PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.0
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.0
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmForm.php +28 -200 6.45.0 View file →
@@ -5,16 +5,13 @@
5 5
6 6 class FrmForm {
7 7
8 8 /**
9 - * @param array $values
10 - * @return int|bool id on success or false on failure.
9 + * @return int|boolean id on success or false on failure
11 10 */
12 11 public static function create( $values ) {
13 12 global $wpdb;
14 13
15 - $values = FrmAppHelper::maybe_filter_array( $values, array( 'name', 'description' ) );
16 -
17 14 $new_values = array(
18 15 'form_key' => FrmAppHelper::get_unique_key( $values['form_key'], $wpdb->prefix . 'frm_forms', 'form_key' ),
19 16 'name' => $values['name'],
20 17 'description' => $values['description'],
@@ -32,21 +29,14 @@
32 29 $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
33 30 $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
34 31 $options['submit_html'] = isset( $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
35 32
36 - /**
37 - * Allows modifying form options before updating or creating.
38 - *
39 - * @since 5.4 Add the third param.
40 - *
41 - * @param array $options Form options.
42 - * @param array $values Form data.
43 - * @param bool $update Is form updating or creating. It's `true` if is updating.
44 - */
45 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, false );
46 - $options = self::maybe_filter_form_options( $options );
33 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
47 34 $new_values['options'] = serialize( $options );
48 35
36 + //if(isset($values['id']) && is_numeric($values['id']))
37 + // $new_values['id'] = $values['id'];
38 +
49 39 $wpdb->insert( $wpdb->prefix . 'frm_forms', $new_values );
50 40
51 41 $id = $wpdb->insert_id;
52 42
@@ -56,21 +46,8 @@
56 46 return $id;
57 47 }
58 48
59 49 /**
60 - * @since 5.0.08
61 - *
62 - * @param array $options
63 - * @return array
64 - */
65 - private static function maybe_filter_form_options( $options ) {
66 - if ( ! FrmAppHelper::allow_unfiltered_html() && ! empty( $options['submit_html'] ) ) {
67 - $options['submit_html'] = FrmAppHelper::kses_submit_button( $options['submit_html'] );
68 - }
69 - return FrmAppHelper::maybe_filter_array( $options, array( 'submit_value', 'success_msg', 'before_html', 'after_html' ) );
70 - }
71 -
72 - /**
73 50 * @return int|boolean ID on success or false on failure
74 51 */
75 52 public static function duplicate( $id, $template = false, $copy_keys = false, $blog_id = false ) {
76 53 global $wpdb;
@@ -140,93 +117,16 @@
140 117 if ( $new_opts != $values['options'] ) {
141 118 global $wpdb;
142 119 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'options' => maybe_serialize( $new_opts ) ), array( 'id' => $form_id ) );
143 120 }
144 -
145 - self::switch_field_ids_in_fields( $form_id );
146 121 }
147 122
148 123 /**
149 - * Switches field ID in fields.
150 - *
151 - * @since 5.3
152 - *
153 - * @param int $form_id Form ID.
154 - */
155 - private static function switch_field_ids_in_fields( $form_id ) {
156 - global $wpdb;
157 -
158 - // Keys of fields that you want to check to replace field ID.
159 - $keys = array( 'default_value', 'field_options' );
160 - $sql_cols = 'fi.id';
161 - foreach ( $keys as $key ) {
162 - $sql_cols .= ( ',fi.' . $key );
163 - }
164 -
165 - $fields = FrmDb::get_results(
166 - "{$wpdb->prefix}frm_fields AS fi LEFT OUTER JOIN {$wpdb->prefix}frm_forms AS fr ON fi.form_id = fr.id",
167 - array(
168 - 'or' => 1,
169 - 'fi.form_id' => $form_id,
170 - 'fr.parent_form_id' => $form_id,
171 - ),
172 - $sql_cols
173 - );
174 -
175 - if ( ! $fields || ! is_array( $fields ) ) {
176 - return;
177 - }
178 -
179 - foreach ( $fields as $field ) {
180 - self::switch_field_ids_in_field( (array) $field );
181 - }
182 - }
183 -
184 - /**
185 - * Switches field ID in a field.
186 - *
187 - * @since 5.3
188 - *
189 - * @param array $field Field array.
190 - */
191 - private static function switch_field_ids_in_field( $field ) {
192 - $new_values = array();
193 - foreach ( $field as $key => $value ) {
194 - if ( 'id' === $key || ! $value ) {
195 - continue;
196 - }
197 -
198 - if ( ! is_string( $value ) && ! is_array( $value ) ) {
199 - continue;
200 - }
201 -
202 - if ( 'field_options' === $key ) {
203 - // Need to loop through field_options to prevent breaking serialized string when length changed.
204 - FrmAppHelper::unserialize_or_decode( $value );
205 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
206 - $new_val = serialize( $new_val );
207 - } else {
208 - $new_val = FrmFieldsHelper::switch_field_ids( $value );
209 - }
210 -
211 - if ( $new_val !== $value ) {
212 - $new_values[ $key ] = $new_val;
213 - }
214 - }
215 -
216 - if ( ! empty( $new_values ) ) {
217 - FrmField::update( $field['id'], $new_values );
218 - }
219 - }
220 -
221 - /**
222 124 * @return int|boolean
223 125 */
224 126 public static function update( $id, $values, $create_link = false ) {
225 127 global $wpdb;
226 128
227 - $values = FrmAppHelper::maybe_filter_array( $values, array( 'name', 'description' ) );
228 -
229 129 if ( ! isset( $values['status'] ) && ( $create_link || isset( $values['options'] ) || isset( $values['item_meta'] ) || isset( $values['field_options'] ) ) ) {
230 130 $values['status'] = 'published';
231 131 }
232 132
@@ -235,9 +135,9 @@
235 135 }
236 136
237 137 $form_fields = array( 'form_key', 'name', 'description', 'status', 'parent_form_id' );
238 138
239 - $new_values = self::set_update_options( array(), $values, array( 'form_id' => $id ) );
139 + $new_values = self::set_update_options( array(), $values );
240 140
241 141 foreach ( $values as $value_key => $value ) {
242 142 if ( $value_key && in_array( $value_key, $form_fields ) ) {
243 143 $new_values[ $value_key ] = $value;
@@ -266,14 +166,11 @@
266 166 return $query_results;
267 167 }
268 168
269 169 /**
270 - * @param array $new_values
271 - * @param array $values
272 - * @param array $args
273 170 * @return array
274 171 */
275 - public static function set_update_options( $new_values, $values, $args = array() ) {
172 + public static function set_update_options( $new_values, $values ) {
276 173 if ( ! isset( $values['options'] ) ) {
277 174 return $new_values;
278 175 }
279 176
@@ -284,19 +181,9 @@
284 181 $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
285 182 $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
286 183 $options['submit_html'] = ( isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
287 184
288 - /**
289 - * Allows modifying form options before updating or creating.
290 - *
291 - * @since 5.4 Added the third param.
292 - *
293 - * @param array $options Form options.
294 - * @param array $values Form data.
295 - * @param bool $update Is form updating or creating. It's `true` if is updating.
296 - */
297 - $options = apply_filters( 'frm_form_options_before_update', $options, $values, true );
298 - $options = self::maybe_filter_form_options( $options );
185 + $options = apply_filters( 'frm_form_options_before_update', $options, $values );
299 186 $new_values['options'] = serialize( $options );
300 187
301 188 return $new_values;
302 189 }
@@ -365,18 +252,8 @@
365 252 'field_options' => $field->field_options,
366 253 'default_value' => isset( $values[ 'default_value_' . $field_id ] ) ? FrmAppHelper::maybe_json_encode( $values[ 'default_value_' . $field_id ] ) : '',
367 254 );
368 255
369 - if ( ! FrmAppHelper::allow_unfiltered_html() && isset( $values['field_options'][ 'options_' . $field_id ] ) && is_array( $values['field_options'][ 'options_' . $field_id ] ) ) {
370 - foreach ( $values['field_options'][ 'options_' . $field_id ] as $option_key => $option ) {
371 - if ( is_array( $option ) ) {
372 - foreach ( $option as $key => $item ) {
373 - $values['field_options'][ 'options_' . $field_id ][ $option_key ][ $key ] = FrmAppHelper::kses( $item, 'all' );
374 - }
375 - }
376 - }
377 - }
378 -
379 256 self::prepare_field_update_values( $field, $values, $new_field );
380 257
381 258 FrmField::update( $field_id, $new_field );
382 259
@@ -386,40 +263,17 @@
386 263
387 264 return $values;
388 265 }
389 266
390 - /**
391 - * @param string $opt
392 - * @param mixed $value
393 - * @return void
394 - */
395 267 private static function sanitize_field_opt( $opt, &$value ) {
396 - if ( ! is_string( $value ) ) {
397 - return;
268 + if ( is_string( $value ) ) {
269 + if ( $opt === 'calc' ) {
270 + $value = self::sanitize_calc( $value );
271 + } else {
272 + $value = FrmAppHelper::kses( $value, 'all' );
273 + }
274 + $value = trim( $value );
398 275 }
399 -
400 - /**
401 - * Allow the option to turn off sanitization for a field. This way a custom rule can be used instead.
402 - * Make sure to add custom sanitization using the frm_update_field_options filter as the data will no longer be sanitized.
403 - *
404 - * @since 6.0
405 - *
406 - * @param bool $should_sanitize
407 - * @param string $opt
408 - */
409 - $should_sanitize = apply_filters( 'frm_should_sanitize_field_opt_string', true, $opt );
410 -
411 - if ( ! $should_sanitize ) {
412 - return;
413 - }
414 -
415 - if ( $opt === 'calc' ) {
416 - $value = self::sanitize_calc( $value );
417 - } else {
418 - $value = FrmAppHelper::kses( $value, 'all' );
419 - }
420 -
421 - $value = trim( $value );
422 276 }
423 277
424 278 /**
425 279 * @param string $value
@@ -510,12 +364,8 @@
510 364 'description',
511 365 'submit_value',
512 366 'submit_msg',
513 367 'success_msg',
514 - 'invalid_msg',
515 - 'failed_msg',
516 - 'login_msg',
517 - 'admin_permission',
518 368 );
519 369
520 370 return apply_filters( 'frm_form_strings', $strings, $form );
521 371 }
@@ -545,9 +395,9 @@
545 395 );
546 396 FrmDb::get_where_clause_and_values( $where );
547 397 array_unshift( $where['values'], $status );
548 398
549 - $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
399 + $query_results = $wpdb->query( $wpdb->prepare( 'UPDATE ' . $wpdb->prefix . 'frm_forms SET status = %s ' . $where['where'], $where['values'] ) ); // WPCS: unprepared SQL ok.
550 400 } else {
551 401 $query_results = $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'id' => $id ) );
552 402 $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'status' => $status ), array( 'parent_form_id' => $id ) );
553 403 }
@@ -653,9 +503,9 @@
653 503
654 504 $trash_forms = FrmDb::get_results( $wpdb->prefix . 'frm_forms', array( 'status' => 'trash' ), 'id, options' );
655 505
656 506 if ( ! $trash_forms ) {
657 - return 0;
507 + return;
658 508 }
659 509
660 510 if ( empty( $delete_timestamp ) ) {
661 511 $delete_timestamp = time() - ( DAY_IN_SECONDS * EMPTY_TRASH_DAYS );
@@ -687,12 +537,10 @@
687 537 }
688 538
689 539 $query_key = is_numeric( $id ) ? 'id' : 'form_key';
690 540 $r = FrmDb::get_var( 'frm_forms', array( $query_key => $id ), 'name' );
541 + $r = stripslashes( $r );
691 542
692 - // An empty form name can result in a null value.
693 - $r = is_null( $r ) ? '' : stripslashes( $r );
694 -
695 543 return $r;
696 544 }
697 545
698 546 /**
@@ -756,9 +604,9 @@
756 604 if ( isset( $cache->options ) ) {
757 605 FrmAppHelper::unserialize_or_decode( $cache->options );
758 606 }
759 607
760 - return apply_filters( 'frm_form_object', wp_unslash( $cache ) );
608 + return wp_unslash( $cache );
761 609 }
762 610 }
763 611
764 612 if ( is_numeric( $id ) ) {
@@ -792,9 +640,9 @@
792 640 global $wpdb;
793 641
794 642 // the query has already been prepared if this is not an array
795 643 $query = 'SELECT * FROM ' . $wpdb->prefix . 'frm_forms' . FrmDb::prepend_and_or_where( ' WHERE ', $where ) . FrmDb::esc_order( $order_by ) . FrmDb::esc_limit( $limit );
796 - $results = $wpdb->get_results( $query ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
644 + $results = $wpdb->get_results( $query ); // WPCS: unprepared SQL ok.
797 645 }
798 646
799 647 if ( $results ) {
800 648 foreach ( $results as $result ) {
@@ -814,13 +662,9 @@
814 662 /**
815 663 * Get all published forms
816 664 *
817 665 * @since 2.0
818 - *
819 - * @param array $query
820 - * @param int $limit
821 - * @param string $inc_children
822 - * @return array|object of forms A single form object would be passed if $limit was set to 1.
666 + * @return array of forms
823 667 */
824 668 public static function get_published_forms( $query = array(), $limit = 999, $inc_children = 'exclude' ) {
825 669 $query['is_template'] = 0;
826 670 $query['status'] = array( null, '', 'published' );
@@ -915,9 +759,9 @@
915 759 if ( isset( $frm_vars['form_params'] ) && is_array( $frm_vars['form_params'] ) && isset( $frm_vars['form_params'][ $form->id ] ) ) {
916 760 return $frm_vars['form_params'][ $form->id ];
917 761 }
918 762
919 - $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // phpcs:ignore WordPress.Security.NonceVerification.Missing
763 + $action_var = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action'; // WPCS: CSRF ok.
920 764 $action = apply_filters( 'frm_show_new_entry_page', FrmAppHelper::get_param( $action_var, 'new', 'get', 'sanitize_title' ), $form );
921 765
922 766 $default_values = array(
923 767 'id' => '',
@@ -955,9 +799,9 @@
955 799 }
956 800 }
957 801
958 802 if ( in_array( $values['action'], array( 'create', 'update' ) ) &&
959 - ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // phpcs:ignore WordPress.Security.NonceVerification.Missing
803 + ( ! $_POST || ( ! isset( $_POST['action'] ) && ! isset( $_POST['frm_action'] ) ) ) // WPCS: CSRF ok.
960 804 ) {
961 805 $values['action'] = 'new';
962 806 }
963 807
@@ -1120,39 +964,23 @@
1120 964 return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id );
1121 965 }
1122 966
1123 967 /**
1124 - * Check if the "Submit this form with AJAX" setting is toggled on.
1125 - *
1126 - * @since 6.2
1127 - *
1128 - * @param stdClass $form
1129 - * @return bool
1130 - */
1131 - public static function is_ajax_on( $form ) {
1132 - return ! empty( $form->options['ajax_submit'] );
1133 - }
1134 -
1135 - /**
1136 - * @deprecated 2.03.05 This is still referenced in a few add ons (API, locations).
968 + * @deprecated 3.0
1137 969 * @codeCoverageIgnore
1138 970 *
1139 971 * @param string $key
972 + *
1140 973 * @return int form id
1141 974 */
1142 975 public static function getIdByKey( $key ) {
1143 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_id_by_key' );
1144 - return self::get_id_by_key( $key );
976 + return FrmFormDeprecated::getIdByKey( $key );
1145 977 }
1146 978
1147 979 /**
1148 - * @deprecated 2.03.05 This is still referenced in the API add on as of v1.13.
980 + * @deprecated 3.0
1149 981 * @codeCoverageIgnore
1150 - *
1151 - * @param string|int $id
1152 - * @return string
1153 982 */
1154 983 public static function getKeyById( $id ) {
1155 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_key_by_id' );
1156 - return self::get_key_by_id( $id );
984 + return FrmFormDeprecated::getKeyById( $id );
1157 985 }
1158 986 }