| @@ -5,12 +5,12 @@ | ||
| 5 | 5 | |
| 6 | 6 | if ( isset( $message ) && '' !== $message ) { |
| 7 | 7 | if ( FrmAppHelper::is_admin() ) { |
| 8 | 8 | echo '<div class="frm_updated_message">'; |
| 9 | - FrmAppHelper::kses_echo( $message, 'all' ); | |
| 9 | + echo FrmAppHelper::kses( $message, 'all' ); // WPCS: XSS ok. | |
| 10 | 10 | echo '</div>'; |
| 11 | 11 | } else { |
| 12 | - echo FrmAppHelper::maybe_kses( $message ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 12 | + echo $message; // WPCS: XSS ok. | |
| 13 | 13 | } |
| 14 | 14 | } |
| 15 | 15 | |
| 16 | 16 | if ( ! isset( $show_messages ) ) { |
| @@ -15,36 +15,24 @@ | ||
| 15 | 15 | |
| 16 | 16 | if ( ! isset( $show_messages ) ) { |
| 17 | 17 | $show_messages = array(); |
| 18 | 18 | } |
| 19 | - | |
| 20 | 19 | $show_messages = apply_filters( 'frm_message_list', $show_messages ); |
| 21 | - | |
| 22 | 20 | if ( is_array( $show_messages ) && count( $show_messages ) > 0 ) { |
| 23 | - // Define a callback function to add 'data-action' attribute to allowed HTML tags | |
| 24 | - $add_data_action_callback = function ( $allowed_html ) { | |
| 25 | - $allowed_html['span']['data-action'] = true; | |
| 26 | - return $allowed_html; | |
| 27 | - }; | |
| 28 | 21 | ?> |
| 29 | 22 | <div class="frm_warning_style" role="alert"> |
| 30 | 23 | <ul id="frm_messages"> |
| 31 | 24 | <?php |
| 32 | - // Add the callback function to the 'frm_striphtml_allowed_tags' filter | |
| 33 | - add_filter( 'frm_striphtml_allowed_tags', $add_data_action_callback ); | |
| 34 | - | |
| 35 | 25 | foreach ( $show_messages as $m ) { |
| 36 | - echo '<li>' . FrmAppHelper::kses( $m, array( 'a', 'br', 'span', 'p', 'svg', 'use' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 26 | + echo '<li>' . FrmAppHelper::kses( $m, array( 'a', 'br', 'span', 'p' ) ) . '</li>'; // WPCS: XSS ok. | |
| 37 | 27 | } |
| 38 | - // Remove the callback function from the 'frm_striphtml_allowed_tags' filter | |
| 39 | - remove_filter( 'frm_striphtml_allowed_tags', $add_data_action_callback ); | |
| 40 | 28 | ?> |
| 41 | 29 | </ul> |
| 42 | 30 | </div> |
| 43 | 31 | <?php |
| 44 | -}//end if | |
| 32 | +} | |
| 45 | 33 | |
| 46 | -if ( ! empty( $warnings ) && is_array( $warnings ) ) { | |
| 34 | +if ( isset( $warnings ) && is_array( $warnings ) && count( $warnings ) > 0 ) { | |
| 47 | 35 | ?> |
| 48 | 36 | <div class="frm_warning_style inline" role="alert"> |
| 49 | 37 | <div class="frm_warning_heading"> <?php echo esc_html__( 'Warning:', 'formidable' ); ?></div> |
| 50 | 38 | <ul id="frm_warnings"> |
| @@ -49,9 +37,9 @@ | ||
| 49 | 37 | <div class="frm_warning_heading"> <?php echo esc_html__( 'Warning:', 'formidable' ); ?></div> |
| 50 | 38 | <ul id="frm_warnings"> |
| 51 | 39 | <?php |
| 52 | 40 | foreach ( $warnings as $warning ) { |
| 53 | - echo '<li>' . FrmAppHelper::kses( $warning, array( 'a', 'br' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 41 | + echo '<li>' . FrmAppHelper::kses( $warning, array( 'a', 'br' ) ) . '</li>'; // WPCS: XSS ok. | |
| 54 | 42 | } |
| 55 | 43 | ?> |
| 56 | 44 | </ul> |
| 57 | 45 | </div> |
| @@ -57,34 +45,17 @@ | ||
| 57 | 45 | </div> |
| 58 | 46 | <?php |
| 59 | 47 | } |
| 60 | 48 | |
| 61 | -if ( ! empty( $errors ) && is_array( $errors ) ) { | |
| 49 | +if ( isset( $errors ) && is_array( $errors ) && count( $errors ) > 0 ) { | |
| 62 | 50 | ?> |
| 63 | 51 | <div class="frm_error_style inline" role="alert"> |
| 64 | 52 | <ul id="frm_errors"> |
| 65 | 53 | <?php |
| 66 | 54 | foreach ( $errors as $error ) { |
| 67 | - echo '<li>' . FrmAppHelper::kses( $error, array( 'a', 'br' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped | |
| 55 | + echo '<li>' . FrmAppHelper::kses( $error, array( 'a', 'br' ) ) . '</li>'; // WPCS: XSS ok. | |
| 68 | 56 | } |
| 69 | 57 | ?> |
| 70 | 58 | </ul> |
| 71 | 59 | </div> |
| 72 | 60 | <?php |
| 73 | -} | |
| 74 | - | |
| 75 | -if ( ! empty( $notes ) && is_array( $notes ) ) { | |
| 76 | - foreach ( $notes as $note ) { | |
| 77 | - ?> | |
| 78 | - <div class="frm_note_style"> | |
| 79 | - <?php | |
| 80 | - if ( is_string( $note ) ) { | |
| 81 | - echo esc_html( $note ); | |
| 82 | - } elseif ( is_callable( $note ) ) { | |
| 83 | - // If $note is a function call it so we can handle cases where we don't want to wrap the whole note in esc_html. | |
| 84 | - $note(); | |
| 85 | - } | |
| 86 | - ?> | |
| 87 | - </div> | |
| 88 | - <?php | |
| 89 | - } | |
| 90 | 61 | } |