PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Services/GlobalSettings/GlobalSettingsService.php +30 -4 6.2.2 → 6.2.15 View file →
@@ -5,10 +5,36 @@
5 5 use FluentForm\Framework\Support\Arr;
6 6
7 7 class GlobalSettingsService
8 8 {
9 + // Keying material and the gateway secrets it encrypts. Together they let a settings
10 + // manager decrypt every stored API key offline, so neither is readable here.
11 + const DENIED_OPTION_KEYS = ['_fluentform_encryption_key'];
12 + const DENIED_OPTION_PREFIXES = ['fluentform_payment_settings_'];
13 +
9 14 private function isAllowedOptionKey($key)
10 15 {
16 + $deniedKeys = (array) apply_filters('fluentform/global_settings_denied_option_keys', self::DENIED_OPTION_KEYS);
17 + $deniedPrefixes = (array) apply_filters('fluentform/global_settings_denied_option_prefixes', self::DENIED_OPTION_PREFIXES);
18 +
19 + // wp_options.option_name also collates accent-insensitively: an accented, fullwidth or zero-width
20 + // spelling misses the deny list yet resolves the denied row, so only the plain alphabet is looked up
21 + $isPlainOptionKey = (bool) preg_match('/^[A-Za-z0-9_-]+$/', $key);
22 + if (!$isPlainOptionKey) {
23 + return false;
24 + }
25 +
26 + $comparableKey = strtolower($key);
27 +
28 + if (in_array($comparableKey, array_map('strtolower', $deniedKeys), true)) {
29 + return false;
30 + }
31 + foreach ($deniedPrefixes as $prefix) {
32 + if ('' !== $prefix && strpos($comparableKey, strtolower($prefix)) === 0) {
33 + return false;
34 + }
35 + }
36 +
11 37 $allowedPrefixes = [
12 38 'fluentform_',
13 39 '_fluentform_',
14 40 'fluentform-',
@@ -14,9 +40,9 @@
14 40 'fluentform-',
15 41 '_fluentform-',
16 42 ];
17 43 foreach ($allowedPrefixes as $prefix) {
18 - if (strpos($key, $prefix) === 0) {
44 + if (strpos($comparableKey, $prefix) === 0) {
19 45 return true;
20 46 }
21 47 }
22 48 return false;
@@ -41,14 +67,14 @@
41 67 return $values;
42 68 }
43 69 $values[$key] = get_option($sanitizedKey);
44 70 }
45 -
71 +
46 72 $values = apply_filters_deprecated(
47 73 'fluentform_get_global_settings_values',
48 74 [
49 75 $values,
50 - $key
76 + $key,
51 77 ],
52 78 FLUENTFORM_FRAMEWORK_UPGRADE,
53 79 'fluentform/get_global_settings_values',
54 80 'Use fluentform/get_global_settings_values instead of fluentform_get_global_settings_values.'
@@ -96,9 +122,9 @@
96 122
97 123 do_action_deprecated(
98 124 'fluentform_saving_global_settings_with_key_method',
99 125 [
100 - $attributes
126 + $attributes,
101 127 ],
102 128 FLUENTFORM_FRAMEWORK_UPGRADE,
103 129 'fluentform/saving_global_settings_with_key_method',
104 130 'Use fluentform/saving_global_settings_with_key_method instead of fluentform_saving_global_settings_with_key_method.'