PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.0
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.0
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmForm.php +183 -595 6.295.0 View file →
@@ -5,49 +5,38 @@
5 5
6 6 class FrmForm {
7 7
8 8 /**
9 - * @param array $values
10 - *
11 - * @return bool|int id on success or false on failure.
9 + * @return int|boolean id on success or false on failure
12 10 */
13 11 public static function create( $values ) {
14 12 global $wpdb;
15 13
16 - $values = FrmAppHelper::maybe_filter_array( $values, array( 'name', 'description' ) );
17 -
18 14 $new_values = array(
19 15 'form_key' => FrmAppHelper::get_unique_key( $values['form_key'], $wpdb->prefix . 'frm_forms', 'form_key' ),
20 16 'name' => $values['name'],
21 17 'description' => $values['description'],
22 - 'status' => $values['status'] ?? 'published',
23 - 'logged_in' => $values['logged_in'] ?? 0,
18 + 'status' => isset( $values['status'] ) ? $values['status'] : 'published',
19 + 'logged_in' => isset( $values['logged_in'] ) ? $values['logged_in'] : 0,
24 20 'is_template' => isset( $values['is_template'] ) ? (int) $values['is_template'] : 0,
25 21 'parent_form_id' => isset( $values['parent_form_id'] ) ? absint( $values['parent_form_id'] ) : 0,
26 22 'editable' => isset( $values['editable'] ) ? (int) $values['editable'] : 0,
27 - 'created_at' => $values['created_at'] ?? current_time( 'mysql', 1 ),
23 + 'created_at' => isset( $values['created_at'] ) ? $values['created_at'] : current_time( 'mysql', 1 ),
28 24 );
29 25
30 26 $options = isset( $values['options'] ) ? (array) $values['options'] : array();
31 27 FrmFormsHelper::fill_form_options( $options, $values );
32 28
33 - $options['before_html'] = $values['options']['before_html'] ?? FrmFormsHelper::get_default_html( 'before' );
34 - $options['after_html'] = $values['options']['after_html'] ?? FrmFormsHelper::get_default_html( 'after' );
35 - $options['submit_html'] = $values['options']['submit_html'] ?? FrmFormsHelper::get_default_html( 'submit' );
29 + $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
30 + $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
31 + $options['submit_html'] = isset( $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
36 32
37 - /**
38 - * Allows modifying form options before updating or creating.
39 - *
40 - * @since 5.4 Add the third param.
41 - *
42 - * @param array $options Form options.
43 - * @param array $values Form data.
44 - * @param bool $update Is form updating or creating. It's `true` if is updating.
45 - */
46 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, false );
47 - $options = self::maybe_filter_form_options( $options );
33 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
48 34 $new_values['options'] = serialize( $options );
49 35
36 + //if(isset($values['id']) && is_numeric($values['id']))
37 + // $new_values['id'] = $values['id'];
38 +
50 39 $wpdb->insert( $wpdb->prefix . 'frm_forms', $new_values );
51 40
52 41 $id = $wpdb->insert_id;
53 42
@@ -57,36 +46,14 @@
57 46 return $id;
58 47 }
59 48
60 49 /**
61 - * @since 5.0.08
62 - *
63 - * @param array $options
64 - *
65 - * @return array
50 + * @return int|boolean ID on success or false on failure
66 51 */
67 - private static function maybe_filter_form_options( $options ) {
68 - if ( ! FrmAppHelper::allow_unfiltered_html() && ! empty( $options['submit_html'] ) ) {
69 - $options['submit_html'] = FrmAppHelper::kses_submit_button( $options['submit_html'] );
70 - }
71 - return FrmAppHelper::maybe_filter_array( $options, array( 'submit_value', 'success_msg', 'before_html', 'after_html' ) );
72 - }
73 -
74 - /**
75 - * Duplicate a form.
76 - *
77 - * @param int $id Form ID to duplicate.
78 - * @param bool $template Whether the duplicated form is a template.
79 - * @param bool $copy_keys Whether to copy the original form key.
80 - * @param false|int $blog_id Blog ID when duplicating across sites, or false for current site.
81 - *
82 - * @return bool|int ID on success or false on failure
83 - */
84 52 public static function duplicate( $id, $template = false, $copy_keys = false, $blog_id = false ) {
85 53 global $wpdb;
86 54
87 55 $values = self::getOne( $id, $blog_id );
88 -
89 56 if ( ! $values ) {
90 57 return false;
91 58 }
92 59
@@ -103,10 +70,10 @@
103 70 'is_template' => $template ? 1 : 0,
104 71 );
105 72
106 73 if ( $blog_id ) {
107 - $new_values['status'] = 'published';
108 - $new_options = $values->options;
74 + $new_values['status'] = 'published';
75 + $new_options = $values->options;
109 76 FrmAppHelper::unserialize_or_decode( $new_options );
110 77 $new_options['email_to'] = get_option( 'admin_email' );
111 78 $new_options['copy'] = false;
112 79 $new_values['options'] = $new_options;
@@ -126,9 +93,9 @@
126 93
127 94 $form_id = $wpdb->insert_id;
128 95 FrmField::duplicate( $id, $form_id, $copy_keys, $blog_id );
129 96
130 - // Update form settings after fields are created
97 + // update form settings after fields are created
131 98 do_action( 'frm_after_duplicate_form', $form_id, $new_values, array( 'old_id' => $id ) );
132 99
133 100 return $form_id;
134 101 }
@@ -135,16 +102,10 @@
135 102
136 103 return false;
137 104 }
138 105
139 - /**
140 - * @param int $form_id
141 - * @param array $values
142 - *
143 - * @return void
144 - */
145 106 public static function after_duplicate( $form_id, $values ) {
146 - $new_opts = $values['options'];
107 + $new_opts = $values['options'];
147 108 FrmAppHelper::unserialize_or_decode( $new_opts );
148 109 $values['options'] = $new_opts;
149 110
150 111 if ( isset( $new_opts['success_msg'] ) ) {
@@ -152,110 +113,20 @@
152 113 }
153 114
154 115 $new_opts = apply_filters( 'frm_after_duplicate_form_values', $new_opts, $form_id );
155 116
156 - // phpcs:ignore Universal.Operators.StrictComparisons
157 117 if ( $new_opts != $values['options'] ) {
158 118 global $wpdb;
159 119 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'options' => maybe_serialize( $new_opts ) ), array( 'id' => $form_id ) );
160 120 }
161 -
162 - self::switch_field_ids_in_fields( $form_id );
163 121 }
164 122
165 123 /**
166 - * Switches field ID in fields.
167 - *
168 - * @since 5.3
169 - *
170 - * @param int $form_id Form ID.
171 - *
172 - * @return void
124 + * @return int|boolean
173 125 */
174 - private static function switch_field_ids_in_fields( $form_id ) {
175 - global $wpdb;
176 -
177 - // Keys of fields that you want to check to replace field ID.
178 - $keys = array( 'default_value', 'field_options' );
179 - $sql_cols = 'fi.id';
180 -
181 - foreach ( $keys as $key ) {
182 - $sql_cols .= ',fi.' . $key;
183 - }
184 -
185 - $fields = FrmDb::get_results(
186 - "{$wpdb->prefix}frm_fields AS fi LEFT OUTER JOIN {$wpdb->prefix}frm_forms AS fr ON fi.form_id = fr.id",
187 - array(
188 - 'or' => 1,
189 - 'fi.form_id' => $form_id,
190 - 'fr.parent_form_id' => $form_id,
191 - ),
192 - $sql_cols
193 - );
194 -
195 - if ( ! $fields || ! is_array( $fields ) ) {
196 - return;
197 - }
198 -
199 - foreach ( $fields as $field ) {
200 - self::switch_field_ids_in_field( (array) $field );
201 - }
202 - }
203 -
204 - /**
205 - * Switches field ID in a field.
206 - *
207 - * @since 5.3
208 - *
209 - * @param array $field Field array.
210 - *
211 - * @return void
212 - */
213 - private static function switch_field_ids_in_field( $field ) {
214 - $new_values = array();
215 -
216 - foreach ( $field as $key => $value ) {
217 - if ( 'id' === $key || ! $value ) {
218 - continue;
219 - }
220 -
221 - if ( ! is_string( $value ) && ! is_array( $value ) ) {
222 - continue;
223 - }
224 -
225 - if ( 'field_options' === $key ) {
226 - // Need to loop through field_options to prevent breaking serialized string when length changed.
227 - FrmAppHelper::unserialize_or_decode( $value );
228 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
229 - $new_val = serialize( $new_val );
230 - } else {
231 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
232 - }
233 -
234 - if ( $new_val !== $value ) {
235 - $new_values[ $key ] = $new_val;
236 - }
237 - }//end foreach
238 -
239 - if ( $new_values ) {
240 - FrmField::update( $field['id'], $new_values );
241 - }
242 - }
243 -
244 - /**
245 - * Update a form.
246 - *
247 - * @param int $id Form ID.
248 - * @param array $values Form values to update.
249 - * @param bool $create_link Whether this is being called from link creation.
250 - *
251 - * @return bool|int
252 - */
253 126 public static function update( $id, $values, $create_link = false ) {
254 127 global $wpdb;
255 128
256 - $values = FrmAppHelper::maybe_filter_array( $values, array( 'name', 'description' ) );
257 -
258 129 if ( ! isset( $values['status'] ) && ( $create_link || isset( $values['options'] ) || isset( $values['item_meta'] ) || isset( $values['field_options'] ) ) ) {
259 130 $values['status'] = 'published';
260 131 }
261 132
@@ -263,23 +134,23 @@
263 134 $values['form_key'] = FrmAppHelper::get_unique_key( $values['form_key'], $wpdb->prefix . 'frm_forms', 'form_key', $id );
264 135 }
265 136
266 137 $form_fields = array( 'form_key', 'name', 'description', 'status', 'parent_form_id' );
267 - $new_values = self::set_update_options( array(), $values, array( 'form_id' => $id ) );
268 138
139 + $new_values = self::set_update_options( array(), $values );
140 +
269 141 foreach ( $values as $value_key => $value ) {
270 - if ( $value_key && in_array( $value_key, $form_fields, true ) ) {
142 + if ( $value_key && in_array( $value_key, $form_fields ) ) {
271 143 $new_values[ $value_key ] = $value;
272 144 }
273 145 }
274 146
275 - if ( ! empty( $values['new_status'] ) ) {
147 + if ( isset( $values['new_status'] ) && ! empty( $values['new_status'] ) ) {
276 148 $new_values['status'] = $values['new_status'];
277 149 }
278 150
279 - if ( $new_values ) {
151 + if ( ! empty( $new_values ) ) {
280 152 $query_results = $wpdb->update( $wpdb->prefix . 'frm_forms', $new_values, array( 'id' => $id ) );
281 -
282 153 if ( $query_results ) {
283 154 self::clear_form_cache();
284 155 }
285 156 } else {
@@ -295,38 +166,24 @@
295 166 return $query_results;
296 167 }
297 168
298 169 /**
299 - * @param array $new_values
300 - * @param array $values
301 - * @param array $args
302 - *
303 170 * @return array
304 171 */
305 - public static function set_update_options( $new_values, $values, $args = array() ) {
172 + public static function set_update_options( $new_values, $values ) {
306 173 if ( ! isset( $values['options'] ) ) {
307 174 return $new_values;
308 175 }
309 176
310 - $options = ! empty( $values['options'] ) ? (array) $values['options'] : array();
177 + $options = isset( $values['options'] ) ? (array) $values['options'] : array();
311 178 FrmFormsHelper::fill_form_options( $options, $values );
312 179
313 - $options['custom_style'] = $values['options']['custom_style'] ?? 0;
314 - $options['before_html'] = $values['options']['before_html'] ?? FrmFormsHelper::get_default_html( 'before' );
315 - $options['after_html'] = $values['options']['after_html'] ?? FrmFormsHelper::get_default_html( 'after' );
316 - $options['submit_html'] = isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
180 + $options['custom_style'] = isset( $values['options']['custom_style'] ) ? $values['options']['custom_style'] : 0;
181 + $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
182 + $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
183 + $options['submit_html'] = ( isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
317 184
318 - /**
319 - * Allows modifying form options before updating or creating.
320 - *
321 - * @since 5.4 Added the third param.
322 - *
323 - * @param array $options Form options.
324 - * @param array $values Form data.
325 - * @param bool $update Is form updating or creating. It's `true` if is updating.
326 - */
327 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, true );
328 - $options = self::maybe_filter_form_options( $options );
185 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
329 186 $new_values['options'] = serialize( $options );
330 187
331 188 return $new_values;
332 189 }
@@ -331,14 +188,11 @@
331 188 return $new_values;
332 189 }
333 190
334 191 /**
335 - * @param int $id Form ID.
336 - * @param array $values Form values array.
337 - *
338 192 * @return array
339 193 */
340 - public static function update_fields( $id, $values ) { // phpcs:ignore SlevomatCodingStandard.Complexity.Cognitive.ComplexityTooHigh
194 + public static function update_fields( $id, $values ) {
341 195
342 196 if ( ! isset( $values['item_meta'] ) && ! isset( $values['field_options'] ) ) {
343 197 return $values;
344 198 }
@@ -343,10 +197,9 @@
343 197 return $values;
344 198 }
345 199
346 200 $all_fields = FrmField::get_all_for_form( $id );
347 -
348 - if ( ! $all_fields ) {
201 + if ( empty( $all_fields ) ) {
349 202 return $values;
350 203 }
351 204
352 205 if ( ! isset( $values['item_meta'] ) ) {
@@ -354,28 +207,28 @@
354 207 }
355 208
356 209 $field_array = array();
357 210 $existing_keys = array_keys( $values['item_meta'] );
358 -
359 211 foreach ( $all_fields as $fid ) {
360 - // phpcs:ignore WordPress.PHP.StrictInArray.MissingTrueStrict, SlevomatCodingStandard.Files.LineLength.LineTooLong
361 212 if ( ! in_array( $fid->id, $existing_keys ) && ( isset( $values['frm_fields_submitted'] ) && in_array( $fid->id, $values['frm_fields_submitted'] ) ) || isset( $values['options'] ) ) {
362 213 $values['item_meta'][ $fid->id ] = '';
363 214 }
364 -
365 215 $field_array[ $fid->id ] = $fid;
366 216 }
367 217 unset( $all_fields );
368 218
369 219 foreach ( $values['item_meta'] as $field_id => $default_value ) {
370 - $field = $field_array[ $field_id ] ?? FrmField::getOne( $field_id );
220 + if ( isset( $field_array[ $field_id ] ) ) {
221 + $field = $field_array[ $field_id ];
222 + } else {
223 + $field = FrmField::getOne( $field_id );
224 + }
371 225
372 226 if ( ! $field ) {
373 227 continue;
374 228 }
375 229
376 - $is_settings_page = isset( $values['options'] ) || isset( $values['field_options'][ 'custom_html_' . $field_id ] );
377 -
230 + $is_settings_page = ( isset( $values['options'] ) || isset( $values['field_options'][ 'custom_html_' . $field_id ] ) );
378 231 if ( $is_settings_page ) {
379 232 self::get_settings_page_html( $values, $field );
380 233
381 234 if ( ! defined( 'WP_IMPORTING' ) ) {
@@ -382,20 +235,15 @@
382 235 continue;
383 236 }
384 237 }
385 238
386 - // Updating the form.
239 + //updating the form
387 240 $update_options = FrmFieldsHelper::get_default_field_options_from_field( $field );
388 - // Don't check for POST html.
389 - unset( $update_options['custom_html'] );
241 + unset( $update_options['custom_html'] ); // don't check for POST html
390 242 $update_options = apply_filters( 'frm_field_options_to_update', $update_options );
391 243
392 - if ( ! is_array( $field->field_options ) ) {
393 - $field->field_options = array();
394 - }
395 -
396 244 foreach ( $update_options as $opt => $default ) {
397 - $field->field_options[ $opt ] = $values['field_options'][ $opt . '_' . $field_id ] ?? $default;
245 + $field->field_options[ $opt ] = isset( $values['field_options'][ $opt . '_' . $field_id ] ) ? $values['field_options'][ $opt . '_' . $field_id ] : $default;
398 246 self::sanitize_field_opt( $opt, $field->field_options[ $opt ] );
399 247 }
400 248
401 249 $field->field_options = apply_filters( 'frm_update_field_options', $field->field_options, $field, $values );
@@ -404,104 +252,44 @@
404 252 'field_options' => $field->field_options,
405 253 'default_value' => isset( $values[ 'default_value_' . $field_id ] ) ? FrmAppHelper::maybe_json_encode( $values[ 'default_value_' . $field_id ] ) : '',
406 254 );
407 255
408 - if ( ! FrmAppHelper::allow_unfiltered_html() && isset( $values['field_options'][ 'options_' . $field_id ] ) && is_array( $values['field_options'][ 'options_' . $field_id ] ) ) { // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
409 - foreach ( $values['field_options'][ 'options_' . $field_id ] as $option_key => $option ) {
410 - if ( ! is_array( $option ) ) {
411 - continue;
412 - }
413 -
414 - foreach ( $option as $key => $item ) {
415 - $values['field_options'][ 'options_' . $field_id ][ $option_key ][ $key ] = FrmAppHelper::kses( $item, 'all' );
416 - }
417 - }
418 - }
419 -
420 256 self::prepare_field_update_values( $field, $values, $new_field );
421 - self::maybe_update_max_option( $field, $values, $new_field );
422 257
423 258 FrmField::update( $field_id, $new_field );
424 259
425 260 FrmField::delete_form_transient( $field->form_id );
426 - }//end foreach
261 + }
427 262 self::clear_form_cache();
428 263
429 264 return $values;
430 265 }
431 266
432 - /**
433 - * Resets the 'max' option of a field when changing paragraph field type to other field types like text, email etc.
434 - *
435 - * @since 6.7
436 - *
437 - * @param object $field
438 - * @param array $values
439 - * @param array $new_field
440 - *
441 - * @return void
442 - */
443 - private static function maybe_update_max_option( $field, $values, &$new_field ) {
444 - if ( $field->type !== 'textarea' ||
445 - empty( $values['field_options'][ 'type_' . $field->id ] ) ||
446 - ! in_array( $values['field_options'][ 'type_' . $field->id ], array( 'text', 'email', 'url', 'password', 'phone' ), true ) ) {
447 - return;
448 - }
449 -
450 - $new_field['field_options']['max'] = '';
451 -
452 - /**
453 - * Update posted field setting so that new 'max' option is displayed after form is saved and page reloads.
454 - * FrmFieldsHelper::fill_default_field_opts populates field options by calling self::get_posted_field_setting.
455 - */
456 - $_POST['field_options'][ 'max_' . $field->id ] = '';
457 - }
458 -
459 - /**
460 - * @param string $opt
461 - * @param mixed $value
462 - *
463 - * @return void
464 - */
465 267 private static function sanitize_field_opt( $opt, &$value ) {
466 - if ( ! is_string( $value ) ) {
467 - return;
268 + if ( is_string( $value ) ) {
269 + if ( $opt === 'calc' ) {
270 + $value = self::sanitize_calc( $value );
271 + } else {
272 + $value = FrmAppHelper::kses( $value, 'all' );
273 + }
274 + $value = trim( $value );
468 275 }
469 -
470 - /**
471 - * Allow the option to turn off sanitization for a field. This way a custom rule can be used instead.
472 - * Make sure to add custom sanitization using the frm_update_field_options filter as the data will no longer be sanitized.
473 - *
474 - * @since 6.0
475 - *
476 - * @param bool $should_sanitize
477 - * @param string $opt
478 - */
479 - $should_sanitize = apply_filters( 'frm_should_sanitize_field_opt_string', true, $opt );
480 -
481 - if ( ! $should_sanitize ) {
482 - return;
483 - }
484 -
485 - $value = $opt === 'calc' ? self::sanitize_calc( $value ) : FrmAppHelper::kses( $value, 'all' );
486 - $value = trim( $value );
487 276 }
488 277
489 278 /**
490 279 * @param string $value
491 - *
492 280 * @return string
493 281 */
494 282 private static function sanitize_calc( $value ) {
495 - if ( str_contains( $value, '<' ) ) {
283 + if ( false !== strpos( $value, '<' ) ) {
496 284 $value = self::normalize_calc_spaces( $value );
497 285 }
498 - // Allow <= and >=.
499 - $allow = array( '<= ', ' >=' );
286 + $allow = array( '<= ', ' >=' ); // Allow <= and >=
500 287 $temp = array( '< = ', ' > =' );
501 288 $value = str_replace( $allow, $temp, $value );
502 289 $value = strip_tags( $value );
503 - return str_replace( $temp, $allow, $value );
290 + $value = str_replace( $temp, $allow, $value );
291 + return $value;
504 292 }
505 293
506 294 /**
507 295 * Format a comparison like 5<10 to 5 < 10. Also works on 5< 10, 5 <10, 5<=10 variations.
@@ -507,58 +295,41 @@
507 295 * Format a comparison like 5<10 to 5 < 10. Also works on 5< 10, 5 <10, 5<=10 variations.
508 296 * This is to avoid an issue with unspaced calculations being recognized as HTML that gets removed when strip_tags is called.
509 297 *
510 298 * @param string $calc
511 - *
512 299 * @return string
513 300 */
514 301 private static function normalize_calc_spaces( $calc ) {
515 302 // Check for a pattern with 5 parts
516 - // $1 \d|\] the first comparison digit or the end of a comparison shortcode.
303 + // $1 \d the first comparison digit.
517 304 // $2 a space (optional).
518 305 // $3 an equals sign (optional) that follows the < operator for <= comparisons.
519 306 // $4 another space (optional).
520 - // $5 \d|\[ the second comparison digit or the start of a comparison shortcode.
521 - return preg_replace( '/(\d|\])( ){0,1}<(=){0,1}( ){0,1}(\d|\[)/', '$1 <$3 $5', $calc );
307 + // $5 \d the second comparison digit.
308 + return preg_replace( '/(\d)( ){0,1}<(=){0,1}( ){0,1}(\d)/', '$1 <$3 $5', $calc );
522 309 }
523 310
524 311 /**
525 312 * Updating the settings page
526 - *
527 - * @param array $values Form values array.
528 - * @param object $field Field object, passed by reference.
529 - *
530 - * @return void
531 313 */
532 314 private static function get_settings_page_html( $values, &$field ) {
533 315 if ( isset( $values['field_options'][ 'custom_html_' . $field->id ] ) ) {
534 316 $prev_opts = array();
535 - $fallback_html = $field->field_options['custom_html'] ?? FrmFieldsHelper::get_default_html( $field->type );
317 + $fallback_html = isset( $field->field_options['custom_html'] ) ? $field->field_options['custom_html'] : FrmFieldsHelper::get_default_html( $field->type );
536 318
537 - $field->field_options['custom_html'] = $values['field_options'][ 'custom_html_' . $field->id ] ?? $fallback_html;
538 - } elseif ( $field->type === 'hidden' || $field->type === 'user_id' ) {
319 + $field->field_options['custom_html'] = isset( $values['field_options'][ 'custom_html_' . $field->id ] ) ? $values['field_options'][ 'custom_html_' . $field->id ] : $fallback_html;
320 + } elseif ( $field->type == 'hidden' || $field->type == 'user_id' ) {
539 321 $prev_opts = $field->field_options;
540 322 }
541 323
542 - if ( ! isset( $prev_opts ) ) {
543 - return;
324 + if ( isset( $prev_opts ) ) {
325 + $field->field_options = apply_filters( 'frm_update_form_field_options', $field->field_options, $field, $values );
326 + if ( $prev_opts != $field->field_options ) {
327 + FrmField::update( $field->id, array( 'field_options' => $field->field_options ) );
328 + }
544 329 }
545 -
546 - $field->field_options = apply_filters( 'frm_update_form_field_options', $field->field_options, $field, $values );
547 -
548 - // phpcs:ignore Universal.Operators.StrictComparisons
549 - if ( $prev_opts != $field->field_options ) {
550 - FrmField::update( $field->id, array( 'field_options' => $field->field_options ) );
551 - }
552 330 }
553 331
554 - /**
555 - * @param object $field
556 - * @param array $values
557 - * @param array $new_field
558 - *
559 - * @return void
560 - */
561 332 private static function prepare_field_update_values( $field, $values, &$new_field ) {
562 333 $field_cols = array(
563 334 'field_order' => 0,
564 335 'field_key' => '',
@@ -567,16 +338,12 @@
567 338 'description' => '',
568 339 'options' => '',
569 340 'name' => '',
570 341 );
571 -
572 342 foreach ( $field_cols as $col => $default ) {
573 - $default = $default === '' ? $field->{$col} : $default;
574 - $new_field[ $col ] = $values['field_options'][ $col . '_' . $field->id ] ?? $default;
575 - }
343 + $default = ( $default === '' ) ? $field->{$col} : $default;
576 344
577 - if ( $field->type === 'submit' && isset( $new_field['field_order'] ) && (int) $new_field['field_order'] === FrmSubmitHelper::DEFAULT_ORDER ) {
578 - $new_field['field_order'] = $field->field_order;
345 + $new_field[ $col ] = isset( $values['field_options'][ $col . '_' . $field->id ] ) ? $values['field_options'][ $col . '_' . $field->id ] : $default;
579 346 }
580 347
581 348 // Don't save the template option.
582 349 if ( is_array( $new_field['options'] ) && isset( $new_field['options']['000'] ) ) {
@@ -588,12 +355,9 @@
588 355 * Get a list of all form settings that should be translated
589 356 * on a multilingual site.
590 357 *
591 358 * @since 3.06.01
592 - *
593 - * @param object $form The form object.
594 - *
595 - * @return array
359 + * @param object $form - The form object
596 360 */
597 361 public static function translatable_strings( $form ) {
598 362 $strings = array(
599 363 'name',
@@ -600,12 +364,8 @@
600 364 'description',
601 365 'submit_value',
602 366 'submit_msg',
603 367 'success_msg',
604 - 'invalid_msg',
605 - 'failed_msg',
606 - 'login_msg',
607 - 'admin_permission',
608 368 );
609 369
610 370 return apply_filters( 'frm_form_strings', $strings, $form );
611 371 }
@@ -610,21 +370,19 @@
610 370 return apply_filters( 'frm_form_strings', $strings, $form );
611 371 }
612 372
613 373 /**
614 - * @param array|int $id
615 - * @param string $status
374 + * @param string $status
616 375 *
617 - * @return bool|int
376 + * @return int|boolean
618 377 */
619 378 public static function set_status( $id, $status ) {
620 - if ( 'trash' === $status ) {
379 + if ( 'trash' == $status ) {
621 380 return self::trash( $id );
622 381 }
623 382
624 383 $statuses = array( 'published', 'draft', 'trash' );
625 -
626 - if ( ! in_array( $status, $statuses, true ) ) {
384 + if ( ! in_array( $status, $statuses ) ) {
627 385 return false;
628 386 }
629 387
630 388 global $wpdb;
@@ -637,9 +395,9 @@
637 395 );
638 396 FrmDb::get_where_clause_and_values( $where );
639 397 array_unshift( $where['values'], $status );
640 398
641 - $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared, SlevomatCodingStandard.Files.LineLength.LineTooLong
399 + $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // WPCS: unprepared SQL ok.
642 400 } else {
643 401 $query_results = $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'id' => $id ) );
644 402 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'parent_form_id' => $id ) );
645 403 }
@@ -651,11 +409,9 @@
651 409 return $query_results;
652 410 }
653 411
654 412 /**
655 - * @param int|string $id Form ID.
656 - *
657 - * @return bool|int
413 + * @return int|boolean
658 414 */
659 415 public static function trash( $id ) {
660 416 if ( ! EMPTY_TRASH_DAYS ) {
661 417 return self::destroy( $id );
@@ -661,17 +417,12 @@
661 417 return self::destroy( $id );
662 418 }
663 419
664 420 $form = self::getOne( $id );
665 -
666 421 if ( ! $form ) {
667 422 return false;
668 423 }
669 424
670 - if ( $form->status === 'trash' ) {
671 - return false;
672 - }
673 -
674 425 $options = $form->options;
675 426 $options['trash_time'] = time();
676 427
677 428 global $wpdb;
@@ -704,26 +455,21 @@
704 455 return $query_results;
705 456 }
706 457
707 458 /**
708 - * @param int|string $id Form ID.
709 - *
710 - * @return bool|int
459 + * @return int|boolean
711 460 */
712 461 public static function destroy( $id ) {
713 462 global $wpdb;
714 463
715 464 $form = self::getOne( $id );
716 -
717 465 if ( ! $form ) {
718 466 return false;
719 467 }
720 -
721 468 $id = $form->id;
722 469
723 470 // Disconnect the entries from this form
724 - $entries = FrmDb::get_col( 'frm_items', array( 'form_id' => $id ) );
725 -
471 + $entries = FrmDb::get_col( $wpdb->prefix . 'frm_items', array( 'form_id' => $id ) );
726 472 foreach ( $entries as $entry_id ) {
727 473 FrmEntry::destroy( $entry_id );
728 474 unset( $entry_id );
729 475 }
@@ -728,29 +474,23 @@
728 474 unset( $entry_id );
729 475 }
730 476
731 477 // Disconnect the fields from this form
732 - $wpdb->query( $wpdb->prepare( 'DELETE fi FROM ' . $wpdb->prefix . 'frm_fields AS fi LEFT JOIN ' . $wpdb->prefix . 'frm_forms fr ON (fi.form_id = fr.id) WHERE fi.form_id=%d OR parent_form_id=%d', $id, $id ) ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
478 + $wpdb->query( $wpdb->prepare( 'DELETE fi FROM ' . $wpdb->prefix . 'frm_fields AS fi LEFT JOIN ' . $wpdb->prefix . 'frm_forms fr ON (fi.form_id = fr.id) WHERE fi.form_id=%d OR parent_form_id=%d', $id, $id ) );
733 479
734 480 $query_results = $wpdb->query( $wpdb->prepare( 'DELETE FROM ' . $wpdb->prefix . 'frm_forms WHERE id=%d OR parent_form_id=%d', $id, $id ) );
481 + if ( $query_results ) {
482 + // Delete all form actions linked to this form
483 + $action_control = FrmFormActionsController::get_form_actions( 'email' );
484 + $action_control->destroy( $id, 'all' );
735 485
736 - if ( ! $query_results ) {
737 - return $query_results;
486 + // Clear form caching
487 + self::clear_form_cache();
488 +
489 + do_action( 'frm_destroy_form', $id );
490 + do_action( 'frm_destroy_form_' . $id );
738 491 }
739 492
740 - // Delete all form actions linked to this form
741 - /**
742 - * @var FrmFormAction
743 - */
744 - $action_control = FrmFormActionsController::get_form_actions( 'email' );
745 - $action_control->destroy( $id, 'all' );
746 -
747 - // Clear form caching
748 - self::clear_form_cache();
749 -
750 - do_action( 'frm_destroy_form', $id );
751 - do_action( 'frm_destroy_form_' . $id );
752 -
753 493 return $query_results;
754 494 }
755 495
756 496 /**
@@ -755,34 +495,29 @@
755 495
756 496 /**
757 497 * Delete trashed forms based on how long they have been trashed
758 498 *
759 - * @param int|string $delete_timestamp Timestamp cutoff for deletion.
760 - *
761 499 * @return int The number of forms deleted
762 500 */
763 501 public static function scheduled_delete( $delete_timestamp = '' ) {
764 - $trash_forms = FrmDb::get_results( 'frm_forms', array( 'status' => 'trash' ), 'id, parent_form_id, options' );
502 + global $wpdb;
765 503
504 + $trash_forms = FrmDb::get_results( $wpdb->prefix . 'frm_forms', array( 'status' => 'trash' ), 'id, options' );
505 +
766 506 if ( ! $trash_forms ) {
767 - return 0;
507 + return;
768 508 }
769 509
770 - if ( ! $delete_timestamp ) {
510 + if ( empty( $delete_timestamp ) ) {
771 511 $delete_timestamp = time() - ( DAY_IN_SECONDS * EMPTY_TRASH_DAYS );
772 512 }
773 513
774 514 $count = 0;
775 -
776 515 foreach ( $trash_forms as $form ) {
777 516 FrmAppHelper::unserialize_or_decode( $form->options );
778 -
779 517 if ( ! isset( $form->options['trash_time'] ) || $form->options['trash_time'] < $delete_timestamp ) {
780 518 self::destroy( $form->id );
781 -
782 - if ( empty( $form->parent_form_id ) ) {
783 - ++$count;
784 - }
519 + $count ++;
785 520 }
786 521
787 522 unset( $form );
788 523 }
@@ -790,24 +525,23 @@
790 525 return $count;
791 526 }
792 527
793 528 /**
794 - * @param int|string $id Form ID or key.
795 - *
796 529 * @return string form name
797 530 */
798 531 public static function getName( $id ) {
799 532 $form = FrmDb::check_cache( $id, 'frm_form' );
533 + if ( $form ) {
534 + $r = stripslashes( $form->name );
800 535
801 - if ( $form ) {
802 - return stripslashes( $form->name );
536 + return $r;
803 537 }
804 538
805 539 $query_key = is_numeric( $id ) ? 'id' : 'form_key';
806 540 $r = FrmDb::get_var( 'frm_forms', array( $query_key => $id ), 'name' );
541 + $r = stripslashes( $r );
807 542
808 - // An empty form name can result in a null value.
809 - return is_null( $r ) ? '' : stripslashes( $r );
543 + return $r;
810 544 }
811 545
812 546 /**
813 547 * @since 3.0
@@ -822,9 +556,9 @@
822 556
823 557 /**
824 558 * @since 3.0
825 559 *
826 - * @param int|string $id
560 + * @param int $id
827 561 *
828 562 * @return string form key
829 563 */
830 564 public static function get_key_by_id( $id ) {
@@ -829,57 +563,59 @@
829 563 */
830 564 public static function get_key_by_id( $id ) {
831 565 $id = (int) $id;
832 566 $cache = FrmDb::check_cache( $id, 'frm_form' );
833 -
834 567 if ( $cache ) {
835 568 return $cache->form_key;
836 569 }
837 570
838 - return FrmDb::get_var( 'frm_forms', array( 'id' => $id ), 'form_key' );
571 + $key = FrmDb::get_var( 'frm_forms', array( 'id' => $id ), 'form_key' );
572 +
573 + return $key;
839 574 }
840 575
841 576 /**
842 577 * If $form is numeric, get the form object
843 578 *
579 + * @param object|int $form
580 + *
844 581 * @since 2.0.9
845 - *
846 - * @param array|int|object $form
847 - *
848 - * @return void
849 582 */
850 583 public static function maybe_get_form( &$form ) {
851 - if ( ! is_object( $form ) && ! is_array( $form ) && $form ) {
584 + if ( ! is_object( $form ) && ! is_array( $form ) && ! empty( $form ) ) {
852 585 $form = self::getOne( $form );
853 586 }
854 587 }
855 588
856 589 /**
857 - * @param int|string $id
858 - * @param false|int $blog_id
859 - *
860 - * @return stdClass|null
590 + * @return object form
861 591 */
862 592 public static function getOne( $id, $blog_id = false ) {
863 593 global $wpdb;
864 594
865 595 if ( $blog_id && is_multisite() ) {
866 - $prefix = $wpdb->get_blog_prefix( $blog_id );
596 + global $wpmuBaseTablePrefix;
597 + $prefix = $wpmuBaseTablePrefix ? $wpmuBaseTablePrefix . $blog_id . '_' : $wpdb->get_blog_prefix( $blog_id );
598 +
867 599 $table_name = $prefix . 'frm_forms';
868 600 } else {
869 601 $table_name = $wpdb->prefix . 'frm_forms';
870 602 $cache = wp_cache_get( $id, 'frm_form' );
871 -
872 603 if ( $cache ) {
873 604 if ( isset( $cache->options ) ) {
874 605 FrmAppHelper::unserialize_or_decode( $cache->options );
875 606 }
876 607
877 - return self::prepare_form_row_data( $cache );
608 + return wp_unslash( $cache );
878 609 }
879 610 }
880 611
881 - $where = is_numeric( $id ) ? array( 'id' => $id ) : array( 'form_key' => $id );
612 + if ( is_numeric( $id ) ) {
613 + $where = array( 'id' => $id );
614 + } else {
615 + $where = array( 'form_key' => $id );
616 + }
617 +
882 618 $results = FrmDb::get_row( $table_name, $where );
883 619
884 620 if ( isset( $results->options ) ) {
885 621 FrmDb::set_cache( $results->id, $results, 'frm_form' );
@@ -885,50 +621,18 @@
885 621 FrmDb::set_cache( $results->id, $results, 'frm_form' );
886 622 FrmAppHelper::unserialize_or_decode( $results->options );
887 623 }
888 624
889 - return self::prepare_form_row_data( $results );
625 + return apply_filters( 'frm_form_object', wp_unslash( $results ) );
890 626 }
891 627
892 628 /**
893 - * Make sure that if $row is an object, that $row->options is an array and not a string.
894 - *
895 - * @since 6.8.3
896 - *
897 - * @param stdClass|null $row The database row for a target form.
898 - *
899 - * @return stdClass|null
629 + * @return object|array of objects
900 630 */
901 - private static function prepare_form_row_data( $row ) {
902 - $row = wp_unslash( $row );
903 -
904 - if ( ! is_object( $row ) ) {
905 - return $row;
906 - }
907 -
908 - if ( ! is_array( $row->options ) ) {
909 - $row->options = FrmFormsHelper::get_default_opts();
910 - }
911 -
912 - /**
913 - * @since 4.03.02
914 - *
915 - * @param stdClass $row
916 - */
917 - return apply_filters( 'frm_form_object', $row );
918 - }
919 -
920 - /**
921 - * @param array|string $where Where conditions array or raw WHERE string.
922 - * @param string $order_by Order by clause.
923 - * @param int|string $limit Limit clause or number.
924 - *
925 - * @return array|object Array of objects. If $limit is 1, a single object is returned.
926 - */
927 631 public static function getAll( $where = array(), $order_by = '', $limit = '' ) {
928 - if ( is_array( $where ) && $where ) {
929 - if ( ! empty( $where['is_template'] ) && ! isset( $where['status'] ) && ! isset( $where['status !'] ) ) {
930 - // Don't get trashed templates
632 + if ( is_array( $where ) && ! empty( $where ) ) {
633 + if ( isset( $where['is_template'] ) && $where['is_template'] && ! isset( $where['status'] ) && ! isset( $where['status !'] ) ) {
634 + // don't get trashed templates
931 635 $where['status'] = array( null, '', 'published' );
932 636 }
933 637
934 638 $results = FrmDb::get_results( 'frm_forms', $where, '*', compact( 'order_by', 'limit' ) );
@@ -934,11 +638,11 @@
934 638 $results = FrmDb::get_results( 'frm_forms', $where, '*', compact( 'order_by', 'limit' ) );
935 639 } else {
936 640 global $wpdb;
937 641
938 - // The query has already been prepared if this is not an array.
939 - $query = 'SELECT * FROM ' . $wpdb->prefix . 'frm_forms' . FrmDb::prepend_and_or_where( ' WHERE ', $where ) . FrmDb::esc_order( $order_by ) . FrmDb::esc_limit( $limit ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
940 - $results = $wpdb->get_results( $query ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
642 + // the query has already been prepared if this is not an array
643 + $query = 'SELECT * FROM ' . $wpdb->prefix . 'frm_forms' . FrmDb::prepend_and_or_where( ' WHERE ', $where ) . FrmDb::esc_order( $order_by ) . FrmDb::esc_limit( $limit );
644 + $results = $wpdb->get_results( $query ); // WPCS: unprepared SQL ok.
941 645 }
942 646
943 647 if ( $results ) {
944 648 foreach ( $results as $result ) {
@@ -946,10 +650,10 @@
946 650 FrmAppHelper::unserialize_or_decode( $result->options );
947 651 }
948 652 }
949 653
950 - if ( $limit === ' LIMIT 1' || (int) $limit === 1 ) {
951 - // Return the first form object if we are only getting one form
654 + if ( $limit == ' LIMIT 1' || $limit == 1 ) {
655 + // return the first form object if we are only getting one form
952 656 $results = reset( $results );
953 657 }
954 658
955 659 return wp_unslash( $results );
@@ -958,24 +662,20 @@
958 662 /**
959 663 * Get all published forms
960 664 *
961 665 * @since 2.0
962 - *
963 - * @param array $query
964 - * @param int $limit
965 - * @param string $inc_children
966 - *
967 - * @return array|object Array of forms. A single form object is returned if $limit is set to 1.
666 + * @return array of forms
968 667 */
969 668 public static function get_published_forms( $query = array(), $limit = 999, $inc_children = 'exclude' ) {
970 669 $query['is_template'] = 0;
971 670 $query['status'] = array( null, '', 'published' );
972 -
973 - if ( $inc_children === 'exclude' ) {
671 + if ( $inc_children == 'exclude' ) {
974 672 $query['parent_form_id'] = array( null, 0 );
975 673 }
976 674
977 - return self::getAll( $query, 'name', $limit );
675 + $forms = self::getAll( $query, 'name', $limit );
676 +
677 + return $forms;
978 678 }
979 679
980 680 /**
981 681 * @return object count of forms
@@ -980,16 +680,18 @@
980 680 /**
981 681 * @return object count of forms
982 682 */
983 683 public static function get_count() {
684 + global $wpdb;
685 +
984 686 $cache_key = 'frm_form_counts';
985 - $counts = wp_cache_get( $cache_key, 'frm_form' );
986 687
688 + $counts = wp_cache_get( $cache_key, 'frm_form' );
987 689 if ( false !== $counts ) {
988 690 return $counts;
989 691 }
990 692
991 - $results = FrmDb::get_results(
693 + $results = (array) FrmDb::get_results(
992 694 'frm_forms',
993 695 array(
994 696 'or' => 1,
995 697 'parent_form_id' => null,
@@ -1001,18 +703,20 @@
1001 703 $statuses = array( 'published', 'draft', 'template', 'trash' );
1002 704 $counts = array_fill_keys( $statuses, 0 );
1003 705
1004 706 foreach ( $results as $row ) {
1005 - if ( 'trash' === $row->status ) {
1006 - ++$counts['trash'];
1007 - } elseif ( $row->is_template ) {
1008 - ++$counts['template'];
707 + if ( 'trash' != $row->status ) {
708 + if ( $row->is_template ) {
709 + $counts['template'] ++;
710 + } else {
711 + $counts['published'] ++;
712 + }
1009 713 } else {
1010 - ++$counts['published'];
714 + $counts['trash'] ++;
1011 715 }
1012 716
1013 - if ( 'draft' === $row->status ) {
1014 - ++$counts['draft'];
717 + if ( 'draft' == $row->status ) {
718 + $counts['draft'] ++;
1015 719 }
1016 720
1017 721 unset( $row );
1018 722 }
@@ -1028,10 +732,8 @@
1028 732 * Called when a form is created, updated, duplicated, or deleted
1029 733 * or when the form status is changed
1030 734 *
1031 735 * @since 2.0.4
1032 - *
1033 - * @return void
1034 736 */
1035 737 public static function clear_form_cache() {
1036 738 FrmDb::cache_delete_group( 'frm_form' );
1037 739 }
@@ -1036,29 +738,23 @@
1036 738 FrmDb::cache_delete_group( 'frm_form' );
1037 739 }
1038 740
1039 741 /**
1040 - * @param array $values Form values to validate.
1041 - *
1042 742 * @return array of errors
1043 743 */
1044 744 public static function validate( $values ) {
1045 745 $errors = array();
746 +
1046 747 return apply_filters( 'frm_validate_form', $errors, $values );
1047 748 }
1048 749
1049 - /**
1050 - * @param object|null $form
1051 - *
1052 - * @return array
1053 - */
1054 750 public static function get_params( $form = null ) {
1055 751 global $frm_vars;
1056 752
1057 - if ( $form ) {
753 + if ( ! $form ) {
754 + $form = self::getAll( array(), 'name', 1 );
755 + } else {
1058 756 self::maybe_get_form( $form );
1059 - } else {
1060 - $form = self::getAll( array(), 'name', 1 );
1061 757 }
1062 758
1063 759 if ( isset( $frm_vars['form_params'] ) && is_array( $frm_vars['form_params'] ) && isset( $frm_vars['form_params'][ $form->id ] ) ) {
1064 760 return $frm_vars['form_params'][ $form->id ];
@@ -1063,9 +759,9 @@
1063 759 if ( isset( $frm_vars['form_params'] ) && is_array( $frm_vars['form_params'] ) && isset( $frm_vars['form_params'][ $form->id ] ) ) {
1064 760 return $frm_vars['form_params'][ $form->id ];
1065 761 }
1066 762
1067 - $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // phpcs:ignore WordPress.Security.NonceVerification.Missing
763 + $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // WPCS: CSRF ok.
1068 764 $action = apply_filters( 'frm_show_new_entry_page', FrmAppHelper::get_param( $action_var, 'new', 'get', 'sanitize_title' ), $form );
1069 765
1070 766 $default_values = array(
1071 767 'id' => '',
@@ -1081,18 +777,16 @@
1081 777 );
1082 778
1083 779 $values = array();
1084 780 $values['posted_form_id'] = FrmAppHelper::get_param( 'form_id', '', 'get', 'absint' );
1085 -
1086 781 if ( ! $values['posted_form_id'] ) {
1087 782 $values['posted_form_id'] = FrmAppHelper::get_param( 'form', '', 'get', 'absint' );
1088 783 }
1089 784
1090 - // phpcs:ignore Universal.Operators.StrictComparisons
1091 785 if ( $form->id == $values['posted_form_id'] ) {
1092 - // If there are two forms on the same page, make sure not to submit both.
786 + //if there are two forms on the same page, make sure not to submit both
1093 787 foreach ( $default_values as $var => $default ) {
1094 - if ( $var === 'action' ) {
788 + if ( $var == 'action' ) {
1095 789 $values[ $var ] = FrmAppHelper::get_param( $action_var, $default, 'get', 'sanitize_title' );
1096 790 } else {
1097 791 $values[ $var ] = FrmAppHelper::get_param( $var, $default, 'get', 'sanitize_text_field' );
1098 792 }
@@ -1104,10 +798,10 @@
1104 798 unset( $var, $default );
1105 799 }
1106 800 }
1107 801
1108 - if ( in_array( $values['action'], array( 'create', 'update' ), true ) &&
1109 - ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // phpcs:ignore WordPress.Security.NonceVerification.Missing
802 + if ( in_array( $values['action'], array( 'create', 'update' ) ) &&
803 + ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // WPCS: CSRF ok.
1110 804 ) {
1111 805 $values['action'] = 'new';
1112 806 }
1113 807
@@ -1113,11 +807,8 @@
1113 807
1114 808 return $values;
1115 809 }
1116 810
1117 - /**
1118 - * @return array
1119 - */
1120 811 public static function list_page_params() {
1121 812 $values = array();
1122 813 $defaults = array(
1123 814 'template' => 0,
@@ -1127,9 +818,8 @@
1127 818 'search' => '',
1128 819 'sort' => '',
1129 820 'sdir' => '',
1130 821 );
1131 -
1132 822 foreach ( $defaults as $var => $default ) {
1133 823 $values[ $var ] = FrmAppHelper::get_param( $var, $default, 'get', 'sanitize_text_field' );
1134 824 }
1135 825
@@ -1135,16 +825,10 @@
1135 825
1136 826 return $values;
1137 827 }
1138 828
1139 - /**
1140 - * @param int|object|string|null $form
1141 - *
1142 - * @return array
1143 - */
1144 829 public static function get_admin_params( $form = null ) {
1145 830 $form_id = $form;
1146 -
1147 831 if ( $form === null ) {
1148 832 $form_id = self::get_current_form_id();
1149 833 } elseif ( $form && is_object( $form ) ) {
1150 834 $form_id = $form->id;
@@ -1162,9 +846,8 @@
1162 846 'sdir' => '',
1163 847 'fid' => '',
1164 848 'keep_post' => '',
1165 849 );
1166 -
1167 850 foreach ( $defaults as $var => $default ) {
1168 851 $values[ $var ] = FrmAppHelper::get_param( $var, $default, 'get', 'sanitize_text_field' );
1169 852 }
1170 853
@@ -1170,55 +853,47 @@
1170 853
1171 854 return $values;
1172 855 }
1173 856
1174 - /**
1175 - * @param string $default_form
1176 - *
1177 - * @return int|string
1178 - */
1179 857 public static function get_current_form_id( $default_form = 'none' ) {
1180 - $form = 'first' === $default_form ? self::get_current_form() : self::maybe_get_current_form();
1181 - return $form ? $form->id : 0;
858 + if ( 'first' == $default_form ) {
859 + $form = self::get_current_form();
860 + } else {
861 + $form = self::maybe_get_current_form();
862 + }
863 + $form_id = $form ? $form->id : 0;
864 +
865 + return $form_id;
1182 866 }
1183 867
1184 - /**
1185 - * @param int|string $form_id
1186 - *
1187 - * @return false|int|object|string
1188 - */
1189 868 public static function maybe_get_current_form( $form_id = 0 ) {
1190 869 global $frm_vars;
1191 870
1192 - if ( ! empty( $frm_vars['current_form'] ) && ( ! $form_id || (int) $form_id === (int) $frm_vars['current_form']->id ) ) {
871 + if ( isset( $frm_vars['current_form'] ) && $frm_vars['current_form'] && ( ! $form_id || $form_id == $frm_vars['current_form']->id ) ) {
1193 872 return $frm_vars['current_form'];
1194 873 }
1195 874
1196 875 $form_id = FrmAppHelper::get_param( 'form', $form_id, 'get', 'absint' );
876 + if ( $form_id ) {
877 + $form_id = self::set_current_form( $form_id );
878 + }
1197 879
1198 - return $form_id ? self::set_current_form( $form_id ) : $form_id;
880 + return $form_id;
1199 881 }
1200 882
1201 - /**
1202 - * @param int $form_id
1203 - *
1204 - * @return false|object
1205 - */
1206 883 public static function get_current_form( $form_id = 0 ) {
1207 884 $form = self::maybe_get_current_form( $form_id );
1208 - return is_numeric( $form ) ? self::set_current_form( $form ) : $form;
885 + if ( is_numeric( $form ) ) {
886 + $form = self::set_current_form( $form );
887 + }
888 +
889 + return $form;
1209 890 }
1210 891
1211 - /**
1212 - * @param int $form_id
1213 - *
1214 - * @return false|object
1215 - */
1216 892 public static function set_current_form( $form_id ) {
1217 893 global $frm_vars;
1218 894
1219 895 $query = array();
1220 -
1221 896 if ( $form_id ) {
1222 897 $query['id'] = $form_id;
1223 898 }
1224 899
@@ -1226,19 +901,11 @@
1226 901
1227 902 return $frm_vars['current_form'];
1228 903 }
1229 904
1230 - /**
1231 - * @param object $form
1232 - * @param int|string $this_load
1233 - * @param bool $global_load
1234 - *
1235 - * @return bool
1236 - */
1237 905 public static function is_form_loaded( $form, $this_load, $global_load ) {
1238 906 global $frm_vars;
1239 907 $small_form = new stdClass();
1240 -
1241 908 foreach ( array( 'id', 'form_key', 'name' ) as $var ) {
1242 909 $small_form->{$var} = $form->{$var};
1243 910 unset( $var );
1244 911 }
@@ -1244,14 +911,14 @@
1244 911 }
1245 912
1246 913 $frm_vars['forms_loaded'][] = $small_form;
1247 914
1248 - if ( $this_load && ! $global_load ) {
915 + if ( $this_load && empty( $global_load ) ) {
1249 916 $global_load = true;
1250 917 $frm_vars['load_css'] = true;
1251 918 }
1252 919
1253 - return empty( $frm_vars['css_loaded'] ) && $global_load;
920 + return ( ( ! isset( $frm_vars['css_loaded'] ) || ! $frm_vars['css_loaded'] ) && $global_load );
1254 921 }
1255 922
1256 923 /**
1257 924 * @since 4.06.03
@@ -1259,9 +926,9 @@
1259 926 * @param object $form
1260 927 *
1261 928 * @return bool
1262 929 */
1263 - public static function is_visible_to_user( $form ) {
930 + public static function &is_visible_to_user( $form ) {
1264 931 if ( $form->logged_in && isset( $form->options['logged_in_role'] ) ) {
1265 932 $visible = FrmAppHelper::user_has_permission( $form->options['logged_in_role'] );
1266 933 } else {
1267 934 $visible = true;
@@ -1266,39 +933,26 @@
1266 933 } else {
1267 934 $visible = true;
1268 935 }
1269 936
1270 - /**
1271 - * @since 6.25
1272 - *
1273 - * @param bool $visible
1274 - * @param object $form
1275 - */
1276 - return (bool) apply_filters( 'frm_form_is_visible', $visible, $form );
937 + return $visible;
1277 938 }
1278 939
1279 - /**
1280 - * @param object $form
1281 - *
1282 - * @return bool
1283 - */
1284 940 public static function show_submit( $form ) {
1285 - $show = ! $form->is_template && $form->status === 'published' && ! FrmAppHelper::is_admin();
1286 - return apply_filters( 'frm_show_submit_button', $show, $form );
941 + $show = ( ! $form->is_template && $form->status == 'published' && ! FrmAppHelper::is_admin() );
942 + $show = apply_filters( 'frm_show_submit_button', $show, $form );
943 +
944 + return $show;
1287 945 }
1288 946
1289 947 /**
1290 948 * @since 2.3
1291 - *
1292 - * @param array $atts Attributes including form, option, and default.
1293 - *
1294 - * @return mixed
1295 949 */
1296 950 public static function get_option( $atts ) {
1297 - $form = $atts['form'];
1298 - $default = $atts['default'] ?? '';
951 + $form = $atts['form'];
952 + $default = isset( $atts['default'] ) ? $atts['default'] : '';
1299 953
1300 - return $form->options[ $atts['option'] ] ?? $default;
954 + return isset( $form->options[ $atts['option'] ] ) ? $form->options[ $atts['option'] ] : $default;
1301 955 }
1302 956
1303 957 /**
1304 958 * Get the link to edit this form.
@@ -1303,12 +957,9 @@
1303 957 /**
1304 958 * Get the link to edit this form.
1305 959 *
1306 960 * @since 4.0
1307 - *
1308 961 * @param int $form_id The id of the form.
1309 - *
1310 - * @return string
1311 962 */
1312 963 public static function get_edit_link( $form_id ) {
1313 964 return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id );
1314 965 }
@@ -1313,65 +964,9 @@
1313 964 return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id );
1314 965 }
1315 966
1316 967 /**
1317 - * Check if the "Submit this form with AJAX" setting is toggled on.
1318 - *
1319 - * @since 6.2
1320 - *
1321 - * @param stdClass $form
1322 - *
1323 - * @return bool
1324 - */
1325 - public static function is_ajax_on( $form ) {
1326 - return ! empty( $form->options['ajax_submit'] );
1327 - }
1328 -
1329 - /**
1330 - * Get the latest form available.
1331 - *
1332 - * @since 6.8
1333 - *
1334 - * @return object
1335 - */
1336 - public static function get_latest_form() {
1337 - $args = array(
1338 - array(
1339 - 'or' => 1,
1340 - 'parent_form_id' => null,
1341 - 'parent_form_id <' => 1,
1342 - ),
1343 - 'is_template' => 0,
1344 - 'status !' => 'trash',
1345 - );
1346 -
1347 - return self::getAll( $args, 'created_at desc', 1 );
1348 - }
1349 -
1350 - /**
1351 - * Count and return total forms.
1352 - *
1353 - * @since 6.8
1354 - *
1355 - * @return int
1356 - */
1357 - public static function get_forms_count() {
1358 - $args = array(
1359 - array(
1360 - 'or' => 1,
1361 - 'parent_form_id' => null,
1362 - 'parent_form_id <' => 1,
1363 - ),
1364 - 'is_template' => 0,
1365 - 'status !' => 'trash',
1366 - );
1367 -
1368 - return FrmDb::get_count( 'frm_forms', $args );
1369 - }
1370 -
1371 - /**
1372 - * @deprecated 2.03.05 This is still referenced in a few add ons (API, locations).
1373 - *
968 + * @deprecated 3.0
1374 969 * @codeCoverageIgnore
1375 970 *
1376 971 * @param string $key
1377 972 *
@@ -1377,22 +972,15 @@
1377 972 *
1378 973 * @return int form id
1379 974 */
1380 975 public static function getIdByKey( $key ) {
1381 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_id_by_key' );
1382 - return self::get_id_by_key( $key );
976 + return FrmFormDeprecated::getIdByKey( $key );
1383 977 }
1384 978
1385 979 /**
1386 - * @deprecated 2.03.05 This is still referenced in the API add on as of v1.13.
1387 - *
980 + * @deprecated 3.0
1388 981 * @codeCoverageIgnore
1389 - *
1390 - * @param int|string $id
1391 - *
1392 - * @return string
1393 982 */
1394 983 public static function getKeyById( $id ) {
1395 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_key_by_id' );
1396 - return self::get_key_by_id( $id );
984 + return FrmFormDeprecated::getKeyById( $id );
1397 985 }
1398 986 }