PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.0
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.0
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmStyle.php +37 -330 6.45.0 View file →
@@ -13,11 +13,8 @@
13 13 public function __construct( $id = 0 ) {
14 14 $this->id = $id;
15 15 }
16 16
17 - /**
18 - * @return stdClass
19 - */
20 17 public function get_new() {
21 18 $this->id = 0;
22 19
23 20 $max_slug_value = 2147483647;
@@ -36,33 +33,20 @@
36 33
37 34 return (object) $style;
38 35 }
39 36
40 - /**
41 - * @param array $settings
42 - * @return int|WP_Error
43 - */
44 37 public function save( $settings ) {
45 38 return FrmDb::save_settings( $settings, 'frm_styles' );
46 39 }
47 40
48 - /**
49 - * @return void
50 - */
51 41 public function duplicate( $id ) {
52 - // Duplicating is a pro feature. This is handled in FrmProStyle::duplicate instead.
42 + // duplicating is a pro feature
53 43 }
54 44
55 - /**
56 - * Handle save actions in the visual styler edit page.
57 - *
58 - * @param mixed $id
59 - * @return array<int|WP_Error>
60 - */
61 45 public function update( $id = 'default' ) {
62 46 $all_instances = $this->get_all();
63 47
64 - if ( ! $id ) {
48 + if ( empty( $id ) ) {
65 49 $new_style = (array) $this->get_new();
66 50 $all_instances[] = $new_style;
67 51 }
68 52
@@ -70,33 +54,31 @@
70 54
71 55 foreach ( $all_instances as $number => $new_instance ) {
72 56 $new_instance = (array) $new_instance;
73 57 $this->id = $new_instance['ID'];
58 + if ( $id != $this->id || ! $_POST || ! isset( $_POST['frm_style_setting'] ) ) {
59 + $all_instances[ $number ] = $new_instance;
74 60
75 - if ( $id != $this->id || ! $_POST || ! isset( $_POST['frm_style_setting'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
76 - // Don't continue if not saving this style.
61 + if ( $new_instance['menu_order'] && $_POST && empty( $_POST['prev_menu_order'] ) && isset( $_POST['frm_style_setting']['menu_order'] ) ) {
62 + // this style was set to default, so remove default setting on previous default style
63 + $new_instance['menu_order'] = 0;
64 + $action_ids[] = $this->save( $new_instance );
65 + }
66 +
67 + // don't continue if not saving this style
77 68 continue;
78 69 }
79 70
80 - // Custom CSS is no longer used from the default style, but it is still checked if the Global Setting is missing.
81 - // Preserve the previous value in case Custom CSS has not been saved as a Global Setting yet.
82 - $custom_css = isset( $new_instance['post_content']['custom_css'] ) ? $new_instance['post_content']['custom_css'] : '';
71 + $new_instance['post_title'] = isset( $_POST['frm_style_setting']['post_title'] ) ? sanitize_text_field( wp_unslash( $_POST['frm_style_setting']['post_title'] ) ) : '';
83 72
84 - // phpcs:ignore WordPress.Security.NonceVerification.Missing
85 - if ( ! empty( $_POST['frm_style_setting']['post_title'] ) ) {
86 - // The nonce check happens in FrmStylesController::save_style before this is called.
87 - // phpcs:ignore WordPress.Security.NonceVerification.Missing
88 - $new_instance['post_title'] = sanitize_text_field( wp_unslash( $_POST['frm_style_setting']['post_title'] ) );
89 - }
90 -
91 - $new_instance['post_content'] = isset( $_POST['frm_style_setting']['post_content'] ) ? $this->sanitize_post_content( wp_unslash( $_POST['frm_style_setting']['post_content'] ) ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.NonceVerification.Missing
92 - $new_instance['post_content']['custom_css'] = $custom_css;
93 - unset( $custom_css );
94 -
73 + // Don't wp_unslash yet since it removes backslashes.
74 + $new_instance['post_content'] = isset( $_POST['frm_style_setting']['post_content'] ) ? $_POST['frm_style_setting']['post_content'] : ''; // WPCS: sanitization ok.
75 + FrmAppHelper::sanitize_value( 'sanitize_textarea_field', $new_instance['post_content'] );
95 76 $new_instance['post_type'] = FrmStylesController::$post_type;
96 77 $new_instance['post_status'] = 'publish';
78 + $new_instance['menu_order'] = isset( $_POST['frm_style_setting']['menu_order'] ) ? absint( $_POST['frm_style_setting']['menu_order'] ) : 0;
97 79
98 - if ( ! $id ) {
80 + if ( empty( $id ) ) {
99 81 $new_instance['post_name'] = $new_instance['post_title'];
100 82 }
101 83
102 84 $default_settings = $this->get_defaults();
@@ -106,22 +88,22 @@
106 88 $new_instance['post_content'][ $setting ] = $default;
107 89 }
108 90
109 91 if ( $this->is_color( $setting ) ) {
110 - $color_val = $new_instance['post_content'][ $setting ];
111 - if ( $color_val !== '' && false !== strpos( $color_val, 'rgb' ) ) {
112 - // Maybe sanitize if invalid rgba value is entered.
113 - $this->maybe_sanitize_rgba_value( $color_val );
114 - }
115 - $new_instance['post_content'][ $setting ] = str_replace( '#', '', $color_val );
116 - } elseif ( in_array( $setting, array( 'submit_style', 'important_style', 'auto_width' ), true ) && ! isset( $new_instance['post_content'][ $setting ] ) ) {
92 + $new_instance['post_content'][ $setting ] = str_replace( '#', '', $new_instance['post_content'][ $setting ] );
93 + } elseif ( in_array( $setting, array( 'submit_style', 'important_style', 'auto_width' ) )
94 + && ! isset( $new_instance['post_content'][ $setting ] )
95 + ) {
117 96 $new_instance['post_content'][ $setting ] = 0;
118 - } elseif ( $setting === 'font' ) {
97 + } elseif ( $setting == 'font' ) {
119 98 $new_instance['post_content'][ $setting ] = $this->force_balanced_quotation( $new_instance['post_content'][ $setting ] );
120 99 }
121 100 }
122 101
102 + $all_instances[ $number ] = $new_instance;
103 +
123 104 $action_ids[] = $this->save( $new_instance );
105 +
124 106 }
125 107
126 108 $this->save_settings();
127 109
@@ -128,238 +110,18 @@
128 110 return $action_ids;
129 111 }
130 112
131 113 /**
132 - * Sanitize custom color values and convert it to valid one filling missing values.
133 - *
134 - * @since 5.3.2
135 - *
136 - * @param string $color_val, The color value, by reference.
137 - * @return void
138 - */
139 - private function maybe_sanitize_rgba_value( &$color_val ) {
140 - if ( preg_match( '/(rgb|rgba)\(/', $color_val ) !== 1 ) {
141 - return;
142 - }
143 -
144 - $color_val = trim( $color_val );
145 - $color_val = ltrim( $color_val, '(' ); // Remove leading braces so (rgba(1,1,1,1) doesn't cause inconsistent braces.
146 - $patterns = array( '/rgba\((\s*\d+\s*,){3}[[0-1]\.]+\)/', '/rgb\((\s*\d+\s*,){2}\s*[\d]+\)/' );
147 - foreach ( $patterns as $pattern ) {
148 - if ( preg_match( $pattern, $color_val ) === 1 ) {
149 - return;
150 - }
151 - }
152 -
153 - // Remove all leading ')' braces, then add one back. This way there's always a single brace.
154 - $color_val = rtrim( $color_val, ')' );
155 - $color_val .= ')';
156 -
157 - $color_rgba = substr( $color_val, strpos( $color_val, '(' ) + 1, strlen( $color_val ) - strpos( $color_val, '(' ) - 2 );
158 - $color_rgba = trim( $color_rgba, '()' ); // Remove any excessive braces from the rgba like rgba((.
159 - $length_of_color_codes = strpos( $color_val, '(' );
160 - $new_color_values = array();
161 -
162 - // replace empty values by 0 or 1 (if alpha position).
163 - foreach ( explode( ',', $color_rgba ) as $index => $value ) {
164 - $new_value = null;
165 - $value_is_empty_string = '' === trim( $value ) || '' === $value;
166 -
167 - if ( 3 === $length_of_color_codes || ( $index !== $length_of_color_codes - 1 ) ) {
168 - // Insert a value for r, g, or b.
169 - if ( $value < 0 ) {
170 - $new_value = 0;
171 - } elseif ( $value > 255 ) {
172 - $new_value = 255;
173 - } elseif ( $value_is_empty_string ) {
174 - $new_value = 0;
175 - } else {
176 - $new_value = absint( $value );
177 - }
178 - } else {
179 - // Insert a value for alpha.
180 - if ( $value_is_empty_string ) {
181 - $new_value = 4 === $length_of_color_codes ? 1 : 0;
182 - } elseif ( $value > 1 || $value < 0 ) {
183 - $new_value = 1;
184 - } else {
185 - $new_value = floatval( $value );
186 - }
187 - }
188 -
189 - $new_color_values[] = null === $new_value ? $value : $new_value;
190 - }
191 -
192 - // add more 0s and 1 (if alpha position) if needed.
193 - $missing_values = $length_of_color_codes - count( $new_color_values );
194 - if ( $missing_values > 1 ) {
195 - $insert_values = array_fill( 0, $missing_values - 1, 0 );
196 - $last_value = 4 === $length_of_color_codes ? 1 : 0;
197 - array_push( $insert_values, $last_value );
198 - } elseif ( $missing_values === 1 ) {
199 - $insert_values = 4 === $length_of_color_codes ? array( 1 ) : array( 0 );
200 - }
201 - if ( ! empty( $insert_values ) ) {
202 - $new_color_values = array_merge( $new_color_values, $insert_values );
203 - }
204 -
205 - $new_color = implode( ',', $new_color_values );
206 - $prefix = substr( $color_val, 0, strpos( $color_val, '(' ) + 1 );
207 - $prefix = rtrim( $prefix, '(' ) . '('; // Limit the number of opening braces after rgb/rgba. There should only be one.
208 - $new_color = $prefix . $new_color . ')';
209 -
210 - $color_val = $new_color;
211 - }
212 -
213 - /**
214 - * Unslash everything in post_content but custom_css
215 - *
216 - * @since 5.0.13
217 - *
218 - * @param array $settings
219 - * @return array
220 - */
221 - private function unslash_post_content( $settings ) {
222 - $custom_css = isset( $settings['custom_css'] ) ? $settings['custom_css'] : '';
223 - $settings = wp_unslash( $settings );
224 - $settings['custom_css'] = $custom_css;
225 - return $settings;
226 - }
227 -
228 - /**
229 - * @since 5.0.13
230 - *
231 - * @param array $settings
232 - * @return array
233 - */
234 - public function sanitize_post_content( $settings ) {
235 - $defaults = $this->get_defaults();
236 - $valid_keys = array_keys( $defaults );
237 - $sanitized_settings = array();
238 - foreach ( $valid_keys as $key ) {
239 - if ( isset( $settings[ $key ] ) ) {
240 - $sanitized_settings[ $key ] = sanitize_textarea_field( $settings[ $key ] );
241 - } else {
242 - $sanitized_settings[ $key ] = $defaults[ $key ];
243 - }
244 -
245 - if ( 'custom_css' !== $key ) {
246 - $sanitized_settings[ $key ] = $this->strip_invalid_characters( $sanitized_settings[ $key ] );
247 - }
248 - }
249 - return $sanitized_settings;
250 - }
251 -
252 - /**
253 - * Remove any characters that should not be used in CSS.
254 - *
255 - * @since 6.2.3
256 - *
257 - * @param string $setting
258 - * @return string
259 - */
260 - private function strip_invalid_characters( $setting ) {
261 - $characters_to_remove = array( '{', '}', ';', '[', ']' );
262 -
263 - // RGB is handled instead in self::maybe_sanitize_rgba_value.
264 - if ( 0 !== strpos( $setting, 'rgb' ) ) {
265 - $setting = $this->maybe_fix_braces( $setting, $characters_to_remove );
266 - }
267 -
268 - return str_replace( $characters_to_remove, '', $setting );
269 - }
270 -
271 - /**
272 - * @since 6.2.3
273 - *
274 - * @param string $setting
275 - * @param array $characters_to_remove
276 - * @return string
277 - */
278 - private function maybe_fix_braces( $setting, &$characters_to_remove ) {
279 - $number_of_opening_braces = substr_count( $setting, '(' );
280 - $number_of_closing_braces = substr_count( $setting, ')' );
281 -
282 - if ( $number_of_opening_braces === $number_of_closing_braces ) {
283 - return $this->trim_braces( $setting );
284 - }
285 -
286 - if ( $this->should_remove_every_brace( $setting ) ) {
287 - // Add to $characters_to_remove to remove when str_replace is called.
288 - array_push( $characters_to_remove, '(', ')' );
289 - return $setting;
290 - }
291 -
292 - return $this->trim_braces( $setting );
293 - }
294 -
295 - /**
296 - * @since 6.2.3
297 - *
298 - * @param string $input
299 - * @return string
300 - */
301 - private function trim_braces( $input ) {
302 - $output = $input;
303 - // Remove any ( from the start of the string as no CSS values expect at the first character.
304 - if ( $output ) {
305 - if ( in_array( $output[0], array( '(', ')' ), true ) ) {
306 - $output = ltrim( $output, '()' );
307 - }
308 - }
309 - // Remove extra braces from the end.
310 - if ( in_array( substr( $output, -1 ), array( '(', ')' ), true ) ) {
311 - $output = rtrim( $output, '()' );
312 - if ( false !== strpos( $output, '(' ) ) {
313 - $output .= ')';
314 - }
315 - }
316 - return $output;
317 - }
318 -
319 - /**
320 - * @since 6.2.3
321 - *
322 - * @param string $setting
323 - * @return bool
324 - */
325 - private function should_remove_every_brace( $setting ) {
326 - if ( 0 === strpos( trim( $setting, '()' ), 'calc' ) ) {
327 - // Support calc() sizes. We do not want to remove all braces when calc is used.
328 - return false;
329 - }
330 -
331 - // Matches hex values but also checks for unexpected ( and ).
332 - $looks_like_a_hex_value = preg_match( '/^(?:\()?(?!#?[a-fA-F0-9]*[^\(#\)\da-fA-F])[a-fA-F0-9\(\)]*(?:\))?$/', $setting );
333 - if ( $looks_like_a_hex_value ) {
334 - return true;
335 - }
336 -
337 - // Matches size values but also checks for unexpected ( and ).
338 - // This is case insensitive so it will catch PX, PT, etc, as well.
339 - $looks_like_a_size = preg_match( '/\(?[+-]?\d*\.?\d+(?:px|%|em|rem|ex|pt|pc|mm|cm|in)\)?/i', $setting );
340 - if ( $looks_like_a_size ) {
341 - return true;
342 - }
343 -
344 - return false;
345 - }
346 -
347 - /**
348 114 * @since 3.01.01
349 - *
350 - * @param string $setting
351 - * @return bool
352 115 */
353 116 private function is_color( $setting ) {
354 117 $extra_colors = array( 'error_bg', 'error_border', 'error_text' );
355 - return strpos( $setting, 'color' ) !== false || in_array( $setting, $extra_colors, true );
118 +
119 + return strpos( $setting, 'color' ) !== false || in_array( $setting, $extra_colors );
356 120 }
357 121
358 122 /**
359 123 * @since 3.01.01
360 - *
361 - * @return array
362 124 */
363 125 public function get_color_settings() {
364 126 $defaults = $this->get_defaults();
365 127 $settings = array_keys( $defaults );
@@ -367,11 +129,9 @@
367 129 return array_filter( $settings, array( $this, 'is_color' ) );
368 130 }
369 131
370 132 /**
371 - * Create static CSS file and update the CSS transient alternative.
372 - *
373 - * @return void
133 + * Create static css file
374 134 */
375 135 public function save_settings() {
376 136 $filename = FrmAppHelper::plugin_path() . '/css/custom_theme.css.php';
377 137 update_option( 'frm_last_style_update', gmdate( 'njGi' ) );
@@ -381,9 +141,10 @@
381 141 }
382 142
383 143 $this->clear_cache();
384 144
385 - $css = $this->get_css_content( $filename );
145 + $css = $this->get_css_content( $filename );
146 +
386 147 $create_file = new FrmCreateFile(
387 148 array(
388 149 'file_name' => FrmStylesController::get_file_name(),
389 150 'new_file_path' => FrmAppHelper::plugin_path() . '/css',
@@ -394,12 +155,8 @@
394 155 update_option( 'frmpro_css', $css, 'no' );
395 156 set_transient( 'frmpro_css', $css, MONTH_IN_SECONDS );
396 157 }
397 158
398 - /**
399 - * @param string $filename
400 - * @return string
401 - */
402 159 private function get_css_content( $filename ) {
403 160 $css = '/* ' . __( 'WARNING: Any changes made to this file will be lost when your Formidable settings are updated', 'formidable' ) . ' */' . "\n";
404 161
405 162 $saving = true;
@@ -405,9 +162,9 @@
405 162 $saving = true;
406 163 $frm_style = $this;
407 164
408 165 ob_start();
409 - include $filename;
166 + include( $filename );
410 167 $css .= preg_replace( '/\/\*(.|\s)*?\*\//', '', str_replace( array( "\r\n", "\r", "\n", "\t", ' ' ), '', ob_get_contents() ) );
411 168 ob_end_clean();
412 169
413 170 return FrmStylesController::replace_relative_url( $css );
@@ -412,11 +169,8 @@
412 169
413 170 return FrmStylesController::replace_relative_url( $css );
414 171 }
415 172
416 - /**
417 - * @return void
418 - */
419 173 private function clear_cache() {
420 174 $default_post_atts = array(
421 175 'post_type' => FrmStylesController::$post_type,
422 176 'post_status' => 'publish',
@@ -429,26 +183,14 @@
429 183 FrmDb::cache_delete_group( 'frm_styles' );
430 184 FrmDb::delete_cache_and_transient( 'frmpro_css' );
431 185 }
432 186
433 - /**
434 - * Delete a style by its post ID.
435 - *
436 - * @param int $id
437 - * @return WP_Post|false|null
438 - */
439 187 public function destroy( $id ) {
440 - if ( $id === $this->get_default_style()->ID ) {
441 - return false;
442 - }
443 188 return wp_delete_post( $id );
444 189 }
445 190
446 - /**
447 - * @return WP_Post|stdClass
448 - */
449 191 public function get_one() {
450 - if ( 'default' === $this->id ) {
192 + if ( 'default' == $this->id ) {
451 193 $style = $this->get_default_style();
452 194 if ( $style ) {
453 195 $this->id = $style->ID;
454 196 } else {
@@ -474,14 +216,8 @@
474 216
475 217 return $style;
476 218 }
477 219
478 - /**
479 - * @param string $orderby
480 - * @param string $order
481 - * @param int $limit
482 - * @return array
483 - */
484 220 public function get_all( $orderby = 'title', $order = 'ASC', $limit = 99 ) {
485 221 $post_atts = array(
486 222 'post_type' => FrmStylesController::$post_type,
487 223 'post_status' => 'publish',
@@ -546,11 +282,8 @@
546 282
547 283 return $styles;
548 284 }
549 285
550 - /**
551 - * @param array|null $styles
552 - */
553 286 public function get_default_style( $styles = null ) {
554 287 if ( ! isset( $styles ) ) {
555 288 $styles = $this->get_all( 'menu_order', 'DESC', 1 );
556 289 }
@@ -561,12 +294,8 @@
561 294 }
562 295 }
563 296 }
564 297
565 - /**
566 - * @param mixed $settings
567 - * @return mixed
568 - */
569 298 public function override_defaults( $settings ) {
570 299 if ( ! is_array( $settings ) ) {
571 300 return $settings;
572 301 }
@@ -596,11 +325,8 @@
596 325
597 326 return apply_filters( 'frm_override_default_styles', $settings );
598 327 }
599 328
600 - /**
601 - * @return array
602 - */
603 329 public function get_defaults() {
604 330 $defaults = array(
605 331 'theme_css' => 'ui-lightness',
606 332 'theme_name' => 'UI Lightness',
@@ -623,9 +349,9 @@
623 349 'form_desc_margin_top' => '10px',
624 350 'form_desc_margin_bottom' => '25px',
625 351 'form_desc_padding' => '0',
626 352
627 - 'font' => '',
353 + 'font' => '"Lucida Grande","Lucida Sans Unicode",Tahoma,sans-serif',
628 354 'font_size' => '15px',
629 355 'label_color' => '3f4b5b',
630 356 'weight' => 'normal',
631 357 'position' => 'none',
@@ -732,9 +458,9 @@
732 458 'progress_active_bg_color' => '579AF6',
733 459 'progress_color' => '3f4b5b',
734 460 'progress_border_color' => 'E5E5E5',
735 461 'progress_border_size' => '2px',
736 - 'progress_size' => '24px',
462 + 'progress_size' => '30px',
737 463
738 464 'custom_css' => '',
739 465 );
740 466
@@ -740,22 +466,12 @@
740 466
741 467 return apply_filters( 'frm_default_style_settings', $defaults );
742 468 }
743 469
744 - /**
745 - * Get a name attribute value for a style setting input.
746 - *
747 - * @param string $field_name
748 - * @param string $post_field
749 - * @return string
750 - */
751 470 public function get_field_name( $field_name, $post_field = 'post_content' ) {
752 471 return 'frm_style_setting' . ( empty( $post_field ) ? '' : '[' . $post_field . ']' ) . '[' . $field_name . ']';
753 472 }
754 473
755 - /**
756 - * @return array
757 - */
758 474 public static function get_bold_options() {
759 475 return array(
760 476 100 => 100,
761 477 200 => 200,
@@ -769,12 +485,9 @@
769 485 );
770 486 }
771 487
772 488 /**
773 - * Don't let imbalanced font families ruin the whole stylesheet.
774 - *
775 - * @param string $value
776 - * @return string
489 + * Don't let imbalanced font families ruin the whole stylesheet
777 490 */
778 491 public function force_balanced_quotation( $value ) {
779 492 $balanced_characters = array( '"', "'" );
780 493 foreach ( $balanced_characters as $char ) {
@@ -779,18 +492,12 @@
779 492 $balanced_characters = array( '"', "'" );
780 493 foreach ( $balanced_characters as $char ) {
781 494 $char_count = substr_count( $value, $char );
782 495 $is_balanced = $char_count % 2 == 0;
783 -
784 - if ( $is_balanced ) {
785 - continue;
786 - }
787 -
788 - if ( $value && $char === $value[ strlen( $value ) - 1 ] ) {
789 - $value = $char . $value;
790 - } else {
496 + if ( ! $is_balanced ) {
791 497 $value .= $char;
792 498 }
793 499 }
500 +
794 501 return $value;
795 502 }
796 503 }