| @@ -398,8 +398,15 @@ | ||
| 398 | 398 | 'description' => __('Range Slider is not available with the free version. Please upgrade to pro to get all the advanced features.', 'fluentform'), |
| 399 | 399 | 'image' => '', |
| 400 | 400 | 'video' => 'https://www.youtube.com/embed/RaY2VcPWk6I', |
| 401 | 401 | ]; |
| 402 | + $disabled['input_ranking'] = [ | |
| 403 | + 'disabled' => true, | |
| 404 | + 'title' => __('Ranking Field', 'fluentform'), | |
| 405 | + 'description' => __('Ranking Field is not available with the free version. Please upgrade to pro to get all the advanced features.', 'fluentform'), | |
| 406 | + 'image' => '', | |
| 407 | + 'video' => '', | |
| 408 | + ]; | |
| 402 | 409 | $disabled['color-picker'] = [ |
| 403 | 410 | 'disabled' => true, |
| 404 | 411 | 'title' => __('Color Picker', 'fluentform'), |
| 405 | 412 | 'description' => __('Color Picker is not available with the free version. Please upgrade to pro to get all the advanced features.', 'fluentform'), |
| @@ -635,8 +642,9 @@ | ||
| 635 | 642 | $data = [ |
| 636 | 643 | 'ajaxUrl' => admin_url('admin-ajax.php'), |
| 637 | 644 | 'forms' => [], |
| 638 | 645 | 'step_text' => $stepText, |
| 646 | + 'step_completed_text' => __('Completed', 'fluentform'), | |
| 639 | 647 | 'is_rtl' => is_rtl(), |
| 640 | 648 | 'date_i18n' => self::getDatei18n(), |
| 641 | 649 | 'pro_version' => (defined('FLUENTFORMPRO_VERSION')) ? FLUENTFORMPRO_VERSION : false, |
| 642 | 650 | 'fluentform_version' => FLUENTFORM_VERSION, |
| @@ -735,8 +743,14 @@ | ||
| 735 | 743 | if ($conditionals = $formBuilder->conditions) { |
| 736 | 744 | $form_vars['conditionals'] = $conditionals; |
| 737 | 745 | } |
| 738 | 746 | |
| 747 | + $form_vars['file_upload_settings'] = apply_filters( | |
| 748 | + 'fluentform/file_upload_settings_for_js', | |
| 749 | + [], | |
| 750 | + $form | |
| 751 | + ); | |
| 752 | + | |
| 739 | 753 | $form_vars = apply_filters('fluentform/form_vars_for_JS', $form_vars, $form); |
| 740 | 754 | |
| 741 | 755 | if ($form->has_payment) { |
| 742 | 756 | do_action_deprecated( |
| @@ -871,10 +885,19 @@ | ||
| 871 | 885 | if (isset($attrDefaultValues['{payment_total}'])) { |
| 872 | 886 | $attrDefaultValues['{payment_total}'] = '<span class="ff_order_total"></span>'; |
| 873 | 887 | } |
| 874 | 888 | |
| 875 | - // Finally, replace the patterns with the replacements and return the output HTML. | |
| 876 | - return str_replace(array_keys($attrDefaultValues), array_values($attrDefaultValues), $output); | |
| 889 | + // Replace in a single pass. str_replace() with arrays re-scans text an earlier key inserted, | |
| 890 | + // so ?a=javascript{get.b}&b=:alert(1) would assemble a script URL from two escaped values. | |
| 891 | + $replacements = []; | |
| 892 | + foreach ($attrDefaultValues as $pattern => $replacement) { | |
| 893 | + // strtr() returns false on an empty key before PHP 8. | |
| 894 | + if ('' !== (string) $pattern && (is_scalar($replacement) || null === $replacement)) { | |
| 895 | + $replacements[(string) $pattern] = (string) $replacement; | |
| 896 | + } | |
| 897 | + } | |
| 898 | + | |
| 899 | + return strtr($output, $replacements); | |
| 877 | 900 | } |
| 878 | 901 | |
| 879 | 902 | /** |
| 880 | 903 | * Register renderer actions for compiling each element |
| @@ -953,8 +976,15 @@ | ||
| 953 | 976 | */ |
| 954 | 977 | public function addIsRenderableFilter() |
| 955 | 978 | { |
| 956 | 979 | $this->app->addFilter('fluentform/is_form_renderable', function ($isRenderable, $form) { |
| 980 | + if ( | |
| 981 | + $this->app->request->get('design_mode') | |
| 982 | + && Acl::hasAnyFormPermission() | |
| 983 | + ) { | |
| 984 | + return $isRenderable; | |
| 985 | + } | |
| 986 | + | |
| 957 | 987 | $checkables = ['limitNumberOfEntries', 'scheduleForm', 'requireLogin']; |
| 958 | 988 | |
| 959 | 989 | // Ensure settings is an array |
| 960 | 990 | if (!isset($form->settings) || !is_array($form->settings)) { |
| @@ -993,9 +1023,9 @@ | ||
| 993 | 1023 | */ |
| 994 | 1024 | private function limitNumberOfEntries($restrictions, $form, &$isRenderable) |
| 995 | 1025 | { |
| 996 | 1026 | |
| 997 | - if (!$restrictions['enabled'] || !isset($restrictions['period']) || !isset($restrictions['numberOfEntries'])) { | |
| 1027 | + if (!Arr::isTrue($restrictions, 'enabled') || !isset($restrictions['period']) || !isset($restrictions['numberOfEntries'])) { | |
| 998 | 1028 | return true; |
| 999 | 1029 | } |
| 1000 | 1030 | |
| 1001 | 1031 | |
| @@ -1055,9 +1085,9 @@ | ||
| 1055 | 1085 | * @return bool |
| 1056 | 1086 | */ |
| 1057 | 1087 | private function scheduleForm($restrictions, $form, &$isRenderable) |
| 1058 | 1088 | { |
| 1059 | - if (!$restrictions['enabled']) { | |
| 1089 | + if (!Arr::isTrue($restrictions, 'enabled')) { | |
| 1060 | 1090 | return true; |
| 1061 | 1091 | } |
| 1062 | 1092 | |
| 1063 | 1093 | $time = time(); |
| @@ -1094,9 +1124,9 @@ | ||
| 1094 | 1124 | * @return bool |
| 1095 | 1125 | */ |
| 1096 | 1126 | private function requireLogin($restrictions, $form, &$isRenderable) |
| 1097 | 1127 | { |
| 1098 | - if (!$restrictions['enabled']) { | |
| 1128 | + if (!Arr::isTrue($restrictions, 'enabled')) { | |
| 1099 | 1129 | return true; |
| 1100 | 1130 | } |
| 1101 | 1131 | |
| 1102 | 1132 | if (!($isLoggedIn = is_user_logged_in())) { |
| @@ -1355,9 +1385,9 @@ | ||
| 1355 | 1385 | $dateFormat = $atts['date_format']; |
| 1356 | 1386 | } else { |
| 1357 | 1387 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1358 | 1388 | } |
| 1359 | - return date($dateFormat, strtotime($form->created_at)); | |
| 1389 | + return esc_html(date($dateFormat, strtotime($form->created_at))); | |
| 1360 | 1390 | } elseif ('updated_at' == $atts['info']) { |
| 1361 | 1391 | if ($atts['date_format']) { |
| 1362 | 1392 | $dateFormat = $atts['date_format']; |
| 1363 | 1393 | } else { |
| @@ -1362,9 +1392,9 @@ | ||
| 1362 | 1392 | $dateFormat = $atts['date_format']; |
| 1363 | 1393 | } else { |
| 1364 | 1394 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1365 | 1395 | } |
| 1366 | - return date($dateFormat, strtotime($form->updated_at)); | |
| 1396 | + return esc_html(date($dateFormat, strtotime($form->updated_at))); | |
| 1367 | 1397 | } elseif ('payment_total' == $atts['info']) { |
| 1368 | 1398 | if (!defined('FLUENTFORMPRO')) { |
| 1369 | 1399 | return ''; |
| 1370 | 1400 | } |
| @@ -1427,17 +1457,19 @@ | ||
| 1427 | 1457 | $atts = shortcode_atts([ |
| 1428 | 1458 | 'param' => '', |
| 1429 | 1459 | ], $atts); |
| 1430 | 1460 | |
| 1461 | + if ('' === $atts['param']) { | |
| 1462 | + return ''; | |
| 1463 | + } | |
| 1464 | + | |
| 1431 | 1465 | $value = $this->app->request->get($atts['param']); |
| 1432 | 1466 | |
| 1433 | - if ($atts['param'] && $value) { | |
| 1434 | - if (is_array($value)) { | |
| 1435 | - return implode(', ', $value); | |
| 1436 | - } | |
| 1437 | - return esc_html($value); | |
| 1467 | + if (null === $value || '' === $value) { | |
| 1468 | + return ''; | |
| 1438 | 1469 | } |
| 1439 | - return ''; | |
| 1470 | + | |
| 1471 | + return esc_html(Helper::flattenRequestValue($value)); | |
| 1440 | 1472 | }); |
| 1441 | 1473 | |
| 1442 | 1474 | $this->app->addShortcode('ff_entry',function($atts){ |
| 1443 | 1475 | ob_start(); |