| @@ -6,9 +6,9 @@ | ||
| 6 | 6 | class FrmForm { |
| 7 | 7 | |
| 8 | 8 | /** |
| 9 | 9 | * @param array $values |
| 10 | - * @return int|bool id on success or false on failure. | |
| 10 | + * @return int|boolean id on success or false on failure | |
| 11 | 11 | */ |
| 12 | 12 | public static function create( $values ) { |
| 13 | 13 | global $wpdb; |
| 14 | 14 | |
| @@ -32,18 +32,9 @@ | ||
| 32 | 32 | $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' ); |
| 33 | 33 | $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' ); |
| 34 | 34 | $options['submit_html'] = isset( $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' ); |
| 35 | 35 | |
| 36 | - /** | |
| 37 | - * Allows modifying form options before updating or creating. | |
| 38 | - * | |
| 39 | - * @since 5.4 Add the third param. | |
| 40 | - * | |
| 41 | - * @param array $options Form options. | |
| 42 | - * @param array $values Form data. | |
| 43 | - * @param bool $update Is form updating or creating. It's `true` if is updating. | |
| 44 | - */ | |
| 45 | - $options = apply_filters( 'frm_form_options_before_update', $options, $values, false ); | |
| 36 | + $options = apply_filters( 'frm_form_options_before_update', $options, $values ); | |
| 46 | 37 | $options = self::maybe_filter_form_options( $options ); |
| 47 | 38 | $new_values['options'] = serialize( $options ); |
| 48 | 39 | |
| 49 | 40 | $wpdb->insert( $wpdb->prefix . 'frm_forms', $new_values ); |
| @@ -140,86 +131,11 @@ | ||
| 140 | 131 | if ( $new_opts != $values['options'] ) { |
| 141 | 132 | global $wpdb; |
| 142 | 133 | $wpdb->update( $wpdb->prefix . 'frm_forms', array( 'options' => maybe_serialize( $new_opts ) ), array( 'id' => $form_id ) ); |
| 143 | 134 | } |
| 144 | - | |
| 145 | - self::switch_field_ids_in_fields( $form_id ); | |
| 146 | 135 | } |
| 147 | 136 | |
| 148 | 137 | /** |
| 149 | - * Switches field ID in fields. | |
| 150 | - * | |
| 151 | - * @since 5.3 | |
| 152 | - * | |
| 153 | - * @param int $form_id Form ID. | |
| 154 | - */ | |
| 155 | - private static function switch_field_ids_in_fields( $form_id ) { | |
| 156 | - global $wpdb; | |
| 157 | - | |
| 158 | - // Keys of fields that you want to check to replace field ID. | |
| 159 | - $keys = array( 'default_value', 'field_options' ); | |
| 160 | - $sql_cols = 'fi.id'; | |
| 161 | - foreach ( $keys as $key ) { | |
| 162 | - $sql_cols .= ( ',fi.' . $key ); | |
| 163 | - } | |
| 164 | - | |
| 165 | - $fields = FrmDb::get_results( | |
| 166 | - "{$wpdb->prefix}frm_fields AS fi LEFT OUTER JOIN {$wpdb->prefix}frm_forms AS fr ON fi.form_id = fr.id", | |
| 167 | - array( | |
| 168 | - 'or' => 1, | |
| 169 | - 'fi.form_id' => $form_id, | |
| 170 | - 'fr.parent_form_id' => $form_id, | |
| 171 | - ), | |
| 172 | - $sql_cols | |
| 173 | - ); | |
| 174 | - | |
| 175 | - if ( ! $fields || ! is_array( $fields ) ) { | |
| 176 | - return; | |
| 177 | - } | |
| 178 | - | |
| 179 | - foreach ( $fields as $field ) { | |
| 180 | - self::switch_field_ids_in_field( (array) $field ); | |
| 181 | - } | |
| 182 | - } | |
| 183 | - | |
| 184 | - /** | |
| 185 | - * Switches field ID in a field. | |
| 186 | - * | |
| 187 | - * @since 5.3 | |
| 188 | - * | |
| 189 | - * @param array $field Field array. | |
| 190 | - */ | |
| 191 | - private static function switch_field_ids_in_field( $field ) { | |
| 192 | - $new_values = array(); | |
| 193 | - foreach ( $field as $key => $value ) { | |
| 194 | - if ( 'id' === $key || ! $value ) { | |
| 195 | - continue; | |
| 196 | - } | |
| 197 | - | |
| 198 | - if ( ! is_string( $value ) && ! is_array( $value ) ) { | |
| 199 | - continue; | |
| 200 | - } | |
| 201 | - | |
| 202 | - if ( 'field_options' === $key ) { | |
| 203 | - // Need to loop through field_options to prevent breaking serialized string when length changed. | |
| 204 | - FrmAppHelper::unserialize_or_decode( $value ); | |
| 205 | - $new_val = FrmFieldsHelper::switch_field_ids( $value ); | |
| 206 | - $new_val = serialize( $new_val ); | |
| 207 | - } else { | |
| 208 | - $new_val = FrmFieldsHelper::switch_field_ids( $value ); | |
| 209 | - } | |
| 210 | - | |
| 211 | - if ( $new_val !== $value ) { | |
| 212 | - $new_values[ $key ] = $new_val; | |
| 213 | - } | |
| 214 | - } | |
| 215 | - | |
| 216 | - if ( ! empty( $new_values ) ) { | |
| 217 | - FrmField::update( $field['id'], $new_values ); | |
| 218 | - } | |
| 219 | - } | |
| 220 | - | |
| 221 | - /** | |
| 222 | 138 | * @return int|boolean |
| 223 | 139 | */ |
| 224 | 140 | public static function update( $id, $values, $create_link = false ) { |
| 225 | 141 | global $wpdb; |
| @@ -284,18 +200,14 @@ | ||
| 284 | 200 | $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' ); |
| 285 | 201 | $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' ); |
| 286 | 202 | $options['submit_html'] = ( isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' ); |
| 287 | 203 | |
| 288 | - /** | |
| 289 | - * Allows modifying form options before updating or creating. | |
| 290 | - * | |
| 291 | - * @since 5.4 Added the third param. | |
| 292 | - * | |
| 293 | - * @param array $options Form options. | |
| 294 | - * @param array $values Form data. | |
| 295 | - * @param bool $update Is form updating or creating. It's `true` if is updating. | |
| 296 | - */ | |
| 297 | - $options = apply_filters( 'frm_form_options_before_update', $options, $values, true ); | |
| 204 | + if ( ! empty( $options['success_url'] ) && ! empty( $args['form_id'] ) ) { | |
| 205 | + $options['success_url'] = FrmFormsHelper::maybe_add_sanitize_url_attr( $options['success_url'], (int) $args['form_id'] ); | |
| 206 | + $values['options']['success_url'] = $options['success_url']; | |
| 207 | + } | |
| 208 | + | |
| 209 | + $options = apply_filters( 'frm_form_options_before_update', $options, $values ); | |
| 298 | 210 | $options = self::maybe_filter_form_options( $options ); |
| 299 | 211 | $new_values['options'] = serialize( $options ); |
| 300 | 212 | |
| 301 | 213 | return $new_values; |
| @@ -365,18 +277,8 @@ | ||
| 365 | 277 | 'field_options' => $field->field_options, |
| 366 | 278 | 'default_value' => isset( $values[ 'default_value_' . $field_id ] ) ? FrmAppHelper::maybe_json_encode( $values[ 'default_value_' . $field_id ] ) : '', |
| 367 | 279 | ); |
| 368 | 280 | |
| 369 | - if ( ! FrmAppHelper::allow_unfiltered_html() && isset( $values['field_options'][ 'options_' . $field_id ] ) && is_array( $values['field_options'][ 'options_' . $field_id ] ) ) { | |
| 370 | - foreach ( $values['field_options'][ 'options_' . $field_id ] as $option_key => $option ) { | |
| 371 | - if ( is_array( $option ) ) { | |
| 372 | - foreach ( $option as $key => $item ) { | |
| 373 | - $values['field_options'][ 'options_' . $field_id ][ $option_key ][ $key ] = FrmAppHelper::kses( $item, 'all' ); | |
| 374 | - } | |
| 375 | - } | |
| 376 | - } | |
| 377 | - } | |
| 378 | - | |
| 379 | 281 | self::prepare_field_update_values( $field, $values, $new_field ); |
| 380 | 282 | |
| 381 | 283 | FrmField::update( $field_id, $new_field ); |
| 382 | 284 | |
| @@ -386,40 +288,17 @@ | ||
| 386 | 288 | |
| 387 | 289 | return $values; |
| 388 | 290 | } |
| 389 | 291 | |
| 390 | - /** | |
| 391 | - * @param string $opt | |
| 392 | - * @param mixed $value | |
| 393 | - * @return void | |
| 394 | - */ | |
| 395 | 292 | private static function sanitize_field_opt( $opt, &$value ) { |
| 396 | - if ( ! is_string( $value ) ) { | |
| 397 | - return; | |
| 293 | + if ( is_string( $value ) ) { | |
| 294 | + if ( $opt === 'calc' ) { | |
| 295 | + $value = self::sanitize_calc( $value ); | |
| 296 | + } else { | |
| 297 | + $value = FrmAppHelper::kses( $value, 'all' ); | |
| 298 | + } | |
| 299 | + $value = trim( $value ); | |
| 398 | 300 | } |
| 399 | - | |
| 400 | - /** | |
| 401 | - * Allow the option to turn off sanitization for a field. This way a custom rule can be used instead. | |
| 402 | - * Make sure to add custom sanitization using the frm_update_field_options filter as the data will no longer be sanitized. | |
| 403 | - * | |
| 404 | - * @since 6.0 | |
| 405 | - * | |
| 406 | - * @param bool $should_sanitize | |
| 407 | - * @param string $opt | |
| 408 | - */ | |
| 409 | - $should_sanitize = apply_filters( 'frm_should_sanitize_field_opt_string', true, $opt ); | |
| 410 | - | |
| 411 | - if ( ! $should_sanitize ) { | |
| 412 | - return; | |
| 413 | - } | |
| 414 | - | |
| 415 | - if ( $opt === 'calc' ) { | |
| 416 | - $value = self::sanitize_calc( $value ); | |
| 417 | - } else { | |
| 418 | - $value = FrmAppHelper::kses( $value, 'all' ); | |
| 419 | - } | |
| 420 | - | |
| 421 | - $value = trim( $value ); | |
| 422 | 301 | } |
| 423 | 302 | |
| 424 | 303 | /** |
| 425 | 304 | * @param string $value |
| @@ -510,12 +389,8 @@ | ||
| 510 | 389 | 'description', |
| 511 | 390 | 'submit_value', |
| 512 | 391 | 'submit_msg', |
| 513 | 392 | 'success_msg', |
| 514 | - 'invalid_msg', | |
| 515 | - 'failed_msg', | |
| 516 | - 'login_msg', | |
| 517 | - 'admin_permission', | |
| 518 | 393 | ); |
| 519 | 394 | |
| 520 | 395 | return apply_filters( 'frm_form_strings', $strings, $form ); |
| 521 | 396 | } |
| @@ -687,12 +562,10 @@ | ||
| 687 | 562 | } |
| 688 | 563 | |
| 689 | 564 | $query_key = is_numeric( $id ) ? 'id' : 'form_key'; |
| 690 | 565 | $r = FrmDb::get_var( 'frm_forms', array( $query_key => $id ), 'name' ); |
| 566 | + $r = stripslashes( $r ); | |
| 691 | 567 | |
| 692 | - // An empty form name can result in a null value. | |
| 693 | - $r = is_null( $r ) ? '' : stripslashes( $r ); | |
| 694 | - | |
| 695 | 568 | return $r; |
| 696 | 569 | } |
| 697 | 570 | |
| 698 | 571 | /** |
| @@ -756,9 +629,9 @@ | ||
| 756 | 629 | if ( isset( $cache->options ) ) { |
| 757 | 630 | FrmAppHelper::unserialize_or_decode( $cache->options ); |
| 758 | 631 | } |
| 759 | 632 | |
| 760 | - return apply_filters( 'frm_form_object', wp_unslash( $cache ) ); | |
| 633 | + return wp_unslash( $cache ); | |
| 761 | 634 | } |
| 762 | 635 | } |
| 763 | 636 | |
| 764 | 637 | if ( is_numeric( $id ) ) { |
| @@ -814,13 +687,9 @@ | ||
| 814 | 687 | /** |
| 815 | 688 | * Get all published forms |
| 816 | 689 | * |
| 817 | 690 | * @since 2.0 |
| 818 | - * | |
| 819 | - * @param array $query | |
| 820 | - * @param int $limit | |
| 821 | - * @param string $inc_children | |
| 822 | - * @return array|object of forms A single form object would be passed if $limit was set to 1. | |
| 691 | + * @return array of forms | |
| 823 | 692 | */ |
| 824 | 693 | public static function get_published_forms( $query = array(), $limit = 999, $inc_children = 'exclude' ) { |
| 825 | 694 | $query['is_template'] = 0; |
| 826 | 695 | $query['status'] = array( null, '', 'published' ); |
| @@ -1120,39 +989,23 @@ | ||
| 1120 | 989 | return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id ); |
| 1121 | 990 | } |
| 1122 | 991 | |
| 1123 | 992 | /** |
| 1124 | - * Check if the "Submit this form with AJAX" setting is toggled on. | |
| 1125 | - * | |
| 1126 | - * @since 6.2 | |
| 1127 | - * | |
| 1128 | - * @param stdClass $form | |
| 1129 | - * @return bool | |
| 1130 | - */ | |
| 1131 | - public static function is_ajax_on( $form ) { | |
| 1132 | - return ! empty( $form->options['ajax_submit'] ); | |
| 1133 | - } | |
| 1134 | - | |
| 1135 | - /** | |
| 1136 | - * @deprecated 2.03.05 This is still referenced in a few add ons (API, locations). | |
| 993 | + * @deprecated 3.0 | |
| 1137 | 994 | * @codeCoverageIgnore |
| 1138 | 995 | * |
| 1139 | 996 | * @param string $key |
| 997 | + * | |
| 1140 | 998 | * @return int form id |
| 1141 | 999 | */ |
| 1142 | 1000 | public static function getIdByKey( $key ) { |
| 1143 | - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_id_by_key' ); | |
| 1144 | - return self::get_id_by_key( $key ); | |
| 1001 | + return FrmFormDeprecated::getIdByKey( $key ); | |
| 1145 | 1002 | } |
| 1146 | 1003 | |
| 1147 | 1004 | /** |
| 1148 | - * @deprecated 2.03.05 This is still referenced in the API add on as of v1.13. | |
| 1005 | + * @deprecated 3.0 | |
| 1149 | 1006 | * @codeCoverageIgnore |
| 1150 | - * | |
| 1151 | - * @param string|int $id | |
| 1152 | - * @return string | |
| 1153 | 1007 | */ |
| 1154 | 1008 | public static function getKeyById( $id ) { |
| 1155 | - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_key_by_id' ); | |
| 1156 | - return self::get_key_by_id( $id ); | |
| 1009 | + return FrmFormDeprecated::getKeyById( $id ); | |
| 1157 | 1010 | } |
| 1158 | 1011 | } |