PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
fluentform / app / Hooks / Ajax.php

Ajax.php in Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 6.2.15, at app/Hooks/Ajax.php

272 lines 9.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 defined('ABSPATH') or die;
4
5 /**
6 * Add all ajax hooks
7 */
8
9 use FluentForm\App\Modules\Acl\Acl;
10
11 /**
12 * App instance
13 *
14 * @var $app \FluentForm\Framework\Foundation\Application
15 */
16
17 $app->addAction('wp_ajax_nopriv_fluentform_submit', function () use ($app) {
18 (new \FluentForm\App\Modules\SubmissionHandler\SubmissionHandler($app))->submit();
19 });
20
21 $app->addAction('wp_ajax_fluentform_submit', function () use ($app) {
22 // (new \FluentForm\App\Modules\Form\FormHandler($app))->onSubmit();
23 (new \FluentForm\App\Modules\SubmissionHandler\SubmissionHandler($app))->submit();
24 });
25
26 /*
27 * We are using this ajax call for updating form fields
28 * REST API seems not working for some servers with Mod Security Enabled
29 */
30 $app->addAction('wp_ajax_fluentform-form-update', function () use ($app) {
31 $formId = Acl::verifyFormId($app->request->get('form_id'));
32 Acl::verify('fluentform_forms_manager', $formId);
33 try {
34 $data = $app->request->all();
35 $data['form_id'] = $formId;
36 $isValidJson = (!empty($data['formFields'])) && json_decode($data['formFields'], true);
37
38 if (!$isValidJson) {
39 wp_send_json([
40 'message' => 'Looks like the provided JSON is invalid. Please try again or contact support',
41 'reason' => 'formFields JSON validation failed',
42 ], 422);
43 }
44
45 $formService = new \FluentForm\App\Services\Form\FormService();
46 $form = $formService->update($data);
47 wp_send_json([
48 'message' => __('The form is successfully updated.', 'fluentform'),
49 ], 200);
50 } catch (\Exception $exception) {
51 wp_send_json([
52 'message' => $exception->getMessage(),
53 ], 422);
54 }
55 });
56
57 /*
58 * This ajax endpoint is used to update form general settings
59 * Mod-Security also block this request
60 */
61 $app->addAction('wp_ajax_fluentform-save-settings-general-formSettings', function () use ($app) {
62 $formId = Acl::verifyFormId($app->request->get('form_id'));
63 Acl::verify('fluentform_forms_manager', $formId);
64 try {
65 $settingsService = new \FluentForm\App\Services\Settings\SettingsService();
66 $attributes = $app->request->all();
67 $attributes['form_id'] = $formId;
68
69 $settingsService->saveGeneral($attributes);
70 wp_send_json([
71 'message' => __('Settings has been saved.', 'fluentform'),
72 ]);
73 } catch (\FluentForm\Framework\Validator\ValidationException $exception) {
74 wp_send_json($exception->errors(), 422);
75 }
76 });
77
78 /*
79 * This ajax endpoint is used to update form email notifications settings
80 * Mod-Security also block this request
81 */
82 $app->addAction('wp_ajax_fluentform-save-form-email-notification', function () use ($app) {
83 $formId = Acl::verifyFormId($app->request->get('form_id'));
84 Acl::verify('fluentform_forms_manager', $formId);
85 try {
86 $settingsService = new \FluentForm\App\Services\Settings\SettingsService();
87 $attributes = $app->request->all();
88 $attributes['form_id'] = $formId;
89
90 [$settingsId, $settings] = $settingsService->store($attributes);
91
92 wp_send_json([
93 'message' => __('Settings has been saved.', 'fluentform'),
94 'id' => $settingsId,
95 'settings' => $settings,
96 ]);
97 } catch (\FluentForm\Framework\Validator\ValidationException $exception) {
98 wp_send_json($exception->errors(), 422);
99 }
100 });
101
102
103 // Legacy AJAX handlers removed — these routes are handled by the REST API.
104 // Kept: fluentform-form-find-shortcode-locations (still in active use)
105 $app->addAdminAjaxAction('fluentform-form-find-shortcode-locations', function () use ($app) {
106 $formId = Acl::verifyFormId($app->request->get('form_id'));
107 Acl::verify('fluentform_forms_manager', $formId);
108
109 (new \FluentForm\App\Modules\Form\Form($app))->findFormLocations();
110 });
111
112 // Legacy AJAX handlers removed — these routes are now handled by the REST API.
113
114
115
116 $resolveSubmissionFormId = function ($submissionId) {
117 if (!$submissionId) {
118 return null;
119 }
120
121 $submission = \FluentForm\App\Models\Submission::select('form_id')->find($submissionId);
122
123 return $submission ? $submission->form_id : null;
124 };
125
126 $app->addAction('wp_ajax_fluentform-form-entries-export', function () use ($app) {
127 $formId = Acl::verifyFormId($app->request->get('form_id'));
128
129 Acl::verify('fluentform_entries_viewer', $formId);
130 (new \FluentForm\App\Modules\Transfer\Transfer())->exportEntries();
131 });
132
133 $app->addAction('wp_ajax_fluentform-update-entry-user', function () use ($app, $resolveSubmissionFormId) {
134 $submissionId = absint($app->request->get('submission_id'));
135 $formId = $resolveSubmissionFormId($submissionId);
136
137 Acl::verify('fluentform_manage_entries', $formId);
138 $userId = absint($app->request->get('user_id'));
139 try {
140 $result = (new \FluentForm\App\Services\Submission\SubmissionService())->updateSubmissionUser($userId, $submissionId);
141 wp_send_json_success($result);
142 } catch (\Exception $e) {
143 wp_send_json_error(['message' => $e->getMessage()], 423);
144 }
145 });
146
147 $app->addAction('wp_ajax_fluentform-get-users', function () use ($app, $resolveSubmissionFormId) {
148 $submissionId = absint($app->request->get('submission_id'));
149 $formId = Acl::verifyFormId(
150 $resolveSubmissionFormId($submissionId),
151 'Invalid submission id.'
152 );
153
154 Acl::verify('fluentform_manage_entries', $formId);
155 $search = sanitize_text_field($app->request->get('search'));
156 if (current_user_can('list_users')) {
157 $users = get_users([
158 'search' => "*{$search}*",
159 'number' => 50,
160 ]);
161 } else {
162 // Non-admins confirm an exact email only, never browse the roster (FF-SEC-45).
163 $user = is_email($search) ? get_user_by('email', $search) : false;
164 $users = $user ? [$user] : [];
165 }
166 $formattedUsers = [];
167 foreach ($users as $user) {
168 $formattedUsers[] = [
169 'ID' => $user->ID,
170 'label' => $user->display_name . ' - ' . $user->user_email,
171 ];
172 }
173 wp_send_json_success(['users' => $formattedUsers]);
174 });
175
176
177 // Legacy log AJAX handlers removed — these routes are now handled by the REST API.
178
179 $app->addAction('wp_ajax_fluentform-change-entry-status', function () use ($app, $resolveSubmissionFormId) {
180 $entryId = absint($app->request->get('entry_id'));
181 $formId = $resolveSubmissionFormId($entryId);
182
183 Acl::verify('fluentform_manage_entries', $formId);
184
185 $attributes = [
186 'entry_id' => $entryId,
187 'status' => sanitize_text_field($app->request->get('status')),
188 ];
189 $newStatus = (new \FluentForm\App\Services\Submission\SubmissionService())->updateStatus($attributes);
190 wp_send_json_success([
191 // translators: %s is the submission status name
192 'message' => sprintf(__('Item has been marked as %s', 'fluentform'), $newStatus),
193 'status' => $newStatus,
194 ], 200);
195 });
196
197
198 $app->addAction('wp_ajax_fluentform_notice_action_track_yes', function () {
199 Acl::verify('fluentform_settings_manager');
200 (new FluentForm\App\Modules\Track\TrackModule())->sendInitialInfo();
201 });
202
203 $app->addAction('wp_ajax_fluentform_install_fluentsmtp', function () {
204 Acl::verify('fluentform_settings_manager');
205 (new FluentForm\App\Modules\Track\SetupModule())->installPlugin('fluent-smtp');
206 });
207
208 // Export forms
209 $app->addAction('wp_ajax_fluentform-export-forms', function () use ($app) {
210 Acl::verify('fluentform_settings_manager', $app->request->get('forms'));
211 (new \FluentForm\App\Modules\Transfer\Transfer())->exportForms();
212 });
213
214 // Import forms
215 $app->addAction('wp_ajax_fluentform-import-forms', function () use ($app) {
216 Acl::verify('fluentform_settings_manager');
217 (new \FluentForm\App\Modules\Transfer\Transfer())->importForms();
218 });
219
220 /*
221 * Background Process Receiver
222 */
223
224 // $this refers to the Application instance (included via Application::requireCommonFiles → includes.php)
225 $app->addAction('wp_ajax_fluentform_background_process', function () {
226 $this->app['fluentFormAsyncRequest']->handleBackgroundCall();
227 });
228
229 $app->addAction('wp_ajax_nopriv_fluentform_background_process', function () {
230 $this->app['fluentFormAsyncRequest']->handleBackgroundCall();
231 });
232
233 /*
234 * Background Report Data Migration
235 */
236 $app->addAction('wp_ajax_fluentform_report_data_migrate', function () {
237 if (!wp_verify_nonce(sanitize_text_field(wpFluentForm('request')->get('nonce')), 'fluentform_report_data_migrate')) {
238 die('invalid');
239 }
240 $formId = Acl::normalizeFormId(wpFluentForm('request')->get('form_id'));
241 if ($formId && Acl::hasPermission('fluentform_entries_viewer', $formId)) {
242 \FluentForm\App\Services\Report\ReportHelper::runMigrationBatch($formId);
243 }
244 die('done');
245 });
246
247 /*
248 * For REST API Nonce Renewal
249 */
250 $app->addAction('wp_ajax_fluentform_renew_rest_nonce', function () {
251 if (!Acl::getCurrentUserPermissions()) {
252 wp_send_json([
253 'error' => 'You do not have permission to do this',
254 ], 403);
255 }
256
257 wp_send_json([
258 'nonce' => wp_create_nonce('wp_rest'),
259 ], 200);
260 });
261 /*
262 * For selectGroup Component Grouped Options
263 * Use this filter to pass data to component
264 */
265
266 add_action('wp_ajax_fluentform_select_group_ajax_data', function () {
267 Acl::verify('fluentform_dashboard_access');
268 $requestData = wpFluentForm('request')->all();
269 $ajaxList = apply_filters('fluentform/select_group_component_ajax_options', [], $requestData);
270 wp_send_json_success($ajaxList);
271 });
272