| @@ -140,16 +140,19 @@ | ||
| 140 | 140 | } |
| 141 | 141 | |
| 142 | 142 | public function getCustomConfig($settings, $form = null) |
| 143 | 143 | { |
| 144 | - $customConfigObject = fluentform_sanitize_json_object( | |
| 145 | - (string) ArrayHelper::get($settings, 'date_config') | |
| 146 | - ); | |
| 144 | + $customConfigObject = trim((string) ArrayHelper::get($settings, 'date_config')); | |
| 147 | 145 | |
| 148 | - // Emitted JS is rebuilt from validated data tokens (ints only) — the raw setting never reaches the script sink. | |
| 149 | - $customConfigObject = fluentform_date_config_to_js($customConfigObject); | |
| 150 | - | |
| 151 | - $customConfigObject = '' !== $customConfigObject ? $customConfigObject : '{}'; | |
| 146 | + if ( | |
| 147 | + !$customConfigObject || | |
| 148 | + '{' !== substr($customConfigObject, 0, 1) || | |
| 149 | + '}' !== substr($customConfigObject, -1) | |
| 150 | + ) { | |
| 151 | + $customConfigObject = '{}'; | |
| 152 | + } else { | |
| 153 | + $customConfigObject = str_ireplace('</script', '<\\/script', $customConfigObject); | |
| 154 | + } | |
| 152 | 155 | |
| 153 | 156 | return apply_filters('fluentform/date_time_custom_config', $customConfigObject, $settings, $form); |
| 154 | 157 | } |
| 155 | 158 | |