| @@ -132,9 +132,9 @@ | ||
| 132 | 132 | ); |
| 133 | 133 | } |
| 134 | 134 | |
| 135 | 135 | // If the token verified, return true. |
| 136 | - if ( $body['success'] === true ) { | |
| 136 | + if ( isset( $body['success'] ) && $body['success'] === true ) { | |
| 137 | 137 | return true; |
| 138 | 138 | } |
| 139 | 139 | |
| 140 | 140 | // Return an error. |
| @@ -142,9 +142,9 @@ | ||
| 142 | 142 | 'convertkit_cloudflare_turnstile_failed', |
| 143 | 143 | sprintf( |
| 144 | 144 | /* translators: Error codes */ |
| 145 | 145 | __( 'Cloudflare Turnstile failure: %s', 'convertkit' ), |
| 146 | - implode( ', ', $body['error-codes'] ) | |
| 146 | + implode( ', ', isset( $body['error-codes'] ) ? (array) $body['error-codes'] : array() ) | |
| 147 | 147 | ) |
| 148 | 148 | ); |
| 149 | 149 | |
| 150 | 150 | } |
| @@ -152,10 +152,11 @@ | ||
| 152 | 152 | /** |
| 153 | 153 | * Inserts a Cloudflare Turnstile widget div immediately before the given |
| 154 | 154 | * submit button within an existing DOM tree. `data-appearance=interaction-only` |
| 155 | 155 | * keeps the widget invisible unless Cloudflare determines a challenge is |
| 156 | - * required, and the `convertKitTurnstileFormSubmit` callback submits the | |
| 157 | - * enclosing form once the challenge is solved. | |
| 156 | + * required. `data-execution=execute` prevents the challenge running until the | |
| 157 | + * form is submitted, and the `convertKitTurnstileFormSubmit` callback then | |
| 158 | + * submits the form once the challenge is solved. | |
| 158 | 159 | * |
| 159 | 160 | * @since 3.3.7 |
| 160 | 161 | * |
| 161 | 162 | * @param ConvertKit_HTML_Parser $parser Parser wrapping the DOM. |
| @@ -169,8 +170,9 @@ | ||
| 169 | 170 | $widget = $parser->html->createElement( 'div' ); |
| 170 | 171 | $widget->setAttribute( 'class', 'cf-turnstile' ); |
| 171 | 172 | $widget->setAttribute( 'data-sitekey', esc_attr( $this->settings->cloudflare_turnstile_site_key() ) ); |
| 172 | 173 | $widget->setAttribute( 'data-appearance', 'interaction-only' ); |
| 174 | + $widget->setAttribute( 'data-execution', 'execute' ); | |
| 173 | 175 | $widget->setAttribute( 'data-callback', 'convertKitTurnstileFormSubmit' ); |
| 174 | 176 | $button->parentNode->insertBefore( $widget, $button ); // phpcs:ignore WordPress.NamingConventions.ValidVariableName.UsedPropertyNotSnakeCase |
| 175 | 177 | |
| 176 | 178 | } |
| @@ -191,9 +193,9 @@ | ||
| 191 | 193 | |
| 192 | 194 | unset( $plugin_action ); |
| 193 | 195 | |
| 194 | 196 | return sprintf( |
| 195 | - '<div class="cf-turnstile" data-sitekey="%1$s" data-appearance="interaction-only" data-callback="convertKitTurnstileFormSubmit"></div><input type="submit" class="%2$s" value="%3$s" />', | |
| 197 | + '<div class="cf-turnstile" data-sitekey="%1$s" data-appearance="interaction-only" data-execution="execute" data-callback="convertKitTurnstileFormSubmit"></div><input type="submit" class="%2$s" value="%3$s" />', | |
| 196 | 198 | esc_attr( $this->settings->cloudflare_turnstile_site_key() ), |
| 197 | 199 | esc_attr( implode( ' ', $css_classes ) ), |
| 198 | 200 | esc_attr( $label ) |
| 199 | 201 | ); |