| 1 |
<?php |
| 2 |
if(!defined('ABSPATH')) die(__('You are not allowed to call this page directly.', 'formidable')); |
| 3 |
|
| 4 |
if(class_exists('FrmEntry')) |
| 5 |
return; |
| 6 |
|
| 7 |
class FrmEntry{ |
| 8 |
|
| 9 |
function create( $values ){ |
| 10 |
global $wpdb, $frm_entry_meta; |
| 11 |
|
| 12 |
$new_values = array( |
| 13 |
'item_key' => FrmAppHelper::get_unique_key($values['item_key'], $wpdb->prefix .'frm_items', 'item_key'), |
| 14 |
'name' => isset($values['name']) ? $values['name'] : $values['item_key'], |
| 15 |
'ip' => $_SERVER['REMOTE_ADDR'], |
| 16 |
'is_draft' => ( ( isset($values['frm_saving_draft']) && $values['frm_saving_draft'] == 1 ) || ( isset($values['is_draft']) && $values['is_draft'] == 1) ) ? 1 : 0, |
| 17 |
'form_id' => isset($values['form_id']) ? (int) $values['form_id']: null, |
| 18 |
'post_id' => isset($values['post_id']) ? (int) $values['post_id']: null, |
| 19 |
'created_at' => isset($values['created_at']) ? $values['created_at'] : current_time('mysql', 1), |
| 20 |
'updated_at' => isset($values['updated_at']) ? $values['updated_at'] : ( isset($values['created_at']) ? $values['created_at'] : current_time('mysql', 1) ), |
| 21 |
); |
| 22 |
|
| 23 |
if(is_array($new_values['name'])) |
| 24 |
$new_values['name'] = reset($new_values['name']); |
| 25 |
|
| 26 |
if(isset($values['description']) and !empty($values['description'])){ |
| 27 |
$new_values['description'] = maybe_serialize($values['description']); |
| 28 |
}else{ |
| 29 |
$referrerinfo = FrmAppHelper::get_referer_info(); |
| 30 |
|
| 31 |
$new_values['description'] = serialize(array('browser' => $_SERVER['HTTP_USER_AGENT'], |
| 32 |
'referrer' => $referrerinfo)); |
| 33 |
} |
| 34 |
|
| 35 |
//if(isset($values['id']) and is_numeric($values['id'])) |
| 36 |
// $new_values['id'] = $values['id']; |
| 37 |
|
| 38 |
if(isset($values['frm_user_id']) and (is_numeric($values['frm_user_id']) or (is_admin() and !defined('DOING_AJAX')))){ |
| 39 |
$new_values['user_id'] = $values['frm_user_id']; |
| 40 |
}else{ |
| 41 |
$user_ID = get_current_user_id(); |
| 42 |
$new_values['user_id'] = $user_ID ? $user_ID : 0; |
| 43 |
} |
| 44 |
|
| 45 |
$new_values['updated_by'] = isset($values['updated_by']) ? $values['updated_by'] : $new_values['user_id']; |
| 46 |
|
| 47 |
//check for duplicate entries created in the last 5 minutes |
| 48 |
if(!defined('WP_IMPORTING')){ |
| 49 |
$create_entry = true; |
| 50 |
|
| 51 |
$check_val = $new_values; |
| 52 |
$check_val['created_at >'] = date('Y-m-d H:i:s', (strtotime($new_values['created_at']) - (60*5))); |
| 53 |
unset($check_val['created_at']); |
| 54 |
unset($check_val['updated_at']); |
| 55 |
unset($check_val['is_draft']); |
| 56 |
unset($check_val['id']); |
| 57 |
unset($check_val['item_key']); |
| 58 |
if($new_values['item_key'] == $new_values['name']) |
| 59 |
unset($check_val['name']); |
| 60 |
|
| 61 |
global $frmdb; |
| 62 |
$entry_exists = $frmdb->get_records($wpdb->prefix .'frm_items', $check_val, 'created_at DESC', '', 'id'); |
| 63 |
unset($frmdb); |
| 64 |
|
| 65 |
if($entry_exists and !empty($entry_exists)){ |
| 66 |
foreach($entry_exists as $entry_exist){ |
| 67 |
if($create_entry){ |
| 68 |
$create_entry = false; |
| 69 |
//add more checks here to make sure it's a duplicate |
| 70 |
if (isset($values['item_meta'])){ |
| 71 |
$metas = $frm_entry_meta->get_entry_meta_info($entry_exist->id); |
| 72 |
$field_metas = array(); |
| 73 |
foreach($metas as $meta) |
| 74 |
$field_metas[$meta->field_id] = $meta->meta_value; |
| 75 |
|
| 76 |
$diff = array_diff_assoc($field_metas, array_map('maybe_serialize', $values['item_meta'])); |
| 77 |
foreach($diff as $field_id => $meta_value){ |
| 78 |
if(!empty($meta_value) and !$create_entry) |
| 79 |
$create_entry = true; |
| 80 |
} |
| 81 |
} |
| 82 |
} |
| 83 |
} |
| 84 |
} |
| 85 |
|
| 86 |
if ( !$create_entry ) { |
| 87 |
return false; |
| 88 |
} |
| 89 |
} |
| 90 |
|
| 91 |
$query_results = $wpdb->insert( $wpdb->prefix .'frm_items', $new_values ); |
| 92 |
|
| 93 |
if ( $query_results ) { |
| 94 |
$entry_id = $wpdb->insert_id; |
| 95 |
|
| 96 |
global $frm_vars; |
| 97 |
if(!isset($frm_vars['saved_entries'])) |
| 98 |
$frm_vars['saved_entries'] = array(); |
| 99 |
$frm_vars['saved_entries'][] = (int)$entry_id; |
| 100 |
|
| 101 |
if ( isset($values['item_meta']) ) { |
| 102 |
$frm_entry_meta->update_entry_metas($entry_id, $values['item_meta']); |
| 103 |
} |
| 104 |
|
| 105 |
do_action('frm_after_create_entry', $entry_id, $new_values['form_id']); |
| 106 |
do_action('frm_after_create_entry_'. $new_values['form_id'], $entry_id); |
| 107 |
return $entry_id; |
| 108 |
} else { |
| 109 |
return false; |
| 110 |
} |
| 111 |
} |
| 112 |
|
| 113 |
function duplicate( $id ){ |
| 114 |
global $wpdb, $frm_entry, $frm_entry_meta; |
| 115 |
|
| 116 |
$values = $frm_entry->getOne( $id ); |
| 117 |
|
| 118 |
$new_values = array(); |
| 119 |
$new_values['item_key'] = FrmAppHelper::get_unique_key('', $wpdb->prefix .'frm_items', 'item_key'); |
| 120 |
$new_values['name'] = $values->name; |
| 121 |
$new_values['is_draft'] = $values->is_draft; |
| 122 |
$new_values['user_id'] = $new_values['updated_by'] = (int)$values->user_id; |
| 123 |
$new_values['form_id'] = $values->form_id ? (int)$values->form_id: null; |
| 124 |
$new_values['created_at'] = $new_values['updated_at'] = current_time('mysql', 1); |
| 125 |
|
| 126 |
$query_results = $wpdb->insert( $wpdb->prefix .'frm_items', $new_values ); |
| 127 |
if($query_results){ |
| 128 |
$entry_id = $wpdb->insert_id; |
| 129 |
|
| 130 |
global $frm_vars; |
| 131 |
if(!isset($frm_vars['saved_entries'])) |
| 132 |
$frm_vars['saved_entries'] = array(); |
| 133 |
$frm_vars['saved_entries'][] = (int)$entry_id; |
| 134 |
|
| 135 |
$frm_entry_meta->duplicate_entry_metas($id, $entry_id); |
| 136 |
|
| 137 |
do_action('frm_after_duplicate_entry', $entry_id, $new_values['form_id']); |
| 138 |
return $entry_id; |
| 139 |
}else |
| 140 |
return false; |
| 141 |
} |
| 142 |
|
| 143 |
function update( $id, $values ){ |
| 144 |
global $wpdb, $frm_entry_meta, $frm_field, $frm_vars; |
| 145 |
if(isset($frm_vars['saved_entries']) && is_array($frm_vars['saved_entries']) && in_array((int)$id, (array)$frm_vars['saved_entries'])) |
| 146 |
return; |
| 147 |
|
| 148 |
$user_ID = get_current_user_id(); |
| 149 |
|
| 150 |
$new_values = array( |
| 151 |
'name' => isset($values['name']) ? $values['name'] : '', |
| 152 |
'form_id' => isset($values['form_id']) ? (int) $values['form_id'] : null, |
| 153 |
'is_draft' => ( ( isset($values['frm_saving_draft']) && $values['frm_saving_draft'] == 1 ) || ( isset($values['is_draft']) && $values['is_draft'] == 1) ) ? 1 : 0, |
| 154 |
'updated_at' => current_time('mysql', 1), |
| 155 |
'updated_by' => isset($values['updated_by']) ? $values['updated_by'] : $user_ID, |
| 156 |
); |
| 157 |
|
| 158 |
if ( isset($values['post_id']) ) { |
| 159 |
$new_values['post_id'] = (int) $values['post_id']; |
| 160 |
} |
| 161 |
|
| 162 |
if ( isset($values['item_key']) ) { |
| 163 |
$new_values['item_key'] = FrmAppHelper::get_unique_key($values['item_key'], $wpdb->prefix .'frm_items', 'item_key', $id); |
| 164 |
} |
| 165 |
|
| 166 |
if(isset($values['frm_user_id']) and is_numeric($values['frm_user_id'])) |
| 167 |
$new_values['user_id'] = $values['frm_user_id']; |
| 168 |
|
| 169 |
$new_values = apply_filters('frm_update_entry', $new_values, $id); |
| 170 |
$query_results = $wpdb->update( $wpdb->prefix .'frm_items', $new_values, compact('id') ); |
| 171 |
if($query_results) |
| 172 |
wp_cache_delete( $id, 'frm_entry'); |
| 173 |
|
| 174 |
if(!isset($frm_vars['saved_entries'])) |
| 175 |
$frm_vars['saved_entries'] = array(); |
| 176 |
|
| 177 |
$frm_vars['saved_entries'][] = (int)$id; |
| 178 |
|
| 179 |
if (isset($values['item_meta'])) |
| 180 |
$frm_entry_meta->update_entry_metas($id, $values['item_meta']); |
| 181 |
do_action('frm_after_update_entry', $id, $new_values['form_id']); |
| 182 |
do_action('frm_after_update_entry_'. $new_values['form_id'], $id); |
| 183 |
return $query_results; |
| 184 |
} |
| 185 |
|
| 186 |
function &destroy( $id ){ |
| 187 |
global $wpdb; |
| 188 |
$id = (int)$id; |
| 189 |
|
| 190 |
$entry = $this->getOne($id); |
| 191 |
if ( !$entry ) { |
| 192 |
$result = false; |
| 193 |
return $result; |
| 194 |
} |
| 195 |
|
| 196 |
do_action('frm_before_destroy_entry', $id, $entry); |
| 197 |
|
| 198 |
wp_cache_delete( $id, 'frm_entry'); |
| 199 |
$wpdb->query('DELETE FROM ' . $wpdb->prefix .'frm_item_metas WHERE item_id=' . $id); |
| 200 |
$result = $wpdb->query('DELETE FROM ' . $wpdb->prefix .'frm_items WHERE id=' . $id); |
| 201 |
return $result; |
| 202 |
} |
| 203 |
|
| 204 |
function &update_form( $id, $value, $form_id ){ |
| 205 |
global $wpdb; |
| 206 |
$form_id = isset($value) ? $form_id : NULL; |
| 207 |
$result = $wpdb->update( $wpdb->prefix .'frm_items', array('form_id' => $form_id), array( 'id' => $id ) ); |
| 208 |
if($result) |
| 209 |
wp_cache_delete( $id, 'frm_entry'); |
| 210 |
return $result; |
| 211 |
} |
| 212 |
|
| 213 |
function getOne( $id, $meta=false){ |
| 214 |
global $wpdb; |
| 215 |
|
| 216 |
$entry = wp_cache_get( $id, 'frm_entry' ); |
| 217 |
if($entry) |
| 218 |
return stripslashes_deep($entry); |
| 219 |
|
| 220 |
$query = "SELECT it.*, fr.name as form_name, fr.form_key as form_key FROM {$wpdb->prefix}frm_items it |
| 221 |
LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id WHERE "; |
| 222 |
|
| 223 |
$query .= $wpdb->prepare( is_numeric($id) ? 'it.id=%d' : 'it.item_key=%s', $id); |
| 224 |
|
| 225 |
$entry = $wpdb->get_row($query); |
| 226 |
|
| 227 |
if($meta and $entry){ |
| 228 |
$metas = $wpdb->get_results($wpdb->prepare("SELECT field_id, meta_value, field_key FROM {$wpdb->prefix}frm_item_metas m LEFT JOIN {$wpdb->prefix}frm_fields f ON m.field_id=f.id WHERE item_id=%d and field_id != %d", $entry->id, 0)); |
| 229 |
|
| 230 |
$entry_metas = array(); |
| 231 |
|
| 232 |
foreach($metas as $meta_val){ |
| 233 |
$entry_metas[$meta_val->field_id] = $entry_metas[$meta_val->field_key] = maybe_unserialize($meta_val->meta_value); |
| 234 |
unset($meta_val); |
| 235 |
} |
| 236 |
unset($metas); |
| 237 |
|
| 238 |
$entry->metas = $entry_metas; |
| 239 |
|
| 240 |
wp_cache_set( $entry->id, $entry, 'frm_entry'); |
| 241 |
} |
| 242 |
|
| 243 |
return stripslashes_deep($entry); |
| 244 |
} |
| 245 |
|
| 246 |
function &exists( $id ){ |
| 247 |
global $wpdb; |
| 248 |
|
| 249 |
if(wp_cache_get( $id, 'frm_entry' )){ |
| 250 |
$exists = true; |
| 251 |
return $exists; |
| 252 |
} |
| 253 |
|
| 254 |
$where = (is_numeric($id)) ? 'id=%d' : 'item_key=%s'; |
| 255 |
|
| 256 |
$id = $wpdb->get_var($wpdb->prepare("SELECT id FROM {$wpdb->prefix}frm_items WHERE $where", $id)); |
| 257 |
|
| 258 |
$exists = ($id && $id > 0) ? true : false; |
| 259 |
return $exists; |
| 260 |
} |
| 261 |
|
| 262 |
function getAll($where = '', $order_by = '', $limit = '', $meta=false, $inc_form=true){ |
| 263 |
global $wpdb; |
| 264 |
|
| 265 |
if(is_numeric($limit)) |
| 266 |
$limit = " LIMIT {$limit}"; |
| 267 |
|
| 268 |
if($inc_form){ |
| 269 |
$query = "SELECT it.*, fr.name as form_name,fr.form_key as form_key |
| 270 |
FROM {$wpdb->prefix}frm_items it LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id" . |
| 271 |
FrmAppHelper::prepend_and_or_where(' WHERE ', $where) . $order_by . $limit; |
| 272 |
}else{ |
| 273 |
$query = "SELECT it.id, it.item_key, it.name, it.ip, it.form_id, it.post_id, it.user_id, it.updated_by, |
| 274 |
it.created_at, it.updated_at, it.is_draft FROM {$wpdb->prefix}frm_items it" . |
| 275 |
FrmAppHelper::prepend_and_or_where(' WHERE ', $where) . $order_by . $limit; |
| 276 |
} |
| 277 |
|
| 278 |
if ( preg_match( '/ meta_([0-9]+)/', $order_by, $order_matches ) ) { |
| 279 |
// sort by a requested field |
| 280 |
$query = str_replace( " FROM {$wpdb->prefix}frm_items ", ", (SELECT meta_value FROM {$wpdb->prefix}frm_item_metas WHERE field_id = {$order_matches[1]} AND item_id = it.id) as meta_{$order_matches[1]} FROM {$wpdb->prefix}frm_items ", $query ); |
| 281 |
} |
| 282 |
|
| 283 |
$entries = $wpdb->get_results($query, OBJECT_K); |
| 284 |
unset($query); |
| 285 |
|
| 286 |
if($meta and $entries){ |
| 287 |
if($limit == '' and !is_array($where) and preg_match('/^it\.form_id=\d+$/', $where)){ |
| 288 |
$meta_where = $wpdb->prepare('fi.form_id=%d', substr($where, 11)); |
| 289 |
}else if($limit == '' and is_array($where) and count($where) == 1 and isset($where['it.form_id'])){ |
| 290 |
$meta_where = $wpdb->prepare('fi.form_id=%d', $where['it.form_id']); |
| 291 |
}else{ |
| 292 |
$meta_where = "item_id in (". implode(',', array_filter(array_keys($entries), 'is_numeric')) .")"; |
| 293 |
} |
| 294 |
$query = "SELECT item_id, meta_value, field_id, field_key FROM {$wpdb->prefix}frm_item_metas it |
| 295 |
LEFT OUTER JOIN {$wpdb->prefix}frm_fields fi ON it.field_id=fi.id |
| 296 |
WHERE $meta_where and field_id != 0"; |
| 297 |
|
| 298 |
$metas = $wpdb->get_results($query); |
| 299 |
unset($query); |
| 300 |
|
| 301 |
if($metas){ |
| 302 |
foreach($metas as $m_key => $meta_val){ |
| 303 |
if(!isset($entries[$meta_val->item_id])) |
| 304 |
continue; |
| 305 |
|
| 306 |
if(!isset($entries[$meta_val->item_id]->metas)) |
| 307 |
$entries[$meta_val->item_id]->metas = array(); |
| 308 |
|
| 309 |
$entries[$meta_val->item_id]->metas[$meta_val->field_id] = $entries[$meta_val->item_id]->metas[$meta_val->field_key] = maybe_unserialize($meta_val->meta_value); |
| 310 |
} |
| 311 |
|
| 312 |
foreach($entries as $entry){ |
| 313 |
wp_cache_set( $entry->id, $entry, 'frm_entry'); |
| 314 |
unset($entry); |
| 315 |
} |
| 316 |
} |
| 317 |
} |
| 318 |
|
| 319 |
return stripslashes_deep($entries); |
| 320 |
} |
| 321 |
|
| 322 |
// Pagination Methods |
| 323 |
function getRecordCount($where=''){ |
| 324 |
global $wpdb; |
| 325 |
if(is_numeric($where)){ |
| 326 |
$query = "SELECT COUNT(*) FROM {$wpdb->prefix}frm_items WHERE form_id=". $where; |
| 327 |
}else{ |
| 328 |
$query = "SELECT COUNT(*) FROM {$wpdb->prefix}frm_items it LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id" . |
| 329 |
FrmAppHelper::prepend_and_or_where(' WHERE ', $where); |
| 330 |
} |
| 331 |
return $wpdb->get_var($query); |
| 332 |
} |
| 333 |
|
| 334 |
function getPageCount($p_size, $where=''){ |
| 335 |
if(is_numeric($where)) |
| 336 |
return ceil((int)$where / (int)$p_size); |
| 337 |
else |
| 338 |
return ceil((int)$this->getRecordCount($where) / (int)$p_size); |
| 339 |
} |
| 340 |
|
| 341 |
function validate( $values, $exclude=false ){ |
| 342 |
global $wpdb, $frm_field, $frm_entry_meta, $frm_settings; |
| 343 |
|
| 344 |
$errors = array(); |
| 345 |
|
| 346 |
if ( ! isset($values['form_id']) || ! isset($values['item_meta']) ) { |
| 347 |
$errors['form'] = __('There was a problem with your submission. Please try again.', 'formidable'); |
| 348 |
return $errors; |
| 349 |
} |
| 350 |
|
| 351 |
if ( is_admin() && is_user_logged_in() && ( ! isset($values['frm_submit_entry_'. $values['form_id']]) || ! wp_verify_nonce($values['frm_submit_entry_'. $values['form_id']], 'frm_submit_entry_nonce') ) ) { |
| 352 |
$errors['form'] = __('You do not have permission to do that', 'formidable'); |
| 353 |
} |
| 354 |
|
| 355 |
if( !isset($values['item_key']) or $values['item_key'] == '' ){ |
| 356 |
$_POST['item_key'] = $values['item_key'] = FrmAppHelper::get_unique_key('', $wpdb->prefix .'frm_items', 'item_key'); |
| 357 |
} |
| 358 |
|
| 359 |
$where = apply_filters('frm_posted_field_ids', 'fi.form_id='. (int)$values['form_id']); |
| 360 |
if($exclude) |
| 361 |
$where .= " and fi.type not in ('". implode("','", array_filter($exclude, 'esc_sql')) ."')"; |
| 362 |
|
| 363 |
$posted_fields = $frm_field->getAll($where, 'field_order'); |
| 364 |
|
| 365 |
foreach($posted_fields as $posted_field){ |
| 366 |
$posted_field->field_options = maybe_unserialize($posted_field->field_options); |
| 367 |
$value = ''; |
| 368 |
if (isset($values['item_meta'][$posted_field->id])) |
| 369 |
$value = $values['item_meta'][$posted_field->id]; |
| 370 |
|
| 371 |
if (isset($posted_field->field_options['default_blank']) and $posted_field->field_options['default_blank'] and $value == $posted_field->default_value) |
| 372 |
$value = ''; |
| 373 |
|
| 374 |
if(is_array($value) and count($value) === 1) |
| 375 |
$value = reset($value); |
| 376 |
|
| 377 |
if($posted_field->type == 'rte' and !is_array($value) and (trim($value) == '<br>')) |
| 378 |
$value = ''; |
| 379 |
|
| 380 |
if ($posted_field->required == '1' and !is_array($value) and trim($value) == ''){ |
| 381 |
$errors['field'. $posted_field->id] = (!isset($posted_field->field_options['blank']) or $posted_field->field_options['blank'] == '' or $posted_field->field_options['blank'] == 'Untitled cannot be blank') ? $frm_settings->blank_msg : $posted_field->field_options['blank']; |
| 382 |
}else if ($posted_field->type == 'text' and !isset($_POST['name'])){ |
| 383 |
$_POST['name'] = $value; |
| 384 |
} |
| 385 |
|
| 386 |
$_POST['item_meta'][$posted_field->id] = $value; |
| 387 |
|
| 388 |
if ($posted_field->type == 'captcha' and isset($_POST['recaptcha_challenge_field'])){ |
| 389 |
global $frm_settings; |
| 390 |
|
| 391 |
if(!function_exists('recaptcha_check_answer')) |
| 392 |
require(FrmAppHelper::plugin_path().'/classes/recaptchalib.php'); |
| 393 |
|
| 394 |
$response = recaptcha_check_answer($frm_settings->privkey, |
| 395 |
$_SERVER['REMOTE_ADDR'], |
| 396 |
$_POST['recaptcha_challenge_field'], |
| 397 |
$_POST['recaptcha_response_field']); |
| 398 |
|
| 399 |
if (!$response->is_valid) { |
| 400 |
// What happens when the CAPTCHA was entered incorrectly |
| 401 |
$errors['captcha-'. $response->error] = $errors['field'. $posted_field->id] = (!isset($posted_field->field_options['invalid']) or $posted_field->field_options['invalid'] == '') ? $frm_settings->re_msg : $posted_field->field_options['invalid']; |
| 402 |
} |
| 403 |
|
| 404 |
} |
| 405 |
|
| 406 |
$errors = apply_filters('frm_validate_field_entry', $errors, $posted_field, $value); |
| 407 |
|
| 408 |
} |
| 409 |
|
| 410 |
|
| 411 |
// check for spam |
| 412 |
if ( empty($exclude) && isset($values['item_meta']) && !empty($values['item_meta']) && empty($errors) ) { |
| 413 |
global $wpcom_api_key; |
| 414 |
if ( (function_exists( 'akismet_http_post' ) || is_callable('Akismet::http_post')) && ((get_option('wordpress_api_key') || $wpcom_api_key)) && $this->akismet($values) ) { |
| 415 |
$frm_form = new FrmForm(); |
| 416 |
$form = $frm_form->getOne($values['form_id']); |
| 417 |
|
| 418 |
if ( isset($form->options['akismet']) && !empty($form->options['akismet']) && ($form->options['akismet'] != 'logged' || !is_user_logged_in()) ) { |
| 419 |
$errors['spam'] = __('Your entry appears to be spam!', 'formidable'); |
| 420 |
} |
| 421 |
} |
| 422 |
|
| 423 |
// check for blacklist keys |
| 424 |
if ( $this->blacklist_check($values) ) { |
| 425 |
$errors['spam'] = __('Your entry appears to be spam!', 'formidable'); |
| 426 |
} |
| 427 |
} |
| 428 |
|
| 429 |
|
| 430 |
$errors = apply_filters('frm_validate_entry', $errors, $values); |
| 431 |
return $errors; |
| 432 |
} |
| 433 |
|
| 434 |
// check the blacklisted words |
| 435 |
function blacklist_check( $values ) { |
| 436 |
if ( ! apply_filters('frm_check_blacklist', true, $values) ) { |
| 437 |
return false; |
| 438 |
} |
| 439 |
|
| 440 |
$mod_keys = trim( get_option( 'blacklist_keys' ) ); |
| 441 |
|
| 442 |
if ( empty( $mod_keys ) ) { |
| 443 |
return false; |
| 444 |
} |
| 445 |
|
| 446 |
$content = FrmEntriesHelper::entry_array_to_string($values); |
| 447 |
|
| 448 |
if ( empty($content) ) { |
| 449 |
return false; |
| 450 |
} |
| 451 |
|
| 452 |
$words = explode( "\n", $mod_keys ); |
| 453 |
|
| 454 |
foreach ( (array) $words as $word ) { |
| 455 |
$word = trim( $word ); |
| 456 |
|
| 457 |
if ( empty($word) ) { |
| 458 |
continue; |
| 459 |
} |
| 460 |
|
| 461 |
if ( preg_match('#' . preg_quote( $word, '#' ) . '#', $content) ) { |
| 462 |
return true; |
| 463 |
} |
| 464 |
} |
| 465 |
|
| 466 |
return false; |
| 467 |
} |
| 468 |
|
| 469 |
//Check entries for spam -- returns true if is spam |
| 470 |
function akismet($values) { |
| 471 |
$content = FrmEntriesHelper::entry_array_to_string($values); |
| 472 |
|
| 473 |
if ( empty($content) ) { |
| 474 |
return false; |
| 475 |
} |
| 476 |
|
| 477 |
$datas = array(); |
| 478 |
$datas['blog'] = FrmAppHelper::site_url(); |
| 479 |
$datas['user_ip'] = preg_replace( '/[^0-9., ]/', '', $_SERVER['REMOTE_ADDR'] ); |
| 480 |
$datas['user_agent'] = $_SERVER['HTTP_USER_AGENT']; |
| 481 |
$datas['referrer'] = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : false; |
| 482 |
$datas['comment_type'] = 'formidable'; |
| 483 |
if ( $permalink = get_permalink() ) |
| 484 |
$datas['permalink'] = $permalink; |
| 485 |
|
| 486 |
$datas['comment_content'] = $content; |
| 487 |
|
| 488 |
foreach ( $_SERVER as $key => $value ) { |
| 489 |
if ( !in_array($key, array('HTTP_COOKIE', 'HTTP_COOKIE2', 'PHP_AUTH_PW')) && is_string($value) ) { |
| 490 |
$datas["$key"] = $value; |
| 491 |
} else { |
| 492 |
$datas["$key"] = ''; |
| 493 |
} |
| 494 |
|
| 495 |
unset($key, $value); |
| 496 |
} |
| 497 |
|
| 498 |
$query_string = ''; |
| 499 |
foreach ( $datas as $key => $data ) { |
| 500 |
$query_string .= $key . '=' . urlencode( stripslashes( $data ) ) . '&'; |
| 501 |
unset($key, $data); |
| 502 |
} |
| 503 |
|
| 504 |
if ( is_callable('Akismet::http_post') ) { |
| 505 |
$response = Akismet::http_post($query_string, 'comment-check'); |
| 506 |
} else { |
| 507 |
global $akismet_api_host, $akismet_api_port; |
| 508 |
$response = akismet_http_post( $query_string, $akismet_api_host, '/1.1/comment-check', $akismet_api_port ); |
| 509 |
} |
| 510 |
|
| 511 |
return ( is_array($response) and $response[1] == 'true' ) ? true : false; |
| 512 |
} |
| 513 |
|
| 514 |
} |
| 515 |
|