0a04SGreg Roach		}
366a25f0a04SGreg Roach
367a25f0a04SGreg Roach		return $this;
368a25f0a04SGreg Roach	}
369a25f0a04SGreg Roach
370a25f0a04SGreg Roach	/**
371a25f0a04SGreg Roach	 * Get the email address of this user.
372a25f0a04SGreg Roach	 *
373a25f0a04SGreg Roach	 * @return string
374a25f0a04SGreg Roach	 */
375a25f0a04SGreg Roach	public function getEmail() {
376a25f0a04SGreg Roach		return $this->email;
377a25f0a04SGreg Roach	}
378a25f0a04SGreg Roach
379a25f0a04SGreg Roach	/**
380a25f0a04SGreg Roach	 * Set the email address of this user.
381a25f0a04SGreg Roach	 *
382a25f0a04SGreg Roach	 * @param string $email
383a25f0a04SGreg Roach	 *
384a25f0a04SGreg Roach	 * @return User
385a25f0a04SGreg Roach	 */
386a25f0a04SGreg Roach	public function setEmail($email) {
387a25f0a04SGreg Roach		if ($this->email !== $email) {
388a25f0a04SGreg Roach			$this->email = $email;
389a25f0a04SGreg Roach			Database::prepare(
390a25f0a04SGreg Roach				"UPDATE `##user` SET email = ? WHERE user_id = ?"
391a25f0a04SGreg Roach			)->execute(array($email, $this->user_id));
392a25f0a04SGreg Roach		}
393a25f0a04SGreg Roach
394a25f0a04SGreg Roach		return $this;
395a25f0a04SGreg Roach	}
396a25f0a04SGreg Roach
397a25f0a04SGreg Roach	/**
398a25f0a04SGreg Roach	 * Set the password of this user.
399a25f0a04SGreg Roach	 *
400a25f0a04SGreg Roach	 * @param string $password
401a25f0a04SGreg Roach	 *
402a25f0a04SGreg Roach	 * @return User
403a25f0a04SGreg Roach	 */
404a25f0a04SGreg Roach	public function setPassword($password) {
405a25f0a04SGreg Roach		Database::prepare(
406a25f0a04SGreg Roach			"UPDATE `##user` SET password = ? WHERE user_id = ?"
407a25f0a04SGreg Roach		)->execute(array(password_hash($password, PASSWORD_DEFAULT), $this->user_id));
408a25f0a04SGreg Roach
409a25f0a04SGreg Roach		return $this;
410a25f0a04SGreg Roach	}
411a25f0a04SGreg Roach
412a25f0a04SGreg Roach	/**
413a25f0a04SGreg Roach	 * Fetch a user option/setting from the wt_user_setting table.
414a25f0a04SGreg Roach	 *
415a25f0a04SGreg Roach	 * Since we'll fetch several settings for each user, and since there aren’t
416a25f0a04SGreg Roach	 * that many of them, fetch them all in one database query
417a25f0a04SGreg Roach	 *
418a25f0a04SGreg Roach	 * @param string      $setting_name
419a25f0a04SGreg Roach	 * @param string|null $default
420a25f0a04SGreg Roach	 *
421a25f0a04SGreg Roach	 * @return string|null
422a25f0a04SGreg Roach	 */
423a25f0a04SGreg Roach	public function getPreference($setting_name, $default = null) {
424a25f0a04SGreg Roach		if ($this->preferences === null) {
425a25f0a04SGreg Roach			if ($this->user_id) {
426a25f0a04SGreg Roach				$this->preferences = Database::prepare(
427a25f0a04SGreg Roach					"SELECT SQL_CACHE setting_name, setting_value FROM `##user_setting` WHERE user_id = ?"
428a25f0a04SGreg Roach				)->execute(array($this->user_id))->fetchAssoc();
429a25f0a04SGreg Roach			} else {
430a25f0a04SGreg Roach				// Not logged in?  We have no preferences.
431a25f0a04SGreg Roach				$this->preferences = array();
432a25f0a04SGreg Roach			}
433a25f0a04SGreg Roach		}
434a25f0a04SGreg Roach
435a25f0a04SGreg Roach		if (array_key_exists($setting_name, $this->preferences)) {
436a25f0a04SGreg Roach			return $this->preferences[$setting_name];
437a25f0a04SGreg Roach		} else {
438a25f0a04SGreg Roach			return $default;
439a25f0a04SGreg Roach		}
440a25f0a04SGreg Roach	}
441a25f0a04SGreg Roach
442a25f0a04SGreg Roach	/**
443a25f0a04SGreg Roach	 * Update a setting for the user.
444a25f0a04SGreg Roach	 *
445a25f0a04SGreg Roach	 * @param string $setting_name
446a25f0a04SGreg Roach	 * @param string $setting_value
447a25f0a04SGreg Roach	 *
448a25f0a04SGreg Roach	 * @return User
449a25f0a04SGreg Roach	 */
450a25f0a04SGreg Roach	public function setPreference($setting_name, $setting_value) {
451a25f0a04SGreg Roach		if ($this->user_id && $this->getPreference($setting_name) !== $setting_value) {
452a25f0a04SGreg Roach			Database::prepare("REPLACE INTO `##user_setting` (user_id, setting_name, setting_value) VALUES (?, ?, LEFT(?, 255))")
453a25f0a04SGreg Roach				->execute(array($this->user_id, $setting_name, $setting_value));
454a25f0a04SGreg Roach			$this->preferences[$setting_name] = $setting_value;
455a25f0a04SGreg Roach		}
456a25f0a04SGreg Roach
457a25f0a04SGreg Roach		return $this;
458a25f0a04SGreg Roach	}
459a25f0a04SGreg Roach
460a25f0a04SGreg Roach	/**
461a25f0a04SGreg Roach	 * Delete a setting for the user.
462a25f0a04SGreg Roach	 *
463a25f0a04SGreg Roach	 * @param string $setting_name
464a25f0a04SGreg Roach	 *
465a25f0a04SGreg Roach	 * @return User
466a25f0a04SGreg Roach	 */
467a25f0a04SGreg Roach	public function deletePreference($setting_name) {
468a25f0a04SGreg Roach		if ($this->user_id && $this->getPreference($setting_name) !== null) {
469a25f0a04SGreg Roach			Database::prepare("DELETE FROM `##user_setting` WHERE user_id = ? AND setting_name = ?")
470a25f0a04SGreg Roach				->execute(array($this->user_id, $setting_name));
471a25f0a04SGreg Roach			unset($this->preferences[$setting_name]);
472a25f0a04SGreg Roach		}
473a25f0a04SGreg Roach
474a25f0a04SGreg Roach		return $this;
475a25f0a04SGreg Roach	}
476a25f0a04SGreg Roach}
477