PluginProbe
Contact Forms by Cimatti / 1.9.2
Contact Forms by Cimatti v1.9.2
2.3.6 2.3.5 2.3.0 2.2.32 2.2.4 2.2.0 2.1.2 2.1.1 trunk 1.0 1.1 1.2 1.2.1 1.3 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.3.6 1.3.7 1.3.8 1.3.9 1.4.0 1.4.1 All 62 releases
← All changes | accua-forms.php +2416 -2056 2.2.321.9.2 View file →
@@ -1,83 +1,11 @@
1 1 <?php
2 -if ( ! defined( 'ABSPATH' ) ) exit;
3 -
4 -require_once __DIR__ . '/admin/fields-page.php';
5 -require_once __DIR__ . '/admin/settings-page.php';
6 -require_once __DIR__ . '/admin/form-editor.php';
7 -require_once __DIR__ . '/includes/privacy.php';
8 -
9 -/**
10 - * Base fill colour for the admin sidebar menu icon.
11 - *
12 - * WordPress core (svg-painter.js) recolours base64 SVG menu icons to the active
13 - * admin colour scheme on load. We resolve that same base colour here and bake it
14 - * into the icon so the first server-rendered paint already matches the painted
15 - * result, avoiding a brief flash of a differently coloured icon before the JS
16 - * repaint. Colour schemes are registered on admin_init (priority 1) which runs
17 - * after admin_menu, so the exact colour is applied later by
18 - * accua_forms_paint_menu_icon() rather than at menu-registration time.
19 - */
20 -function accua_forms_admin_menu_icon_color(){
21 - global $_wp_admin_css_colors;
22 - $scheme = get_user_option('admin_color');
23 -
24 - if ( empty($scheme) || ! isset($_wp_admin_css_colors[$scheme]) ) {
25 - $scheme = 'modern';
26 - }
27 -
28 - if ( ! empty($_wp_admin_css_colors[$scheme]->icon_colors['base']) ) {
29 - return $_wp_admin_css_colors[$scheme]->icon_colors['base'];
30 - }
31 -
32 - if ( ! empty($_wp_admin_css_colors['modern']->icon_colors['base']) ) {
33 - return $_wp_admin_css_colors['modern']->icon_colors['base'];
34 - }
35 -
36 - return '#a7aaad'; // WordPress default menu icon base colour.
37 -}
38 -
39 -/**
40 - * Monochrome sidebar menu icon as a base64 data URI.
41 - *
42 - * The standalone brand icon (assets/img/accua-contacts-forms.svg) stays coloured
43 - * and is used unchanged in page headers and other contexts; only the sidebar menu
44 - * icon is neutral, per the WordPress.org plugin guidelines.
45 - */
46 -function accua_forms_admin_menu_icon(){
47 - $color = accua_forms_admin_menu_icon_color();
48 - $svg = '<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 44.46 44.46"><path fill="' . esc_attr($color) . '" d="m23.97,28.72c1.85,0,2.93-.11,2.93-.11,1.49-.15,2.75.95,2.8,2.44l.01.14c.05,1.5-1.11,2.96-2.58,3.25,0,0-2.53.5-5.25.5-7.24,0-10.11-3.84-10.11-12.98,0-8.6,3.01-12.44,10.26-12.44,2.82,0,5.11.47,5.11.47,1.47.3,2.63,1.78,2.57,3.27l-.01.15c-.05,1.5-1.31,2.6-2.8,2.45,0,0-1.13-.12-2.98-.12-4.67,0-5.54,1.6-5.54,6.22,0,5.2.92,6.76,5.59,6.76M33.36,1.93c-1.06-1.06-3.15-1.93-4.65-1.93H15.75c-1.5,0-3.59.87-4.65,1.93L1.93,11.1C.87,12.16,0,14.25,0,15.75v12.97c0,1.5.87,3.59,1.93,4.65l9.17,9.17c1.06,1.06,3.15,1.93,4.65,1.93h12.97c1.5,0,3.59-.87,4.65-1.93l9.17-9.17c1.06-1.06,1.93-3.15,1.93-4.65V15.75c0-1.5-.87-3.59-1.93-4.65z"/></svg>';
49 - return 'data:image/svg+xml;base64,' . base64_encode($svg);
50 -}
51 -
52 -/**
53 - * Repaint the sidebar menu icon with the active colour scheme's base colour.
54 - *
55 - * Runs on admin_init (priority 20, after register_admin_color_schemes at 1) when
56 - * the colour schemes are available. The icon set at menu-registration time uses
57 - * the fallback colour; here we overwrite it in the $menu global with the exact
58 - * scheme colour so the first paint matches svg-painter.js and there is no flash.
59 - */
60 -add_action('admin_init', 'accua_forms_paint_menu_icon', 20);
61 -function accua_forms_paint_menu_icon(){
62 - global $menu;
63 - if ( ! is_array($menu) ) {
64 - return;
65 - }
66 - foreach ( $menu as $i => $item ) {
67 - if ( isset($item[2]) && 'accua_forms' === $item[2] ) {
68 - $menu[$i][6] = accua_forms_admin_menu_icon();
69 - break;
70 - }
71 - }
72 -}
73 -
74 2 add_action('admin_menu', 'accua_forms_menu', -95);
75 3 function accua_forms_menu(){
76 - $dashboard_admin_page=add_menu_page('Contact Forms by Cimatti', 'Contact Forms', 'manage_options', 'accua_forms', 'accua_forms_dashboard_page', accua_forms_admin_menu_icon(), '90.90300');
4 + $dashboard_admin_page=add_menu_page('Wordpress Contact Forms by Cimatti', 'Contact Forms', 'manage_options', 'accua_forms', 'accua_forms_dashboard_page', ACCUA_FORMS_DIR_URL.'img/cimatti-icon-10.png', '90.90300');
77 5 add_action('load-'.$dashboard_admin_page, 'accua_forms_dashboard_page_head');
78 6
79 - add_submenu_page('accua_forms', 'Contact Forms by Cimatti', 'Dashboard', 'manage_options', "accua_forms", 'accua_forms_dashboard_page');
7 + add_submenu_page('accua_forms', 'Wordpress Contact Forms by Cimatti', 'Dashboard', 'manage_options', "accua_forms", 'accua_forms_dashboard_page');
80 8
81 9 $form_edit_page = add_submenu_page('accua_forms', 'Forms', 'Forms', 'manage_options', "accua_forms_list", 'accua_forms_list_page');
82 10 add_action('admin_head-'.$form_edit_page, 'accua_forms_edit_page_head');
83 11 add_action( 'admin_print_styles-'.$form_edit_page, 'accua_forms_edit_page_head_styles');
@@ -88,15 +16,14 @@
88 16 add_action( 'admin_print_styles-'.$form_add_page, 'accua_forms_edit_page_head_styles');
89 17 add_action( 'admin_print_scripts-'.$form_add_page, 'accua_forms_edit_page_head_scripts');
90 18
91 19 $form_submissions_page = add_submenu_page('accua_forms', __('Forms submissions', 'contact-forms') , __('Submissions', 'contact-forms'), 'manage_options', "accua_forms_submissions_list", '__accua_forms_submissions_list_page');
92 - add_action('load-'.$form_submissions_page, 'accua_forms_submissions_list_page_load');
93 20 add_action('admin_head-'.$form_submissions_page, 'accua_forms_submissions_list_page_head');
94 21 add_action( 'admin_print_styles-'.$form_submissions_page, 'accua_forms_edit_page_head_styles');
95 22
96 23 $form_fields_page = add_submenu_page('accua_forms', __( 'Form fields', 'contact-forms'), __('Fields', 'contact-forms'), 'manage_options', "accua_forms_fields", 'accua_forms_fields_page');
24 + //add_action('admin_head-'.$form_fields_page, 'accua_forms_fields_page_head');
97 25 add_action( 'admin_print_styles-'.$form_fields_page, 'accua_forms_edit_page_head_styles');
98 - add_action( 'admin_print_scripts-'.$form_fields_page, 'accua_forms_fields_page_enqueue_scripts');
99 26
100 27 $settings_page = add_submenu_page('accua_forms', __( 'Default Forms settings', 'contact-forms'), __('Settings', 'contact-forms'), 'manage_options', "accua_forms_settings", 'accua_forms_settings_page');
101 28 add_action( 'admin_print_styles-'.$settings_page, 'accua_forms_edit_page_head_styles');
102 29 add_action( 'admin_print_scripts-'.$settings_page, 'accua_forms_settings_page_head_scripts');
@@ -103,8 +30,9 @@
103 30
104 31 wp_enqueue_script('jquery-form');
105 32 wp_enqueue_script('jquery-color');
106 33 wp_enqueue_script('jquery-ui-core');
34 + wp_enqueue_script('jquery-ui-tabs');
107 35 wp_enqueue_script('jquery-ui-sortable');
108 36 wp_enqueue_script('jquery-ui-draggable');
109 37 wp_enqueue_script('jquery-ui-droppable');
110 38 wp_enqueue_script('jquery-ui-selectable');
@@ -120,8 +48,14 @@
120 48 'submissions' => __('Total submissions', 'contact-forms'),
121 49 );
122 50 global $hook_suffix;
123 51 register_column_headers($hook_suffix, $column_list);
52 +
53 + //$baseurl = WP_PLUGIN_URL.'/'.substr(plugin_basename(__FILE__),0,-strlen(basename(__FILE__)));
54 + //echo '<link href="'.$baseurl.'/flot/layout.css" rel="stylesheet" type="text/css">';
55 + //echo '<!--[if lte IE 8]><script language="javascript" type="text/javascript" src="'.$baseurl.'/flot/excanvas.min.js"></script><![endif]-->';
56 + //echo '<script language="javascript" type="text/javascript" src="'.$baseurl.'/flot/jquery.flot.js"></script>';
57 +
124 58 }
125 59
126 60
127 61 function accua_forms_report_page() {
@@ -137,9 +71,8 @@
137 71 FROM `{$wpdb->prefix}cformssubmissions`
138 72 GROUP BY `year`, `month`
139 73 ORDER BY `year` DESC, `month` DESC";
140 74
141 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared -- No user input in query
142 75 $results = $wpdb->get_results($query);
143 76
144 77 if ($results) {
145 78 ?>
@@ -147,8 +80,9 @@
147 80 .column-submissions, .column-unique_submissions {
148 81 text-align: right !important;
149 82 }
150 83 </style>
84 + <div id="accua-form-report-graph" style="height:300px;"></div>
151 85 <table class="widefat" id="stnl_review_reviewed">
152 86 <thead>
153 87 <tr><?php print_column_headers($hook_suffix); ?></tr>
154 88 </thead>
@@ -160,30 +94,55 @@
160 94 <tbody>
161 95 <?php
162 96 $alternate = false;
163 97 $hidden = get_hidden_columns($hook_suffix);
98 + $data = array(
99 + array( 'label' => __( 'Unique submissions', 'contact-forms'), 'data' => array()),
100 + array( 'label' => __( 'Total submissions', 'contact-forms'), 'data' => array()),
101 + );
164 102 foreach ($results as $result){
165 - $month = esc_html( $months[$result->month] );
166 - $year = esc_html( $result->year );
167 - $unique_submissions = esc_html( $result->unique_submissions );
168 - $submissions = esc_html( $result->submissions );
169 - $alternate_class = ( $alternate = ! $alternate ) ? 'alternate' : '';
170 - $month_style = in_array( 'month', $hidden, true ) ? " style='display:none;'" : '';
171 - $unique_style = in_array( 'unique_submissions', $hidden, true ) ? " style='display:none;'" : '';
172 - $sub_style = in_array( 'submissions', $hidden, true ) ? " style='display:none;'" : '';
173 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- All variables pre-escaped above
174 - echo "<tr class='iedit " . esc_attr( $alternate_class ) . "'>\n";
175 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $month, $year pre-escaped with esc_html()
176 - echo "<td class='column-month'" . $month_style . ">" . $month . " " . $year . "</td>\n";
177 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $unique_submissions pre-escaped with esc_html()
178 - echo "<td class='column-unique_submissions'" . $unique_style . ">" . $unique_submissions . "</td>\n";
179 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $submissions pre-escaped with esc_html()
180 - echo "<td class='column-submissions'" . $sub_style . ">" . $submissions . "</td>\n";
103 + $month = $months[$result->month];
104 + echo "<tr class='iedit ".(($alternate = !$alternate)?'alternate':'')."'>\n";
105 + echo "<td class='column-month'".(in_array('month', $hidden)?" style='display:none;'":'').">$month {$result->year}</td>\n";
106 + echo "<td class='column-unique_submissions'".(in_array('unique_submissions', $hidden)?" style='display:none;'":'').">{$result->unique_submissions}</td>\n";
107 + echo "<td class='column-submissions'".(in_array('submissions', $hidden)?" style='display:none;'":'').">{$result->submissions}</td>\n";
181 108 echo "</tr>\n";
109 + $time = mktime(0, 0, 0, $result->month, 1, $result->year) * 1000;
110 + $data[0]['data'][] = array($time, (int)$result->unique_submissions);
111 + $data[1]['data'][] = array($time, (int)$result->submissions);
182 112 }
113 + /*
114 + $year = $results[0]->year;
115 + $month = $results[0]->month;
116 + while ($year <= $result->year || $month <= $result->month) {
117 +
118 + $month++;
119 + if ($month > 12) {
120 + $year++;
121 + $month = 1;
122 + }
123 + }
124 + */
183 125 ?>
184 126 </tbody>
185 127 </table>
128 +<script type="text/javascript">
129 +jQuery(function($){
130 + var data = <?php print _accua_forms_json_encode($data); ?> ;
131 + var options = {
132 + xaxis: {
133 + //autoscaleMargin: 0.005,
134 + mode: "time",
135 + timeformat: "%b %y",
136 + minTickSize: [1, "month"]
137 + },
138 + legend: {
139 + position: "nw"
140 + }
141 + };
142 + $.plot($("#accua-form-report-graph"), data, options);
143 +});
144 +</script>
186 145 <?php
187 146 }
188 147 ?>
189 148
@@ -191,46 +150,53 @@
191 150 <?php
192 151 }
193 152
194 153 function accua_forms_edit_page_head_styles() {
195 - wp_enqueue_style( 'accua-forms-admin', plugins_url('assets/css/admin.css', ACCUA_FORMS_FILE), array(), ACCUA_FORMS_CSS_VERSION); //
154 + //wp_admin_css( 'widgets' );
155 + wp_enqueue_style( 'wp-pointer' ); //for tooltips
156 + wp_enqueue_style( 'accua-forms-admin', plugins_url('accua-forms-admin.css', ACCUA_FORMS_FILE), array(), ACCUA_FORMS_CSS_VERSION); //
196 157 }
197 158
198 -add_action( 'admin_enqueue_scripts', 'accua_forms_enqueue_deactivation_modal' );
199 -function accua_forms_enqueue_deactivation_modal( $hook ) {
200 - if ( $hook !== 'plugins.php' ) {
201 - return;
202 - }
159 +function accua_forms_edit_page_head_scripts() {
160 + //wp_enqueue_script('admin-widgets');
161 + /*wp_enqueue_script('jquery-ui-sortable');
162 + wp_enqueue_script('jquery-ui-draggable');
163 + wp_enqueue_script('jquery-ui-droppable');*/
164 + wp_enqueue_script( 'wp-pointer' ); //for tooltips
165 + wp_enqueue_script('accua-jqColorPicker', plugins_url('/js/jqColorPicker.min.js', ACCUA_FORMS_FILE ), array( 'jquery' ), ACCUA_FORMS_JS_VERSION);
203 166
204 - wp_enqueue_script(
205 - 'accua-forms-deactivation-modal',
206 - plugins_url( 'assets/js/admin/deactivation-modal.js', ACCUA_FORMS_FILE ),
207 - array( 'jquery' ),
208 - ACCUA_FORMS_JS_VERSION,
209 - true
210 - );
167 + wp_enqueue_script( 'accua-form-fields', plugins_url( 'form-fields.js' , ACCUA_FORMS_FILE ), array( 'jquery-ui-sortable', 'jquery-ui-draggable', 'jquery-ui-droppable' ), ACCUA_FORMS_JS_VERSION);
168 + wp_enqueue_script( 'accua-form-settings', plugins_url('form-settings.js', ACCUA_FORMS_FILE), array('jquery'), ACCUA_FORMS_JS_VERSION);
169 +}
211 170
212 - wp_localize_script( 'accua-forms-deactivation-modal', 'accuaFormsDeactivation', array(
213 - 'ajaxUrl' => admin_url( 'admin-ajax.php' ),
214 - 'nonce' => wp_create_nonce( 'accua_forms_deactivation_cleanup' ),
215 - 'pluginBasename' => plugin_basename( ACCUA_FORMS_FILE ),
216 - 'i18n' => array(
217 - 'title' => __( 'What would you like to do with your Contact Forms data?', 'contact-forms' ),
218 - 'description' => __( 'You are about to deactivate Contact Forms. Choose what to do with your existing data:', 'contact-forms' ),
219 - 'deleteAll' => __( 'Delete all data', 'contact-forms' ),
220 - 'deleteAllDesc' => __( 'Permanently remove all forms, submissions, settings, and uploaded files. This cannot be undone.', 'contact-forms' ),
221 - 'anonymizeAll' => __( 'Anonymize all submissions', 'contact-forms' ),
222 - 'anonymizeAllDesc'=> __( 'Replace personal data with placeholders and set IPs to 0.0.0.0. Forms and settings will be kept. This cannot be undone.', 'contact-forms' ),
223 - 'skip' => __( 'Just deactivate', 'contact-forms' ),
224 - 'skipDesc' => __( 'Keep all data. You can reactivate the plugin later.', 'contact-forms' ),
225 - 'confirmDelete' => __( 'Are you sure? This will permanently delete ALL forms, submissions, settings, and uploaded files. This cannot be undone.', 'contact-forms' ),
226 - 'confirmAnonymize'=> __( 'Are you sure? This will anonymize ALL submissions, replacing personal data with placeholders. This cannot be undone.', 'contact-forms' ),
227 - 'processing' => __( 'Processing…', 'contact-forms' ),
228 - 'cancel' => __( 'Cancel', 'contact-forms' ),
229 - ),
230 - ) );
171 +function accua_forms_settings_page_head_scripts() {
172 + wp_enqueue_script('accua-jqColorPicker', plugins_url('/js/jqColorPicker.min.js', ACCUA_FORMS_FILE ), array( 'jquery' ), ACCUA_FORMS_JS_VERSION);
231 173 }
232 174
175 +function accua_forms_edit_page_head() {
176 +if (isset($_POST['accua-form-edit-action']) || (!isset($_GET['fid']))) {
177 + _accua_forms_form_edit_action();
178 + require_once('accua-forms-list-page.php');
179 + accua_forms_list_page_table(true);
180 +}
181 +
182 +?>
183 + <style type="text/css">
184 + .container > div {
185 + padding: 0px;
186 + margin-bottom: 6px;
187 + }
188 + .widget-liquid-right .widget, #wp_inactive_widgets .widget, .widget-liquid-right .sidebar-description, .widget-placeholder {
189 + width: 95%;
190 + }
191 + .column-submissions {
192 + text-align: right !important;
193 + }
194 + </style>
195 +<?php
196 +}
197 +
198 +add_action( 'wp_ajax_accua-form-fields-order' , 'accua_forms_form_fields_order');
233 199 function accua_forms_form_fields_order() {
234 200 if (!current_user_can('manage_options')){
235 201 wp_die( -1, 403 );
236 202 }
@@ -236,29 +202,28 @@
236 202 }
237 203 check_ajax_referer('edit_form', '_nonce_edit_form');
238 204
239 205 $post = stripslashes_deep($_POST);
206 + //update_option('accua_forms_form_fields_order_post', $post);
240 207
241 208 if (empty($post['sidebars'])) {
242 209 die('-1');
243 210 }
244 211
245 - // Save to draft instead of directly to database
246 - foreach ($post['sidebars'] as $sidebar_id => $order) {
247 - if (strpos($sidebar_id, 'cimatti-accua-fields-form-area-') !== 0){
212 + $forms_data = get_option('accua_forms_saved_forms', array());
213 +
214 + foreach ($post['sidebars'] as $fid => $order) {
215 + if (strpos($fid, 'cimatti-accua-fields-form-area-') !== 0){
248 216 die('-1');
249 217 }
250 - $fid = substr($sidebar_id, 31);
218 + $fid = substr($fid, 31);
251 219
252 - // Get draft data for this form
253 - $draft_data = _accua_forms_get_draft_data($fid);
254 -
255 - if (empty($draft_data['fields'])) {
220 + if (empty($forms_data[$fid]['fields'])) {
256 221 die('-1');
257 222 }
258 223
259 - $old_fields = $draft_data['fields'];
260 - unset($draft_data['fields']);
224 + $old_fields = $forms_data[$fid]['fields'];
225 + unset($forms_data[$fid]['fields']);
261 226 $new_fields = array();
262 227
263 228 $order = explode(',', $order);
264 229
@@ -272,19 +237,18 @@
272 237
273 238 if($old_fields){
274 239 $new_fields += $old_fields;
275 240 }
276 - $draft_data['fields'] = $new_fields;
241 + $forms_data[$fid]['fields'] = $new_fields;
242 + }
277 243
278 - // Save to draft (not to live database)
279 - _accua_forms_save_draft($fid, $draft_data);
280 - }
244 + update_option('accua_forms_saved_forms', $forms_data);
281 245
282 246 die('1');
283 247 }
284 248
285 249 add_action( 'wp_ajax_accua-save-form-field', 'accua_forms_save_form_field');
286 -/* azione dove vengono salvati i campi dei un form - saves to draft */
250 +/* azione dove vengono salvati i campi dei un form */
287 251 function accua_forms_save_form_field() {
288 252 if (!current_user_can('manage_options')){
289 253 wp_die( -1, 403 );
290 254 }
@@ -291,17 +255,17 @@
291 255 check_ajax_referer('edit_form', '_nonce_edit_form');
292 256
293 257 $post = stripslashes_deep($_POST);
294 258
259 + //update_option('accua_forms_save_form_field_post', $post);
260 +
261 + $forms_data = get_option('accua_forms_saved_forms', array());
295 262 $fid = $post['form-id'];
296 263 if (accua_forms_validate_form_id($fid) !== '') {
297 264 die('-1');
298 265 }
299 -
300 - // Get draft data instead of live data
301 - $draft_data = _accua_forms_get_draft_data($fid);
302 - if (empty($draft_data['fields'])) {
303 - $draft_data['fields'] = array();
266 + if (empty($forms_data[$fid]['fields'])) {
267 + $forms_data[$fid]['fields'] = array();
304 268 }
305 269
306 270 $avail_fields = get_option('accua_forms_avail_fields', array());
307 271 @ $wid = (string) $post['widget-id'];
@@ -314,8 +278,9 @@
314 278 die('-1');
315 279 }
316 280 }
317 281 if (empty($post['delete_widget'])) {
282 + //$istance_id = $post['multi_number'];
318 283 @ $ref = $post['id_base'];
319 284 if ($ref !== $check_ref) {
320 285 die('-1');
321 286 }
@@ -321,15 +286,15 @@
321 286 }
322 287 $required = !empty($post["form-field-{$wid}-required"]);
323 288 $widget_number = empty($post['multi_number']) ? (empty($post['widget_number']) ? '' : (int)$post['widget_number']) : (int)$post['multi_number'];
324 289
325 - if (isset($draft_data['fields'][$wid])) {
326 - $old_istance_data = $draft_data['fields'][$wid];
290 + if (isset($forms_data[$fid]['fields'][$wid])) {
291 + $old_istance_data = $forms_data[$fid]['fields'][$wid];
327 292 } else {
328 293 $old_istance_data = array();
329 294 }
330 295
331 - $draft_data['fields'][$wid] = array (
296 + $forms_data[$fid]['fields'][$wid] = array (
332 297 'version' => 2,
333 298 'istance_id' => $wid,
334 299 'widget_number' => $widget_number,
335 300 'ref' => $ref,
@@ -340,9 +305,9 @@
340 305 @ $label = (string) $post["form-field-{$wid}-label"];
341 306 if (!current_user_can('unfiltered_html')) {
342 307 $label = wp_kses($label, 'post');
343 308 }
344 - $draft_data['fields'][$wid]['label'] = $label;
309 + $forms_data[$fid]['fields'][$wid]['label'] = $label;
345 310 }
346 311
347 312 $is_file = false;
348 313 $is_date = false;
@@ -348,9 +313,9 @@
348 313 $is_date = false;
349 314 if (isset($avail_fields[$wid]['type'])) {
350 315 if ($avail_fields[$wid]['type'] == 'file') {
351 316 $is_file = true;
352 - } elseif ($avail_fields[$wid]['type'] == 'date') {
317 + } else if ($avail_fields[$wid]['type'] == 'date') {
353 318 $is_date = true;
354 319 }
355 320 }
356 321
@@ -357,114 +322,36 @@
357 322 if (!empty($post["form-field-{$wid}-override-default-value"])) {
358 323 @ $default_value = (string) $post["form-field-{$wid}-default-value"];
359 324 if ($is_date) {
360 325 $default_value = accua_forms_filter_date($default_value);
361 - } elseif (!current_user_can('unfiltered_html')) {
326 + } else if (!current_user_can('unfiltered_html')) {
362 327 //This is filtered in any case because field type can change
363 328 $default_value = wp_kses($default_value, 'post');
364 329 }
365 - $draft_data['fields'][$wid]['default_value'] = $default_value;
330 + $forms_data[$fid]['fields'][$wid]['default_value'] = $default_value;
366 331 }
367 332
368 333 if (!empty($post["form-field-{$wid}-override-allowed-values"])) {
369 334 @ $allowed_values = (string) $post["form-field-{$wid}-allowed-values"];
370 335 if ($is_file){
371 - $draft_data['fields'][$wid]['allowed_extensions'] = accua_forms_filter_extensions($allowed_values);
336 + $forms_data[$fid]['fields'][$wid]['allowed_extensions'] = accua_forms_filter_extensions($allowed_values);
372 337 } else {
373 - $draft_data['fields'][$wid]['allowed_values'] = $allowed_values;
338 + $forms_data[$fid]['fields'][$wid]['allowed_values'] = $allowed_values;
374 339 }
375 340 }
376 341 if (!empty($post["form-field-{$wid}-override-datemin-values"])) {
377 342 @ $mindate_values = (string) $post["form-field-{$wid}-min-of-date"];
378 - $draft_data['fields'][$wid]['min_date'] = accua_forms_filter_date($mindate_values);
343 + $forms_data[$fid]['fields'][$wid]['min_date'] = accua_forms_filter_date($mindate_values);
379 344 }
380 345 if (!empty($post["form-field-{$wid}-override-datemax-values"])) {
381 346 @ $maxdate_values = (string) $post["form-field-{$wid}-max-of-date"];
382 - $draft_data['fields'][$wid]['max_date'] = accua_forms_filter_date($maxdate_values);
347 + $forms_data[$fid]['fields'][$wid]['max_date'] = accua_forms_filter_date($maxdate_values);
383 348 }
384 -
385 - // Save post_type for post-select and post-multicheckbox fields
386 - if (isset($post["form-field-{$wid}-post-type"])) {
387 - @ $post_type_value = (string) $post["form-field-{$wid}-post-type"];
388 - // Validate post type
389 - $valid_post_types = get_post_types(array('public' => true));
390 - if (isset($valid_post_types[$post_type_value])) {
391 - $draft_data['fields'][$wid]['post_type'] = $post_type_value;
392 - }
393 - }
394 -
395 - // Save country_code for telephone fields (for libphonenumber validation)
396 - if (isset($post["form-field-{$wid}-country-code"])) {
397 - $country_code = strtoupper(sanitize_text_field($post["form-field-{$wid}-country-code"]));
398 - // Validate against the list of countries
399 - $valid_countries = accua_forms_get_countries();
400 - if (isset($valid_countries[$country_code])) {
401 - $draft_data['fields'][$wid]['country_code'] = $country_code;
402 - }
403 - }
404 -
405 - /**
406 - * Filter field instance data before saving to draft.
407 - *
408 - * @param array $field_instance The field instance data being saved.
409 - * @param string $widget_id The field widget ID.
410 - * @param array $post_data The raw POST data (already stripslashed).
411 - * @param array $field_def The field definition from avail_fields.
412 - */
413 - $draft_data['fields'][$wid] = apply_filters(
414 - 'accua_forms_save_field_data',
415 - $draft_data['fields'][$wid],
416 - $wid,
417 - $post,
418 - isset($avail_fields[$wid]) ? $avail_fields[$wid] : array()
419 - );
420 -
421 - // Save custom CSS class for the field wrapper
422 - if (isset($post["form-field-{$wid}-css-class"])) {
423 - $css_class_raw = sanitize_text_field($post["form-field-{$wid}-css-class"]);
424 - if ($css_class_raw !== '') {
425 - // Sanitize each class individually
426 - $classes = array_filter(array_map('sanitize_html_class', explode(' ', $css_class_raw)));
427 - $draft_data['fields'][$wid]['css_class'] = implode(' ', $classes);
428 - } else {
429 - $draft_data['fields'][$wid]['css_class'] = '';
430 - }
431 - }
432 -
433 - // Save custom CSS ID for the field wrapper
434 - if (isset($post["form-field-{$wid}-css-id"])) {
435 - $css_id_raw = sanitize_text_field($post["form-field-{$wid}-css-id"]);
436 - $draft_data['fields'][$wid]['css_id'] = sanitize_html_class($css_id_raw);
437 - }
438 -
439 - // Save fieldset style (fieldset-begin only)
440 - if (isset($post["form-field-{$wid}-fieldset-style"])) {
441 - $allowed_fieldset_styles = array(
442 - 'border-off-title-off', 'border-on-title-off',
443 - 'border-on-title-inline', 'border-on-title-outside',
444 - 'border-on-title-inside', 'border-off-title-on',
445 - );
446 - $fs = sanitize_text_field($post["form-field-{$wid}-fieldset-style"]);
447 - if (in_array($fs, $allowed_fieldset_styles, true)) {
448 - $draft_data['fields'][$wid]['fieldset_style'] = $fs;
449 - }
450 - }
451 -
452 - // Save custom required message override
453 - if (!empty($post["form-field-{$wid}-override-required-msg"])) {
454 - $draft_data['fields'][$wid]['custom_required_message'] = sanitize_text_field($post["form-field-{$wid}-custom-required-msg"]);
455 - }
456 -
457 - // Save custom format message override (email/phone)
458 - if (!empty($post["form-field-{$wid}-override-format-msg"])) {
459 - $draft_data['fields'][$wid]['custom_format_message'] = sanitize_text_field($post["form-field-{$wid}-custom-format-msg"]);
460 - }
461 349 } else {
462 - unset($draft_data['fields'][$wid]);
350 + unset($forms_data[$fid]['fields'][$wid]);
463 351 }
464 352
465 - // Save to draft (not to live database)
466 - _accua_forms_save_draft($fid, $draft_data);
353 + update_option('accua_forms_saved_forms', $forms_data);
467 354
468 355 die('1');
469 356 }
470 357
@@ -505,9 +392,9 @@
505 392 $cleaned_extensions = array();
506 393 $mimes = get_allowed_mime_types();
507 394 $extensions = explode("\n", $extensions);
508 395 foreach ($extensions as $extension) {
509 - $extension = strtolower( trim( ltrim( trim( $extension ), '.' ) ) );
396 + $extension = trim($extension);
510 397 if ($extension !== '') {
511 398 foreach ( $mimes as $ext_preg => $mime_match ) {
512 399 $ext_preg = '!^' . $ext_preg . '$!i';
513 400 if ( preg_match( $ext_preg, $extension ) ) {
@@ -531,14 +418,9 @@
531 418 //boolean
532 419 $form_settings[$k] = (bool) $v;
533 420 break;
534 421 case 'layout':
535 - // Only set if valid layout value, otherwise remove to use default
536 - if ($v === 'toplabel' || $v === 'inlinelabel' || $v === 'sidebyside') {
537 - $form_settings[$k] = $v;
538 - } else {
539 - unset($form_settings[$k]); // Reset to default
540 - }
422 + $form_settings[$k] = ($v === 'toplabel') ? 'toplabel' : 'sidebyside';
541 423 break;
542 424 case 'emails_from':
543 425 // single email
544 426 $form_settings[$k] = accua_forms_filter_email($v);
@@ -569,66 +451,8 @@
569 451 }
570 452 return $form_settings;
571 453 }
572 454
573 -/**
574 - * AJAX handler to restore default message values.
575 - *
576 - * Restores the default content for a specific message section:
577 - * - success_message: On-screen success message
578 - * - error_message: On-screen error message
579 - * - admin_emails: Admin notification email (subject + message only)
580 - * - confirmation_emails: Confirmation email (subject + message only)
581 - *
582 - * @since 2.0.0-beta.6
583 - */
584 -add_action('wp_ajax_accua_forms_restore_default_message', 'accua_forms_restore_default_message');
585 -function accua_forms_restore_default_message() {
586 - if (!current_user_can('manage_options')) {
587 - wp_send_json_error(array('message' => __('Permission denied.', 'contact-forms')), 403);
588 - }
589 -
590 - check_ajax_referer('accua_forms_restore_default', 'nonce');
591 -
592 - $message_type = isset($_POST['message_type']) ? sanitize_key($_POST['message_type']) : '';
593 -
594 - // Get default values
595 - $defaults = accua_forms_get_default_form_data();
596 -
597 - // Define which fields to restore for each message type
598 - $restore_map = array(
599 - 'success_message' => array('success_message'),
600 - 'error_message' => array('error_message'),
601 - 'admin_emails' => array('admin_emails_subject', 'admin_emails_message'),
602 - 'confirmation_emails' => array('confirmation_emails_subject', 'confirmation_emails_message'),
603 - );
604 -
605 - if (!isset($restore_map[$message_type])) {
606 - wp_send_json_error(array('message' => __('Invalid message type.', 'contact-forms')), 400);
607 - }
608 -
609 - // Get current form data
610 - $form_data = get_option('accua_forms_default_form_data', array());
611 - if (!is_array($form_data)) {
612 - $form_data = array();
613 - }
614 -
615 - // Restore the specified fields
616 - $restored_values = array();
617 - foreach ($restore_map[$message_type] as $field) {
618 - $form_data[$field] = $defaults[$field];
619 - $restored_values[$field] = $defaults[$field];
620 - }
621 -
622 - // Save updated form data
623 - update_option('accua_forms_default_form_data', $form_data);
624 -
625 - wp_send_json_success(array(
626 - 'message' => __('Default values restored successfully.', 'contact-forms'),
627 - 'values' => $restored_values,
628 - ));
629 -}
630 -
631 455 add_action( 'wp_ajax_accua-save-form-settings', 'accua_forms_save_form_settings');
632 456 function accua_forms_save_form_settings() {
633 457 if (!current_user_can('manage_options')){
634 458 wp_die( -1, 403 );
@@ -636,16 +460,14 @@
636 460 check_ajax_referer('edit_form', '_nonce_edit_form');
637 461
638 462 $post = stripslashes_deep($_POST);
639 463
464 + $forms_data = get_option('accua_forms_saved_forms', array());
640 465 $fid = $post['form-id'];
641 466 if (accua_forms_validate_form_id($fid) !== '') {
642 467 die('-1');
643 468 }
644 469
645 - // Get draft data instead of live data
646 - $draft_data = _accua_forms_get_draft_data($fid);
647 -
648 470 $settings = array(
649 471 'title',
650 472 'success_message',
651 473 'success_message_no_message',
@@ -660,9 +482,8 @@
660 482 'admin_emails_message_no_message',
661 483 'confirmation_emails_subject',
662 484 'confirmation_emails_message',
663 485 'confirmation_emails_message_no_message',
664 - 'gads_conversion_tracking_code',
665 486 //'use_ajax',
666 487
667 488 'layout',
668 489 'style_margin',
@@ -686,11 +507,8 @@
686 507 'style_submit_background_color',
687 508 'style_submit_padding',
688 509 'style_submit_color',
689 510 'style_submit_font_size',
690 - 'submission_retention_value',
691 - 'submission_retention_unit',
692 - 'submission_retention_mode',
693 511 );
694 512
695 513 // print_r($post);
696 514
@@ -698,328 +516,22 @@
698 516 foreach($settings as $i) {
699 517 if (isset($post[$i])) {
700 518 $new_form_settings[$i] = $post[$i];
701 519 }
702 - if (isset($draft_data[$i])) {
703 - unset($draft_data[$i]);
704 - }
520 + unset($forms_data[$fid][$i]);
705 521 }
706 522
707 - $draft_data += accua_forms_filter_settings($new_form_settings);
523 + $forms_data[$fid] += accua_forms_filter_settings($new_form_settings);
708 524
709 - $draft_data['use_ajax'] = !empty($post['use_ajax']);
710 - $draft_data['submission_retention_override'] = !empty($post['submission_retention_override']);
525 + $forms_data[$fid]['use_ajax'] = !empty($post['use_ajax']);
711 526
712 - // Save to draft (not to live database)
713 - _accua_forms_save_draft($fid, $draft_data);
527 + update_option('accua_forms_saved_forms', $forms_data);
714 528
715 - // Return JSON response for AJAX handler
716 - wp_send_json_success($draft_data);
717 -}
529 + //print_r($forms_data[$fid]);
718 530
719 -/**
720 - * AJAX handler to publish draft to live database.
721 - * Called when user clicks the Save button.
722 - */
723 -add_action( 'wp_ajax_accua-publish-form-draft', 'accua_forms_publish_form_draft');
724 -function accua_forms_publish_form_draft() {
725 - if (!current_user_can('manage_options')){
726 - wp_die( -1, 403 );
727 - }
728 - check_ajax_referer('edit_form', '_nonce_edit_form');
729 -
730 - $post = stripslashes_deep($_POST);
731 - $fid = isset($post['form-id']) ? $post['form-id'] : '';
732 -
733 - if (accua_forms_validate_form_id($fid) !== '') {
734 - wp_send_json_error(array('message' => __('Invalid form ID.', 'contact-forms')), 400);
735 - }
736 -
737 - // Publish the draft
738 - $result = _accua_forms_publish_draft($fid);
739 -
740 - if ($result) {
741 - wp_send_json_success(array('message' => __('Form saved successfully.', 'contact-forms')));
742 - } else {
743 - // Draft might not exist (nothing to publish) - this is OK for a new form
744 - // Check if form exists in database
745 - $forms_data = get_option('accua_forms_saved_forms', array());
746 - if (isset($forms_data[$fid])) {
747 - wp_send_json_success(array('message' => __('No changes to save.', 'contact-forms')));
748 - } else {
749 - wp_send_json_error(array('message' => __('Failed to save form.', 'contact-forms')), 500);
750 - }
751 - }
531 + die('');
752 532 }
753 533
754 -/**
755 - * AJAX handler to discard draft and reload from published data.
756 - * Called when user clicks "Discard changes".
757 - */
758 -add_action( 'wp_ajax_accua-discard-form-draft', 'accua_forms_discard_form_draft');
759 -function accua_forms_discard_form_draft() {
760 - if (!current_user_can('manage_options')){
761 - wp_die( -1, 403 );
762 - }
763 - check_ajax_referer('edit_form', '_nonce_edit_form');
764 -
765 - $post = stripslashes_deep($_POST);
766 - $fid = isset($post['form-id']) ? $post['form-id'] : '';
767 -
768 - if (accua_forms_validate_form_id($fid) !== '') {
769 - wp_send_json_error(array('message' => __('Invalid form ID.', 'contact-forms')), 400);
770 - }
771 -
772 - // Delete the draft
773 - _accua_forms_delete_draft($fid);
774 -
775 - wp_send_json_success(array('message' => __('Changes discarded.', 'contact-forms')));
776 -}
777 -
778 -/**
779 - * Filter an admin-configured post_status value for post fields down to the
780 - * statuses those fields may expose in a public dropdown: publish and private.
781 - *
782 - * Draft/pending/future content is never exposed, regardless of configuration.
783 - *
784 - * @since 2.2.27
785 - * @param string|array $post_status Comma-separated string or array of statuses.
786 - * @return array Allowed statuses (may be empty).
787 - */
788 -function accua_forms_filter_field_post_status($post_status) {
789 - if (!is_array($post_status)) {
790 - $post_status = explode(',', (string) $post_status);
791 - }
792 - $post_status = array_map('trim', $post_status);
793 - return array_values(array_intersect($post_status, array('publish', 'private')));
794 -}
795 -
796 -/**
797 - * Check whether an extra_args string received from the AJAX endpoint matches a
798 - * post-select / post-multicheckbox configuration actually stored by an admin,
799 - * for the post type the request resolved to.
800 - *
801 - * The extra_args string is echoed into the form markup and sent back by the
802 - * browser, so it is client-controlled. Privileged parameters (post_status=private)
803 - * are only honored when the exact string exists in a saved field configuration —
804 - * otherwise any visitor could craft a request that enumerates private post titles.
805 - * The post type is part of the match: a query string saved for one post type must
806 - * not unlock private posts of a different type (the field's post type lives in a
807 - * separate setting, so the string alone does not identify what it exposes).
808 - *
809 - * @since 2.2.27
810 - * @param string $extra_args Sanitized extra_args string from the request.
811 - * @param string $post_type Post type the request resolved to (after the
812 - * post_type override inside extra_args, if any).
813 - * @return bool True when a stored field configuration matches both.
814 - */
815 -function accua_forms_extra_args_is_saved_config($extra_args, $post_type) {
816 - $extra_args = trim($extra_args);
817 - if ($extra_args === '') {
818 - return false;
819 - }
820 -
821 - // Candidate configurations: array of (allowed_values, configured post type).
822 - $candidates = array();
823 - $avail_fields = get_option('accua_forms_avail_fields', array());
824 - foreach ($avail_fields as $field) {
825 - if (!empty($field['type']) && ($field['type'] === 'post-select' || $field['type'] === 'post-multicheckbox') && isset($field['allowed_values'])) {
826 - $candidates[] = array($field['allowed_values'], isset($field['post_type']) ? $field['post_type'] : 'page');
827 - }
828 - }
829 - $forms = get_option('accua_forms_saved_forms', array());
830 - foreach ($forms as $form) {
831 - if (empty($form['fields']) || !is_array($form['fields'])) {
832 - continue;
833 - }
834 - foreach ($form['fields'] as $inst) {
835 - if (!is_array($inst) || empty($inst['ref']) || !isset($avail_fields[$inst['ref']]['type'])) {
836 - continue;
837 - }
838 - $type = $avail_fields[$inst['ref']]['type'];
839 - if (($type === 'post-select' || $type === 'post-multicheckbox') && isset($inst['allowed_values'])) {
840 - $inst_post_type = isset($inst['post_type']) ? $inst['post_type']
841 - : (isset($avail_fields[$inst['ref']]['post_type']) ? $avail_fields[$inst['ref']]['post_type'] : 'page');
842 - $candidates[] = array($inst['allowed_values'], $inst_post_type);
843 - }
844 - }
845 - }
846 -
847 - foreach ($candidates as $candidate) {
848 - list($candidate_args, $candidate_post_type) = $candidate;
849 - if (trim(sanitize_text_field($candidate_args)) !== $extra_args) {
850 - continue;
851 - }
852 - // Resolve the candidate's effective post type the same way the request
853 - // does: a post_type override inside the string wins over the field setting.
854 - $candidate_extra = array();
855 - wp_parse_str($extra_args, $candidate_extra);
856 - if (!empty($candidate_extra['post_type'])) {
857 - $candidate_post_type = sanitize_text_field($candidate_extra['post_type']);
858 - }
859 - if ($candidate_post_type === $post_type) {
860 - return true;
861 - }
862 - }
863 - return false;
864 -}
865 -
866 -/**
867 - * AJAX handler to get posts for post-select fields with pagination.
868 - * Available to both logged-in and anonymous users (for frontend forms).
869 - *
870 - * @since 2.0.0-beta.29
871 - */
872 -add_action('wp_ajax_accua_forms_get_posts', 'accua_forms_ajax_get_posts');
873 -add_action('wp_ajax_nopriv_accua_forms_get_posts', 'accua_forms_ajax_get_posts');
874 -function accua_forms_ajax_get_posts() {
875 - // Verify nonce
876 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Nonce verification
877 - if (!isset($_REQUEST['_nonce']) || !wp_verify_nonce($_REQUEST['_nonce'], 'accua_forms_get_posts')) {
878 - wp_send_json_error(array('message' => __('Security check failed.', 'contact-forms')), 403);
879 - }
880 -
881 - // Sanitize inputs
882 - $post_type = isset($_REQUEST['post_type']) ? sanitize_text_field(wp_unslash($_REQUEST['post_type'])) : 'page';
883 - $search = isset($_REQUEST['search']) ? sanitize_text_field(wp_unslash($_REQUEST['search'])) : '';
884 - $page = isset($_REQUEST['page']) ? absint($_REQUEST['page']) : 1;
885 - $per_page = isset($_REQUEST['per_page']) ? min(absint($_REQUEST['per_page']), 100) : 50;
886 - $extra_args = isset($_REQUEST['extra_args']) ? sanitize_text_field(wp_unslash($_REQUEST['extra_args'])) : '';
887 - $selected = isset($_REQUEST['selected']) ? sanitize_text_field(wp_unslash($_REQUEST['selected'])) : '';
888 -
889 - // Validate post type
890 - $valid_post_types = get_post_types(array('public' => true));
891 - if (!isset($valid_post_types[$post_type])) {
892 - $post_type = 'page';
893 - }
894 -
895 - // Calculate offset
896 - $offset = ($page - 1) * $per_page;
897 -
898 - // Statuses the response may contain (extended below when the field
899 - // configuration explicitly requests private posts).
900 - $allowed_statuses = array('publish');
901 -
902 - // Build query arguments
903 - $args = array(
904 - 'post_type' => $post_type,
905 - 'number' => $per_page + 1, // Get one extra to check if there are more
906 - 'offset' => $offset,
907 - 's' => $search,
908 - );
909 -
910 - // Parse extra arguments (backward compatibility with allowed_values textarea)
911 - if (!empty($extra_args)) {
912 - // Parse the query string format
913 - $extra = array();
914 - wp_parse_str($extra_args, $extra);
915 -
916 - // Allow post_type override from extra_args (backward compatibility)
917 - if (isset($extra['post_type'])) {
918 - $override_post_type = sanitize_text_field($extra['post_type']);
919 - // Validate the overridden post type
920 - if (isset($valid_post_types[$override_post_type])) {
921 - $post_type = $override_post_type;
922 - $args['post_type'] = $post_type;
923 - }
924 - }
925 -
926 - // Merge only safe parameters
927 - $safe_params = array('meta_key', 'meta_value', 'authors', 'parent', 'child_of', 'exclude', 'include', 'sort_column', 'sort_order');
928 - foreach ($safe_params as $param) {
929 - if (isset($extra[$param])) {
930 - $args[$param] = $extra[$param];
931 - }
932 - }
933 -
934 - // post_status is a privileged parameter: only publish/private are ever
935 - // honored, and 'private' only when the extra_args string matches a field
936 - // configuration stored by an admin (or the user can read private posts,
937 - // e.g. the form editor preview). Otherwise a visitor could craft a request
938 - // that enumerates private post titles.
939 - if (!empty($extra['post_status'])) {
940 - $requested_statuses = accua_forms_filter_field_post_status($extra['post_status']);
941 - if (in_array('private', $requested_statuses, true)
942 - && !current_user_can('read_private_posts')
943 - && !accua_forms_extra_args_is_saved_config($extra_args, $post_type)) {
944 - $requested_statuses = array('publish');
945 - }
946 - if (!empty($requested_statuses)) {
947 - $args['post_status'] = $requested_statuses;
948 - $allowed_statuses = $requested_statuses;
949 - }
950 - }
951 - }
952 -
953 - // Get posts using WPML-compatible function
954 - $posts = accua_get_pages($args);
955 -
956 - // Check if there are more results
957 - $has_more = count($posts) > $per_page;
958 - if ($has_more) {
959 - array_pop($posts); // Remove the extra item
960 - }
961 -
962 - // Format results for the dropdown
963 - $results = array();
964 - foreach ($posts as $post) {
965 - $results[] = array(
966 - 'id' => $post->ID,
967 - 'text' => $post->post_title,
968 - );
969 - }
970 -
971 - // If this is the first page and we have a selected value, ensure it's in the list
972 - if ($page === 1 && !empty($selected) && is_numeric($selected)) {
973 - $selected_id = absint($selected);
974 - $found = false;
975 - foreach ($results as $result) {
976 - if ($result['id'] === $selected_id) {
977 - $found = true;
978 - break;
979 - }
980 - }
981 - // If selected post not in results, fetch it separately and prepend.
982 - // Only statuses the field is allowed to expose (publish, plus private when
983 - // explicitly configured): this endpoint is available to anonymous visitors,
984 - // so it must not disclose titles of other drafts/private/pending posts.
985 - if (!$found) {
986 - $selected_post = get_post($selected_id);
987 - if ($selected_post && $selected_post->post_type === $post_type && in_array($selected_post->post_status, $allowed_statuses, true)) {
988 - array_unshift($results, array(
989 - 'id' => $selected_post->ID,
990 - 'text' => $selected_post->post_title,
991 - ));
992 - }
993 - }
994 - }
995 -
996 - wp_send_json_success(array(
997 - 'results' => $results,
998 - 'more' => $has_more,
999 - 'page' => $page,
1000 - ));
1001 -}
1002 -
1003 -/**
1004 - * Get available public post types for the post-select field editor.
1005 - *
1006 - * @since 2.0.0-beta.29
1007 - * @return array Array of post type slug => label pairs.
1008 - */
1009 -function accua_forms_get_public_post_types() {
1010 - $post_types = get_post_types(array('public' => true), 'objects');
1011 - $options = array();
1012 - foreach ($post_types as $post_type) {
1013 - // Skip attachments
1014 - if ($post_type->name === 'attachment') {
1015 - continue;
1016 - }
1017 - $options[$post_type->name] = $post_type->labels->singular_name;
1018 - }
1019 - return $options;
1020 -}
1021 -
1022 534 function accua_forms_field_settings_form_counter() {
1023 535 static $i = 0;
1024 536 $i++;
1025 537 return $i;
@@ -1059,10 +571,8 @@
1059 571 $override_label = isset($istance_data['label']) ? 'checked="checked"' : '';
1060 572 $override_default_value = isset($istance_data['default_value']) ? 'checked="checked"' : '';
1061 573 $override_allowed_values = isset($istance_data['allowed_values']) ? 'checked="checked"' : '';
1062 574 $override_allowed_extensions = '';
1063 - $override_custom_required_msg = isset($istance_data['custom_required_message']) ? 'checked="checked"' : '';
1064 - $override_custom_format_msg = isset($istance_data['custom_format_message']) ? 'checked="checked"' : '';
1065 575
1066 576 if ($field_data['type'] == 'file') {
1067 577 if (isset($istance_data['version']) && $istance_data['version'] >= 2) {
1068 578 if (isset($istance_data['allowed_extensions'])) {
@@ -1089,8 +599,10 @@
1089 599
1090 600 if ($field_data['type'] == 'date') {
1091 601 $override_mindate_values = isset($istance_data['min_date']) ? 'checked="checked"' : '';
1092 602 $override_maxdate_values = isset($istance_data['max_date']) ? 'checked="checked"' : '';
603 + //$override_default_value = isset($istance_data['default_date_value']) ? 'checked="checked"' : '';
604 +
1093 605 $istance_data += array(
1094 606 'min_date' => $field_data['min_date'],
1095 607 'max_date' => $field_data['max_date'],
1096 608 'default_value' => $field_data['default_date_value'],
@@ -1106,22 +618,16 @@
1106 618 'default_value' => $field_data['default_value'],
1107 619 'allowed_values' => $field_data['allowed_values'],
1108 620 'allowed_extensions' => $field_data['allowed_extensions'],
1109 621 'required' => false,
1110 - 'post_type' => 'page', // Default post type for post-select fields
1111 - 'css_class' => '',
1112 - 'css_id' => '',
1113 - 'custom_required_message' => '',
1114 - 'custom_format_message' => '',
1115 - 'fieldset_style' => 'border-off-title-off',
1116 622 );
1117 623
1118 624 foreach ($istance_data as $key => $value) {
1119 - $istance_data[$key] = esc_attr($istance_data[$key]);
625 + $istance_data[$key] = htmlspecialchars($istance_data[$key], ENT_QUOTES);
1120 626 }
1121 627
1122 628 foreach ($field_data as $key => $value) {
1123 - $field_data[$key] = esc_attr($field_data[$key]);
629 + $field_data[$key] = htmlspecialchars($field_data[$key], ENT_QUOTES);
1124 630 }
1125 631
1126 632 $multi_number = '';
1127 633 $add_new = '';
@@ -1142,9 +648,9 @@
1142 648 $forceoverride_field = false;
1143 649 $add_new = $empty_istance ? 'single' : '';
1144 650 }
1145 651
1146 - $fid = esc_attr($fid);
652 + $fid = htmlspecialchars($fid, ENT_QUOTES);
1147 653 $testi_eot = array (
1148 654 'label' => __( 'Label', 'contact-forms'),
1149 655 'override' => __( 'override', 'contact-forms'),
1150 656 'default_value' => __( 'Default value', 'contact-forms'),
@@ -1155,10 +661,8 @@
1155 661 'allowed_extensions' => __( 'Allowed extensions', 'contact-forms'),
1156 662 'desc_all_ext' => __( 'Accepted file extensions. One per line, without dots.', 'contact-forms'),
1157 663 'required' => __( 'Required', 'contact-forms'),
1158 664 'custom_HTML_content' => __( 'Custom HTML content', 'contact-forms'),
1159 - 'refresh_preview' => __( 'Refresh Preview', 'contact-forms'),
1160 - 'add' => __( 'Add field', 'contact-forms'),
1161 665 'remove' => __( 'Remove', 'contact-forms'),
1162 666 'close' => __( 'Close', 'contact-forms'),
1163 667 'save' => __( 'Save', 'contact-forms'),
1164 668 'min-of-date' => __( 'Min date', 'contact-forms'),
@@ -1174,9 +678,8 @@
1174 678 $override_type = 'checkbox';
1175 679 $override_end = ')';
1176 680 }
1177 681
1178 - // phpcs:disable PluginCheck.CodeAnalysis.Heredoc.NotAllowed, WordPress.Security.EscapeOutput.HeredocOutputNotEscaped -- Heredoc used for HTML templates with pre-escaped variables
1179 682 $content = <<<EOT
1180 683 <p><label for="widget-{$istance_data['istance_id']}-label">{$testi_eot['label']}:</label>
1181 684 {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-label" value="1" {$override_label} />{$override_end}<br>
1182 685 <input type="text" value="{$istance_data['label']}" name="form-field-{$istance_data['istance_id']}-label" id="widget-{$istance_data['istance_id']}-label" class="widefat"></p>
@@ -1214,43 +717,8 @@
1214 717 <p><label for="widget-{$istance_data['istance_id']}-required">{$testi_eot['required']}:</label>
1215 718 <input type="checkbox" value="1" {$required_checked} name="form-field-{$istance_data['istance_id']}-required" id="widget-{$istance_data['istance_id']}-required"></p>
1216 719 EOT;
1217 720
1218 - // Custom required message override (checkbox + text input, same pattern as custom label)
1219 - $custom_required_msg_label = __( 'Custom required message', 'contact-forms');
1220 - // translators: %s is the field name/label
1221 - $custom_required_msg_desc = __( 'Overrides the default "required" error message. Use %s for the field name.', 'contact-forms');
1222 - $custom_required_msg = <<<EOT
1223 - <p><label for="widget-{$istance_data['istance_id']}-custom-required-msg">{$custom_required_msg_label}:</label>
1224 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-required-msg" value="1" {$override_custom_required_msg} />{$override_end}<br>
1225 - <input type="text" value="{$istance_data['custom_required_message']}" name="form-field-{$istance_data['istance_id']}-custom-required-msg" id="widget-{$istance_data['istance_id']}-custom-required-msg" class="widefat"><br>
1226 - <small>{$custom_required_msg_desc}</small></p>
1227 -EOT;
1228 -
1229 - // Custom format message override for email and telephone fields
1230 - $custom_format_msg = '';
1231 - if ($field_data['type'] === 'email' || $field_data['type'] === 'autoreply_email') {
1232 - $custom_format_msg_label = __( 'Custom invalid email message', 'contact-forms');
1233 - // translators: %s is the field name/label
1234 - $custom_format_msg_desc = __( 'Overrides the default email format error message. Use %s for the field name.', 'contact-forms');
1235 - $custom_format_msg = <<<EOT
1236 - <p><label for="widget-{$istance_data['istance_id']}-custom-format-msg">{$custom_format_msg_label}:</label>
1237 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-format-msg" value="1" {$override_custom_format_msg} />{$override_end}<br>
1238 - <input type="text" value="{$istance_data['custom_format_message']}" name="form-field-{$istance_data['istance_id']}-custom-format-msg" id="widget-{$istance_data['istance_id']}-custom-format-msg" class="widefat"><br>
1239 - <small>{$custom_format_msg_desc}</small></p>
1240 -EOT;
1241 - } elseif ($field_data['type'] === 'telephone') {
1242 - $custom_format_msg_label = __( 'Custom invalid phone message', 'contact-forms');
1243 - // translators: %s is the field name/label
1244 - $custom_format_msg_desc = __( 'Overrides the default phone format error message. Use %s for the field name.', 'contact-forms');
1245 - $custom_format_msg = <<<EOT
1246 - <p><label for="widget-{$istance_data['istance_id']}-custom-format-msg">{$custom_format_msg_label}:</label>
1247 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-format-msg" value="1" {$override_custom_format_msg} />{$override_end}<br>
1248 - <input type="text" value="{$istance_data['custom_format_message']}" name="form-field-{$istance_data['istance_id']}-custom-format-msg" id="widget-{$istance_data['istance_id']}-custom-format-msg" class="widefat"><br>
1249 - <small>{$custom_format_msg_desc}</small></p>
1250 -EOT;
1251 - }
1252 -
1253 721 if ($field_data['type'] == 'date'){
1254 722 $default_date_value = <<<EOT
1255 723 <p><label for="widget-{$istance_data['istance_id']}-default-value">{$testi_eot['default_value']}:</label>
1256 724 {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-default-value" value="1" {$override_default_value} />{$override_end}<br>
@@ -1267,76 +735,8 @@
1267 735 <input type="date" value="{$istance_data['max_date']}" name="form-field-{$istance_data['istance_id']}-max-of-date" id="widget-{$istance_data['istance_id']}-max-of-date"></p>
1268 736 EOT;
1269 737 }
1270 738
1271 - // Post type selector for post-select and post-multicheckbox fields
1272 - $post_type_selector = '';
1273 - if ($field_data['type'] === 'post-select' || $field_data['type'] === 'post-multicheckbox') {
1274 - $override_post_type = isset($istance_data['post_type']) && $istance_data['post_type'] !== 'page' ? 'checked="checked"' : '';
1275 - $post_types = accua_forms_get_public_post_types();
1276 - $post_type_options = '';
1277 - $current_post_type = esc_attr($istance_data['post_type']);
1278 - foreach ($post_types as $pt_slug => $pt_label) {
1279 - $selected = ($pt_slug === $current_post_type) ? ' selected="selected"' : '';
1280 - $post_type_options .= '<option value="' . esc_attr($pt_slug) . '"' . $selected . '>' . esc_html($pt_label) . '</option>';
1281 - }
1282 - $post_type_label = __('Post type', 'contact-forms');
1283 - $post_type_desc = __('Select which post type to show in the dropdown.', 'contact-forms');
1284 - $query_params_label = __('Additional query parameters', 'contact-forms');
1285 - // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_value -- This is example help text, not actual code.
1286 - $query_params_desc = __('Optional: Filter posts using query parameters (e.g., authors=admin or meta_key=featured&meta_value=1). Add post_status=publish,private to also include private posts (their titles become visible to all visitors of this form). Leave empty for all published posts of the selected type.', 'contact-forms');
1287 - $post_type_selector = <<<EOT
1288 - <p><label for="widget-{$istance_data['istance_id']}-post-type">{$post_type_label}:</label>
1289 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-post-type" value="1" {$override_post_type} />{$override_end}<br>
1290 - <select name="form-field-{$istance_data['istance_id']}-post-type" id="widget-{$istance_data['istance_id']}-post-type" class="widefat">{$post_type_options}</select><br />
1291 - {$post_type_desc}</p>
1292 - <p><label for="widget-{$istance_data['istance_id']}-allowed-values">{$query_params_label}:</label>
1293 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-allowed-values" value="1" {$override_allowed_values} />{$override_end}<br>
1294 - <textarea rows="3" cols="50" name="form-field-{$istance_data['istance_id']}-allowed-values" id="widget-{$istance_data['istance_id']}-allowed-values" class="widefat">{$istance_data['allowed_values']}</textarea><br />
1295 - {$query_params_desc}</p>
1296 -EOT;
1297 - }
1298 -
1299 - // Country selector for telephone fields (for libphonenumber validation)
1300 - $country_selector = '';
1301 - if ($field_data['type'] === 'telephone') {
1302 - $countries = accua_forms_get_countries();
1303 - $current_country = isset($istance_data['country_code']) ? esc_attr($istance_data['country_code']) : 'IT';
1304 - $override_country = isset($istance_data['country_code']) && $istance_data['country_code'] !== 'IT' ? 'checked="checked"' : '';
1305 - $country_options = '';
1306 - foreach ($countries as $code => $country_name) {
1307 - $selected = ($code === $current_country) ? ' selected="selected"' : '';
1308 - $country_options .= '<option value="' . esc_attr($code) . '"' . $selected . '>' . esc_html($country_name) . '</option>';
1309 - }
1310 - $country_label = __('Default country', 'contact-forms');
1311 - // translators: Help text for phone field country selector in form editor
1312 - $country_desc = __('For numbers without international prefix, validation assumes this country.', 'contact-forms');
1313 - $country_selector = <<<EOT
1314 - <p><label for="widget-{$istance_data['istance_id']}-country-code">{$country_label}:</label>
1315 - {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-country-code" value="1" {$override_country} />{$override_end}<br>
1316 - <select name="form-field-{$istance_data['istance_id']}-country-code" id="widget-{$istance_data['istance_id']}-country-code" class="widefat">{$country_options}</select><br />
1317 - {$country_desc}</p>
1318 -EOT;
1319 - }
1320 -
1321 - // CSS Class and CSS ID fields (universal, apply to all field types)
1322 - $css_class_label = __( 'CSS Class', 'contact-forms');
1323 - $css_id_label = __( 'CSS ID', 'contact-forms');
1324 - // translators: Help text for CSS Class field in form editor
1325 - $css_class_desc = __( 'Custom CSS class(es) for the field wrapper. Separate multiple classes with spaces.', 'contact-forms');
1326 - // translators: Help text for CSS ID field in form editor
1327 - $css_id_desc = __( 'Custom CSS ID for the field wrapper. Must be unique on the page.', 'contact-forms');
1328 - $css_class_field = <<<EOT
1329 - <p><label for="widget-{$istance_data['istance_id']}-css-class">{$css_class_label}:</label><br>
1330 - <input type="text" value="{$istance_data['css_class']}" name="form-field-{$istance_data['istance_id']}-css-class" id="widget-{$istance_data['istance_id']}-css-class" class="widefat"><br>
1331 - <small>{$css_class_desc}</small></p>
1332 -EOT;
1333 - $css_id_field = <<<EOT
1334 - <p><label for="widget-{$istance_data['istance_id']}-css-id">{$css_id_label}:</label><br>
1335 - <input type="text" value="{$istance_data['css_id']}" name="form-field-{$istance_data['istance_id']}-css-id" id="widget-{$istance_data['istance_id']}-css-id" class="widefat"><br>
1336 - <small>{$css_id_desc}</small></p>
1337 -EOT;
1338 -
1339 739 switch ($field_data['type']) {
1340 740 case 'textarea':
1341 741 $content .= <<<EOT
1342 742 <p><label for="widget-{$istance_data['istance_id']}-default-value">{$testi_eot['default_value']}:</label>
@@ -1342,9 +742,8 @@
1342 742 <p><label for="widget-{$istance_data['istance_id']}-default-value">{$testi_eot['default_value']}:</label>
1343 743 {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-default-value" value="1" {$override_default_value} />{$override_end}<br>
1344 744 <textarea rows="6" cols="50" name="form-field-{$istance_data['istance_id']}-default-value" id="widget-{$istance_data['istance_id']}-default-value" class="widefat">{$istance_data['default_value']}</textarea></p>
1345 745 $required
1346 - $custom_required_msg
1347 746 EOT;
1348 747 break;
1349 748 case 'hidden':
1350 749 $content = $default_value;
@@ -1349,58 +748,26 @@
1349 748 case 'hidden':
1350 749 $content = $default_value;
1351 750 break;
1352 751 case 'checkbox':
1353 - $content .= $default_value . $required . $custom_required_msg;
752 + $content .= $default_value . $required;
1354 753 break;
1355 754 case 'select':
1356 755 case 'radio':
1357 - $content .= $default_value . $allowed_values . $required . $custom_required_msg;
1358 - break;
1359 756 case 'post-select':
1360 - $content .= $default_value . $post_type_selector . $required . $custom_required_msg;
757 + $content .= $default_value . $allowed_values . $required;
1361 758 break;
1362 759 case 'multiselect':
1363 760 case 'multicheckbox':
1364 - $content .= $default_values . $allowed_values . $required . $custom_required_msg;
1365 - break;
1366 761 case 'post-multicheckbox':
1367 - $content .= $default_values . $post_type_selector . $required . $custom_required_msg;
762 + $content .= $default_values . $allowed_values . $required;
1368 763 break;
1369 764 case 'file':
1370 - $content .= $allowed_ext . $required . $custom_required_msg;
1371 - break;
765 + $content .= $allowed_ext . $required;
1372 766 case 'submit':
767 + case 'fieldset-begin':
1373 768 //just the label
1374 769 break;
1375 - case 'fieldset-begin':
1376 - $fs_label_text = __('Border and Title', 'contact-forms');
1377 - $gt_label_text = __('Group Title', 'contact-forms');
1378 - // translators: Help text under the Group Title field for fieldset groups in the form editor
1379 - $gt_desc_text = __('Section heading. Shown in the form when a title option is selected.', 'contact-forms');
1380 - $fs_opts_map = array(
1381 - 'border-off-title-off' => __('Border OFF | Title OFF', 'contact-forms'),
1382 - 'border-on-title-off' => __('Border ON | Title OFF', 'contact-forms'),
1383 - 'border-on-title-inline' => __('Border ON | Title ON (inline)', 'contact-forms'),
1384 - 'border-on-title-outside' => __('Border ON | Title ON (outside)', 'contact-forms'),
1385 - 'border-on-title-inside' => __('Border ON | Title ON (inside)', 'contact-forms'),
1386 - 'border-off-title-on' => __('Border OFF | Title ON', 'contact-forms'),
1387 - );
1388 - $fs_options_html = '';
1389 - foreach ($fs_opts_map as $opt_val => $opt_label) {
1390 - $opt_selected = ($istance_data['fieldset_style'] === $opt_val) ? ' selected="selected"' : '';
1391 - $fs_options_html .= '<option value="' . esc_attr($opt_val) . '"' . $opt_selected . '>' . esc_html($opt_label) . '</option>';
1392 - }
1393 - $content = <<<EOT
1394 - <p><label for="widget-{$istance_data['istance_id']}-label">{$gt_label_text}:</label><br>
1395 - <input type="hidden" name="form-field-{$istance_data['istance_id']}-override-label" value="1">
1396 - <input type="text" value="{$istance_data['label']}" name="form-field-{$istance_data['istance_id']}-label" id="widget-{$istance_data['istance_id']}-label" class="widefat"><br>
1397 - <small>{$gt_desc_text}</small></p>
1398 - <p><label for="widget-{$istance_data['istance_id']}-fieldset-style">{$fs_label_text}:</label><br>
1399 - <select name="form-field-{$istance_data['istance_id']}-fieldset-style" id="widget-{$istance_data['istance_id']}-fieldset-style" class="widefat accua-fieldset-style-select">{$fs_options_html}</select></p>
1400 -EOT;
1401 - $content .= $css_class_field . $css_id_field;
1402 - break;
1403 770 case 'fieldset-end':
1404 771 //Nothing!
1405 772 $content = '';
1406 773 break;
@@ -1408,52 +775,28 @@
1408 775 $content = <<<EOT
1409 776 <p><label for="widget-{$istance_data['istance_id']}-default-value">{$testi_eot['custom_HTML_content']}</label>
1410 777 {$override_begin}<input type="{$override_type}" name="form-field-{$istance_data['istance_id']}-override-default-value" value="1" {$override_default_value} />{$override_end}<br>
1411 778 <textarea rows="6" cols="50" name="form-field-{$istance_data['istance_id']}-default-value" id="widget-{$istance_data['istance_id']}-default-value" class="widefat">{$istance_data['default_value']}</textarea></p>
1412 - <p><a href="#" class="accua-refresh-preview">{$testi_eot['refresh_preview']}</a></p>
1413 779 EOT;
1414 780 break;
1415 781 case 'date':
1416 - $content .= $default_date_value . $min_date . $max_date . $required . $custom_required_msg;
782 + $content .= $default_date_value . $min_date . $max_date . $required;
1417 783 break;
1418 - case 'telephone':
1419 - $content .= $default_value . $country_selector . $required . $custom_required_msg . $custom_format_msg;
1420 - break;
1421 784 case 'email':
1422 785 case 'autoreply_email':
1423 - $content .= $default_value . $required . $custom_required_msg . $custom_format_msg;
1424 - break;
1425 786 case 'textfield':
1426 787 case 'colorpicker':
1427 788 case 'datepicker':
1428 789 case 'dateselect':
1429 790 default:
1430 - /**
1431 - * Action to render additional field settings in the form editor.
1432 - *
1433 - * @param string $field_type The field type identifier.
1434 - * @param array $field_data The field definition.
1435 - * @param array $istance_data The field instance data.
1436 - * @param string $content The current settings HTML (passed by reference via output buffering).
1437 - */
1438 - ob_start();
1439 - do_action( 'accua_forms_field_settings', $field_data['type'], $field_data, $istance_data );
1440 - $extra_settings = ob_get_clean();
1441 - $content .= $default_value . $extra_settings . $required . $custom_required_msg;
791 + $content .= $default_value . $required;
1442 792 break;
1443 793 }
1444 -
1445 - // Append CSS Class and CSS ID fields to all types except fieldset-end (which has no settings)
1446 - if ($field_data['type'] !== 'fieldset-end' && $field_data['type'] !== 'fieldset-begin') {
1447 - $content .= $css_class_field . $css_id_field;
1448 - }
1449 -
1450 794 $adminurl = admin_url();
1451 795
1452 796 return <<<EOT
1453 -<div class="widget ui-draggable" id="widget-{$i}_{$istance_data['istance_id']}" data-field-type="{$field_data['type']}" $hidden> <div class="widget-top">
797 +<div class="widget ui-draggable" id="widget-{$i}_{$istance_data['istance_id']}" $hidden> <div class="widget-top">
1454 798 <div class="widget-title-action">
1455 - <a href="#add-field" class="widget-add-action hide-if-no-js" title="{$testi_eot['add']}" aria-label="{$testi_eot['add']}"></a>
1456 799 <a href="#available-widgets" class="widget-action hide-if-no-js"></a>
1457 800 </div>
1458 801 <div class="widget-title"><h4>{$field_data['name']}<span class="in-widget-title"></span></h4></div>
1459 802 </div>
@@ -1477,9 +820,10 @@
1477 820 <a href="#remove" class="widget-control-remove delete">{$testi_eot['remove']}</a> |
1478 821 <a href="#close" class="widget-control-close">{$testi_eot['close']}</a>
1479 822 </div>
1480 823 <div class="alignright">
1481 - <input type="submit" value="{$testi_eot['save']}" class="button button-primary widget-control-save accua-field-save-btn" id="widget-{$istance_data['istance_id']}-savewidget" name="savewidget">
824 + <img alt="" title="" class="ajax-feedback" src="{$adminurl}images/wpspin_light.gif">
825 + <input type="submit" value="{$testi_eot['save']}" class="button-primary widget-control-save" id="widget-{$istance_data['istance_id']}-savewidget" name="savewidget">
1482 826 </div>
1483 827 <br class="clear">
1484 828 </div>
1485 829 </form>
@@ -1490,17 +834,1847 @@
1490 834 </div>-->
1491 835 </div>
1492 836
1493 837 EOT;
1494 - // phpcs:enable PluginCheck.CodeAnalysis.Heredoc.NotAllowed, WordPress.Security.EscapeOutput.HeredocOutputNotEscaped
1495 838 }
1496 839
840 +function accua_forms_add_page($message='') {
841 + $forms_data = get_option('accua_forms_saved_forms', array());
842 + $trash_data = get_option('accua_forms_trash_forms', array());
843 + if (!empty($_GET['fid'])) {
844 + $fid = htmlspecialchars(stripslashes($_GET['fid']), ENT_QUOTES);
845 + } else {
846 + if ($message === '') {
847 + $fid = 1 + ((int) get_option('accua_forms_lastid', 0));
848 + while (isset($forms_data[$fid]) || isset($trash_data[$fid])) {
849 + $fid++;
850 + }
851 + update_option('accua_forms_lastid', $fid);
852 + $message = _accua_forms_test_clonefrom($fid);
853 + if ($message === '') {
854 + return accua_forms_edit_page($fid);
855 + }
856 + } else {
857 + $fid = '';
858 + }
859 + }
860 + if (!empty($_GET['clonefrom'])) {
861 + check_admin_referer('clone_posts');
862 + $clonefrom = stripslashes($_GET['clonefrom']);
863 + } else {
864 + $clonefrom = '';
865 + }
866 +?>
1497 867
1498 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function, underscore prefix indicates private
868 +<div id="accua_forms_add_page" class="accua_forms_admin_page wrap">
869 +<h2><?php _e( 'Create a form', 'contact-forms'); ?> </h2>
870 +<?php if ($message !== '') {
871 + echo "<div style='border:1px solid; padding: 10px;'>$message</div>";
872 +} ?>
873 +<form action="admin.php" method="GET">
874 +<?php wp_nonce_field('edit_posts', '_wpnonce', false, true) ?>
875 +<input type="hidden" name="page" value="accua_forms_list" />
876 +<p>Form id: <input type="text" name="fid" value="<?php echo $fid; ?>" /></p>
877 +<?php
878 + if ($forms_data) {
879 + echo '<p><select name="clonefrom">
880 + <option value="">'.__( 'Empty form', 'contact-forms').'</option>
881 + <optgroup label="'.__( 'Clone form:', 'contact-forms').'">';
882 + foreach ($forms_data as $i => $formdata) {
883 + $sel = ($i == $clonefrom) ? " selected='selected'" : '';
884 + $i = htmlspecialchars($i, ENT_QUOTES);
885 + if (isset($formdata['title']) && ('' !== trim($formdata['title']))) {
886 + $formtitle = htmlspecialchars($formdata['title']);
887 + } else {
888 + $formtitle = $i;
889 + }
890 + echo "<option value='$i'$sel>$formtitle</option>\n";
891 + }
892 + echo '</optgroup></select></p>';
893 + }
894 +?>
895 +<p><input type="submit" value="<?php _e( 'Create', 'contact-forms'); ?>" /></p>
896 +</form>
897 +</div>
898 +<?php
899 +}
900 +
901 +function _accua_forms_test_clonefrom($fid){
902 + $error = '';
903 + if (isset($_GET['clonefrom'])&&$_GET['clonefrom']!=='') {
904 + $clonefrom = stripslashes($_GET['clonefrom']);
905 + $forms_data = get_option('accua_forms_saved_forms', array());
906 + if (isset($forms_data[$fid])){
907 + $error .= "<p>".__( 'Form already exists', 'contact-forms')."</p>";
908 + } else if (empty($forms_data[$clonefrom])) {
909 + $error .= "<p>".__( 'Source form doesn\'t exists.', 'contact-forms')."</p>";
910 + } else {
911 + $forms_data[$fid] = $forms_data[$clonefrom];
912 + if (!isset($forms_data[$fid]['title'])) {
913 + $forms_data[$fid]['title'] = $clonefrom ." ".__( 'clone', 'contact-forms');
914 + } else {
915 + $forms_data[$fid]['title'] .= " ". __( 'clone', 'contact-forms');
916 + }
917 + update_option('accua_forms_saved_forms', $forms_data);
918 + }
919 + }
920 + return $error;
921 +}
922 +
923 +function _accua_forms_form_edit_action() {
924 + static $message = null;
925 + if ($message === null) {
926 + $message = '';
927 + if (isset($_POST['accua-form-edit-action'])){
928 + $post = stripslashes_deep($_POST);
929 + switch ($post['accua-form-edit-action']) {
930 + case 'delete':
931 + $fid = $post['form-id'];
932 + check_admin_referer('contact-forms-delete_'.$fid);
933 + $forms_data = get_option('accua_forms_saved_forms', array());
934 + unset($forms_data[$fid]);
935 + update_option('accua_forms_saved_forms', $forms_data);
936 + $fid = htmlspecialchars($fid);
937 + $message .= sprintf( __( 'Form "%s" deleted','contact-forms' ), $fid );
938 + break;
939 + }
940 + }
941 + }
942 + return $message;
943 +}
944 +
945 +function accua_forms_validate_form_id($fid) {
946 + $error = '';
947 + if (!preg_match('/^[a-z0-9_-]+$/i', $fid)) {
948 + $error .= "<p>".__( 'Only letters, numbers, hyphen and underscores allowed in form identificative name', 'contact-forms')."</p>";
949 + }
950 + if (substr($fid,0,2) == '__') {
951 + $error .= "<p>".__( 'The identificative name can\'t start with two underscores (__)', 'contact-forms')."</p>";
952 + }
953 + if (strlen($fid) > 70) {
954 + $error .= "<p>".__( 'You cannot use more than 70 characters for the identificative name', 'contact-forms')."</p>";
955 + }
956 + return $error;
957 +}
958 +
959 +function accua_forms_list_page() {
960 + $message = '';
961 + if (isset($_POST['accua-form-edit-action'])){
962 + $message = _accua_forms_form_edit_action();
963 + } else if (isset($_GET['fid'])) {
964 + check_admin_referer('edit_posts');
965 + $fid = stripslashes($_GET['fid']);
966 + $error = accua_forms_validate_form_id($fid);
967 + if ($error === '' && (isset($_GET['clonefrom'])&&$_GET['clonefrom']!=='')) {
968 + $error .= _accua_forms_test_clonefrom($fid);
969 + }
970 + if ($error === '') {
971 + return accua_forms_edit_page($fid);
972 + } else {
973 + return accua_forms_add_page($error);
974 + }
975 + }
976 +?>
977 +<div id="accua_forms_list_page" class="accua_forms_admin_page wrap">
978 +<?php if ($message !== '') {
979 + echo "<div style='border:1px solid; padding: 10px;'>$message</div>";
980 +} ?>
981 +<h2><img src="<?php echo ACCUA_FORMS_DIR_URL.'img/cimatti-icon-20.png'; ?>"/> <?php _e( 'Contact Forms', 'contact-forms'); ?>
982 + <a class="add-new-h2" href="<?php echo get_admin_url(); ?>admin.php?page=accua_forms_add"><?php _e('Add New','contact-forms'); ?></a>
983 +</h2>
984 +<div ><?php
985 + echo strtr(__( 'Use the turquoise blue %img_c button in the TinyMCE editor to include the forms in posts, pages or other content types (shortcode and php functions also available)', 'contact-forms'),
986 + array('%img_c'=>'<img alt="C" src="' . plugins_url('img/cimatti-icon-16.png', ACCUA_FORMS_FILE ) . '" />')
987 + );
988 +?></div>
989 +<?php
990 +accua_forms_list_page_table();
991 +?>
992 +</div>
993 +<?php
994 +}
995 +
996 +function accua_forms_edit_page($fid) {
997 + wp_enqueue_script('jquery-ui-tabs','','','',true);
998 + wp_enqueue_script('contact_forms_tabs', plugins_url('accua_tabs.js', ACCUA_FORMS_FILE ), array( 'jquery' ), ACCUA_FORMS_JS_VERSION);
999 +
1000 + if (!class_exists('AccuaFormsHelp')) {
1001 + require_once('accua-forms-help.php');
1002 + }
1003 + $accuaHelp = AccuaFormsHelp::getInstance();
1004 + /*
1005 + $avail_fields = array(
1006 + 'first_name' => array (
1007 + 'id' => "first_name",
1008 + 'name' => "First Name",
1009 + 'type' => "textfield",
1010 + 'description' => 'This is the first name',
1011 + ),
1012 + 'last_name' => array (
1013 + 'id' => "last_name",
1014 + 'name' => "Last Name",
1015 + 'type' => "textfield",
1016 + 'description' => 'This is the last name',
1017 + ),
1018 + 'email' => array (
1019 + 'id' => "email",
1020 + 'name' => "Email",
1021 + 'type' => "email",
1022 + 'description' => 'This is the email',
1023 + ),
1024 + );
1025 + */
1026 +
1027 + $avail_fields = get_option('accua_forms_avail_fields', array());
1028 + $default_form_data = get_option('accua_forms_default_form_data',array());
1029 +
1030 +
1031 +
1032 + $form_data = _accua_forms_get_form_data($fid, true, !empty($_GET['restore']));
1033 + $form_overrided_data = $form_data['_overrided'];
1034 +
1035 + $fid_esc = htmlspecialchars($fid, ENT_QUOTES);
1036 +
1037 + $adminurl = admin_url();
1038 +
1039 + global $wp_version;
1040 + if (version_compare($wp_version, '4') >= 0) {
1041 +?>
1042 +<style>
1043 +#widgets-right .accua-form-widget-scroll-wrapper .widget.ui-draggable {
1044 + height: auto !important;
1045 +}
1046 +</style>
1047 +<?php
1048 + }
1049 +
1050 +?>
1051 +<div id="accua_forms_edit_page" class="accua_forms_admin_page wrap">
1052 +<h2><img src="<?php echo ACCUA_FORMS_DIR_URL.'img/cimatti-icon-20.png'; ?>"/> <?php _e('Contact Forms - Edit Form', 'contact-forms'); ?></h2>
1053 +<div class="accua_form_save_settings_status"></div>
1054 +<?php wp_nonce_field('edit_form', '_nonce_edit_form'); ?>
1055 +<div id="titlediv"><br />
1056 + <label id="title-prompt-text" class="screen-reader-text" for="title"><?php _e( 'Enter title here', 'contact-forms'); ?></label>
1057 + <input id="title" type="text" autocomplete="off" value="<?php echo htmlspecialchars($form_data['title'], ENT_QUOTES) ?>" size="30" name="post_title">
1058 + <script type="text/javascript">
1059 + jQuery(function($){
1060 + if ( jQuery('#titlediv #title').val() == '' )
1061 + jQuery('#title-prompt-text').removeClass('screen-reader-text');
1062 +
1063 + jQuery('#titlediv #title').focus(function() {
1064 + jQuery('#title-prompt-text').addClass('screen-reader-text');
1065 + });
1066 + jQuery('#titlediv #title').blur(function() {
1067 + if ( jQuery('#titlediv #title').val() == '' )
1068 + jQuery('#title-prompt-text').removeClass('screen-reader-text');
1069 + });
1070 + });
1071 + </script>
1072 +</div>
1073 + <div id="accua_tabs">
1074 + <div id="save_settings_top" class="accua_forms_save_settings_top">
1075 + <form id="delete_form" action="admin.php?page=accua_forms_list" method="POST" onsubmit="return confirm(<?php print htmlspecialchars(_accua_forms_json_encode(__('Do you really want to delete this form?', 'contact-forms')), ENT_QUOTES); ?>);">
1076 + <input type="hidden" name="accua-form-edit-action" value="delete" />
1077 + <input type="hidden" name="form-id" value="<?php echo $fid_esc; ?>" />
1078 + <input type="submit" value="<?php _e( 'Delete this form', 'contact-forms'); ?>" />
1079 + <?php wp_nonce_field( 'contact-forms-delete_'.$fid ); ?>
1080 + </form>
1081 + <?php /*<input class="button button-primary button-large accua_form_save_settings_button" id="accua_form_save_settings" type="button" value="<?php echo htmlspecialchars(__( 'Save settings', 'contact-forms'), ENT_QUOTES); ?>" /> */ ?>
1082 + </div>
1083 + <ul id="ul_accua_tabs">
1084 + <li class="tabs"><a href="#accua_tab_fields"><?php _e( 'Fields', 'contact-forms'); ?></a></li>
1085 + <li class="tabs"><a href="#accua_tab_messages"><?php _e( 'Messages', 'contact-forms'); ?></a></li>
1086 + <?php /*<li class="tabs"><a href="#accua_tab_preview"><?php _e( 'Preview/Test', 'contact-forms'); ?></a></li> */ ?>
1087 + </ul>
1088 + <div id="accua_tab_fields" class="content_tab">
1089 + <div style="width:50%; float:left;background: #f4f4f4;">
1090 + <div style="padding: 20px;">
1091 + <input class="button button-primary button-large accua_form_save_settings_button" id="accua_form_save_settings_inside" type="button" value="<?php echo htmlspecialchars(__( 'Save', 'contact-forms'), ENT_QUOTES); ?>" />
1092 + <div id="accua_tabs2">
1093 + <ul>
1094 + <li class="tabs"><a href="#accua_tab_fields2"><?php _e( 'Fields', 'contact-forms'); ?></a></li>
1095 + <li class="tabs"><a href="#accua_tab_customise"><?php _e( 'Appearance', 'contact-forms'); ?></a></li>
1096 + </ul>
1097 + <div id="accua_tab_fields2">
1098 + <h2><?php _e( 'Drag & Drop Form Fields', 'contact-forms'); ?></h2>
1099 + <?php /*<a href="admin.php?page=accua_forms_fields" target="_blank"><strong><?php _e( 'Create new fields here', 'contact-forms'); ?></strong></a></p> */ ?>
1100 + <div style="width:30%; float:left;">
1101 + <!-- Begin available fields -->
1102 +
1103 + <div class="widget-liquid-left" style="margin-right:0">
1104 + <!-- <div id="widgets-left"> -->
1105 + <div id="widgets-left" style="margin-right:5px;">
1106 + <div id="available-widgets" class="widgets-holder-wrap">
1107 + <div class="widget-holder">
1108 + <div id="widget-list">
1109 + <!-- begin fields list -->
1110 +
1111 + <?php
1112 +
1113 + //This block must be executed before the output of available fields so accua_forms_field_text_settings_form() can initialize $html_multi_number for further html and fieldset fields
1114 + $form_fields_html = '';
1115 + foreach ($form_data['fields'] as $field) {
1116 + if (empty($avail_fields[$field['ref']])) {
1117 + $ref = array();
1118 + if (!empty($field['ref'])) {
1119 + if ($field['ref'] == '__fieldset-begin') {
1120 + $ref = array(
1121 + 'id' => '__fieldset-begin',
1122 + 'name' => __('Fieldset begin', 'contact-forms'),
1123 + 'type' => 'fieldset-begin',
1124 + 'description' => '',
1125 + );
1126 + } else if ($field['ref'] == '__fieldset-end') {
1127 + $ref = array(
1128 + 'id' => '__fieldset-end',
1129 + 'name' => __('Fieldset end', 'contact-forms'),
1130 + 'type' => 'fieldset-end',
1131 + 'description' => '',
1132 + );
1133 + }
1134 + }
1135 + } else {
1136 + $ref = $avail_fields[$field['ref']];
1137 + }
1138 +
1139 + //print_r($ref);
1140 + $form_fields_html .= accua_forms_field_text_settings_form($fid, $ref, $field);
1141 + }
1142 +
1143 +
1144 + foreach ($avail_fields as $avail_field) {
1145 + $hidden = (empty($form_data['fields'][$avail_field['id']])) ? false : 'hidden';
1146 + echo accua_forms_field_text_settings_form($fid, $avail_field, $hidden);
1147 + }
1148 + //Custom HTML field
1149 + echo accua_forms_field_text_settings_form($fid);
1150 + //Fieldset begin
1151 + echo accua_forms_field_text_settings_form($fid, array(
1152 + 'id' => '__fieldset-begin',
1153 + 'name' => __( 'Fieldset begin', 'contact-forms'),
1154 + 'type' => 'fieldset-begin',
1155 + 'description' => __('You can use this field multiple times.', 'contact-forms'),
1156 + 'default_value' => '',
1157 + 'allowed_values' => '',
1158 + ));
1159 + //Fieldset end
1160 + echo accua_forms_field_text_settings_form($fid, array(
1161 + 'id' => '__fieldset-end',
1162 + 'name' => __( 'Fieldset end', 'contact-forms'),
1163 + 'type' => 'fieldset-end',
1164 + 'description' => __('You can use this field multiple times.', 'contact-forms'),
1165 + 'default_value' => '',
1166 + 'allowed_values' => '',
1167 + ));
1168 + ?>
1169 +
1170 + <!-- end fields list -->
1171 + </div>
1172 +
1173 + <br class='clear' />
1174 + </div>
1175 + <br class="clear" />
1176 + </div>
1177 +
1178 + </div>
1179 + </div>
1180 + <!-- End available fields -->
1181 + </div>
1182 +
1183 + <div style="width:70%; float:left;" class="container">
1184 + <!--
1185 + <h3>Form Fields</h3>
1186 + <div id="form_fields_container">
1187 + </div>
1188 + -->
1189 +
1190 + <div class="widget-liquid-right" style="width:100%">
1191 + <div id="widgets-right" style="width:100%">
1192 + <div class="widgets-holder-wrap dashed">
1193 + <div class="sidebar-name">
1194 + <div class="sidebar-name-arrow"><br></div>
1195 + <h3><?php _e( 'Drop fields here', 'contact-forms'); ?> <span><img alt="" title="" class="ajax-feedback" src="<?php echo $adminurl;?>images/wpspin_light.gif"></span></h3>
1196 + </div>
1197 + <div class="widgets-sortables ui-sortable" id="cimatti-accua-fields-form-area-<?php echo $fid_esc ?>">
1198 + <?php echo $form_fields_html; ?>
1199 + </div>
1200 + </div>
1201 + </div>
1202 + </div>
1203 +
1204 + </div>
1205 + </div>
1206 + <div id="accua_tab_customise">
1207 + <div style="width: 48%; float:left;">
1208 + <h3><?php _e( 'General', 'contact-forms'); ?></h3>
1209 + <p id="accua_form_use_ajax"><input class="accua_form_value" type="checkbox" value="1" <?php if (!empty($form_data['use_ajax'])) {echo 'checked="checked" ';} ?>/><?php _e('Do not reload the page on form submission', 'contact-forms'); ?></p>
1210 +
1211 + <p id="accua_form_layout"><?php _e( 'Labels', 'contact-forms'); ?> <select name="layout" class="accua_form_value">
1212 + <option value="" <?php if (isset($form_overrided_data['layout'])) { echo 'selected="selected"'; } ?>>default (<?php if($default_form_data['layout']=='sidebyside') _e( 'Labels on the left of the fields', 'contact-forms'); else _e( 'Labels on top of the fields', 'contact-forms'); ?>)</option><option value="sidebyside" <?php if ((isset($form_overrided_data['layout'])) && ($form_data['layout'] == 'sidebyside')) { echo 'selected="selected"'; } ?>><?php _e( 'Labels on the left of the fields', 'contact-forms'); ?></option><option value="toplabel" <?php if ((isset($form_overrided_data['layout'])) && ($form_data['layout'] == 'toplabel')) { echo 'selected="selected"'; } ?>><?php _e( 'Labels on top of the fields', 'contact-forms'); ?></option></select>
1213 + </p>
1214 +
1215 + <div id="accua_form_style_margin" class="label_input" class="label_container">
1216 + <input name="accua_form_style_margin" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_margin'])) {echo 'checked="checked" ';} ?>/><strong><?php _e( 'Margin', 'contact-forms'); ?></strong>
1217 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_margin']); ?></div>
1218 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_margin'], ENT_QUOTES) ?>" />
1219 +
1220 + </div>
1221 +
1222 + <div class="label_input">
1223 + <div id="accua_form_style_border_color" class="label_container">
1224 + <input name="accua_form_style_border_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_border_color'])) {echo 'checked="checked" ';} ?>/><strong><?php _e( 'Border color', 'contact-forms'); ?></strong>
1225 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_border_color']); ?></div>
1226 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_color'], ENT_QUOTES) ?>" />
1227 + </div>
1228 + <div id="accua_form_style_border_width" class="label_container">
1229 + <input name="accua_form_style_border_width" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_border_width'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Width', 'contact-forms'); ?>
1230 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_border_width']); ?></div>
1231 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_width'], ENT_QUOTES) ?>" />
1232 + </div>
1233 + <div id="accua_form_style_border_radius" class="label_container">
1234 + <input name="accua_form_style_border_radius" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_border_radius'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Radius', 'contact-forms'); ?>
1235 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_border_radius']); ?></div>
1236 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_radius'], ENT_QUOTES) ?>" />
1237 + </div>
1238 + </div>
1239 +
1240 + <div class="label_input">
1241 + <div id="accua_form_style_background_color" class="label_container">
1242 + <input name="accua_form_style_background_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_background_color'])) {echo 'checked="checked" ';} ?>/><strong><?php _e( 'Background', 'contact-forms'); ?></strong>
1243 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_background_color']); ?></div>
1244 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_background_color'], ENT_QUOTES) ?>" />
1245 + </div>
1246 +
1247 + <div id="accua_form_style_padding" class="label_container">
1248 + <input name="accua_form_style_padding" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_padding'])) {echo 'checked="checked" ';} ?>/><strong><?php _e( 'Padding', 'contact-forms'); ?></strong>
1249 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_padding']); ?></div>
1250 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_padding'], ENT_QUOTES) ?>" />
1251 + </div>
1252 + </div>
1253 + <div class="label_input">
1254 + <div id="accua_form_style_color" class="label_container">
1255 + <input name="accua_form_style_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_color'])) {echo 'checked="checked" ';} ?>/><strong><?php _e( 'Font', 'contact-forms'); ?></strong>
1256 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_color']); ?></div>
1257 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_color'], ENT_QUOTES) ?>" />
1258 + </div>
1259 +
1260 + <div id="accua_form_style_font_size" class="label_container">
1261 + <input name="accua_form_style_font_size" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_font_size'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Size', 'contact-forms'); ?>
1262 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_font_size']); ?></div>
1263 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_font_size'], ENT_QUOTES) ?>" />
1264 + </div>
1265 + </div>
1266 + </div>
1267 + <div style="width: 48%; float:left;">
1268 +
1269 + <h3><?php _e( 'Fields', 'contact-forms'); ?></h3>
1270 +
1271 + <div id="accua_form_style_field_spacing" class="label_input">
1272 + <input name="accua_form_style_field_spacing" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_spacing'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Spacing', 'contact-forms'); ?>
1273 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_spacing']); ?></div>
1274 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_spacing'], ENT_QUOTES) ?>" />
1275 + </div>
1276 +
1277 + <div id="accua_form_style_field_border_color" class="label_input">
1278 + <input name="accua_form_style_field_border_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_border_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Border color', 'contact-forms'); ?>
1279 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_border_color']); ?></div>
1280 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_color'], ENT_QUOTES) ?>" />
1281 + </div>
1282 +
1283 + <div id="accua_form_style_field_border_width" class="label_input">
1284 + <input name="accua_form_style_field_border_width" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_border_width'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Border width', 'contact-forms'); ?>
1285 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_border_width']); ?></div>
1286 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_width'], ENT_QUOTES) ?>" />
1287 + </div>
1288 +
1289 + <div id="accua_form_style_field_border_radius" class="label_input">
1290 + <input name="accua_form_style_field_border_radius" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_border_radius'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Rounded corner radius', 'contact-forms'); ?>
1291 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_border_radius']); ?></div>
1292 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_radius'], ENT_QUOTES) ?>" />
1293 + </div>
1294 +
1295 + <div id="accua_form_style_field_background_color" class="label_input">
1296 + <input name="accua_form_style_field_background_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_background_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Background color', 'contact-forms'); ?>
1297 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_background_color']); ?></div>
1298 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_background_color'], ENT_QUOTES) ?>" />
1299 + </div>
1300 +
1301 + <div id="accua_form_style_field_padding" class="label_input">
1302 + <input name="accua_form_style_field_padding" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_padding'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Padding', 'contact-forms'); ?>
1303 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_padding']); ?></div>
1304 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_padding'], ENT_QUOTES) ?>" />
1305 + </div>
1306 +
1307 + <div id="accua_form_style_field_color" class="label_input">
1308 + <input name="accua_form_style_field_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_field_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Text color', 'contact-forms'); ?>
1309 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_field_color']); ?></div>
1310 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_color'], ENT_QUOTES) ?>" />
1311 + </div>
1312 +
1313 +
1314 + <h3><?php _e( 'Submit button', 'contact-forms'); ?></h3>
1315 +
1316 + <div id="accua_form_style_submit_border_color" class="label_input">
1317 + <input name="accua_form_style_submit_border_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_border_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Border color', 'contact-forms'); ?>
1318 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_border_color']); ?></div>
1319 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_color'], ENT_QUOTES) ?>" />
1320 + <?php _e( 'Customize', 'contact-forms'); ?>
1321 + </div>
1322 +
1323 + <div id="accua_form_style_submit_border_width" class="label_input">
1324 + <input name="accua_form_style_submit_border_width" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_border_width'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Border width', 'contact-forms'); ?>
1325 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_border_width']); ?></div>
1326 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_width'], ENT_QUOTES) ?>" />
1327 + </div>
1328 +
1329 + <div id="accua_form_style_submit_border_radius" class="label_input">
1330 + <input name="accua_form_style_submit_border_radius" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_border_radius'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Rounded corner radius', 'contact-forms'); ?>
1331 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_border_radius']); ?></div>
1332 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_radius'], ENT_QUOTES) ?>" />
1333 + </div>
1334 +
1335 + <div id="accua_form_style_submit_background_color" class="label_input">
1336 + <input name="accua_form_style_submit_background_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_background_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Background color', 'contact-forms'); ?>
1337 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_background_color']); ?></div>
1338 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_background_color'], ENT_QUOTES) ?>" />
1339 + </div>
1340 +
1341 + <div id="accua_form_style_submit_padding" class="label_input">
1342 + <input name="accua_form_style_submit_padding" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_padding'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Padding', 'contact-forms'); ?>
1343 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_padding']); ?></div>
1344 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_padding'], ENT_QUOTES) ?>" />
1345 + </div>
1346 +
1347 + <div id="accua_form_style_submit_color" class="label_input">
1348 + <input name="accua_form_style_submit_color" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_color'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Text color', 'contact-forms'); ?>
1349 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_color']); ?></div>
1350 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_color'], ENT_QUOTES) ?>" />
1351 + </div>
1352 +
1353 + <div id="accua_form_style_submit_font_size" class="label_input">
1354 + <input name="accua_form_style_submit_font_size" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['style_submit_font_size'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Font size', 'contact-forms'); ?>
1355 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['style_submit_font_size']); ?></div>
1356 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_font_size'], ENT_QUOTES) ?>" />
1357 + </div>
1358 +
1359 + <br clear="all"/>
1360 + </div>
1361 + </div>
1362 + </div>
1363 +
1364 +
1365 +
1366 + </div>
1367 + </div>
1368 + <div style="width:50%; float:right;">
1369 + <div style="padding: 15px;">
1370 + <h2><?php _e('Preview', 'contact-forms'); ?>
1371 + <?php echo $accuaHelp->add_pointer('form_edit_preview'); ?>
1372 + </h2>
1373 + <div id="accua_form_preview_area_wrapper">
1374 + <?php
1375 + echo "<script>
1376 + function resizeIframe(obj) {
1377 + altezza = obj.contentWindow.document.documentElement.scrollHeight + 200;
1378 + obj.style.height = altezza + 'px';
1379 + }
1380 + </script>";
1381 +
1382 + ?>
1383 + <iframe id="accua_form_preview_area" src="admin-ajax.php?action=accua_forms_preview&fid=<?php echo htmlspecialchars($fid,ENT_QUOTES);?>" frameborder="0" scrolling="no" onload="resizeIframe(this)" ></iframe>
1384 + <?php //todo: posso usare lo stile del sito? font ecc ?>
1385 + </div>
1386 +
1387 + </div>
1388 + </div>
1389 +
1390 + <div style="clear:both;">&nbsp;</div>
1391 +
1392 + <?php /* * / ?>
1393 + <pre>
1394 + accua_forms_form_fields_order_post: <?php echo htmlspecialchars(print_r(get_option('accua_forms_form_fields_order_post'), true)); ?>
1395 +
1396 + accua_forms_save_form_field_post: <?php echo htmlspecialchars(print_r(get_option('accua_forms_save_form_field_post'), true)); ?>
1397 +
1398 + accua_forms_saved_form_data: <?php echo htmlspecialchars(print_r($form_data, true)); ?>
1399 +
1400 + </pre>
1401 + <?php /* */ ?>
1402 +</div>
1403 + <div id="accua_tab_messages" class="content_tab">
1404 + <?php
1405 + $settings_editor = array(
1406 + 'teeny' => true,
1407 + 'editor_class' => 'accua_form_value',
1408 + 'tinymce' => array(
1409 + 'theme_advanced_buttons1' => 'bold,italic,underline,|,bullist,numlist,'));
1410 + ?>
1411 +
1412 + <div class="metabox-holder accua-forms-metabox-holder">
1413 + <div class="postbox ">
1414 + <h3 class="hndle"><span><?php _e('1. On-screen success message', 'contact-forms'); ?></span></h3>
1415 + <div class="inside" id="dashboard_right_now">
1416 + <div id="accua_form_success_message">
1417 + <input class="accua_form_check_override" name="accua_form_success_message" type="radio" value="0" <?php if (!isset($form_overrided_data['success_message'])) {echo ' checked ';} ?>> <?php _e( 'Use the default message', 'contact-forms'); ?>
1418 + <input class="accua_form_check_override" name="accua_form_success_message" type="radio" value="1" <?php if (isset($form_overrided_data['success_message']) && !isset($form_overrided_data['success_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Customize', 'contact-forms'); ?>
1419 + <input class="accua_form_check_override" name="accua_form_success_message" type="radio" value="-1" <?php if (isset($form_overrided_data['success_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Don\'t show any messages', 'contact-forms'); ?><br />
1420 + <div class="defalut_message">
1421 + <?php _e( 'Default Success message', 'contact-forms'); ?>
1422 + <div class="defalut_content_message"><?php echo wpautop($default_form_data['success_message']); ?></div>
1423 + </div>
1424 + <?php wp_editor( $form_data['success_message'] , 'accua_form_success_message_textarea' , $settings_editor); ?>
1425 + <!-- <textarea class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($form_data['success_message'], ENT_QUOTES) ?></textarea> -->
1426 + </div>
1427 + </div>
1428 + </div>
1429 + </div>
1430 +
1431 + <div class="metabox-holder accua-forms-metabox-holder">
1432 + <div class="postbox ">
1433 + <h3 class="hndle"><span><?php _e('2. On-screen error message', 'contact-forms'); ?></span></h3>
1434 + <div class="inside" id="dashboard_right_now">
1435 + <div id="accua_form_error_message">
1436 + <input class="accua_form_check_override" name="accua_form_error_message" type="radio" value="0" <?php if (!isset($form_overrided_data['error_message'])) {echo ' checked ';} ?>> <?php _e( 'Use the default message', 'contact-forms'); ?>
1437 + <input class="accua_form_check_override" name="accua_form_error_message" type="radio" value="1" <?php if (isset($form_overrided_data['error_message']) && !isset($form_overrided_data['error_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Customize', 'contact-forms'); ?>
1438 + <input class="accua_form_check_override" name="accua_form_error_message" type="radio" value="-1" <?php if (isset($form_overrided_data['error_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Don\'t show any messages', 'contact-forms'); ?><br />
1439 + <div class="defalut_message">
1440 + <?php _e( 'Default error message', 'contact-forms'); ?> <br />
1441 + <div class="defalut_content_message" ><?php echo wpautop($default_form_data['error_message']); ?></div>
1442 + </div>
1443 + <?php wp_editor( $form_data['error_message'] , 'accua_form_error_message_textarea' , $settings_editor); ?>
1444 + </div>
1445 + </div>
1446 + </div>
1447 + </div>
1448 + <br clear="all"/>
1449 + <div class="metabox-holder accua-forms-metabox-holder">
1450 + <div class="postbox ">
1451 + <h3 class="hndle"><span><?php _e('3. Email to notify administrator', 'contact-forms'); ?></span></h3>
1452 + <div class="inside" id="dashboard_right_now">
1453 + <div id="accua_form_admin_emails_to" class="label_input">
1454 + <label><?php _e('To', 'contact-forms'); ?></label>
1455 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['admin_emails_to']); ?></div>
1456 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_to'], ENT_QUOTES) ?>" />
1457 + <input name="accua_form_admin_emails_to" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['admin_emails_to'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1458 + </div>
1459 + <div id="accua_form_emails_bcc" class="label_input">
1460 + <label><?php _e('Bcc', 'contact-forms'); ?></label>
1461 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['emails_bcc']); ?></div>
1462 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_bcc'], ENT_QUOTES) ?>" />
1463 + <input name ="accua_form_emails_bcc" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['emails_bcc'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1464 + </div>
1465 +
1466 + <div id="accua_form_admin_emails_subject" class="label_input">
1467 + <label><?php _e( 'Subject', 'contact-forms'); ?></label>
1468 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['admin_emails_subject']); ?></div>
1469 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_subject'], ENT_QUOTES) ?>" />
1470 + <input name="accua_form_admin_emails_subject" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['admin_emails_subject'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1471 + </div>
1472 +
1473 + <div id="accua_form_admin_emails_message">
1474 + <input class="accua_form_check_override" name="accua_form_admin_emails_message" type="radio" value="0" <?php if (!isset($form_overrided_data['admin_emails_message'])) {echo ' checked ';} ?>> <?php _e( 'Use the default message', 'contact-forms'); ?>
1475 + <input class="accua_form_check_override" name="accua_form_admin_emails_message" type="radio" value="1" <?php if (isset($form_overrided_data['admin_emails_message']) && !isset($form_overrided_data['admin_emails_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Customize', 'contact-forms'); ?>
1476 + <input class="accua_form_check_override" name="accua_form_admin_emails_message" type="radio" value="-1" <?php if (isset($form_overrided_data['admin_emails_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Don\'t show any messages', 'contact-forms'); ?><br />
1477 + <div class="defalut_message">
1478 + <?php _e( 'Default message', 'contact-forms'); ?>
1479 + <div class="defalut_content_message"><?php echo wpautop($default_form_data['admin_emails_message']); ?></div>
1480 + </div>
1481 + <?php wp_editor( $form_data['admin_emails_message'] , 'accua_form_admin_emails_message_textarea' , $settings_editor); ?>
1482 + </div>
1483 +
1484 + </div>
1485 + </div>
1486 + </div>
1487 +
1488 + <div class="metabox-holder accua-forms-metabox-holder">
1489 + <div class="postbox ">
1490 + <h3 class="hndle"><span><?php _e('4. Email confirmation to the person who completed the form', 'contact-forms'); ?></span></h3>
1491 + <div class="inside" id="dashboard_right_now">
1492 + <div id="accua_form_emails_from_name" class="label_input">
1493 + <label><?php _e( 'From name', 'contact-forms'); ?></label>
1494 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['emails_from_name']); ?></div>
1495 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_from_name'], ENT_QUOTES) ?>" />
1496 + <input name="accua_form_emails_from_name" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['emails_from_name'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1497 + </div>
1498 + <div id="accua_form_emails_from" class="label_input">
1499 + <label><?php _e( 'From email', 'contact-forms'); ?></label>
1500 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['emails_from']); ?></div>
1501 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_from'], ENT_QUOTES) ?>" />
1502 + <input name="accua_form_emails_from" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['emails_from'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1503 + </div>
1504 + <div id="accua_form_confirmation_emails_subject" class="label_input">
1505 + <label><?php _e( 'Subject', 'contact-forms'); ?></label>
1506 + <div class="default_value"><?php echo htmlspecialchars($default_form_data['confirmation_emails_subject']); ?></div>
1507 + <input class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['confirmation_emails_subject'], ENT_QUOTES) ?>" />
1508 + <input name="accua_form_confirmation_emails_subject" class="accua_form_check_override" type="checkbox" value="1" <?php if (isset($form_overrided_data['confirmation_emails_subject'])) {echo 'checked="checked" ';} ?>/><?php _e( 'Customize', 'contact-forms'); ?>
1509 + </div>
1510 +
1511 + <div id="accua_form_confirmation_emails_message">
1512 + <input class="accua_form_check_override" name="accua_form_confirmation_emails_message" type="radio" value="0" <?php if (!isset($form_overrided_data['confirmation_emails_message'])) {echo ' checked ';} ?>> <?php _e( 'Use the default message', 'contact-forms'); ?>
1513 + <input class="accua_form_check_override" name="accua_form_confirmation_emails_message" type="radio" value="1" <?php if (isset($form_overrided_data['confirmation_emails_message']) && !isset($form_overrided_data['confirmation_emails_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Customize', 'contact-forms'); ?>
1514 + <input class="accua_form_check_override" name="accua_form_confirmation_emails_message" type="radio" value="-1" <?php if (isset($form_overrided_data['confirmation_emails_message_no_message'])) {echo ' checked ';} ?>/> <?php _e( 'Don\'t show any messages', 'contact-forms'); ?><br />
1515 + <div class="defalut_message">
1516 + <?php _e( 'Default message', 'contact-forms'); ?>
1517 + <div class="defalut_content_message"><?php echo wpautop($default_form_data['confirmation_emails_message']); ?></div>
1518 + </div>
1519 + <?php wp_editor( $form_data['confirmation_emails_message'] , 'accua_form_confirmation_emails_message_textarea' , $settings_editor); ?>
1520 + </div>
1521 + </div>
1522 + </div>
1523 + </div>
1524 + <br clear="all"/>
1525 +
1526 +<?php accua_forms_print_tokens(); ?>
1527 +
1528 +<input type="hidden" id="accua_form_save_settings_id" value="<?php echo $fid_esc; ?>" />
1529 +</div>
1530 +<?php /*
1531 +<div id="accua_tab_preview" class="content_tab">
1532 +</div> */?>
1533 +<p></p>
1534 +<input class="button button-primary button-large accua_form_save_settings_button" id="accua_form_save_settings_2" type="button" value="<?php _e( 'Save settings', 'contact-forms'); ?>" /> <span class="accua_form_save_settings_status"></span>
1535 +
1536 +</div>
1537 +<script>
1538 +jQuery('input[type=radio]').change(function() {
1539 + var name = jQuery(this).attr('name');
1540 + if (jQuery(this).val() == '1') {
1541 + jQuery('#'+name+' .defalut_message').hide();
1542 + jQuery('#'+name+' .wp-editor-wrap').show();
1543 + }
1544 + else {
1545 + if(jQuery(this).val() != '-1')
1546 + jQuery('#'+name+' .defalut_message').show();
1547 + else
1548 + jQuery('#'+name+' .defalut_message').hide();
1549 + jQuery('#'+name+' .wp-editor-wrap').hide();
1550 + }
1551 +});
1552 +
1553 +jQuery('input[type=checkbox]').click(function() {
1554 + var name = jQuery(this).attr('name');
1555 + if (!this.checked) {
1556 + jQuery('#'+name+' .default_value').show();
1557 + jQuery('#'+name+' .accua_form_value, #'+name+' .cp-color-picker').hide();
1558 + }
1559 + else {
1560 + jQuery('#'+name+' .default_value').hide();
1561 + jQuery('#'+name+' .accua_form_value, #'+name+' .cp-color-picker').show();
1562 + //cp-color-picker
1563 + }
1564 +});
1565 +
1566 +jQuery(".token_link").click(function() {
1567 + jQuery("#dialog_token").dialog("open");
1568 + return false;
1569 +});
1570 +
1571 +//inizializzazione
1572 +jQuery(document).ready(function($){
1573 + $('#accua_form_preview_area_wrapper').resizable({handles: 's'});
1574 + $('#accua_form_preview_area').css({
1575 + 'width': '100%',
1576 + 'height': '100%'
1577 + });
1578 + $.each(
1579 + ['success_message','error_message','admin_emails_message','confirmation_emails_message'],
1580 + function(i,key){
1581 + var value = $('#accua_form_'+key+' .accua_form_check_override:checked').val();
1582 + if(value!=undefined && value!=0) {
1583 + if(value!=-1)
1584 + jQuery('#accua_form_'+key+' .wp-editor-wrap').show();
1585 + else
1586 + jQuery('#accua_form_'+key+' .wp-editor-wrap').hide();
1587 + jQuery('#accua_form_'+key+' .defalut_message').hide();
1588 +
1589 + }
1590 + else {
1591 + jQuery('#accua_form_'+key+' .wp-editor-wrap').hide();
1592 + jQuery('#accua_form_'+key+' .defalut_message').show();
1593 + }
1594 + }
1595 + );
1596 + $.each(
1597 + ['emails_from_name','emails_from','admin_emails_to','emails_bcc','admin_emails_subject','confirmation_emails_subject','style_margin','style_border_color','style_border_width','style_border_radius','style_background_color','style_padding','style_color','style_font_size','style_field_spacing','style_field_border_color','style_field_border_width','style_field_border_radius','style_field_background_color','style_field_padding','style_field_color','style_submit_border_color','style_submit_border_width','style_submit_border_radius','style_submit_background_color','style_submit_padding','style_submit_color','style_submit_font_size'],
1598 + function(i,key){
1599 + if(!$('#accua_form_'+key+' .accua_form_check_override').is(':checked')) {
1600 + jQuery('#accua_form_'+key+' .default_value').show();
1601 + jQuery('#accua_form_'+key+' .accua_form_value, #accua_form_'+key+' .wp-picker-container').hide();
1602 + }
1603 + else {
1604 + jQuery('#accua_form_'+key+' .default_value').hide();
1605 + jQuery('#accua_form_'+key+' .accua_form_value, #accua_form_'+key+' .wp-picker-container').show();
1606 + }
1607 + });
1608 + $("#dialog_token").dialog({ dialogClass:'wp-dialog' ,autoOpen : false, modal : true, show : "blind", hide : "blind"});
1609 +
1610 + $('#accua_token a').appendTo('.wp-media-buttons');
1611 +
1612 +});
1613 +
1614 +jQuery(document).ready(function($){
1615 +
1616 + var originalWidth = $(document).width();
1617 + if(originalWidth <= 883) { //iphone
1618 + $(".metabox-holder").width('98%');
1619 + }
1620 +
1621 + $(window).resize(function (e) {
1622 + var newWidth = $(document).width();
1623 + if(newWidth <= 883) {
1624 + if (originalWidth > 883) {
1625 + $(".metabox-holder").width('98%');
1626 + }
1627 + } else if (originalWidth<=883) {
1628 + $(".metabox-holder").width('47%');
1629 + }
1630 + originalWidth = newWidth;
1631 + });
1632 +});
1633 +
1634 +</script>
1635 +
1636 +<?php
1637 + $accuaHelp->finished();
1638 +}
1639 +
1640 +function accua_forms_fields_page_head() {
1641 +/*
1642 + $baseurl = WP_PLUGIN_URL.'/'.substr(plugin_basename(__FILE__),0,-strlen(basename(__FILE__)));
1643 +?>
1644 + <script type="text/javascript" src="<?php echo $baseurl.'/qtip/jquery.qtip-1.0.0-rc3.js'; ?>"></script>
1645 + <script type="text/javascript">
1646 + var avail_fields = {
1647 + first_name: {
1648 + id: "first_name",
1649 + name: "First Name",
1650 + type: "textfield"
1651 + },
1652 + last_name: {
1653 + id: "last_name",
1654 + name: "Last Name",
1655 + type: "textfield"
1656 + },
1657 + email: {
1658 + id: "email",
1659 + name: "Email",
1660 + type: "email"
1661 + }
1662 + };
1663 +
1664 + jQuery(function($){
1665 + $avail = $('#available_fields_container');
1666 + for(var id in avail_fields) {
1667 + var field = avail_fields[id];
1668 + var el = $('<div></div>').text(field.name);
1669 + el.prepend('<input type="checkbox" />');
1670 + var content = $('<div><span>Id: </span></div>');
1671 + content.append($('<input type="text" />').val(field.id));
1672 + content.append($('<br /><span>Name: </span>'));
1673 + content.append($('<input type="text" />').val(field.name));
1674 + content.append($('<br /><span>Type: </span>'));
1675 + content.append($('<select><option value="textfield">Textfield</option><option value="textarea">Textarea</option><option value="email">Email</option></select>').val(field.type));
1676 + el.qtip({
1677 + content: {
1678 + text: content
1679 + },
1680 + position: {
1681 + target: 'mouse',
1682 + corner: {
1683 + target: 'bottomRight',
1684 + tooltip: 'topLeft'
1685 + },
1686 + adjust: {
1687 + mouse: false
1688 + }
1689 + },
1690 + show: {
1691 + when: {
1692 + event: 'mouseover'
1693 + },
1694 + solo: true
1695 + },
1696 + hide: {
1697 + when: {
1698 + event: 'unfocus'
1699 + }
1700 + }
1701 + });
1702 + $avail.append(el);
1703 + }
1704 + });
1705 + </script>
1706 + <style type="text/css">
1707 + .container > div {
1708 + padding: 0px;
1709 + margin-bottom: 6px;
1710 + }
1711 + </style>
1712 +<?php
1713 +*/
1714 +}
1715 +
1716 +function accua_forms_fields_get_types() {
1717 + return array(
1718 + 'textfield' => __( 'Text Field', 'contact-forms'),
1719 + 'textarea' => __( 'Text Area', 'contact-forms'),
1720 + 'email' => __( 'Email', 'contact-forms'),
1721 + 'autoreply_email' => __( 'Autoreply Email', 'contact-forms'),
1722 + 'checkbox' => __( 'Checkbox','contact-forms'),
1723 + 'select' => __('Select', 'contact-forms'),
1724 + 'radio' => __( 'Radio buttons', 'contact-forms'),
1725 + 'multiselect' => __( 'Multiple selections area', 'contact-forms'),
1726 + 'multicheckbox' => __( 'Multiple checkboxes', 'contact-forms'),
1727 + 'post-select' => __( 'Post select', 'contact-forms'),
1728 + 'post-multicheckbox' => __( 'Multiple post checkboxes', 'contact-forms'),
1729 + 'colorpicker' => __( 'Color picker', 'contact-forms'),
1730 + 'hidden' => __('Hidden value', 'contact-forms'),
1731 + 'file' => __('File upload', 'contact-forms'),
1732 + 'submit' => __( 'Submit button', 'contact-forms'),
1733 + 'html' => __( 'Custom HTML', 'contact-forms'),
1734 + 'captcha' => __( 'Captcha', 'contact-forms'),
1735 + 'password' => 'Password',
1736 + 'password-and-confirm' => __( 'Password and password confirmation','contact-forms'),
1737 + 'date' => __( 'Date','contact-forms'),
1738 + );
1739 +}
1740 +
1741 +function accua_forms_filter_date($value){
1742 + if (($value !== '') && preg_match('/^\d{4}-\d{2}-\d{2}$/', $value)) {
1743 + try {
1744 + $date = new DateTime($value);
1745 + if ($date) {
1746 + return $value;
1747 + }
1748 + } catch (Exception $e) {
1749 + }
1750 + }
1751 + return '';
1752 +}
1753 +
1754 +function accua_forms_fields_filter_values($post, $old_data = array()) {
1755 + //TODO: funzione di validazione dei field
1756 + $data = array(
1757 + 'version' => 2,
1758 + 'id' => $post['form-field-id'],
1759 + 'name' => $post['form-field-name'],
1760 + 'type' => $post['form-field-type'],
1761 + 'description' => $post['form-field-description'],
1762 + 'default_value' => $post['form-field-default-value'],
1763 + 'default_date_value' => $post['form-field-default-date-value'],
1764 + 'allowed_values' => $post['form-field-allowed-values'],
1765 + 'allowed_extensions' => '',
1766 + 'min_date' => $post['form-field-min-of-date'],
1767 + 'max_date' => $post['form-field-max-of-date'],
1768 + );
1769 + $valid = true;
1770 + $message = '';
1771 +
1772 + $types = accua_forms_fields_get_types();
1773 + if (!isset($types[$data['type']])) {
1774 + $message .= "<p>".__('Invalid type', 'contact-forms')."</p>";
1775 + $valid = false;
1776 + $data['type'] = 'textfield';
1777 + }
1778 +
1779 + if (!current_user_can('unfiltered_html')) {
1780 + $filter_fields = array('name', 'description', 'default_value', 'allowed_values');
1781 + foreach ($filter_fields as $k) {
1782 + $data[$k] = wp_kses($data[$k], 'post');
1783 + }
1784 + }
1785 +
1786 + if ($data['type'] == 'file') {
1787 + $data['allowed_extensions'] = accua_forms_filter_extensions($data['allowed_values']);
1788 + }
1789 +
1790 + $dates = array(
1791 + 'default_date_value' => __('Invalid default date', 'contact-forms'),
1792 + 'min_date' => __('Invalid min date', 'contact-forms'),
1793 + 'max_date' => __('Invalid max date', 'contact-forms'),
1794 + );
1795 + foreach ($dates as $k => $errormsg) {
1796 + if ($data[$k] !== '') {
1797 + $data[$k] = accua_forms_filter_date($data[$k]);
1798 + if ($data[$k] === '') {
1799 + $message .= "<p>".$errormsg."</p>";
1800 + $valid = false;
1801 + }
1802 + }
1803 + }
1804 +
1805 + return array(
1806 + 'data' => $data,
1807 + 'valid' => $valid,
1808 + 'message' => $message,
1809 + );
1810 +}
1811 +
1812 +function accua_forms_fields_page() {
1813 +/*
1814 +?>
1815 +<div class="wrap"><h2>Edit Form Fields</h2>
1816 + <div id="available_fields_container" class="container"></div>
1817 +</div>
1818 +<?php
1819 +*/
1820 + $message = '';
1821 + $taxonomy = '';
1822 + $post_type = '';
1823 +
1824 + /*
1825 + $avail_fields = array(
1826 + 'first_name' => array (
1827 + 'id' => "first_name",
1828 + 'name' => "First Name",
1829 + 'type' => "textfield",
1830 + 'description' => 'This is the first name',
1831 + ),
1832 + 'last_name' => array (
1833 + 'id' => "last_name",
1834 + 'name' => "Last Name",
1835 + 'type' => "textfield",
1836 + 'description' => 'This is the last name',
1837 + ),
1838 + 'email' => array (
1839 + 'id' => "email",
1840 + 'name' => "Email",
1841 + 'type' => "email",
1842 + 'description' => 'This is the email',
1843 + ),
1844 + );
1845 + */
1846 +
1847 + $avail_fields = get_option('accua_forms_avail_fields', array());
1848 +
1849 + $default_form_values = array(
1850 + 'version' => 1,
1851 + 'id' => '',
1852 + 'name' => '',
1853 + 'type' => 'textfield',
1854 + 'description' => '',
1855 + 'default_value' => '',
1856 + 'default_date_value' => '',
1857 + 'allowed_values' => '',
1858 + 'allowed_extensions' => '',
1859 + 'min_date' => '',
1860 + 'max_date' => '',
1861 + );
1862 +
1863 + $editing = false;
1864 + $adding = true;
1865 +
1866 + if (!empty($_POST['action'])) {
1867 + check_admin_referer('edit_form_field', '_wpnonce_edit_form_field');
1868 + $post = stripslashes_deep($_POST) + $default_form_values;
1869 + switch($post['action']) {
1870 + case 'edit-form-field':
1871 + if (empty($avail_fields[$post['form-field-id']])) {
1872 + $message .= 'Field "'.htmlspecialchars(sanitize_text_field($post['form-field-id'])).'" doesn\'t exists';
1873 + } else {
1874 + if (empty($post['delete-field'])) {
1875 + $filtered_data = accua_forms_fields_filter_values($post, $avail_fields[$post['form-field-id']]);
1876 + $avail_fields[$post['form-field-id']] = $filtered_data['data'];
1877 + $message .= sprintf( __( 'Field "%s" updated', 'contact-forms'), htmlspecialchars($post['form-field-id']) );
1878 + do_action('accua_forms_field_updated', $avail_fields[$post['form-field-id']]);
1879 + } else {
1880 + $deleting_field = $avail_fields[$post['form-field-id']];
1881 + unset ($avail_fields[$post['form-field-id']]);
1882 + $message .= sprintf( __( 'Field "%s" deleted', 'contact-forms'), htmlspecialchars($post['form-field-id']) );
1883 + do_action('accua_forms_field_deleted', $deleting_field);
1884 + }
1885 + update_option('accua_forms_avail_fields', $avail_fields);
1886 + }
1887 + break;
1888 + case 'add-form-field':
1889 + $fill_form_fields = true;
1890 + $valid = true;
1891 + if (empty($post['form-field-id']) || !preg_match('/^[a-z0-9_-]+$/i', $post['form-field-id'])) {
1892 + $message .= "<p>".__( 'Only letters, numbers, hyphen and underscores allowed in field identificative slug', 'contact-forms')."</p>";
1893 + $valid = false;
1894 + }
1895 + if(substr($post['form-field-id'], 0, 2) == '__') {
1896 + $message .= "<p>".__( 'The field identificative slug can\'t start with two underscores (__)', 'contact-forms')."</p>";
1897 + $valid = false;
1898 + }
1899 + if (!empty($avail_fields[$post['form-field-id']])) {
1900 + $message .= sprintf( __( '<p>A field with identificative slug "%s" already exists</p> Field "%s" deleted', 'contact-forms'), htmlspecialchars($post['form-field-id']) );
1901 + $valid = false;
1902 + }
1903 + if (strlen($post['form-field-id']) > 70) {
1904 + $message .= "<p>".__( 'The identificative slug cannot be longer than 70 characters', 'contact-forms')."</p>";
1905 + $valid = false;
1906 + }
1907 + $filtered_data = accua_forms_fields_filter_values($post);
1908 + $message .= $filtered_data['message'];
1909 + $valid = $valid && $filtered_data['valid'];
1910 + if ($valid) {
1911 + $fill_form_fields = false;
1912 + $avail_fields[$post['form-field-id']] = $filtered_data['data'];
1913 + update_option('accua_forms_avail_fields', $avail_fields);
1914 + $message .= sprintf( __( 'Field "%s" created', 'contact-forms'), htmlspecialchars($post['form-field-id']) );
1915 + do_action('accua_forms_field_added', $avail_fields[$post['form-field-id']]);
1916 + }
1917 + if ($fill_form_fields) {
1918 + $editing = true;
1919 + $default_form_values = $filtered_data['data'];
1920 + }
1921 + break;
1922 + }
1923 + } else if (!empty($_GET['edit-fid'])) {
1924 + $fid = stripslashes($_GET['edit-fid']);
1925 + if (empty($avail_fields[$fid])) {
1926 + $message .= sprintf( __( 'Field "%s" doesn\'t exists', 'contact-forms'), htmlspecialchars($fid) );
1927 + } else {
1928 + $adding = false;
1929 + $editing = true;
1930 + $default_form_values = $avail_fields[$fid] + $default_form_values;
1931 + }
1932 + }
1933 + if ($default_form_values['version'] >= 2 && $default_form_values['type'] == 'file') {
1934 + //Show allowed_extensions value in allowed_values field
1935 + $default_form_values['allowed_values'] = $default_form_values['allowed_extensions'];
1936 + }
1937 +
1938 +?>
1939 +<div id="accua_forms_fields_page" class="accua_forms_admin_page wrap nosubsub">
1940 +<h2><img src="<?php echo ACCUA_FORMS_DIR_URL.'img/cimatti-icon-20.png'; ?>"/> <?php _e('Contact Forms - Fields', 'contact-forms'); ?></h2>
1941 +<?php /* screen_icon(); ?>
1942 +<h2><?php echo esc_html( $title );
1943 +if ( !empty($_REQUEST['s']) )
1944 + printf( '<span class="subtitle">' . __('Search results for &#8220;%s&#8221;') . '</span>', esc_html( stripslashes($_REQUEST['s']) ) ); ?>
1945 +</h2>
1946 +
1947 +<?php if ( isset($_REQUEST['message']) && ( $msg = (int) $_REQUEST['message'] ) ) : ?>
1948 +<div id="message" class="updated"><p><?php echo $messages[$msg]; ?></p></div>
1949 +<?php $_SERVER['REQUEST_URI'] = remove_query_arg(array('message'), $_SERVER['REQUEST_URI']);
1950 +endif; */ ?>
1951 +<div id="ajax-response"><?php echo $message?></div>
1952 +
1953 +<?php /*
1954 +<form class="search-form" action="" method="get">
1955 +<input type="hidden" name="taxonomy" value="<?php echo esc_attr($taxonomy); ?>" />
1956 +<input type="hidden" name="post_type" value="<?php echo esc_attr($post_type); ?>" />
1957 +
1958 +<?php $wp_list_table->search_box( $tax->labels->search_items, 'tag' ); ?>
1959 +
1960 +</form>
1961 +*/ ?>
1962 +
1963 +<br class="clear" />
1964 +
1965 +<div id="col-container">
1966 +
1967 +<div id="col-right">
1968 +<div class="col-wrap">
1969 +<?php if (!$editing) { ?>
1970 +<form id="posts-filter" action="" method="post">
1971 +<input type="hidden" name="taxonomy" value="<?php echo esc_attr($taxonomy); /* TODO: Is this needed? */ ?>" />
1972 +<input type="hidden" name="post_type" value="<?php echo esc_attr($post_type); /* TODO: Is this needed? */ ?>" />
1973 +
1974 +<?php /* $wp_list_table->display(); */ ?>
1975 +
1976 +<table cellspacing="0" class="wp-list-table widefat fixed tags">
1977 + <thead>
1978 + <tr>
1979 + <th style="" class="manage-column column-cb check-column" id="cb" scope="col"><input type="checkbox" /></th>
1980 + <th style="" class="manage-column column-name" id="name" scope="col"><?php _e( 'Label', 'contact-forms'); ?></th>
1981 + <th style="" class="manage-column column-description" id="description" scope="col"><?php _e( 'Description', 'contact-forms'); ?></th>
1982 + <th style="" class="manage-column column-slug" id="slug" scope="col"><?php _e( 'Slug', 'contact-forms'); ?></th>
1983 + <th style="" class="manage-column column-type" id="type" scope="col"><?php _e( 'Type', 'contact-forms'); ?></th>
1984 + </tr>
1985 + </thead>
1986 +
1987 + <tfoot>
1988 + <tr>
1989 + <th style="" class="manage-column column-cb check-column" scope="col"><input type="checkbox" /></th>
1990 + <th style="" class="manage-column column-name" scope="col"><?php _e( 'Label', 'contact-forms'); ?></th>
1991 + <th style="" class="manage-column column-description" scope="col"><?php _e( 'Description', 'contact-forms'); ?></th>
1992 + <th style="" class="manage-column column-slug" scope="col"><?php _e( 'Slug', 'contact-forms'); ?></th>
1993 + <th style="" class="manage-column column-type" scope="col"><?php _e( 'Type', 'contact-forms'); ?></th>
1994 + </tr>
1995 + </tfoot>
1996 +
1997 + <tbody class="list:tag" id="the-list">
1998 +<?php
1999 + foreach ($avail_fields as $id => $field) {
2000 + foreach (array('id', 'name', 'type', 'description') as $i) {
2001 + $field[$i] = htmlspecialchars($field[$i], ENT_QUOTES);
2002 + $field[$i] = sanitize_text_field($field[$i]);
2003 + }
2004 + echo <<<END_OF_ROW
2005 + <tr id="field-{$field['id']}">
2006 + <th class="check-column" scope="row"><input type="checkbox" /></th>
2007 + <td class="name column-name"><strong><a title="Edit “{$field['name']}”" href="admin.php?page=accua_forms_fields&amp;edit-fid={$field['id']}" class="row-title">{$field['name']}</a></strong><br><div class="row-actions"><span class="edit"><a href="admin.php?page=accua_forms_fields&amp;edit-fid={$field['id']}">Edit</a></span></div></td>
2008 + <td class="description column-description">{$field['description']}</td>
2009 + <td class="slug column-slug">{$field['id']}</td>
2010 + <td class="type column-type">{$field['type']}</td>
2011 + </tr>
2012 +END_OF_ROW;
2013 + }
2014 +?>
2015 + </tbody>
2016 +</table>
2017 +
2018 +<br class="clear" />
2019 +</form>
2020 +<?php } ?>
2021 +<?php /* if ( 'category' == $taxonomy ) : ?>
2022 +<div class="form-wrap">
2023 +<p><?php printf(__('<strong>Note:</strong><br />Deleting a category does not delete the posts in that category. Instead, posts that were only assigned to the deleted category are set to the category <strong>%s</strong>.'), apply_filters('the_category', get_cat_name(get_option('default_category')))) ?></p>
2024 +<?php if ( current_user_can( 'import' ) ) : ?>
2025 +<p><?php printf(__('Categories can be selectively converted to tags using the <a href="%s">category to tag converter</a>.'), 'import.php') ?></p>
2026 +<?php endif; ?>
2027 +</div>
2028 +<?php elseif ( 'post_tag' == $taxonomy && current_user_can( 'import' ) ) : ?>
2029 +<div class="form-wrap">
2030 +<p><?php printf(__('Tags can be selectively converted to categories using the <a href="%s">tag to category converter</a>'), 'import.php') ;?>.</p>
2031 +</div>
2032 +<?php endif;
2033 +do_action('after-' . $taxonomy . '-table', $taxonomy);
2034 +*/ ?>
2035 +
2036 +</div>
2037 +</div><!-- /col-right -->
2038 +
2039 +<div id="col-left">
2040 +<div class="col-wrap">
2041 +
2042 +<?php
2043 +/*
2044 +if ( !is_null( $tax->labels->popular_items ) ) {
2045 + if ( current_user_can( $tax->cap->edit_terms ) )
2046 + $tag_cloud = wp_tag_cloud( array( 'taxonomy' => $taxonomy, 'echo' => false, 'link' => 'edit' ) );
2047 + else
2048 + $tag_cloud = wp_tag_cloud( array( 'taxonomy' => $taxonomy, 'echo' => false ) );
2049 +
2050 + if ( $tag_cloud ) :
2051 + ?>
2052 +<div class="tagcloud">
2053 +<h3><?php echo $tax->labels->popular_items; ?></h3>
2054 +<?php echo $tag_cloud; unset( $tag_cloud ); ?>
2055 +</div>
2056 +<?php
2057 +endif;
2058 +}
2059 +*/
2060 +
2061 +/*
2062 +if ( current_user_can($tax->cap->edit_terms) ) {
2063 + // Back compat hooks. Deprecated in preference to {$taxonomy}_pre_add_form
2064 + if ( 'category' == $taxonomy )
2065 + do_action('add_category_form_pre', (object)array('parent' => 0) );
2066 + elseif ( 'link_category' == $taxonomy )
2067 + do_action('add_link_category_form_pre', (object)array('parent' => 0) );
2068 + else
2069 + do_action('add_tag_form_pre', $taxonomy);
2070 +
2071 + do_action($taxonomy . '_pre_add_form', $taxonomy);
2072 +*/
2073 +
2074 +$types = accua_forms_fields_get_types();
2075 +?>
2076 +<div class="form-wrap">
2077 +<h3><?php echo $adding? __( 'Add new field','contact-forms'): __( 'Edit field','contact-forms') ; ?></h3>
2078 +<form id="addtag" method="post" action="admin.php?page=accua_forms_fields" class="validate">
2079 +<input type="hidden" name="action" value="<?php echo $adding?'add':'edit'; ?>-form-field" />
2080 +<?php /*
2081 +<input type="hidden" name="screen" value="<?php echo esc_attr($current_screen->id); ?>" />
2082 +<input type="hidden" name="taxonomy" value="<?php echo esc_attr($taxonomy); ?>" />
2083 +<input type="hidden" name="post_type" value="<?php echo esc_attr($post_type); ?>" />
2084 +*/ ?>
2085 +<?php wp_nonce_field('edit_form_field', '_wpnonce_edit_form_field'); ?>
2086 +
2087 +<div class="form-field form-required">
2088 + <label for="tag-name"><?php _e( 'Field label', 'contact-forms'); ?></label>
2089 + <input name="form-field-name" id="tag-name" type="text" value="<?php echo htmlspecialchars($default_form_values['name'], ENT_QUOTES) ?>" size="40" aria-required="true" />
2090 + <p><?php _e('The name is how it appears on your site.', 'contact-forms'); ?></p>
2091 +</div>
2092 +<?php /* if ( ! global_terms_enabled() ) : */ ?>
2093 +<div class="form-field">
2094 + <label for="tag-slug"><?php _e( 'Field slug (identificative)', 'contact-forms'); ?></label>
2095 + <input name="form-field-id" id="tag-slug" type="text" value="<?php echo htmlspecialchars($default_form_values['id'], ENT_QUOTES) ?>" <?php if (!$adding) { echo 'disabled="disabled"'; } ?> size="40" />
2096 + <?php if (!$adding) { echo '<input type="hidden" name="form-field-id" value="'.htmlspecialchars($default_form_values['id'], ENT_QUOTES).'" />'; } ?>
2097 + <p><?php _e('The &#8220;slug&#8221; is the URL-friendly version of the name. It is used as an identificator, and is unchangeable. It is usually all lowercase and it must contains only letters, numbers, and underscores.', 'contact-forms'); ?></p>
2098 +</div>
2099 +<div class="form-field">
2100 + <label for="parent"><?php _e( 'Field type', 'contact-forms'); ?></label>
2101 + <select class="postform" id="parent" name="form-field-type">
2102 + <?php /*
2103 + <option value="textfield" class="level-0" <?php echo ($default_form_values['type'] == 'textfield')?'selected="selected"':'';?> >Text Field</option>
2104 + <option value="textarea" class="level-0" <?php echo ($default_form_values['type'] == 'textarea')?'selected="selected"':'';?> >Text Area</option>
2105 + <option value="email" class="level-0" <?php echo ($default_form_values['type'] == 'email')?'selected="selected"':'';?> >Email</option>
2106 + <option value="checkbox" class="level-0" <?php echo ($default_form_values['type'] == 'checkbox')?'selected="selected"':'';?> >Checkbox</option>
2107 + <option value="select" class="level-0" <?php echo ($default_form_values['type'] == 'select')?'selected="selected"':'';?> >Select</option>
2108 + */
2109 + foreach ($types as $typeid => $typename) {
2110 + $selected = ($default_form_values['type'] == $typeid)?'selected="selected"':'';
2111 + echo <<<EOT
2112 +<option value="{$typeid}" class="level-0" {$selected} >{$typename}</option>
2113 +EOT;
2114 + }
2115 +
2116 + ?>
2117 + </select>
2118 +</div>
2119 +<?php /* endif; // global_terms_enabled() */ ?>
2120 +<?php /* if ( is_taxonomy_hierarchical($taxonomy) ) : ?>
2121 +<div class="form-field">
2122 + <label for="parent"><?php _ex('Parent', 'Taxonomy Parent'); ?></label>
2123 + <?php wp_dropdown_categories(array('hide_empty' => 0, 'hide_if_empty' => false, 'taxonomy' => $taxonomy, 'name' => 'parent', 'orderby' => 'name', 'hierarchical' => true, 'show_option_none' => __('None'))); ?>
2124 + <?php if ( 'category' == $taxonomy ) : // @todo: Generic text for hierarchical taxonomies ?>
2125 + <p><?php _e('Categories, unlike tags, can have a hierarchy. You might have a Jazz category, and under that have children categories for Bebop and Big Band. Totally optional.'); ?></p>
2126 + <?php endif; ?>
2127 +</div>
2128 +<?php endif; // is_taxonomy_hierarchical() */ ?>
2129 +<div class="form-field">
2130 + <label for="tag-description"><?php _e( 'Field description', 'contact-forms'); ?></label>
2131 + <textarea name="form-field-description" id="tag-description" rows="5" cols="40"><?php echo htmlspecialchars($default_form_values['description'], ENT_QUOTES) ?></textarea>
2132 + <p><?php _e('The description is not prominent by default; however, some themes may show it.', 'contact-forms'); ?></p>
2133 +</div>
2134 +
2135 +<div class="form-field">
2136 + <label for="form-field-default-value"><?php _e( 'Default value(s)', 'contact-forms'); ?>:</label>
2137 + <textarea name="form-field-default-value" id="form-field-default-value" rows="5" cols="40"><?php echo htmlspecialchars($default_form_values['default_value'], ENT_QUOTES) ?></textarea>
2138 + <p><?php _e( 'For multiple default values in multiple select and multiple checkboxes, use | as separator.', 'contact-forms'); ?></p>
2139 +</div>
2140 +
2141 +<div class="form-field">
2142 + <label for="form-field-allowed-values"><?php _e( 'Allowed values', 'contact-forms'); ?>:</label>
2143 + <textarea rows="5" cols="40" name="form-field-allowed-values" id=form-field-allowed-values"><?php echo htmlspecialchars($default_form_values['allowed_values'], ENT_QUOTES) ?></textarea>
2144 + <p><?php _e( 'Options used in select, radio and multiple checkboxes. Enter one value per line, in the format key|label. The key is the value that will be stored in the database. The label is optional, and the key will be used as the label if no label is specified. For file fields, this indicates allowed extensions (one per line without dot)', 'contact-forms'); ?></p>
2145 +</div>
2146 +
2147 +<div class="form-field">
2148 +<?php _e( 'Settings for date fields', 'contact-forms'); ?>
2149 +<div class="form-field">
2150 + <label for="form-field-default-date-value"><?php _e( 'Default value', 'contact-forms'); ?>:</label>
2151 + <input type="date" name="form-field-default-date-value" id="form-field-default-date-value" value="<?php echo htmlspecialchars($default_form_values['default_date_value'], ENT_QUOTES) ?>">
2152 +</div>
2153 +
2154 +
2155 +<label for="form-field-min-of-date"><?php _e( 'Min date', 'contact-forms'); ?>:</label>
2156 +<input type="date" id="form-field-min-of-date" name="form-field-min-of-date" value="<?php echo htmlspecialchars($default_form_values['min_date'], ENT_QUOTES) ?>">
2157 +
2158 +<label for="form-field-max-of-date"><?php _e( 'Max date', 'contact-forms'); ?>:</label>
2159 +<input type="date" id="form-field-max-of-date" name="form-field-max-of-date" value="<?php echo htmlspecialchars($default_form_values['max_date'], ENT_QUOTES) ?>">
2160 +
2161 +</div>
2162 +
2163 +
2164 +<?php
2165 +/*
2166 +if ( ! is_taxonomy_hierarchical($taxonomy) )
2167 + do_action('add_tag_form_fields', $taxonomy);
2168 +do_action($taxonomy . '_add_form_fields', $taxonomy);
2169 +*/
2170 +
2171 +if ($adding) {
2172 + submit_button( __( 'Add new field', 'contact-forms'), 'button' );
2173 +} else {
2174 + submit_button( __( 'Save changes', 'contact-forms'), 'button' );
2175 + submit_button( __( 'Delete field', 'contact-forms'), 'button', 'delete-field');
2176 +}
2177 +
2178 +/*
2179 +// Back compat hooks. Deprecated in preference to {$taxonomy}_add_form
2180 +if ( 'category' == $taxonomy )
2181 + do_action('edit_category_form', (object)array('parent' => 0) );
2182 +elseif ( 'link_category' == $taxonomy )
2183 + do_action('edit_link_category_form', (object)array('parent' => 0) );
2184 +else
2185 + do_action('add_tag_form', $taxonomy);
2186 +
2187 +do_action($taxonomy . '_add_form', $taxonomy);
2188 +*/
2189 +?>
2190 +</form></div>
2191 +<?php /* } */ ?>
2192 +
2193 +</div>
2194 +</div><!-- /col-left -->
2195 +
2196 +</div><!-- /col-container -->
2197 +</div><!-- /wrap -->
2198 +<?php
2199 + /* echo '<pre>accua_forms_avail_fields:', htmlspecialchars(print_r($avail_fields, true)), '</pre>'; */
2200 +}
2201 +
2202 +function accua_forms_settings_page() {
2203 +?>
2204 +<div id="accua_forms_settings_page" class="accua_forms_admin_page wrap">
2205 +<h2><img src="<?php echo ACCUA_FORMS_DIR_URL.'img/cimatti-icon-20.png'; ?>"/> <?php _e('Contact Forms - Default Settings', 'contact-forms'); ?></h2>
2206 +<?php
2207 + $empty_form_data = array(
2208 + 'success_message' => '',
2209 + 'error_message' => '',
2210 + 'emails_from_name' => '',
2211 + 'emails_from' => '',
2212 + 'admin_emails_to' => '',
2213 + 'emails_bcc' => '',
2214 + 'admin_emails_subject' => '',
2215 + 'admin_emails_message' => '',
2216 + 'confirmation_emails_subject' => '',
2217 + 'confirmation_emails_message' => '',
2218 + 'layout' => 'sidebyside',
2219 + 'style_margin' => '',
2220 + 'style_border_color' => '',
2221 + 'style_border_width' => '',
2222 + 'style_border_radius' => '',
2223 + 'style_background_color' => '',
2224 + 'style_padding' => '',
2225 + 'style_color' => '',
2226 + 'style_font_size' => '',
2227 + 'style_field_spacing' => '',
2228 + 'style_field_border_color' => '',
2229 + 'style_field_border_width' => '',
2230 + 'style_field_border_radius' => '',
2231 + 'style_field_background_color' => '',
2232 + 'style_field_padding' => '',
2233 + 'style_field_color' => '',
2234 + 'style_submit_border_color' => '',
2235 + 'style_submit_border_width' => '',
2236 + 'style_submit_border_radius' => '',
2237 + 'style_submit_background_color' => '',
2238 + 'style_submit_padding' => '',
2239 + 'style_submit_color' => '',
2240 + 'style_submit_font_size' => '',
2241 + );
2242 +
2243 + $empty_file_data = array(
2244 + 'valid_extensions' => '',
2245 + 'max_size' => '',
2246 + 'dest_path' => '',
2247 + );
2248 +
2249 + $empty_captcha_data = array(
2250 + 'recaptcha_force_v1' => '',
2251 + 'recaptcha_public_key' => '',
2252 + 'recaptcha_private_key' => '',
2253 + );
2254 +
2255 + $empty_analytics_data = array(
2256 + 'analytics_track_submit' => false,
2257 + 'analytics_track_fields' => false,
2258 + );
2259 +
2260 + $empty_anonymize_ip_data = array(
2261 + 'anonymize_ip_bytes' => 0,
2262 + );
2263 +
2264 + if($_SERVER['REQUEST_METHOD'] == 'POST' && !empty($_POST['accua_form_save_form_settings'])) {
2265 + check_admin_referer('accua_form_save_settings', '_nonce_accua_form_save_settings');
2266 + $post = stripslashes_deep($_POST);
2267 + $post += $empty_form_data;
2268 + $post += $empty_file_data;
2269 + $post += $empty_captcha_data;
2270 + $post += $empty_analytics_data;
2271 + $post += $empty_anonymize_ip_data;
2272 + $form_data = array();
2273 + $file_data = array();
2274 + $captcha_data = array();
2275 + $analytics_data = array();
2276 + $anonymize_ip_data = array();
2277 + foreach($empty_form_data as $key=>$val){
2278 + $form_data[$key] = $post[$key];
2279 + }
2280 + $form_data = accua_forms_filter_settings($form_data);
2281 +
2282 + $file_data['valid_extensions'] = accua_forms_filter_extensions($post['valid_extensions']);
2283 + $file_data['max_size'] = $post['max_size'];
2284 + if (current_user_can('edit_files') || current_user_can('install_plugins')) {
2285 + $file_data['dest_path'] = $post['dest_path'];
2286 + } else {
2287 + $old_file_data = get_option('accua_forms_default_file_field_data',array());
2288 + $file_data['dest_path'] = isset($old_file_data['dest_path']) ? $old_file_data['dest_path'] : '';
2289 + }
2290 +
2291 + $captcha_data['recaptcha_force_v1'] = (bool) $post['recaptcha_force_v1'];
2292 + $captcha_data['recaptcha_public_key'] = sanitize_text_field($post['recaptcha_public_key']);
2293 + $captcha_data['recaptcha_private_key'] = sanitize_text_field($post['recaptcha_private_key']);
2294 +
2295 + foreach($empty_analytics_data as $key=>$val){
2296 + $analytics_data[$key] = (bool) $post[$key];
2297 + }
2298 +
2299 + /* foreach($empty_anonymize_ip_data as $key=>$val){
2300 + $anonymize_ip_data[$key] = $post[$key];
2301 + } */
2302 + $anonymize_ip_bytes = (int) $post['anonymize_ip_bytes'];
2303 + if ($anonymize_ip_bytes < 0) {
2304 + $anonymize_ip_bytes = 0;
2305 + } else if ($anonymize_ip_bytes > 4) {
2306 + $anonymize_ip_bytes = 4;
2307 + }
2308 + $anonymize_ip_data['anonymize_ip_bytes'] = $anonymize_ip_bytes;
2309 +
2310 + update_option('accua_forms_default_form_data', $form_data);
2311 + update_option('accua_forms_default_file_field_data', $file_data);
2312 + update_option('accua_forms_default_captcha_field_data', $captcha_data);
2313 + update_option('accua_forms_default_analytics_data', $analytics_data);
2314 + update_option('accua_forms_anonymize_ip_data', $anonymize_ip_data);
2315 +
2316 + if (!empty($post['delete_previous_ip_values'])) {
2317 + global $wpdb;
2318 + $wpdb->query("UPDATE `{$wpdb->prefix}accua_forms_submissions` SET afs_ip = ''");
2319 + }
2320 + } else {
2321 + $form_data = get_option('accua_forms_default_form_data',array()) + $empty_form_data;
2322 + $file_data = get_option('accua_forms_default_file_field_data',array()) + $empty_file_data;
2323 + $captcha_data = get_option('accua_forms_default_captcha_field_data',array()) + $empty_captcha_data;
2324 + $analytics_data = get_option('accua_forms_default_analytics_data',array()) + $empty_analytics_data;
2325 + $anonymize_ip_data = get_option('accua_forms_anonymize_ip_data',array()) + $empty_anonymize_ip_data;
2326 + }
2327 + if ($captcha_data['recaptcha_force_v1']) {
2328 + $captcha_data = $empty_captcha_data;
2329 + }
2330 +?>
2331 +<form method="post">
2332 +<?php wp_nonce_field('accua_form_save_settings', '_nonce_accua_form_save_settings'); ?>
2333 +<input type="hidden" name="accua_form_save_form_settings" value="1" />
2334 +<?php /*
2335 +<p id="accua_form_layout"><?php _e( 'Layout', 'contact-forms'); ?>: <select name="layout" class="accua_form_value"><option value="sidebyside" <?php if ($form_data['layout'] == 'sidebyside') { echo 'selected="selected"'; } ?>>Labels on the left of the fields</option><option value="toplabel" <?php if ($form_data['layout'] == 'toplabel') { echo 'selected="selected"'; } ?>>Labels on top of the fields</option></select></p>
2336 +<p id="accua_form_success_message"><?php _e( 'Success message', 'contact-forms'); ?>:<br /><textarea name="success_message" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($form_data['success_message'], ENT_QUOTES) ?></textarea></p>
2337 +<p id="accua_form_error_message"><?php _e( 'Error message', 'contact-forms'); ?>:<br /><textarea name="error_message" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($form_data['error_message'], ENT_QUOTES) ?></textarea></p>
2338 +<p id="accua_form_emails_from"><?php _e( 'Emails from', 'contact-forms'); ?>: <input name="emails_from" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_from'], ENT_QUOTES) ?>" /></p>
2339 +<p id="accua_form_admin_emails_to"><?php _e( 'Admin emails to', 'contact-forms'); ?>: <input name="admin_emails_to" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_to'], ENT_QUOTES) ?>" /></p>
2340 +<p id="accua_form_emails_bcc"><?php _e( 'Emails bcc', 'contact-forms'); ?>: <input name="emails_bcc" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_bcc'], ENT_QUOTES) ?>" /></p>
2341 +<p id="accua_form_admin_emails_subject"><?php _e( 'Admin email subject', 'contact-forms'); ?>: <input name="admin_emails_subject" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_subject'], ENT_QUOTES) ?>" /></p>
2342 +<p id="accua_form_admin_emails_message"><?php _e( 'Admin email message', 'contact-forms'); ?>:<br /><textarea name="admin_emails_message" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($form_data['admin_emails_message'], ENT_QUOTES) ?></textarea></p>
2343 +<p id="accua_form_confirmation_emails_subject"><?php _e( 'Confirmation email subject', 'contact-forms'); ?>: <input name="confirmation_emails_subject" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['confirmation_emails_subject'], ENT_QUOTES) ?>" /></p>
2344 +<p id="accua_form_confirmation_emails_message"><?php _e( 'Confirmation email message', 'contact-forms'); ?>:<br /><textarea name="confirmation_emails_message" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($form_data['confirmation_emails_message'], ENT_QUOTES) ?></textarea></p>
2345 +*/ ?>
2346 +<div id="accua_tab_messages" class="content_tab">
2347 + <?php
2348 + $settings_editor = array(
2349 + 'teeny' => true,
2350 + 'editor_class' => 'accua_form_value',
2351 + 'tinymce' => array(
2352 + 'theme_advanced_buttons1' => 'bold,italic,underline,|,bullist,numlist,'));
2353 + ?>
2354 + <div class="metabox-holder accua-forms-metabox-holder">
2355 + <div class="postbox ">
2356 + <h3 class="hndle"><span><?php _e('1. On-screen success message', 'contact-forms'); ?></span></h3>
2357 + <div class="inside" id="dashboard_right_now">
2358 + <div id="accua_form_success_message">
2359 + <?php wp_editor( $form_data['success_message'] , 'success_message' , $settings_editor); ?>
2360 + </div>
2361 + </div>
2362 + </div>
2363 + </div>
2364 +
2365 + <div class="metabox-holder accua-forms-metabox-holder">
2366 + <div class="postbox ">
2367 + <h3 class="hndle"><span><?php _e('2. On-screen error message', 'contact-forms'); ?></span></h3>
2368 + <div class="inside" id="dashboard_right_now">
2369 + <div id="accua_form_error_message">
2370 + <?php wp_editor( $form_data['error_message'] , 'error_message' , $settings_editor); ?>
2371 + </div>
2372 + </div>
2373 + </div>
2374 + </div>
2375 + <br clear="all"/>
2376 + <div class="metabox-holder accua-forms-metabox-holder">
2377 + <div class="postbox ">
2378 + <h3 class="hndle"><span><?php _e('3. Email to notify administrator', 'contact-forms'); ?></span></h3>
2379 + <div class="inside" id="dashboard_right_now">
2380 + <div id="accua_form_admin_emails_to" class="label_input">
2381 + <label><?php _e( 'To', 'contact-forms'); ?></label>
2382 + <input name="admin_emails_to" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_to'], ENT_QUOTES) ?>" />
2383 + </div>
2384 + <br clear="all" />
2385 + <div id="accua_form_emails_bcc" class="label_input">
2386 + <label><?php _e( 'Bcc', 'contact-forms'); ?></label>
2387 + <input name="emails_bcc" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['emails_bcc'], ENT_QUOTES) ?>" />
2388 + </div>
2389 + <br clear="all" />
2390 + <div id="accua_form_admin_emails_subject" class="label_input">
2391 + <label><?php _e( 'Subject', 'contact-forms'); ?></label>
2392 + <input name="admin_emails_subject" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['admin_emails_subject'], ENT_QUOTES) ?>" />
2393 + </div>
2394 + <br clear="all" />
2395 + <div id="accua_form_admin_emails_message">
2396 + <?php wp_editor( $form_data['admin_emails_message'] , 'admin_emails_message' , $settings_editor); ?>
2397 + </div>
2398 +
2399 + </div>
2400 + </div>
2401 + </div>
2402 +
2403 + <div class="metabox-holder accua-forms-metabox-holder">
2404 + <div class="postbox ">
2405 + <h3 class="hndle"><span><?php _e('4. Email confirmation to the person who completed the form', 'contact-forms'); ?></span></h3>
2406 + <div class="inside" id="dashboard_right_now">
2407 + <div id="accua_form_emails_from_name" class="label_input">
2408 + <label><?php _e( 'From name', 'contact-forms'); ?></label>
2409 + <input class="accua_form_value" name="emails_from_name" type="text" value="<?php echo htmlspecialchars($form_data['emails_from_name'], ENT_QUOTES) ?>" />
2410 + </div>
2411 + <div id="accua_form_emails_from" class="label_input">
2412 + <label><?php _e( 'From email', 'contact-forms'); ?></label>
2413 + <input class="accua_form_value" name="emails_from" type="text" value="<?php echo htmlspecialchars($form_data['emails_from'], ENT_QUOTES) ?>" />
2414 + </div>
2415 + <br clear="all" />
2416 + <div id="accua_form_confirmation_emails_subject" class="label_input">
2417 + <label><?php _e( 'Subject', 'contact-forms'); ?></label>
2418 + <input class="accua_form_value" type="text" name="confirmation_emails_subject" value="<?php echo htmlspecialchars($form_data['confirmation_emails_subject'], ENT_QUOTES) ?>" />
2419 + </div>
2420 + <br clear="all" />
2421 + <div id="accua_form_confirmation_emails_message">
2422 + <?php wp_editor( $form_data['confirmation_emails_message'] , 'confirmation_emails_message' , $settings_editor); ?>
2423 + </div>
2424 + </div>
2425 + </div>
2426 + </div>
2427 + <br clear="all"/>
2428 +
2429 + <div class="metabox-holder accua-forms-metabox-holder">
2430 + <div class="postbox ">
2431 + <h3 class="hndle"><span><?php _e( 'File upload default settings', 'contact-forms'); ?></span></h3>
2432 + <div class="inside" id="dashboard_right_now">
2433 + <div id="accua_form_valid_extensions"><?php _e( 'Valid extensions', 'contact-forms'); ?> <br /><textarea name="valid_extensions" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($file_data['valid_extensions'], ENT_QUOTES) ?></textarea>
2434 + <small><?php _e( 'List of valid extensions, without dot, one per line.', 'contact-forms'); ?></small>
2435 + </div>
2436 + <div id="accua_form_max_size"><?php _e( 'Maximum file size:', 'contact-forms'); ?> <input name="max_size" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($file_data['max_size'], ENT_QUOTES) ?>" /><br />
2437 + <small><?php _e( 'You can use suffix K, M or G for kilobyte, megabyte or gigabyte.', 'contact-forms'); ?>
2438 + <?php
2439 + $server_max_size = AccuaForm_Element_File::file_upload_max_size();
2440 + if ($server_max_size > 0) {
2441 + _e( 'This value is limited by server upload limits of ', 'contact-forms');
2442 + echo AccuaForm_Element_File::format_size($server_max_size).". ";
2443 + _e( 'If you need a greater limit you should ask to the server administrator.', 'contact-forms');
2444 + }
2445 + ?>
2446 + </small>
2447 + </div>
2448 + <?php if (current_user_can('edit_files') || current_user_can('install_plugins')) { ?>
2449 + <div id="accua_form_dest_path"><?php _e( 'Upload path', 'contact-forms');?> : <input name="dest_path" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($file_data['dest_path'], ENT_QUOTES) ?>" />
2450 + <small><?php _e( 'If it stars with \'/\' an absolute path is used, otherwise a path relative to the WordPress installation directory. Default value is "wp-content/uploads/accua-forms"', 'contact-forms');?>.</small>
2451 + </div>
2452 + <?php } ?>
2453 + </div>
2454 + </div>
2455 +
2456 + <div class="postbox ">
2457 + <h3 class="hndle"><span><?php _e( 'reCaptcha settings', 'contact-forms'); ?></span></h3>
2458 + <div class="inside" id="dashboard_right_now">
2459 + <p><?php _e( 'As reCAPTCHA v1 is discontinued, only reCAPTCHA v2 is supported', 'contact-forms');?></p>
2460 + <p><?php echo strtr(__('Please register this site for reCAPTCHA v2 on %REGISTERURL%, then enter the keys for this site in the following fields', 'contact-forms'), array('%REGISTERURL%' => '<a href="https://www.google.com/recaptcha" target="_blank">google.com/recaptcha</a>'));?></p>
2461 + <div id="accua_form_recaptcha_public_key"><?php _e('Site key', 'contact-forms');?> : <input name="recaptcha_public_key" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($captcha_data['recaptcha_public_key'], ENT_QUOTES) ?>" />
2462 + </div>
2463 + <div id="accua_form_recaptcha_private_key"><?php _e('Secret key', 'contact-forms');?> : <input name="recaptcha_private_key" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($captcha_data['recaptcha_private_key'], ENT_QUOTES) ?>" />
2464 + </div>
2465 + </div>
2466 + </div>
2467 +
2468 + <div class="postbox ">
2469 + <h3 class="hndle"><span><?php _e( 'IP address tracking', 'contact-forms'); ?></span></h3>
2470 + <div class="inside" id="dashboard_accua_form_anonymize_ip_addresses">
2471 + <p>
2472 + <?php _e("Select how many bytes of the visitor's IPs should be masked.", 'contact-forms');?>
2473 + </p>
2474 + <p>
2475 + <input type="radio" name="anonymize_ip_bytes" id="anonymize_ip_bytes_0" value="0" <?php if($anonymize_ip_data['anonymize_ip_bytes'] == 0) { echo 'checked="checked"'; } ?> />
2476 + <label for="anonymize_ip_bytes_0"><?php _e('No mask - e.g. 192.168.1.1', 'contact-forms');?></label><br />
2477 + </p>
2478 + <p>
2479 + <input type="radio" name="anonymize_ip_bytes" id="anonymize_ip_bytes_1" value="1" <?php if($anonymize_ip_data['anonymize_ip_bytes'] == 1) { echo 'checked="checked"'; } ?> />
2480 + <label for="anonymize_ip_bytes_1"><?php _e('1 byte - e.g. 192.168.1.xxx', 'contact-forms');?></label><br />
2481 + </p>
2482 + <p>
2483 + <input type="radio" name="anonymize_ip_bytes" id="anonymize_ip_bytes_2" value="2" <?php if($anonymize_ip_data['anonymize_ip_bytes'] == 2) { echo 'checked="checked"'; } ?> />
2484 + <label for="anonymize_ip_bytes_2"><?php _e('2 byte - e.g. 192.168.xxx.xxx', 'contact-forms');?></label><br />
2485 + </p>
2486 + <p>
2487 + <input type="radio" name="anonymize_ip_bytes" id="anonymize_ip_bytes_3" value="3" <?php if($anonymize_ip_data['anonymize_ip_bytes'] == 3) { echo 'checked="checked"'; } ?> />
2488 + <label for="anonymize_ip_bytes_3"><?php _e('3 byte - e.g. 192.xxx.xxx.xxx', 'contact-forms');?></label><br />
2489 + </p>
2490 + <p>
2491 + <input type="radio" name="anonymize_ip_bytes" id="anonymize_ip_bytes_4" value="4" <?php if($anonymize_ip_data['anonymize_ip_bytes'] == 4) { echo 'checked="checked"'; } ?> />
2492 + <label for="anonymize_ip_bytes_4"><?php _e('Fully mask IP address', 'contact-forms');?></label><br />
2493 + </p>
2494 + <h4><?php _e( 'Delete IP addresses', 'contact-forms'); ?></h4>
2495 + <p>
2496 + <input type="checkbox" id="delete_previous_ip_values" name="delete_previous_ip_values" class="accua_form_value" value="1" />
2497 + <label for="delete_previous_ip_values"><?php _e('Delete all previous IP values', 'contact-forms');?></label><br />
2498 + </p>
2499 + <br clear="all">
2500 + </div>
2501 + </div>
2502 +
2503 + <div class="postbox ">
2504 + <h3 class="hndle"><span><?php _e( 'Track actions with Google Analytics', 'contact-forms'); ?></span></h3>
2505 + <div class="inside" id="dashboard_right_now">
2506 + <p>
2507 + <input type="checkbox" id="accua_form_analytics_track_submit" name="analytics_track_submit" class="accua_form_value" value="1" <?php if($analytics_data['analytics_track_submit']) { echo 'checked="checked"'; } ?> />
2508 + <label for="accua_form_analytics_track_submit"><?php _e('Track submissions', 'contact-forms');?></label>
2509 + </p>
2510 + <p>
2511 + <input type="checkbox" id="accua_form_analytics_track_fields" name="analytics_track_fields" class="accua_form_value" value="1" <?php if($analytics_data['analytics_track_fields']) { echo 'checked="checked"'; } ?> />
2512 + <label for="accua_form_analytics_track_fields"><?php _e('Track fields filled in', 'contact-forms');?></label>
2513 + </p>
2514 + </div>
2515 + </div>
2516 +
2517 + </div>
2518 +
2519 + <div class="metabox-holder accua-forms-metabox-holder">
2520 + <div class="postbox ">
2521 + <h3 class="hndle"><span><?php _e( 'Layout &amp; Styling', 'contact-forms'); ?></span></h3>
2522 + <div class="inside" id="dashboard_right_now">
2523 + <p><?php _e( 'Customize the look and feel of your forms. Leave fields empty if you wish to use the native styles of your WordPress Theme.', 'contact-forms'); ?><p>
2524 + <h4><?php _e( 'Forms', 'contact-forms'); ?></h4>
2525 + <div id="accua_form_layout"> <?php _e( 'Layout', 'contact-forms'); ?>
2526 + <select name="layout" class="accua_form_value"><option value="sidebyside" <?php if ($form_data['layout'] == 'sidebyside') { echo 'selected="selected"'; } ?>>Labels on the left of the fields</option><option value="toplabel" <?php if ($form_data['layout'] == 'toplabel') { echo 'selected="selected"'; } ?>>Labels on top of the fields</option></select>
2527 + </div>
2528 + <div id="accua_form_style_margin" class="label_input">
2529 + <label><?php _e( 'Margin', 'contact-forms'); ?></label>
2530 + <input name="style_margin" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_margin'], ENT_QUOTES) ?>" />
2531 + </div>
2532 + <div id="accua_form_style_border_color" class="label_input">
2533 + <label><?php _e( 'Border color', 'contact-forms'); ?></label>
2534 + <input name="style_border_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_color'], ENT_QUOTES) ?>" />
2535 + </div>
2536 + <div id="accua_form_style_border_width" class="label_input">
2537 + <label><?php _e( 'Border width', 'contact-forms'); ?></label>
2538 + <input name="style_border_width" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_width'], ENT_QUOTES) ?>" />
2539 + </div>
2540 + <div id="accua_form_style_border_radius" class="label_input">
2541 + <label><?php _e( 'Rounded corner radius', 'contact-forms'); ?></label>
2542 + <input name="style_border_radius" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_border_radius'], ENT_QUOTES) ?>" />
2543 + </div>
2544 + <div id="accua_form_style_background_color" class="label_input">
2545 + <label><?php _e( 'Background color', 'contact-forms'); ?></label>
2546 + <input name="style_background_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_background_color'], ENT_QUOTES) ?>" />
2547 + </div>
2548 + <div id="accua_form_style_padding" class="label_input">
2549 + <label><?php _e( 'Padding', 'contact-forms'); ?></label>
2550 + <input name="style_padding" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_padding'], ENT_QUOTES) ?>" />
2551 + </div>
2552 + <div id="accua_form_style_color" class="label_input">
2553 + <label><?php _e( 'Text color', 'contact-forms'); ?></label>
2554 + <input name="style_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_color'], ENT_QUOTES) ?>" />
2555 + </div>
2556 + <div id="accua_form_style_font_size" class="label_input">
2557 + <label><?php _e( 'Font size', 'contact-forms'); ?></label>
2558 + <input name="style_font_size" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_font_size'], ENT_QUOTES) ?>" />
2559 + </div>
2560 +
2561 + <h4><?php _e( 'Fields', 'contact-forms'); ?></h4>
2562 + <div id="accua_form_style_field_spacing" class="label_input">
2563 + <label><?php _e( 'Spacing', 'contact-forms'); ?></label>
2564 + <input name="style_field_spacing" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_spacing'], ENT_QUOTES) ?>" />
2565 + </div>
2566 + <div id="accua_form_style_field_border_color" class="label_input">
2567 + <label><?php _e( 'Border color', 'contact-forms'); ?></label>
2568 + <input name="style_field_border_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_color'], ENT_QUOTES) ?>" />
2569 + </div>
2570 + <div id="accua_form_style_field_border_width" class="label_input">
2571 + <label><?php _e( 'Border width', 'contact-forms'); ?></label>
2572 + <input name="style_field_border_width" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_width'], ENT_QUOTES) ?>" />
2573 + </div>
2574 + <div id="accua_form_style_field_border_radius" class="label_input">
2575 + <label><?php _e( 'Rounded corner radius', 'contact-forms'); ?></label>
2576 + <input name="style_field_border_radius" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_border_radius'], ENT_QUOTES) ?>" />
2577 + </div>
2578 + <div id="accua_form_style_field_background_color" class="label_input">
2579 + <label><?php _e( 'Background color', 'contact-forms'); ?></label>
2580 + <input name="style_field_background_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_background_color'], ENT_QUOTES) ?>" />
2581 + </div>
2582 + <div id="accua_form_style_field_padding" class="label_input">
2583 + <label><?php _e( 'Padding', 'contact-forms'); ?></label>
2584 + <input name="style_field_padding" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_padding'], ENT_QUOTES) ?>" />
2585 + </div>
2586 + <div id="accua_form_style_field_color" class="label_input">
2587 + <label><?php _e( 'Text color', 'contact-forms'); ?></label>
2588 + <input name="style_field_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_field_color'], ENT_QUOTES) ?>" />
2589 + </div>
2590 +
2591 + <h4><?php _e( 'Submit button', 'contact-forms'); ?></h4>
2592 + <div id="accua_form_style_submit_border_color" class="label_input">
2593 + <label><?php _e( 'Border color', 'contact-forms'); ?></label>
2594 + <input name="style_submit_border_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_color'], ENT_QUOTES) ?>" />
2595 + </div>
2596 + <div id="accua_form_style_submit_border_width" class="label_input">
2597 + <label><?php _e( 'Border width', 'contact-forms'); ?></label>
2598 + <input name="style_submit_border_width" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_width'], ENT_QUOTES) ?>" />
2599 + </div>
2600 + <div id="accua_form_style_submit_border_radius" class="label_input">
2601 + <label><?php _e( 'Rounded corner radius', 'contact-forms'); ?></label>
2602 + <input name="style_submit_border_radius" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_border_radius'], ENT_QUOTES) ?>" />
2603 + </div>
2604 + <div id="accua_form_style_submit_background_color" class="label_input">
2605 + <label><?php _e( 'Background color', 'contact-forms'); ?></label>
2606 + <input name="style_submit_background_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_background_color'], ENT_QUOTES) ?>" />
2607 + </div>
2608 + <div id="accua_form_style_submit_padding" class="label_input">
2609 + <label><?php _e( 'Padding', 'contact-forms'); ?></label>
2610 + <input name="style_submit_padding" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_padding'], ENT_QUOTES) ?>" />
2611 + </div>
2612 + <div id="accua_form_style_submit_color" class="label_input">
2613 + <label><?php _e( 'Text color', 'contact-forms'); ?></label>
2614 + <input name="style_submit_color" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_color'], ENT_QUOTES) ?>" />
2615 + </div>
2616 + <div id="accua_form_style_submit_font_size" class="label_input">
2617 + <label><?php _e( 'Font size', 'contact-forms'); ?></label>
2618 + <input name="style_submit_font_size" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($form_data['style_submit_font_size'], ENT_QUOTES) ?>" />
2619 + </div>
2620 + <br clear="all" />
2621 + </div>
2622 + </div>
2623 + </div>
2624 +
2625 +
2626 + <br clear="all"/>
2627 +
2628 +</div>
2629 +
2630 +<?php /*
2631 +<h3><?php _e( 'File upload default settings', 'contact-forms'); ?></h3>
2632 +<p id="accua_form_valid_extensions"><?php _e( 'Valid extensions', 'contact-forms'); ?> <br /><textarea name="valid_extensions" class="accua_form_value" style="width:95%"; cols="80" rows="8"><?php echo htmlspecialchars($file_data['valid_extensions'], ENT_QUOTES) ?></textarea>
2633 + <small><?php _e( 'List of valid extensions, without dot, one per line.', 'contact-forms'); ?></small>
2634 +</p>
2635 +<p id="accua_form_max_size"><?php _e( 'Maximum file size:', 'contact-forms'); ?> <input name="max_size" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($file_data['max_size'], ENT_QUOTES) ?>" /><br />
2636 + <small><?php _e( 'You can use suffix K, M or G for kilobyte, megabyte or gigabyte.', 'contact-forms'); ?>
2637 +<?php
2638 + $server_max_size = AccuaForm_Element_File::file_upload_max_size();
2639 + if ($server_max_size > 0) {
2640 + _e( 'This value is limited by server upload limits of ', 'contact-forms');
2641 + echo AccuaForm_Element_File::format_size($server_max_size).". ";
2642 + _e( 'If you need a greater limit you should ask to the server administrator.', 'contact-forms');
2643 + }
2644 +?>
2645 + </small></p>
2646 +<p id="accua_form_dest_path"><?php _e( 'Upload path', 'contact-forms');?> : <input name="dest_path" class="accua_form_value" type="text" value="<?php echo htmlspecialchars($file_data['dest_path'], ENT_QUOTES) ?>" />
2647 + <small><?php _e( 'If it stars with \'/\' an absolute path is used, otherwise a path relative to the WordPress installation directory. Default value is "wp-content/uploads/accua-forms"', 'contact-forms');?>.</small>
2648 +</p> */ ?>
2649 +<p><input class="button button-primary button-large" id="accua_form_save_settings" type="submit" value="Save settings" /></p>
2650 +
2651 +<?php accua_forms_print_tokens(); ?>
2652 +
2653 +</form>
2654 +</div>
2655 +
2656 +<script type='text/javascript'>
2657 +jQuery(function($) {
2658 + $('#accua_form_style_border_color .accua_form_value').colorPicker();
2659 + $('#accua_form_style_background_color .accua_form_value').colorPicker();
2660 + $('#accua_form_style_color .accua_form_value').colorPicker();
2661 + $('#accua_form_style_field_border_color .accua_form_value').colorPicker();
2662 + $('#accua_form_style_field_background_color .accua_form_value').colorPicker();
2663 + $('#accua_form_style_field_color .accua_form_value').colorPicker();
2664 + $('#accua_form_style_submit_border_color .accua_form_value').colorPicker();
2665 + $('#accua_form_style_submit_background_color .accua_form_value').colorPicker();
2666 + $('#accua_form_style_submit_color .accua_form_value').colorPicker();
2667 +});
2668 +</script>
2669 +
2670 +<?php
2671 +}
2672 +
1499 2673 function _accua_forms_get_abs_dest_path($dest_path = '') {
1500 2674 if ($dest_path === '') {
1501 2675 return realpath(ABSPATH) . '/wp-content/uploads/accua-forms';
1502 - } elseif (substr($dest_path,0,1) === '/') {
2676 + } else if (substr($dest_path,0,1) === '/') {
1503 2677 return $dest_path;
1504 2678 } else {
1505 2679 return realpath(ABSPATH) . '/' . $dest_path;
1506 2680 }
@@ -1505,9 +2679,8 @@
1505 2679 return realpath(ABSPATH) . '/' . $dest_path;
1506 2680 }
1507 2681 }
1508 2682
1509 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function, underscore prefix indicates private
1510 2683 function _accua_forms_get_form_data($fid = false, $return_empty = true, $restore_trash = false){
1511 2684 $empty_form_data = array(
1512 2685 'fields' => array(),
1513 2686 'title' => '',
@@ -1521,9 +2694,8 @@
1521 2694 'admin_emails_message' => '',
1522 2695 'confirmation_emails_subject' => '',
1523 2696 'confirmation_emails_message' => '',
1524 2697 'use_ajax' => true,
1525 - 'gads_conversion_tracking_code' => '',
1526 2698 'layout' => 'sidebyside',
1527 2699 'style_margin' => '',
1528 2700 'style_border_color' => '',
1529 2701 'style_border_width' => '',
@@ -1545,12 +2717,8 @@
1545 2717 'style_submit_background_color' => '',
1546 2718 'style_submit_padding' => '',
1547 2719 'style_submit_color' => '',
1548 2720 'style_submit_font_size' => '',
1549 - 'submission_retention_override' => false,
1550 - 'submission_retention_value' => 0,
1551 - 'submission_retention_unit' => 'months',
1552 - 'submission_retention_mode' => 'anonymize',
1553 2721 );
1554 2722
1555 2723 if ($fid === false) {
1556 2724 return $empty_form_data;
@@ -1576,10 +2744,17 @@
1576 2744 if (isset($forms_data[$fid])) {
1577 2745 $form_data = array(
1578 2746 '_overrided' => $forms_data[$fid]
1579 2747 ) + $forms_data[$fid] + $default_form_data + $empty_form_data;
2748 + /*
2749 + if ($form_data['fields']) {
2750 + foreach ($form_data['fields'] as $i => $istance_data) {
2751 + // TODO: popuplate default fields data?
2752 + }
2753 + }
2754 + */
1580 2755 return $form_data;
1581 - } elseif ($return_empty) {
2756 + } else if ($return_empty) {
1582 2757 return array(
1583 2758 '_overrided' => array()
1584 2759 ) + $default_form_data + $empty_form_data;
1585 2760 } else {
@@ -1587,174 +2762,8 @@
1587 2762 }
1588 2763
1589 2764 }
1590 2765
1591 -/**
1592 - * Draft System Functions
1593 - *
1594 - * The draft system allows users to make changes to forms in the admin editor
1595 - * without immediately affecting the live/published form. Changes are stored in
1596 - * a transient until the user clicks Save, which publishes the draft.
1597 - *
1598 - * Pattern follows WordPress auto-draft system.
1599 - */
1600 -
1601 -/**
1602 - * Get the transient key for a form's draft data.
1603 - *
1604 - * @param string|int $fid Form ID.
1605 - * @return string Transient key.
1606 - */
1607 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1608 -function _accua_forms_get_draft_key( $fid ) {
1609 - return 'accua_forms_draft_' . $fid;
1610 -}
1611 -
1612 -/**
1613 - * Initialize or get existing draft for a form.
1614 - * Called when the form editor is loaded.
1615 - *
1616 - * If a draft exists, returns it.
1617 - * If no draft exists, creates one from published data.
1618 - *
1619 - * @param string|int $fid Form ID.
1620 - * @return array Draft data array.
1621 - */
1622 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1623 -function _accua_forms_init_draft( $fid ) {
1624 - $draft_key = _accua_forms_get_draft_key( $fid );
1625 -
1626 - // Check for existing draft
1627 - $draft_data = get_transient( $draft_key );
1628 -
1629 - if ( $draft_data !== false ) {
1630 - // Draft exists - return it
1631 - return $draft_data;
1632 - }
1633 -
1634 - // No draft - create from published data
1635 - $forms_data = get_option( 'accua_forms_saved_forms', array() );
1636 -
1637 - if ( isset( $forms_data[ $fid ] ) ) {
1638 - $draft_data = $forms_data[ $fid ];
1639 - } else {
1640 - // New form - initialize empty structure
1641 - $draft_data = array( 'fields' => array() );
1642 - }
1643 -
1644 - // Store as draft with 24 hour expiry
1645 - set_transient( $draft_key, $draft_data, DAY_IN_SECONDS );
1646 -
1647 - return $draft_data;
1648 -}
1649 -
1650 -/**
1651 - * Get draft data for a form (creating if necessary).
1652 - * Used by AJAX handlers to read current draft state.
1653 - *
1654 - * @param string|int $fid Form ID.
1655 - * @return array Draft data array.
1656 - */
1657 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1658 -function _accua_forms_get_draft_data( $fid ) {
1659 - $draft_key = _accua_forms_get_draft_key( $fid );
1660 - $draft_data = get_transient( $draft_key );
1661 -
1662 - if ( $draft_data === false ) {
1663 - // Initialize draft from published data
1664 - $draft_data = _accua_forms_init_draft( $fid );
1665 - }
1666 -
1667 - return $draft_data;
1668 -}
1669 -
1670 -/**
1671 - * Save data to draft transient.
1672 - * Called by AJAX handlers when fields are edited.
1673 - *
1674 - * @param string|int $fid Form ID.
1675 - * @param array $draft_data Complete draft data to save.
1676 - * @return bool True on success.
1677 - */
1678 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1679 -function _accua_forms_save_draft( $fid, $draft_data ) {
1680 - $draft_key = _accua_forms_get_draft_key( $fid );
1681 - return set_transient( $draft_key, $draft_data, DAY_IN_SECONDS );
1682 -}
1683 -
1684 -/**
1685 - * Publish draft to live data.
1686 - * Called when user clicks Save button.
1687 - *
1688 - * @param string|int $fid Form ID.
1689 - * @return bool True on success.
1690 - */
1691 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1692 -function _accua_forms_publish_draft( $fid ) {
1693 - $draft_key = _accua_forms_get_draft_key( $fid );
1694 - $draft_data = get_transient( $draft_key );
1695 -
1696 - if ( $draft_data === false ) {
1697 - // No draft to publish - shouldn't happen normally
1698 - return false;
1699 - }
1700 -
1701 - // Get current published data
1702 - $forms_data = get_option( 'accua_forms_saved_forms', array() );
1703 -
1704 - // Update with draft
1705 - $forms_data[ $fid ] = $draft_data;
1706 -
1707 - // Save to database
1708 - $result = update_option( 'accua_forms_saved_forms', $forms_data );
1709 -
1710 - if ( $result ) {
1711 - // Clear draft after successful publish
1712 - delete_transient( $draft_key );
1713 - }
1714 -
1715 - return $result;
1716 -}
1717 -
1718 -/**
1719 - * Delete draft for a form.
1720 - * Called when discarding changes or after successful publish.
1721 - *
1722 - * @param string|int $fid Form ID.
1723 - * @return bool True on success.
1724 - */
1725 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1726 -function _accua_forms_delete_draft( $fid ) {
1727 - $draft_key = _accua_forms_get_draft_key( $fid );
1728 - return delete_transient( $draft_key );
1729 -}
1730 -
1731 -/**
1732 - * Check if a draft exists and differs from published data.
1733 - * Used to show "unsaved changes" warning.
1734 - *
1735 - * @param string|int $fid Form ID.
1736 - * @return bool True if draft exists and differs from published.
1737 - */
1738 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function
1739 -function _accua_forms_has_unsaved_draft( $fid ) {
1740 - $draft_key = _accua_forms_get_draft_key( $fid );
1741 - $draft_data = get_transient( $draft_key );
1742 -
1743 - if ( $draft_data === false ) {
1744 - return false;
1745 - }
1746 -
1747 - // Compare with published data
1748 - $forms_data = get_option( 'accua_forms_saved_forms', array() );
1749 - $published_data = isset( $forms_data[ $fid ] ) ? $forms_data[ $fid ] : array();
1750 -
1751 - // Deep comparison (serialize for simplicity)
1752 - // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.serialize_serialize -- Used for comparison only
1753 - return serialize( $draft_data ) !== serialize( $published_data );
1754 -}
1755 -
1756 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function, underscore prefix indicates private
1757 2766 function _accua_forms_style_parameters($params) {
1758 2767 $ret = '';
1759 2768 foreach ($params as $key => $value) {
1760 2769 $value = trim($value);
@@ -1778,23 +2787,9 @@
1778 2787 add_action('accua_form_alter', 'accua_forms_form_generate', -999, 2);
1779 2788 function accua_forms_form_generate($baseid, $form) {
1780 2789 if (substr($baseid, 0, 14) == '__accua-form__') {
1781 2790 $fid = substr($baseid,14);
1782 -
1783 - // Check if we're in admin preview mode - if so, read from draft
1784 - $use_draft = apply_filters('accua_forms_use_draft_for_preview', false);
1785 - if ($use_draft) {
1786 - // Get draft data and merge with defaults
1787 - $draft_data = _accua_forms_get_draft_data($fid);
1788 - $default_form_data = get_option('accua_forms_default_form_data', array());
1789 - $empty_form_data = _accua_forms_get_form_data(false); // Get empty structure
1790 - $form_data = array(
1791 - '_overrided' => $draft_data
1792 - ) + $draft_data + $default_form_data + $empty_form_data;
1793 - } else {
1794 - // Frontend: read from published data
1795 - $form_data = _accua_forms_get_form_data($fid, false);
1796 - }
2791 + $form_data = _accua_forms_get_form_data($fid, false);
1797 2792 /*
1798 2793 echo '<!-- fid = ';
1799 2794 print_r($fid);
1800 2795 echo "\n\nform_data = ";
@@ -1801,45 +2796,14 @@
1801 2796 print_r($form_data);
1802 2797 echo "\n-->";
1803 2798 */
1804 2799 if ($form_data) {
1805 - // Check for preview order override (allows live preview of field reorder before save)
1806 - $preview_order_override = apply_filters('accua_forms_preview_order_override', null);
1807 - if ($preview_order_override && !empty($form_data['fields'])) {
1808 - // Find the sidebar key for this form (format: cimatti-accua-fields-form-area-{fid})
1809 - $sidebar_key = 'cimatti-accua-fields-form-area-' . $fid;
1810 - if (isset($preview_order_override[$sidebar_key])) {
1811 - $order_string = $preview_order_override[$sidebar_key];
1812 - $order_array = explode(',', $order_string);
1813 -
1814 - // Reorder fields according to preview order
1815 - $old_fields = $form_data['fields'];
1816 - $new_fields = array();;
1817 -
1818 - foreach ($order_array as $widget_id) {
1819 - // Extract instance ID from widget ID (format: widget-{type}_{instance_id})
1820 - $instance_id = preg_replace('/^(new-)?widget-\\d+_/', '', $widget_id);
1821 - if (isset($old_fields[$instance_id])) {
1822 - $new_fields[$instance_id] = $old_fields[$instance_id];
1823 - unset($old_fields[$instance_id]);
1824 - }
1825 - }
1826 -
1827 - // Append any remaining fields not in order
1828 - if ($old_fields) {
1829 - $new_fields += $old_fields;
1830 - }
1831 -
1832 - $form_data['fields'] = $new_fields;
1833 - }
1834 - }
1835 -
1836 2800 $form_style = _accua_forms_style_parameters(array(
1837 2801 'margin' => $form_data['style_margin'],
1838 2802 'border-color' => $form_data['style_border_color'],
1839 2803 'border-width' => $form_data['style_border_width'],
1840 2804 'border-radius' => $form_data['style_border_radius'],
1841 - 'background-color' => $form_data['style_background_color'],
2805 + 'background' => $form_data['style_background_color'],
1842 2806 'padding' => $form_data['style_padding'],
1843 2807 'color' => $form_data['style_color'],
1844 2808 'font-size' => $form_data['style_font_size'],
1845 2809 ));
@@ -1848,9 +2812,9 @@
1848 2812 'margin-bottom' => $form_data['style_field_spacing'],
1849 2813 'border-color' => $form_data['style_field_border_color'],
1850 2814 'border-width' => $form_data['style_field_border_width'],
1851 2815 'border-radius' => $form_data['style_field_border_radius'],
1852 - 'background-color' => $form_data['style_field_background_color'],
2816 + 'background' => (trim($form_data['style_field_background_color']) === '')?'transparent':$form_data['style_field_background_color'],
1853 2817 'padding' => $form_data['style_field_padding'],
1854 2818 'color' => (trim($form_data['style_field_color']) === '')?$form_data['style_color']:$form_data['style_field_color'],
1855 2819 'font-size' => $form_data['style_font_size'],
1856 2820 ));
@@ -1857,17 +2821,14 @@
1857 2821 $field_properties = array();
1858 2822 if ($field_style !== '') {
1859 2823 $field_properties['style'] = $field_style;
1860 2824 }
1861 - // These will be set per-field in the loop below, initialized empty here
1862 - $field_properties['wrapperCssClass'] = '';
1863 - $field_properties['wrapperCssId'] = '';
1864 2825
1865 2826 $submit_style = _accua_forms_style_parameters(array(
1866 2827 'border-color' => $form_data['style_submit_border_color'],
1867 2828 'border-width' => $form_data['style_submit_border_width'],
1868 2829 'border-radius' => $form_data['style_submit_border_radius'],
1869 - 'background-color' => $form_data['style_submit_background_color'],
2830 + 'background' => $form_data['style_submit_background_color'],
1870 2831 'padding' => $form_data['style_submit_padding'],
1871 2832 'color' => $form_data['style_submit_color'],
1872 2833 'font-size' => $form_data['style_submit_font_size'],
1873 2834 ));
@@ -1900,9 +2861,9 @@
1900 2861 'name' => __('Fieldset begin', 'contact-forms'),
1901 2862 'type' => 'fieldset-begin',
1902 2863 'description' => '',
1903 2864 );
1904 - } elseif ($istance_data['ref'] == '__fieldset-end') {
2865 + } else if ($istance_data['ref'] == '__fieldset-end') {
1905 2866 $field_data = array(
1906 2867 'id' => '__fieldset-end',
1907 2868 'name' => __('Fieldset end', 'contact-forms'),
1908 2869 'type' => 'fieldset-end',
@@ -1922,10 +2883,8 @@
1922 2883 'description' => __('Use this special field to inject raw HTML in the form. You can use this multiple times.', 'contact-forms'),
1923 2884 'default_value' => '',
1924 2885 'allowed_values' => '',
1925 2886 'allowed_extensions' => '',
1926 - 'custom_required_message' => '',
1927 - 'custom_format_message' => '',
1928 2887 );
1929 2888
1930 2889 $istance_data += array(
1931 2890 'version' => 1,
@@ -1959,13 +2918,8 @@
1959 2918 'label' => $field_data['name'],
1960 2919 'default_value' => $field_data['default_value'], /* viene impostato il valore di defualt se non è un campo data */
1961 2920 'allowed_values' => $field_data['allowed_values'],
1962 2921 'allowed_extensions' => $field_data['allowed_extensions'],
1963 - 'post_type' => 'page', // Default for post-select fields
1964 - 'css_class' => '',
1965 - 'css_id' => '',
1966 - 'custom_required_message' => '',
1967 - 'custom_format_message' => '',
1968 2922 );
1969 2923
1970 2924 $element = NULL;
1971 2925 $element_conf = NULL;
@@ -1971,45 +2925,15 @@
1971 2925 $element_conf = NULL;
1972 2926
1973 2927 $allowed_val = trim($istance_data['allowed_values']);
1974 2928
1975 - // For post-select fields, we use lazy loading via AJAX, so don't pre-load posts here
1976 - if ($field_data['type'] == 'post-multicheckbox') {
1977 - // Post-multicheckbox still needs pre-loaded options for checkbox rendering
1978 - $post_type = isset($istance_data['post_type']) ? $istance_data['post_type'] : 'page';
1979 - $query_args = array();
1980 - if (!empty($allowed_val)) {
1981 - wp_parse_str($allowed_val, $query_args);
1982 - }
1983 - // Let a post_type in the query parameters override the field's
1984 - // post-type setting, matching post-select. The value comes from the
1985 - // saved field configuration (not a client request) and is validated
1986 - // against public post types.
1987 - if (!empty($query_args['post_type'])) {
1988 - $mc_public_types = get_post_types(array('public' => true));
1989 - $mc_override = sanitize_text_field($query_args['post_type']);
1990 - if (isset($mc_public_types[$mc_override])) {
1991 - $post_type = $mc_override;
1992 - }
1993 - }
1994 - $query_args['post_type'] = $post_type;
1995 - // Only publish/private may be exposed, even if the admin configured other statuses.
1996 - if (!empty($query_args['post_status'])) {
1997 - $mc_statuses = accua_forms_filter_field_post_status($query_args['post_status']);
1998 - if (!empty($mc_statuses)) {
1999 - $query_args['post_status'] = $mc_statuses;
2000 - } else {
2001 - unset($query_args['post_status']);
2002 - }
2003 - }
2004 - $posts = accua_get_pages($query_args);
2929 + if ($field_data['type'] == 'post-multicheckbox' || $field_data['type'] == 'post-select') {
2930 + $posts = accua_get_pages($allowed_val);
2005 2931 $allowed_values = array();
2006 2932 foreach ($posts as $p) {
2933 + //$allowed_values[$p->ID] = apply_filters( 'the_title', $p->post_title, $p->ID );
2007 2934 $allowed_values[$p->ID] = $p->post_title;
2008 2935 }
2009 - } elseif ($field_data['type'] == 'post-select') {
2010 - // Post-select uses lazy loading - just set empty options, JS will fetch
2011 - $allowed_values = array();
2012 2936 } else {
2013 2937 if ($field_data['type'] == 'file') {
2014 2938 $filedata = get_option('accua_forms_default_file_field_data',array());
2015 2939 $filedata += array(
@@ -2043,47 +2967,14 @@
2043 2967 $allowed_values[$val[0]] = $val[1];
2044 2968 }
2045 2969 }
2046 2970
2047 - // Set per-field wrapper CSS class and ID
2048 - $field_properties['wrapperCssClass'] = isset($istance_data['css_class']) ? $istance_data['css_class'] : '';
2049 - $field_properties['wrapperCssId'] = isset($istance_data['css_id']) ? $istance_data['css_id'] : '';
2050 -
2051 - // Resolve per-field custom validation messages (per-form instance → field definition → default)
2052 - $resolved_required_msg = '';
2053 - if (!empty($istance_data['custom_required_message'])) {
2054 - $resolved_required_msg = $istance_data['custom_required_message'];
2055 - } elseif (!empty($field_data['custom_required_message'])) {
2056 - $resolved_required_msg = $field_data['custom_required_message'];
2057 - }
2058 -
2059 - $resolved_format_msg = '';
2060 - if (!empty($istance_data['custom_format_message'])) {
2061 - $resolved_format_msg = $istance_data['custom_format_message'];
2062 - } elseif (!empty($field_data['custom_format_message'])) {
2063 - $resolved_format_msg = $field_data['custom_format_message'];
2064 - }
2065 -
2066 - // Add data attributes for client-side custom messages (reset each iteration)
2067 - unset($field_properties['data-custom-required-msg']);
2068 - unset($field_properties['data-custom-format-msg']);
2069 - if ($resolved_required_msg !== '') {
2070 - $field_properties['data-custom-required-msg'] = $resolved_required_msg;
2071 - }
2072 - if ($resolved_format_msg !== '') {
2073 - $field_properties['data-custom-format-msg'] = $resolved_format_msg;
2074 - }
2075 -
2076 2971 switch ($field_data['type']) {
2077 2972 case 'textarea':
2078 2973 $element = new Element_Textarea($istance_data['label'], $istance_data['istance_id'], $field_properties+array('cols' => '50', 'value'=>$istance_data['default_value']));
2079 2974 break;
2080 2975 case 'hidden':
2081 - $hidden_props = array();
2082 - if ( !empty($field_properties['wrapperCssId']) ) {
2083 - $hidden_props['id'] = $field_properties['wrapperCssId'];
2084 - }
2085 - $element = new Element_Hidden($istance_data['istance_id'], $istance_data['default_value'], !empty($hidden_props) ? $hidden_props : null);
2976 + $element = new Element_Hidden($istance_data['istance_id'], $istance_data['default_value']);
2086 2977 break;
2087 2978 case 'checkbox':
2088 2979 $lab = $istance_data['label'];
2089 2980 if (!empty($istance_data['required'])) {
@@ -2092,17 +2983,18 @@
2092 2983 if ($allowed_values) {
2093 2984 reset($allowed_values);
2094 2985 $val = (string) key($allowed_values);
2095 2986 $defval = trim($istance_data['default_value']);
2096 - } elseif ($istance_data['default_value'] == '1') {
2987 + } else if ($istance_data['default_value'] == '1') {
2097 2988 $defval = $val = '1';
2098 2989 } else {
2099 2990 $val = empty($istance_data['default_value'])?'1':$istance_data['default_value'];
2100 2991 $defval = '';
2101 2992 }
2102 - $element = new AccuaForm_Element_Checkbox('', $istance_data['istance_id'], array($val => $lab), $field_properties+array('value' => $defval));
2993 + $element = new AccuaForm_Element_Checkbox('', $istance_data['istance_id'], array($val => $lab), array('value' => $defval));
2103 2994 break;
2104 2995 case 'select':
2996 + case 'post-select':
2105 2997 if (!isset($allowed_values[''])) {
2106 2998 $allowed_values = array('' => '') + $allowed_values;
2107 2999 }
2108 3000 $defval = trim($istance_data['default_value']);
@@ -2107,17 +2999,11 @@
2107 2999 }
2108 3000 $defval = trim($istance_data['default_value']);
2109 3001 $element = new AccuaForm_Element_Select($istance_data['label'], $istance_data['istance_id'], $allowed_values, $field_properties+array('value'=>$defval));
2110 3002 break;
2111 - case 'post-select':
2112 - $post_type = isset($istance_data['post_type']) ? $istance_data['post_type'] : 'page';
2113 - $extra_args = trim($istance_data['allowed_values']);
2114 - $defval = trim($istance_data['default_value']);
2115 - $element = new AccuaForm_Element_PostSelect($istance_data['label'], $istance_data['istance_id'], $post_type, $extra_args, $field_properties+array('value'=>$defval));
2116 - break;
2117 3003 case 'radio':
2118 3004 $defval = trim($istance_data['default_value']);
2119 - $element = new AccuaForm_Element_Radio($istance_data['label'], $istance_data['istance_id'], $allowed_values, $field_properties+array('value'=>$defval));
3005 + $element = new AccuaForm_Element_Radio($istance_data['label'], $istance_data['istance_id'], $allowed_values, array('value'=>$defval));
2120 3006 break;
2121 3007 case 'multiselect':
2122 3008 $defval = explode('|', $istance_data['default_value']);
2123 3009 foreach ($defval as $k => $v) {
@@ -2130,9 +3016,9 @@
2130 3016 $defval = explode('|', $istance_data['default_value']);
2131 3017 foreach ($defval as $k => $v) {
2132 3018 $defval[$k] = trim($v);
2133 3019 }
2134 - $element = new AccuaForm_Element_Checkbox($istance_data['label'], $istance_data['istance_id'], $allowed_values, $field_properties+array('value'=>$defval));
3020 + $element = new AccuaForm_Element_Checkbox($istance_data['label'], $istance_data['istance_id'], $allowed_values, array('value'=>$defval));
2135 3021 break;
2136 3022 case 'file':
2137 3023 $fdata = array();
2138 3024
@@ -2148,17 +3034,17 @@
2148 3034
2149 3035 $element = new AccuaForm_Element_File($istance_data['label'], $istance_data['istance_id'], $field_properties+$fdata);
2150 3036 break;
2151 3037 case 'html':
2152 - $element = new Element_HTML($istance_data['default_value'], $field_properties);
3038 + $element = new Element_HTML($istance_data['default_value']);
2153 3039 break;
2154 3040 case 'email':
2155 3041 case 'autoreply_email':
2156 - $email_props = $field_properties+array('value'=>$istance_data['default_value']);
2157 - if ($resolved_format_msg !== '') {
2158 - $email_props['custom_format_message'] = $resolved_format_msg;
2159 - }
2160 - $element = new AccuaForm_Element_Email($istance_data['label'], $istance_data['istance_id'], $email_props);
3042 + $element = new AccuaForm_Element_Email($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
3043 + $element->setValidation(new Validation_Email(
3044 + str_replace('%element%', $istance_data['label'], __("Attention: '%element%' must contain an email address.", 'contact-forms'))
3045 + ));
3046 + //"Errore: '{$istance_data['label']}' deve contenere un indirizzo email valido."
2161 3047 break;
2162 3048 case 'colorpicker':
2163 3049 $element = new AccuaForm_Element_ColorPicker($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
2164 3050 break;
@@ -2167,11 +3053,9 @@
2167 3053 $form->addElement(new AccuaForm_Element_FieldsetEnd());
2168 3054 } else {
2169 3055 $fieldset_open = true;
2170 3056 }
2171 - $fs_props = $field_properties;
2172 - $fs_props['fieldset_style'] = isset($istance_data['fieldset_style']) ? $istance_data['fieldset_style'] : 'border-off-title-off';
2173 - $element = new AccuaForm_Element_FieldsetBegin($istance_data['label'], $istance_data['istance_id'], $fs_props);
3057 + $element = new AccuaForm_Element_FieldsetBegin($istance_data['label'], $istance_data['istance_id']);
2174 3058 break;
2175 3059 case 'fieldset-end':
2176 3060 if ($fieldset_open) {
2177 3061 $element = new AccuaForm_Element_FieldsetEnd();
@@ -2198,20 +3082,17 @@
2198 3082 }
2199 3083 if ($captcha_use_v1) {
2200 3084 $element = new Element_HTML("\n\n<!-- ReCaptcha 1 is discontinued, please go to Contact Forms settings page and set reCaptcha v2 keys -->\n\n");
2201 3085 } else {
2202 - $element = new AccuaForm_Element_Captcha2 ($istance_data['label'], '', $field_properties+$captcha_properties);
3086 + $element = new AccuaForm_Element_Captcha2 ($istance_data['label'], '', $captcha_properties);
2203 3087 }
2204 3088 break;
2205 - case 'turnstile':
2206 - $element = new AccuaForm_Element_Turnstile($istance_data['label'], $istance_data['istance_id'], $field_properties+array("description" => ""));
2207 - break;
2208 3089 case 'password':
2209 3090 $element = new Element_Password($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
2210 3091 break;
2211 3092 case 'password-and-confirm':
2212 3093 $id_2 = "___{$istance_data['istance_id']}___confirmpass";
2213 - $element = new Element_Password($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
3094 + $element = new Element_Password(__("Password", 'contact-forms'), $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
2214 3095 $element_conf = new Element_Password(__("Confirm password", 'contact-forms'), $id_2, $field_properties+array('value'=>$istance_data['default_value']));
2215 3096 $element_conf_validator = new AccuaForm_Validation_Password();
2216 3097 $element_conf_validator->configure(array('otherPasswordFieldName'=>$istance_data['istance_id']));
2217 3098 $element_conf->setValidation($element_conf_validator);
@@ -2218,57 +3099,26 @@
2218 3099 break;
2219 3100 case 'date':
2220 3101 $element = new AccuaForm_Element_Date($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value'], 'minDate'=>$istance_data['min_date'], 'maxDate'=>$istance_data['max_date']));
2221 3102 break;
2222 - case 'telephone':
2223 - $phone_country = isset($istance_data['country_code']) ? $istance_data['country_code'] : 'IT';
2224 - $phone_props = $field_properties+array('value'=>$istance_data['default_value'], 'country_code'=>$phone_country);
2225 - if ($resolved_format_msg !== '') {
2226 - $phone_props['custom_format_message'] = $resolved_format_msg;
2227 - }
2228 - $element = new AccuaForm_Element_Telephone($istance_data['label'], $istance_data['istance_id'], $phone_props);
2229 - break;
2230 3103 //case 'textfield':
2231 3104 default:
2232 - /**
2233 - * Filter to create a custom Element for an external field type.
2234 - *
2235 - * @param Element|null $element Null by default; return an Element to override.
2236 - * @param string $field_type The field type identifier.
2237 - * @param array $field_data The field definition from avail_fields.
2238 - * @param array $istance_data The field instance data (label, required, etc.).
2239 - * @param array $field_properties Common properties (description, shortDesc, etc.).
2240 - */
2241 - $element = apply_filters( 'accua_forms_render_field_element', null, $field_data['type'], $field_data, $istance_data, $field_properties );
2242 - if ( ! $element ) {
2243 - $element = new Element_Textbox($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
2244 - }
3105 + $element = new Element_Textbox($istance_data['label'], $istance_data['istance_id'], $field_properties+array('value'=>$istance_data['default_value']));
2245 3106 break;
2246 3107 }
2247 3108 if ($element) {
2248 3109 if (!empty($istance_data['required'])) {
2249 3110 $element->setClass('accuaforms-field-required');
2250 - if ($field_data['type'] === 'captcha' && empty($captcha_use_v1)) {
3111 + if($field_data['type'] == 'captcha' && empty($captcha_use_v1)) {
2251 3112 //nothing
2252 - } elseif ($field_data['type'] === 'turnstile') {
2253 - //nothing - turnstile has its own validation set in the Element constructor
2254 - } elseif ($field_data['type'] === 'password-and-confirm') {
2255 - if ($resolved_required_msg !== '') {
2256 - $req_msg = str_replace(array('%s', '%element%'), $istance_data['label'], $resolved_required_msg);
2257 - } else {
2258 - /* translators: Password field required error */
2259 - $req_msg = __( 'Password is required', 'contact-forms' );
2260 - }
2261 - $element->setValidation(new Validation_Required($req_msg));
3113 + } else if($field_data['type'] == 'password-and-confirm') {
3114 + $element->setValidation(new Validation_Required(
3115 + str_replace('%element%', $istance_data['label'], __("Attention: Passwords are required fields.", 'contact-forms'))
3116 + ));
2262 3117 } else {
2263 - if ($resolved_required_msg !== '') {
2264 - $req_msg = str_replace(array('%s', '%element%'), $istance_data['label'], $resolved_required_msg);
2265 - } else {
2266 - /* translators: %element% is the field label, replaced with str_replace() */
2267 - // phpcs:ignore WordPress.WP.I18n.MissingTranslatorsComment -- Translators comment is above
2268 - $req_msg = str_replace('%element%', $istance_data['label'], __( '%element% is required', 'contact-forms' ));
2269 - }
2270 - $element->setValidation(new Validation_Required($req_msg));
3118 + $element->setValidation(new Validation_Required(
3119 + str_replace('%element%', $istance_data['label'], __("Attention: '%element%' is a required field.", 'contact-forms'))
3120 + ));
2271 3121 }
2272 3122 }
2273 3123
2274 3124 if ($elementName = $element->getName()) {
@@ -2311,9 +3161,9 @@
2311 3161 if (!empty($params['txt'])) {
2312 3162 $replace_map['__submitted_txt'] = implode("\n",$replace_map['__submitted_txt_raw']);
2313 3163 }
2314 3164 if (!empty($params['html'])) {
2315 - $replace_map['__submitted_html'] = implode("</td></tr>\n<tr>\n<td style='white-space:nowrap;vertical-align:top;padding:4px 10px 4px 0;'>",$replace_map['__submitted_html_raw']);
3165 + $replace_map['__submitted_html'] = implode('</td></tr><tr><td>',$replace_map['__submitted_html_raw']);
2316 3166 }
2317 3167 if (!empty($params['json'])) {
2318 3168 $replace_map['__submitted_json'] = _accua_forms_json_encode($replace_map['__submitted_json_raw']);
2319 3169 }
@@ -2383,9 +3233,8 @@
2383 3233 ));
2384 3234
2385 3235 $anonymized_ip = accua_forms_anonymize_ip($form->stats['ip']);
2386 3236
2387 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery -- Form submission insert requires direct query
2388 3237 $insert_ret = $wpdb->insert(
2389 3238 $wpdb->prefix . 'accua_forms_submissions',
2390 3239 array (
2391 3240 'afs_form_id' => (string) $fid,
@@ -2403,10 +3252,9 @@
2403 3252 if ($insert_ret) {
2404 3253 $submission_id = $form->stats['submission_id'] = $wpdb->insert_id;
2405 3254 } else {
2406 3255 $submission_id = $form->stats['submission_id'] = 0;
2407 - // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Legitimate error logging for failed DB insert
2408 - error_log("[Contact Forms] unable to save submitted form data");
3256 + error_log("[WordPress Contact Forms] unable to save submitted form data");
2409 3257 }
2410 3258
2411 3259 $review_submission_url = admin_url('admin.php').'?page=accua_forms_submissions_list&sid='.$submission_id;
2412 3260
@@ -2421,15 +3269,15 @@
2421 3269 '__referrer' => $form->stats['referrer'],
2422 3270 '__lang' => $form->stats['lang'],
2423 3271 '__locale' => $form->stats['locale'],
2424 3272 '__created' => $form->stats['created'],
2425 - '__created_day' => wp_date('l j F Y', $form->stats['created']),
2426 - '__created_day_month_year' => wp_date('j F Y', $form->stats['created']),
2427 - '__created_hour' => wp_date('G:i', $form->stats['created']),
3273 + '__created_day' => date('l j F Y', $form->stats['created']),
3274 + '__created_day_month_year' => date('j F Y', $form->stats['created']),
3275 + '__created_hour' => date('G:i', $form->stats['created']),
2428 3276 '__submitted' => $time,
2429 - '__submitted_day' => wp_date('l j F Y', $time),
2430 - '__submitted_day_month_year' => wp_date('j F Y', $time),
2431 - '__submitted_hour' => wp_date('G:i', $time),
3277 + '__submitted_day' => date('l j F Y', $time),
3278 + '__submitted_day_month_year' => date('j F Y', $time),
3279 + '__submitted_hour' => date('G:i', $time),
2432 3280 '__confirmation_emails_message' => $form_data['confirmation_emails_message'],
2433 3281 '__user_agent' => $form->stats['user_agent'],
2434 3282 '__platform' => $form->stats['platform'],
2435 3283 '__tentatives' => $form->stats['tentatives'],
@@ -2463,9 +3311,9 @@
2463 3311 'name' => __('Fieldset begin', 'contact-forms'),
2464 3312 'type' => 'fieldset-begin',
2465 3313 'description' => '',
2466 3314 );
2467 - } elseif ($istance_data['ref'] == '__fieldset-end') {
3315 + } else if ($istance_data['ref'] == '__fieldset-end') {
2468 3316 $field_data = array(
2469 3317 'id' => '__fieldset-end',
2470 3318 'name' => __('Fieldset end', 'contact-forms'),
2471 3319 'type' => 'fieldset-end',
@@ -2551,10 +3399,10 @@
2551 3399 $urls = array();
2552 3400 foreach ($value as $val) {
2553 3401 if (isset($opts[$val])) {
2554 3402 $titles[] = $opts[$val];
2555 - $ids[] = $val;
2556 - $urls[] = get_permalink($val);
3403 + $ids[] = $value;
3404 + $urls[] = get_permalink($value);
2557 3405 $value2[] = $val . ': ' . trim(preg_replace('/[\s\n\r]+/', ' ', $opts[$val]));
2558 3406 }
2559 3407 }
2560 3408 $replace_map['__label_'.$istance_data['istance_id']] = $replace_map['__post_title_'.$istance_data['istance_id']] = implode("\n", $titles);
@@ -2569,26 +3417,15 @@
2569 3417 }
2570 3418 break;
2571 3419 case 'post-select':
2572 3420 if ($value !== '') {
2573 - $post = get_post(absint($value));
2574 - // The submitted ID must belong to the post type the field is
2575 - // configured for and have a status the field may expose (publish,
2576 - // plus private when explicitly configured); otherwise any post ID
2577 - // would be accepted.
2578 - $expected_post_type = isset($istance_data['post_type']) ? $istance_data['post_type'] : 'page';
2579 - $ps_allowed_statuses = array('publish');
2580 - $ps_element = $form->getElementByName($istance_id);
2581 - if ($ps_element instanceof AccuaForm_Element_PostSelect) {
2582 - $expected_post_type = $ps_element->getEffectivePostType();
2583 - $ps_allowed_statuses = $ps_element->getAllowedPostStatuses();
2584 - }
2585 - if ($post && in_array($post->post_status, $ps_allowed_statuses, true) && $post->post_type === $expected_post_type) {
2586 - $title = $post->post_title;
2587 - $replace_map['__label_'.$istance_data['istance_id']] = $replace_map['__post_title_'.$istance_data['istance_id']] = $title;
3421 + $el = $form->getElementByName($istance_id);
3422 + $opts = $el->getOptions();
3423 + if (isset($opts[$value])) {
3424 + $replace_map['__label_'.$istance_data['istance_id']] = $replace_map['__post_title_'.$istance_data['istance_id']] = $opts[$value];
2588 3425 $replace_map['__post_id_'.$istance_data['istance_id']] = $value;
2589 3426 $replace_map['__post_url_'.$istance_data['istance_id']] = get_permalink($value);
2590 - $value = $value . ': ' . trim(preg_replace('/[\s\n\r]+/', ' ', $title));
3427 + $value = $value . ': ' . trim(preg_replace('/[\s\n\r]+/', ' ', $opts[$value]));
2591 3428 } else {
2592 3429 $replace_map['__label_'.$istance_data['istance_id']] = $replace_map['__post_title_'.$istance_data['istance_id']] = '';
2593 3430 $replace_map['__post_id_'.$istance_data['istance_id']] = '';
2594 3431 $replace_map['__post_url_'.$istance_data['istance_id']] = '';
@@ -2610,10 +3447,9 @@
2610 3447 if ($value !== null && $value !== '' && $file) {
2611 3448 if ($form->renameFile($istance_id, "{$submission_id}_{$field_data['id']}_{$file['name']}")) {
2612 3449 $urlfield = rawurlencode($istance_data['istance_id']);
2613 3450 $urlfile = rawurlencode($value);
2614 - $token = accua_forms_generate_download_token($submission_id);
2615 - $file_download_url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$submission_id}&field={$urlfield}&file={$urlfile}&nonce=" . wp_create_nonce('accua_forms_download_nonce')."&token={$token}&_wpnonce=" . wp_create_nonce('download_file_' . $submission_id . '_' . $urlfield);
3451 + $file_download_url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$submission_id}&field={$urlfield}&file={$urlfile}";
2616 3452 }
2617 3453 }
2618 3454 $replace_map[$istance_data['istance_id']] = $value;
2619 3455 $replace_map['__download_'.$istance_data['istance_id']] = $file_download_url;
@@ -2632,20 +3468,12 @@
2632 3468 $replace_map[$istance_data['istance_id']] = $value;
2633 3469 }
2634 3470
2635 3471 switch ($field_data['type']) {
2636 - case 'fieldset-begin':
2637 - $fieldset_label = !empty($istance_data['label']) ? esc_html($istance_data['label']) : esc_html($istance_data['istance_id']);
2638 - $replace_map['__submitted_txt_raw'][$istance_data['istance_id']] = "\n--- {$istance_data['label']} ---";
2639 - $replace_map['__submitted_json_raw'][$istance_data['istance_id']] = $value;
2640 - $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong style='font-size:14px;'>{$fieldset_label}</strong></td><td class='valori_submitted'>";
2641 - break;
2642 - case 'fieldset-end':
2643 - break;
2644 3472 case 'file':
2645 3473 $replace_map['__submitted_txt_raw'][$istance_data['istance_id']] = "{$istance_data['istance_id']}\t$value\t$file_download_url";
2646 3474 $replace_map['__submitted_json_raw'][$istance_data['istance_id']] = "$value\t$file_download_url";
2647 - $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'><a href='".esc_url($file_download_url)."'>".esc_html($value)."</a>";
3475 + $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'><a href='".htmlspecialchars($file_download_url,ENT_QUOTES)."'>".htmlspecialchars($value)."</a>";
2648 3476 break;
2649 3477
2650 3478 case 'email':
2651 3479 case 'autoreply_email':
@@ -2650,9 +3478,9 @@
2650 3478 case 'email':
2651 3479 case 'autoreply_email':
2652 3480 $replace_map['__submitted_txt_raw'][$istance_data['istance_id']] = "{$istance_data['istance_id']}\t$value";
2653 3481 $replace_map['__submitted_json_raw'][$istance_data['istance_id']] = $value;
2654 - $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'><a href='mailto:".esc_attr($value)."'>".esc_html($value)."</a>";
3482 + $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'><a href='mailto:".htmlspecialchars($value,ENT_QUOTES)."'>".htmlspecialchars($value)."</a>";
2655 3483 break;
2656 3484 case 'submit':
2657 3485 break;
2658 3486 case 'colorpicker':
@@ -2660,9 +3488,9 @@
2660 3488 $replace_map['__submitted_json_raw'][$istance_data['istance_id']] = $value;
2661 3489 if ($value === '') {
2662 3490 $value_html = '';
2663 3491 } else {
2664 - $value_esc = esc_attr($value);
3492 + $value_esc = htmlspecialchars($value, ENT_QUOTES);
2665 3493 $value_html = "<span style='color: $value_esc'><font color='$value_esc'>&#9608;</font></span> $value_esc";
2666 3494 }
2667 3495 $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'>$value_html";
2668 3496 break;
@@ -2671,14 +3499,12 @@
2671 3499 break;
2672 3500 default:
2673 3501 $replace_map['__submitted_txt_raw'][$istance_data['istance_id']] = "{$istance_data['istance_id']}\t$value";
2674 3502 $replace_map['__submitted_json_raw'][$istance_data['istance_id']] = $value;
2675 - $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'>".esc_html($value);
2676 - } if ($submission_id) {
2677 - // Ensure value is never NULL to prevent database errors
2678 - $safe_value = $value === null ? '' : $value;
2679 -
2680 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery -- Form field values insert requires direct query
3503 + $replace_map['__submitted_html_raw'][$istance_data['istance_id']] = "<strong>{$istance_data['istance_id']}</strong></td><td class='valori_submitted'>".htmlspecialchars($value);
3504 + }
3505 +
3506 + if ($submission_id) {
2681 3507 $wpdb->insert(
2682 3508 $wpdb->prefix . 'accua_forms_submissions_values',
2683 3509 array (
2684 3510 'afsv_sub_id' => $submission_id,
@@ -2683,9 +3509,9 @@
2683 3509 array (
2684 3510 'afsv_sub_id' => $submission_id,
2685 3511 'afsv_field_id' => $istance_data['istance_id'],
2686 3512 'afsv_type' => $type,
2687 - 'afsv_value' => $safe_value,
3513 + 'afsv_value' => $value,
2688 3514 ),
2689 3515 array('%d','%s','%s','%s')
2690 3516 );
2691 3517 }
@@ -2706,10 +3532,9 @@
2706 3532
2707 3533 //Newer filter, with an easier name
2708 3534 $replace_map = apply_filters('accua_forms_submission', $replace_map, $fid, $submittedData, $form, $_field_data, $_istance_data);
2709 3535
2710 - $submitted_html = "<table style='width:100%;border-collapse:collapse;'>\n<tr>\n<td style='white-space:nowrap;vertical-align:top;padding:4px 10px 4px 0;'>" . $replace_map['__submitted_html'] . "</td></tr></table>";
2711 - $submitted_html = str_replace("class='valori_submitted'", "class='valori_submitted' style='vertical-align:top;padding:4px 0;overflow-wrap:break-word;word-break:break-word;'", $submitted_html);
3536 + $submitted_html = '<table><tr><td>' . $replace_map['__submitted_html'] . '</td></tr></table>';
2712 3537 $confirmation_emails_message = $replace_map['__confirmation_emails_message'];
2713 3538 unset($replace_map['__submitted_html'], $replace_map['__confirmation_emails_message'], $replace_map['__submitted_txt_raw'], $replace_map['__submitted_html_raw'], $replace_map['__submitted_json_raw'], $replace_map['__autoreply_email_raw']);
2714 3539
2715 3540 $replace_map_html = array();
@@ -2714,9 +3539,9 @@
2714 3539
2715 3540 $replace_map_html = array();
2716 3541 foreach($replace_map as $key => $value) {
2717 3542 $replace_map_html["!$key"] = wp_kses($value, 'post');
2718 - $replace_map_html[$key] = esc_attr($value);
3543 + $replace_map_html[$key] = htmlspecialchars($value, ENT_QUOTES);
2719 3544 }
2720 3545
2721 3546 $replace_map['__submitted_html'] = $replace_map_html['__submitted_html'] = $replace_map_html['!__submitted_html'] = $submitted_html;
2722 3547 $replacer_html = new AccuaConditionalReplacer($replace_map_html);
@@ -2741,9 +3566,8 @@
2741 3566 }
2742 3567
2743 3568 $settings_html = array(
2744 3569 'success_message',
2745 - 'error_message',
2746 3570 'admin_emails_message',
2747 3571 );
2748 3572
2749 3573 foreach($settings_html as $i) {
@@ -2749,12 +3573,9 @@
2749 3573 foreach($settings_html as $i) {
2750 3574 $form_data_replaced[$i] = $replacer_html->doReplace($form_data[$i]);
2751 3575 }
2752 3576
2753 - // Track mail sending success for showing appropriate message
2754 - $mail_success = true;
2755 - $mail1 = true;
2756 - $mail2 = true;
3577 + AccuaForm::appendSubmittedMessages(wpautop($form_data_replaced['success_message']));
2757 3578
2758 3579 $header = array("Content-Type: text/html; charset=".get_option('blog_charset'));
2759 3580
2760 3581 $emails_from = trim($form_data_replaced['emails_from']);
@@ -2779,12 +3600,9 @@
2779 3600 foreach ($admin_tos as $admin_to) {
2780 3601 $mail1 = wp_mail(trim($admin_to), $form_data_replaced['admin_emails_subject'], $form_data_replaced['admin_emails_message'], $header);
2781 3602 }
2782 3603 */
2783 - $mail1 = wp_mail($form_data_replaced['admin_emails_to'], $form_data_replaced['admin_emails_subject'],'<html><head></head><body style="background:#f9f8f8;font-size: 12px;font-family: &quot;Lucida Sans&quot;,&quot;Lucida Grande&quot;, Verdana, Arial, Sans-Serif;">'.wpautop($form_data_replaced['admin_emails_message']).'</body></html>', $header);
2784 - if (!$mail1) {
2785 - $mail_success = false;
2786 - }
3604 + $mail1 = wp_mail($form_data_replaced['admin_emails_to'], $form_data_replaced['admin_emails_subject'],'<html><head></head><body style="background:#f9f8f8;font-size: 12px;font-family: "Lucida Sans","Lucida Grande", Verdana, Arial, Sans-Serif;"">'.wpautop($form_data_replaced['admin_emails_message']).'</body></html>', $header);
2787 3605 }
2788 3606
2789 3607 if ($replace_map['__autoreply'] && $replace_map['__autoreply_email']
2790 3608 && $form_data_replaced['confirmation_emails_subject']
@@ -2789,32 +3607,10 @@
2789 3607 if ($replace_map['__autoreply'] && $replace_map['__autoreply_email']
2790 3608 && $form_data_replaced['confirmation_emails_subject']
2791 3609 && $confirmation_emails_message) {
2792 3610 $mail2 = wp_mail($replace_map['__autoreply_email'], $form_data_replaced['confirmation_emails_subject'], '<html><head></head><body>'.wpautop($confirmation_emails_message).'</body></html>', $header);
2793 - if (!$mail2) {
2794 - $mail_success = false;
2795 - }
2796 3611 }
2797 3612
2798 - // Determine which message to show based on mail success and user settings
2799 - if ($mail_success) {
2800 - // Show success message unless "Don't show any messages" is selected
2801 - if (empty($form_data['success_message_no_message'])) {
2802 - $message_content = trim($form_data_replaced['success_message']);
2803 - if ($message_content !== '') {
2804 - AccuaForm::appendSubmittedMessages(wpautop($message_content));
2805 - }
2806 - }
2807 - } else {
2808 - // Mail failed - show error message unless "Don't show any messages" is selected
2809 - if (empty($form_data['error_message_no_message'])) {
2810 - $error_content = trim($form_data_replaced['error_message']);
2811 - if ($error_content !== '') {
2812 - AccuaForm::appendSubmittedMessages(wpautop($error_content));
2813 - }
2814 - }
2815 - }
2816 -
2817 3613 /*
2818 3614 echo "<!-- replace_map: "
2819 3615 , print_r($replace_map, true)
2820 3616 , "\nreplace_map: "
@@ -2842,16 +3638,11 @@
2842 3638 'file_format' => 'name',
2843 3639 );
2844 3640 $ret = array();
2845 3641 if ($options['extra']) {
2846 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Submission data lookup requires direct query
2847 - $query1 = $wpdb->prepare(
2848 - "SELECT *
3642 + $query1 = "SELECT *
2849 3643 FROM `{$wpdb->prefix}accua_forms_submissions`
2850 - WHERE afs_id = %d",
2851 - $subid
2852 - );
2853 - // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared, WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- $query1 is prepared above, submission lookup requires direct query
3644 + WHERE afs_id = $subid";
2854 3645 $data = $wpdb->get_row($query1);
2855 3646 if (!empty($data)) {
2856 3647 $created = $data->afs_created;
2857 3648 $created[10] = 'T';
@@ -2884,13 +3675,13 @@
2884 3675 '__uri' => $data->afs_uri,
2885 3676 '__referrer' => $data->afs_referrer,
2886 3677 '__lang' => $data->afs_lang,
2887 3678 '__created' => $created,
2888 - '__created_day' => wp_date('l j F Y', $created),
2889 - '__created_hour' => wp_date('G:i', $created),
3679 + '__created_day' => date('l j F Y', $created),
3680 + '__created_hour' => date('G:i', $created),
2890 3681 '__submitted' => $submitted,
2891 - '__submitted_day' => wp_date('l j F Y', $submitted),
2892 - '__submitted_hour' => wp_date('G:i', $submitted),
3682 + '__submitted_day' => date('l j F Y', $submitted),
3683 + '__submitted_hour' => date('G:i', $submitted),
2893 3684 '__user_agent' => $stats['user_agent'],
2894 3685 '__platform' => $stats['platform'],
2895 3686 '__tentatives' => $stats['tentatives'],
2896 3687 '__submit_method' => $stats['submit_method'],
@@ -2897,17 +3688,12 @@
2897 3688 );
2898 3689 }
2899 3690 }
2900 3691
2901 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Submission values lookup requires direct query
2902 - $query2 = $wpdb->prepare(
2903 - "SELECT *
2904 - FROM `{$wpdb->prefix}accua_forms_submissions_values`
2905 - WHERE afsv_sub_id = %d",
2906 - $subid
2907 - );
3692 + $query2 = "SELECT *
3693 + FROM `{$wpdb->prefix}accua_forms_submissions_values`
3694 + WHERE afsv_sub_id = $subid";
2908 3695
2909 - // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared, WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- $query2 is prepared above, submission values lookup requires direct query
2910 3696 $data2 = $wpdb->get_results($query2, OBJECT);
2911 3697
2912 3698 foreach ($data2 as $row) {
2913 3699 switch ($row->afsv_type) {
@@ -2914,15 +3700,12 @@
2914 3700 case 'file' :
2915 3701 if ($options['file_format'] == 'url' || $options['file_format'] == 'link') {
2916 3702 $fieldid = rawurlencode($row->afsv_field_id);
2917 3703 $filename = rawurlencode($row->afsv_value);
2918 - $url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$row->afsv_sub_id}&field={$fieldid}&file={$filename}&nonce=" . wp_create_nonce('accua_forms_download_nonce') . "&_wpnonce=" . wp_create_nonce('download_file_' . $row->afsv_sub_id . '_' . $fieldid);
2919 - if(isset($options['token'])){
2920 - $url .= '&token='.$options['token'];
2921 - }
3704 + $url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$row->afsv_sub_id}&field={$fieldid}&file={$filename}";
2922 3705 if ($options['file_format'] == 'link'){
2923 - $url = esc_url($url);
2924 - $filename = esc_html($row->afsv_value);
3706 + $url = htmlspecialchars($url,ENT_QUOTES);
3707 + $filename = htmlspecialchars($row->afsv_value,ENT_QUOTES);
2925 3708 $fielddata = "<a href='{$url}' target='_blank'>{$filename}</a>";
2926 3709 } else {
2927 3710 $fielddata = $url;
2928 3711 }
@@ -2947,20 +3730,11 @@
2947 3730 $fid = $atts['fid'];
2948 3731 $form_data = _accua_forms_get_form_data($fid, false);
2949 3732
2950 3733 if (! $form_data) {
2951 - // In preview mode, allow unsaved (new) forms to render using draft + defaults
2952 - if (! apply_filters('accua_forms_use_draft_for_preview', false)) {
2953 - return '';
2954 - }
2955 - $default_form_data = get_option('accua_forms_default_form_data', array());
2956 - $empty_form_data = _accua_forms_get_form_data(false);
2957 - $form_data = array('_overrided' => array()) + $default_form_data + $empty_form_data;
3734 + return '';
2958 3735 }
2959 3736
2960 - // Note: Preview field order override is handled in accua_forms_form_generate()
2961 - // which applies the filter there for live preview
2962 -
2963 3737 $fid = '__accua-form__'.$fid;
2964 3738
2965 3739 $out = '';
2966 3740
@@ -2965,26 +3739,12 @@
2965 3739 $out = '';
2966 3740
2967 3741 if (AccuaForm::getSubmittedID() == $fid) {
2968 3742 /* return "<pre>Form submitted.\n\nData: " . print_r(AccuaForm::getSubmittedData(), true) . '</pre>'; */
2969 - // Get per-form messages (supports multiple forms on same page)
2970 - $messages = AccuaForm::getSubmittedMessages($fid);
2971 - if ($messages && trim($messages) !== '') {
3743 + $messages = AccuaForm::getSubmittedMessages();
3744 + if ($messages) {
2972 3745 $out .= '<div id="_response_messages_'.$fid.'" class="accua-form-messages">'.$messages.'</div>';
2973 3746 }
2974 -
2975 - // Non-AJAX fallback: set URL hash and scroll to result messages on page load.
2976 - // The anchor elements are only created by the AJAX JS block (which is not output for
2977 - // non-AJAX forms), so we scroll to the messages div by class instead.
2978 - $anchor_suffix = preg_replace('/[^a-zA-Z0-9]+/', '_', str_replace('__accua-form__', '', $fid));
2979 - $hash_type = AccuaForm::isValid() ? 'formSubmitSuccess' : 'formSubmitInvalid';
2980 - $anchor_full = esc_js($hash_type . '-' . $anchor_suffix);
2981 - $out .= '<script>document.addEventListener("DOMContentLoaded",function(){'
2982 - . 'if(history.replaceState)history.replaceState(null,"","#' . $anchor_full . '");'
2983 - . 'var m=document.querySelector(".accua-form-messages");'
2984 - . 'if(m)m.scrollIntoView({behavior:"smooth",block:"start"})'
2985 - . '});</script>';
2986 -
2987 3747 if (AccuaForm::isValid()) {
2988 3748 return $out;
2989 3749 }
2990 3750 $form = AccuaForm::getSubmittedForm();
@@ -2989,28 +3749,13 @@
2989 3749 }
2990 3750 $form = AccuaForm::getSubmittedForm();
2991 3751 } else {
2992 3752 $analytics_data = get_option('accua_forms_default_analytics_data',array());
2993 -
2994 - // Check for preview layout override (allows live preview of layout changes before save)
2995 - $layout = $form_data['layout'];
2996 - $preview_layout_override = apply_filters('accua_forms_preview_layout_override', '');
2997 - if ($preview_layout_override) {
2998 - $layout = $preview_layout_override;
2999 - }
3000 -
3001 - // If layout is empty (meaning "use default"), resolve to the global default layout
3002 - if (empty($layout)) {
3003 - $default_form_data = get_option('accua_forms_default_form_data', array());
3004 - $layout = !empty($default_form_data['layout']) ? $default_form_data['layout'] : 'sidebyside';
3005 - }
3006 -
3007 3753 $params = array(
3008 - 'layout' => $layout,
3754 + 'layout' => $form_data['layout'],
3009 3755 'title' => $form_data['title'],
3010 3756 'track_submit' => !empty($analytics_data['analytics_track_submit']),
3011 3757 'track_fields' => !empty($analytics_data['analytics_track_fields']),
3012 - 'gads_conversion_tracking_code' => $form_data['gads_conversion_tracking_code'],
3013 3758 );
3014 3759 $form = AccuaForm::create($fid, $params);
3015 3760 }
3016 3761
@@ -3016,10 +3761,9 @@
3016 3761
3017 3762 $out .= $form->render(true);
3018 3763
3019 3764 $doing_ajax = function_exists('wp_doing_ajax') ? wp_doing_ajax() : (defined( 'DOING_AJAX' ) && DOING_AJAX);
3020 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only check for Yoast SEO compatibility, strips HTML for preview
3021 - if ($doing_ajax && isset($_REQUEST['action']) && ($_REQUEST['action'] === 'wpseo_filter_shortcodes')) {
3765 + if ($doing_ajax && ($_REQUEST['action'] === 'wpseo_filter_shortcodes')) {
3022 3766 $strip_regexp = '/(<iframe[^>]*>(.*?)<\/iframe>|<script[^>]*>(.*?)<\/script>|<input([^>]*)type="hidden"[^>]*>)/is';
3023 3767 $out = preg_replace($strip_regexp, '', $out);
3024 3768 }
3025 3769
@@ -3028,15 +3772,12 @@
3028 3772 }
3029 3773
3030 3774 function accua_forms_include($fid, $atts=array(), $content = '', $code = '') {
3031 3775 $atts['fid'] = $fid;
3032 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Shortcode handler manages its own escaping
3033 3776 echo accua_forms_shortcode_handler($atts, $content, $code);
3034 3777 }
3035 3778
3036 -// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedFunctionFound -- Internal helper function, double underscore prefix indicates private
3037 3779 function __accua_forms_submissions_list_page(){
3038 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only routing, actual actions have nonce checks
3039 3780 if(isset($_GET['sid'])) {
3040 3781 accua_forms_single_submission();
3041 3782 } else {
3042 3783 accua_forms_submissions_list_page();
@@ -3041,189 +3782,32 @@
3041 3782 } else {
3042 3783 accua_forms_submissions_list_page();
3043 3784 }
3044 3785 }
3045 -function accua_forms_submissions_list_page_load(){
3046 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only routing for screen option registration
3047 - if(isset($_GET['sid'])) {
3048 - // Handle GET-based trash/restore actions here (before any output is sent)
3049 - require_once __DIR__ . '/admin/single-submission.php';
3050 - $sid = (int) $_GET['sid'];
3051 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Nonce verified below before processing
3052 - if ( $sid && isset( $_GET['action'] ) ) {
3053 - if ( $_GET['action'] === 'trash' ) {
3054 - check_admin_referer( 'del_sub_form_' . $sid );
3055 - accua_forms_trash_submission( $sid );
3056 - wp_safe_redirect( admin_url( 'admin.php?page=accua_forms_submissions_list&trashed=1' ) );
3057 - exit;
3058 - }
3059 - if ( $_GET['action'] === 'restore' ) {
3060 - check_admin_referer( 'restore_sub_form_' . $sid );
3061 - accua_forms_restore_submission( $sid );
3062 - wp_safe_redirect( admin_url( 'admin.php?page=accua_forms_submissions_list&restored=1' ) );
3063 - exit;
3064 - }
3065 - }
3066 - return;
3067 - }
3068 - add_screen_option('per_page', array(
3069 - 'default' => 100,
3070 - 'option' => 'accua_forms_submissions_per_page',
3071 - ));
3072 -
3073 - // Set default hidden columns for first-time users: hide non-essential columns.
3074 - add_filter( 'default_hidden_columns', function( $hidden ) {
3075 - $non_essential = [ 'form_id', 'pid', 'created', 'lead_status' ];
3076 - $avail_fields = get_option( 'accua_forms_avail_fields', [] );
3077 - foreach ( array_keys( $avail_fields ) as $slug ) {
3078 - if ( $slug !== 'email' ) {
3079 - $non_essential[] = '_field_' . $slug;
3080 - }
3081 - }
3082 - return array_unique( array_merge( $hidden, $non_essential ) );
3083 - } );
3084 -
3085 - $screen = get_current_screen();
3086 - $screen->add_help_tab( array(
3087 - 'id' => 'accua_forms_lead_statuses',
3088 - 'title' => __( 'Lead Statuses', 'contact-forms' ),
3089 - 'content' => '<p>' . accua_forms_get_lead_statuses_help() . '</p>',
3090 - ) );
3091 -}
3092 -add_filter('set_screen_option_accua_forms_submissions_per_page', function($status, $option, $value) {
3093 - return (int) $value;
3094 -}, 10, 3);
3095 3786 function accua_forms_submissions_list_page_head(){
3096 - // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only routing, actual actions have nonce checks
3097 3787 if(isset($_GET['sid'])) {
3098 - require_once __DIR__ . '/admin/single-submission.php';
3788 + require_once('accua-forms-single-submission.php');
3099 3789 accua_forms_single_submission(true);
3100 3790 } else {
3101 - require_once __DIR__ . '/admin/submissions-list-page.php';
3791 + require_once('accua-forms-submissions-page.php');
3102 3792 accua_forms_submissions_list_page(true);
3103 3793 }
3104 3794
3105 3795 }
3106 3796
3107 -/* Generiamo token di sicurezza per poter accedere anche da anonimo - email */
3108 -function accua_forms_generate_download_token($subid) {
3109 - global $wpdb;
3110 - $token = wp_generate_password(32, false); // Token casuale di 32 caratteri
3111 -
3112 - // Controlla se esiste già un token per questo sub_id
3113 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Token lookup requires direct query
3114 - $existing_token = $wpdb->get_var($wpdb->prepare(
3115 - "SELECT afsv_value FROM `{$wpdb->prefix}accua_forms_submissions_values` WHERE afsv_sub_id = %d AND afsv_field_id = '_accua_download_token'",
3116 - $subid
3117 - ));
3118 - if ($existing_token) {
3119 - return $existing_token;
3120 - } else{
3121 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery -- Token insert requires direct query
3122 - $wpdb->insert(
3123 - $wpdb->prefix . 'accua_forms_submissions_values',
3124 - [
3125 - 'afsv_sub_id' => $subid,
3126 - 'afsv_field_id' => '_accua_download_token',
3127 - 'afsv_type' => 'token',
3128 - 'afsv_value' => $token
3129 - ],
3130 - ['%d', '%s', '%s', '%s']
3131 - );
3132 - return $token;
3133 - }
3134 -}
3135 -
3136 -function accua_forms_check_download_token($subid, $get_token) {
3137 - global $wpdb;
3138 -
3139 - $subid = (int) $subid; // Cast to integer for security
3140 -
3141 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Token verification requires direct query
3142 - $saved_token = $wpdb->get_var($wpdb->prepare(
3143 - "SELECT afsv_value FROM `{$wpdb->prefix}accua_forms_submissions_values` WHERE afsv_sub_id = %d AND afsv_field_id = '_accua_download_token'",
3144 - $subid
3145 - ));
3146 -
3147 - // Debug logging for token verification (comment out in production)
3148 - // error_log("Token check: Submission ID: $subid, Provided token: $get_token, Saved token: $saved_token");
3149 -
3150 - return isset($get_token) && $get_token === $saved_token;
3151 -}
3152 -
3153 -/**
3154 - * Gestisce il download di un file inviato tramite un modulo.
3155 - *
3156 - * Questa funzione viene eseguita tramite una richiesta AJAX e permette agli utenti di scaricare
3157 - * un file precedentemente caricato con un modulo. Controlla i parametri della richiesta per verificare
3158 - * la presenza di un file associato a un determinato ID di invio e campo del modulo.
3159 - *
3160 - * - Se il parametro "html" è presente, genera una pagina HTML con un link di reindirizzamento automatico.
3161 - * - Recupera le informazioni del file dal database per verificarne l'esistenza.
3162 - * - Se il file esiste e può essere letto, restituisce il contenuto con gli appropriati header HTTP.
3163 - * - Se il file non viene trovato, restituisce un errore 404.
3164 - *
3165 - * Sicurezza:
3166 - * - Nonce
3167 - * - Utilizza `stripslashes_deep` per sanificare i dati in ingresso.
3168 - * - Protegge il database utilizzando `wpdb->prepare` per prevenire SQL Injection.
3169 - * - Determina il tipo MIME del file per un download sicuro.
3170 - * - Aggiunto token di verifica per utenti
3171 - */
3172 -
3173 3797 add_action('wp_ajax_accua_forms_download_submitted_file', 'accua_forms_download_submitted_file');
3174 3798 add_action('wp_ajax_nopriv_accua_forms_download_submitted_file', 'accua_forms_download_submitted_file');
3175 3799 function accua_forms_download_submitted_file(){
3176 3800 $get = stripslashes_deep($_GET);
3177 - $token_valid = false;
3178 - $nonce_valid = false;
3179 - $subid = '';
3180 -
3181 - if(isset($get['subid'])){
3182 - $subid = rawurlencode($get['subid']);
3183 - }
3184 -
3185 - // First verify WordPress nonce for CSRF protection (for logged-in users)
3186 - if (isset($get['_wpnonce']) && wp_verify_nonce($get['_wpnonce'], 'download_file_' . $subid . '_' . $get['field'])) {
3187 - $nonce_valid = true;
3188 - }
3189 -
3190 - // For backward compatibility with older URL format that use 'nonce' instead of '_wpnonce'
3191 - if (!$nonce_valid && isset($get['nonce']) && check_ajax_referer('accua_forms_download_nonce', 'nonce', false)) {
3192 - $nonce_valid = true;
3193 - }
3194 -
3195 - // Check for token-based authentication (for email links and unauthenticated users)
3196 - if (isset($get['token']) && $subid != '') {
3197 - if (accua_forms_check_download_token($subid, $get['token']) == 1) {
3198 - $token_valid = true;
3199 - }
3200 - }
3201 -
3202 - // If both authentication methods fail, deny access
3203 - if (!$nonce_valid && !$token_valid) {
3204 - wp_die(esc_html__('Security check failed.', 'contact-forms'), 403);
3205 - }
3206 - // Additional permission check for admin users
3207 - if(!$token_valid && !$nonce_valid && $subid != ''){
3208 - // If neither token nor nonce is valid, check for logged-in admin permissions
3209 - if (!is_user_logged_in() || !current_user_can('manage_options')) {
3210 - wp_die(esc_html__('You do not have sufficient permissions to access this page.', 'contact-forms'));
3211 - }
3212 - }
3213 3801 if (isset($get['subid'],$get['field'],$get['file'])) {
3214 - if (!empty($get['html'])) { /* export xls*/
3802 + if (!empty($get['html'])) {
3215 3803 header("Content-type: text/html");
3216 3804 $subid = rawurlencode($get['subid']);
3217 3805 $fieldid = rawurlencode($get['field']);
3218 3806 $filename = rawurlencode($get['file']);
3219 - $url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$subid}&field={$fieldid}&file={$filename}&nonce=" . wp_create_nonce('accua_forms_download_nonce') . "&_wpnonce=" . wp_create_nonce('download_file_' . $subid . '_' . $fieldid);
3220 - if(isset($get['token'])){
3221 - $url .= '&token='.$get['token'];
3222 - }
3223 - $url = esc_url($url);
3224 - $filename = esc_html($get['file']);
3225 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $filename and $url are pre-escaped above
3807 + $url = admin_url('admin-ajax.php') . "?action=accua_forms_download_submitted_file&subid={$subid}&field={$fieldid}&file={$filename}";
3808 + $url = htmlspecialchars($url,ENT_QUOTES);
3809 + $filename = htmlspecialchars($get['file'],ENT_QUOTES);
3226 3810 die("<html><head><title>{$filename}</title><meta http-equiv='refresh' content='0;URL={$url}'></head><body><a href='{$url}'>{$filename}</a></body></html>");
3227 3811 }
3228 3812 global $wpdb;
3229 3813 $subid = (int) $get['subid'];
@@ -3228,19 +3812,15 @@
3228 3812 global $wpdb;
3229 3813 $subid = (int) $get['subid'];
3230 3814 $field = $get['field'];
3231 3815 $file = $get['file'];
3232 - $query = $wpdb->prepare(
3233 - "SELECT *
3234 - FROM `{$wpdb->prefix}accua_forms_submissions_values`
3235 - WHERE afsv_sub_id = %d
3236 - AND afsv_field_id = %s
3237 - AND afsv_value = %s",
3238 - $subid,
3239 - $field,
3240 - $file
3241 - );
3242 - // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared, WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- $query is prepared above, file download verification requires direct query
3816 + $query = "SELECT *
3817 + FROM `{$wpdb->prefix}accua_forms_submissions_values`
3818 + WHERE afsv_sub_id = %d
3819 + AND afsv_field_id = %s
3820 + AND afsv_value = %s
3821 + ";
3822 + $query = $wpdb->prepare($query, $subid, $field, $file);
3243 3823 $subval = $wpdb->get_results($query, OBJECT);
3244 3824 if ($subval) {
3245 3825 $file_data = get_option('accua_forms_default_file_field_data',array()) + array('dest_path' => '');
3246 3826 $dest_path = _accua_forms_get_abs_dest_path($file_data['dest_path']);
@@ -3246,9 +3826,9 @@
3246 3826 $dest_path = _accua_forms_get_abs_dest_path($file_data['dest_path']);
3247 3827 $filename = "{$dest_path}/{$subid}_{$field}_{$file}";
3248 3828 if (is_file($filename) && is_readable($filename)){
3249 3829 if (function_exists('finfo_open')){
3250 - @ $finfo = finfo_open(FILEINFO_MIME_TYPE);
3830 + @ $finfo = finfo_open(FILEINFO_MIME);
3251 3831 if ($finfo) {
3252 3832 @ $filetype = finfo_file($finfo, $filename);
3253 3833 @ finfo_close($finfo);
3254 3834 }
@@ -3258,23 +3838,15 @@
3258 3838 }
3259 3839 if (empty($filetype)) {
3260 3840 $filetype = "application/octet-stream";
3261 3841 }
3262 - // Clean any output buffers to prevent stale content from being sent before the file
3263 - while (ob_get_level()) {
3264 - ob_end_clean();
3265 - }
3266 - // Remove all pre-set headers (admin-ajax.php sets Content-Type: text/html early)
3267 - header_remove();
3268 - nocache_headers();
3269 - header("Content-Type: $filetype");
3270 - header("Content-Length: ".filesize($filename));
3842 + header("Content-type: $filetype");
3843 + header("Content-length: ".filesize($filename));
3271 3844 if (empty($_GET['view'])) {
3272 - header("Content-Disposition: attachment; filename=\"$file\"");
3845 + header("Content-disposition: attachment; filename=\"$file\"");
3273 3846 }
3274 - // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_readfile -- WP_Filesystem not suitable for binary file streaming
3275 3847 readfile($filename);
3276 - exit;
3848 + die('');
3277 3849 }
3278 3850 }
3279 3851 }
3280 3852 header("HTTP/1.0 404 Not Found");
@@ -3294,87 +3866,17 @@
3294 3866 function accua_forms_preview() {
3295 3867 if (!current_user_can('manage_options')){
3296 3868 die ('');
3297 3869 }
3298 -
3299 - // Check nonce for CSRF protection
3300 - $nonce = isset( $_REQUEST['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['_wpnonce'] ) ) : '';
3301 - if ( ! wp_verify_nonce( $nonce, 'accua_forms_preview' ) ) {
3302 - wp_die( esc_html__( 'Security check failed.', 'contact-forms' ), 403 );
3303 - }
3304 3870
3305 - // Enqueue form styles before printing them
3306 - accua_form_enqueue_scripts_and_styles();
3307 -
3308 - // Accept temporary layout override for live preview (before save)
3309 - // This allows real-time preview when user changes layout dropdown
3310 - $preview_layout = '';
3311 - if ( ! empty( $_REQUEST['preview_layout'] ) ) {
3312 - $layout_input = sanitize_text_field( wp_unslash( $_REQUEST['preview_layout'] ) );
3313 - $allowed_layouts = array( 'toplabel', 'sidebyside', 'inlinelabel' );
3314 - if ( in_array( $layout_input, $allowed_layouts, true ) ) {
3315 - $preview_layout = $layout_input;
3316 - } elseif ( 'default' === $layout_input ) {
3317 - // 'default' means use the global default layout
3318 - $default_form_data = get_option( 'accua_forms_default_form_data', array() );
3319 - $preview_layout = ! empty( $default_form_data['layout'] ) ? $default_form_data['layout'] : 'sidebyside';
3320 - }
3321 - }
3322 -
3323 - // Accept temporary field order for live preview (before save)
3324 - // This allows preview to show reordered fields without saving to database
3325 - $preview_order = null;
3326 - if ( ! empty( $_REQUEST['preview_order'] ) ) {
3327 - // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- JSON decoded and validated below
3328 - $order_json = wp_unslash( $_REQUEST['preview_order'] );
3329 - $preview_order = json_decode( $order_json, true );
3330 - if ( json_last_error() !== JSON_ERROR_NONE ) {
3331 - $preview_order = null;
3332 - }
3333 - }
3334 -
3335 - // Store the preview layout override in a filter so shortcode handler can use it
3336 - if ($preview_layout) {
3337 - add_filter('accua_forms_preview_layout_override', function() use ($preview_layout) {
3338 - return $preview_layout;
3339 - });
3340 - }
3341 -
3342 - // Store the preview order override in a filter so shortcode handler can use it
3343 - if ($preview_order) {
3344 - add_filter('accua_forms_preview_order_override', function() use ($preview_order) {
3345 - return $preview_order;
3346 - });
3347 - }
3348 -
3349 - // Signal that we're in admin preview mode - form generator should read from draft
3350 - add_filter('accua_forms_use_draft_for_preview', '__return_true');
3351 -
3352 3871 echo '<html><head>
3353 3872 <style>
3354 - *, *::before, *::after { box-sizing: border-box; }
3355 - body {
3356 - font-family: -apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen-Sans,Ubuntu,Cantarell,"Helvetica Neue",sans-serif;
3357 - margin: 0;
3358 - padding: 16px;
3359 - background: #fff;
3360 - font-size: 14px;
3361 - line-height: 1.5;
3362 - }
3873 + body {font-family: -apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen-Sans,Ubuntu,Cantarell,"Helvetica Neue",sans-serif;}
3363 3874 </style>';
3364 3875 wp_print_styles();
3365 3876 wp_print_head_scripts();
3366 3877 echo '</head><body>';
3367 - $preview_fid = isset($_REQUEST['fid']) ? sanitize_text_field(wp_unslash($_REQUEST['fid'])) : '';
3368 -
3369 - // Check if the form has any fields — show placeholder if empty
3370 - $draft_data = _accua_forms_get_draft_data($preview_fid);
3371 - if (empty($draft_data['fields'])) {
3372 - echo '<p style="color:#50575e;text-align:center;margin-top:40px;">' . esc_html__('Add fields to the form to see the preview.', 'contact-forms') . '</p>';
3373 - } else {
3374 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Shortcode handler manages its own escaping
3375 - echo accua_forms_shortcode_handler(array('fid' => $preview_fid));
3376 - }
3878 + echo accua_forms_shortcode_handler(array('fid'=>$_REQUEST['fid']));
3377 3879 wp_print_footer_scripts();
3378 3880 echo '</body></html>';
3379 3881 die('');
3380 3882 }
@@ -3388,24 +3890,17 @@
3388 3890 header("HTTP/1.0 401 Access Denied");
3389 3891 //header("Status: 401 Access Denied");
3390 3892 die('You are not authorized to access this page.');
3391 3893 }
3392 -
3393 - // Check nonce for CSRF protection
3394 - if (!isset($_REQUEST['_wpnonce']) || !wp_verify_nonce(sanitize_text_field(wp_unslash($_REQUEST['_wpnonce'])), 'accua_forms_export_excel')) {
3395 - wp_die(esc_html__('Security check failed.', 'contact-forms'), 403);
3396 - }
3397 3894
3398 - require_once __DIR__ . '/admin/submissions-list-page.php';
3895 + require_once('accua-forms-submissions-page.php');
3399 3896 $listTable = new Accua_Forms_Submissions_List_Table();
3400 3897 $listTable->export_xls = true;
3401 3898 $listTable->prepare_items(true);
3402 - // Sanitize column selection input
3403 - $show_col_input = isset($_GET['accua_show_field']) ? sanitize_text_field(wp_unslash($_GET['accua_show_field'])) : '';
3404 - $show_col = array_map('sanitize_key', explode(',', $show_col_input));
3899 + $show_col = explode( ',', $_GET['accua_show_field']);
3405 3900 $show_col = array_diff($show_col, array('singlesub'));
3406 - header('Content-disposition: attachment; filename=downloads-report.xls');
3407 - header('Content-type: application/vnd.ms-excel');
3901 + header("Content-disposition: attachment; filename=downloads-report.xls");
3902 + header("Content-type: application/vnd.ms-excel");
3408 3903 accua_forms_submission_page_save_excel_general($listTable,$show_col);
3409 3904 die('');
3410 3905 }
3411 3906
@@ -3420,9 +3915,9 @@
3420 3915 ?><html xmlns:o="urn:schemas-microsoft-com:office:office"
3421 3916 xmlns:x="urn:schemas-microsoft-com:office:excel"
3422 3917 xmlns="http://www.w3.org/TR/REC-html40">
3423 3918 <head>
3424 - <meta http-equiv=Content-Type content="<?php echo esc_attr( $content_type ); ?>" />
3919 + <meta http-equiv=Content-Type content="<?php echo $content_type; ?>" />
3425 3920 <meta name=ProgId content=Excel.Sheet />
3426 3921 <style>
3427 3922 <!--
3428 3923 td {vertical-align:top;}
@@ -3461,9 +3956,9 @@
3461 3956 <?php
3462 3957 $cols = $listTable->get_columns();
3463 3958 foreach($cols as $col_key=>$col_value) {
3464 3959 if(in_array($col_key, $show_col)) { ?>
3465 - <td x:autofilter="all"><?php echo esc_html( $col_value ); ?></td>
3960 + <td x:autofilter="all"><?php echo $col_value; ?></td>
3466 3961 <?php }
3467 3962 } ?>
3468 3963 </tr>
3469 3964
@@ -3470,24 +3965,22 @@
3470 3965 <?php
3471 3966 $lead_statuses = accua_forms_get_lead_statuses();
3472 3967
3473 3968 foreach($listTable->items as $id_submission=>$single_submission) {
3474 - // phpcs:ignore Squiz.PHP.DiscouragedFunctions.Discouraged -- Required to prevent timeout during large exports
3475 3969 @ set_time_limit(10);
3476 3970 echo "<tr>";
3477 3971 foreach($cols as $col_key=>$col_value) {
3478 3972 if(in_array($col_key, $show_col)) {
3479 - echo '<td class="' . esc_attr($col_key) . '">';
3973 + echo "<td class='.$col_key.'>";
3480 3974 if ($col_key == 'lead_status') {
3481 3975 if (isset($lead_statuses[$single_submission['lead_status']])) {
3482 - echo esc_html($lead_statuses[$single_submission['lead_status']]);
3976 + echo htmlspecialchars($lead_statuses[$single_submission['lead_status']]);
3483 3977 }
3484 - } elseif(isset($single_submission[$col_key])) {
3978 + } else if(isset($single_submission[$col_key])) {
3485 3979 if ( method_exists( $listTable, 'column_' . $col_key ) ) {
3486 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- List table column methods handle their own escaping
3487 3980 echo call_user_func( array( &$listTable, 'column_' . $col_key ), $single_submission );
3488 - } else {
3489 - // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- List table column_default handles escaping
3981 + }
3982 + else {
3490 3983 echo $listTable->column_default( $single_submission, $col_key );
3491 3984 }
3492 3985 }
3493 3986 echo "</td>";
@@ -3507,36 +4000,34 @@
3507 4000 function accua_forms_print_tokens() {
3508 4001 $avail_fields = get_option('accua_forms_avail_fields', array());
3509 4002 $tokens = '';
3510 4003 foreach($avail_fields as $key=>$value) {
3511 - $field_name = $value['name'] ?? $value['label'] ?? $key;
3512 - $tokens .= $field_name . ": {" . $key . "}\n";
4004 + $tokens .= $value['name'] . ": {" . $key . "}\n";
3513 4005 switch ($value['type']) {
3514 4006 case 'file':
3515 - $tokens .= $field_name . " (download link): {__download_" . $key . "}\n";
4007 + $tokens .= $value['name'] . " (download link): {__download_" . $key . "}\n";
3516 4008 break;
3517 4009 case 'multiselect':
3518 4010 case 'multicheckbox':
3519 - $tokens .= $field_name . " (labels): {__label_" . $key . "}\n";
4011 + $tokens .= $value['name'] . " (labels): {__label_" . $key . "}\n";
3520 4012 break;
3521 4013 case 'select':
3522 4014 case 'radio':
3523 - $tokens .= $field_name . " (label): {__label_" . $key . "}\n";
4015 + $tokens .= $value['name'] . " (label): {__label_" . $key . "}\n";
3524 4016 break;
3525 4017 case 'post-multicheckbox':
3526 - $tokens .= $field_name . " (posts titles): {__label_" . $key . "}\n";
3527 - $tokens .= $field_name . " (posts ids): {__post_id_" . $key . "}\n";
3528 - $tokens .= $field_name . " (posts urls): {__post_url_" . $key . "}\n";
4018 + $tokens .= $value['name'] . " (posts titles): {__label_" . $key . "}\n";
4019 + $tokens .= $value['name'] . " (posts ids): {__post_id_" . $key . "}\n";
4020 + $tokens .= $value['name'] . " (posts urls): {__post_url_" . $key . "}\n";
3529 4021 break;
3530 4022 case 'post-select':
3531 - $tokens .= $field_name . " (post title): {__label_" . $key . "}\n";
3532 - $tokens .= $field_name . " (post id): {__post_id_" . $key . "}\n";
3533 - $tokens .= $field_name . " (post url): {__post_url_" . $key . "}\n";
4023 + $tokens .= $value['name'] . " (post title): {__label_" . $key . "}\n";
4024 + $tokens .= $value['name'] . " (post id): {__post_id_" . $key . "}\n";
4025 + $tokens .= $value['name'] . " (post url): {__post_url_" . $key . "}\n";
3534 4026 break;
3535 4027 }
3536 4028 }
3537 4029
3538 - // phpcs:disable PluginCheck.CodeAnalysis.Heredoc.NotAllowed, WordPress.Security.EscapeOutput.HeredocOutputNotEscaped -- Heredoc for tokens help HTML
3539 4030 echo <<<EOT
3540 4031 <div class="accua_forms_token_list">
3541 4032 <h2>Tokens</h2>
3542 4033 <em>In HTML text, use {!token_name} to insert unfiltered token value</em>
@@ -3574,431 +4065,356 @@
3574 4065 {__confirmation_emails_message}
3575 4066 {__review_submission_url}</pre>
3576 4067 </div>
3577 4068 EOT;
3578 - // phpcs:enable PluginCheck.CodeAnalysis.Heredoc.NotAllowed, WordPress.Security.EscapeOutput.HeredocOutputNotEscaped
3579 4069 do_action('accua_forms_print_tokens');
3580 4070 }
3581 4071
3582 -/**
3583 - * Get posts/pages for post-select fields using get_posts() for WPML compatibility.
3584 - *
3585 - * Uses WordPress get_posts() instead of direct SQL to ensure WPML and other
3586 - * language plugins can filter results to current language automatically.
3587 - *
3588 - * Performance considerations:
3589 - * - Results are cached using transients (5 minute TTL) to reduce database queries
3590 - * - meta_key/meta_value queries are necessary for filtering by custom fields
3591 - * - post__not_in is used only when exclude is explicitly requested by admin
3592 - * - Default limit of 500 posts prevents runaway queries
3593 - *
3594 - * Hierarchy handling:
3595 - * - child_of returns all descendants of the given post; exclude_tree removes a
3596 - * post and all its descendants. Both are resolved to explicit ID lists via
3597 - * accua_forms_get_post_descendant_ids() before querying, so they remain
3598 - * correct with pagination and search.
3599 - * - hierarchical only affects ordering (parents before children) and only when
3600 - * the result set is complete and title-sorted; it never drops posts whose
3601 - * parent is unavailable (e.g. published children of draft parents).
3602 - *
3603 - * @since 2.0.0-beta.29
3604 - * @param string|array $args Query arguments (backward compatible with old function).
3605 - * @return array Array of post objects.
3606 - */
3607 4072 function accua_get_pages($args = '') {
3608 - // phpcs:disable WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude, WordPress.DB.SlowDBQuery.slow_db_query_meta_key, WordPress.DB.SlowDBQuery.slow_db_query_meta_value -- These are function parameter defaults, not actual query execution.
4073 + global $wpdb;
4074 +
3609 4075 $defaults = array(
3610 - 'child_of' => 0,
3611 - 'sort_order' => 'ASC',
3612 - 'sort_column' => 'post_title',
3613 - 'hierarchical' => 1,
3614 - 'exclude' => array(),
3615 - 'include' => array(),
3616 - 'meta_key' => '',
3617 - 'meta_value' => '',
3618 - 'meta_value_lt' => '',
3619 - 'meta_value_gt' => '',
3620 - 'meta_value_le' => '',
3621 - 'meta_value_ge' => '',
3622 - 'meta_value_like' => '',
3623 - 'meta_value_format' => 'string',
3624 - 'authors' => '',
3625 - 'parent' => -1,
3626 - 'exclude_tree' => '',
3627 - 'number' => 500, // Default limit for performance
3628 - 'offset' => 0,
3629 - 'post_type' => 'page',
3630 - 'post_status' => 'publish',
3631 - 'suppress_filters' => false, // IMPORTANT: Allow WPML to filter by language
3632 - 's' => '', // Search term (new parameter for AJAX search)
4076 + 'child_of' => 0,
4077 + 'sort_order' => 'ASC',
4078 + 'sort_column' => 'post_title',
4079 + 'hierarchical' => 1,
4080 + 'exclude' => array(),
4081 + 'include' => array(),
4082 + 'meta_key' => '',
4083 + 'meta_value' => '',
4084 + 'meta_value_lt' => '',
4085 + 'meta_value_gt' => '',
4086 + 'meta_value_le' => '',
4087 + 'meta_value_ge' => '',
4088 + 'meta_value_like' => '',
4089 + 'meta_value_format' => 'string',
4090 + 'authors' => '',
4091 + 'parent' => -1,
4092 + 'exclude_tree' => '',
4093 + 'number' => '',
4094 + 'offset' => 0,
4095 + 'post_type' => 'page',
4096 + 'post_status' => 'publish',
3633 4097 );
3634 - // phpcs:enable WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude, WordPress.DB.SlowDBQuery.slow_db_query_meta_key, WordPress.DB.SlowDBQuery.slow_db_query_meta_value
3635 4098
3636 - $r = wp_parse_args($args, $defaults);
4099 + $r = wp_parse_args( $args, $defaults );
4100 + $child_of = (int) $r['child_of'];
4101 + $sort_order = $r['sort_order'];
4102 + $sort_column = $r['sort_column'];
4103 + $hierarchical = $r['hierarchical'];
4104 + $exclude = $r['exclude'];
4105 + $include = $r['include'];
4106 + $meta_key = $r['meta_key'];
4107 + $meta_value = $r['meta_value'];
4108 + $meta_value_lt = $r['meta_value_lt'];
4109 + $meta_value_gt = $r['meta_value_gt'];
4110 + $meta_value_le = $r['meta_value_le'];
4111 + $meta_value_ge = $r['meta_value_ge'];
4112 + $meta_value_like = $r['meta_value_like'];
4113 + $meta_value_format = $r['meta_value_format'];
4114 + $authors = $r['authors'];
4115 + $parent = $r['parent'];
4116 + $exclude_tree = $r['exclude_tree'];
4117 + $number = (int) $r['number'];
4118 + $offset = (int) $r['offset'];
4119 + $post_type = $r['post_type'];
4120 + $post_status = $r['post_status'];
3637 4121
3638 - // Generate cache key based on arguments and current language
3639 - $cache_key_data = $r;
3640 - // Add current language to cache key for WPML/Polylang compatibility
3641 - if (function_exists('pll_current_language')) {
3642 - $cache_key_data['_lang'] = pll_current_language();
3643 - } elseif (defined('ICL_LANGUAGE_CODE')) {
3644 - $cache_key_data['_lang'] = ICL_LANGUAGE_CODE;
3645 - }
3646 - $cache_key = 'accua_pages_' . md5(wp_json_encode($cache_key_data));
4122 + /*
4123 + // Make sure the post type is hierarchical
4124 + $hierarchical_post_types = get_post_types( array( 'hierarchical' => true ) );
4125 + if ( !in_array( $post_type, $hierarchical_post_types ) )
4126 + return false;
4127 + */
3647 4128
3648 - // Check transient cache first (skip for search queries and random ordering)
3649 - $use_cache = empty($r['s']) && $r['sort_column'] !== 'rand';
3650 - if ($use_cache) {
3651 - $cached = get_transient($cache_key);
3652 - if ($cached !== false) {
3653 - return $cached;
3654 - }
3655 - }
4129 + // Make sure we have a valid post type
4130 + if ( !is_array( $post_type ) )
4131 + $post_type = explode( ',', $post_type );
4132 + if ( array_diff( $post_type, get_post_types() ) )
4133 + return false;
3656 4134
3657 - // Validate post type
3658 - $post_type = $r['post_type'];
3659 - if (!is_array($post_type)) {
3660 - $post_type = array_map('trim', explode(',', $post_type));
3661 - }
3662 - $valid_post_types = get_post_types();
3663 - $post_type = array_filter($post_type, function($pt) use ($valid_post_types) {
3664 - return in_array($pt, $valid_post_types, true);
3665 - });
3666 - if (empty($post_type)) {
3667 - return array();
3668 - }
4135 + // Make sure we have a valid post status
4136 + if ( !is_array( $post_status ) )
4137 + $post_status = explode( ',', $post_status );
4138 + if ( array_diff( $post_status, get_post_stati() ) )
4139 + return false;
3669 4140
3670 - // Validate post status
3671 - $post_status = $r['post_status'];
3672 - if (!is_array($post_status)) {
3673 - $post_status = array_map('trim', explode(',', $post_status));
4141 + /*
4142 + $cache = array();
4143 + $key = md5( serialize( compact(array_keys($defaults)) ) );
4144 + if ( $cache = wp_cache_get( 'get_pages', 'posts' ) ) {
4145 + if ( is_array($cache) && isset( $cache[ $key ] ) ) {
4146 + $pages = apply_filters('get_pages', $cache[ $key ], $r );
4147 + return $pages;
3674 4148 }
3675 - $valid_statuses = get_post_stati();
3676 - $post_status = array_filter($post_status, function($ps) use ($valid_statuses) {
3677 - return in_array($ps, $valid_statuses, true);
3678 - });
3679 - if (empty($post_status)) {
3680 - $post_status = array('publish');
3681 4149 }
3682 4150
3683 - // Map sort_column to orderby
3684 - $orderby_map = array(
3685 - 'post_title' => 'title',
3686 - 'title' => 'title',
3687 - 'post_date' => 'date',
3688 - 'date' => 'date',
3689 - 'post_modified' => 'modified',
3690 - 'modified' => 'modified',
3691 - 'menu_order' => 'menu_order',
3692 - 'post_name' => 'name',
3693 - 'name' => 'name',
3694 - 'post_parent' => 'parent',
3695 - 'parent' => 'parent',
3696 - 'ID' => 'ID',
3697 - 'rand' => 'rand',
3698 - 'comment_count' => 'comment_count',
3699 - 'post_author' => 'author',
3700 - 'author' => 'author',
3701 - );
3702 - $sort_column = $r['sort_column'];
3703 - $orderby = isset($orderby_map[$sort_column]) ? $orderby_map[$sort_column] : 'title';
4151 + if ( !is_array($cache) )
4152 + $cache = array();
4153 + */
3704 4154
3705 - // Build get_posts arguments
3706 - $query_args = array(
3707 - 'post_type' => $post_type,
3708 - 'post_status' => $post_status,
3709 - 'orderby' => $orderby,
3710 - 'order' => strtoupper($r['sort_order']) === 'DESC' ? 'DESC' : 'ASC',
3711 - 'posts_per_page' => !empty($r['number']) ? (int) $r['number'] : 500,
3712 - 'offset' => (int) $r['offset'],
3713 - 'suppress_filters' => (bool) $r['suppress_filters'],
3714 - );
3715 -
3716 - // Search term
3717 - if (!empty($r['s'])) {
3718 - $query_args['s'] = sanitize_text_field($r['s']);
4155 + $inclusions = '';
4156 + if ( !empty($include) ) {
4157 + $child_of = 0; //ignore child_of, parent, exclude, meta_key, and meta_value params if using include
4158 + $parent = -1;
4159 + $exclude = '';
4160 + $meta_key = '';
4161 + $meta_value = '';
4162 + $meta_value_lt = '';
4163 + $meta_value_gt = '';
4164 + $meta_value_le = '';
4165 + $meta_value_ge = '';
4166 + $meta_value_like = '';
4167 + $hierarchical = false;
4168 + $incpages = wp_parse_id_list( $include );
4169 + if ( ! empty( $incpages ) ) {
4170 + foreach ( $incpages as $incpage ) {
4171 + if (empty($inclusions))
4172 + $inclusions = $wpdb->prepare(' AND ( ID = %d ', $incpage);
4173 + else
4174 + $inclusions .= $wpdb->prepare(' OR ID = %d ', $incpage);
4175 + }
4176 + }
3719 4177 }
4178 + if (!empty($inclusions))
4179 + $inclusions .= ')';
3720 4180
3721 - // Include specific posts (overrides other filters)
3722 - if (!empty($r['include'])) {
3723 - $include = wp_parse_id_list($r['include']);
3724 - if (!empty($include)) {
3725 - $query_args['post__in'] = $include;
3726 - $query_args['orderby'] = 'post__in'; // Preserve include order
4181 + $exclusions = '';
4182 + if ( !empty($exclude) ) {
4183 + $expages = wp_parse_id_list( $exclude );
4184 + if ( ! empty( $expages ) ) {
4185 + foreach ( $expages as $expage ) {
4186 + if (empty($exclusions))
4187 + $exclusions = $wpdb->prepare(' AND ( ID <> %d ', $expage);
4188 + else
4189 + $exclusions .= $wpdb->prepare(' AND ID <> %d ', $expage);
4190 + }
3727 4191 }
3728 - } else {
3729 - // Exclude posts - only used when admin explicitly configures exclusions.
3730 - // exclude_tree also removes all descendants of the given post, resolved
3731 - // against the full tree so it works with pagination and search.
3732 - $exclude_ids = array();
3733 - if (!empty($r['exclude'])) {
3734 - $exclude_ids = wp_parse_id_list($r['exclude']);
3735 - }
3736 - if (!empty($r['exclude_tree'])) {
3737 - $exclude_tree = (int) $r['exclude_tree'];
3738 - $exclude_ids = array_merge($exclude_ids, array($exclude_tree), accua_forms_get_post_descendant_ids($exclude_tree, $post_type));
3739 - }
4192 + }
4193 + if (!empty($exclusions))
4194 + $exclusions .= ')';
3740 4195
3741 - // Child of: restrict to all descendants of the given post, like core get_pages().
3742 - // Resolved to an explicit ID list so it stays correct with pagination and search.
3743 - if (!empty($r['child_of'])) {
3744 - $descendant_ids = accua_forms_get_post_descendant_ids((int) $r['child_of'], $post_type);
3745 - // post__in cannot be combined with post__not_in, so exclusions are applied to the list itself.
3746 - $descendant_ids = array_values(array_diff($descendant_ids, $exclude_ids));
3747 - $query_args['post__in'] = !empty($descendant_ids) ? $descendant_ids : array(0);
3748 - } elseif (!empty($exclude_ids)) {
3749 - // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_post__not_in -- Exclusion is an optional admin-configured feature, not default behavior.
3750 - $query_args['post__not_in'] = $exclude_ids;
3751 - }
4196 + $author_query = '';
4197 + if (!empty($authors)) {
4198 + $post_authors = preg_split('/[\s,]+/',$authors);
3752 4199
3753 - // Parent filter (direct children only)
3754 - if ((int) $r['parent'] >= 0) {
3755 - $query_args['post_parent'] = (int) $r['parent'];
3756 - }
4200 + if ( ! empty( $post_authors ) ) {
4201 + foreach ( $post_authors as $post_author ) {
4202 + //Do we have an author id or an author login?
4203 + if ( 0 == intval($post_author) ) {
4204 + $post_author = get_user_by('login', $post_author);
4205 + if ( empty($post_author) )
4206 + continue;
4207 + if ( empty($post_author->ID) )
4208 + continue;
4209 + $post_author = $post_author->ID;
4210 + }
3757 4211
3758 - // Authors filter
3759 - if (!empty($r['authors'])) {
3760 - $author_ids = array();
3761 - $post_authors = preg_split('/[\s,]+/', $r['authors']);
3762 - foreach ($post_authors as $post_author) {
3763 - $post_author = trim($post_author);
3764 - if (empty($post_author)) {
3765 - continue;
3766 - }
3767 - if (is_numeric($post_author)) {
3768 - $author_ids[] = (int) $post_author;
3769 - } else {
3770 - $user = get_user_by('login', $post_author);
3771 - if ($user && !empty($user->ID)) {
3772 - $author_ids[] = $user->ID;
3773 - }
3774 - }
4212 + if ( '' == $author_query )
4213 + $author_query = $wpdb->prepare(' post_author = %d ', $post_author);
4214 + else
4215 + $author_query .= $wpdb->prepare(' OR post_author = %d ', $post_author);
3775 4216 }
3776 - if (!empty($author_ids)) {
3777 - $query_args['author__in'] = $author_ids;
3778 - }
4217 + if ( '' != $author_query )
4218 + $author_query = " AND ($author_query)";
3779 4219 }
4220 + }
3780 4221
3781 - // Build meta_query for advanced meta comparisons
3782 - $meta_query = array();
4222 + $allowed_keys = array('author', 'post_author', 'date', 'post_date', 'title', 'post_title', 'name', 'post_name', 'modified',
4223 + 'post_modified', 'modified_gmt', 'post_modified_gmt', 'menu_order', 'parent', 'post_parent',
4224 + 'ID', 'rand', 'comment_count');
3783 4225
3784 - // Standard meta_key/meta_value - used for filtering posts by custom field.
3785 - // This is an optional admin-configured feature for advanced post filtering.
3786 - if (!empty($r['meta_key'])) {
3787 - // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_key -- Required for custom field filtering feature.
3788 - $query_args['meta_key'] = stripslashes($r['meta_key']);
3789 - if (!empty($r['meta_value'])) {
3790 - // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_value -- Required for custom field filtering feature.
3791 - $query_args['meta_value'] = stripslashes($r['meta_value']);
3792 - }
4226 + $join = '';
4227 + $where = "$exclusions $inclusions ";
4228 + if ( ! ( empty( $meta_key ) && empty( $meta_value )
4229 + && empty( $meta_value_lt ) && empty( $meta_value_gt )
4230 + && empty( $meta_value_le ) && empty( $meta_value_ge )
4231 + && empty( $meta_value_like ) ) ) {
4232 + $join = " LEFT JOIN $wpdb->postmeta ON ( $wpdb->posts.ID = $wpdb->postmeta.post_id )";
4233 + $allowed_keys[] = 'meta_key';
4234 + $allowed_keys[] = 'meta_value';
4235 +
4236 + // meta_key and meta_value might be slashed
4237 + $meta_key = stripslashes($meta_key);
4238 + $meta_value = stripslashes($meta_value);
4239 + $meta_value_lt = stripslashes($meta_value_lt);
4240 + $meta_value_gt = stripslashes($meta_value_gt);
4241 + $meta_value_le = stripslashes($meta_value_le);
4242 + $meta_value_ge = stripslashes($meta_value_ge);
4243 + $meta_value_like = stripslashes($meta_value_like);
4244 +
4245 + if ( ! empty( $meta_key ) ) {
4246 + $where .= $wpdb->prepare(" AND $wpdb->postmeta.meta_key = %s", $meta_key);
3793 4247 }
3794 4248
3795 - // Advanced meta comparisons (lt, gt, le, ge, like)
3796 - if (!empty($r['meta_key']) && (
3797 - !empty($r['meta_value_lt']) || !empty($r['meta_value_gt']) ||
3798 - !empty($r['meta_value_le']) || !empty($r['meta_value_ge']) ||
3799 - !empty($r['meta_value_like'])
3800 - )) {
3801 - $meta_key = stripslashes($r['meta_key']);
3802 - $meta_type = 'CHAR';
3803 - switch ($r['meta_value_format']) {
3804 - case 'int':
3805 - $meta_type = 'NUMERIC';
3806 - break;
3807 - case 'float':
3808 - $meta_type = 'DECIMAL';
3809 - break;
3810 - case 'timestamp':
3811 - $meta_type = 'DATETIME';
3812 - break;
3813 - }
4249 + $meta_value_field = "$wpdb->postmeta.meta_value";
4250 + $meta_value_timestamp = false;
4251 + switch($meta_value_format) {
4252 + case 'timestamp':
4253 + $meta_value_field = "TIMESTAMP( $meta_value_field )";
4254 + $meta_value_param = "FROM_UNIXTIME( %s )";
4255 + $meta_value_timestamp = true;
4256 + break;
4257 + case 'int':
4258 + $meta_value_param = "%d";
4259 + break;
4260 + case 'float':
4261 + $meta_value_param = "%f";
4262 + break;
4263 + //case 'string':
4264 + default:
4265 + $meta_value_param = "%s";
4266 + }
3814 4267
3815 - if (!empty($r['meta_value_lt'])) {
3816 - $value = stripslashes($r['meta_value_lt']);
3817 - if ($r['meta_value_format'] === 'timestamp') {
3818 - $value = gmdate('Y-m-d H:i:s', strtotime($value));
3819 - }
3820 - $meta_query[] = array(
3821 - 'key' => $meta_key,
3822 - 'value' => $value,
3823 - 'compare' => '<',
3824 - 'type' => $meta_type,
3825 - );
4268 + if ( ! empty( $meta_value ) ) {
4269 + if ($meta_value_timestamp) {
4270 + $meta_value = strtotime($meta_value);
3826 4271 }
3827 - if (!empty($r['meta_value_gt'])) {
3828 - $value = stripslashes($r['meta_value_gt']);
3829 - if ($r['meta_value_format'] === 'timestamp') {
3830 - $value = gmdate('Y-m-d H:i:s', strtotime($value));
3831 - }
3832 - $meta_query[] = array(
3833 - 'key' => $meta_key,
3834 - 'value' => $value,
3835 - 'compare' => '>',
3836 - 'type' => $meta_type,
3837 - );
4272 + $where .= $wpdb->prepare(" AND $meta_value_field = $meta_value_param", $meta_value);
4273 + }
4274 + if ( ! empty( $meta_value_lt ) ) {
4275 + if ($meta_value_timestamp) {
4276 + $meta_value_lt = strtotime($meta_value_lt);
3838 4277 }
3839 - if (!empty($r['meta_value_le'])) {
3840 - $value = stripslashes($r['meta_value_le']);
3841 - if ($r['meta_value_format'] === 'timestamp') {
3842 - $value = gmdate('Y-m-d H:i:s', strtotime($value));
3843 - }
3844 - $meta_query[] = array(
3845 - 'key' => $meta_key,
3846 - 'value' => $value,
3847 - 'compare' => '<=',
3848 - 'type' => $meta_type,
3849 - );
4278 + $where .= $wpdb->prepare(" AND $meta_value_field < $meta_value_param", $meta_value_lt);
4279 + }
4280 + if ( ! empty( $meta_value_gt ) ) {
4281 + if ($meta_value_timestamp) {
4282 + $meta_value_gt = strtotime($meta_value_gt);
3850 4283 }
3851 - if (!empty($r['meta_value_ge'])) {
3852 - $value = stripslashes($r['meta_value_ge']);
3853 - if ($r['meta_value_format'] === 'timestamp') {
3854 - $value = gmdate('Y-m-d H:i:s', strtotime($value));
3855 - }
3856 - $meta_query[] = array(
3857 - 'key' => $meta_key,
3858 - 'value' => $value,
3859 - 'compare' => '>=',
3860 - 'type' => $meta_type,
3861 - );
4284 + $where .= $wpdb->prepare(" AND $meta_value_field > $meta_value_param", $meta_value_gt);
4285 + }
4286 + if ( ! empty( $meta_value_le ) ) {
4287 + if ($meta_value_timestamp) {
4288 + $meta_value_le = strtotime($meta_value_le);
3862 4289 }
3863 - if (!empty($r['meta_value_like'])) {
3864 - $meta_query[] = array(
3865 - 'key' => $meta_key,
3866 - 'value' => stripslashes($r['meta_value_like']),
3867 - 'compare' => 'LIKE',
3868 - );
4290 + $where .= $wpdb->prepare(" AND $meta_value_field <= $meta_value_param", $meta_value_le);
4291 + }
4292 + if ( ! empty( $meta_value_ge ) ) {
4293 + if ($meta_value_timestamp) {
4294 + $meta_value_ge = strtotime($meta_value_ge);
3869 4295 }
3870 -
3871 - if (!empty($meta_query)) {
3872 - // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query -- Required for advanced meta comparison operators (lt, gt, like, etc.).
3873 - $query_args['meta_query'] = $meta_query;
3874 - // Remove simple meta_value if we're using meta_query
3875 - unset($query_args['meta_value']);
4296 + $where .= $wpdb->prepare(" AND $meta_value_field >= $meta_value_param", $meta_value_ge);
4297 + }
4298 + if ( ! empty( $meta_value_like ) ) {
4299 + if ($meta_value_timestamp) {
4300 + $meta_value_like = strtotime($meta_value_like);
3876 4301 }
4302 + $where .= $wpdb->prepare(" AND $meta_value_field like $meta_value_param", $meta_value_like);
3877 4303 }
3878 4304 }
3879 4305
3880 - // Get posts using WordPress function (WPML automatically filters by current language)
3881 - $pages = get_posts($query_args);
4306 + if ( $parent >= 0 )
4307 + $where .= $wpdb->prepare(' AND post_parent = %d ', $parent);
3882 4308
3883 - if (empty($pages)) {
3884 - // Cache empty results too (5 minutes)
3885 - if ($use_cache) {
3886 - set_transient($cache_key, array(), 5 * MINUTE_IN_SECONDS);
4309 +
4310 + if ( 1 == count ( $post_type ) ) {
4311 + $where_post_type = $wpdb->prepare( "post_type = %s", array_shift( $post_type ) );
4312 + } else {
4313 + $post_type = implode( "', '", $post_type );
4314 + $where_post_type = "post_type IN ('$post_type')";
4315 + }
4316 +
4317 + if ( 1 == count( $post_status ) ) {
4318 + $where_post_type .= $wpdb->prepare( " AND post_status = %s", array_shift( $post_status ) );
4319 + } else {
4320 + $post_status = implode( "', '", $post_status );
4321 + $where_post_type .= " AND post_status IN ('$post_status')";
4322 + }
4323 +
4324 + $orderby_array = array();
4325 + foreach ( explode( ',', $sort_column ) as $orderby ) {
4326 + $orderby = trim( $orderby );
4327 + if ( !in_array( $orderby, $allowed_keys ) )
4328 + continue;
4329 +
4330 + switch ( $orderby ) {
4331 + case 'menu_order':
4332 + break;
4333 + case 'ID':
4334 + $orderby = "$wpdb->posts.ID";
4335 + break;
4336 + case 'rand':
4337 + $orderby = 'RAND()';
4338 + break;
4339 + case 'comment_count':
4340 + $orderby = "$wpdb->posts.comment_count";
4341 + break;
4342 + case 'meta_key':
4343 + case 'meta_value':
4344 + $orderby = "$wpdb->postmeta.$orderby";
4345 + break;
4346 + default:
4347 + if ( 0 === strpos( $orderby, 'post_' ) )
4348 + $orderby = "$wpdb->posts." . $orderby;
4349 + else
4350 + $orderby = "$wpdb->posts.post_" . $orderby;
3887 4351 }
3888 - /**
3889 - * Filters the list of pages retrieved from accua_get_pages.
3890 - *
3891 - * @since 2.0.0-beta.29
3892 - *
3893 - * @param array $pages List of page objects.
3894 - * @param array $r Arguments passed to accua_get_pages.
3895 - */
3896 - return apply_filters('accua_forms_get_pages', array(), $r);
4352 +
4353 + $orderby_array[] = $orderby;
4354 +
3897 4355 }
4356 + $sort_column = ! empty( $orderby_array ) ? implode( ',', $orderby_array ) : "$wpdb->posts.post_title";
3898 4357
3899 - // Hierarchical (tree) ordering: list parents before their children, like core
3900 - // get_pages(). Only applied when the result set is complete (no search, no
3901 - // offset, not truncated by the limit) and title-sorted — reordering a paginated
3902 - // or filtered slice would drop children whose parent is not in the same slice.
3903 - if ($r['hierarchical'] && empty($r['s']) && (int) $r['offset'] === 0
3904 - && count($pages) < (int) $query_args['posts_per_page']
3905 - && $orderby === 'title'
3906 - && function_exists('get_page_children')) {
3907 - $tree_ordered = get_page_children((int) $r['child_of'], $pages);
3908 - if (count($tree_ordered) < count($pages)) {
3909 - // Posts whose ancestors are not part of the result set (e.g. published
3910 - // children of a draft parent) go at the end instead of being dropped.
3911 - $tree_ids = array();
3912 - foreach ($tree_ordered as $page) {
3913 - $tree_ids[$page->ID] = true;
3914 - }
3915 - foreach ($pages as $page) {
3916 - if (!isset($tree_ids[$page->ID])) {
3917 - $tree_ordered[] = $page;
3918 - }
3919 - }
3920 - }
3921 - $pages = $tree_ordered;
4358 + $sort_order = strtoupper( $sort_order );
4359 + if ( '' !== $sort_order && !in_array( $sort_order, array( 'ASC', 'DESC' ) ) )
4360 + $sort_order = 'ASC';
4361 +
4362 + $query = "SELECT * FROM $wpdb->posts $join WHERE ($where_post_type) $where ";
4363 + $query .= $author_query;
4364 + $query .= " ORDER BY " . $sort_column . " " . $sort_order ;
4365 +
4366 + if ( !empty($number) && !empty($offset) ) {
4367 + $query .= $wpdb->prepare(' LIMIT %d, %d', $offset, $number);
3922 4368 }
3923 4369
3924 - // Cache results for 5 minutes to improve performance
3925 - if ($use_cache) {
3926 - set_transient($cache_key, $pages, 5 * MINUTE_IN_SECONDS);
4370 + //echo "<!-- accua_forms_query:\n$query\n-->";
4371 +
4372 + $pages = $wpdb->get_results($query);
4373 +
4374 + if ( empty($pages) ) {
4375 + $pages = apply_filters('get_pages', array(), $r);
4376 + return $pages;
3927 4377 }
3928 4378
3929 - /** This filter is documented above */
3930 - return apply_filters('accua_forms_get_pages', $pages, $r);
3931 -}
4379 + // Sanitize before caching so it'll only get done once
4380 + $num_pages = count($pages);
4381 + for ($i = 0; $i < $num_pages; $i++) {
4382 + $pages[$i] = sanitize_post($pages[$i], 'raw');
4383 + }
3932 4384
3933 -/**
3934 - * Get the IDs of all descendants of a post by traversing the post_parent tree.
3935 - *
3936 - * Used to resolve the child_of and exclude_tree arguments of accua_get_pages()
3937 - * to an explicit ID list, so the main query stays correct with pagination and
3938 - * search. Traverses posts of any status so that e.g. a published grandchild of
3939 - * a draft child is still found (the main query applies its own status filter).
3940 - *
3941 - * @since 2.2.27
3942 - * @param int $parent_id Root post ID (not included in the result).
3943 - * @param string|array $post_type Post type(s) to traverse.
3944 - * @return int[] Descendant post IDs.
3945 - */
3946 -function accua_forms_get_post_descendant_ids($parent_id, $post_type) {
3947 - $descendant_ids = array();
3948 - $level = array((int) $parent_id);
3949 - // Depth guard: hierarchies deeper than 25 levels are treated as data corruption (parent loops).
3950 - for ($depth = 0; $depth < 25 && !empty($level); $depth++) {
3951 - $children = get_posts(array(
3952 - 'post_type' => $post_type,
3953 - 'post_status' => 'any',
3954 - 'post_parent__in' => $level,
3955 - 'posts_per_page' => -1,
3956 - 'fields' => 'ids',
3957 - 'suppress_filters' => true, // Structural traversal: do not let language plugins hide ancestors.
3958 - 'orderby' => 'ID',
3959 - 'order' => 'ASC',
3960 - ));
3961 - $children = array_map('intval', array_diff($children, $descendant_ids, array((int) $parent_id)));
3962 - $descendant_ids = array_merge($descendant_ids, $children);
3963 - $level = $children;
4385 + /*
4386 + // Update cache.
4387 + update_post_cache( $pages );
4388 + */
4389 +
4390 + if ( $child_of || $hierarchical )
4391 + $pages = get_page_children($child_of, $pages);
4392 +
4393 + if ( !empty($exclude_tree) ) {
4394 + $exclude = (int) $exclude_tree;
4395 + $children = get_page_children($exclude, $pages);
4396 + $excludes = array();
4397 + foreach ( $children as $child )
4398 + $excludes[] = $child->ID;
4399 + $excludes[] = $exclude;
4400 + $num_pages = count($pages);
4401 + for ( $i = 0; $i < $num_pages; $i++ ) {
4402 + if ( in_array($pages[$i]->ID, $excludes) )
4403 + unset($pages[$i]);
4404 + }
3964 4405 }
3965 - return $descendant_ids;
4406 +
4407 + $pages = apply_filters('get_pages', $pages, $r);
4408 +
4409 + return $pages;
3966 4410 }
3967 4411
3968 -// phpcs:disable WordPress.DB.DirectDatabaseQuery
3969 4412 function accua_forms_trash_submission($id_sub){
3970 4413 global $wpdb;
3971 4414 return $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}accua_forms_submissions` SET afs_status = -1 WHERE afs_id = %d", $id_sub)) !== FALSE;
3972 4415 }
3973 4416
3974 -function accua_forms_restore_submission($id_sub){
3975 - global $wpdb;
3976 - return $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}accua_forms_submissions` SET afs_status = 0 WHERE afs_id = %d", $id_sub)) !== FALSE;
3977 -}
3978 -// phpcs:enable WordPress.DB.DirectDatabaseQuery
3979 -
3980 -/**
3981 - * Clear accua_get_pages cache when posts are modified.
3982 - *
3983 - * Called when posts are created, updated, deleted, or have status changed.
3984 - * This ensures that post-select dropdowns always show fresh data.
3985 - *
3986 - * @since 2.0.0-beta.29
3987 - * @param int $post_id Post ID that was modified.
3988 - */
3989 -function accua_forms_clear_pages_cache($post_id = 0) {
3990 - global $wpdb;
3991 - // Delete all transients that start with 'accua_pages_'
3992 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Direct query required to delete transients by prefix, and we're clearing cache not reading data.
3993 - $wpdb->query("DELETE FROM {$wpdb->options} WHERE option_name LIKE '_transient_accua_pages_%' OR option_name LIKE '_transient_timeout_accua_pages_%'");
3994 -}
3995 -// Clear cache when posts are modified
3996 -add_action('save_post', 'accua_forms_clear_pages_cache');
3997 -add_action('delete_post', 'accua_forms_clear_pages_cache');
3998 -add_action('trash_post', 'accua_forms_clear_pages_cache');
3999 -add_action('untrash_post', 'accua_forms_clear_pages_cache');
4000 -
4001 4417 function accua_forms_get_lead_statuses() {
4002 4418 static $statuses = NULL;
4003 4419 if ($statuses === NULL) {
4004 4420 $statuses = array(
@@ -4015,33 +4431,24 @@
4015 4431 }
4016 4432 return $statuses;
4017 4433 }
4018 4434
4019 -/**
4020 - * Get lead statuses help text (used in toggletip and Help Tab).
4021 - */
4022 -function accua_forms_get_lead_statuses_help() {
4023 - return '<strong>' . esc_html__( 'Spam', 'contact-forms' ) . '</strong> – ' . esc_html__( 'All submissions that can be discarded immediately, including submission tests', 'contact-forms' ) . '<br>'
4024 - . '<strong>' . esc_html__( 'Job Candidate', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Includes spontaneous and specific job applications', 'contact-forms' ) . '<br>'
4025 - . '<strong>' . esc_html__( 'Lead', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Unclear (general info request)', 'contact-forms' ) . '<br>'
4026 - . '<strong>' . esc_html__( 'Prospect', 'contact-forms' ) . '</strong> – ' . esc_html__( 'A qualified lead passed to Sales', 'contact-forms' ) . '<br>'
4027 - . '<strong>' . esc_html__( 'Opportunity', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Quote / Pricing request that must be followed up', 'contact-forms' ) . '<br>'
4028 - . '<strong>' . esc_html__( 'Customer', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Has already purchased', 'contact-forms' ) . '<br>'
4029 - . '<strong>' . esc_html__( 'Supplier', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Contact whose role is or can only be supplier of goods and services', 'contact-forms' ) . '<br>'
4030 - . '<strong>' . esc_html__( 'Other', 'contact-forms' ) . '</strong> – ' . esc_html__( 'Contact is valid but not within lead generation', 'contact-forms' );
4031 -}
4032 -
4033 4435 function accua_forms_select_lead_status($subid, $original_lead_status) {
4034 - $subid = absint( $subid );
4035 - $original_lead_status = absint( $original_lead_status );
4036 - $nonce = esc_attr( wp_json_encode( wp_create_nonce( "set_lead_status_$subid" ) ) );
4037 - $ret = '<select onchange="accua_forms_set_lead_status(this, ' . $subid . ', ' . $nonce . ', ' . $original_lead_status . ')">';
4436 + static $accuaHelp = NULL;
4437 + if ($accuaHelp === NULL) {
4438 + if (!class_exists('AccuaFormsHelp')) {
4439 + require_once('accua-forms-help.php');
4440 + }
4441 + $accuaHelp = AccuaFormsHelp::getInstance();
4442 + }
4443 + $nonce = htmlspecialchars(_accua_forms_json_encode(wp_create_nonce( "set_lead_status_$subid" )),ENT_QUOTES);
4444 + $ret = "<select onchange=\"accua_forms_set_lead_status(this, $subid, $nonce, $original_lead_status)\">";
4038 4445 $statuses = accua_forms_get_lead_statuses();
4039 4446 foreach ($statuses as $k => $l) {
4040 - $selected = ( (int) $k === $original_lead_status ) ? ' selected="selected" ' : '';
4041 - $ret .= '<option value="' . esc_attr( $k ) . '"' . $selected . '>' . esc_html( $l ) . '</option>';
4447 + $selected = ($k == $original_lead_status) ? ' selected="selected" ' : '';
4448 + $ret .= "<option value=\"$k\"$selected>" . htmlspecialchars($l) . "</option>";
4042 4449 }
4043 - $ret .= '</select>';
4450 + $ret .= "</select>" . $accuaHelp->add_pointer('contact_forms_lead_statuses') . "<span class='accua-forms-select-lead-status-progress'></span>";
4044 4451 return $ret;
4045 4452 }
4046 4453
4047 4454 add_action( 'wp_ajax_accua-forms-set-lead-status' , 'accua_forms_set_lead_status');
@@ -4048,9 +4455,8 @@
4048 4455 function accua_forms_set_lead_status() {
4049 4456 if (!current_user_can('manage_options')){
4050 4457 wp_die(0, 403);
4051 4458 }
4052 - // phpcs:ignore WordPress.Security.NonceVerification.Missing -- Nonce verification happens after subid is extracted via check_ajax_referer()
4053 4459 $post = $_POST + array(
4054 4460 'subid' => 0,
4055 4461 'lead_status' => 0,
4056 4462 );
@@ -4061,62 +4467,16 @@
4061 4467 $lead_status = (int) $post['lead_status'];
4062 4468 $statuses = accua_forms_get_lead_statuses();
4063 4469 if (isset($statuses[$lead_status])) {
4064 4470 global $wpdb;
4065 - // phpcs:disable WordPress.DB.DirectDatabaseQuery
4066 - $ret = $wpdb->update(
4067 - "{$wpdb->prefix}accua_forms_submissions",
4471 + $ret = $wpdb->update("{$wpdb->prefix}accua_forms_submissions",
4068 4472 array('afs_lead_status' => $lead_status),
4069 4473 array('afs_id' => $subid),
4070 - array('%d'),
4071 - array('%d')
4474 + '%d', '%d'
4072 4475 );
4073 - // phpcs:enable WordPress.DB.DirectDatabaseQuery
4074 4476 if ($ret !== FALSE) {
4075 - wp_die(1);
4477 + wp_die(1, 200);
4076 4478 }
4077 4479 }
4078 4480 }
4079 4481 wp_die(0, 500);
4080 4482 }
4081 -
4082 -add_action( 'wp_ajax_accua-forms-add-note', 'accua_forms_ajax_add_note' );
4083 -function accua_forms_ajax_add_note() {
4084 - $sub_id = isset( $_POST['subid'] ) ? (int) $_POST['subid'] : 0;
4085 - $text = isset( $_POST['text'] ) ? sanitize_textarea_field( wp_unslash( $_POST['text'] ) ) : '';
4086 -
4087 - if ( ! $sub_id || ! $text ) {
4088 - wp_send_json_error();
4089 - }
4090 - check_ajax_referer( "submission_{$sub_id}_note_add", '_nonce' );
4091 - if ( ! current_user_can( 'manage_options' ) ) {
4092 - wp_send_json_error();
4093 - }
4094 -
4095 - require_once __DIR__ . '/admin/single-submission.php';
4096 - $result = accua_forms_add_submission_note( $sub_id, $text );
4097 - if ( ! $result ) {
4098 - wp_send_json_error();
4099 - }
4100 - $result['del_nonce'] = wp_create_nonce( "submission_{$sub_id}_note_del" );
4101 - wp_send_json_success( $result );
4102 -}
4103 -
4104 -add_action( 'wp_ajax_accua-forms-delete-note', 'accua_forms_ajax_delete_note' );
4105 -function accua_forms_ajax_delete_note() {
4106 - $sub_id = isset( $_POST['subid'] ) ? (int) $_POST['subid'] : 0;
4107 - $date = isset( $_POST['date'] ) ? sanitize_text_field( wp_unslash( $_POST['date'] ) ) : '';
4108 -
4109 - if ( ! $sub_id || ! $date ) {
4110 - wp_send_json_error();
4111 - }
4112 - check_ajax_referer( "submission_{$sub_id}_note_del", '_nonce' );
4113 - if ( ! current_user_can( 'manage_options' ) ) {
4114 - wp_send_json_error();
4115 - }
4116 -
4117 - require_once __DIR__ . '/admin/single-submission.php';
4118 - if ( ! accua_forms_delete_submission_note( $sub_id, $date ) ) {
4119 - wp_send_json_error();
4120 - }
4121 - wp_send_json_success();
4122 -}