PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.0.07
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.0.07
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmForm.php +29 -198 6.55.0.07 View file →
@@ -5,16 +5,13 @@
5 5
6 6 class FrmForm {
7 7
8 8 /**
9 - * @param array $values
10 - * @return int|bool id on success or false on failure.
9 + * @return int|boolean id on success or false on failure
11 10 */
12 11 public static function create( $values ) {
13 12 global $wpdb;
14 13
15 - $values = FrmAppHelper::maybe_filter_array( $values, array( 'name', 'description' ) );
16 -
17 14 $new_values = array(
18 15 'form_key' => FrmAppHelper::get_unique_key( $values['form_key'], $wpdb->prefix . 'frm_forms', 'form_key' ),
19 16 'name' => $values['name'],
20 17 'description' => $values['description'],
@@ -32,21 +29,14 @@
32 29 $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
33 30 $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
34 31 $options['submit_html'] = isset( $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
35 32
36 - /**
37 - * Allows modifying form options before updating or creating.
38 - *
39 - * @since 5.4 Add the third param.
40 - *
41 - * @param array $options Form options.
42 - * @param array $values Form data.
43 - * @param bool $update Is form updating or creating. It's `true` if is updating.
44 - */
45 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, false );
46 - $options = self::maybe_filter_form_options( $options );
33 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
47 34 $new_values['options'] = serialize( $options );
48 35
36 + //if(isset($values['id']) && is_numeric($values['id']))
37 + // $new_values['id'] = $values['id'];
38 +
49 39 $wpdb->insert( $wpdb->prefix . 'frm_forms', $new_values );
50 40
51 41 $id = $wpdb->insert_id;
52 42
@@ -56,21 +46,8 @@
56 46 return $id;
57 47 }
58 48
59 49 /**
60 - * @since 5.0.08
61 - *
62 - * @param array $options
63 - * @return array
64 - */
65 - private static function maybe_filter_form_options( $options ) {
66 - if ( ! FrmAppHelper::allow_unfiltered_html() && ! empty( $options['submit_html'] ) ) {
67 - $options['submit_html'] = FrmAppHelper::kses_submit_button( $options['submit_html'] );
68 - }
69 - return FrmAppHelper::maybe_filter_array( $options, array( 'submit_value', 'success_msg', 'before_html', 'after_html' ) );
70 - }
71 -
72 - /**
73 50 * @return int|boolean ID on success or false on failure
74 51 */
75 52 public static function duplicate( $id, $template = false, $copy_keys = false, $blog_id = false ) {
76 53 global $wpdb;
@@ -140,86 +117,11 @@
140 117 if ( $new_opts != $values['options'] ) {
141 118 global $wpdb;
142 119 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'options' => maybe_serialize( $new_opts ) ), array( 'id' => $form_id ) );
143 120 }
144 -
145 - self::switch_field_ids_in_fields( $form_id );
146 121 }
147 122
148 123 /**
149 - * Switches field ID in fields.
150 - *
151 - * @since 5.3
152 - *
153 - * @param int $form_id Form ID.
154 - */
155 - private static function switch_field_ids_in_fields( $form_id ) {
156 - global $wpdb;
157 -
158 - // Keys of fields that you want to check to replace field ID.
159 - $keys = array( 'default_value', 'field_options' );
160 - $sql_cols = 'fi.id';
161 - foreach ( $keys as $key ) {
162 - $sql_cols .= ( ',fi.' . $key );
163 - }
164 -
165 - $fields = FrmDb::get_results(
166 - "{$wpdb->prefix}frm_fields AS fi LEFT OUTER JOIN {$wpdb->prefix}frm_forms AS fr ON fi.form_id = fr.id",
167 - array(
168 - 'or' => 1,
169 - 'fi.form_id' => $form_id,
170 - 'fr.parent_form_id' => $form_id,
171 - ),
172 - $sql_cols
173 - );
174 -
175 - if ( ! $fields || ! is_array( $fields ) ) {
176 - return;
177 - }
178 -
179 - foreach ( $fields as $field ) {
180 - self::switch_field_ids_in_field( (array) $field );
181 - }
182 - }
183 -
184 - /**
185 - * Switches field ID in a field.
186 - *
187 - * @since 5.3
188 - *
189 - * @param array $field Field array.
190 - */
191 - private static function switch_field_ids_in_field( $field ) {
192 - $new_values = array();
193 - foreach ( $field as $key => $value ) {
194 - if ( 'id' === $key || ! $value ) {
195 - continue;
196 - }
197 -
198 - if ( ! is_string( $value ) && ! is_array( $value ) ) {
199 - continue;
200 - }
201 -
202 - if ( 'field_options' === $key ) {
203 - // Need to loop through field_options to prevent breaking serialized string when length changed.
204 - FrmAppHelper::unserialize_or_decode( $value );
205 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
206 - $new_val = serialize( $new_val );
207 - } else {
208 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
209 - }
210 -
211 - if ( $new_val !== $value ) {
212 - $new_values[ $key ] = $new_val;
213 - }
214 - }
215 -
216 - if ( ! empty( $new_values ) ) {
217 - FrmField::update( $field['id'], $new_values );
218 - }
219 - }
220 -
221 - /**
222 124 * @return int|boolean
223 125 */
224 126 public static function update( $id, $values, $create_link = false ) {
225 127 global $wpdb;
@@ -235,9 +137,9 @@
235 137 }
236 138
237 139 $form_fields = array( 'form_key', 'name', 'description', 'status', 'parent_form_id' );
238 140
239 - $new_values = self::set_update_options( array(), $values, array( 'form_id' => $id ) );
141 + $new_values = self::set_update_options( array(), $values );
240 142
241 143 foreach ( $values as $value_key => $value ) {
242 144 if ( $value_key && in_array( $value_key, $form_fields ) ) {
243 145 $new_values[ $value_key ] = $value;
@@ -266,14 +168,11 @@
266 168 return $query_results;
267 169 }
268 170
269 171 /**
270 - * @param array $new_values
271 - * @param array $values
272 - * @param array $args
273 172 * @return array
274 173 */
275 - public static function set_update_options( $new_values, $values, $args = array() ) {
174 + public static function set_update_options( $new_values, $values ) {
276 175 if ( ! isset( $values['options'] ) ) {
277 176 return $new_values;
278 177 }
279 178
@@ -284,19 +183,10 @@
284 183 $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
285 184 $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
286 185 $options['submit_html'] = ( isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
287 186
288 - /**
289 - * Allows modifying form options before updating or creating.
290 - *
291 - * @since 5.4 Added the third param.
292 - *
293 - * @param array $options Form options.
294 - * @param array $values Form data.
295 - * @param bool $update Is form updating or creating. It's `true` if is updating.
296 - */
297 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, true );
298 - $options = self::maybe_filter_form_options( $options );
187 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
188 + $options = FrmAppHelper::maybe_filter_array( $options, array( 'submit_value', 'success_msg', 'before_html', 'after_html', 'submit_html' ) );
299 189 $new_values['options'] = serialize( $options );
300 190
301 191 return $new_values;
302 192 }
@@ -365,18 +255,8 @@
365 255 'field_options' => $field->field_options,
366 256 'default_value' => isset( $values[ 'default_value_' . $field_id ] ) ? FrmAppHelper::maybe_json_encode( $values[ 'default_value_' . $field_id ] ) : '',
367 257 );
368 258
369 - if ( ! FrmAppHelper::allow_unfiltered_html() && isset( $values['field_options'][ 'options_' . $field_id ] ) && is_array( $values['field_options'][ 'options_' . $field_id ] ) ) {
370 - foreach ( $values['field_options'][ 'options_' . $field_id ] as $option_key => $option ) {
371 - if ( is_array( $option ) ) {
372 - foreach ( $option as $key => $item ) {
373 - $values['field_options'][ 'options_' . $field_id ][ $option_key ][ $key ] = FrmAppHelper::kses( $item, 'all' );
374 - }
375 - }
376 - }
377 - }
378 -
379 259 self::prepare_field_update_values( $field, $values, $new_field );
380 260
381 261 FrmField::update( $field_id, $new_field );
382 262
@@ -386,40 +266,17 @@
386 266
387 267 return $values;
388 268 }
389 269
390 - /**
391 - * @param string $opt
392 - * @param mixed $value
393 - * @return void
394 - */
395 270 private static function sanitize_field_opt( $opt, &$value ) {
396 - if ( ! is_string( $value ) ) {
397 - return;
271 + if ( is_string( $value ) ) {
272 + if ( $opt === 'calc' ) {
273 + $value = self::sanitize_calc( $value );
274 + } else {
275 + $value = FrmAppHelper::kses( $value, 'all' );
276 + }
277 + $value = trim( $value );
398 278 }
399 -
400 - /**
401 - * Allow the option to turn off sanitization for a field. This way a custom rule can be used instead.
402 - * Make sure to add custom sanitization using the frm_update_field_options filter as the data will no longer be sanitized.
403 - *
404 - * @since 6.0
405 - *
406 - * @param bool $should_sanitize
407 - * @param string $opt
408 - */
409 - $should_sanitize = apply_filters( 'frm_should_sanitize_field_opt_string', true, $opt );
410 -
411 - if ( ! $should_sanitize ) {
412 - return;
413 - }
414 -
415 - if ( $opt === 'calc' ) {
416 - $value = self::sanitize_calc( $value );
417 - } else {
418 - $value = FrmAppHelper::kses( $value, 'all' );
419 - }
420 -
421 - $value = trim( $value );
422 279 }
423 280
424 281 /**
425 282 * @param string $value
@@ -510,12 +367,8 @@
510 367 'description',
511 368 'submit_value',
512 369 'submit_msg',
513 370 'success_msg',
514 - 'invalid_msg',
515 - 'failed_msg',
516 - 'login_msg',
517 - 'admin_permission',
518 371 );
519 372
520 373 return apply_filters( 'frm_form_strings', $strings, $form );
521 374 }
@@ -545,9 +398,9 @@
545 398 );
546 399 FrmDb::get_where_clause_and_values( $where );
547 400 array_unshift( $where['values'], $status );
548 401
549 - $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
402 + $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // WPCS: unprepared SQL ok.
550 403 } else {
551 404 $query_results = $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'id' => $id ) );
552 405 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'parent_form_id' => $id ) );
553 406 }
@@ -653,9 +506,9 @@
653 506
654 507 $trash_forms = FrmDb::get_results( $wpdb->prefix . 'frm_forms', array( 'status' => 'trash' ), 'id, options' );
655 508
656 509 if ( ! $trash_forms ) {
657 - return 0;
510 + return;
658 511 }
659 512
660 513 if ( empty( $delete_timestamp ) ) {
661 514 $delete_timestamp = time() - ( DAY_IN_SECONDS * EMPTY_TRASH_DAYS );
@@ -687,12 +540,10 @@
687 540 }
688 541
689 542 $query_key = is_numeric( $id ) ? 'id' : 'form_key';
690 543 $r = FrmDb::get_var( 'frm_forms', array( $query_key => $id ), 'name' );
544 + $r = stripslashes( $r );
691 545
692 - // An empty form name can result in a null value.
693 - $r = is_null( $r ) ? '' : stripslashes( $r );
694 -
695 546 return $r;
696 547 }
697 548
698 549 /**
@@ -756,9 +607,9 @@
756 607 if ( isset( $cache->options ) ) {
757 608 FrmAppHelper::unserialize_or_decode( $cache->options );
758 609 }
759 610
760 - return apply_filters( 'frm_form_object', wp_unslash( $cache ) );
611 + return wp_unslash( $cache );
761 612 }
762 613 }
763 614
764 615 if ( is_numeric( $id ) ) {
@@ -792,9 +643,9 @@
792 643 global $wpdb;
793 644
794 645 // the query has already been prepared if this is not an array
795 646 $query = 'SELECT * FROM ' . $wpdb->prefix . 'frm_forms' . FrmDb::prepend_and_or_where( ' WHERE ', $where ) . FrmDb::esc_order( $order_by ) . FrmDb::esc_limit( $limit );
796 - $results = $wpdb->get_results( $query ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
647 + $results = $wpdb->get_results( $query ); // WPCS: unprepared SQL ok.
797 648 }
798 649
799 650 if ( $results ) {
800 651 foreach ( $results as $result ) {
@@ -814,13 +665,9 @@
814 665 /**
815 666 * Get all published forms
816 667 *
817 668 * @since 2.0
818 - *
819 - * @param array $query
820 - * @param int $limit
821 - * @param string $inc_children
822 - * @return array|object of forms A single form object would be passed if $limit was set to 1.
669 + * @return array of forms
823 670 */
824 671 public static function get_published_forms( $query = array(), $limit = 999, $inc_children = 'exclude' ) {
825 672 $query['is_template'] = 0;
826 673 $query['status'] = array( null, '', 'published' );
@@ -915,9 +762,9 @@
915 762 if ( isset( $frm_vars['form_params'] ) && is_array( $frm_vars['form_params'] ) && isset( $frm_vars['form_params'][ $form->id ] ) ) {
916 763 return $frm_vars['form_params'][ $form->id ];
917 764 }
918 765
919 - $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // phpcs:ignore WordPress.Security.NonceVerification.Missing
766 + $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // WPCS: CSRF ok.
920 767 $action = apply_filters( 'frm_show_new_entry_page', FrmAppHelper::get_param( $action_var, 'new', 'get', 'sanitize_title' ), $form );
921 768
922 769 $default_values = array(
923 770 'id' => '',
@@ -955,9 +802,9 @@
955 802 }
956 803 }
957 804
958 805 if ( in_array( $values['action'], array( 'create', 'update' ) ) &&
959 - ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // phpcs:ignore WordPress.Security.NonceVerification.Missing
806 + ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // WPCS: CSRF ok.
960 807 ) {
961 808 $values['action'] = 'new';
962 809 }
963 810
@@ -1120,39 +967,23 @@
1120 967 return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id );
1121 968 }
1122 969
1123 970 /**
1124 - * Check if the "Submit this form with AJAX" setting is toggled on.
1125 - *
1126 - * @since 6.2
1127 - *
1128 - * @param stdClass $form
1129 - * @return bool
1130 - */
1131 - public static function is_ajax_on( $form ) {
1132 - return ! empty( $form->options['ajax_submit'] );
1133 - }
1134 -
1135 - /**
1136 - * @deprecated 2.03.05 This is still referenced in a few add ons (API, locations).
971 + * @deprecated 3.0
1137 972 * @codeCoverageIgnore
1138 973 *
1139 974 * @param string $key
975 + *
1140 976 * @return int form id
1141 977 */
1142 978 public static function getIdByKey( $key ) {
1143 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_id_by_key' );
1144 - return self::get_id_by_key( $key );
979 + return FrmFormDeprecated::getIdByKey( $key );
1145 980 }
1146 981
1147 982 /**
1148 - * @deprecated 2.03.05 This is still referenced in the API add on as of v1.13.
983 + * @deprecated 3.0
1149 984 * @codeCoverageIgnore
1150 - *
1151 - * @param string|int $id
1152 - * @return string
1153 985 */
1154 986 public static function getKeyById( $id ) {
1155 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_key_by_id' );
1156 - return self::get_key_by_id( $id );
987 + return FrmFormDeprecated::getKeyById( $id );
1157 988 }
1158 989 }