register_preview_option_filter();
add_filter( 'wpbc_bfb_get_form_structure', array( $this, 'filter_form_structure_for_preview' ), 10, 2 );
add_filter( 'wpbc_bfb_get_form_advanced_form', array( $this, 'filter_form_advanced_form_for_preview' ), 10, 2 );
add_filter( 'wpbc_bfb_get_form_content_form', array( $this, 'filter_form_content_form_for_preview' ), 10, 2 );
add_filter( 'wpbc_fe_form_source_resolution', array( $this, 'filter_form_source_resolution_for_preview' ), 10, 2 );
add_filter( 'wpbc_bfb_form_loader_from_builder', array( $this, 'filter_form_pair_for_preview' ), 100, 2 );
add_filter( 'wpbc_booking_appointment_form_status', array( $this, 'filter_appointment_form_status_for_preview' ), 10, 4 );
add_filter( 'wpbc_booking_form__should_collect_inline_scripts', array( $this, 'filter_inline_script_collection_for_preview' ), 10, 4 );
}
/**
* Remove request-scoped source filters after synchronous preview rendering.
*
* @return void
*/
private function remove_preview_source_filters() {
remove_filter( 'wpbc_bfb_get_form_structure', array( $this, 'filter_form_structure_for_preview' ), 10 );
remove_filter( 'wpbc_bfb_get_form_advanced_form', array( $this, 'filter_form_advanced_form_for_preview' ), 10 );
remove_filter( 'wpbc_bfb_get_form_content_form', array( $this, 'filter_form_content_form_for_preview' ), 10 );
remove_filter( 'wpbc_fe_form_source_resolution', array( $this, 'filter_form_source_resolution_for_preview' ), 10 );
remove_filter( 'wpbc_bfb_form_loader_from_builder', array( $this, 'filter_form_pair_for_preview' ), 100 );
remove_filter( 'wpbc_booking_appointment_form_status', array( $this, 'filter_appointment_form_status_for_preview' ), 10 );
remove_filter( 'wpbc_booking_form__should_collect_inline_scripts', array( $this, 'filter_inline_script_collection_for_preview' ), 10 );
}
/**
* Prevent legacy page-level callbacks from escaping an inline preview render.
*
* Inline previews discard renderer scripts and initialize the returned form
* with a JSON-safe bootstrap contract. Queuing the logged-in-user autofill
* callback on the parent administration page can therefore target a preview
* form that has already been replaced. Full-page signed previews keep the
* normal front-end behavior.
*
* @since 11.9.0
*
* @param bool $should_collect Whether the renderer should collect legacy inline scripts.
* @param int $resource_id Booking resource ID used by the rendered form.
* @param string $custom_booking_form Booking form slug requested by the renderer.
* @param string $form_status Normalized renderer status.
*
* @return bool False for request-local inline previews; otherwise the prior decision.
*/
public function filter_inline_script_collection_for_preview( $should_collect, $resource_id, $custom_booking_form, $form_status ) { // phpcs:ignore Generic.CodeAnalysis.UnusedFunctionParameter.FoundAfterLastUsed
if ( 'inline_preview' === ( isset( $this->current_preview_data['scope'] ) ? $this->current_preview_data['scope'] : '' ) ) {
return false;
}
return (bool) $should_collect;
}
/**
* Remove the request-scoped Booking Calendar option override filter.
*
* Front-end preview requests intentionally keep this filter for the complete
* request because assets are resolved before the preview shortcode. Inline
* administration previews have a narrower lifetime and must restore canonical
* options immediately after their synchronous render completes.
*
* @return void
*/
private function remove_preview_option_filter() {
if ( ! $this->preview_option_filter_registered ) {
return;
}
remove_bk_filter( 'wpdev_bk_get_option', array( $this, 'filter_option_for_preview' ) );
$this->preview_option_filter_registered = false;
}
/**
* Get singleton instance.
*
* @return WPBC_BFB_Preview_Service
*/
public static function get_instance() {
if ( null === self::$instance ) {
self::$instance = new self();
}
return self::$instance;
}
/**
* Constructor (private, use get_instance()).
*/
private function __construct() {
// Ensure preview page exists (lazy).
add_action( 'init', array( $this, 'ensure_preview_page_exists' ), 20 );
// Re-apply template after switching theme.
add_action( 'after_switch_theme', array( $this, 'ensure_preview_page_template' ), 20 );
// Inject preview content into preview page.
add_filter( 'the_content', array( $this, 'filter_the_content_for_preview' ) );
// Optionally hide preview page from Pages list in admin.
// add_action( 'pre_get_posts', array( $this, 'hide_preview_page_in_admin_list' ) );
// Enqueue JS/CSS on Builder admin page.
add_action( 'wpbc_enqueue_js_files_on_page_done', array( $this, 'enqueue_js_files' ) );
// Hide admin bar in preview iframe only.
add_action( 'after_setup_theme', array( $this, 'maybe_hide_admin_bar_for_preview' ) );
/*
* Calendar skins and front-end JavaScript variables are resolved while
* assets are enqueued, before `the_content` renders the preview shortcode.
* Activate a validated transient override early enough for those consumers.
*/
add_action( 'wp_enqueue_scripts', array( $this, 'activate_preview_option_overrides' ), 1 );
add_filter( 'wp_robots', array( $this, 'add_noindex_to_preview_page' ), 99 );
}
/**
* Activate allow-listed preview option overrides for the current front-end request.
*
* The method is intentionally read-only. It accepts only the authenticated,
* user-bound transient loaded by `get_preview_data_from_request()` and never
* changes canonical Booking Calendar options.
*
* @return void
*/
public function activate_preview_option_overrides() {
$preview_data = $this->get_preview_data_from_request();
if ( empty( $preview_data['option_overrides'] ) ) {
return;
}
$this->register_preview_option_filter();
}
/**
* Register the internal Booking Calendar option filter once per request.
*
* @return void
*/
private function register_preview_option_filter() {
if ( $this->preview_option_filter_registered || empty( $this->current_preview_data['option_overrides'] ) ) {
return;
}
add_bk_filter( 'wpdev_bk_get_option', array( $this, 'filter_option_for_preview' ) );
$this->preview_option_filter_registered = true;
}
/**
* Return one validated transient option override during preview rendering.
*
* @param mixed $value Current option value.
* @param string $option Booking Calendar option name.
* @param mixed $default Caller-provided default value.
*
* @return mixed Preview override or the unchanged option value.
*/
public function filter_option_for_preview( $value, $option, $default = null ) { // phpcs:ignore Generic.CodeAnalysis.UnusedFunctionParameter.FoundAfterLastUsed
$option = is_scalar( $option ) ? sanitize_key( (string) $option ) : '';
if (
! empty( $this->current_preview_data['option_overrides'] )
&& array_key_exists( $option, $this->current_preview_data['option_overrides'] )
) {
return $this->current_preview_data['option_overrides'][ $option ];
}
return $value;
}
/**
* Ensure that the preview page exists and is stored in options.
*
* This runs on 'init' and can also be called manually.
*
* @return int|false Page ID on success, false on failure.
*/
public function ensure_preview_page_exists() {
$option_key = $this->get_page_option_key();
$page_id = (int) get_option( $option_key );
if ( $page_id > 0 ) {
// phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
if ( is_admin() && ( defined( 'DOING_AJAX' ) ) && ( DOING_AJAX ) && ( isset( $_POST['action'] ) ) && ( 'WPBC_AJX_BFB_SAVE_FORM_CONFIG' === $_POST['action'] ) ) {
// Probably saving preview before making this preview, so we can check about ensure preview page.
} else {
return false;
}
$page = get_post( $page_id );
if ( $page instanceof WP_Post && 'page' === $page->post_type ) {
// Ensure it uses full-width template (if available).
$this->ensure_preview_page_template();
return $page_id;
}
delete_option( $option_key );
}
$page_id = $this->create_preview_page();
if ( $page_id > 0 ) {
update_option( $option_key, $page_id );
// Set full-width template right after creation.
$this->ensure_preview_page_template();
return $page_id;
}
return false;
}
public function add_noindex_to_preview_page( $robots ) {
if ( ! $this->is_main_query_page() ) {
return $robots;
}
$page_id = (int) get_queried_object_id();
if ( $page_id !== (int) $this->get_preview_page_id() ) {
return $robots;
}
$robots['noindex'] = true;
$robots['nofollow'] = true;
$robots['noarchive'] = true;
return $robots;
}
/**
* Check the main query directly without calling a conditional query tag too early.
*
* @return bool
*/
protected function is_main_query_page() {
return isset( $GLOBALS['wp_query'] )
&& ( $GLOBALS['wp_query'] instanceof WP_Query )
&& $GLOBALS['wp_query']->is_page();
}
/**
* Resolve capability used for preview / Builder access.
*
* Uses wpbc_bfb_get_manage_cap() when available, falls back to manage_options.
*
* @return string
*/
protected function get_manage_cap() {
if ( function_exists( 'wpbc_bfb_get_manage_cap' ) ) {
return wpbc_bfb_get_manage_cap();
}
return 'manage_options';
}
/**
* Check if current request is a BFB preview request.
*
* @return bool
*/
protected function is_preview_request() {
// Quick GET check (works before main query is parsed).
if (
isset( $_GET['wpbc_bfb_preview'] )
&& is_scalar( $_GET['wpbc_bfb_preview'] )
&& '' !== (string) wp_unslash( $_GET['wpbc_bfb_preview'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
) {
return true;
}
// Fallback for places where query vars are already set.
$is_preview = get_query_var( 'wpbc_bfb_preview' );
return is_scalar( $is_preview ) && ! empty( $is_preview );
}
/**
* Hide admin toolbar on front-end preview requests.
*
* This affects ONLY the preview page loaded in the iframe.
*/
public function maybe_hide_admin_bar_for_preview() {
// Do not affect wp-admin.
if ( is_admin() ) {
return;
}
if ( ! $this->is_preview_request() ) {
return;
}
$cap = $this->get_manage_cap();
// Optionally limit to users who can see this preview anyway.
if ( ! is_user_logged_in() || ! current_user_can( $cap ) ) {
return;
}
// Disable admin bar for this request only.
show_admin_bar( false );
}
public function enqueue_js_files() {
if ( ! is_admin() ) {
return;
}
// BFB preview script on the Builder admin page.
wp_enqueue_script(
'wpbc-bfb-preview',
wpbc_plugin_url( '/includes/page-form-builder/preview/_out/bfb-preview.js' ),
array( 'wpbc-bfb_builder' ),
WP_BK_VERSION_NUM,
true
);
wp_enqueue_style(
'wpbc-bfb-preview-mode',
wpbc_plugin_url( '/includes/page-form-builder/preview/_out/bfb-preview.css' ),
array(),
WP_BK_VERSION_NUM
);
}
/**
* Return the option key where preview page ID is stored.
*
* @return string
*/
protected function get_page_option_key() {
return 'wpbc_bfb_preview_page_id';
}
/**
* Create the private "Booking Form Preview" page.
*
* @return int|false Page ID on success, false on failure.
*/
protected function create_preview_page() {
$page_id = wpbc_bfb_activation__create_preview_page_raw();
return $page_id;
}
/**
* Get the preview page ID (ensures it exists).
*
* @return int|false
*/
public function get_preview_page_id() {
$option_key = $this->get_page_option_key();
$page_id = (int) get_option( $option_key );
if ( $page_id > 0 ) {
return $page_id;
}
return $this->ensure_preview_page_exists();
}
/**
* Build transient key for storing preview snapshot.
*
* @param int $user_id Current user ID.
* @param string $token Random token.
* @param int $form_id Booking form ID.
*
* @return string
*/
protected function get_transient_key( $user_id, $token, $form_id ) {
$user_id = (int) $user_id;
$form_id = (int) $form_id;
return 'wpbc_bfb_preview_' . $user_id . '_' . $form_id . '_' . sanitize_key( $token );
}
/**
* Try to load preview data from current request (front-end).
*
* @return array|null
*/
protected function get_preview_data_from_request() {
if ( null !== $this->current_preview_data ) {
return $this->current_preview_data;
}
// Check query flag.
$is_preview = get_query_var( 'wpbc_bfb_preview' );
$is_preview = is_scalar( $is_preview ) ? (string) $is_preview : '';
$is_preview_get = isset( $_GET['wpbc_bfb_preview'] ) && is_scalar( $_GET['wpbc_bfb_preview'] )
? (string) wp_unslash( $_GET['wpbc_bfb_preview'] ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
: '';
if ( empty( $is_preview ) && empty( $is_preview_get ) ) {
return null;
}
$token_raw = get_query_var( 'wpbc_bfb_preview_token' );
$form_id_raw = get_query_var( 'wpbc_bfb_preview_form_id' );
$token = is_scalar( $token_raw ) ? sanitize_text_field( wp_unslash( (string) $token_raw ) ) : '';
$form_id = is_scalar( $form_id_raw ) ? absint( $form_id_raw ) : 0;
if ( empty( $token ) ) {
$token = isset( $_GET['wpbc_bfb_preview_token'] ) && is_scalar( $_GET['wpbc_bfb_preview_token'] )
? sanitize_text_field( wp_unslash( (string) $_GET['wpbc_bfb_preview_token'] ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
: '';
}
if ( empty( $form_id ) ) {
$form_id = isset( $_GET['wpbc_bfb_preview_form_id'] ) && is_scalar( $_GET['wpbc_bfb_preview_form_id'] )
? absint( wp_unslash( $_GET['wpbc_bfb_preview_form_id'] ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
: 0;
}
$nonce = isset( $_GET['nonce'] ) && is_scalar( $_GET['nonce'] )
? sanitize_text_field( wp_unslash( (string) $_GET['nonce'] ) ) // phpcs:ignore WordPress.Security.NonceVerification.Recommended
: '';
return $this->load_preview_data( $token, $form_id, $nonce );
}
/**
* Enqueue the reusable administration inline-preview renderer.
*
* Settings and setup pages may call this before replacing an authorized
* server-rendered booking form without duplicating Datepick cleanup or WPBC
* bootstrap ordering logic.
*
* @return void
*/
public function enqueue_inline_preview_assets() {
if ( ! is_admin() ) {
return;
}
wp_enqueue_script(
'wpbc-bfb-inline-preview',
wpbc_plugin_url( '/includes/page-form-builder/preview/_out/bfb-inline-preview.js' ),
array( 'jquery', 'wpbc-main-client' ),
WP_BK_VERSION_NUM,
true
);
}
/**
* Activate an Appointment preview from its signed configuration return URL.
*
* The Appointment AJAX endpoint receives this URL only inside its HMAC-signed
* configuration. This method additionally verifies the preview nonce, current
* user, capability, transient scope, and expiry before registering temporary
* source filters. A normal public Appointment request therefore cannot opt in
* to an administrator's unsaved preview snapshot.
*
* @param mixed $preview_url Signed Appointment configuration return URL.
*
* @return bool True when an authenticated Appointment preview was activated.
*/
public function activate_appointment_preview_from_url( $preview_url ) {
if ( ! is_scalar( $preview_url ) || '' === trim( (string) $preview_url ) ) {
return false;
}
$query_string = wp_parse_url( (string) $preview_url, PHP_URL_QUERY );
if ( ! is_string( $query_string ) || '' === $query_string ) {
return false;
}
$query_args = array();
wp_parse_str( $query_string, $query_args );
$is_preview = isset( $query_args['wpbc_bfb_preview'] ) && is_scalar( $query_args['wpbc_bfb_preview'] )
? sanitize_text_field( (string) $query_args['wpbc_bfb_preview'] )
: '';
$token = isset( $query_args['wpbc_bfb_preview_token'] ) && is_scalar( $query_args['wpbc_bfb_preview_token'] )
? sanitize_key( (string) $query_args['wpbc_bfb_preview_token'] )
: '';
$form_id = isset( $query_args['wpbc_bfb_preview_form_id'] ) && is_scalar( $query_args['wpbc_bfb_preview_form_id'] )
? absint( $query_args['wpbc_bfb_preview_form_id'] )
: 0;
$nonce = isset( $query_args['nonce'] ) && is_scalar( $query_args['nonce'] )
? sanitize_text_field( (string) $query_args['nonce'] )
: '';
if ( '1' !== $is_preview || null === $this->load_preview_data( $token, $form_id, $nonce ) ) {
return false;
}
if ( 'appointment' !== $this->get_current_preview_render_mode() ) {
$this->current_preview_data = null;
return false;
}
$this->register_preview_source_filters();
return true;
}
/**
* Load and validate one user-bound preview transient.
*
* @param string $token Random preview token.
* @param int $form_id Preview resource ID encoded into the transient key.
* @param string $nonce Nonce bound to the preview token.
*
* @return array|null Normalized preview data or null when validation fails.
*/
private function load_preview_data( $token, $form_id, $nonce ) {
$token = is_scalar( $token ) ? sanitize_key( (string) $token ) : '';
$form_id = is_scalar( $form_id ) ? absint( $form_id ) : 0;
$nonce = is_scalar( $nonce ) ? sanitize_text_field( (string) $nonce ) : '';
if (
'' === $token
|| $form_id <= 0
|| ! is_user_logged_in()
|| ! current_user_can( $this->get_manage_cap() )
|| ! wp_verify_nonce( $nonce, 'wpbc_bfb_preview_' . $token )
) {
return null;
}
$user_id = get_current_user_id();
if ( $user_id <= 0 ) {
return null;
}
$data = get_transient( $this->get_transient_key( $user_id, $token, $form_id ) );
$data = $this->normalize_preview_data( $data );
$current_time = time();
if (
null === $data
|| $user_id !== $data['user_id']
|| $form_id !== $data['form_id']
|| $form_id !== $data['resource_id']
|| 'preview' !== $data['scope']
|| $data['time'] <= 0
|| $data['time'] > ( $current_time + MINUTE_IN_SECONDS )
|| $data['time'] < ( $current_time - ( 10 * MINUTE_IN_SECONDS ) )
) {
return null;
}
$has_structure = ! empty( $data['structure'] ) && is_array( $data['structure'] );
$has_advanced = ! empty( $data['advanced_form'] ) || ! empty( $data['content_form'] );
if ( ! $has_structure && ! $has_advanced ) {
return null;
}
$this->current_preview_data = $data;
return $this->current_preview_data;
}
/**
* Normalize and validate a preview transient before any array offsets are read.
*
* Object-cache implementations and third-party code can return unexpected
* values for a transient. Keeping this normalization at the shared read
* boundary prevents malformed values from producing warnings or reaching the
* booking-form renderer.
*
* @param mixed $preview_data Raw transient value.
*
* @return array|null Normalized preview snapshot, or null for an invalid shape.
*/
private function normalize_preview_data( $preview_data ) {
if ( ! is_array( $preview_data ) ) {
return null;
}
$user_id = isset( $preview_data['user_id'] ) && is_scalar( $preview_data['user_id'] )
? absint( $preview_data['user_id'] )
: 0;
$form_id = isset( $preview_data['form_id'] ) && is_scalar( $preview_data['form_id'] )
? absint( $preview_data['form_id'] )
: 0;
$resource_id = isset( $preview_data['resource_id'] ) && is_scalar( $preview_data['resource_id'] )
? absint( $preview_data['resource_id'] )
: $form_id;
$form_name = isset( $preview_data['form_name'] ) && is_scalar( $preview_data['form_name'] )
? sanitize_text_field( (string) $preview_data['form_name'] )
: 'standard';
$scope = isset( $preview_data['scope'] ) && is_scalar( $preview_data['scope'] )
? sanitize_key( (string) $preview_data['scope'] )
: '';
$render_mode = isset( $preview_data['render_mode'] ) && is_scalar( $preview_data['render_mode'] )
? sanitize_key( (string) $preview_data['render_mode'] )
: 'booking';
$render_mode = 'appointment' === $render_mode ? 'appointment' : 'booking';
if ( $user_id <= 0 || $form_id <= 0 || $resource_id <= 0 ) {
return null;
}
return array(
'user_id' => $user_id,
'form_id' => $form_id,
'resource_id' => $resource_id,
'form_name' => '' === $form_name ? 'standard' : $form_name,
'scope' => $scope,
'render_mode' => $render_mode,
'structure' => isset( $preview_data['structure'] ) && is_array( $preview_data['structure'] )
? $preview_data['structure']
: array(),
'time' => isset( $preview_data['time'] ) && is_scalar( $preview_data['time'] )
? absint( $preview_data['time'] )
: 0,
'advanced_form' => isset( $preview_data['advanced_form'] ) && is_scalar( $preview_data['advanced_form'] )
? (string) $preview_data['advanced_form']
: '',
'content_form' => isset( $preview_data['content_form'] ) && is_scalar( $preview_data['content_form'] )
? (string) $preview_data['content_form']
: '',
'settings_json' => isset( $preview_data['settings_json'] ) && is_scalar( $preview_data['settings_json'] )
? (string) $preview_data['settings_json']
: '',
'form_style' => isset( $preview_data['form_style'] ) && is_array( $preview_data['form_style'] )
? $preview_data['form_style']
: array(),
'option_overrides' => isset( $preview_data['option_overrides'] ) && is_array( $preview_data['option_overrides'] )
? $this->sanitize_preview_option_overrides( $preview_data['option_overrides'] )
: array(),
'calendar_parameters' => isset( $preview_data['calendar_parameters'] ) && is_array( $preview_data['calendar_parameters'] )
? $this->sanitize_preview_calendar_parameters( $preview_data['calendar_parameters'] )
: array(),
'calendar_request_overrides' => isset( $preview_data['calendar_request_overrides'] ) && is_array( $preview_data['calendar_request_overrides'] )
? $this->sanitize_preview_calendar_request_overrides( $preview_data['calendar_request_overrides'] )
: array(),
);
}
// -----------------------------------------------------------------------------------------------------------------
/**
* Ensure preview page uses a "full width" template (if the current theme provides one).
*
* WordPress stores selected templates in post meta: _wp_page_template. :contentReference[oaicite:1]{index=1}
*
* Developers can hard-force a template via:
* apply_filters( 'wpbc_bfb_preview_page_template', $template, $page_id )
*
* - Classic theme template value: 'templates/full-width.php'
* - Block theme template value: 'page-no-title' (template slug)
*
* @return void
*/
public function ensure_preview_page_template() {
$page_id = (int) $this->get_preview_page_id();
if ( $page_id <= 0 ) {
return;
}
// If already set and valid, do nothing (fast path).
$current = (string) get_post_meta( $page_id, '_wp_page_template', true );
if ( $this->is_preview_template_value_valid( $current ) ) {
return;
}
$template = $this->detect_full_width_template_value();
/**
* Force/override template for preview page.
*
* Return values:
* - '' or 'default' => keep theme default
* - classic: 'templates/full-width.php'
* - block: 'page-no-title' (slug)
*/
$template = apply_filters( 'wpbc_bfb_preview_page_template', $template, $page_id );
$template = (string) $template;
$template = trim( $template );
if ( '' === $template || 'default' === $template ) {
// Use default template.
delete_post_meta( $page_id, '_wp_page_template' );
return;
}
// Store chosen template.
update_post_meta( $page_id, '_wp_page_template', $template );
}
/**
* Validate existing _wp_page_template meta value for classic themes.
* For block themes we can’t reliably "locate" the template file here, so we accept non-empty values.
*
* @param string $template_value Existing _wp_page_template meta value.
*
* @return bool
*/
protected function is_preview_template_value_valid( $template_value ) {
$template_value = (string) $template_value;
$template_value = trim( $template_value );
if ( '' === $template_value || 'default' === $template_value ) {
return false;
}
// Classic themes: validate that file exists in theme.
if ( function_exists( 'wp_is_block_theme' ) && wp_is_block_theme() ) {
return true;
}
$located = locate_template( array( $template_value ), false, false );
return ( ! empty( $located ) );
}
/**
* Detect a full-width template value for current theme.
*
* @return string Template value for _wp_page_template, or '' if none found.
*/
protected function detect_full_width_template_value() {
// Block themes: try to find a block template slug.
if ( function_exists( 'wp_is_block_theme' ) && wp_is_block_theme() && function_exists( 'get_block_templates' ) ) {
$slug = $this->detect_block_theme_full_width_slug();
if ( '' !== $slug ) {
return $slug;
}
}
// Classic themes: try registered page templates first.
$file = $this->detect_classic_theme_full_width_file();
if ( '' !== $file ) {
return $file;
}
return '';
}
/**
* Try to detect a "full width" template slug in block themes.
*
* @return string
*/
protected function detect_block_theme_full_width_slug() {
$best_slug = '';
$best_score = 0;
$templates = get_block_templates( array(
'post_type' => 'page',
), 'wp_template' );
if ( empty( $templates ) || ! is_array( $templates ) ) {
return '';
}
foreach ( $templates as $tpl ) {
$title = '';
$slug = '';
if ( is_object( $tpl ) ) {
$title = isset( $tpl->title ) ? (string) $tpl->title : '';
$slug = isset( $tpl->slug ) ? (string) $tpl->slug : '';
}
$score = $this->score_full_width_candidate( $title . ' ' . $slug );
if ( $score > $best_score && '' !== $slug ) {
$best_score = $score;
$best_slug = $slug;
}
}
return ( $best_score >= 60 ) ? $best_slug : '';
}
/**
* Try to detect a "full width" template file in classic themes.
*
* @return string
*/
protected function detect_classic_theme_full_width_file() {
$theme = wp_get_theme();
$templates = $theme->get_page_templates( null, 'page' ); // array( 'Name' => 'file.php' ).
$best_file = '';
$best_score = 0;
if ( ! empty( $templates ) && is_array( $templates ) ) {
foreach ( $templates as $name => $file ) {
$score = $this->score_full_width_candidate( $name . ' ' . $file );
if ( $score > $best_score && ! empty( $file ) ) {
$best_score = $score;
$best_file = (string) $file;
}
}
}
// Accept strong match from registered templates.
if ( $best_score >= 60 && '' !== $best_file ) {
$located = locate_template( array( $best_file ), false, false );
if ( ! empty( $located ) ) {
return $best_file;
}
}
// Fallback: common filenames (theme-dependent).
$candidates = array(
'page-templates/full-width.php',
'page-templates/fullwidth.php',
'templates/full-width.php',
'templates/fullwidth.php',
'full-width.php',
'fullwidth.php',
'page-no-sidebar.php',
'page-nosidebar.php',
);
foreach ( $candidates as $candidate ) {
$located = locate_template( array( $candidate ), false, false );
if ( ! empty( $located ) ) {
return $candidate;
}
}
return '';
}
/**
* Score a candidate (template name/slug/file) as "full width".
*
* @param string $haystack Text to score.
*
* @return int
*/
protected function score_full_width_candidate( $haystack ) {
$h = strtolower( (string) $haystack );
$s = 0;
if ( false !== strpos( $h, 'full' ) && false !== strpos( $h, 'width' ) ) {
$s += 100;
}
if ( false !== strpos( $h, 'no' ) && false !== strpos( $h, 'sidebar' ) ) {
$s += 95;
}
// My theme exception for local test server.
if ( ( isset( $_SERVER['HTTP_HOST'] ) && ( 'beta' === sanitize_key( wp_unslash( $_SERVER['HTTP_HOST'] ) ) ) ) && ( false !== strpos( $h, 'no-title' ) ) ) {
$s += 61;
}
if ( false !== strpos( $h, 'wide' ) ) {
$s += 60;
}
if ( false !== strpos( $h, 'canvas' ) || false !== strpos( $h, 'blank' ) ) {
$s += 40;
}
if ( false !== strpos( $h, 'elementor' ) && false !== strpos( $h, 'full' ) ) {
$s += 30;
}
return $s;
}
// -----------------------------------------------------------------------------------------------------------------
/**
* Filter "the_content" to inject the real booking form into the preview page.
*
* Note:
* - This is where we run the actual booking shortcode.
* - The theme (classic or block) wraps this content as usual.
*
* @param string $content Original page content.
*
* @return string
*/
public function filter_the_content_for_preview( $content ) {
if ( ! $this->is_main_query_page() ) {
return $content;
}
$page_id = get_the_ID();
$preview_page_id = $this->get_preview_page_id();
if ( $preview_page_id <= 0 || (int) $page_id !== (int) $preview_page_id ) {
return $content;
}
$preview_data = $this->get_preview_data_from_request();
if ( empty( $preview_data ) ) {
// No active preview snapshot, show a simple message.
return '
' . esc_html__( 'This is a booking form preview page. Please refresh the preview from the Builder.', 'booking' ) . '
';
}
// Safety: disable caching for this request.
// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedConstantFound
if ( ! defined( 'DONOTCACHEPAGE' ) ) { define( 'DONOTCACHEPAGE', true ); }
nocache_headers();
// Store preview data for this request so other hooks can access it.
$this->current_preview_data = $preview_data;
$this->register_preview_source_filters();
$resource_id = $this->get_current_preview_resource_id();
if ( $resource_id <= 0 ) {
$resource_id = WPBC_FE_Attr_Postprocessor::get_default_booking_resource_id();
}
$form_name = isset( $preview_data['form_name'] ) ? sanitize_text_field( wp_unslash( $preview_data['form_name'] ) ) : 'standard';
if ( '' === $form_name ) {
$form_name = 'standard';
}
if ( 'appointment' === $this->get_current_preview_render_mode() ) {
$shortcode = '[booking_appointment form_type="' . esc_attr( $form_name ) . '"]';
$preview_html = do_shortcode( $shortcode );
} else {
$preview_html = WPBC_FE_Render::render_booking_form(
array(
'resource_id' => $resource_id,
'cal_count' => 1,
'is_echo' => 0,
'custom_booking_form' => $form_name,
'form_status' => 'preview',
'calendar_request_overrides' => $this->get_current_preview_calendar_request_overrides(),
)
);
}
$this->remove_preview_source_filters();
return $this->filter_wrapped_html_for_preview_form_style( $preview_html, array(), $resource_id, $form_name );
}
/**
* Make the authenticated transient snapshot the source for this preview.
*
* The preview must not depend on a saved `preview` database row. The returned
* loader arguments include a server-owned marker that the paired loader
* filter recognizes during this request only.
*
* @param array $resolution Existing database or missing-source resolution.
* @param array $request Front-end form source request.
*
* @return array Preview resolution or the unchanged result when it is unrelated.
*/
public function filter_form_source_resolution_for_preview( $resolution, $request ) {
if ( ! $this->is_current_preview_request( $request ) ) {
return $resolution;
}
$resolution = is_array( $resolution ) ? $resolution : array();
$fallback_chain = isset( $resolution['fallback_chain'] ) && is_array( $resolution['fallback_chain'] )
? $resolution['fallback_chain']
: array();
$request_resource_id = isset( $request['resource_id'] ) ? absint( $request['resource_id'] ) : 0;
$loader_resource_id = 'appointment' === $this->get_current_preview_render_mode()
? $request_resource_id
: $this->get_current_preview_resource_id();
return array(
'engine' => 'bfb_db',
'apply_after_load_filter' => true,
'bfb_loader_args' => array(
'form_slug' => $this->get_current_preview_form_name(),
'status' => 'preview',
'resource_id' => $loader_resource_id,
'wpbc_preview_snapshot' => 1,
),
'fallback_chain' => $fallback_chain,
);
}
/**
* Return the transient form pair instead of a saved Form Builder row.
*
* @param array $form_pair Pair already returned by the Form Builder loader.
* @param array $loader_args Normalized Form Builder loader arguments.
*
* @return array Selected preview snapshot or the unchanged pair.
*/
public function filter_form_pair_for_preview( $form_pair, $loader_args ) {
if ( ! is_array( $loader_args ) || empty( $loader_args['wpbc_preview_snapshot'] ) ) {
return $form_pair;
}
$request = array(
'resource_id' => isset( $loader_args['resource_id'] ) ? $loader_args['resource_id'] : 0,
'form_slug' => isset( $loader_args['form_slug'] ) ? $loader_args['form_slug'] : '',
'form_status' => isset( $loader_args['status'] ) ? $loader_args['status'] : '',
);
if ( ! $this->is_current_preview_request( $request ) ) {
return $form_pair;
}
return array(
'form' => isset( $this->current_preview_data['advanced_form'] ) ? (string) $this->current_preview_data['advanced_form'] : '',
'content' => isset( $this->current_preview_data['content_form'] ) ? (string) $this->current_preview_data['content_form'] : '',
'settings_json' => isset( $this->current_preview_data['settings_json'] ) ? (string) $this->current_preview_data['settings_json'] : '',
);
}
/**
* Check whether a renderer or loader request belongs to this preview snapshot.
*
* @param array $request Source resolver or loader request values.
*
* @return bool True only for the exact preview resource, form, and status.
*/
private function is_current_preview_request( $request ) {
if ( empty( $this->current_preview_data ) || ! is_array( $request ) ) {
return false;
}
$request_resource_id = isset( $request['resource_id'] ) ? absint( $request['resource_id'] ) : 0;
$request_form_name = isset( $request['form_slug'] ) ? sanitize_text_field( (string) $request['form_slug'] ) : '';
$request_status = isset( $request['form_status'] ) ? sanitize_key( (string) $request['form_status'] ) : '';
$resource_matches = 'appointment' === $this->get_current_preview_render_mode()
? $request_resource_id > 0
: $request_resource_id === $this->get_current_preview_resource_id();
return $resource_matches
&& $request_form_name === $this->get_current_preview_form_name()
&& 'preview' === $request_status;
}
/**
* Switch the selected Appointment form to the authenticated preview source.
*
* @param string $form_status Existing form status.
* @param string $form_slug Resolved Appointment form slug.
* @param int $provider_id Selected Provider resource ID.
* @param array $config Signed Appointment configuration.
*
* @return string Preview only for the active snapshot and exact form slug.
*/
public function filter_appointment_form_status_for_preview( $form_status, $form_slug, $provider_id, $config ) { // phpcs:ignore Generic.CodeAnalysis.UnusedFunctionParameter.FoundAfterLastUsed
if (
'appointment' !== $this->get_current_preview_render_mode()
|| absint( $provider_id ) <= 0
|| sanitize_text_field( (string) $form_slug ) !== $this->get_current_preview_form_name()
) {
return $form_status;
}
return 'preview';
}
/**
* Return the resource/calendar ID scoped to the active preview snapshot.
*
* Older transients stored this context only under `form_id`; retain that
* fallback until all ten-minute preview sessions have naturally expired.
*
* @return int Preview resource ID.
*/
private function get_current_preview_resource_id() {
if ( isset( $this->current_preview_data['resource_id'] ) ) {
return absint( $this->current_preview_data['resource_id'] );
}
return isset( $this->current_preview_data['form_id'] ) ? absint( $this->current_preview_data['form_id'] ) : 0;
}
/**
* Return the normalized form name scoped to the active preview snapshot.
*
* @return string Preview form name.
*/
private function get_current_preview_form_name() {
$form_name = isset( $this->current_preview_data['form_name'] )
? sanitize_text_field( (string) $this->current_preview_data['form_name'] )
: 'standard';
return '' === $form_name ? 'standard' : $form_name;
}
/**
* Return the allow-listed renderer used by the active preview snapshot.
*
* @return string Either booking or appointment.
*/
private function get_current_preview_render_mode() {
$render_mode = isset( $this->current_preview_data['render_mode'] )
? sanitize_key( (string) $this->current_preview_data['render_mode'] )
: 'booking';
return 'appointment' === $render_mode ? 'appointment' : 'booking';
}
/**
* Return calendar-load overrides scoped to the active preview snapshot.
*
* Appointment rendering happens in a later signed AJAX request, so the
* renderer needs a public, read-only accessor rather than direct access to
* transient internals. Values were allow-list sanitized at the transient
* boundary and are sanitized again here for defense in depth.
*
* @return array Safe calendar-load request overrides.
*/
public function get_current_preview_calendar_request_overrides() {
$calendar_request_overrides = isset( $this->current_preview_data['calendar_request_overrides'] )
? $this->current_preview_data['calendar_request_overrides']
: array();
return $this->sanitize_preview_calendar_request_overrides( $calendar_request_overrides );
}
/**
* Sanitize booking-form source before it enters a preview transient.
*
* Preview markup is intentionally rendered as booking-form markup rather than
* escaped as plain text. Therefore the shared preview service, rather than
* each caller, must enforce the established Form Builder KSES policy. An
* unavailable sanitizer fails closed for non-empty markup.
*
* @param mixed $form_source Raw advanced-form or content-form source.
*
* @return string|null Sanitized source, or null when it cannot be sanitized.
*/
private function sanitize_preview_form_source( $form_source ) {
if ( ! is_scalar( $form_source ) ) {
return '';
}
$form_source = (string) $form_source;
if ( '' === $form_source ) {
return '';
}
if ( ! function_exists( 'wpbc_bfb_sanitize_form_text' ) ) {
return null;
}
return (string) wpbc_bfb_sanitize_form_text( $form_source );
}
/**
* Normalize Form Builder structure at the shared preview write boundary.
*
* @param mixed $structure Candidate decoded Form Builder structure.
*
* @return array|null Sanitized structure, or null when normalization fails.
*/
private function sanitize_preview_structure( $structure ) {
$structure = is_array( $structure ) ? $structure : array();
$structure = apply_filters( 'wpbc_bfb_sanitize_structure_before_save', $structure );
return is_array( $structure ) ? $structure : null;
}
/**
* Normalize optional Form Style values for a preview snapshot.
*
* @param mixed $form_style Candidate Form Style overrides.
*
* @return array|null Sanitized style values, or null when required helpers are unavailable.
*/
private function sanitize_preview_form_style( $form_style ) {
if ( ! is_array( $form_style ) || empty( $form_style ) ) {
return array();
}
$scalar_style = array();
foreach ( $form_style as $style_key => $style_value ) {
if ( is_scalar( $style_value ) ) {
$scalar_style[ $style_key ] = (string) $style_value;
}
}
if ( empty( $scalar_style ) ) {
return array();
}
if (
! function_exists( 'wpbc_bfb_settings__sanitize_form_style' )
|| ! function_exists( 'wpbc_bfb_settings__get_custom_form_style_options' )
|| ! function_exists( 'wpbc_bfb_settings__get_form_accent_options' )
) {
return null;
}
$style_name = isset( $scalar_style['booking_form_style'] )
? $scalar_style['booking_form_style']
: '';
return array_merge(
array(
'booking_form_style' => wpbc_bfb_settings__sanitize_form_style( $style_name ),
),
wpbc_bfb_settings__get_custom_form_style_options( $scalar_style ),
wpbc_bfb_settings__get_form_accent_options( $scalar_style )
);
}
/**
* Normalize the global options supported by transient previews.
*
* Calendar skin values must match the current server-side skin registry.
* Appearance and Date Selection modules share this narrow allow-list. Unknown
* keys are discarded so callers cannot turn the preview transient into a
* generic option override channel.
*
* @param mixed $option_overrides Candidate preview option overrides.
*
* @return array Sanitized allow-listed overrides.
*/
private function sanitize_preview_option_overrides( $option_overrides ) {
if ( ! is_array( $option_overrides ) ) {
return array();
}
$sanitized = array();
$toggle_keys = array(
'booking_timeslot_picker',
'booking_range_selection_time_is_active',
'booking_change_over_days_triangles',
'booking_last_checkout_day_available',
'booking_recurrent_time',
'booking_is_show_legend',
'booking_legend_is_show_numbers',
'booking_legend_is_vertical',
'booking_legend_is_show_item_available',
'booking_legend_is_show_item_pending',
'booking_legend_is_show_item_approved',
'booking_legend_is_show_item_partially',
'booking_legend_is_show_item_unavailable',
);
foreach ( $toggle_keys as $toggle_key ) {
if ( isset( $option_overrides[ $toggle_key ] ) && is_scalar( $option_overrides[ $toggle_key ] ) && in_array( (string) $option_overrides[ $toggle_key ], array( 'On', 'Off' ), true ) ) {
$sanitized[ $toggle_key ] = (string) $option_overrides[ $toggle_key ];
}
}
$choice_keys = array(
'booking_type_of_day_selections' => array( 'single', 'multiple', 'range' ),
'booking_range_selection_type' => array( 'dynamic', 'fixed' ),
);
foreach ( $choice_keys as $choice_key => $allowed_choices ) {
if ( isset( $option_overrides[ $choice_key ] ) && is_scalar( $option_overrides[ $choice_key ] ) ) {
$choice = sanitize_key( (string) $option_overrides[ $choice_key ] );
if ( in_array( $choice, $allowed_choices, true ) ) {
$sanitized[ $choice_key ] = $choice;
}
}
}
$bounded_integer_keys = array(
'booking_range_selection_days_count' => array( 1, 180 ),
'booking_range_selection_days_count_dynamic' => array( 1, 1095 ),
'booking_range_selection_days_max_count_dynamic' => array( 1, 1095 ),
);
foreach ( $bounded_integer_keys as $integer_key => $bounds ) {
if ( isset( $option_overrides[ $integer_key ] ) && is_scalar( $option_overrides[ $integer_key ] ) && preg_match( '/^\d+$/', (string) $option_overrides[ $integer_key ] ) ) {
$integer_value = (int) $option_overrides[ $integer_key ];
if ( $integer_value >= $bounds[0] && $integer_value <= $bounds[1] ) {
$sanitized[ $integer_key ] = (string) $integer_value;
}
}
}
foreach ( array( 'booking_range_start_day', 'booking_range_start_day_dynamic' ) as $weekday_key ) {
if ( isset( $option_overrides[ $weekday_key ] ) ) {
$weekdays = $this->sanitize_preview_integer_list( $option_overrides[ $weekday_key ], -1, 6, array( -1 ) );
$sanitized[ $weekday_key ] = implode( ',', $weekdays );
}
}
if ( isset( $option_overrides['booking_range_selection_days_specific_num_dynamic'] ) ) {
$specific_days = $this->sanitize_preview_integer_list( $option_overrides['booking_range_selection_days_specific_num_dynamic'], 1, 1095, array() );
$sanitized['booking_range_selection_days_specific_num_dynamic'] = implode( ',', $specific_days );
}
foreach ( array( 'booking_range_selection_start_time', 'booking_range_selection_end_time' ) as $time_key ) {
if ( isset( $option_overrides[ $time_key ] ) && is_scalar( $option_overrides[ $time_key ] ) && preg_match( '/^(?:[01]\d|2[0-3]):[0-5]\d$/', (string) $option_overrides[ $time_key ] ) ) {
$sanitized[ $time_key ] = (string) $option_overrides[ $time_key ];
}
}
foreach ( array( 'available', 'pending', 'approved', 'partially', 'unavailable' ) as $legend_item ) {
$text_key = 'booking_legend_text_for_item_' . $legend_item;
if ( isset( $option_overrides[ $text_key ] ) && is_scalar( $option_overrides[ $text_key ] ) ) {
$legend_text = sanitize_text_field( (string) $option_overrides[ $text_key ] );
$sanitized[ $text_key ] = function_exists( 'mb_substr' ) ? mb_substr( $legend_text, 0, 255 ) : substr( $legend_text, 0, 255 );
}
}
if ( array_key_exists( 'booking_skin', $option_overrides ) && is_scalar( $option_overrides['booking_skin'] ) ) {
$calendar_skin = $this->sanitize_preview_calendar_skin( (string) $option_overrides['booking_skin'] );
if ( '' !== $calendar_skin ) {
$sanitized['booking_skin'] = $calendar_skin;
}
}
return $sanitized;
}
/**
* Normalize Date Selection values used by the explicit browser bootstrap.
*
* @param mixed $calendar_parameters Candidate calendar parameters.
*
* @return array Sanitized allow-listed parameters.
*/
private function sanitize_preview_calendar_parameters( $calendar_parameters ) {
if ( ! is_array( $calendar_parameters ) ) {
return array();
}
$sanitized = array();
if ( array_key_exists( 'is_enabled_change_over', $calendar_parameters ) ) {
$is_enabled_change_over = $this->sanitize_preview_boolean( $calendar_parameters['is_enabled_change_over'] );
if ( null !== $is_enabled_change_over ) {
$sanitized['is_enabled_change_over'] = $is_enabled_change_over;
}
}
if ( isset( $calendar_parameters['days_select_mode'] ) && is_scalar( $calendar_parameters['days_select_mode'] ) ) {
$days_select_mode = sanitize_key( (string) $calendar_parameters['days_select_mode'] );
if ( in_array( $days_select_mode, array( 'single', 'multiple', 'range' ), true ) ) {
$sanitized['days_select_mode'] = $days_select_mode;
}
}
$integer_keys = array(
'fixed__days_num' => array( 0, 180 ),
'dynamic__days_min' => array( 0, 1095 ),
'dynamic__days_max' => array( 0, 1095 ),
);
foreach ( $integer_keys as $integer_key => $bounds ) {
if ( isset( $calendar_parameters[ $integer_key ] ) && is_scalar( $calendar_parameters[ $integer_key ] ) && preg_match( '/^\d+$/', (string) $calendar_parameters[ $integer_key ] ) ) {
$integer_value = (int) $calendar_parameters[ $integer_key ];
if ( $integer_value >= $bounds[0] && $integer_value <= $bounds[1] ) {
$sanitized[ $integer_key ] = $integer_value;
}
}
}
$list_keys = array(
'fixed__week_days__start' => array( -1, 6, array( -1 ) ),
'dynamic__days_specific' => array( 1, 1095, array() ),
'dynamic__week_days__start' => array( -1, 6, array( -1 ) ),
);
foreach ( $list_keys as $list_key => $bounds ) {
if ( array_key_exists( $list_key, $calendar_parameters ) ) {
$sanitized[ $list_key ] = $this->sanitize_preview_integer_list( $calendar_parameters[ $list_key ], $bounds[0], $bounds[1], $bounds[2] );
}
}
if ( isset( $calendar_parameters['booking_recurrent_time'] ) && in_array( (string) $calendar_parameters['booking_recurrent_time'], array( 'On', 'Off' ), true ) ) {
$sanitized['booking_recurrent_time'] = (string) $calendar_parameters['booking_recurrent_time'];
}
return $sanitized;
}
/**
* Normalize Date Selection values forwarded to calendar-load requests.
*
* @param mixed $request_overrides Candidate request overrides.
*
* @return array Sanitized allow-listed request values.
*/
private function sanitize_preview_calendar_request_overrides( $request_overrides ) {
if ( ! is_array( $request_overrides ) ) {
return array();
}
$sanitized = array();
foreach ( array( 'wpbc_settings_calendar_preview', 'wpbc_setup_wizard_date_selection_preview' ) as $marker_key ) {
if (
isset( $request_overrides[ $marker_key ] )
&& is_scalar( $request_overrides[ $marker_key ] )
&& '1' === (string) $request_overrides[ $marker_key ]
) {
$sanitized[ $marker_key ] = 1;
}
}
if ( isset( $request_overrides['wpbc_setup_wizard_date_selection_preview_nonce'] ) && is_scalar( $request_overrides['wpbc_setup_wizard_date_selection_preview_nonce'] ) ) {
$sanitized['wpbc_setup_wizard_date_selection_preview_nonce'] = sanitize_text_field( (string) $request_overrides['wpbc_setup_wizard_date_selection_preview_nonce'] );
}
$toggle_keys = array(
'wpbc_settings_calendar_preview_changeover',
'wpbc_settings_calendar_preview_triangles',
'wpbc_settings_calendar_preview_recurrent_time',
'wpbc_settings_calendar_preview_last_checkout',
'wpbc_settings_calendar_preview_show_legend',
'wpbc_settings_calendar_preview_legend_show_numbers',
'wpbc_settings_calendar_preview_legend_vertical',
);
foreach ( array( 'available', 'pending', 'approved', 'partially', 'unavailable' ) as $legend_item ) {
$toggle_keys[] = 'wpbc_settings_calendar_preview_legend_show_' . $legend_item;
}
foreach ( $toggle_keys as $toggle_key ) {
if ( isset( $request_overrides[ $toggle_key ] ) && is_scalar( $request_overrides[ $toggle_key ] ) && in_array( (string) $request_overrides[ $toggle_key ], array( 'On', 'Off' ), true ) ) {
$sanitized[ $toggle_key ] = (string) $request_overrides[ $toggle_key ];
}
}
foreach ( array( 'available', 'pending', 'approved', 'partially', 'unavailable' ) as $legend_item ) {
$text_key = 'wpbc_settings_calendar_preview_legend_text_' . $legend_item;
if ( isset( $request_overrides[ $text_key ] ) && is_scalar( $request_overrides[ $text_key ] ) ) {
$legend_text = sanitize_text_field( (string) $request_overrides[ $text_key ] );
$sanitized[ $text_key ] = function_exists( 'mb_substr' ) ? mb_substr( $legend_text, 0, 255 ) : substr( $legend_text, 0, 255 );
}
}
return $sanitized;
}
/**
* Normalize one preview boolean without treating malformed containers as true.
*
* Preview context normally originates from a server-owned mapper, but the
* shared transient boundary validates it again so future callers cannot turn
* arrays or arbitrary strings into enabled behavior through PHP casting.
*
* @param mixed $raw_value Candidate boolean value.
*
* @return bool|null Normalized boolean, or null when the value is invalid.
*/
private function sanitize_preview_boolean( $raw_value ) {
if ( true === $raw_value || 1 === $raw_value || '1' === $raw_value || 'On' === $raw_value ) {
return true;
}
if ( false === $raw_value || 0 === $raw_value || '0' === $raw_value || 'Off' === $raw_value ) {
return false;
}
return null;
}
/**
* Normalize a scalar or array of integers against explicit bounds.
*
* @param mixed $raw_list Candidate array or comma-separated list.
* @param int $minimum Inclusive lower bound.
* @param int $maximum Inclusive upper bound.
* @param int[] $fallback Fallback list when no values remain.
*
* @return int[] Unique normalized integers.
*/
private function sanitize_preview_integer_list( $raw_list, $minimum, $maximum, array $fallback ) {
$raw_values = is_array( $raw_list ) ? $raw_list : explode( ',', is_scalar( $raw_list ) ? (string) $raw_list : '' );
$integers = array();
foreach ( $raw_values as $raw_value ) {
if ( ! is_scalar( $raw_value ) || ! preg_match( '/^-?\d+$/', trim( (string) $raw_value ) ) ) {
continue;
}
$integer_value = (int) $raw_value;
if ( $integer_value >= $minimum && $integer_value <= $maximum ) {
$integers[] = $integer_value;
}
}
return empty( $integers ) ? $fallback : array_values( array_unique( $integers ) );
}
/**
* Validate one relative calendar skin path against the live skin registry.
*
* @param string $calendar_skin Candidate relative path or registered URL.
*
* @return string Valid relative skin path, or an empty string.
*/
private function sanitize_preview_calendar_skin( $calendar_skin ) {
if ( ! function_exists( 'wpbc_get_calendar_skin_options' ) ) {
return '';
}
$calendar_skin = $this->normalize_preview_calendar_skin( $calendar_skin );
foreach ( wpbc_get_calendar_skin_options() as $registered_skin => $registered_label ) {
if ( is_array( $registered_label ) && ! empty( $registered_label['optgroup'] ) ) {
continue;
}
if ( $calendar_skin === $this->normalize_preview_calendar_skin( $registered_skin ) ) {
return $calendar_skin;
}
}
return '';
}
/**
* Convert a registered skin URL or filesystem path to canonical relative form.
*
* @param mixed $calendar_skin Calendar skin path or URL.
*
* @return string Normalized relative path.
*/
private function normalize_preview_calendar_skin( $calendar_skin ) {
$calendar_skin = is_scalar( $calendar_skin ) ? sanitize_text_field( (string) $calendar_skin ) : '';
$replace = array( WPBC_PLUGIN_DIR, WPBC_PLUGIN_URL );
$upload_dir = wp_upload_dir();
if ( ! empty( $upload_dir['basedir'] ) ) {
$replace[] = $upload_dir['basedir'];
}
if ( ! empty( $upload_dir['baseurl'] ) ) {
$replace[] = $upload_dir['baseurl'];
}
return str_replace( $replace, '', $calendar_skin );
}
public function filter_form_advanced_form_for_preview( $advanced_form, $form_id ) {
if ( empty( $this->current_preview_data ) ) {
return $advanced_form;
}
if ( 'appointment' !== $this->get_current_preview_render_mode() && (int) $form_id !== (int) $this->current_preview_data['form_id'] ) {
return $advanced_form;
}
if ( isset( $this->current_preview_data['advanced_form'] ) ) {
return (string) $this->current_preview_data['advanced_form'];
}
return $advanced_form;
}
public function filter_form_content_form_for_preview( $content_form, $form_id ) {
if ( empty( $this->current_preview_data ) ) {
return $content_form;
}
if ( 'appointment' !== $this->get_current_preview_render_mode() && (int) $form_id !== (int) $this->current_preview_data['form_id'] ) {
return $content_form;
}
if ( isset( $this->current_preview_data['content_form'] ) ) {
return (string) $this->current_preview_data['content_form'];
}
return $content_form;
}
/**
* Filter that allows BFB structure loader to receive snapshot for preview.
*
* Usage example in your loader:
* $structure = apply_filters( 'wpbc_bfb_get_form_structure', $structure, $form_id );
*
* @param array $structure Default structure loaded from DB.
* @param int $form_id Booking form ID.
*
* @return array
*/
public function filter_form_structure_for_preview( $structure, $form_id ) {
if ( empty( $this->current_preview_data ) ) {
return $structure;
}
if ( 'appointment' !== $this->get_current_preview_render_mode() && (int) $form_id !== (int) $this->current_preview_data['form_id'] ) {
return $structure;
}
if ( empty( $this->current_preview_data['structure'] ) || ! is_array( $this->current_preview_data['structure'] ) ) {
return $structure;
}
return $this->current_preview_data['structure'];
}
/**
* Apply unsaved global Form Style values to the preview iframe only.
*
* @param string $wrapped_html Wrapped booking form HTML.
* @param array $bfb_settings BFB settings.
* @param int $resource_id Booking resource ID.
* @param string $custom_booking_form_name Form slug.
* @return string
*/
public function filter_wrapped_html_for_preview_form_style( $wrapped_html, $bfb_settings, $resource_id, $custom_booking_form_name ) { // phpcs:ignore Generic.CodeAnalysis.UnusedFunctionParameter.FoundAfterLastUsed
$preview_style = $this->get_preview_form_style();
if ( empty( $preview_style ) ) {
return $wrapped_html;
}
$style = isset( $preview_style['booking_form_style'] ) ? wpbc_bfb_settings__sanitize_form_style( $preview_style['booking_form_style'] ) : wpbc_bfb_settings__get_default_form_style();
$preset = wpbc_bfb_settings__get_form_style_preset( $style );
$wrapped_html = $this->remove_classes_from_first_form_wrapper(
$wrapped_html,
array(
'wpbc_theme_dark_1',
'wpbc_bfb_form_appearance_custom',
)
);
$wrapped_html = $this->remove_classes_from_first_tag_with_classes(
$wrapped_html,
array( 'wpbc_bfb_form' ),
array(
'wpbc_theme_dark_1',
'wpbc_bfb_form_appearance_custom',
)
);
$theme_class = isset( $preset['theme_class'] ) ? sanitize_html_class( (string) $preset['theme_class'] ) : '';
if ( '' !== $theme_class ) {
$wrapped_html = WPBC_FE_Form_Style_Injector::add_class_to_first_tag_with_classes( $wrapped_html, array( 'wpbc_container', 'wpbc_form' ), $theme_class );
}
$css_vars = wpbc_bfb_settings__get_form_style_css_vars( $style, $preview_style );
if ( ! empty( $css_vars ) ) {
$wrapped_html = WPBC_FE_Form_Style_Injector::inject_css_vars_into_form_wrapper( $wrapped_html, $css_vars );
$wrapped_html = WPBC_FE_Form_Style_Injector::inject_css_vars_into_bfb_root( $wrapped_html, $css_vars );
}
if ( wpbc_bfb_settings__is_custom_form_style( $style ) ) {
$wrapped_html = WPBC_FE_Form_Style_Injector::add_class_to_first_tag_with_classes( $wrapped_html, array( 'wpbc_container', 'wpbc_form' ), 'wpbc_bfb_form_appearance_custom' );
$wrapped_html = WPBC_FE_Form_Style_Injector::add_class_to_first_tag_with_classes( $wrapped_html, array( 'wpbc_bfb_form' ), 'wpbc_bfb_form_appearance_custom' );
}
return $wrapped_html;
}
/**
* Get sanitized preview Form Style override from the current transient data.
*
* @return array
*/
protected function get_preview_form_style() {
if ( empty( $this->current_preview_data['form_style'] ) || ! is_array( $this->current_preview_data['form_style'] ) ) {
return array();
}
$style = isset( $this->current_preview_data['form_style']['booking_form_style'] ) ? $this->current_preview_data['form_style']['booking_form_style'] : '';
$style = wpbc_bfb_settings__sanitize_form_style( $style );
$custom_options = wpbc_bfb_settings__get_custom_form_style_options( $this->current_preview_data['form_style'] );
$accent_options = wpbc_bfb_settings__get_form_accent_options( $this->current_preview_data['form_style'] );
return array_merge(
array(
'booking_form_style' => $style,
),
$custom_options,
$accent_options
);
}
/**
* Remove classes from the first outer booking form wrapper.
*
* @param string $html HTML.
* @param array $class_names Class names to remove.
* @return string
*/
protected function remove_classes_from_first_form_wrapper( $html, $class_names ) {
return $this->remove_classes_from_first_tag_with_classes( $html, array( 'wpbc_container', 'wpbc_form' ), $class_names );
}
/**
* Remove classes from the first tag that has all required classes.
*
* @param string $html HTML.
* @param array $required_classes Required classes.
* @param array $class_names Class names to remove.
* @return string
*/
protected function remove_classes_from_first_tag_with_classes( $html, $required_classes, $class_names ) {
$html = (string) $html;
$required_classes = is_array( $required_classes ) ? $required_classes : array();
$class_names = is_array( $class_names ) ? $class_names : array();
$remove_map = array();
$required_map = array();
foreach ( $required_classes as $class_name ) {
$class_name = sanitize_html_class( (string) $class_name );
if ( '' !== $class_name ) {
$required_map[ $class_name ] = true;
}
}
foreach ( $class_names as $class_name ) {
$class_name = sanitize_html_class( (string) $class_name );
if ( '' !== $class_name ) {
$remove_map[ $class_name ] = true;
}
}
if ( empty( $remove_map ) || empty( $required_map ) ) {
return $html;
}
$done = false;
$out = preg_replace_callback(
'/]*\bclass\s*=\s*(["\'])(.*?)\1[^>]*>/i',
function ( $matches ) use ( &$done, $remove_map, $required_map ) {
$tag = $matches[0];
if ( $done ) {
return $tag;
}
$quote = $matches[1];
$classes = preg_split( '/\s+/', trim( (string) $matches[2] ) );
$classes = is_array( $classes ) ? $classes : array();
foreach ( $required_map as $required_class => $unused ) {
if ( ! in_array( $required_class, $classes, true ) ) {
return $tag;
}
}
$filtered = array();
foreach ( $classes as $class_name ) {
if ( '' === $class_name || isset( $remove_map[ $class_name ] ) ) {
continue;
}
$filtered[] = $class_name;
}
$done = true;
return preg_replace( '/\bclass\s*=\s*(["\'])(.*?)\1/i', 'class=' . $quote . esc_attr( implode( ' ', $filtered ) ) . $quote, $tag, 1 );
},
$html
);
return ( null === $out ) ? $html : $out;
}
/**
* Hide the preview page from the Pages list in admin.
*
* @param WP_Query $query Main query.
*/
public function hide_preview_page_in_admin_list( $query ) {
if ( ! is_admin() || ! $query->is_main_query() ) {
return;
}
global $pagenow;
if ( 'edit.php' !== $pagenow ) {
return;
}
$post_type = $query->get( 'post_type' );
if ( 'page' !== $post_type && '' !== $post_type ) {
return;
}
$page_id = $this->get_preview_page_id();
if ( $page_id <= 0 ) {
return;
}
$not_in = (array) $query->get( 'post__not_in' );
$not_in[] = (int) $page_id;
$query->set( 'post__not_in', $not_in );
}
/**
* Render one inline preview and return its data-only browser bootstrap.
*
* This is the reusable response boundary for authenticated administration
* screens. The HTML is rendered by the normal front-end renderer, while all
* script elements are removed. The browser receives only JSON-safe values and
* initializes the form through known Booking Calendar functions; response
* JavaScript is never evaluated.
*
* The caller must resolve templates from a server-owned allow-list and must
* perform its own capability and nonce checks before returning this payload.
*
* @param int $preview_form_id Preview resource/calendar ID.
* @param array $structure Decoded BFB structure.
* @param string $form_name Form slug rendered by the booking form.
* @param string $advanced_form Exported booking form source.
* @param string $content_form Exported booking-data content source.
* @param array $form_style Optional unsaved Form Style settings.
* @param array $preview_context Optional server-owned renderer and option context.
*
* @return array
|false Inline HTML and bootstrap data, or false on failure.
*/
public function render_inline_preview_payload( $preview_form_id, $structure, $form_name = 'standard', $advanced_form = '', $content_form = '', $form_style = array(), $preview_context = array() ) {
$preview_form_id = is_scalar( $preview_form_id ) ? absint( $preview_form_id ) : 0;
$preview_form_id = $preview_form_id > 0 ? $preview_form_id : 1;
$form_name = is_scalar( $form_name ) ? sanitize_key( (string) $form_name ) : '';
$form_name = '' === $form_name ? 'standard' : $form_name;
$preview_html = $this->render_inline_preview(
$preview_form_id,
$structure,
$form_name,
$advanced_form,
$content_form,
$form_style,
$preview_context
);
if ( ! is_string( $preview_html ) || '' === trim( $preview_html ) ) {
return false;
}
return array(
'html' => $this->remove_script_elements( $preview_html ),
'bootstrap' => $this->get_inline_preview_bootstrap_data( $preview_form_id, $form_name, $preview_context ),
);
}
/**
* Remove executable elements from renderer HTML before an AJAX response.
*
* The normal front-end renderer can return a legacy inline calendar bootstrap
* during AJAX requests. Inline previews use the structured bootstrap returned
* beside the HTML, so no script element is needed or permitted in this path.
*
* @param string $preview_html Server-rendered preview HTML.
*
* @return string Preview HTML without script elements.
*/
private function remove_script_elements( $preview_html ) {
$preview_html = is_string( $preview_html ) ? $preview_html : '';
$preview_html = preg_replace( '##is', '', $preview_html );
return is_string( $preview_html ) ? $preview_html : '';
}
/**
* Build the explicit JSON-safe bootstrap contract for an inline form.
*
* @param int $preview_form_id Positive booking resource ID.
* @param string $form_name Validated Form Builder slug.
* @param array $preview_context Optional server-owned calendar context.
*
* @return array Allow-listed Booking Calendar initialization data.
*/
private function get_inline_preview_bootstrap_data( $preview_form_id, $form_name, array $preview_context = array() ) {
$days_selection = $this->get_inline_preview_days_selection();
$balancer_max_threads = absint( get_bk_option( 'booking_load_balancer_max_threads' ) );
$balancer_max_threads = $balancer_max_threads > 0 ? $balancer_max_threads : 1;
$is_enabled_change_over = function_exists( 'wpbc_is_booking_used_check_in_out_time' )
? (bool) wpbc_is_booking_used_check_in_out_time( false, $preview_form_id )
: false;
$range_guidance_default = function_exists( 'wpbc_frontend_messages__is_enabled' )
? wpbc_frontend_messages__is_enabled( 'message_range_selection_click_last_date' )
: true;
$range_guidance_enabled = (bool) apply_filters(
'wpbc_calendar_range_selection_guidance_is_enabled',
$range_guidance_default,
$preview_form_id,
array(
'resource_id' => $preview_form_id,
'custom_form' => $form_name,
)
);
$request_uri = '';
if ( isset( $_SERVER['REQUEST_URI'] ) && is_scalar( $_SERVER['REQUEST_URI'] ) ) { // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
$request_uri = esc_url_raw( wp_unslash( (string) $_SERVER['REQUEST_URI'] ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
}
$calendar_parameters = array(
'is_enabled_change_over' => $is_enabled_change_over,
'calendar_scroll_to' => false,
'calendar_dates_start' => '',
'calendar_dates_end' => '',
'booking_max_monthes_in_calendar' => (string) get_bk_option( 'booking_max_monthes_in_calendar' ),
'booking_start_day_weeek' => (string) get_bk_option( 'booking_start_day_weeek' ),
'calendar_number_of_months' => '1',
'days_select_mode' => (string) $days_selection['days_select_mode'],
'fixed__days_num' => (int) $days_selection['fixed__days_num'],
'fixed__week_days__start' => $this->normalize_inline_preview_integer_list( $days_selection['fixed__week_days__start'], array( -1 ) ),
'dynamic__days_min' => (int) $days_selection['dynamic__days_min'],
'dynamic__days_max' => (int) $days_selection['dynamic__days_max'],
'dynamic__days_specific' => $this->normalize_inline_preview_integer_list( $days_selection['dynamic__days_specific'], array() ),
'dynamic__week_days__start' => $this->normalize_inline_preview_integer_list( $days_selection['dynamic__week_days__start'], array( -1 ) ),
'range_selection_guidance_is_enabled' => $range_guidance_enabled,
'booking_date_format' => (string) get_bk_option( 'booking_date_format' ),
'booking_time_format' => (string) get_bk_option( 'booking_time_format' ),
);
if ( class_exists( 'wpdev_bk_biz_l' ) ) {
$calendar_parameters['is_parent_resource'] = function_exists( 'wpbc_get_child_resources_number' ) && wpbc_get_child_resources_number( $preview_form_id ) ? 1 : 0;
$calendar_parameters['booking_capacity_field'] = function_exists( 'wpbc_get__booking_capacity_field__name' ) ? (string) wpbc_get__booking_capacity_field__name() : '';
$calendar_parameters['booking_is_dissbale_booking_for_different_sub_resources'] = (string) get_bk_option( 'booking_is_dissbale_booking_for_different_sub_resources' );
}
if ( class_exists( 'wpdev_bk_biz_s' ) ) {
$calendar_parameters['booking_recurrent_time'] = (string) get_bk_option( 'booking_recurrent_time' );
}
$preview_calendar_parameters = isset( $preview_context['calendar_parameters'] )
? $this->sanitize_preview_calendar_parameters( $preview_context['calendar_parameters'] )
: array();
$calendar_parameters = array_replace( $calendar_parameters, $preview_calendar_parameters );
$is_enabled_change_over = isset( $calendar_parameters['is_enabled_change_over'] )
? (bool) $calendar_parameters['is_enabled_change_over']
: $is_enabled_change_over;
$calendar_request_overrides = isset( $preview_context['calendar_request_overrides'] )
? $this->sanitize_preview_calendar_request_overrides( $preview_context['calendar_request_overrides'] )
: array();
return array(
'balancer_max_threads' => $balancer_max_threads,
'is_enabled_change_over' => $is_enabled_change_over,
'classic_booking_context_token' => '',
'calendar_parameters' => $calendar_parameters,
'secure_parameters' => array(
'nonce' => wp_create_nonce( 'wpbc_calendar_load_ajx_wpbcnonce' ),
'user_id' => function_exists( 'wpbc_get_current_user_id' ) ? (string) wpbc_get_current_user_id() : (string) get_current_user_id(),
'locale' => (string) get_user_locale(),
),
'calendar_request' => array_merge(
array(
'resource_id' => $preview_form_id,
'booking_hash' => '',
'request_uri' => $request_uri,
'custom_form' => $form_name,
'aggregate_resource_id_str' => '',
'aggregate_type' => 'all',
'skip_general_availability' => 0,
'classic_booking_context_token' => '',
),
$calendar_request_overrides
),
);
}
/**
* Return normalized day-selection options for the inline calendar contract.
*
* @return array Day-selection values.
*/
private function get_inline_preview_days_selection() {
$defaults = array(
'days_select_mode' => 'multiple',
'fixed__days_num' => 0,
'fixed__week_days__start' => '-1',
'dynamic__days_min' => 0,
'dynamic__days_max' => 0,
'dynamic__days_specific' => '',
'dynamic__week_days__start' => '-1',
);
$days_selection = function_exists( 'wpbc__calendar__js_params__get_days_selection_arr' )
? wpbc__calendar__js_params__get_days_selection_arr()
: array();
return wp_parse_args( is_array( $days_selection ) ? $days_selection : array(), $defaults );
}
/**
* Convert a stored comma list into bounded JSON-safe integers.
*
* @param mixed $raw_list Candidate array or comma-separated list.
* @param array $fallback Fallback list when no integers are present.
*
* @return int[] Normalized integers.
*/
private function normalize_inline_preview_integer_list( $raw_list, array $fallback ) {
$raw_values = is_array( $raw_list ) ? $raw_list : explode( ',', (string) $raw_list );
$integers = array();
foreach ( $raw_values as $raw_value ) {
if ( ! is_scalar( $raw_value ) || ! preg_match( '/^-?\d+$/', trim( (string) $raw_value ) ) ) {
continue;
}
$integers[] = (int) $raw_value;
}
return empty( $integers ) ? $fallback : array_values( array_unique( $integers ) );
}
/**
* Render one unsaved Form Builder snapshot directly in the current request.
*
* This is the synchronous counterpart to {@see create_preview_session()} for
* administration screens that already load the Booking Calendar front-end
* assets. It uses the same source, markup, option, and Form Style filters but
* creates no transient, page, post, or saved Form Builder record. All filters
* and request-scoped state are removed before returning.
*
* The caller must resolve template definitions from a server-owned allow-list
* before invoking this method. Raw request values must never be passed here.
*
* @param int $preview_form_id Preview resource/calendar ID.
* @param array $structure Decoded BFB structure.
* @param string $form_name Form slug rendered by the booking form.
* @param string $advanced_form Exported booking form source.
* @param string $content_form Exported booking-data content source.
* @param array $form_style Optional unsaved Form Style settings.
* @param array $preview_context Optional server-owned renderer and option context.
*
* @return string|false Rendered booking form HTML, or false when validation or rendering fails.
*/
public function render_inline_preview( $preview_form_id, $structure, $form_name = 'standard', $advanced_form = '', $content_form = '', $form_style = array(), $preview_context = array() ) {
if ( ! class_exists( 'WPBC_FE_Render' ) || null !== $this->current_preview_data ) {
return false;
}
$preview_form_id = is_scalar( $preview_form_id ) ? absint( $preview_form_id ) : 0;
$preview_form_id = $preview_form_id > 0 ? $preview_form_id : 1;
$structure = $this->sanitize_preview_structure( $structure );
$form_name = is_scalar( $form_name ) ? sanitize_text_field( (string) $form_name ) : '';
$advanced_form = $this->sanitize_preview_form_source( $advanced_form );
$content_form = $this->sanitize_preview_form_source( $content_form );
$form_style = $this->sanitize_preview_form_style( $form_style );
$preview_context = is_array( $preview_context ) ? $preview_context : array();
$render_mode = isset( $preview_context['render_mode'] )
&& is_scalar( $preview_context['render_mode'] )
&& 'appointment' === sanitize_key( (string) $preview_context['render_mode'] )
? 'appointment'
: 'booking';
$option_overrides = isset( $preview_context['option_overrides'] )
? $this->sanitize_preview_option_overrides( $preview_context['option_overrides'] )
: array();
$calendar_parameters = isset( $preview_context['calendar_parameters'] )
? $this->sanitize_preview_calendar_parameters( $preview_context['calendar_parameters'] )
: array();
$calendar_request_overrides = isset( $preview_context['calendar_request_overrides'] )
? $this->sanitize_preview_calendar_request_overrides( $preview_context['calendar_request_overrides'] )
: array();
if (
null === $structure
|| null === $advanced_form
|| null === $content_form
|| null === $form_style
) {
return false;
}
$form_name = '' === $form_name ? 'standard' : $form_name;
$this->current_preview_data = array(
'form_id' => $preview_form_id,
'resource_id' => $preview_form_id,
'form_name' => $form_name,
'scope' => 'inline_preview',
'render_mode' => $render_mode,
'structure' => $structure,
'advanced_form' => $advanced_form,
'content_form' => $content_form,
'form_style' => $form_style,
'option_overrides' => $option_overrides,
'calendar_parameters' => $calendar_parameters,
'calendar_request_overrides' => $calendar_request_overrides,
);
$this->register_preview_source_filters();
try {
$preview_html = WPBC_FE_Render::render_booking_form(
array(
'resource_id' => $preview_form_id,
'cal_count' => 1,
'is_echo' => 0,
'custom_booking_form' => $form_name,
'form_status' => 'preview',
'calendar_request_overrides' => $calendar_request_overrides,
)
);
$preview_html = is_string( $preview_html ) ? $preview_html : '';
return $this->filter_wrapped_html_for_preview_form_style( $preview_html, array(), $preview_form_id, $form_name );
} finally {
$this->remove_preview_source_filters();
$this->remove_preview_option_filter();
$this->current_preview_data = null;
}
}
// FixIn: 2026-01-03 14:31.
/**
* Create a preview session: store transient snapshot and return preview URL + token.
*
* @param int $preview_form_id Preview resource/calendar ID.
* @param int $user_id Current user ID.
* @param array $structure Decoded BFB structure.
* @param string $form_name Form slug rendered by the booking shortcode.
* @param string $advanced_form Exported booking form source.
* @param string $content_form Exported booking-data content source.
* @param array $form_style Optional unsaved Form Style settings.
* @param array $preview_context Optional server-owned renderer and option context.
*
* @return array|false Preview URL and token, or false on failure.
*/
public function create_preview_session( $preview_form_id, $user_id, $structure, $form_name = 'standard', $advanced_form = '', $content_form = '', $form_style = array(), $preview_context = array() ) {
$preview_form_id = is_scalar( $preview_form_id ) ? absint( $preview_form_id ) : 0;
$user_id = is_scalar( $user_id ) ? absint( $user_id ) : 0;
$authenticated_user_id = get_current_user_id();
if ( $preview_form_id <= 0 ) {
$preview_form_id = 1;
}
if ( $authenticated_user_id <= 0 || $user_id !== $authenticated_user_id ) {
return false;
}
$user_id = $authenticated_user_id;
$structure = $this->sanitize_preview_structure( $structure );
$form_name = is_scalar( $form_name ) ? sanitize_text_field( (string) $form_name ) : '';
$advanced_form = $this->sanitize_preview_form_source( $advanced_form );
$content_form = $this->sanitize_preview_form_source( $content_form );
$form_style = $this->sanitize_preview_form_style( $form_style );
$preview_context = is_array( $preview_context ) ? $preview_context : array();
$render_mode = isset( $preview_context['render_mode'] )
&& is_scalar( $preview_context['render_mode'] )
&& 'appointment' === sanitize_key( (string) $preview_context['render_mode'] )
? 'appointment'
: 'booking';
$option_overrides = isset( $preview_context['option_overrides'] )
? $this->sanitize_preview_option_overrides( $preview_context['option_overrides'] )
: array();
$calendar_parameters = isset( $preview_context['calendar_parameters'] )
? $this->sanitize_preview_calendar_parameters( $preview_context['calendar_parameters'] )
: array();
$calendar_request_overrides = isset( $preview_context['calendar_request_overrides'] )
? $this->sanitize_preview_calendar_request_overrides( $preview_context['calendar_request_overrides'] )
: array();
if (
null === $structure
|| null === $advanced_form
|| null === $content_form
|| null === $form_style
) {
return false;
}
if ( '' === $form_name ) {
$form_name = 'standard';
}
$page_id = $this->get_preview_page_id();
if ( ! $page_id ) {
return false;
}
$token = sanitize_key( wp_generate_password( 24, false, false ) );
if ( '' === $token ) {
return false;
}
$transient_key = $this->get_transient_key( $user_id, $token, $preview_form_id );
$payload = array(
'user_id' => $user_id,
// Keep form_id for the existing URL/transient and booking-submit contract.
'form_id' => $preview_form_id,
'resource_id' => $preview_form_id,
'form_name' => $form_name,
'scope' => 'preview',
'render_mode' => $render_mode,
'structure' => $structure,
'time' => time(),
'advanced_form' => $advanced_form,
'content_form' => $content_form,
'form_style' => $form_style,
'option_overrides' => $option_overrides,
'calendar_parameters' => $calendar_parameters,
'calendar_request_overrides' => $calendar_request_overrides,
);
if ( ! set_transient( $transient_key, $payload, 10 * MINUTE_IN_SECONDS ) ) {
return false;
}
$preview_url = add_query_arg( array(
'wpbc_bfb_preview' => 1,
'wpbc_bfb_preview_token' => rawurlencode( $token ),
'wpbc_bfb_preview_form_id' => $preview_form_id,
'nonce' => wp_create_nonce( 'wpbc_bfb_preview_' . $token ),
), get_permalink( $page_id ) );
return array(
'preview_url' => esc_url_raw( $preview_url ),
'token' => $token,
);
}
}
/**
* Render BFB Preview Panel in the Builder admin page.
*
* @param int $form_id Current booking form / resource ID.
*/
function wpbc_bfb_render_preview_panel( $form_id = 1 ) {
$form_id = absint( $form_id );
if ( $form_id <= 0 ) {
$form_id = 1;
}
$preview_nonce = wp_create_nonce( 'wpbc_bfb_preview' );
?>