PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 1.07.11
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v1.07.11
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmEntry.php +467 -1322 6.35 → 1.07.11 View file →
@@ -1,1369 +1,514 @@
1 1 <?php
2 -if ( ! defined( 'ABSPATH' ) ) {
3 - die( 'You are not allowed to call this page directly.' );
4 -}
2 +if(!defined('ABSPATH')) die(__('You are not allowed to call this page directly.', 'formidable'));
5 3
6 -class FrmEntry {
4 +if(class_exists('FrmEntry'))
5 + return;
7 6
8 - /**
9 - * @since 6.16.3
10 - *
11 - * @var array
12 - */
13 - private static $unique_id_match_checks = array();
7 +class FrmEntry{
14 8
15 - /**
16 - * Create a new entry
17 - *
18 - * @param array $values
19 - *
20 - * @return bool|int Entry ID.
21 - */
22 - public static function create( $values ) {
23 - return self::create_entry( $values, 'standard' );
24 - }
9 + function create( $values ){
10 + global $wpdb, $frm_entry_meta;
11 +
12 + $new_values = array(
13 + 'item_key' => FrmAppHelper::get_unique_key($values['item_key'], $wpdb->prefix .'frm_items', 'item_key'),
14 + 'name' => isset($values['name']) ? $values['name'] : $values['item_key'],
15 + 'ip' => $_SERVER['REMOTE_ADDR'],
16 + 'is_draft' => ( ( isset($values['frm_saving_draft']) && $values['frm_saving_draft'] == 1 ) || ( isset($values['is_draft']) && $values['is_draft'] == 1) ) ? 1 : 0,
17 + 'form_id' => isset($values['form_id']) ? (int) $values['form_id']: null,
18 + 'post_id' => isset($values['post_id']) ? (int) $values['post_id']: null,
19 + 'created_at' => isset($values['created_at']) ? $values['created_at'] : current_time('mysql', 1),
20 + 'updated_at' => isset($values['updated_at']) ? $values['updated_at'] : ( isset($values['created_at']) ? $values['created_at'] : current_time('mysql', 1) ),
21 + );
22 +
23 + if(is_array($new_values['name']))
24 + $new_values['name'] = reset($new_values['name']);
25 +
26 + if(isset($values['description']) and !empty($values['description'])){
27 + $new_values['description'] = maybe_serialize($values['description']);
28 + }else{
29 + $referrerinfo = FrmAppHelper::get_referer_info();
30 +
31 + $new_values['description'] = serialize(array('browser' => $_SERVER['HTTP_USER_AGENT'],
32 + 'referrer' => $referrerinfo));
33 + }
34 +
35 + //if(isset($values['id']) and is_numeric($values['id']))
36 + // $new_values['id'] = $values['id'];
37 +
38 + if(isset($values['frm_user_id']) and (is_numeric($values['frm_user_id']) or (is_admin() and !defined('DOING_AJAX')))){
39 + $new_values['user_id'] = $values['frm_user_id'];
40 + }else{
41 + $user_ID = get_current_user_id();
42 + $new_values['user_id'] = $user_ID ? $user_ID : 0;
43 + }
44 +
45 + $new_values['updated_by'] = isset($values['updated_by']) ? $values['updated_by'] : $new_values['user_id'];
46 +
47 + //check for duplicate entries created in the last 5 minutes
48 + if(!defined('WP_IMPORTING')){
49 + $create_entry = true;
50 +
51 + $check_val = $new_values;
52 + $check_val['created_at >'] = date('Y-m-d H:i:s', (strtotime($new_values['created_at']) - (60*5)));
53 + unset($check_val['created_at']);
54 + unset($check_val['updated_at']);
55 + unset($check_val['is_draft']);
56 + unset($check_val['id']);
57 + unset($check_val['item_key']);
58 + if($new_values['item_key'] == $new_values['name'])
59 + unset($check_val['name']);
60 +
61 + global $frmdb;
62 + $entry_exists = $frmdb->get_records($wpdb->prefix .'frm_items', $check_val, 'created_at DESC', '', 'id');
63 + unset($frmdb);
64 +
65 + if($entry_exists and !empty($entry_exists)){
66 + foreach($entry_exists as $entry_exist){
67 + if($create_entry){
68 + $create_entry = false;
69 + //add more checks here to make sure it's a duplicate
70 + if (isset($values['item_meta'])){
71 + $metas = $frm_entry_meta->get_entry_meta_info($entry_exist->id);
72 + $field_metas = array();
73 + foreach($metas as $meta)
74 + $field_metas[$meta->field_id] = $meta->meta_value;
25 75
26 - /**
27 - * Create a new entry with some differences depending on type
28 - *
29 - * @param array $values
30 - * @param string $type
31 - *
32 - * @return bool|int Entry ID.
33 - */
34 - private static function create_entry( $values, $type ) {
35 - $new_values = self::before_insert_entry_in_database( $values, $type );
76 + $diff = array_diff_assoc($field_metas, array_map('maybe_serialize', $values['item_meta']));
77 + foreach($diff as $field_id => $meta_value){
78 + if(!empty($meta_value) and !$create_entry)
79 + $create_entry = true;
80 + }
81 + }
82 + }
83 + }
84 + }
85 +
86 + if ( !$create_entry ) {
87 + return false;
88 + }
89 + }
90 +
91 + $query_results = $wpdb->insert( $wpdb->prefix .'frm_items', $new_values );
92 +
93 + if ( $query_results ) {
94 + $entry_id = $wpdb->insert_id;
95 +
96 + global $frm_vars;
97 + if(!isset($frm_vars['saved_entries']))
98 + $frm_vars['saved_entries'] = array();
99 + $frm_vars['saved_entries'][] = (int)$entry_id;
100 +
101 + if ( isset($values['item_meta']) ) {
102 + $frm_entry_meta->update_entry_metas($entry_id, $values['item_meta']);
103 + }
104 +
105 + do_action('frm_after_create_entry', $entry_id, $new_values['form_id']);
106 + do_action('frm_after_create_entry_'. $new_values['form_id'], $entry_id);
107 + return $entry_id;
108 + } else {
109 + return false;
110 + }
111 + }
112 +
113 + function duplicate( $id ){
114 + global $wpdb, $frm_entry, $frm_entry_meta;
36 115
37 - // Don't check XML entries for duplicates
38 - if ( $type !== 'xml' && self::is_duplicate( $new_values, $values ) ) {
39 - return false;
40 - }
116 + $values = $frm_entry->getOne( $id );
41 117
42 - return self::continue_to_create_entry( $values, $new_values );
43 - }
118 + $new_values = array();
119 + $new_values['item_key'] = FrmAppHelper::get_unique_key('', $wpdb->prefix .'frm_items', 'item_key');
120 + $new_values['name'] = $values->name;
121 + $new_values['is_draft'] = $values->is_draft;
122 + $new_values['user_id'] = $new_values['updated_by'] = (int)$values->user_id;
123 + $new_values['form_id'] = $values->form_id ? (int)$values->form_id: null;
124 + $new_values['created_at'] = $new_values['updated_at'] = current_time('mysql', 1);
44 125
45 - /**
46 - * Flag the memoized unique id check after a new entry is created.
47 - * This prevents possibly DB requests and helps avoid issues when creating repeater entries.
48 - *
49 - * @since 6.16.3
50 - *
51 - * @param string $unique_id
52 - *
53 - * @return void
54 - */
55 - private static function flag_new_unique_key( $unique_id ) {
56 - if ( ! isset( self::$unique_id_match_checks[ $unique_id ] ) ) {
57 - self::$unique_id_match_checks[ $unique_id ] = false;
58 - }
59 - }
126 + $query_results = $wpdb->insert( $wpdb->prefix .'frm_items', $new_values );
127 + if($query_results){
128 + $entry_id = $wpdb->insert_id;
129 +
130 + global $frm_vars;
131 + if(!isset($frm_vars['saved_entries']))
132 + $frm_vars['saved_entries'] = array();
133 + $frm_vars['saved_entries'][] = (int)$entry_id;
134 +
135 + $frm_entry_meta->duplicate_entry_metas($id, $entry_id);
136 +
137 + do_action('frm_after_duplicate_entry', $entry_id, $new_values['form_id']);
138 + return $entry_id;
139 + }else
140 + return false;
141 + }
60 142
61 - /**
62 - * Check for duplicate entries created in the last minute
63 - *
64 - * @param array $new_values New values.
65 - * @param array $values Values.
66 - *
67 - * @return bool
68 - */
69 - public static function is_duplicate( $new_values, $values ) {
70 - $duplicate_entry_time = apply_filters( 'frm_time_to_check_duplicates', 60, $new_values );
143 + function update( $id, $values ){
144 + global $wpdb, $frm_entry_meta, $frm_field, $frm_vars;
145 + if(isset($frm_vars['saved_entries']) && is_array($frm_vars['saved_entries']) && in_array((int)$id, (array)$frm_vars['saved_entries']))
146 + return;
71 147
72 - if ( false === self::is_duplicate_check_needed( $values, $duplicate_entry_time ) ) {
73 - return false;
74 - }
148 + $user_ID = get_current_user_id();
149 +
150 + $new_values = array(
151 + 'name' => isset($values['name']) ? $values['name'] : '',
152 + 'form_id' => isset($values['form_id']) ? (int) $values['form_id'] : null,
153 + 'is_draft' => ( ( isset($values['frm_saving_draft']) && $values['frm_saving_draft'] == 1 ) || ( isset($values['is_draft']) && $values['is_draft'] == 1) ) ? 1 : 0,
154 + 'updated_at' => current_time('mysql', 1),
155 + 'updated_by' => isset($values['updated_by']) ? $values['updated_by'] : $user_ID,
156 + );
157 +
158 + if ( isset($values['post_id']) ) {
159 + $new_values['post_id'] = (int) $values['post_id'];
160 + }
75 161
76 - if ( self::maybe_check_for_unique_id_match( $values, $new_values['created_at'] ) ) {
77 - return true;
78 - }
162 + if ( isset($values['item_key']) ) {
163 + $new_values['item_key'] = FrmAppHelper::get_unique_key($values['item_key'], $wpdb->prefix .'frm_items', 'item_key', $id);
164 + }
165 +
166 + if(isset($values['frm_user_id']) and is_numeric($values['frm_user_id']))
167 + $new_values['user_id'] = $values['frm_user_id'];
79 168
80 - $check_val = $new_values;
81 - $check_val['created_at >'] = gmdate( 'Y-m-d H:i:s', strtotime( $new_values['created_at'] ) - absint( $duplicate_entry_time ) );
169 + $new_values = apply_filters('frm_update_entry', $new_values, $id);
170 + $query_results = $wpdb->update( $wpdb->prefix .'frm_items', $new_values, compact('id') );
171 + if($query_results)
172 + wp_cache_delete( $id, 'frm_entry');
173 +
174 + if(!isset($frm_vars['saved_entries']))
175 + $frm_vars['saved_entries'] = array();
176 +
177 + $frm_vars['saved_entries'][] = (int)$id;
178 +
179 + if (isset($values['item_meta']))
180 + $frm_entry_meta->update_entry_metas($id, $values['item_meta']);
181 + do_action('frm_after_update_entry', $id, $new_values['form_id']);
182 + do_action('frm_after_update_entry_'. $new_values['form_id'], $id);
183 + return $query_results;
184 + }
82 185
83 - unset( $check_val['created_at'], $check_val['updated_at'], $check_val['is_draft'], $check_val['id'], $check_val['item_key'] );
186 + function &destroy( $id ){
187 + global $wpdb;
188 + $id = (int)$id;
189 +
190 + $entry = $this->getOne($id);
191 + if ( !$entry ) {
192 + $result = false;
193 + return $result;
194 + }
195 +
196 + do_action('frm_before_destroy_entry', $id, $entry);
197 +
198 + wp_cache_delete( $id, 'frm_entry');
199 + $wpdb->query('DELETE FROM ' . $wpdb->prefix .'frm_item_metas WHERE item_id=' . $id);
200 + $result = $wpdb->query('DELETE FROM ' . $wpdb->prefix .'frm_items WHERE id=' . $id);
201 + return $result;
202 + }
203 +
204 + function &update_form( $id, $value, $form_id ){
205 + global $wpdb;
206 + $form_id = isset($value) ? $form_id : NULL;
207 + $result = $wpdb->update( $wpdb->prefix .'frm_items', array('form_id' => $form_id), array( 'id' => $id ) );
208 + if($result)
209 + wp_cache_delete( $id, 'frm_entry');
210 + return $result;
211 + }
212 +
213 + function getOne( $id, $meta=false){
214 + global $wpdb;
215 +
216 + $entry = wp_cache_get( $id, 'frm_entry' );
217 + if($entry)
218 + return stripslashes_deep($entry);
84 219
85 - // phpcs:ignore Universal.Operators.StrictComparisons
86 - if ( $new_values['item_key'] == $new_values['name'] ) {
87 - unset( $check_val['name'] );
88 - }
89 -
90 - $check_val = apply_filters( 'frm_duplicate_check_val', $check_val );
91 -
92 - if ( ! isset( $values['item_meta'] ) ) {
93 - return false;
94 - }
95 -
96 - $entry_exists = FrmDb::get_col( 'frm_items', $check_val, 'id', array( 'order_by' => 'created_at DESC' ) );
97 -
98 - if ( ! $entry_exists ) {
99 - return false;
100 - }
101 -
102 - global $frm_vars;
103 - $frm_vars['checking_duplicates'] = true;
104 - $is_duplicate = false;
105 -
106 - foreach ( $entry_exists as $entry_exist ) {
107 - $is_duplicate = true;
108 -
109 - // Make sure it's a duplicate
110 - $metas = FrmEntryMeta::get_entry_meta_info( $entry_exist );
111 - $field_metas = array();
112 -
113 - foreach ( $metas as $meta ) {
114 - if ( 0 === (int) $meta->field_id ) {
115 - continue;
116 - }
117 -
118 - $field_metas[ $meta->field_id ] = $meta->meta_value;
119 - }
120 -
121 - $filtered_vals = array_filter( $values['item_meta'] );
122 - $filtered_vals = self::convert_values_to_their_saved_value( $filtered_vals, $entry_exist );
123 - $field_metas = array_filter( $field_metas );
124 -
125 - // If prev entry is empty and current entry is not, they are not duplicates
126 - if ( ! $field_metas && $filtered_vals ) {
127 - return false;
128 - }
129 -
130 - // Compare serialized values and not arrays
131 - $new_meta = array_map( 'maybe_serialize', $filtered_vals );
132 -
133 - if ( $field_metas === $new_meta ) {
134 - $is_duplicate = true;
135 - break;
136 - }
137 -
138 - if ( count( $field_metas ) !== count( $new_meta ) ) {
139 - // TODO: compare values saved in the post also
140 - $is_duplicate = false;
141 - continue;
142 - }
143 -
144 - $diff = array_diff_assoc( $field_metas, $new_meta );
145 -
146 - foreach ( $diff as $meta_value ) {
147 - if ( $meta_value ) {
148 - $is_duplicate = false;
149 - }
150 - }
151 -
152 - if ( $is_duplicate ) {
153 - break;
154 - }
155 - }//end foreach
156 -
157 - $frm_vars['checking_duplicates'] = false;
158 -
159 - return $is_duplicate;
160 - }
161 -
162 - /**
163 - * @since 6.16.3
164 - *
165 - * @param array $values POST request data.
166 - * @param string $created_at The timestamp of the entry we are checking for.
167 - *
168 - * @return bool
169 - */
170 - private static function maybe_check_for_unique_id_match( $values, $created_at ) {
171 - if ( ! self::should_check_for_unique_id_match() ) {
172 - return false;
173 - }
174 -
175 - if ( empty( $values['unique_id'] ) ) {
176 - return false;
177 - }
178 -
179 - $unique_id = sanitize_key( $values['unique_id'] );
180 -
181 - if ( ! $unique_id ) {
182 - // Only continue if a unique ID was generated on form submit.
183 - return false;
184 - }
185 -
186 - if ( isset( self::$unique_id_match_checks[ $unique_id ] ) ) {
187 - return self::$unique_id_match_checks[ $unique_id ];
188 - }
189 -
190 - $timestamp = strtotime( $created_at );
191 -
192 - if ( false === $timestamp ) {
193 - $timestamp = time();
194 - }
195 -
196 - self::$unique_id_match_checks[ $unique_id ] = (bool) FrmDb::get_var(
197 - 'frm_item_metas',
198 - array(
199 - 'field_id' => 0,
200 - 'meta_value' => serialize( compact( 'unique_id' ) ),
201 - 'created_at >' => gmdate( 'Y-m-d H:i:s', $timestamp - MONTH_IN_SECONDS ),
202 - ),
203 - 'id'
204 - );
205 -
206 - return self::$unique_id_match_checks[ $unique_id ];
207 - }
208 -
209 - /**
210 - * @since 6.16.3
211 - *
212 - * @return bool
213 - */
214 - private static function should_check_for_unique_id_match() {
215 - /**
216 - * Allow users to opt out of the DB query, in case it causes performance issues.
217 - *
218 - * @since 6.16.3
219 - *
220 - * @param bool $should_extend
221 - */
222 - $should_check = apply_filters( 'frm_check_for_unique_id_match', true );
223 - return (bool) $should_check;
224 - }
225 -
226 - /**
227 - * Convert form data to the actual value that would be saved into the database.
228 - *
229 - * This is important for the duplicate check as something like 'a:2:{s:5:"typed";s:0:"";s:6:"output";s:0:"";}'
230 - * (a signature value) is actually an empty string and does not get saved.
231 - *
232 - * @param array $filter_vals
233 - * @param int $entry_id
234 - *
235 - * @return array
236 - */
237 - private static function convert_values_to_their_saved_value( $filter_vals, $entry_id ) {
238 - $reduced = array();
239 -
240 - foreach ( $filter_vals as $field_id => $value ) {
241 - $field = FrmFieldFactory::get_field_object( $field_id );
242 - $reduced[ $field_id ] = $field->get_value_to_save( $value, array( 'entry_id' => $entry_id ) );
243 - $reduced[ $field_id ] = $field->set_value_before_save( $reduced[ $field_id ] );
244 -
245 - if ( '' === $reduced[ $field_id ] || array() === $reduced[ $field_id ] ) {
246 - unset( $reduced[ $field_id ] );
247 - }
248 - }
249 -
250 - return $reduced;
251 - }
252 -
253 - /**
254 - * Determine if an entry needs to be checked as a possible duplicate
255 - *
256 - * @since 2.0.23
257 - *
258 - * @param array $values
259 - * @param int $duplicate_entry_time
260 - *
261 - * @return bool
262 - */
263 - private static function is_duplicate_check_needed( $values, $duplicate_entry_time ) {
264 - // If time for checking duplicates is set to an empty value, don't check for duplicates
265 - if ( ! $duplicate_entry_time ) {
266 - return false;
267 - }
268 -
269 - // If CSV is importing, don't check for duplicates
270 - if ( defined( 'WP_IMPORTING' ) && WP_IMPORTING ) {
271 - return false;
272 - }
273 -
274 - // If repeating field entries are getting created, don't check for duplicates
275 - return empty( $values['parent_form_id'] );
276 - }
277 -
278 - /**
279 - * @param int|string $id
280 - *
281 - * @return false|int
282 - */
283 - public static function duplicate( $id ) {
284 - global $wpdb;
285 -
286 - $values = self::getOne( $id );
287 - $new_values = array();
288 - $new_values['item_key'] = FrmAppHelper::get_unique_key( '', $wpdb->prefix . 'frm_items', 'item_key' );
289 - $new_values['name'] = $values->name;
290 - $new_values['is_draft'] = $values->is_draft;
291 - $new_values['user_id'] = (int) $values->user_id;
292 - $new_values['updated_by'] = (int) $values->user_id;
293 - $new_values['form_id'] = $values->form_id ? (int) $values->form_id : null;
294 - $new_values['created_at'] = current_time( 'mysql', 1 );
295 - $new_values['updated_at'] = $new_values['created_at'];
296 -
297 - $query_results = $wpdb->insert( $wpdb->prefix . 'frm_items', $new_values );
298 -
299 - if ( ! $query_results ) {
300 - return false;
301 - }
302 -
303 - $entry_id = $wpdb->insert_id;
304 -
305 - global $frm_vars;
306 -
307 - if ( ! isset( $frm_vars['saved_entries'] ) ) {
308 - $frm_vars['saved_entries'] = array();
309 - }
310 - $frm_vars['saved_entries'][] = (int) $entry_id;
311 -
312 - FrmEntryMeta::duplicate_entry_metas( $id, $entry_id );
313 - self::clear_cache();
314 -
315 - do_action( 'frm_after_duplicate_entry', $entry_id, $new_values['form_id'], array( 'old_id' => $id ) );
316 -
317 - return $entry_id;
318 - }
319 -
320 - /**
321 - * Update an entry (not via XML)
322 - *
323 - * @param int $id
324 - * @param array $values
325 - *
326 - * @return bool|int Update results.
327 - */
328 - public static function update( $id, $values ) {
329 - return self::update_entry( $id, $values, 'standard' );
330 - }
331 -
332 - /**
333 - * Update an entry with some differences depending on the update type
334 - *
335 - * @since 2.0.16
336 - *
337 - * @param int $id
338 - * @param array $values
339 - * @param string $update_type
340 - *
341 - * @return bool|int Query results.
342 - */
343 - private static function update_entry( $id, $values, $update_type ) {
344 - global $wpdb;
345 -
346 - $update = self::before_update_entry( $id, $values, $update_type );
347 -
348 - if ( ! $update ) {
349 - return false;
350 - }
351 -
352 - $new_values = self::package_entry_to_update( $id, $values, $update_type );
353 - $query_results = $wpdb->update( $wpdb->prefix . 'frm_items', $new_values, compact( 'id' ) );
354 -
355 - self::after_update_entry( $query_results, $id, $values, $new_values );
356 -
357 - return $query_results;
358 - }
359 -
360 - /**
361 - * Delete an entry.
362 - *
363 - * @param int|string $id
364 - *
365 - * @return bool True on success, false if nothing was deleted.
366 - */
367 - public static function destroy( $id ) {
368 - global $wpdb;
369 - $id = (int) $id;
370 -
371 - // Item meta is required for conditional logic in actions with 'delete' events.
372 - $entry = self::getOne( $id, true );
373 -
374 - if ( ! $entry ) {
375 - return false;
376 - }
377 -
378 - /**
379 - * Trigger an action to run custom logic before the entry is deleted.
380 - *
381 - * @param int $id The id of the entry that was destroyed.
382 - * @param stdClass $entry The entry object.
383 - */
384 - do_action( 'frm_before_destroy_entry', $id, $entry );
385 -
386 - $wpdb->query( $wpdb->prepare( 'DELETE FROM ' . $wpdb->prefix . 'frm_item_metas WHERE item_id=%d', $id ) );
387 - $result = $wpdb->query( $wpdb->prepare( 'DELETE FROM ' . $wpdb->prefix . 'frm_items WHERE id=%d', $id ) );
388 -
389 - self::clear_cache();
390 -
391 - /**
392 - * Trigger an action to run custom logic after the entry is deleted.
393 - * Use this hook if you need to update caching after an entry is deleted.
394 - *
395 - * @since 5.4.1
396 - *
397 - * @param int $id The id of the entry that was destroyed.
398 - * @param stdClass $entry The entry object.
399 - */
400 - do_action( 'frm_after_destroy_entry', $id, $entry );
401 -
402 - return $result;
403 - }
404 -
405 - /**
406 - * @param int $id
407 - * @param mixed $value
408 - * @param int|string $form_id
409 - *
410 - * @return false|int
411 - */
412 - public static function update_form( $id, $value, $form_id ) {
413 - global $wpdb;
414 - $form_id = isset( $value ) ? $form_id : null;
415 - $result = $wpdb->update( $wpdb->prefix . 'frm_items', array( 'form_id' => $form_id ), array( 'id' => $id ) );
416 -
417 - if ( $result ) {
418 - self::clear_cache();
419 - }
420 -
421 - return $result;
422 - }
423 -
424 - /**
425 - * Clear entry caching
426 - * Called when an entry is changed
427 - *
428 - * @since 2.0.5
429 - *
430 - * @return void
431 - */
432 - public static function clear_cache() {
433 - FrmDb::cache_delete_group( 'frm_entry' );
434 - FrmDb::cache_delete_group( 'frm_item' );
435 - FrmDb::cache_delete_group( 'frm_entry_meta' );
436 - FrmDb::cache_delete_group( 'frm_item_meta' );
437 - }
438 -
439 - /**
440 - * After switching to the wp_loaded hook for processing entries,
441 - * we can no longer use 'name', but check it as a fallback
442 - *
443 - * @since 2.0.11
444 - *
445 - * @param array $values
446 - * @param array|string $default
447 - *
448 - * @return string
449 - */
450 - public static function get_new_entry_name( $values, $default = '' ) {
451 - $name = $values['item_name'] ?? $values['name'] ?? $default;
452 - return is_array( $name ) ? reset( $name ) : $name;
453 - }
454 -
455 - /**
456 - * If $entry is numeric, get the entry object
457 - *
458 - * @since 2.0.9
459 - *
460 - * @param int|object|string $entry By reference.
461 - *
462 - * @return void
463 - */
464 - public static function maybe_get_entry( &$entry ) {
465 - if ( $entry && is_numeric( $entry ) ) {
466 - $entry = self::getOne( $entry );
467 - } elseif ( ! $entry || 'false' === $entry ) {
468 - $entry = false;
469 - }
470 - }
471 -
472 - /**
473 - * @param int|string $id
474 - * @param bool $meta
475 - *
476 - * @return object|null
477 - */
478 - public static function getOne( $id, $meta = false ) {
479 - global $wpdb;
480 -
481 - $query = "SELECT it.*, fr.name as form_name, fr.form_key as form_key FROM {$wpdb->prefix}frm_items it
220 + $query = "SELECT it.*, fr.name as form_name, fr.form_key as form_key FROM {$wpdb->prefix}frm_items it
482 221 LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id WHERE ";
222 +
223 + $query .= $wpdb->prepare( is_numeric($id) ? 'it.id=%d' : 'it.item_key=%s', $id);
483 224
484 - $query .= is_numeric( $id ) ? 'it.id=%d' : 'it.item_key=%s';
485 - $query_args = array( $id );
486 - $query = $wpdb->prepare( $query, $query_args ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
225 + $entry = $wpdb->get_row($query);
487 226
488 - if ( ! $meta ) {
489 - $entry = FrmDb::check_cache( $id . '_nometa', 'frm_entry', $query, 'get_row' );
490 - self::prepare_entry( $entry );
491 - return $entry;
492 - }
227 + if($meta and $entry){
228 + $metas = $wpdb->get_results($wpdb->prepare("SELECT field_id, meta_value, field_key FROM {$wpdb->prefix}frm_item_metas m LEFT JOIN {$wpdb->prefix}frm_fields f ON m.field_id=f.id WHERE item_id=%d and field_id != %d", $entry->id, 0));
229 +
230 + $entry_metas = array();
231 +
232 + foreach($metas as $meta_val){
233 + $entry_metas[$meta_val->field_id] = $entry_metas[$meta_val->field_key] = maybe_unserialize($meta_val->meta_value);
234 + unset($meta_val);
235 + }
236 + unset($metas);
493 237
494 - $entry = FrmDb::check_cache( $id, 'frm_entry' );
238 + $entry->metas = $entry_metas;
495 239
496 - if ( $entry !== false ) {
497 - self::prepare_entry( $entry );
498 - return $entry;
499 - }
240 + wp_cache_set( $entry->id, $entry, 'frm_entry');
241 + }
500 242
501 - $entry = $wpdb->get_row( $query ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
502 - $entry = self::get_meta( $entry );
503 - self::prepare_entry( $entry );
243 + return stripslashes_deep($entry);
244 + }
245 +
246 + function &exists( $id ){
247 + global $wpdb;
248 +
249 + if(wp_cache_get( $id, 'frm_entry' )){
250 + $exists = true;
251 + return $exists;
252 + }
253 +
254 + $where = (is_numeric($id)) ? 'id=%d' : 'item_key=%s';
504 255
505 - return $entry;
506 - }
256 + $id = $wpdb->get_var($wpdb->prepare("SELECT id FROM {$wpdb->prefix}frm_items WHERE $where", $id));
257 +
258 + $exists = ($id && $id > 0) ? true : false;
259 + return $exists;
260 + }
507 261
508 - /**
509 - * @since 4.02.03
510 - *
511 - * @param object $entry
512 - *
513 - * @return void
514 - */
515 - private static function prepare_entry( &$entry ) {
516 - if ( ! $entry ) {
517 - return;
262 + function getAll($where = '', $order_by = '', $limit = '', $meta=false, $inc_form=true){
263 + global $wpdb;
264 +
265 + if(is_numeric($limit))
266 + $limit = " LIMIT {$limit}";
267 +
268 + if($inc_form){
269 + $query = "SELECT it.*, fr.name as form_name,fr.form_key as form_key
270 + FROM {$wpdb->prefix}frm_items it LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id" .
271 + FrmAppHelper::prepend_and_or_where(' WHERE ', $where) . $order_by . $limit;
272 + }else{
273 + $query = "SELECT it.id, it.item_key, it.name, it.ip, it.form_id, it.post_id, it.user_id, it.updated_by,
274 + it.created_at, it.updated_at, it.is_draft FROM {$wpdb->prefix}frm_items it" .
275 + FrmAppHelper::prepend_and_or_where(' WHERE ', $where) . $order_by . $limit;
276 + }
277 +
278 + if ( preg_match( '/ meta_([0-9]+)/', $order_by, $order_matches ) ) {
279 + // sort by a requested field
280 + $query = str_replace( " FROM {$wpdb->prefix}frm_items ", ", (SELECT meta_value FROM {$wpdb->prefix}frm_item_metas WHERE field_id = {$order_matches[1]} AND item_id = it.id) as meta_{$order_matches[1]} FROM {$wpdb->prefix}frm_items ", $query );
518 281 }
282 +
283 + $entries = $wpdb->get_results($query, OBJECT_K);
284 + unset($query);
285 +
286 + if($meta and $entries){
287 + if($limit == '' and !is_array($where) and preg_match('/^it\.form_id=\d+$/', $where)){
288 + $meta_where = $wpdb->prepare('fi.form_id=%d', substr($where, 11));
289 + }else if($limit == '' and is_array($where) and count($where) == 1 and isset($where['it.form_id'])){
290 + $meta_where = $wpdb->prepare('fi.form_id=%d', $where['it.form_id']);
291 + }else{
292 + $meta_where = "item_id in (". implode(',', array_filter(array_keys($entries), 'is_numeric')) .")";
293 + }
294 + $query = "SELECT item_id, meta_value, field_id, field_key FROM {$wpdb->prefix}frm_item_metas it
295 + LEFT OUTER JOIN {$wpdb->prefix}frm_fields fi ON it.field_id=fi.id
296 + WHERE $meta_where and field_id != 0";
297 +
298 + $metas = $wpdb->get_results($query);
299 + unset($query);
300 +
301 + if($metas){
302 + foreach($metas as $m_key => $meta_val){
303 + if(!isset($entries[$meta_val->item_id]))
304 + continue;
305 +
306 + if(!isset($entries[$meta_val->item_id]->metas))
307 + $entries[$meta_val->item_id]->metas = array();
308 +
309 + $entries[$meta_val->item_id]->metas[$meta_val->field_id] = $entries[$meta_val->item_id]->metas[$meta_val->field_key] = maybe_unserialize($meta_val->meta_value);
310 + }
311 +
312 + foreach($entries as $entry){
313 + wp_cache_set( $entry->id, $entry, 'frm_entry');
314 + unset($entry);
315 + }
316 + }
317 + }
318 +
319 + return stripslashes_deep($entries);
320 + }
519 321
520 - FrmAppHelper::unserialize_or_decode( $entry->description );
521 - // TODO: Remove slashes on input only, not output.
522 - $entry = wp_unslash( $entry );
523 - }
322 + // Pagination Methods
323 + function getRecordCount($where=''){
324 + global $wpdb;
325 + if(is_numeric($where)){
326 + $query = "SELECT COUNT(*) FROM {$wpdb->prefix}frm_items WHERE form_id=". $where;
327 + }else{
328 + $query = "SELECT COUNT(*) FROM {$wpdb->prefix}frm_items it LEFT OUTER JOIN {$wpdb->prefix}frm_forms fr ON it.form_id=fr.id" .
329 + FrmAppHelper::prepend_and_or_where(' WHERE ', $where);
330 + }
331 + return $wpdb->get_var($query);
332 + }
524 333
525 - /**
526 - * @since 4.02.03
527 - *
528 - * @param array $entries
529 - *
530 - * @return void
531 - */
532 - private static function prepare_entries( &$entries ) {
533 - foreach ( $entries as $k => $entry ) {
534 - self::prepare_entry( $entry );
535 - $entries[ $k ] = $entry;
536 - }
537 - }
334 + function getPageCount($p_size, $where=''){
335 + if(is_numeric($where))
336 + return ceil((int)$where / (int)$p_size);
337 + else
338 + return ceil((int)$this->getRecordCount($where) / (int)$p_size);
339 + }
538 340
539 - /**
540 - * @param object|null $entry
541 - *
542 - * @return object|null
543 - */
544 - public static function get_meta( $entry ) {
545 - if ( ! $entry ) {
546 - return $entry;
547 - }
341 + function validate( $values, $exclude=false ){
342 + global $wpdb, $frm_field, $frm_entry_meta, $frm_settings;
343 +
344 + $errors = array();
345 +
346 + if ( ! isset($values['form_id']) || ! isset($values['item_meta']) ) {
347 + $errors['form'] = __('There was a problem with your submission. Please try again.', 'formidable');
348 + return $errors;
349 + }
350 +
351 + if ( is_admin() && is_user_logged_in() && ( ! isset($values['frm_submit_entry_'. $values['form_id']]) || ! wp_verify_nonce($values['frm_submit_entry_'. $values['form_id']], 'frm_submit_entry_nonce') ) ) {
352 + $errors['form'] = __('You do not have permission to do that', 'formidable');
353 + }
354 +
355 + if( !isset($values['item_key']) or $values['item_key'] == '' ){
356 + $_POST['item_key'] = $values['item_key'] = FrmAppHelper::get_unique_key('', $wpdb->prefix .'frm_items', 'item_key');
357 + }
358 +
359 + $where = apply_filters('frm_posted_field_ids', 'fi.form_id='. (int)$values['form_id']);
360 + if($exclude)
361 + $where .= " and fi.type not in ('". implode("','", array_filter($exclude, 'esc_sql')) ."')";
362 +
363 + $posted_fields = $frm_field->getAll($where, 'field_order');
364 +
365 + foreach($posted_fields as $posted_field){
366 + $posted_field->field_options = maybe_unserialize($posted_field->field_options);
367 + $value = '';
368 + if (isset($values['item_meta'][$posted_field->id]))
369 + $value = $values['item_meta'][$posted_field->id];
370 +
371 + if (isset($posted_field->field_options['default_blank']) and $posted_field->field_options['default_blank'] and $value == $posted_field->default_value)
372 + $value = '';
373 +
374 + if(is_array($value) and count($value) === 1)
375 + $value = reset($value);
376 +
377 + if($posted_field->type == 'rte' and !is_array($value) and (trim($value) == '<br>'))
378 + $value = '';
379 +
380 + if ($posted_field->required == '1' and !is_array($value) and trim($value) == ''){
381 + $errors['field'. $posted_field->id] = (!isset($posted_field->field_options['blank']) or $posted_field->field_options['blank'] == '' or $posted_field->field_options['blank'] == 'Untitled cannot be blank') ? $frm_settings->blank_msg : $posted_field->field_options['blank'];
382 + }else if ($posted_field->type == 'text' and !isset($_POST['name'])){
383 + $_POST['name'] = $value;
384 + }
385 +
386 + $_POST['item_meta'][$posted_field->id] = $value;
387 +
388 + if ($posted_field->type == 'captcha' and isset($_POST['recaptcha_challenge_field'])){
389 + global $frm_settings;
548 390
549 - global $wpdb;
550 - $metas = FrmDb::get_results(
551 - $wpdb->prefix . 'frm_item_metas m LEFT JOIN ' . $wpdb->prefix . 'frm_fields f ON m.field_id=f.id',
552 - array(
553 - 'item_id' => $entry->id,
554 - 'field_id !' => 0,
555 - ),
556 - 'field_id, meta_value, field_key, item_id, f.type'
557 - );
391 + if(!function_exists('recaptcha_check_answer'))
392 + require(FrmAppHelper::plugin_path().'/classes/recaptchalib.php');
558 393
559 - $entry->metas = array();
394 + $response = recaptcha_check_answer($frm_settings->privkey,
395 + $_SERVER['REMOTE_ADDR'],
396 + $_POST['recaptcha_challenge_field'],
397 + $_POST['recaptcha_response_field']);
560 398
561 - $include_key = apply_filters( 'frm_include_meta_keys', false, array( 'form_id' => $entry->form_id ) );
399 + if (!$response->is_valid) {
400 + // What happens when the CAPTCHA was entered incorrectly
401 + $errors['captcha-'. $response->error] = $errors['field'. $posted_field->id] = (!isset($posted_field->field_options['invalid']) or $posted_field->field_options['invalid'] == '') ? $frm_settings->re_msg : $posted_field->field_options['invalid'];
402 + }
562 403
563 - foreach ( $metas as $meta_val ) {
564 - FrmFieldsHelper::prepare_field_value( $meta_val->meta_value, $meta_val->type );
404 + }
405 +
406 + $errors = apply_filters('frm_validate_field_entry', $errors, $posted_field, $value);
407 +
408 + }
409 +
410 +
411 + // check for spam
412 + if ( empty($exclude) && isset($values['item_meta']) && !empty($values['item_meta']) && empty($errors) ) {
413 + global $wpcom_api_key;
414 + if ( (function_exists( 'akismet_http_post' ) || is_callable('Akismet::http_post')) && ((get_option('wordpress_api_key') || $wpcom_api_key)) && $this->akismet($values) ) {
415 + $frm_form = new FrmForm();
416 + $form = $frm_form->getOne($values['form_id']);
417 +
418 + if ( isset($form->options['akismet']) && !empty($form->options['akismet']) && ($form->options['akismet'] != 'logged' || !is_user_logged_in()) ) {
419 + $errors['spam'] = __('Your entry appears to be spam!', 'formidable');
420 + }
421 + }
422 +
423 + // check for blacklist keys
424 + if ( $this->blacklist_check($values) ) {
425 + $errors['spam'] = __('Your entry appears to be spam!', 'formidable');
426 + }
427 + }
565 428
566 - if ( (int) $meta_val->item_id === (int) $entry->id ) {
567 - $entry->metas[ $meta_val->field_id ] = $meta_val->meta_value;
429 +
430 + $errors = apply_filters('frm_validate_entry', $errors, $values);
431 + return $errors;
432 + }
433 +
434 + // check the blacklisted words
435 + function blacklist_check( $values ) {
436 + if ( ! apply_filters('frm_check_blacklist', true, $values) ) {
437 + return false;
438 + }
439 +
440 + $mod_keys = trim( get_option( 'blacklist_keys' ) );
568 441
569 - if ( $include_key ) {
570 - $entry->metas[ $meta_val->field_key ] = $entry->metas[ $meta_val->field_id ];
571 - }
572 - continue;
573 - }
574 -
575 - // Include sub entries in an array
576 - if ( ! isset( $entry->metas[ $meta_val->field_id ] ) ) {
577 - $entry->metas[ $meta_val->field_id ] = array();
578 - }
579 -
580 - $entry->metas[ $meta_val->field_id ][] = $meta_val->meta_value;
581 -
582 - unset( $meta_val );
583 - }//end foreach
584 - unset( $metas );
585 -
586 - FrmDb::set_cache( $entry->id, $entry, 'frm_entry' );
587 -
588 - return $entry;
589 - }
590 -
591 - /**
592 - * @param string $id
593 - *
594 - * @return bool
595 - */
596 - public static function exists( $id ) {
597 - if ( FrmDb::check_cache( $id, 'frm_entry' ) ) {
598 - return true;
442 + if ( empty( $mod_keys ) ) {
443 + return false;
444 + }
445 +
446 + $content = FrmEntriesHelper::entry_array_to_string($values);
447 +
448 + if ( empty($content) ) {
449 + return false;
599 450 }
600 451
601 - $where = is_numeric( $id ) ? array( 'id' => $id ) : array( 'item_key' => $id );
602 - $id = FrmDb::get_var( 'frm_items', $where );
452 + $words = explode( "\n", $mod_keys );
603 453
604 - return $id && $id > 0;
605 - }
454 + foreach ( (array) $words as $word ) {
455 + $word = trim( $word );
606 456
607 - /**
608 - * @param array|string $where
609 - * @param string $order_by
610 - * @param string $limit
611 - * @param bool $meta
612 - * @param bool $inc_form
613 - *
614 - * @return array
615 - */
616 - public static function getAll( $where, $order_by = '', $limit = '', $meta = false, $inc_form = true ) {
617 - global $wpdb;
457 + if ( empty($word) ) {
458 + continue;
459 + }
618 460
619 - $limit = FrmDb::esc_limit( $limit );
620 - $cache_key = FrmAppHelper::maybe_json_encode( $where ) . $order_by . $limit . $inc_form;
621 - $entries = wp_cache_get( $cache_key, 'frm_entry' );
461 + if ( preg_match('#' . preg_quote( $word, '#' ) . '#', $content) ) {
462 + return true;
463 + }
464 + }
622 465
623 - if ( false === $entries ) {
624 - $fields = 'it.id, it.item_key, it.name, it.ip, it.form_id, it.post_id, it.user_id, it.parent_item_id, it.updated_by, it.created_at, it.updated_at, it.is_draft, it.description'; // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
625 - $table = $wpdb->prefix . 'frm_items it ';
626 -
627 - if ( $inc_form ) {
628 - $fields = 'it.*, fr.name as form_name,fr.form_key as form_key';
629 - $table .= 'LEFT OUTER JOIN ' . $wpdb->prefix . 'frm_forms fr ON it.form_id=fr.id ';
630 - }
631 -
632 - if ( preg_match( '/ meta_([0-9]+)/', $order_by, $order_matches ) ) {
633 - $fields .= self::sort_by_field( $order_matches[1] );
634 - unset( $order_matches );
635 - }
636 -
637 - // Prepare the query
638 - $query = 'SELECT ' . $fields . ' FROM ' . $table . FrmDb::prepend_and_or_where( ' WHERE ', $where ) . $order_by . $limit;
639 -
640 - $entries = $wpdb->get_results( $query, OBJECT_K ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
641 - unset( $query );
642 -
643 - FrmDb::set_cache( $cache_key, $entries, 'frm_entry' );
644 - }//end if
645 -
646 - if ( ! $meta || ! $entries ) {
647 - self::prepare_entries( $entries );
648 - return $entries;
466 + return false;
467 + }
468 +
469 + //Check entries for spam -- returns true if is spam
470 + function akismet($values) {
471 + $content = FrmEntriesHelper::entry_array_to_string($values);
472 +
473 + if ( empty($content) ) {
474 + return false;
649 475 }
650 - unset( $meta );
476 +
477 + $datas = array();
478 + $datas['blog'] = FrmAppHelper::site_url();
479 + $datas['user_ip'] = preg_replace( '/[^0-9., ]/', '', $_SERVER['REMOTE_ADDR'] );
480 + $datas['user_agent'] = $_SERVER['HTTP_USER_AGENT'];
481 + $datas['referrer'] = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : false;
482 + $datas['comment_type'] = 'formidable';
483 + if ( $permalink = get_permalink() )
484 + $datas['permalink'] = $permalink;
651 485
652 - if ( ! is_array( $where ) && preg_match( '/^it\.form_id=\d+$/', $where ) ) {
653 - $where = array( 'it.form_id' => substr( $where, 11 ) );
654 - }
486 + $datas['comment_content'] = $content;
655 487
656 - $meta_where = array( 'field_id !' => 0 );
657 -
658 - // phpcs:ignore Universal.Operators.StrictComparisons
659 - if ( $limit == '' && is_array( $where ) && count( $where ) === 1 && isset( $where['it.form_id'] ) ) {
660 - $meta_where['fi.form_id'] = $where['it.form_id'];
661 - } else {
662 - $meta_where['item_id'] = array_keys( $entries );
663 - }
664 -
665 - $metas = FrmDb::get_results(
666 - $wpdb->prefix . 'frm_item_metas it LEFT OUTER JOIN ' . $wpdb->prefix . 'frm_fields fi ON it.field_id = fi.id',
667 - $meta_where,
668 - 'item_id, meta_value, field_id, field_key, form_id, fi.type'
669 - );
670 -
671 - unset( $meta_where );
672 -
673 - if ( ! $metas ) {
674 - self::prepare_entries( $entries );
675 - return $entries;
676 - }
677 -
678 - foreach ( $metas as $m_key => $meta_val ) {
679 - if ( ! isset( $entries[ $meta_val->item_id ] ) ) {
680 - continue;
488 + foreach ( $_SERVER as $key => $value ) {
489 + if ( !in_array($key, array('HTTP_COOKIE', 'HTTP_COOKIE2', 'PHP_AUTH_PW')) && is_string($value) ) {
490 + $datas["$key"] = $value;
491 + } else {
492 + $datas["$key"] = '';
681 493 }
682 -
683 - if ( ! isset( $entries[ $meta_val->item_id ]->metas ) ) {
684 - $entries[ $meta_val->item_id ]->metas = array();
685 - }
686 -
687 - FrmFieldsHelper::prepare_field_value( $meta_val->meta_value, $meta_val->type );
688 - $entries[ $meta_val->item_id ]->metas[ $meta_val->field_id ] = $meta_val->meta_value;
689 - unset( $m_key, $meta_val );
494 +
495 + unset($key, $value);
690 496 }
691 497
692 - if ( ! FrmAppHelper::prevent_caching() ) {
693 - foreach ( $entries as $entry ) {
694 - FrmDb::set_cache( $entry->id, $entry, 'frm_entry' );
695 - unset( $entry );
696 - }
498 + $query_string = '';
499 + foreach ( $datas as $key => $data ) {
500 + $query_string .= $key . '=' . urlencode( stripslashes( $data ) ) . '&';
501 + unset($key, $data);
697 502 }
698 503
699 - self::prepare_entries( $entries );
700 - return $entries;
701 - }
702 -
703 - /**
704 - * @param int|string $field_id
705 - *
706 - * @return string
707 - */
708 - private static function sort_by_field( $field_id ) {
709 - global $wpdb;
710 - $field_id = (int) $field_id;
711 - $field_options = FrmDb::get_var( 'frm_fields', array( 'id' => $field_id ), 'field_options' );
712 - FrmAppHelper::unserialize_or_decode( $field_options );
713 -
714 - if ( empty( $field_options['post_field'] ) ) {
715 - $sort = ', (SELECT meta_value FROM ' . $wpdb->prefix . 'frm_item_metas WHERE field_id = ' . $field_id . ' AND item_id = it.id) as meta_' . $field_id;
716 - } else {
717 - $sort = '';
718 - }
719 -
720 - return apply_filters( 'frm_handle_field_column_sort', $sort, $field_id, $field_options );
721 - }
722 -
723 - // Pagination Methods
724 - /**
725 - * @param array|int|string $where If int, use the form id.
726 - *
727 - * @return int|string
728 - */
729 - public static function getRecordCount( $where = '' ) {
730 - global $wpdb;
731 - $table_join = $wpdb->prefix . 'frm_items it JOIN ' . $wpdb->prefix . 'frm_forms fr ON it.form_id=fr.id';
732 -
733 - if ( is_numeric( $where ) ) {
734 - $table_join = 'frm_items';
735 - $where = array( 'form_id' => $where );
736 - }
737 -
738 - if ( is_array( $where ) ) {
739 - return FrmDb::get_count( $table_join, $where );
740 - }
741 -
742 - $cache_key = 'count_' . FrmAppHelper::maybe_json_encode( $where );
743 - $query = 'SELECT COUNT(*) FROM ' . $table_join . FrmDb::prepend_and_or_where( ' WHERE ', $where );
744 -
745 - return FrmDb::check_cache( $cache_key, 'frm_entry', $query, 'get_var' );
746 - }
747 -
748 - /**
749 - * @param int|string $p_size
750 - * @param array|int|string $where
751 - *
752 - * @return int
753 - */
754 - public static function getPageCount( $p_size, $where = '' ) {
755 - $p_size = (int) $p_size;
756 -
757 - if ( $p_size ) {
758 - if ( ! is_numeric( $where ) ) {
759 - $where = self::getRecordCount( $where );
760 - }
761 -
762 - return ceil( (int) $where / $p_size );
763 - }
764 -
765 - return 1;
766 - }
767 -
768 - /**
769 - * Prepare the data before inserting it into the database
770 - *
771 - * @since 2.0.16
772 - *
773 - * @param array $values
774 - * @param string $type
775 - *
776 - * @return array New values.
777 - */
778 - private static function before_insert_entry_in_database( &$values, $type ) {
779 - self::sanitize_entry_post( $values );
780 -
781 - if ( $type !== 'xml' ) {
782 - $values = apply_filters( 'frm_pre_create_entry', $values );
783 - }
784 -
785 - return self::package_entry_data( $values, $type );
786 - }
787 -
788 - /**
789 - * Create an entry and perform after create actions
790 - *
791 - * @since 2.0.16
792 - *
793 - * @param array $values
794 - * @param array $new_values
795 - *
796 - * @return bool|int Entry ID.
797 - */
798 - private static function continue_to_create_entry( $values, $new_values ) {
799 - $entry_id = self::insert_entry_into_database( $new_values );
800 -
801 - if ( ! $entry_id ) {
802 - return false;
803 - }
804 -
805 - self::after_insert_entry_in_database( $values, $new_values, $entry_id );
806 -
807 - return $entry_id;
808 - }
809 -
810 - /**
811 - * Sanitize the POST values before we use them
812 - *
813 - * @since 2.0
814 - *
815 - * @param array $values The POST values by reference.
816 - *
817 - * @return void
818 - */
819 - public static function sanitize_entry_post( &$values ) {
820 - $sanitize_method = array(
821 - 'form_id' => 'absint',
822 - 'frm_action' => 'sanitize_title',
823 - 'form_key' => 'sanitize_title',
824 - 'item_key' => 'sanitize_title',
825 - 'item_name' => 'sanitize_text_field',
826 - 'frm_saving_draft' => 'absint',
827 - 'is_draft' => 'absint',
828 - 'post_id' => 'absint',
829 - 'parent_item_id' => 'absint',
830 - 'created_at' => 'sanitize_text_field',
831 - 'updated_at' => 'sanitize_text_field',
832 - );
833 -
834 - FrmAppHelper::sanitize_request( $sanitize_method, $values );
835 - }
836 -
837 - /**
838 - * Prepare the new values for inserting into the database
839 - *
840 - * @since 2.0.16
841 - *
842 - * @param array $values
843 - * @param string $type The create type. 'xml' for an import.
844 - *
845 - * @return array New values.
846 - */
847 - private static function package_entry_data( &$values, $type = 'standard' ) {
848 - global $wpdb;
849 -
850 - if ( ! isset( $values['item_key'] ) ) {
851 - $values['item_key'] = '';
852 - }
853 -
854 - $item_name = self::get_new_entry_name( $values, $values['item_key'] );
855 - $new_values = array(
856 - 'item_key' => FrmAppHelper::get_unique_key( $values['item_key'], $wpdb->prefix . 'frm_items', 'item_key' ),
857 - 'name' => FrmAppHelper::truncate( $item_name, 255, 1, '', true ),
858 - 'ip' => self::get_ip( $values ),
859 - 'is_draft' => self::get_is_draft_value( $values ),
860 - 'form_id' => (int) self::get_entry_value( $values, 'form_id', null ),
861 - 'post_id' => (int) self::get_entry_value( $values, 'post_id', 0 ),
862 - 'parent_item_id' => (int) self::get_entry_value( $values, 'parent_item_id', 0 ),
863 - 'created_at' => self::get_created_at( $values ),
864 - 'updated_at' => self::get_updated_at( $values ),
865 - 'description' => self::get_entry_description( $values ),
866 - 'user_id' => self::get_entry_user_id( $values, $type ),
867 - );
868 -
869 - $new_values['updated_by'] = self::get_updated_by( $values, $type, $new_values['user_id'] );
870 -
871 - return $new_values;
872 - }
873 -
874 - /**
875 - * @param array $values
876 - * @param string $name
877 - * @param mixed $default
878 - *
879 - * @return mixed
880 - */
881 - private static function get_entry_value( $values, $name, $default ) {
882 - return $values[ $name ] ?? $default;
883 - }
884 -
885 - /**
886 - * Get the updated_by value for an entry.
887 - *
888 - * The submitted value is only used during a trusted import, which restores the user who last
889 - * edited each entry. Every other save is being made by the current user, so a submitted
890 - * updated_by is ignored and cannot be pointed at another account. This matters because
891 - * updated_by is treated as a privilege signal when deciding how much HTML to strip from entry
892 - * values in FrmFieldType::should_strip_most_html().
893 - *
894 - * @since 6.35
895 - *
896 - * @param array $values
897 - * @param string $type The create/update type. 'xml' for an import.
898 - * @param int|string $default The value to use when an import doesn't include updated_by.
899 - *
900 - * @return int
901 - */
902 - private static function get_updated_by( $values, $type, $default ) {
903 - if ( self::is_trusted_import( $type ) ) {
904 - return absint( self::get_entry_value( $values, 'updated_by', $default ) );
905 - }
906 -
907 - return get_current_user_id();
908 - }
909 -
910 - /**
911 - * Get the ip for a new entry.
912 - * Allow the import to override the value.
913 - *
914 - * @since 2.03.10
915 - *
916 - * @param array $values
917 - *
918 - * @return string
919 - */
920 - private static function get_ip( $values ) {
921 - if ( ! FrmAppHelper::ips_saved() ) {
922 - return '';
923 - }
924 -
925 - $ip = FrmAppHelper::get_ip_address();
926 -
927 - if ( defined( 'WP_IMPORTING' ) && WP_IMPORTING ) {
928 - return self::get_entry_value( $values, 'ip', $ip );
929 - }
930 -
931 - return $ip;
932 - }
933 -
934 - /**
935 - * Get the is_draft value for a new entry
936 - *
937 - * @since 2.0.16
938 - *
939 - * @param array $values
940 - *
941 - * @return int
942 - */
943 - private static function get_is_draft_value( $values ) {
944 - if ( isset( $values['frm_saving_draft'] ) && FrmEntriesHelper::DRAFT_ENTRY_STATUS === (int) $values['frm_saving_draft'] ) {
945 - return FrmEntriesHelper::DRAFT_ENTRY_STATUS;
946 - }
947 -
948 - return isset( $values['is_draft'] ) ? absint( $values['is_draft'] ) : FrmEntriesHelper::SUBMITTED_ENTRY_STATUS;
949 - }
950 -
951 - /**
952 - * Get the created_at value for a new entry
953 - *
954 - * @since 2.0.16
955 - *
956 - * @param array $values
957 - *
958 - * @return string
959 - */
960 - private static function get_created_at( $values ) {
961 - return self::get_entry_value( $values, 'created_at', current_time( 'mysql', 1 ) );
962 - }
963 -
964 - /**
965 - * Get the updated_at value for a new entry
966 - *
967 - * @since 2.0.16
968 - *
969 - * @param array $values
970 - *
971 - * @return string
972 - */
973 - private static function get_updated_at( $values ) {
974 - return $values['updated_at'] ?? self::get_created_at( $values );
975 - }
976 -
977 - /**
978 - * Get the description value for a new entry
979 - *
980 - * @since 2.0.16
981 - *
982 - * @param array $values
983 - *
984 - * @return string
985 - */
986 - private static function get_entry_description( $values ) {
987 - if ( ! empty( $values['description'] ) ) {
988 - return FrmAppHelper::maybe_json_encode( $values['description'] );
989 - }
990 -
991 - return json_encode(
992 - array(
993 - 'browser' => FrmAppHelper::get_server_value( 'HTTP_USER_AGENT' ),
994 - 'referrer' => FrmAppHelper::get_server_value( 'HTTP_REFERER' ),
995 - )
996 - );
997 - }
998 -
999 - /**
1000 - * Get the user_id value for a new entry
1001 - *
1002 - * @since 2.0.16
1003 - *
1004 - * @param array $values
1005 - * @param string $type The create type. 'xml' for an import.
1006 - *
1007 - * @return int
1008 - */
1009 - private static function get_entry_user_id( $values, $type = 'standard' ) {
1010 - if ( isset( $values['frm_user_id'] ) && self::can_set_entry_user_id_from_values( $type ) ) {
1011 - return $values['frm_user_id'];
1012 - }
1013 -
1014 - $current_user_id = get_current_user_id();
1015 - return $current_user_id ? $current_user_id : 0;
1016 - }
1017 -
1018 - /**
1019 - * Whether a submitted frm_user_id is allowed to set the entry owner.
1020 - *
1021 - * The owner is only taken from the submitted value when the current user is allowed to manage
1022 - * entries, or during a trusted import that restores each entry's original owner. On a public
1023 - * submission neither is true, so the owner falls back to the current user and cannot be set to
1024 - * another account.
1025 - *
1026 - * @since 6.34
1027 - *
1028 - * @param string $type The create/update type. 'xml' for an import.
1029 - *
1030 - * @return bool
1031 - */
1032 - private static function can_set_entry_user_id_from_values( $type = 'standard' ) {
1033 - if ( self::is_trusted_import( $type ) ) {
1034 - return true;
1035 - }
1036 -
1037 - return current_user_can( 'frm_edit_entries' ) || current_user_can( 'administrator' );
1038 - }
1039 -
1040 - /**
1041 - * Whether an entry is being saved by an import rather than by a normal request.
1042 - *
1043 - * An import is trusted to restore the values stored on each entry, including the columns that
1044 - * are otherwise taken from the current request.
1045 - *
1046 - * @since 6.35
1047 - *
1048 - * @param string $type The create/update type. 'xml' for an import.
1049 - *
1050 - * @return bool
1051 - */
1052 - private static function is_trusted_import( $type = 'standard' ) {
1053 - return 'xml' === $type || ( defined( 'WP_IMPORTING' ) && WP_IMPORTING );
1054 - }
1055 -
1056 - /**
1057 - * Insert new entry into the database
1058 - *
1059 - * @since 2.0.16
1060 - *
1061 - * @param array $new_values
1062 - *
1063 - * @return bool|int Entry ID.
1064 - */
1065 - private static function insert_entry_into_database( $new_values ) {
1066 - global $wpdb;
1067 -
1068 - $query_results = $wpdb->insert( $wpdb->prefix . 'frm_items', $new_values );
1069 -
1070 - return $query_results ? $wpdb->insert_id : false;
1071 - }
1072 -
1073 - /**
1074 - * Add the new entry to global $frm_vars
1075 - *
1076 - * @since 2.0.16
1077 - *
1078 - * @param int|string $entry_id
1079 - *
1080 - * @return void
1081 - */
1082 - private static function add_new_entry_to_frm_vars( $entry_id ) {
1083 - global $frm_vars;
1084 -
1085 - if ( ! isset( $frm_vars['saved_entries'] ) ) {
1086 - $frm_vars['saved_entries'] = array();
1087 - }
1088 -
1089 - $frm_vars['saved_entries'][] = (int) $entry_id;
1090 - }
1091 -
1092 - /**
1093 - * Add entry metas, if there are any
1094 - *
1095 - * @since 2.0.16
1096 - *
1097 - * @param array $values
1098 - * @param int|string $entry_id
1099 - *
1100 - * @return void
1101 - */
1102 - private static function maybe_add_entry_metas( $values, $entry_id ) {
1103 - if ( isset( $values['item_meta'] ) ) {
1104 - FrmEntryMeta::update_entry_metas( $entry_id, $values['item_meta'] );
1105 - self::maybe_add_unique_id_meta( $values, $entry_id );
1106 - }
1107 - self::maybe_add_captcha_meta( (int) $values['form_id'], (int) $entry_id );
1108 - }
1109 -
1110 - /**
1111 - * @since 6.16.3
1112 - *
1113 - * @param array $values
1114 - * @param int $entry_id
1115 - *
1116 - * @return void
1117 - */
1118 - private static function maybe_add_unique_id_meta( $values, $entry_id ) {
1119 - if ( ! empty( $values['parent_form_id'] ) || empty( $values['unique_id'] ) || ! self::should_check_for_unique_id_match() ) {
1120 - return;
1121 - }
1122 -
1123 - // This unique ID is inserted with JS on form submit.
1124 - // It is used to check for duplicate entries.
1125 - $unique_id = sanitize_key( $values['unique_id'] );
1126 -
1127 - if ( ! $unique_id ) {
1128 - return;
1129 - }
1130 -
1131 - FrmEntryMeta::add_entry_meta( $entry_id, 0, '', compact( 'unique_id' ) );
1132 - self::flag_new_unique_key( $unique_id );
1133 - }
1134 -
1135 - /**
1136 - * @since 5.0.15
1137 - *
1138 - * @param int $form_id
1139 - * @param int $entry_id
1140 - *
1141 - * @return void
1142 - */
1143 - private static function maybe_add_captcha_meta( $form_id, $entry_id ) {
1144 - global $frm_vars;
1145 -
1146 - if ( ! array_key_exists( 'captcha_scores', $frm_vars ) || ! array_key_exists( $form_id, $frm_vars['captcha_scores'] ) ) {
1147 - return;
1148 - }
1149 -
1150 - $captcha_score_meta = array( 'captcha_score' => $frm_vars['captcha_scores'][ $form_id ] );
1151 - FrmEntryMeta::add_entry_meta( $entry_id, 0, '', maybe_serialize( $captcha_score_meta ) );
1152 - }
1153 -
1154 - /**
1155 - * Trigger frm_after_create_entry hooks
1156 - *
1157 - * @since 2.0.16
1158 - *
1159 - * @param int $entry_id
1160 - * @param array $values
1161 - * @param array $new_values
1162 - *
1163 - * @return void
1164 - */
1165 - private static function after_entry_created_actions( $entry_id, $values, $new_values ) {
1166 - // This is a child entry.
1167 - $is_child = isset( $values['parent_nonce'] ) && ! empty( $values['parent_form_id'] ) && wp_verify_nonce( $values['parent_nonce'], 'parent' );
1168 -
1169 - do_action( 'frm_after_create_entry', $entry_id, $new_values['form_id'], compact( 'is_child' ) );
1170 - do_action( 'frm_after_create_entry_' . $new_values['form_id'], $entry_id, compact( 'is_child' ) );
1171 -
1172 - if ( ! empty( $values['form_key'] ) ) {
1173 - /**
1174 - * @since 6.30
1175 - *
1176 - * @param int $entry_id
1177 - * @param array $is_child
1178 - */
1179 - do_action( 'frm_after_create_entry_' . $values['form_key'], $entry_id, compact( 'is_child' ) );
1180 - }
1181 - }
1182 -
1183 - /**
1184 - * Actions to perform immediately after an entry is inserted in the frm_items database
1185 - *
1186 - * @since 2.0.16
1187 - *
1188 - * @param array $values
1189 - * @param array $new_values
1190 - * @param int $entry_id
1191 - *
1192 - * @return void
1193 - */
1194 - private static function after_insert_entry_in_database( $values, $new_values, $entry_id ) {
1195 - self::add_new_entry_to_frm_vars( $entry_id );
1196 -
1197 - self::maybe_add_entry_metas( $values, $entry_id );
1198 -
1199 - self::clear_cache();
1200 -
1201 - self::after_entry_created_actions( $entry_id, $values, $new_values );
1202 - }
1203 -
1204 - /**
1205 - * Perform some actions right before updating an entry
1206 - *
1207 - * @since 2.0.16
1208 - *
1209 - * @param int|string $id
1210 - * @param array $values
1211 - * @param string $update_type
1212 - *
1213 - * @return bool Update.
1214 - */
1215 - private static function before_update_entry( $id, &$values, $update_type ) {
1216 - $update = true;
1217 -
1218 - global $frm_vars;
1219 -
1220 - // phpcs:ignore WordPress.PHP.StrictInArray.MissingTrueStrict
1221 - if ( isset( $frm_vars['saved_entries'] ) && is_array( $frm_vars['saved_entries'] ) && in_array( (int) $id, $frm_vars['saved_entries'] ) ) {
1222 - $update = false;
1223 - }
1224 -
1225 - if ( $update && $update_type !== 'xml' ) {
1226 - $values = apply_filters( 'frm_pre_update_entry', $values, $id );
1227 - }
1228 -
1229 - return $update;
1230 - }
1231 -
1232 - /**
1233 - * Package the entry data for updating
1234 - *
1235 - * @since 2.0.16
1236 - *
1237 - * @param int $id
1238 - * @param array $values
1239 - * @param string $update_type The update type. 'xml' for an import.
1240 - *
1241 - * @return array New values.
1242 - */
1243 - private static function package_entry_to_update( $id, $values, $update_type = 'standard' ) {
1244 - global $wpdb;
1245 -
1246 - $new_values = array(
1247 - 'name' => FrmAppHelper::truncate( self::get_new_entry_name( $values ), 255, 1, '', true ),
1248 - 'form_id' => (int) self::get_entry_value( $values, 'form_id', null ),
1249 - 'is_draft' => self::get_is_draft_value( $values ),
1250 - 'updated_at' => current_time( 'mysql', 1 ),
1251 - 'updated_by' => self::get_updated_by( $values, $update_type, get_current_user_id() ),
1252 - );
1253 -
1254 - if ( isset( $values['post_id'] ) ) {
1255 - $new_values['post_id'] = (int) $values['post_id'];
1256 - }
1257 -
1258 - if ( isset( $values['item_key'] ) ) {
1259 - $new_values['item_key'] = FrmAppHelper::get_unique_key( $values['item_key'], $wpdb->prefix . 'frm_items', 'item_key', $id );
1260 - }
1261 -
1262 - if ( isset( $values['parent_item_id'] ) ) {
1263 - $new_values['parent_item_id'] = (int) $values['parent_item_id'];
1264 - }
1265 -
1266 - if ( isset( $values['frm_user_id'] ) && is_numeric( $values['frm_user_id'] ) && self::can_set_entry_user_id_from_values( $update_type ) ) {
1267 - $new_values['user_id'] = $values['frm_user_id'];
1268 - }
1269 -
1270 - return apply_filters( 'frm_update_entry', $new_values, $id );
1271 - }
1272 -
1273 - /**
1274 - * Perform some actions right after updating an entry
1275 - *
1276 - * @since 2.0.16
1277 - *
1278 - * @param bool|int $query_results
1279 - * @param int|string $id
1280 - * @param array $values
1281 - * @param array $new_values
1282 - *
1283 - * @return void
1284 - */
1285 - private static function after_update_entry( $query_results, $id, $values, $new_values ) {
1286 - if ( $query_results ) {
1287 - self::clear_cache();
1288 - }
1289 -
1290 - global $frm_vars;
1291 -
1292 - if ( ! isset( $frm_vars['saved_entries'] ) ) {
1293 - $frm_vars['saved_entries'] = array();
1294 - }
1295 -
1296 - $frm_vars['saved_entries'][] = (int) $id;
1297 -
1298 - if ( isset( $values['item_meta'] ) ) {
1299 - FrmEntryMeta::update_entry_metas( $id, $values['item_meta'] );
1300 - }
1301 -
1302 - do_action( 'frm_after_update_entry', $id, $new_values['form_id'] );
1303 - do_action( 'frm_after_update_entry_' . $new_values['form_id'], $id );
1304 -
1305 - if ( ! empty( $values['form_key'] ) ) {
1306 - /**
1307 - * @since 6.30
1308 - *
1309 - * @param int $entry_id
1310 - */
1311 - do_action( 'frm_after_update_entry_' . $values['form_key'], $id );
1312 - }
1313 - }
1314 -
1315 - /**
1316 - * Create entry from an XML import
1317 - * Certain actions aren't necessary when importing (like saving sub entries, checking for duplicates, etc.)
1318 - *
1319 - * @since 2.0.16
1320 - *
1321 - * @param array $values
1322 - *
1323 - * @return bool|int Entry ID.
1324 - */
1325 - public static function create_entry_from_xml( $values ) {
1326 - return self::create_entry( $values, 'xml' );
1327 - }
1328 -
1329 - /**
1330 - * Update entry from an XML import
1331 - * Certain actions aren't necessary when importing (like saving sub entries and modifying other vals)
1332 - *
1333 - * @since 2.0.16
1334 - *
1335 - * @param int $id
1336 - * @param array $values
1337 - *
1338 - * @return bool|int Updated.
1339 - */
1340 - public static function update_entry_from_xml( $id, $values ) {
1341 - return self::update_entry( $id, $values, 'xml' );
1342 - }
1343 -
1344 - /**
1345 - * @param string $key
1346 - *
1347 - * @return int entry_id
1348 - */
1349 - public static function get_id_by_key( $key ) {
1350 - $entry_id = FrmDb::get_var( 'frm_items', array( 'item_key' => sanitize_title( $key ) ) );
1351 - return (int) $entry_id;
1352 - }
1353 -
1354 - /**
1355 - * Get entries count.
1356 - *
1357 - * @since 6.8
1358 - *
1359 - * @return int|string
1360 - */
1361 - public static function get_entries_count() {
1362 - $args = array(
1363 - 'or' => 1,
1364 - 'parent_form_id' => null,
1365 - 'parent_form_id <' => 1,
1366 - );
1367 - return self::getRecordCount( $args );
1368 - }
504 + if ( is_callable('Akismet::http_post') ) {
505 + $response = Akismet::http_post($query_string, 'comment-check');
506 + } else {
507 + global $akismet_api_host, $akismet_api_port;
508 + $response = akismet_http_post( $query_string, $akismet_api_host, '/1.1/comment-check', $akismet_api_port );
509 + }
510 +
511 + return ( is_array($response) and $response[1] == 'true' ) ? true : false;
512 + }
513 +
1369 514 }