| @@ -1,16 +1,18 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace FluentForm\App\Modules\Widgets; |
| 4 | 4 | |
| 5 | +use FluentForm\App\Models\Form; | |
| 6 | + | |
| 5 | 7 | class SidebarWidgets extends \WP_Widget |
| 6 | 8 | { |
| 7 | - function __construct() | |
| 9 | + public function __construct() | |
| 8 | 10 | { |
| 9 | 11 | parent::__construct( |
| 10 | 12 | 'fluentform_widget', |
| 11 | - esc_html__('WP Fluent Forms Widget', 'fluentform'), | |
| 12 | - array('description' => esc_html__('Add your form by WP Fluent Forms', 'fluentform'),) | |
| 13 | + esc_html__('Fluent Forms Widget', 'fluentform'), | |
| 14 | + ['description' => esc_html__('Add your form by Fluent Forms', 'fluentform'), ] | |
| 13 | 15 | ); |
| 14 | 16 | } |
| 15 | 17 | |
| 16 | 18 | public function widget($args, $instance) |
| @@ -16,75 +18,82 @@ | ||
| 16 | 18 | public function widget($args, $instance) |
| 17 | 19 | { |
| 18 | 20 | $selectedForm = empty($instance['allforms']) ? '' : intval($instance['allforms']); |
| 19 | 21 | |
| 20 | - if(!$selectedForm) { | |
| 22 | + if (!$selectedForm) { | |
| 21 | 23 | return; |
| 22 | 24 | } |
| 23 | 25 | |
| 26 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $args['before_widget'] is provided by WordPress core | |
| 24 | 27 | echo $args['before_widget']; |
| 25 | 28 | |
| 26 | - if ( ! empty( $instance['title'] ) ) { | |
| 27 | - echo $args['before_title'] . apply_filters( 'widget_title', $instance['title'] ) . $args['after_title']; | |
| 29 | + if (!empty($instance['title'])) { | |
| 30 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $args['before_title'], $args['after_title'] are provided by WordPress core, widget_title filter is expected to return safe HTML | |
| 31 | + echo $args['before_title'] . apply_filters('widget_title', $instance['title']) . $args['after_title']; | |
| 28 | 32 | } |
| 29 | 33 | |
| 30 | - if ($selectedForm != '') { | |
| 34 | + if ('' != $selectedForm) { | |
| 31 | 35 | $shortcode = "[fluentform id='$selectedForm']"; |
| 36 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_shortcode() output is safe | |
| 32 | 37 | echo do_shortcode($shortcode); |
| 33 | 38 | } |
| 34 | 39 | |
| 40 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $args['after_widget'] is provided by WordPress core | |
| 35 | 41 | echo $args['after_widget']; |
| 36 | - | |
| 37 | 42 | } |
| 38 | 43 | |
| 39 | 44 | public function form($instance) |
| 40 | 45 | { |
| 41 | 46 | $selectedForm = empty($instance['allforms']) ? '' : $instance['allforms']; |
| 42 | - | |
| 47 | + | |
| 43 | 48 | if (isset($instance['title'])) { |
| 44 | 49 | $title = $instance['title']; |
| 45 | 50 | } else { |
| 46 | - $title = __('', 'fluentform'); | |
| 51 | + $title = ''; | |
| 47 | 52 | } |
| 48 | 53 | // Widget admin form |
| 49 | 54 | ?> |
| 50 | 55 | <p> |
| 51 | - <label for="<?php echo $this->get_field_id('title'); ?>"><?php _e('Title (optional):'); ?></label> | |
| 52 | - <input class="widefat" id="<?php echo $this->get_field_id('title'); ?>" | |
| 53 | - name="<?php echo $this->get_field_name('title'); ?>" type="text" | |
| 54 | - value="<?php echo esc_attr($title); ?>"/> | |
| 56 | + <label | |
| 57 | + for="<?php echo esc_attr($this->get_field_id('title')); ?>"><?php esc_html_e('Title (optional):', 'fluentform'); ?></label> | |
| 58 | + <input class="widefat" | |
| 59 | + id="<?php echo esc_attr($this->get_field_id('title')); ?>" | |
| 60 | + name="<?php echo esc_attr($this->get_field_name('title')); ?>" | |
| 61 | + type="text" value="<?php echo esc_attr($title); ?>" /> | |
| 55 | 62 | </p> |
| 56 | 63 | <?php |
| 57 | - $forms = wpFluent()->table('fluentform_forms') | |
| 58 | - ->select(array('id', 'title')) | |
| 64 | + $forms = Form::select(['id', 'title']) | |
| 59 | 65 | ->orderBy('id', 'DESC') |
| 60 | 66 | ->get(); |
| 61 | 67 | ?> |
| 62 | - | |
| 63 | - <label for="<?php echo $this->get_field_id('allforms'); ?>">Select a form: | |
| 64 | - <select style="margin-bottom: 12px;" class='widefat' id="<?php echo $this->get_field_id('allforms'); ?>" | |
| 65 | - name="<?php echo $this->get_field_name('allforms'); ?>" type="text" | |
| 66 | - > | |
| 68 | + | |
| 69 | + <label | |
| 70 | + for="<?php echo esc_attr($this->get_field_id('allforms')); ?>">Select | |
| 71 | + a form: | |
| 72 | + <select style="margin-bottom: 12px;" class='widefat' | |
| 73 | + id="<?php echo esc_attr($this->get_field_id('allforms')); ?>" | |
| 74 | + name="<?php echo esc_attr($this->get_field_name('allforms')); ?>" | |
| 75 | + type="text"> | |
| 67 | 76 | <?php |
| 68 | - foreach ($forms as $item) { | |
| 69 | - ?> | |
| 70 | - <option <?php if ($item->id == $selectedForm) { | |
| 71 | - echo 'selected'; | |
| 72 | - } ?> value='<?php echo $item->id; ?>'> | |
| 73 | - <?php echo $item->title; ?> (<?php echo $item->id; ?>) | |
| 74 | - </option> | |
| 75 | - <?php | |
| 76 | - } | |
| 77 | + foreach ($forms as $item) { | |
| 78 | + ?> | |
| 79 | + <option <?php if ($item->id == $selectedForm) { | |
| 80 | + echo 'selected'; | |
| 81 | + } ?> value='<?php echo esc_attr($item->id); ?>'> | |
| 82 | + <?php echo esc_html($item->title); ?> (<?php echo esc_attr($item->id); ?>) | |
| 83 | + </option> | |
| 84 | + <?php | |
| 85 | + } | |
| 77 | 86 | ?> |
| 78 | 87 | </select> |
| 79 | 88 | </label> |
| 80 | - <?php | |
| 89 | + <?php | |
| 81 | 90 | } |
| 82 | 91 | |
| 83 | 92 | public function update($new_instance, $old_instance) |
| 84 | 93 | { |
| 85 | - $instance = array(); | |
| 86 | - $instance['title'] = (!empty($new_instance['title'])) ? strip_tags($new_instance['title']) : ''; | |
| 94 | + $instance = []; | |
| 95 | + $instance['title'] = (!empty($new_instance['title'])) ? wp_strip_all_tags($new_instance['title']) : ''; | |
| 87 | 96 | $instance['allforms'] = intval($new_instance['allforms']); |
| 88 | 97 | return $instance; |
| 89 | 98 | } |
| 90 | 99 | } |